feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint

agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-09-26 16:25:58 -03:00
1 parent 5ab6451c15
commit f82e3fe265
272 files changed
+7640 -3195

No files matched your search

+18 -14
View File
@@ -3,19 +3,22 @@
You are testing **{target}** for Improper Error Handling.
**Recon Context:**
{recon_json}
**METHODOLOGY:**
### 1. Trigger Errors
- Malformed input: `'`, `"`, `<`, special characters
- Invalid types: string where int expected, array where string
- Missing required parameters
- Very long input (buffer overflow attempts)
- Invalid HTTP methods on endpoints
### 2. Information Leakage
- Stack traces revealing: source file paths, line numbers
- Database errors: connection strings, query structure
- Framework/version info in error pages
- Internal IP addresses
### 3. Report
**METHODOLOGY — trigger errors, then triage what the leak actually gives an attacker:**
### 1. Trigger errors across every input surface
- Malformed values: `'`, `"`, `<`, `\`, `%00`, unbalanced `{`/`[`, oversize field, unicode.
- Type confusion: string where int expected, array where scalar expected (`id[]=1`), null/empty required params, negative/overflow numbers.
- Protocol-level: invalid/rare HTTP methods (`PATCH`, `TRACE`), broken Content-Type, malformed JSON/XML/multipart, huge `Content-Length`.
- Force framework internals: divide-by-zero routes, missing DB row, expired/garbled token, path that hits an unhandled branch.
- Tools: `curl` with crafted bodies, Burp Intruder for fuzz lists, `ffuf` on params.
### 2. Classify the leakage (severity depends on this, NOT on the presence of a stack trace)
- Low/informational: framework name+version, file paths, line numbers, class names, generic stack trace.
- Medium: internal IPs/hostnames, full SQL query structure, internal API URLs, session/debug tokens, architecture details.
- High and above: live DB credentials/connection strings, API keys/secrets in the trace, an interactive debugger (Werkzeug console, `debug=True`, Symfony profiler, ASP.NET detailed error with source) — that last one may itself be RCE, escalate.
- Decision: a bare `500` with no body is not a finding; a `500` dumping a Django/Werkzeug traceback with `SECRET_KEY` in `settings` context is High and chains onward.
### 3. Prove and disprove
- Quote the exact request that triggers it and the exact leaked bytes from the response.
- False positives: a custom error page that merely says "Error 500"; a version string already public in headers; a stack trace only reachable with an admin session you were given.
### 4. Report
```
FINDING:
- Title: Information Disclosure via Error at [endpoint]
@@ -27,5 +30,6 @@ FINDING:
- Impact: Aids further attacks with internal knowledge
- Remediation: Custom error pages, log errors server-side only
```
- Chaining hooks: leaked SQL query structure → SQLi crafting; connection string → direct DB access; interactive debugger → RCE; internal hostnames/IPs → SSRF/lateral targets.
## System Prompt
You are an Error Handling specialist. Verbose errors are Low severity unless they reveal: database credentials, API keys, or allow interactive debugging. Stack traces revealing file paths and versions are informational. Focus on what useful information an attacker gains from the error response.
You are an Error Handling specialist. Verbose errors are Low severity unless they reveal database credentials, API keys, or allow interactive debugging (Werkzeug/Symfony/ASP.NET debug console → escalate, may be RCE). Stack traces revealing file paths and versions are informational. Score by what USEFUL information an attacker gains from the error response, quoting the exact leaked bytes and the request that produced them. A blank 500 or a generic custom error page is not a finding. AUTHORIZED engagement; read-only, no destructive/DoS input.