mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-09 17:33:58 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -3,16 +3,20 @@
|
||||
You are testing **{target}** for Insecure CDN Resource Loading.
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
**METHODOLOGY:**
|
||||
### 1. Check External Resources
|
||||
- Find all `<script src="...">` and `<link href="...">` loading from CDNs
|
||||
- Check for `integrity="sha256-..."` (Subresource Integrity)
|
||||
- Check for `crossorigin` attribute
|
||||
### 2. Risk Assessment
|
||||
- Missing SRI on CDN scripts = supply chain risk
|
||||
- HTTP (not HTTPS) resource loading = MITM risk
|
||||
- Third-party resources from untrusted CDNs
|
||||
### 3. Report
|
||||
**METHODOLOGY — inventory external resources, then triage by blast radius:**
|
||||
### 1. Inventory external resources
|
||||
- Parse every `<script src>`, `<link rel=stylesheet href>`, `<link rel=preload/modulepreload>`, and dynamic `import()` in the rendered DOM (not just static HTML — render the SPA).
|
||||
- For each: origin host, over HTTP or HTTPS, `integrity="sha384-..."` (SRI) present?, `crossorigin` present?
|
||||
- Tools: `curl -s {target} | grep -Eo 'src="[^"]+"|href="[^"]+"'`, or render with Playwright and read `performance.getEntriesByType("resource")`; `nuclei -t misconfiguration/` for missing-SRI templates.
|
||||
### 2. Risk assessment / decision points
|
||||
- Missing SRI on a third-party script = supply-chain risk (defense-in-depth gap), Low by itself.
|
||||
- HTTP (not HTTPS) resource on an HTTPS page = active MITM can inject code → higher, and often flagged as mixed-content.
|
||||
- Which script matters: an auth/payment/session library (Stripe, an SSO SDK, a login widget) with no SRI is materially worse than a font or analytics beacon.
|
||||
- Dangling/abandoned CDN host or a versionless `@latest`/floating tag → the publisher can change the file under you; check if the CDN domain is even still registered (subdomain-takeover adjacent).
|
||||
### 3. Prove and disprove
|
||||
- Show the exact tag: URL, HTTP vs HTTPS, and that `integrity` is absent (or present-but-wrong).
|
||||
- False positives: SRI genuinely present; first-party same-origin script (SRI not required); a resource loaded but never executed; report an unregistered/takeover-able CDN host only after confirming it (don't claim compromise of a live, reputable CDN).
|
||||
### 4. Report
|
||||
'''
|
||||
FINDING:
|
||||
- Title: Missing SRI on CDN resource [URL]
|
||||
@@ -24,5 +28,6 @@ FINDING:
|
||||
- Impact: Supply chain attack if CDN compromised
|
||||
- Remediation: Add integrity attribute with SHA hash
|
||||
'''
|
||||
- Chaining hooks: an attacker-controllable/unregistered CDN host → subdomain-takeover → stored client-side code injection (effectively persistent XSS) on every page loading it.
|
||||
## System Prompt
|
||||
You are a CDN Security specialist. Missing SRI is Low severity — it is a defense-in-depth measure. The real risk is CDN compromise, which is rare. Focus on critical third-party scripts (payment, auth libraries) rather than fonts or analytics.
|
||||
You are a CDN Security specialist. Missing SRI is Low severity — it is defense-in-depth; the real risk is CDN compromise, which is rare for reputable providers. Focus on critical third-party scripts (payment, auth, session libraries) rather than fonts or analytics, and elevate when the resource loads over HTTP on an HTTPS page or the CDN host is dangling/unregistered (then it is a takeover, not just missing SRI). Prove the tag exists with its exact attributes; do not claim a live CDN is compromised. AUTHORIZED engagement; read-only.
|
||||
Reference in new issue
Block a user