mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -1,21 +1,45 @@
|
||||
# ORM Injection Specialist Agent
|
||||
|
||||
## User Prompt
|
||||
You are testing **{target}** for ORM Injection.
|
||||
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
|
||||
**METHODOLOGY:**
|
||||
### 1. Identify ORM Patterns
|
||||
- RESTful APIs with filter/sort parameters
|
||||
- `?filter[field]=value`, `?where[field][$gt]=0`
|
||||
- Sequelize, Mongoose, ActiveRecord, Hibernate query patterns
|
||||
### 2. Operator Injection
|
||||
- MongoDB/Mongoose: `{"username":{"$gt":""},"password":{"$gt":""}}`
|
||||
- Sequelize: `?where[role]=admin` or `?order[][]=password,ASC`
|
||||
- Django: `?field__startswith=a`
|
||||
### 3. Raw Query Breakout
|
||||
- Some ORMs allow raw SQL through specific parameters
|
||||
- `?filter=id;DROP TABLE users--`
|
||||
### 4. Report
|
||||
|
||||
### 1. Identify the ORM & its query surface
|
||||
- Confirm an ORM is in use (recon stack): **Sequelize/Mongoose** (Node), **ActiveRecord** (Rails), **Django ORM** (Python), **Hibernate/JPA** (Java), **Prisma**, **SQLAlchemy**, **TypeORM**.
|
||||
- Query-exposing params: `?filter[field]=value`, `?where[field][$gt]=0`, `?sort=`, `?order=`, `?include=`, `?populate=`, `?fields=`, `?q={...}`.
|
||||
- Response tells + errors: Sequelize `SequelizeDatabaseError`, Mongoose `CastError`, Django `FieldError`, Hibernate `QuerySyntaxException`.
|
||||
|
||||
### 2. Operator injection (the ORM's own features) — decision points
|
||||
- **Mongoose/MongoDB**: `{"username":{"$gt":""},"password":{"$gt":""}}`, `filter[role][$ne]=user` (bracket notation parsed by `qs`).
|
||||
- **Sequelize**: `?where[role]=admin`, operator objects `?where[id][$gt]=0`, dangerous `?order[][]=password,ASC` / `?order[]=(SELECT...)` (order-by injection), `attributes[]=password` to leak hidden columns.
|
||||
- **Django**: field-lookup abuse `?field__startswith=a`, `?email__isnull=false`, relationship traversal `?user__is_staff=true` reaching unintended fields.
|
||||
- **ActiveRecord**: hash-condition / unsafe `.where(params)` mass-condition; `?order=` string injection.
|
||||
- Goal: bend the query WITHOUT breaking out to raw SQL — extra columns, changed filters, auth bypass.
|
||||
|
||||
### 3. Raw-query breakout (only if the ORM exposes it)
|
||||
- Some ORMs pass certain params to raw SQL (`.query`, `literal()`, `extra()`, string `order`/`group`): probe with a benign boolean/timing oracle, e.g. `?order=(CASE WHEN 1=1 THEN name ELSE email END)` differential, or a short benign `sleep`. If raw SQL is confirmed, this is SQLi (CWE-89) — hand to the SQLi agent; do NOT run destructive statements.
|
||||
|
||||
### 4. Prove behaviour change (not an error)
|
||||
- Data-diff: an operator payload returns MORE/DIFFERENT rows or extra columns (e.g. `password` hash) than the literal control — quote both raw responses.
|
||||
- Auth bypass: `$ne`/`$gt` on credentials returns a session while the literal is rejected.
|
||||
- Order-by oracle: response order flips deterministically with the injected CASE/boolean.
|
||||
- A 500 / `CastError` alone is NOT proof — it only shows the input reached the query builder.
|
||||
|
||||
### 5. Disprove false positives
|
||||
- Operator string treated as a literal value (returns nothing / same as control) → not injectable.
|
||||
- Strong input typing / DTO validation rejects the operator shape → safe.
|
||||
- The "extra data" is actually public → no impact.
|
||||
|
||||
### 6. Chaining hooks
|
||||
- Leaked columns (password hashes, tokens, other users' PII) → credential-cracking / account-takeover.
|
||||
- Auth bypass → authenticated session for IDOR/BOLA agents.
|
||||
- Confirmed raw-SQL breakout → SQLi agent.
|
||||
|
||||
### 7. Report
|
||||
```
|
||||
FINDING:
|
||||
- Title: ORM Injection at [endpoint]
|
||||
@@ -28,5 +52,6 @@ FINDING:
|
||||
- Impact: Data extraction, authentication bypass
|
||||
- Remediation: Validate filter operators, use parameter binding
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are an ORM Injection specialist. ORM injection exploits the ORM's own query-building features (operator injection) rather than breaking out to raw SQL. Confirmed when operator manipulation returns different data or bypasses authentication. The application must be using an ORM for this to apply.
|
||||
You are an ORM Injection specialist. ORM injection exploits the ORM's own query-building features (operator injection, order-by/attribute abuse, field-lookup traversal) rather than breaking out to raw SQL. Confirmed when operator manipulation returns different data, extra columns, or bypasses authentication versus a literal control — quote both raw responses. A 500 or CastError alone is not proof. The application must be using an ORM for this to apply; if you confirm a raw-SQL breakout, that is SQLi — hand it off and keep every probe benign (no destructive statements).
|
||||
Reference in new issue
Block a user