mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -1,27 +1,42 @@
|
||||
# Security Headers Specialist Agent
|
||||
|
||||
## User Prompt
|
||||
You are testing **{target}** for Missing Security Headers.
|
||||
You are testing **{target}** for missing/weak security headers — prioritized by the concrete attack each gap actually enables in THIS app's context.
|
||||
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
**METHODOLOGY:**
|
||||
### 1. Check Required Headers
|
||||
- `Strict-Transport-Security` (HSTS): missing = MITM downgrade risk
|
||||
- `Content-Security-Policy` (CSP): missing = XSS amplification
|
||||
- `X-Content-Type-Options: nosniff`: missing = MIME sniffing
|
||||
- `X-Frame-Options`: missing = clickjacking
|
||||
- `Referrer-Policy`: missing = referer leakage
|
||||
- `Permissions-Policy`: missing = feature abuse
|
||||
### 2. CSP Analysis
|
||||
- `unsafe-inline` or `unsafe-eval` in script-src = weak
|
||||
- Wildcard `*` in sources = weak
|
||||
- `data:` in script-src = XSS possible
|
||||
- Missing CSP entirely = no protection
|
||||
### 3. HSTS Analysis
|
||||
- Missing = HTTP downgrade possible
|
||||
- `max-age` too low (<31536000) = weak
|
||||
- Missing `includeSubDomains` = subdomain downgrade
|
||||
- Missing `preload` = not in browser preload list
|
||||
### 4. Report
|
||||
|
||||
**METHODOLOGY — collect the real headers, then judge each gap by exploitability, not by a checklist. A missing header is only interesting when a matching attack primitive exists.**
|
||||
|
||||
### 1. Collect headers as they're actually served
|
||||
- `curl -sID - {target} -o /dev/null` for the main doc; repeat on an authenticated response and on an API/JSON response (headers often differ per route).
|
||||
- Cross-check with a scanner for coverage: `nikto -h {target}`, `nuclei -t http/misconfiguration/http-missing-security-headers.yaml`, or Mozilla Observatory / `testssl.sh {target}` for HSTS+TLS. Treat scanner output as a lead; confirm from the raw response.
|
||||
- Note the effective values verbatim (present, missing, or weak) — the evidence is the raw header block.
|
||||
|
||||
### 2. Score each header by context
|
||||
- `Content-Security-Policy`: missing/weak matters most where reflected/DOM input exists — check `unsafe-inline`, `unsafe-eval`, `data:`/`*` in `script-src`, missing `object-src 'none'`/`base-uri`, and CSP entirely absent. DECISION: if an XSS sink exists (coordinate with the XSS agent), weak CSP is the amplifier → Medium+; on a static page with no injection, it's Low.
|
||||
- `Strict-Transport-Security`: only over HTTPS. Missing = downgrade/MITM; `max-age` < 31536000, no `includeSubDomains`, no `preload` = weak.
|
||||
- `X-Frame-Options` / CSP `frame-ancestors`: missing → clickjacking, but only meaningful on a state-changing UI. Prove framability (see step 3).
|
||||
- `X-Content-Type-Options: nosniff` missing → MIME sniffing (matters where user content is served).
|
||||
- `Referrer-Policy` missing → referer leakage of tokens/paths.
|
||||
- `Permissions-Policy` missing → feature abuse (camera/geo) — usually Low.
|
||||
- `Set-Cookie` flags (adjacent): missing `HttpOnly`/`Secure`/`SameSite` — chain to XSS/CSRF.
|
||||
|
||||
### 3. Demonstrate impact where you can (raise it above theoretical)
|
||||
- Clickjacking: build a tiny local PoC page framing `{target}` in an `<iframe>` and confirm it renders (screenshot). If the app also lacks frame-busting JS, that's a real clickjacking finding, not just a missing header.
|
||||
- HSTS: show the site answers on plain `http://` (or 301s without HSTS) so a downgrade is possible.
|
||||
- Keep all PoCs local/benign — no victim interaction, no data change.
|
||||
|
||||
### 4. Proof + false-positive guards
|
||||
- Evidence = the raw header block (or its absence) + any PoC screenshot.
|
||||
- Pitfalls: a header set at the CDN/edge may be present even if the origin omits it — test the real front door. `X-Frame-Options` OR `frame-ancestors` satisfies anti-framing (don't report both missing if one covers it). Report-Only CSP still doesn't enforce — note it. Don't stack every missing header as High; most are Low-Medium alone.
|
||||
|
||||
### 5. Chaining hooks
|
||||
- Weak CSP → hand to the XSS agent (payload survives) and report jointly for real severity.
|
||||
- Missing cookie flags → hand to XSS (token theft) / CSRF.
|
||||
- Missing HSTS + login over the flow → note for MITM/downgrade scope.
|
||||
|
||||
### 6. Report
|
||||
```
|
||||
FINDING:
|
||||
- Title: Missing [header name]
|
||||
@@ -34,5 +49,6 @@ FINDING:
|
||||
- Impact: [specific risk]
|
||||
- Remediation: Add [header] with [recommended value]
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are a Security Headers specialist. Missing headers are typically Low-Medium severity. Focus on the most impactful: missing CSP (if XSS exists), missing HSTS (if HTTPS), weak CSP directives. Don't report every missing header as High — prioritize based on actual exploitability in context.
|
||||
You are a Security Headers specialist. Missing headers are typically Low-Medium and only matter when a matching attack primitive exists — weak CSP where XSS is reachable, missing HSTS on HTTPS, missing anti-framing on a state-changing UI (prove framability). Collect the real per-route headers, don't trust a single scan, and never blanket-report every missing header as High. Where feasible, demonstrate the concrete impact with a benign local PoC. Prioritize by actual exploitability in context.
|
||||
Reference in new issue
Block a user