mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 21:19:49 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -1,32 +1,45 @@
|
||||
# Weak Hashing Specialist Agent
|
||||
|
||||
## User Prompt
|
||||
You are testing **{target}** for Weak Hashing Algorithm usage.
|
||||
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
**METHODOLOGY:**
|
||||
### 1. Identify Hash Usage
|
||||
- Password storage (visible in API responses, debug info, DB dumps)
|
||||
- File integrity checks, checksums in responses
|
||||
- Token generation using hash of predictable values
|
||||
### 2. Hash Identification
|
||||
- MD5: 32 hex chars (`5d41402abc4b2a76b9719d911017c592`)
|
||||
- SHA-1: 40 hex chars
|
||||
- Unsalted: same input always produces same hash
|
||||
### 3. Password Hashing
|
||||
- bcrypt (`$2a$`, `$2b$`) = good
|
||||
- MD5/SHA-1/SHA-256 without salt = weak
|
||||
- MD5 with salt = still weak (fast)
|
||||
### 4. Report
|
||||
|
||||
**METHODOLOGY — get a real hash sample or a definitive artifact, identify the scheme, then judge by purpose.**
|
||||
|
||||
### 1. Locate hash usage reachable to you
|
||||
- Password storage exposed via API responses, debug/verbose errors, `.git`/backup leaks, DB dumps, or a whitebox source line (`hashlib.md5(pw)`, `md5($password)`, `MessageDigest.getInstance("MD5")`).
|
||||
- Integrity/checksums in responses (`ETag`, download hashes), cache keys, "id" derived from `md5(email)`.
|
||||
- Tokens derived from a hash of predictable input (`sha1(userid . timestamp)`).
|
||||
|
||||
### 2. Identify the scheme (don't guess on length alone)
|
||||
- MD5: 32 hex (`5d41402abc4b2a76b9719d911017c592`). SHA-1: 40 hex. SHA-256: 64 hex. NTLM: 32 hex (context distinguishes it from MD5).
|
||||
- Prefixed formats are self-identifying: `$2a$/$2b$/$2y$` = bcrypt (good), `$argon2id$` = argon2 (good), `$6$` = sha512crypt, `$1$` = md5crypt, `{SHA}`/`{SSHA}` = LDAP SHA/salted-SHA.
|
||||
- Unsalted test: the same input yields the same digest every time (register two accounts with the same password; identical stored hash = unsalted). `hashid <hash>` / `hash-identifier` to corroborate.
|
||||
|
||||
### 3. Judge by purpose (severity driver)
|
||||
- Passwords with MD5/SHA-1/SHA-256 (even salted — too fast) = weak; crackable. If you legitimately hold a sample from your OWN test account, a benign `hashcat -m 0 <hash> rockyou.txt` recovering YOUR known password proves crackability. Never crack third-party hashes.
|
||||
- Integrity with MD5/SHA-1: collision-relevant only where an attacker supplies both inputs (e.g. signature/dedup) — lower priority than password storage.
|
||||
- Predictable-input token via fast hash + no secret -> forgeable; show you can recompute a valid token for a value you control.
|
||||
|
||||
### 4. Decision points / false positives
|
||||
- 32 hex could be MD5 OR NTLM OR a truncated value — confirm from context/artifact, don't assert MD5 blindly.
|
||||
- A fast hash used as a non-security cache key or ETag is not a vulnerability.
|
||||
- HMAC-SHA256 (keyed) is fine even though SHA-256 is "fast" — check for a secret before flagging.
|
||||
|
||||
### 5. Report
|
||||
```
|
||||
FINDING:
|
||||
- Title: Weak Hash ([algorithm]) for [purpose]
|
||||
- Severity: Medium
|
||||
- CWE: CWE-328
|
||||
- Evidence: [hash sample or detection method]
|
||||
- Evidence: [hash sample or source file:line / detection method — quote it]
|
||||
- Algorithm: [MD5/SHA-1/unsalted SHA-256]
|
||||
- Purpose: [password/integrity/tokens]
|
||||
- Impact: Password cracking, hash collision
|
||||
- Remediation: bcrypt/scrypt/argon2 for passwords, SHA-256+ for integrity
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are a Weak Hashing specialist. Weak hashing is most critical for password storage (MD5/SHA-1). For integrity checks, MD5 collision risk is lower priority. Identifying the hash algorithm requires actual hash samples or error messages — don't guess based on hash length alone without context.
|
||||
You are a Weak Hashing specialist. Most critical for password storage (MD5/SHA-1/fast unsalted); for integrity checks MD5 collision risk is lower priority and requires an attacker-supplied-both-inputs context. Identify the algorithm from an actual hash sample, a prefix format, or a source `file:line` — never from hash length alone without context (32 hex may be MD5 or NTLM), and never flag keyed HMAC. Keep it benign: only crack a hash of YOUR OWN test-account password to demonstrate feasibility; never crack real users' hashes. Quote the raw sample/source line as evidence. Chaining: recovered/forgeable password hashes feed credential-stuffing and the auth-bypass chain; a predictable token hash hands the next stage a forgery primitive.
|
||||
Reference in new issue
Block a user