mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
+42
-4
@@ -1,7 +1,7 @@
|
||||
#!/usr/bin/env node
|
||||
'use strict';
|
||||
/**
|
||||
* NeuroSploit v4.2.0 — web console backend.
|
||||
* NeuroSploit v4.2.1 — web console backend.
|
||||
*
|
||||
* Zero-dependency Node HTTP server that:
|
||||
* - serves the static SPA in ./public
|
||||
@@ -506,10 +506,36 @@ async function runDetail(id) {
|
||||
function safeRunDir(id) {
|
||||
if (!/^[a-zA-Z0-9_.-]+$/.test(id)) return null;
|
||||
const dir = path.join(RUNS_DIR, id);
|
||||
if (!dir.startsWith(RUNS_DIR)) return null;
|
||||
// Contain the delete to RUNS_DIR: reject anything that resolves out of it
|
||||
// (defence in depth on top of the charset check, which already forbids `/`).
|
||||
if (dir !== RUNS_DIR && !dir.startsWith(RUNS_DIR + path.sep)) return null;
|
||||
return dir;
|
||||
}
|
||||
|
||||
/// Permanently delete one run: its whole directory (findings, evidence, PoCs,
|
||||
/// every report artifact) and its remembered engagement name. Returns false if
|
||||
/// the id is unsafe or the directory does not exist.
|
||||
async function deleteRun(id) {
|
||||
const dir = safeRunDir(id);
|
||||
if (!dir || dir === RUNS_DIR || !fs.existsSync(dir)) return false;
|
||||
await fsp.rm(dir, { recursive: true, force: true });
|
||||
if (engagementNames.delete(id)) {
|
||||
await fsp.mkdir(path.dirname(NAMES_FILE), { recursive: true })
|
||||
.then(() => fsp.writeFile(NAMES_FILE, JSON.stringify(Object.fromEntries(engagementNames), null, 2)))
|
||||
.catch(() => {});
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
/// Delete every run under RUNS_DIR (ns-* directories only). Returns the count.
|
||||
async function deleteAllRuns() {
|
||||
let ids = [];
|
||||
try { ids = (await fsp.readdir(RUNS_DIR)).filter((d) => d.startsWith('ns-')); } catch { return 0; }
|
||||
let n = 0;
|
||||
for (const id of ids) { if (await deleteRun(id)) n += 1; }
|
||||
return n;
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Exploitation jobs — spawn `neurosploit <mode> <target> --only ... -v`
|
||||
// and parse its stdout into structured live state (mirrors app/src/repl.rs
|
||||
@@ -1014,6 +1040,18 @@ const server = http.createServer(async (req, res) => {
|
||||
if (req.method === 'GET' && m) {
|
||||
return serveRunAsset(req, res, decodeURIComponent(m[1]), decodeURIComponent(m[2]));
|
||||
}
|
||||
// Delete ALL runs (must come before the single-run matcher below).
|
||||
if (req.method === 'DELETE' && p === '/api/runs') {
|
||||
const n = await deleteAllRuns();
|
||||
return sendJson(res, 200, { ok: true, deleted: n });
|
||||
}
|
||||
m = p.match(/^\/api\/runs\/([^/]+)$/);
|
||||
if (req.method === 'DELETE' && m) {
|
||||
const id = decodeURIComponent(m[1]);
|
||||
const ok = await deleteRun(id);
|
||||
if (!ok) return sendJson(res, 404, { error: 'run not found' });
|
||||
return sendJson(res, 200, { ok: true, deleted: 1, id });
|
||||
}
|
||||
|
||||
// ---- exploitation jobs ----
|
||||
if (req.method === 'GET' && p === '/api/exploit') {
|
||||
@@ -1191,7 +1229,7 @@ const server = http.createServer(async (req, res) => {
|
||||
}
|
||||
|
||||
if (req.method === 'GET' && p === '/api/meta') {
|
||||
return sendJson(res, 200, { version: '4.0.0', binary: BIN, root: ROOT });
|
||||
return sendJson(res, 200, { version: '4.2.1', binary: BIN, root: ROOT });
|
||||
}
|
||||
|
||||
// ---- providers / API keys (in-memory only, never persisted) ----
|
||||
@@ -1223,7 +1261,7 @@ const server = http.createServer(async (req, res) => {
|
||||
});
|
||||
|
||||
server.listen(PORT, () => {
|
||||
console.log(`NeuroSploit v4.2.0 web console → http://localhost:${PORT}`);
|
||||
console.log(`NeuroSploit v4.2.1 web console → http://localhost:${PORT}`);
|
||||
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
|
||||
console.log(` agents : ${AGENTS_DIR}`);
|
||||
console.log(` runs : ${RUNS_DIR}`);
|
||||
|
||||
Reference in new issue
Block a user