mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 04:21:44 +02:00
feat(chain,skills): close benchmark misses — CRLF-on-Location, second-order precondition; condense BENCHMARK
The 13-target benchmark left 3 misses. Root-caused and fixed the two that were coverage gaps (the third was single-run variance, already handled by the session-limit fix): - CRLF header injection (web_crlf_header_go): the agent confirmed the open redirect on /go?url= and stopped; the CRLF payload was never generated. The open_redirect skill now tests %0d%0a header injection on the SAME param, and CHAIN_DOCTRINE says a param landing in a Location header must also be tested for response splitting. chain.rs: CWE-113/93/644 now provide capabilities; attack_graph maps their kill-chain stage. - Second-order SQLi (web_sqli_second_order): the sink was behind /admin, which the customer account could not reach. CHAIN_DOCTRINE now teaches the precondition pattern (store the payload, trigger from every identity, escalate first if the trigger page needs a role you lack, else report as a chained lead). chain.rs: CWE-564 requires PrivilegedContext so it chains after privesc. BENCHMARK.md: added the TypeSafe calibrated-adjudication row; dropped the "genuinely ahead" prose (the table is the summary); condensed the rest 188 -> 89 lines; refreshed scale (27 validators, 47 modules, 383 tests). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
dff2e3c0f0
commit
fce86522ca
@@ -20,6 +20,13 @@ You are testing **{target}** for Open Redirect vulnerabilities.
|
||||
- Follow the redirect chain manually
|
||||
- Check if Location header points to external domain
|
||||
- Verify the browser actually navigates to evil.com
|
||||
### 3b. Same param, test CRLF / header injection
|
||||
A parameter that lands in the `Location` header is also a response-splitting
|
||||
sink. On the SAME parameter, try:
|
||||
- `/go?url=/%0d%0aX-Injected:%20pwned` — look for `X-Injected: pwned` as a real response header
|
||||
- `/go?url=/%0d%0aSet-Cookie:%20session=attacker` — a planted cookie header
|
||||
- If the marker appears as a HEADER (not the body), that is CRLF injection (CWE-113), report it IN ADDITION to the open redirect. Never stop at the redirect.
|
||||
|
||||
### 4. Chain with Other Vulns
|
||||
- OAuth token theft via redirect_uri manipulation
|
||||
- Phishing: redirect from trusted domain to fake login
|
||||
|
||||
Reference in New Issue
Block a user