mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 04:21:44 +02:00
Two halves of the same problem — proving what actually happened rather than what a response suggested. browser.rs — a payload echoed into HTML is reflection; it is XSS only when a browser parses that response and runs it. The gap between the two is where most XSS false positives live: the value lands in an attribute that is never evaluated, inside a <textarea>, HTML-encoded on the way out, or blocked by CSP. All four look identical to a string match on the body. So a real Chromium loads the URL and reports whether a marker THE HARNESS CHOSE came back through a channel only executing code can reach: a dialog message, a document.title assignment, a window global. A console line is watched too but never treated as decisive on its own — a page can log the value it reflected without ever running it. Payloads are self-reporting rather than generic (alert(1) proves nothing attributable) and cover the contexts a reflected value lands in: raw HTML, attribute break-out, event handler, URL, raw-text element, template expression. When the marker is reflected but does not execute, that is recorded as a note: it tells the operator the input reaches the response and the context is what stopped it. Missing node or playwright yields available:false and confirms nothing. A missing tool must never read as a missing vulnerability — or as a present one. replay.rs — the engagement recorded 25 accepted POSTs and concluded "reset email flooding". Those are facts at different layers and the pipeline could not say so. observe_effects() now records three: request_effect the response: status, headers, latency, size application_effect a read-back showing state actually changed external_effect something left the building (mail, webhook, job) Without a verification request the application layer is reported as unexamined rather than inferred from a 200 — APIs accept and ignore writes routinely. The external layer is honestly reported as unobserved until the harness owns a mailbox or callback listener. deepest_observed() gives the ceiling an impact claim may be built on, which is exactly the line the agent crossed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>