Files
NeuroSploit/examples/scopes/rockstargames.yaml
T
CyberSecurityUPandClaude Opus 4.8 4ef1c9cada feat: importable scope configs + /scope-file REPL command; Rockstar & NASA templates
- /scope-file <path> (aliases /scopefile, /import-scope): import a ready scope
  config (hard allowlist + exclusions + guardrails) in the REPL — one step to
  "scope set correctly", instead of typing /inscope repeatedly. Pins the scope.
- scope_pinned: once scope is set explicitly (scope-file / /inscope / capability),
  /target no longer re-derives the scope from the target, so an imported
  allowlist is not clobbered by picking a target.
- examples/scopes/rockstargames.yaml and examples/scopes/nasa.yaml — ready
  TEMPLATES scoped to *.rockstargames.com / *.nasa.gov with conservative,
  bounty/VDP-safe guardrails (no destructive verbs, no mass accounts, low rate,
  forbidden payloads) and a clear "verify the program's current in/out-of-scope
  before running" banner. Both parse and enforce; subdomain enumeration happens
  inside the wildcard boundary.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:53:53 -03:00

75 lines
3.5 KiB
YAML

# ===========================================================================
# NeuroSploit scope config — Rockstar Games (TEMPLATE)
# ---------------------------------------------------------------------------
# ⚠ BEFORE YOU RUN: confirm this matches the program's CURRENT scope.
# Rockstar Games bug bounty: https://hackerone.com/rockstargames
# Open the program page and align the `hard` allowlist and `exclude` list
# below with the EXACT in-scope / out-of-scope assets it lists today. Scope
# on a bounty program changes; this file is a starting point, not authority.
#
# HARD scope is enforced in code: a request whose host is not covered by `hard`
# (or hit by `exclude`) is REFUSED before it leaves. `*.rockstargames.com`
# authorizes the apex AND every subdomain, so NeuroSploit's recon will
# enumerate subdomains and test them within this boundary.
#
# Import it:
# neurosploit run "*.rockstargames.com" --scope-file examples/scopes/rockstargames.yaml --subscription
# or in the REPL:
# /scope-file examples/scopes/rockstargames.yaml
# /authorization https://hackerone.com/rockstargames
# /target *.rockstargames.com
# /run
# ===========================================================================
# --- HARD: the allowlist. Only these are testable. ------------------------
# Start with the apex + all subdomains the user named. ADD the specific extra
# roots the program lists (and REMOVE this wildcard if the program only allows
# named subdomains — check first).
hard:
- "*.rockstargames.com" # apex + every subdomain
- rockstargames.com # the apex itself
# --- EXCLUDE: carve-outs that always beat the allowlist. ------------------
# Fill these in from the program's OUT-OF-SCOPE list. Common exclusions on a
# gaming publisher: live game servers, payment/billing, support/helpdesk,
# status pages, third-party-hosted marketing. Examples below are PLACEHOLDERS —
# verify the real ones on the program page before relying on them.
exclude:
# - support.rockstargames.com
# - "*.status.rockstargames.com"
# - https://www.rockstargames.com/billing
# --- SOFT: guardrails inside the boundary (bounty-safe defaults) -----------
soft:
# Hosts you may LOOK at but never send payloads to.
observe_only: []
# State-mutating verbs (DELETE/PUT/PATCH) stay OFF — a scan must not change
# the target's state to "prove" a bug on someone's production.
allow_destructive_methods: false
# No account creation by default. Most programs forbid mass registration;
# flip to true only if the program allows it AND keep it to a couple accounts.
allow_account_creation: false
max_accounts: 0
# Conservative rate: a bounty target is production. Raise only within the
# program's stated limit.
max_requests_per_minute: 120
# Classes that damage production rather than demonstrate a bug — never run.
forbidden_payloads:
- "drop table"
- "truncate table"
- "delete from"
- "rm -rf /"
- "shutdown"
- "while(true)"
# Free-text context for the agents (NOT enforced — prose, not a control).
notes:
- "Authorized under the Rockstar Games bug bounty program (https://hackerone.com/rockstargames)."
- "Stay within the program's rules of engagement: no DoS, no social engineering, no spam/mass-account creation, no disruption of live game services."
- "Prove data access with a benign canary, never pull real player PII."
- "Verify in/out-of-scope on the program page before each run — scope changes."