Files
NeuroSploit/examples/scopes/nasa.yaml
T
CyberSecurityUPandClaude Opus 4.8 4ef1c9cada feat: importable scope configs + /scope-file REPL command; Rockstar & NASA templates
- /scope-file <path> (aliases /scopefile, /import-scope): import a ready scope
  config (hard allowlist + exclusions + guardrails) in the REPL — one step to
  "scope set correctly", instead of typing /inscope repeatedly. Pins the scope.
- scope_pinned: once scope is set explicitly (scope-file / /inscope / capability),
  /target no longer re-derives the scope from the target, so an imported
  allowlist is not clobbered by picking a target.
- examples/scopes/rockstargames.yaml and examples/scopes/nasa.yaml — ready
  TEMPLATES scoped to *.rockstargames.com / *.nasa.gov with conservative,
  bounty/VDP-safe guardrails (no destructive verbs, no mass accounts, low rate,
  forbidden payloads) and a clear "verify the program's current in/out-of-scope
  before running" banner. Both parse and enforce; subdomain enumeration happens
  inside the wildcard boundary.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:53:53 -03:00

64 lines
2.8 KiB
YAML

# ===========================================================================
# NeuroSploit scope config — NASA (TEMPLATE)
# ---------------------------------------------------------------------------
# ⚠ BEFORE YOU RUN: confirm this matches NASA's CURRENT VDP scope.
# NASA Vulnerability Disclosure Policy: https://www.nasa.gov/nasa-vulnerability-disclosure-policy/
# (coordinated via https://bugcrowd.com/nasa-vdp). Open the policy/program
# page and align `hard` / `exclude` with the EXACT in- and out-of-scope assets
# it lists today. A VDP is for good-faith disclosure — follow its rules.
#
# `*.nasa.gov` authorizes the apex AND every subdomain, so NeuroSploit's recon
# will enumerate subdomains and test within this boundary. NASA runs MANY
# subdomains/mission sites; several are explicitly out of scope and some are
# third-party hosted — verify before testing.
#
# Import it:
# neurosploit run "*.nasa.gov" --scope-file examples/scopes/nasa.yaml --subscription
# or in the REPL:
# /scope-file examples/scopes/nasa.yaml
# /authorization https://www.nasa.gov/nasa-vulnerability-disclosure-policy/
# /target *.nasa.gov
# /run
# ===========================================================================
# --- HARD: the allowlist. Only these are testable. ------------------------
hard:
- "*.nasa.gov" # apex + every subdomain (VERIFY against the VDP)
- nasa.gov
# --- EXCLUDE: carve-outs that always beat the allowlist. ------------------
# Fill from the VDP's OUT-OF-SCOPE list. Typical for a large gov org: auth/SSO
# providers, third-party-hosted services, APIs with their own terms, and any
# system the policy names as excluded. Examples are PLACEHOLDERS — verify.
exclude:
# - auth.launchpad.nasa.gov
# - "*.ndc.nasa.gov"
# - api.nasa.gov # has its own API terms / key system — check first
# --- SOFT: guardrails inside the boundary (VDP-safe, conservative) ---------
soft:
observe_only: []
# No state-mutating verbs, no account creation — a government VDP expects
# minimal-impact, good-faith testing.
allow_destructive_methods: false
allow_account_creation: false
max_accounts: 0
# Low rate: these are production government systems.
max_requests_per_minute: 60
forbidden_payloads:
- "drop table"
- "truncate table"
- "delete from"
- "rm -rf /"
- "shutdown"
- "while(true)"
notes:
- "Authorized under NASA's Vulnerability Disclosure Policy (good-faith research only)."
- "No DoS, no social engineering, no physical testing, no disruption of operations or spacecraft/mission systems."
- "Access only the minimum data needed to demonstrate a vulnerability; never exfiltrate or retain PII/ITAR/sensitive data; stop and report if you encounter it."
- "Verify in/out-of-scope on the VDP page before each run — scope changes."