Files
NeuroSploit/web
CyberSecurityUPandClaude Opus 5 8aa776665a feat(net): fail-closed egress, self-hosted OOB channel, inbound SMS
transport.rs — internal engagements happen through a VPN, a bastion or a
tunnel, and the dangerous failure is silent: with the VPN down, 10.20.0.15
is a machine on the operator's own network and the scan succeeds against
the wrong host. So an internal target with no transport is refused before
any traffic leaves, and a transport that is up must prove it (the apparent
source address has to change) rather than be assumed. Supports SOCKS, HTTP
proxy, OpenVPN, SSH bastion (dynamic or single-host forward) and cloudflared.

oob.rs — our own Collaborator, self-hosted by default because callbacks are
engagement data (internal hostnames, resolver addresses, sometimes the
exfiltrated value). HTTP and DNS listeners written on tokio directly, no new
dependency. The two levels of proof are separated in code: an HTTP callback
proves egress, a DNS query proves only that a resolver saw the name — the
overclaim this channel otherwise invites.

inbox.rs — mail.tm and inbound SMS (Twilio or webhook). extract_code() scores
candidates by surrounding text and returns nothing rather than a guess, so a
copyright year never gets submitted as an OTP. A throttling claim requires
delivered messages carrying DISTINCT codes, not HTTP 200s.

Wired through RunConfig, the CLI (global flags, so a session cannot re-route
itself mid-engagement), the REPL and the web console's Authorization tab.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 01:35:36 -03:00
..

NeuroSploit v4.0.0 — web console

A browser UI for the neurosploit CLI harness: a 5-step engagement wizard (Asset → Scope & Auth → Leads → Model & Run → Review), a live structured findings view with a generative attack-path graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual CLI binary, never a reimplementation of harness logic.

  • Asset — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
  • Scope & Auth — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
  • Leads — the categorized agent picker (435 agents auto-classified) + custom leads.
  • Model & Run — pick a provider/model from the live catalog, API-key vs. subscription auth mode, votes/chain-depth/recon intensity.
  • Review — confirm the plan, then Start Exploitation spawns the real CLI.
  • Auth & Keys (one menu, 🔑 in the sidebar) — target auth header + named roles for IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and an explicit creds.yaml path override.
  • Generative Attack Path Chaining — findings are grouped into kill-chain columns (recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings linked back to their parent, built live as findings stream in.
  • Terminal dock (xterm.js) — ❭_ in the sidebar, the topbar button, or Ctrl+\`` opens a docked terminal running a real neurosploitREPL session. Its stdout is streamed **unstripped**, so the harness's own colour and box-drawn panels render as they do in a local shell. Line editing (echo, ←/→, history,Tabslash-command completion,Ctrl+C/L/U/A/E`) is local because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target picker in its header switches between a standalone session and the running engagement, so mid-run instructions go to the same process that is doing the testing.
  • Real REPL underneath run/whitebox/greybox — the wizard scripts an actual interactive neurosploit session instead of a one-shot CLI call, so it keeps reading stdin while the engagement streams. The Activity log tab grows a ❭ prompt box to send /status, /stop, /continue, or a plain-language instruction mid-run. host/aitest/skills stay one-shot (their onboarding scope picker can't be scripted over piped stdin).
cd neurosploit-rs && cargo build --release   # build the CLI once
node web/server.js                            # → http://localhost:4173

Zero npm dependencies (Node ≥18, built-ins only: http, child_process, events, fs).

API reference: API.md.

Layout

web/
├── server.js         backend: static server + agents_md/runs reader + CLI process manager
├── public/
│   ├── index.html     SPA shell
│   ├── style.css       lead-board / live-run / terminal-dock styling
│   ├── app.js          client logic (fetch + EventSource + terminal, no framework)
│   └── vendor/         xterm.js + fit addon (vendored; nothing is fetched at runtime)
├── API.md
└── package.json