Files
NeuroSploit/web/README.md
T
CyberSecurityUPandClaude Opus 5 0ef0ce8d94 feat(web): xterm.js terminal dock + front-end QA pass
Replaces the floating REPL drawer with a docked terminal, and fixes the
usability problems a screenshot audit of the console turned up.

Terminal (the reason for the change):

- The drawer rendered the harness into a <div>, so the server had to strip
  ANSI before sending it: colour, the box-drawn /status panel and the banner
  all arrived flattened, and long lines rewrapped mid-glyph. The stream is now
  sent verbatim and rendered by xterm.js (vendored, nothing fetched at
  runtime), decoded with a streaming UTF-8 decoder so a multi-byte character
  split across two reads survives.
- The drawer floated bottom-right, directly over "Next →" and "Start
  Exploitation" — the wizard's primary buttons. The dock is a flex child of
  .main, so opening it shortens the view instead of covering it. Drag its top
  edge to resize; the height is remembered.
- The child is spawned over a pipe, not a PTY, so it never echoes: line
  editing is local — echo, ←/→, Home/End, history, Tab completion over the
  slash commands, Ctrl+C/L/U/K/A/E. Ctrl-C is delivered as SIGINT by the
  server, since a raw 0x03 byte over a pipe interrupts nothing.
- A target picker switches the terminal between a standalone REPL session and
  the engagement currently running, so mid-run instructions go to the same
  process doing the testing.

QA fixes:

- Findings tables sorted by severity (a LOW above a CRITICAL made a 27-row
  result unreadable), with sortable headers, a severity summary that doubles
  as a filter, a text filter, a sticky header, and horizontal scroll confined
  to the table instead of the whole page.
- alert()/prompt() replaced by inline field errors, a custom-lead modal and
  toasts — a modal alert hid the very field it was complaining about.
- Lead categories start collapsed (412 leads over ~30 categories); search
  auto-expands what it matches and shows per-category hit counts.
- Sidebar rows truncate inside the rail (a long target URL used to spill past
  its border), and carry a worst-severity dot, finding count and age.
- Past-run header shows when it ran, how many agents ran, the recon asset,
  PoC count and run id — two runs of one target were indistinguishable.
- Off-canvas sidebar below 768px had no way to be opened; added the toggle.
- Long evidence values (cookies, tokens) now wrap instead of running under
  the finding modal's edge.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BvdGy9XtVWSdXDTa3FFLJv
2026-09-07 13:33:16 -03:00

55 lines
3.2 KiB
Markdown

# NeuroSploit v4.0.0 — web console
A browser UI for the `neurosploit` CLI harness: a 5-step engagement wizard (Asset → Scope & Auth
→ Leads → Model & Run → Review), a live structured findings view with a generative attack-path
graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual
CLI binary, never a reimplementation of harness logic.
- **Asset** — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
- **Scope & Auth** — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
- **Leads** — the categorized agent picker (435 agents auto-classified) + custom leads.
- **Model & Run** — pick a provider/model from the live catalog, API-key vs. subscription auth
mode, votes/chain-depth/recon intensity.
- **Review** — confirm the plan, then `Start Exploitation` spawns the real CLI.
- **Auth & Keys** (one menu, 🔑 in the sidebar) — target auth header + named roles for
IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and
an explicit `creds.yaml` path override.
- **Generative Attack Path Chaining** — findings are grouped into kill-chain columns
(recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings
linked back to their parent, built live as findings stream in.
- **Terminal dock (xterm.js)** — `❭_` in the sidebar, the topbar button, or `Ctrl+\`` opens a
docked terminal running a real `neurosploit` REPL session. Its stdout is streamed **unstripped**,
so the harness's own colour and box-drawn panels render as they do in a local shell. Line
editing (echo, ←/→, history, `Tab` slash-command completion, `Ctrl+C`/`L`/`U`/`A`/`E`) is local
because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target
picker in its header switches between a standalone session and the **running engagement**, so
mid-run instructions go to the same process that is doing the testing.
- **Real REPL underneath run/whitebox/greybox** — the wizard scripts an actual interactive
`neurosploit` session instead of a one-shot CLI call, so it keeps reading stdin while the
engagement streams. The Activity log tab grows a `❭` prompt box to send `/status`, `/stop`,
`/continue`, or a plain-language instruction mid-run. `host`/`aitest`/`skills` stay one-shot
(their onboarding scope picker can't be scripted over piped stdin).
```bash
cd neurosploit-rs && cargo build --release # build the CLI once
node web/server.js # → http://localhost:4173
```
Zero npm dependencies (Node ≥18, built-ins only: `http`, `child_process`, `events`, `fs`).
API reference: [`API.md`](./API.md).
## Layout
```
web/
├── server.js backend: static server + agents_md/runs reader + CLI process manager
├── public/
│ ├── index.html SPA shell
│ ├── style.css lead-board / live-run / terminal-dock styling
│ ├── app.js client logic (fetch + EventSource + terminal, no framework)
│ └── vendor/ xterm.js + fit addon (vendored; nothing is fetched at runtime)
├── API.md
└── package.json
```