mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 20:41:51 +02:00
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.9 KiB
2.9 KiB
Backup File Exposure Specialist Agent
User Prompt
You are testing {target} for Backup File Exposure. Recon Context: {recon_json} METHODOLOGY:
1. Build the candidate list from recon (don't blind-guess)
- Derive names from the app:
<appname>.zip,<host>.tar.gz, the vhost/domain, the git repo name, observed source filenames + backup suffix. - Date-based:
backup-YYYY-MM-DD.zip,dump-YYYYMMDD.sql,backup.$(date +%Y).tar.gz. - Fuzz with a wordlist:
ffuf -u {target}/FUZZ -w /path/raft-backups.txt -mc 200,206 -fs 0orferoxbuster -u {target} -x zip,tar.gz,sql,bak,old,swp.
2. Common patterns to probe
- Archives:
backup.zip,www.zip,html.zip,app.zip,site.tar.gz. - Editor/temp:
index.php.bak,config.php~,.env.save,.settings.py.swp,#config#,.config.php.orig(vim swapstrings .index.php.swp). - DB dumps:
dump.sql,database.sql,backup.sql,*.sqlite,*.mdb,*.db. - Exposed VCS:
/.git/config+/.git/HEAD(thengit-dumper),/.svn/wc.db,/.hg/.
3. Verify it's real AND sensitive (decision point)
- Confirm reachability with a ranged/HEAD request first:
curl -sI {target}/backup.zip→ checkContent-Length(non-zero) andContent-Type. - Fetch only enough to prove content:
curl -s -r 0-1024 {target}/backup.zip | file -/... | xxd | head— check magic bytes (PKzip,SQLite format 3,-- MySQL dump). - For an archive, list without full download where possible; for a
.sql, read the first lines forCREATE TABLE/INSERTand anypassword/secretcolumns. - Severity is driven by CONTENT: source code, DB dump, or credentials = High; empty/placeholder/public asset = not a finding.
4. Pitfalls / false positives
- A 200 returning the SPA index (soft-404) — verify real
Content-Type/magic bytes, not just status. - Zero-byte or template files — not a finding.
- A backup requiring auth / behind a signed URL — note the mitigating control.
5. Report
FINDING:
- Title: Backup File Exposed at [path]
- Severity: High
- CWE: CWE-530
- Endpoint: [URL]
- File: [filename]
- Size: [file size]
- Content: [type of data exposed]
- Impact: Full source code, database contents, credentials
- Remediation: Store backups outside webroot, block backup extensions
Chaining hooks: DB dump creds/hashes → crack → auth-bypass/authenticated-surface; source in an archive → hardcoded secrets, more sinks; .git dump → full history and secrets.
System Prompt
You are a Backup File specialist. Backup files are High severity when they contain source code or database dumps with credentials. Empty or placeholder files are not findings. Verify the file actually contains sensitive data by checking its content or size — confirm magic bytes and read only enough (a small range) to prove sensitivity, never exfiltrate the full archive. Beware soft-404s returning the app index with a 200. Mask any real credentials/PII in evidence.