99 lines
3.2 KiB
Markdown
99 lines
3.2 KiB
Markdown
# Coruna Lab C2 + Admin
|
||
|
||
Laravel reporting C2 API and LayuiAdmin console for local lab use.
|
||
|
||
- Implements reporting routes from the Coruna dataflow doc (§7.2)
|
||
- AES-256-ECB JSON transport + multipart `/api/user/check` 7z extract
|
||
- Persists devices / apps / photos / notes / wallets + full `c2_raw_logs`
|
||
- Telegram notify on **new device** and **new/changed wallet address** only
|
||
- **Does not** implement `/kill` or any mnemonic/private-key transfer
|
||
|
||
## Requirements
|
||
|
||
| Tool | Path / note |
|
||
|------|-------------|
|
||
| PHP 8.5+ | `/opt/homebrew/opt/php/bin/php` (do **not** use PATH’s old 7.3) |
|
||
| Composer | via brew PHP |
|
||
| MySQL 8.0 | preferred (`coruna_lab` DB) — sqlite works for smoke |
|
||
| p7zip | `CORUNA_7Z_BIN` or `server/bin/7z` (panel `open_basedir` friendly) |
|
||
|
||
```bash
|
||
export PATH="/opt/homebrew/opt/php/bin:$PATH"
|
||
php -v # expect 8.5.x
|
||
```
|
||
|
||
## Setup
|
||
|
||
```bash
|
||
cd coruna-lab/server
|
||
cp .env.example .env # if needed
|
||
# edit .env: DB_*, TELEGRAM_*, ADMIN_*
|
||
|
||
# MySQL 8 (DB: coruna) — set DB_* in .env then:
|
||
php artisan key:generate # once
|
||
php artisan migrate --seed
|
||
php artisan serve --host=0.0.0.0 --port=8000
|
||
```
|
||
|
||
Admin UI uses **layuiAdmin std iframe** assets from `public/static/layuiadmin/`
|
||
(synced from local `layuiAdmin.std-v1.4.0/dist/layuiadmin`).
|
||
|
||
Default admin (from seeder / `.env`):
|
||
|
||
- Shell: `http://127.0.0.1:8000/admin`
|
||
- Login: `http://127.0.0.1:8000/admin/login` — `admin` / `admin123`
|
||
|
||
## Point reporting at this lab
|
||
|
||
Implants call the campaign reporting host. For lab capture, resolve that host to this machine (DNS / `/etc/hosts` / mitm) so traffic hits `php artisan serve` (or a reverse proxy in front of `public/`).
|
||
|
||
C2 routes are unauthenticated (client-compatible). Admin is session-auth under `/admin`.
|
||
|
||
## C2 API reference
|
||
|
||
各 reporting 接口用途、请求/响应数据结构:[`docs/C2_API.md`](docs/C2_API.md)。
|
||
|
||
## Crypto
|
||
|
||
```text
|
||
session_key = map(b -> (b%94)+33, bytes.fromhex(derive_archive_password(0))) # 16 ASCII
|
||
aes_key = SHA256(session_key || timestamp) # 13-digit header
|
||
body = Base64(AES-256-ECB-PKCS7(timestamp || payload))
|
||
```
|
||
|
||
Optional `.env` override: `CORUNA_SESSION_KEY` (16 ASCII). Empty = PHP KDF (parity with Python `coruna_netconfig_pipeline.derive_archive_password(0)`).
|
||
|
||
Known vector: `SHA256(session_key) = 9bcc53d7…ef1be1e4`.
|
||
|
||
`/api/user/check`: repair Coruna 7z header, password `session_key||batchBase` (default `0`). `sig` is ignored.
|
||
|
||
## Env knobs
|
||
|
||
| Key | Purpose |
|
||
|-----|---------|
|
||
| `TELEGRAM_BOT_TOKEN` / `TELEGRAM_OWNER_CHAT_ID` | New device / wallet alerts |
|
||
| `PAYOUT_ETH` / `BTC` / `TRON` / `SOL` | Reserved only — **not wired** |
|
||
| `CORUNA_7Z_BIN` | p7zip binary |
|
||
|
||
## Tests
|
||
|
||
```bash
|
||
php artisan test
|
||
# Unit: CorunaCrypto vs Python vectors
|
||
# Feature: query / avatar/set ingest / admin login
|
||
```
|
||
|
||
## Layout
|
||
|
||
```text
|
||
app/Services/CorunaCrypto.php # KDF + AES
|
||
app/Services/CorunaArchive.php # 7z repair/extract
|
||
app/Services/IngestService.php # device/apps/photos/notes/wallets
|
||
app/Services/TelegramNotifier.php
|
||
app/Http/Middleware/DecryptCorunaBody.php
|
||
app/Http/Controllers/C2/…
|
||
app/Http/Controllers/Admin/…
|
||
public/static/layuiadmin/ # Layui UI assets
|
||
storage/app/c2/ # check extracts + photos
|
||
```
|