2022-06-26 02:40:39 +00:00
|
|
|
var DEBUG = false;
|
2022-05-07 23:45:13 +00:00
|
|
|
var isMobile = false;
|
2023-09-29 06:15:06 +00:00
|
|
|
var USE_ORIGIN = "";
|
|
|
|
// TODO: Add check for DOMAIN_OVERRIDE
|
2022-05-01 07:35:44 +00:00
|
|
|
|
|
|
|
const dbp = (msg) => {
|
2022-05-07 08:09:11 +00:00
|
|
|
if(DEBUG){
|
|
|
|
console.log(msg);
|
|
|
|
}
|
2022-05-01 07:35:44 +00:00
|
|
|
};
|
|
|
|
|
2022-05-07 23:45:13 +00:00
|
|
|
const dbd = (msg) => {
|
|
|
|
if(DEBUG){
|
|
|
|
console.dir(msg);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2022-05-07 08:02:58 +00:00
|
|
|
const SwalConfig = {
|
|
|
|
color: "#79F257",
|
|
|
|
background: "#022601",
|
2022-05-07 23:45:13 +00:00
|
|
|
buttonsStyling: false,
|
2022-05-07 08:02:58 +00:00
|
|
|
}
|
|
|
|
|
2022-09-08 00:12:37 +00:00
|
|
|
const invalidChars = ['/', '\\', '>', '<', ':', '*', '|', '"', '\'', '?', '\0'];
|
|
|
|
|
|
|
|
const replaceInvalid = (str) => {
|
|
|
|
var cache = str;
|
|
|
|
invalidChars.forEach(ch => {
|
2022-09-08 00:17:25 +00:00
|
|
|
cache = cache.replaceAll(ch, "#");
|
2022-09-08 00:12:37 +00:00
|
|
|
});
|
|
|
|
return cache;
|
|
|
|
}
|
|
|
|
|
2022-05-01 07:35:44 +00:00
|
|
|
const isOverflown = ({ clientHeight, scrollHeight }) => scrollHeight > clientHeight
|
|
|
|
|
2022-05-07 08:02:58 +00:00
|
|
|
const setCookie = (cname, cvalue, exdays) => {
|
|
|
|
const d = new Date();
|
|
|
|
d.setTime(d.getTime() + (exdays*24*60*60*1000));
|
|
|
|
let expires = "expires="+ d.toUTCString();
|
2023-09-29 06:15:06 +00:00
|
|
|
document.cookie = cname + "=" + cvalue + ";" + expires + ";SameSite=Strict;path=/auth";
|
2022-05-07 08:02:58 +00:00
|
|
|
}
|
|
|
|
|
2022-05-01 07:35:44 +00:00
|
|
|
const resizeText = ({ element, elements, minSize = 10, maxSize = 512, step = 1, unit = 'px' }) => {
|
|
|
|
dbp("Resize");
|
|
|
|
(elements || [element]).forEach(el => {
|
2022-05-07 23:45:13 +00:00
|
|
|
let i = minSize;
|
|
|
|
let overflow = false;
|
|
|
|
const parent = el.parentNode;
|
2022-05-01 07:35:44 +00:00
|
|
|
while (!overflow && i < maxSize) {
|
2022-05-07 23:45:13 +00:00
|
|
|
el.style.fontSize = `${i}${unit}`;
|
|
|
|
overflow = isOverflown(parent);
|
|
|
|
if (!overflow) i += step;
|
2022-05-01 07:35:44 +00:00
|
|
|
}
|
|
|
|
// revert to last state where no overflow happened
|
2022-05-07 23:45:13 +00:00
|
|
|
el.style.fontSize = `${i - step}${unit}`;
|
|
|
|
});
|
2022-05-01 07:35:44 +00:00
|
|
|
}
|
|
|
|
|
2022-05-01 20:20:59 +00:00
|
|
|
const saveFile = (name, type, data) => {
|
|
|
|
if (data !== null && navigator.msSaveBlob)
|
2022-05-07 23:45:13 +00:00
|
|
|
return navigator.msSaveBlob(new Blob([data], { type: type }), name);
|
2022-05-01 20:20:59 +00:00
|
|
|
var a = $("<a style='display: none;'/>");
|
|
|
|
var url = window.URL.createObjectURL(new Blob([data], {type: type}));
|
|
|
|
a.attr("href", url);
|
|
|
|
a.attr("download", name);
|
|
|
|
$("body").append(a);
|
|
|
|
a[0].click();
|
|
|
|
window.URL.revokeObjectURL(url);
|
|
|
|
a.remove();
|
|
|
|
}
|
|
|
|
|
2022-05-01 07:35:44 +00:00
|
|
|
const disableNonDesktopElements = () => {
|
|
|
|
var disableElements = document.getElementsByClassName("desktopOnly");
|
|
|
|
for(var i=0; i< disableElements.length; i++){
|
|
|
|
var gutter = disableElements.item(i);
|
|
|
|
gutter.classList.remove("col-4");
|
|
|
|
gutter.classList.add("col-1");
|
|
|
|
}
|
|
|
|
var content = document.getElementById("content");
|
|
|
|
content.style.marginTop = "6vw";
|
|
|
|
content.classList.remove("col-4");
|
|
|
|
content.classList.add("col-10");
|
|
|
|
var te = document.getElementById("resizer");
|
|
|
|
window.fitText(te);
|
2022-05-01 20:20:59 +00:00
|
|
|
var buttons = document.getElementsByClassName("keyButton");
|
|
|
|
for(var i=0; i<buttons.length; i++){
|
|
|
|
var bttn = buttons.item(i);
|
|
|
|
bttn.style.height = "15vw";
|
|
|
|
}
|
2022-05-01 07:35:44 +00:00
|
|
|
}
|
2022-05-01 20:20:59 +00:00
|
|
|
|
2022-05-07 08:02:58 +00:00
|
|
|
const failMsg = (msg) => {
|
|
|
|
$("#resizer").html(msg);
|
|
|
|
$("#resizer").css("color", "#400112");
|
|
|
|
$("#resizer").css("background-color", "#79F257");
|
|
|
|
$("#resizer").animate({
|
|
|
|
color: "#79F257",
|
|
|
|
backgroundColor: "#022601"
|
|
|
|
}, 1000);
|
|
|
|
}
|
|
|
|
|
2022-05-07 23:45:13 +00:00
|
|
|
const validatePubKey = (key) => {
|
|
|
|
return /^(ssh-rsa AAAAB3NzaC1yc2|ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNT|ecdsa-sha2-nistp384 AAAAE2VjZHNhLXNoYTItbmlzdHAzODQAAAAIbmlzdHAzOD|ecdsa-sha2-nistp521 AAAAE2VjZHNhLXNoYTItbmlzdHA1MjEAAAAIbmlzdHA1Mj|ssh-ed25519 AAAAC3NzaC1lZDI1NTE5|ssh-dss AAAAB3NzaC1kc3)[0-9A-Za-z+\/]+[=]{0,3}( .*)?$/.test(key);
|
|
|
|
}
|
|
|
|
|
|
|
|
const sendSSH = (key, id, token) => {
|
|
|
|
var payload = {
|
|
|
|
pubkey: key,
|
|
|
|
userId: id,
|
|
|
|
authToken: token
|
|
|
|
};
|
2023-09-29 06:15:06 +00:00
|
|
|
$.post(USE_ORIGIN+"/auth/setKey.php", payload, (response) => {
|
2022-05-07 23:45:13 +00:00
|
|
|
dbp(response);
|
|
|
|
if(response.status){
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Success!",
|
|
|
|
text: "Your key has been uploaded to the server."
|
2022-06-26 02:40:39 +00:00
|
|
|
}).then(()=>{
|
|
|
|
window.location.reload();
|
2022-05-07 23:45:13 +00:00
|
|
|
});
|
|
|
|
}else{
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Failed!",
|
|
|
|
text: response.error
|
2022-06-26 02:40:39 +00:00
|
|
|
}).then(()=>{
|
|
|
|
window.location.reload();
|
2022-05-07 23:45:13 +00:00
|
|
|
});
|
2023-09-29 06:15:06 +00:00
|
|
|
}
|
2022-06-26 02:40:39 +00:00
|
|
|
}).fail((resp) => {
|
2022-05-07 23:45:13 +00:00
|
|
|
dbp("Failed");
|
2022-06-26 02:40:39 +00:00
|
|
|
dbd(resp);
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Failed!",
|
|
|
|
text: resp.toString()
|
|
|
|
}).then(()=>{
|
|
|
|
window.location.reload();
|
|
|
|
});
|
2022-05-07 23:45:13 +00:00
|
|
|
});
|
|
|
|
}
|
2022-05-07 08:02:58 +00:00
|
|
|
|
|
|
|
const generateSSH = async (name, id, token) => {
|
2022-05-01 20:20:59 +00:00
|
|
|
dbp("Generate Key");
|
2023-09-29 06:15:06 +00:00
|
|
|
if (window.location.protocol === "http:") {
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Error!",
|
|
|
|
text: "You must use HTTPS to generate keys."
|
|
|
|
});
|
|
|
|
return;
|
|
|
|
}
|
2023-09-29 14:40:40 +00:00
|
|
|
generateKeyPair("RSASSA-PKCS1-v1_5", 4096, "WebGen " + Date())
|
2022-05-01 20:20:59 +00:00
|
|
|
.then((keys) => {
|
|
|
|
var KeyExport = new JSZip();
|
2022-09-08 00:12:37 +00:00
|
|
|
name = replaceInvalid(name);
|
2022-05-01 20:20:59 +00:00
|
|
|
KeyExport.file("HackersTownTTY-"+name, keys[0]);
|
|
|
|
KeyExport.file("HackersTownTTY-"+name+".pub", keys[1]);
|
|
|
|
KeyExport.generateAsync({type:"blob"})
|
|
|
|
.then((content) => {
|
|
|
|
saveFile("HackersTownTTY-"+name+".zip", "application/zip", content);
|
2022-05-07 08:02:58 +00:00
|
|
|
});
|
2022-05-07 23:45:13 +00:00
|
|
|
sendSSH(keys[1], id, token);
|
2022-05-01 20:20:59 +00:00
|
|
|
}).catch((err) => {
|
2022-05-07 08:09:11 +00:00
|
|
|
dbp(err);
|
2022-05-01 20:20:59 +00:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2022-05-07 08:02:58 +00:00
|
|
|
const testSwal = () => {
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Success!",
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2022-05-07 23:45:13 +00:00
|
|
|
const uploadSSH = (id, token) => {
|
2022-05-07 08:02:58 +00:00
|
|
|
//request local file
|
|
|
|
var kf = document.getElementById("keyfile");
|
|
|
|
kf.onchange = function(e) {
|
|
|
|
// File selected
|
2022-05-07 23:45:13 +00:00
|
|
|
var file = e.target.files[0];
|
|
|
|
if(file){
|
|
|
|
dbd(file);
|
|
|
|
var reader = new FileReader();
|
|
|
|
reader.readAsText(file, "UTF-8");
|
|
|
|
reader.onload = function (evt) {
|
|
|
|
var pubkey = evt.target.result;
|
2022-06-26 05:55:48 +00:00
|
|
|
pubkey = pubkey.replace(/\r\n/g, "\n");
|
|
|
|
dbp(pubkey);
|
|
|
|
pubkey = pubkey.replace(/\n/g, "");
|
|
|
|
dbp(pubkey);
|
2022-05-07 23:45:13 +00:00
|
|
|
if(validatePubKey(pubkey)){
|
|
|
|
sendSSH(pubkey, id, token);
|
|
|
|
}else{
|
|
|
|
failMsg("Invalid key");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
reader.onerror = function (evt) {
|
|
|
|
failMsg("Unable to load Keyfile");
|
|
|
|
}
|
2023-09-29 06:15:06 +00:00
|
|
|
|
2022-05-07 23:45:13 +00:00
|
|
|
}
|
2022-05-07 08:02:58 +00:00
|
|
|
}
|
|
|
|
kf.click();
|
2022-05-01 20:20:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
const beginOauth = () => {
|
|
|
|
dbp("Auth");
|
|
|
|
$.ajax({
|
2023-09-29 06:15:06 +00:00
|
|
|
url: USE_ORIGIN+"/auth?act=id"
|
2022-05-01 20:20:59 +00:00
|
|
|
}).then((data) => {
|
2022-05-08 00:15:19 +00:00
|
|
|
dbd(data);
|
2022-05-01 20:20:59 +00:00
|
|
|
if(data.id){
|
|
|
|
var redirect = "https://hackers.town/oauth/authorize?"+
|
|
|
|
"response_type=code&client_id="+data.id+"&redirect_uri="+
|
2023-09-29 06:15:06 +00:00
|
|
|
USE_ORIGIN+"/auth&scope=read:accounts";
|
2022-05-01 20:20:59 +00:00
|
|
|
dbp(redirect);
|
2022-05-07 08:02:58 +00:00
|
|
|
dbp(window.location.pathname);
|
|
|
|
if(window.location.pathname.includes("auth")){
|
|
|
|
setCookie("oa_retries", 0, 0.1);
|
|
|
|
}
|
2022-05-01 20:20:59 +00:00
|
|
|
window.location.href = redirect;
|
|
|
|
}else{
|
|
|
|
// Auth Failed
|
2022-05-07 08:02:58 +00:00
|
|
|
failMsg("AUTH FAILED");
|
2022-05-01 20:20:59 +00:00
|
|
|
}
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2023-09-29 06:15:06 +00:00
|
|
|
const displayFingerprints = () => {
|
|
|
|
// Get SSH Fingerprints and display them
|
|
|
|
$.get(USE_ORIGIN+"/fingerprint.php", (response) => {
|
|
|
|
dbp(response);
|
|
|
|
if (response) {
|
2023-09-29 14:40:40 +00:00
|
|
|
var html = "<div><table class=\"fingerprintTable\"><tr><th>Bits</th><th>Fingerprint (SHA256)</th><th class=\"text-start\">Algorithm</th></tr>";
|
2023-09-29 06:15:06 +00:00
|
|
|
response.split("\n").forEach((line) => {
|
|
|
|
var parts = line.split(" ");
|
|
|
|
if(parts.length === 4){
|
2023-09-29 14:40:40 +00:00
|
|
|
html += "<tr><td class=\"fingerprintBit\">"+parts[0]+"</td><td class=\"fingerprintData\">"+parts[1].replace("SHA256:", "")+"</td><td class=\"fingerprintAlgo\">"+parts[3].replace("(", "").replace(")", "")+"</td></tr>";
|
2023-09-29 06:15:06 +00:00
|
|
|
}
|
|
|
|
});
|
|
|
|
html += "</table></div>";
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "SSH Fingerprints",
|
|
|
|
html: html
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
Swal.fire({
|
|
|
|
...SwalConfig,
|
|
|
|
title: "Unable to Lookup SSH Fingerprints",
|
|
|
|
text: response.error
|
|
|
|
});
|
|
|
|
}
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2022-05-01 20:20:59 +00:00
|
|
|
// On Page Load...
|
2022-05-01 07:35:44 +00:00
|
|
|
$(() => {
|
|
|
|
dbp("Begin Init Content");
|
2023-09-29 06:15:06 +00:00
|
|
|
|
|
|
|
// Override domain
|
|
|
|
$.get("/DOMAIN_OVERRIDE", function (data) {
|
|
|
|
USE_ORIGIN = data.replaceAll("\n", "");
|
|
|
|
DEBUG = true;
|
2023-09-29 14:25:58 +00:00
|
|
|
}).fail(() => {
|
2023-09-29 06:15:06 +00:00
|
|
|
USE_ORIGIN = "https://tty.hackers.town";
|
2023-09-29 14:25:58 +00:00
|
|
|
}).always(() => {
|
2022-05-07 23:45:13 +00:00
|
|
|
|
2023-09-29 06:15:06 +00:00
|
|
|
// Device Detection
|
|
|
|
if (/(android|bb\d+|meego).+mobile|avantgo|bada\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|ipad|iris|kindle|Android|Silk|lge |maemo|midp|mmp|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\.(browser|link)|vodafone|wap|windows (ce|phone)|xda|xiino/i.test(navigator.userAgent) ||
|
|
|
|
/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\-(n|u)|c55\/|capi|ccwa|cdm\-|cell|chtm|cldc|cmd\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\-s|devi|dica|dmob|do(c|p)o|ds(12|\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\-|_)|g1 u|g560|gene|gf\-5|g\-mo|go(\.w|od)|gr(ad|un)|haie|hcit|hd\-(m|p|t)|hei\-|hi(pt|ta)|hp( i|ip)|hs\-c|ht(c(\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\-(20|go|ma)|i230|iac( |\-|\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\/)|klon|kpt |kwc\-|kyo(c|k)|le(no|xi)|lg( g|\/(k|l|u)|50|54|\-[a-w])|libw|lynx|m1\-w|m3ga|m50\/|ma(te|ui|xo)|mc(01|21|ca)|m\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\-2|po(ck|rt|se)|prox|psio|pt\-g|qa\-a|qc(07|12|21|32|60|\-[2-7]|i\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\-|oo|p\-)|sdk\/|se(c(\-|0|1)|47|mc|nd|ri)|sgh\-|shar|sie(\-|m)|sk\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\-|v\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\-|tdg\-|tel(i|m)|tim\-|t\-mo|to(pl|sh)|ts(70|m\-|m3|m5)|tx\-9|up(\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\-|your|zeto|zte\-/i.test(navigator.userAgent.substr(0, 4))) {
|
|
|
|
isMobile = true;
|
|
|
|
}
|
|
|
|
// Adjust for Mobile
|
|
|
|
if(isMobile){
|
|
|
|
dbp("Is Mobile 👍🏻");
|
|
|
|
disableNonDesktopElements();
|
|
|
|
}
|
|
|
|
// Auto Retry
|
|
|
|
var isRetry = false;
|
|
|
|
if(window.location.pathname.includes("auth")){
|
|
|
|
var ErrorMsg = document.getElementById("ErrorResult");
|
|
|
|
dbp(typeof ErrorMsg);
|
|
|
|
if(typeof ErrorMsg !== 'undefined' && ErrorMsg.innerText.includes("Retry")){
|
|
|
|
dbp("attempt retry");
|
|
|
|
isRetry = true;
|
2023-09-29 14:25:58 +00:00
|
|
|
beginOauth();
|
2023-09-29 06:15:06 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
// Console Welcome
|
|
|
|
if(!isRetry){
|
|
|
|
console.log("%cWelcome Hacker!", "color: #ff0000; font-size: 7em; font-style: italic; font-family: 'Times New Roman', Times, serif;");
|
|
|
|
}
|
|
|
|
|
|
|
|
// Enable Extra Debug Stuff
|
|
|
|
if(DEBUG){
|
|
|
|
dbp("Debug Mode Enabled");
|
|
|
|
$('.debug').each((i,e)=>{
|
|
|
|
e.style.display = "unset";
|
|
|
|
});
|
|
|
|
}
|
|
|
|
})
|
|
|
|
});
|