WalleGriffkinder commited on
Commit
fa9a9a3
·
verified ·
1 Parent(s): 29f722f

Update server.js

Browse files
Files changed (1) hide show
  1. server.js +54 -23
server.js CHANGED
@@ -1,57 +1,87 @@
 
1
  const express=require('express');const {v4:uuidv4}=require('uuid');const {createWorker,PSM}=require('tesseract.js');const genericPool=require('generic-pool');const sharp=require('sharp');
 
 
2
  const app=express();const port=process.env.PORT||7860;app.use(express.json({limit:'5mb'}));
3
  const cs={};const CEX=5*60*1000;const OCS="ACEFHJKMNPRTUVWXY23469";const OCL=6;
4
- const WCC=[{n:"r",rgb:[1,0,0]},{n:"g",rgb:[0,1,0]},{n:"b",rgb:[0,0,1]},{n:"y",rgb:[1,1,0]}];const XK="KluchevoyeSlovoDlyaDemo";
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
5
  const TPL=4;let tp=null;let pDO=false;
6
  const fac={create:async()=>{const w=await createWorker('eng',1,{cachePath:'/tmp/.tesscache',cacheMethod:'fs'});await w.setParameters({tessedit_char_whitelist:OCS,tessedit_pageseg_mode:PSM.SINGLE_WORD});return w;},destroy:async(w)=>{await w.terminate();}};
7
  const pO={min:TPL,max:TPL,acquireTimeoutMillis:7000};
8
- async function iTP(){try{tp=genericPool.createPool(fac,pO);console.log(`Pool(s:${TPL})OK`);const ws=await Promise.all(Array(TPL).fill(null).map(()=>tp.acquire()));ws.forEach(w=>tp.release(w));console.log(`${TPL}wOK`);}catch(e){console.error("PoolInitFail:",e);process.exit(1);}}
9
- iTP();
10
  async function pIFOCR(b){try{return await sharp(b).grayscale().normalize().sharpen({sigma:0.5,m1:0,m2:3,x1:0,y2:3,y3:3}).toBuffer();}catch(e){console.warn("PreProcFail:",e.message.slice(0,50));return b;}}
11
  async function rWPW(b,h){if(!tp){console.error("PoolNA!");return null;}let w=null;try{w=await tp.acquire();const pB=await pIFOCR(b);const{data:{text}}=await w.recognize(pB);return text.trim().replace(new RegExp(`[^${OCS}]`,'g'),'');}catch(e){console.error(`OCR ${h} Err:`,e.message.slice(0,50));return null;}finally{if(w)await tp.release(w);}}
12
- async function pSO(d){if(!d||!d.startsWith('data:image/png;base64,'))return{fT:null,aL:[]};const bD=d.replace(/^data:image\/png;base64,/,"");const iB=Buffer.from(bD,'base64');let rs=[];let aL=[];
13
- if(!pDO&&tp&&tp.available>=2){pDO=true;try{const[r1,r2]=await Promise.all([rWPW(iB,"D1"),rWPW(iB,"D2")]);rs.push(r1,r2);aL.push({t:"D1",x:r1},{t:"D2",x:r2});}catch(e){console.error("DualOCRErr:",e);}finally{pDO=false;}}
14
- else if(tp&&tp.available>=1){try{const rS=await rWPW(iB,"S1");rs.push(rS);aL.push({t:"S1",x:rS});}catch(e){console.error("SingleOCRErr:",e);}}
15
- else{console.warn("NoWForOCR");aL.push({t:"N",x:null,r:"NoW"});}
16
- const vR=rs.filter(t=>t!==null&&t!=="");const fT=vR.length>0?vR[0]:null;console.log(`OCRLog: ${aL.map(a=>`${a.t}:${a.x||'-'}`).join('; ')}. Fin:"${fT||'-'}"`);return{fT,aL};}
17
  function ld(a,b){if(!a&&!b)return 0;if(!a)return b.length;if(!b)return a.length;const m=[];for(let i=0;i<=b.length;i++)m[i]=[i];for(let j=0;j<=a.length;j++)m[0][j]=j;for(let i=1;i<=b.length;i++){for(let j=1;j<=a.length;j++){if(b.charAt(i-1)===a.charAt(j-1))m[i][j]=m[i-1][j-1];else m[i][j]=Math.min(m[i-1][j-1]+1,Math.min(m[i][j-1]+1,m[i-1][j]+1));}}return m[b.length][a.length];}
18
- function xS(t,k){let r="";for(let i=0;i<t.length;i++)r+=String.fromCharCode(t.charCodeAt(i)^k.charCodeAt(i%k.length));return r;}
19
- function dF(d){try{const x=atob(d);const o=xS(x,XK);return JSON.parse(o);}catch(e){console.error("DecErr:",e.message.slice(0,50));return null;}}
20
  app.use((req,res,next)=>{res.header('Access-Control-Allow-Origin','*');res.header('Access-Control-Allow-Headers','Origin,X-Requested-With,Content-Type,Accept');res.header('Access-Control-Allow-Methods','GET,POST,OPTIONS');if(req.method==='OPTIONS')return res.sendStatus(200);next();});
21
  app.get('/api/challenge',(req,res)=>{const sT=uuidv4();let oCT="";for(let i=0;i<OCL;i++)oCT+=OCS[Math.floor(Math.random()*OCS.length)];const wI=WCC[Math.floor(Math.random()*WCC.length)];cs[sT]={iat:Date.now(),exp:Date.now()+CEX,usd:false,ip:req.ip,eOT:oCT,eWCN:wI.n,eWCR:wI.rgb};res.json({sT,oCT,wCC:wI.rgb});});
 
22
  app.post('/api/check', async (req, res) => {
23
  const p=req.body; let sc=0; const stgs=[]; let mF=false;
24
- const sT=p.sT; const oCDU=p.oCDU; const dD=p.eD?dF(p.eD):null;
25
- let s0P=false; if(dD){s0P=true;sc+=10;}else{mF=true;} stgs.push({n:"E0",p:s0P,pts:s0P?10:-100});
26
- const wR=dD?.wgl; const nI=dD?.nav; const pT=dD?.perf; const aV=dD?.aut;
 
 
 
 
27
  let sV=false; let sD=null; let s1P=false;
28
  if(!mF){if(!sT||!cs[sT]||cs[sT].usd||Date.now()>cs[sT].exp){mF=true;}else{sD=cs[sT];sV=true;s1P=true;sc+=30;}}
29
- stgs.push({n:"E1",p:s1P,pts:s1P?30:(mF&&!s0P?0:-100)});
30
  let oP=false; let oPts=0;
31
  if(!mF){
32
  if(!oCDU||!oCDU.startsWith('data:image/png;base64,')||oCDU.length<150){oPts=-80;mF=true;}
33
  else{const oRes=await pSO(oCDU); const rT=oRes.fT; const eT=sD.eOT;
34
  if(rT!==null){const dist=ld(rT,eT);if(dist<=1){oP=true;oPts=40+(dist===0?5:0);}else{oPts=-80;mF=true;}}
35
  else{oPts=-70;mF=true;}}
36
- if(!oP&&!mF){if(Math.random()<0.10){oP=true;oPts=5;stgs.push({n:"E2",p:true,pts:oPts,note:"RND"});}else{mF=true;if(!stgs.find(s=>s.n==="E2"))stgs.push({n:"E2",p:false,pts:oPts});}}
37
- if(oP&&!stgs.find(s=>s.n==="E2")){stgs.push({n:"E2",p:true,pts:oPts});}
38
- else if(!oP&&!stgs.find(s=>s.n==="E2")){stgs.push({n:"E2",p:false,pts:oPts});}
39
  sc+=oPts;
40
- }else{stgs.push({n:"E2",p:false,pts:0});}
41
  let wglP=false; let wglPts=0;
42
  if(sV&&wR){const eR=sD.eWCR;const eP=[Math.round(eR[0]*255),Math.round(eR[1]*255),Math.round(eR[2]*255)];
43
  if(wR.px&&wR.px.length>=3){const cP=wR.px.slice(0,3);if(cP.every((v,i)=>Math.abs(v-eP[i])<=8)){wglP=true;wglPts=70;}else{wglPts=-10;}}else{wglPts=-5;}
44
  const rdr=wR.rdr?.toLowerCase()||"";if(rdr.includes("swiftshader")||rdr.includes("llvmpipe")){wglPts-=20;wglP=false;}}else if(wR?.err){wglPts=-5;}
45
- sc+=wglPts;stgs.push({n:"E3",p:wglP,pts:wglPts});
46
  let navP=true; let navPts=0;
47
  if(nI){if(nI.wd===true){navPts-=30;navP=false;}if(!nI.ua||nI.ua===""){navPts-=10;navP=false;}else if(nI.ua.toLowerCase().includes("bot")||nI.ua.toLowerCase().includes("headless")){if(!nI.ua.toLowerCase().includes("headlesschrome")){navPts-=20;navP=false;}}}else{navPts-=5;navP=false;}
48
- sc+=navPts;stgs.push({n:"E4",p:navP,pts:navPts});
49
  let perfP=true; let perfPts=0;
50
  if(pT&&sV){const{dct,ocrt,wrt}=pT;if(typeof dct==='number'&&dct<10){perfPts-=10;perfP=false;}if(typeof ocrt==='number'&&ocrt<3&&oCDU){perfPts-=10;perfP=false;}if(typeof wrt==='number'&&wrt<3&&wR?.px){perfPts-=10;perfP=false;}}else if(!pT){perfPts-=3;perfP=false;}
51
- sc+=perfPts;stgs.push({n:"E5",p:perfP,pts:perfPts});
52
  let autoP=true; let autoPts=0;
53
  if(aV&&Object.keys(aV).length>0){autoPts-=40;autoP=false;}else{autoPts+=5;}
54
- sc+=autoPts;stgs.push({n:"E6",p:autoP,pts:autoPts});
55
  sc=Math.max(0,Math.min(sc,150));
56
  let vT="";
57
  if(mF){vT="Блок (Критический провал)";}
@@ -61,7 +91,8 @@ app.post('/api/check', async (req, res) => {
61
  console.log(`[${new Date().toISOString().slice(0,19).replace('T',' ')}] Chk: T=${sT||'N/A'},S=${sc},V=${vT},IP=${req.ip},MF=${mF},OCR=${oP},WebGL=${wglP},Nav=${navP},Perf=${perfP},Auto=${autoP}`);
62
  res.json({vT,fS:sc,cS:stgs});
63
  });
 
64
  setInterval(()=>{const n=Date.now();for(const t in cs){if(cs[t].exp<n||(cs[t].usd&&(n-cs[t].iat>CEX*2))){delete cs[t];}}},60000);
65
  async function shutdown(){console.log("Shutdown...");if(tp){console.log("Draining pool...");await tp.drain().then(()=>tp.clear()).then(()=>console.log("Pool cleared.")).catch(e=>console.error("Pool drain err:",e));}process.exit(0);}
66
  process.on('SIGTERM',shutdown);process.on('SIGINT',shutdown);
67
- app.listen(port,()=>{console.log(`Stealthy API v4 on ${port}`);});
 
1
+ // server.js
2
  const express=require('express');const {v4:uuidv4}=require('uuid');const {createWorker,PSM}=require('tesseract.js');const genericPool=require('generic-pool');const sharp=require('sharp');
3
+ const crypto = require('crypto'); // Для AES дешифрования
4
+
5
  const app=express();const port=process.env.PORT||7860;app.use(express.json({limit:'5mb'}));
6
  const cs={};const CEX=5*60*1000;const OCS="ACEFHJKMNPRTUVWXY23469";const OCL=6;
7
+ const WCC=[{n:"r",rgb:[1,0,0]},{n:"g",rgb:[0,1,0]},{n:"b",rgb:[0,0,1]},{n:"y",rgb:[1,1,0]}];
8
+
9
+ // --- AES-GCM Дешифрование ---
10
+ const AES_KEY_STRING = "ThisIsMySuperSecretKeyForAES128"; // ТОТ ЖЕ КЛЮЧ, ЧТО И НА КЛИЕНТЕ (16 байт для AES-128)
11
+ const AES_KEY_BUFFER = Buffer.from(AES_KEY_STRING.slice(0, 16), 'utf-8'); // Используем первые 16 байт
12
+ const AES_ALGORITHM = 'aes-128-gcm';
13
+ const IV_LENGTH = 12; // 96 bits
14
+ const AUTH_TAG_LENGTH = 16; // GCM auth tag
15
+
16
+ function decryptData(encryptedBase64) {
17
+ try {
18
+ const combinedBuffer = Buffer.from(encryptedBase64, 'base64');
19
+ const iv = combinedBuffer.subarray(0, IV_LENGTH);
20
+ const ciphertextWithTag = combinedBuffer.subarray(IV_LENGTH);
21
+ const ciphertext = ciphertextWithTag.subarray(0, ciphertextWithTag.length - AUTH_TAG_LENGTH);
22
+ const authTag = ciphertextWithTag.subarray(ciphertextWithTag.length - AUTH_TAG_LENGTH);
23
+
24
+ const decipher = crypto.createDecipheriv(AES_ALGORITHM, AES_KEY_BUFFER, iv);
25
+ decipher.setAuthTag(authTag);
26
+ let decrypted = decipher.update(ciphertext, null, 'utf8'); // null для inputEncoding, если ciphertext это Buffer
27
+ decrypted += decipher.final('utf8');
28
+ return JSON.parse(decrypted);
29
+ } catch (e) {
30
+ console.error("AES Decrypt Error:", e.message.slice(0,100));
31
+ return null;
32
+ }
33
+ }
34
+ // --- Конец AES-GCM Дешифрования ---
35
+
36
  const TPL=4;let tp=null;let pDO=false;
37
  const fac={create:async()=>{const w=await createWorker('eng',1,{cachePath:'/tmp/.tesscache',cacheMethod:'fs'});await w.setParameters({tessedit_char_whitelist:OCS,tessedit_pageseg_mode:PSM.SINGLE_WORD});return w;},destroy:async(w)=>{await w.terminate();}};
38
  const pO={min:TPL,max:TPL,acquireTimeoutMillis:7000};
39
+ async function iTP(){try{tp=genericPool.createPool(fac,pO);console.log(`Pool(s:${TPL})OK`);const ws=await Promise.all(Array(TPL).fill(null).map(()=>tp.acquire()));ws.forEach(w=>tp.release(w));console.log(`${TPL}wOK`);}catch(e){console.error("PoolInitFail:",e);process.exit(1);}}iTP();
 
40
  async function pIFOCR(b){try{return await sharp(b).grayscale().normalize().sharpen({sigma:0.5,m1:0,m2:3,x1:0,y2:3,y3:3}).toBuffer();}catch(e){console.warn("PreProcFail:",e.message.slice(0,50));return b;}}
41
  async function rWPW(b,h){if(!tp){console.error("PoolNA!");return null;}let w=null;try{w=await tp.acquire();const pB=await pIFOCR(b);const{data:{text}}=await w.recognize(pB);return text.trim().replace(new RegExp(`[^${OCS}]`,'g'),'');}catch(e){console.error(`OCR ${h} Err:`,e.message.slice(0,50));return null;}finally{if(w)await tp.release(w);}}
42
+ async function pSO(d){if(!d||!d.startsWith('data:image/png;base64,'))return{fT:null,aL:[]};const bD=d.replace(/^data:image\/png;base64,/,"");const iB=Buffer.from(bD,'base64');let rs=[];let aL=[];if(!pDO&&tp&&tp.available>=2){pDO=true;try{const[r1,r2]=await Promise.all([rWPW(iB,"D1"),rWPW(iB,"D2")]);rs.push(r1,r2);aL.push({t:"D1",x:r1},{t:"D2",x:r2});}catch(e){console.error("DualOCRErr:",e);}finally{pDO=false;}}else if(tp&&tp.available>=1){try{const rS=await rWPW(iB,"S1");rs.push(rS);aL.push({t:"S1",x:rS});}catch(e){console.error("SingleOCRErr:",e);}}else{console.warn("NoWForOCR");aL.push({t:"N",x:null,r:"NoW"});}const vR=rs.filter(t=>t!==null&&t!=="");const fT=vR.length>0?vR[0]:null;console.log(`OCRLog: ${aL.map(a=>`${a.t}:${a.x||'-'}`).join('; ')}. Fin:"${fT||'-'}"`);return{fT,aL};}
 
 
 
 
43
  function ld(a,b){if(!a&&!b)return 0;if(!a)return b.length;if(!b)return a.length;const m=[];for(let i=0;i<=b.length;i++)m[i]=[i];for(let j=0;j<=a.length;j++)m[0][j]=j;for(let i=1;i<=b.length;i++){for(let j=1;j<=a.length;j++){if(b.charAt(i-1)===a.charAt(j-1))m[i][j]=m[i-1][j-1];else m[i][j]=Math.min(m[i-1][j-1]+1,Math.min(m[i][j-1]+1,m[i-1][j]+1));}}return m[b.length][a.length];}
44
+
 
45
  app.use((req,res,next)=>{res.header('Access-Control-Allow-Origin','*');res.header('Access-Control-Allow-Headers','Origin,X-Requested-With,Content-Type,Accept');res.header('Access-Control-Allow-Methods','GET,POST,OPTIONS');if(req.method==='OPTIONS')return res.sendStatus(200);next();});
46
  app.get('/api/challenge',(req,res)=>{const sT=uuidv4();let oCT="";for(let i=0;i<OCL;i++)oCT+=OCS[Math.floor(Math.random()*OCS.length)];const wI=WCC[Math.floor(Math.random()*WCC.length)];cs[sT]={iat:Date.now(),exp:Date.now()+CEX,usd:false,ip:req.ip,eOT:oCT,eWCN:wI.n,eWCR:wI.rgb};res.json({sT,oCT,wCC:wI.rgb});});
47
+
48
  app.post('/api/check', async (req, res) => {
49
  const p=req.body; let sc=0; const stgs=[]; let mF=false;
50
+ const sT=p.sT; const oCDU=p.oCDU;
51
+ const decData = p.eD ? decryptData(p.eD) : null; // Используем AES дешифрование
52
+
53
+ let s0P=false; if(decData){s0P=true;sc+=10;}else{mF=true;stgs.push({n:"E0(Dec)",p:false,pts:-100}); /* Добавил лог для этапа 0 */}
54
+ if(s0P) stgs.push({n:"E0(Dec)",p:s0P,pts:10}); // Логируем успех если есть
55
+
56
+ const wR=decData?.wgl; const nI=decData?.nav; const pT=decData?.perf; const aV=decData?.aut;
57
  let sV=false; let sD=null; let s1P=false;
58
  if(!mF){if(!sT||!cs[sT]||cs[sT].usd||Date.now()>cs[sT].exp){mF=true;}else{sD=cs[sT];sV=true;s1P=true;sc+=30;}}
59
+ stgs.push({n:"E1(Ses)",p:s1P,pts:s1P?30:(mF&&!s0P?0:-100)});
60
  let oP=false; let oPts=0;
61
  if(!mF){
62
  if(!oCDU||!oCDU.startsWith('data:image/png;base64,')||oCDU.length<150){oPts=-80;mF=true;}
63
  else{const oRes=await pSO(oCDU); const rT=oRes.fT; const eT=sD.eOT;
64
  if(rT!==null){const dist=ld(rT,eT);if(dist<=1){oP=true;oPts=40+(dist===0?5:0);}else{oPts=-80;mF=true;}}
65
  else{oPts=-70;mF=true;}}
66
+ if(!oP&&!mF){if(Math.random()<0.10){oP=true;oPts=5;stgs.push({n:"E2(OCR)",p:true,pts:oPts,note:"RND"});}else{mF=true;if(!stgs.find(s=>s.n==="E2(OCR)"))stgs.push({n:"E2(OCR)",p:false,pts:oPts});}}
67
+ if(oP&&!stgs.find(s=>s.n==="E2(OCR)")){stgs.push({n:"E2(OCR)",p:true,pts:oPts});}
68
+ else if(!oP&&!stgs.find(s=>s.n==="E2(OCR)")){stgs.push({n:"E2(OCR)",p:false,pts:oPts});}
69
  sc+=oPts;
70
+ }else{stgs.push({n:"E2(OCR)",p:false,pts:0});}
71
  let wglP=false; let wglPts=0;
72
  if(sV&&wR){const eR=sD.eWCR;const eP=[Math.round(eR[0]*255),Math.round(eR[1]*255),Math.round(eR[2]*255)];
73
  if(wR.px&&wR.px.length>=3){const cP=wR.px.slice(0,3);if(cP.every((v,i)=>Math.abs(v-eP[i])<=8)){wglP=true;wglPts=70;}else{wglPts=-10;}}else{wglPts=-5;}
74
  const rdr=wR.rdr?.toLowerCase()||"";if(rdr.includes("swiftshader")||rdr.includes("llvmpipe")){wglPts-=20;wglP=false;}}else if(wR?.err){wglPts=-5;}
75
+ sc+=wglPts;stgs.push({n:"E3(WebGL)",p:wglP,pts:wglPts});
76
  let navP=true; let navPts=0;
77
  if(nI){if(nI.wd===true){navPts-=30;navP=false;}if(!nI.ua||nI.ua===""){navPts-=10;navP=false;}else if(nI.ua.toLowerCase().includes("bot")||nI.ua.toLowerCase().includes("headless")){if(!nI.ua.toLowerCase().includes("headlesschrome")){navPts-=20;navP=false;}}}else{navPts-=5;navP=false;}
78
+ sc+=navPts;stgs.push({n:"E4(Nav)",p:navP,pts:navPts});
79
  let perfP=true; let perfPts=0;
80
  if(pT&&sV){const{dct,ocrt,wrt}=pT;if(typeof dct==='number'&&dct<10){perfPts-=10;perfP=false;}if(typeof ocrt==='number'&&ocrt<3&&oCDU){perfPts-=10;perfP=false;}if(typeof wrt==='number'&&wrt<3&&wR?.px){perfPts-=10;perfP=false;}}else if(!pT){perfPts-=3;perfP=false;}
81
+ sc+=perfPts;stgs.push({n:"E5(Perf)",p:perfP,pts:perfPts});
82
  let autoP=true; let autoPts=0;
83
  if(aV&&Object.keys(aV).length>0){autoPts-=40;autoP=false;}else{autoPts+=5;}
84
+ sc+=autoPts;stgs.push({n:"E6(Auto)",p:autoP,pts:autoPts});
85
  sc=Math.max(0,Math.min(sc,150));
86
  let vT="";
87
  if(mF){vT="Блок (Критический провал)";}
 
91
  console.log(`[${new Date().toISOString().slice(0,19).replace('T',' ')}] Chk: T=${sT||'N/A'},S=${sc},V=${vT},IP=${req.ip},MF=${mF},OCR=${oP},WebGL=${wglP},Nav=${navP},Perf=${perfP},Auto=${autoP}`);
92
  res.json({vT,fS:sc,cS:stgs});
93
  });
94
+
95
  setInterval(()=>{const n=Date.now();for(const t in cs){if(cs[t].exp<n||(cs[t].usd&&(n-cs[t].iat>CEX*2))){delete cs[t];}}},60000);
96
  async function shutdown(){console.log("Shutdown...");if(tp){console.log("Draining pool...");await tp.drain().then(()=>tp.clear()).then(()=>console.log("Pool cleared.")).catch(e=>console.error("Pool drain err:",e));}process.exit(0);}
97
  process.on('SIGTERM',shutdown);process.on('SIGINT',shutdown);
98
+ app.listen(port,()=>{console.log(`AES Encrypted API on ${port}`);});