working alpha version
This commit is contained in:
4
mini-pc/etc/nginx/sites-available/talia-sd
Normal file
4
mini-pc/etc/nginx/sites-available/talia-sd
Normal file
@ -0,0 +1,4 @@
|
|||||||
|
server {
|
||||||
|
autoindex on;
|
||||||
|
root /var/www/talia;
|
||||||
|
}
|
||||||
10
mini-pc/etc/systemd/system/talia-wait.service
Normal file
10
mini-pc/etc/systemd/system/talia-wait.service
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Talia SD Wait Service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/root/scripts/wait.sh
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=60
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
13
mini-pc/readme
Normal file
13
mini-pc/readme
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
# mini pc
|
||||||
|
# debian 13 trixie
|
||||||
|
|
||||||
|
# packages
|
||||||
|
# libclamunrar require non-free
|
||||||
|
apt-get install clamav libclamunrar nginx
|
||||||
|
|
||||||
|
# create app dirs
|
||||||
|
mkdir -p /mnt/usb_share /var/www/talia /var/local/talia
|
||||||
|
|
||||||
|
# enable service
|
||||||
|
systemctl enable talia-wait.service
|
||||||
|
systemctl start talia-wait.service
|
||||||
33
mini-pc/root/scripts/scan.sh
Executable file
33
mini-pc/root/scripts/scan.sh
Executable file
@ -0,0 +1,33 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
LOCAL_DIR="/var/local/talia/"
|
||||||
|
WEB_DIR="/var/www/talia/"
|
||||||
|
|
||||||
|
cd $LOCAL_DIR
|
||||||
|
# hash control
|
||||||
|
if hashinfo=$(md5sum --check talia-md5sum.txt | egrep 'FAILED$')
|
||||||
|
then
|
||||||
|
file_list=$(echo "$hashinfo" | rev | cut -d ":" -f 2- | rev)
|
||||||
|
for i in $(echo "$file_list")
|
||||||
|
do
|
||||||
|
sed -i "s|.*"$i"$|Hash Mismatch "$i"|" talia-md5sum.txt
|
||||||
|
rm $LOCAL_DIR/"$i"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
# av scan
|
||||||
|
if ! scaninfo=$(clamscan --no-summary --infected --recursive "$LOCAL_DIR")
|
||||||
|
then
|
||||||
|
file_list=$(echo "$scaninfo" | cut -d '/' -f 5- | rev | cut -d ':' -f2 | rev)
|
||||||
|
for i in $(echo "$file_list")
|
||||||
|
do
|
||||||
|
sed -i "s|.*"$i"$|Virus Detected "$i"|" talia-md5sum.txt
|
||||||
|
rm $LOCAL_DIR/"$i"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
# mv files to web dir
|
||||||
|
scan_date=$(date "+%Y%m%d_%H%M%S")
|
||||||
|
mv $LOCAL_DIR $WEB_DIR/$scan_date
|
||||||
|
mkdir $LOCAL_DIR
|
||||||
|
chown -R www-data:www-data $WEB_DIR/$scan_date
|
||||||
26
mini-pc/root/scripts/wait.sh
Executable file
26
mini-pc/root/scripts/wait.sh
Executable file
@ -0,0 +1,26 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
SERIAL_PORT="/dev/ttyACM0"
|
||||||
|
USB_MOUNT="/mnt/usb_share/"
|
||||||
|
LOCAL_DIR="/var/local/talia/"
|
||||||
|
|
||||||
|
while sleep 3
|
||||||
|
do
|
||||||
|
# device is ready
|
||||||
|
USB_DEV=$(lsblk -ndo PATH,SERIAL | grep "TALIA003512M" | cut -d " " -f 1)
|
||||||
|
if [ -e "$USB_DEV" ] && [ -c "$SERIAL_PORT" ]
|
||||||
|
then
|
||||||
|
mkdir -p "$USB_MOUNT"
|
||||||
|
mount "$USB_DEV" "$USB_MOUNT"
|
||||||
|
rsync -a "$USB_MOUNT"talia-sd/ "$LOCAL_DIR"
|
||||||
|
umount "$USB_MOUNT"
|
||||||
|
stty -F "$SERIAL_PORT" raw
|
||||||
|
# send done and wait for disconnect
|
||||||
|
while [ -e "$USB_DEV" ] && [ -c "$SERIAL_PORT" ]
|
||||||
|
do
|
||||||
|
echo "DONE" > "$SERIAL_PORT"
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
/root/scripts/scan.sh
|
||||||
|
fi
|
||||||
|
done
|
||||||
11
raspberry-pi/etc/systemd/system/talia-serial-wait.service
Normal file
11
raspberry-pi/etc/systemd/system/talia-serial-wait.service
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Talia SD Serial Wait Service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=exec
|
||||||
|
ExecStart=/root/scripts/serial-wait.sh
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=5
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
10
raspberry-pi/etc/systemd/system/talia-wait.service
Normal file
10
raspberry-pi/etc/systemd/system/talia-wait.service
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Talia SD Wait Service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/root/scripts/wait.sh
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=60
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
156
raspberry-pi/etc/vsftpd.conf
Normal file
156
raspberry-pi/etc/vsftpd.conf
Normal file
@ -0,0 +1,156 @@
|
|||||||
|
# Example config file /etc/vsftpd.conf
|
||||||
|
#
|
||||||
|
# The default compiled in settings are fairly paranoid. This sample file
|
||||||
|
# loosens things up a bit, to make the ftp daemon more usable.
|
||||||
|
# Please see vsftpd.conf.5 for all compiled in defaults.
|
||||||
|
#
|
||||||
|
# READ THIS: This example file is NOT an exhaustive list of vsftpd options.
|
||||||
|
# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's
|
||||||
|
# capabilities.
|
||||||
|
#
|
||||||
|
#
|
||||||
|
# Run standalone? vsftpd can run either from an inetd or as a standalone
|
||||||
|
# daemon started from an initscript.
|
||||||
|
listen=NO
|
||||||
|
#
|
||||||
|
# This directive enables listening on IPv6 sockets. By default, listening
|
||||||
|
# on the IPv6 "any" address (::) will accept connections from both IPv6
|
||||||
|
# and IPv4 clients. It is not necessary to listen on *both* IPv4 and IPv6
|
||||||
|
# sockets. If you want that (perhaps because you want to listen on specific
|
||||||
|
# addresses) then you must run two copies of vsftpd with two configuration
|
||||||
|
# files.
|
||||||
|
listen_ipv6=YES
|
||||||
|
#
|
||||||
|
# Allow anonymous FTP? (Disabled by default).
|
||||||
|
anonymous_enable=NO
|
||||||
|
#
|
||||||
|
# Uncomment this to allow local users to log in.
|
||||||
|
local_enable=YES
|
||||||
|
#
|
||||||
|
# Uncomment this to enable any form of FTP write command.
|
||||||
|
# talia
|
||||||
|
write_enable=YES
|
||||||
|
#
|
||||||
|
# Default umask for local users is 077. You may wish to change this to 022,
|
||||||
|
# if your users expect that (022 is used by most other ftpd's)
|
||||||
|
#local_umask=022
|
||||||
|
#
|
||||||
|
# Uncomment this to allow the anonymous FTP user to upload files. This only
|
||||||
|
# has an effect if the above global write enable is activated. Also, you will
|
||||||
|
# obviously need to create a directory writable by the FTP user.
|
||||||
|
#anon_upload_enable=YES
|
||||||
|
#
|
||||||
|
# Uncomment this if you want the anonymous FTP user to be able to create
|
||||||
|
# new directories.
|
||||||
|
#anon_mkdir_write_enable=YES
|
||||||
|
#
|
||||||
|
# Activate directory messages - messages given to remote users when they
|
||||||
|
# go into a certain directory.
|
||||||
|
dirmessage_enable=YES
|
||||||
|
#
|
||||||
|
# If enabled, vsftpd will display directory listings with the time
|
||||||
|
# in your local time zone. The default is to display GMT. The
|
||||||
|
# times returned by the MDTM FTP command are also affected by this
|
||||||
|
# option.
|
||||||
|
use_localtime=YES
|
||||||
|
#
|
||||||
|
# Activate logging of uploads/downloads.
|
||||||
|
xferlog_enable=YES
|
||||||
|
#
|
||||||
|
# Make sure PORT transfer connections originate from port 20 (ftp-data).
|
||||||
|
connect_from_port_20=YES
|
||||||
|
#
|
||||||
|
# If you want, you can arrange for uploaded anonymous files to be owned by
|
||||||
|
# a different user. Note! Using "root" for uploaded files is not
|
||||||
|
# recommended!
|
||||||
|
#chown_uploads=YES
|
||||||
|
#chown_username=whoever
|
||||||
|
#
|
||||||
|
# You may override where the log file goes if you like. The default is shown
|
||||||
|
# below.
|
||||||
|
#xferlog_file=/var/log/vsftpd.log
|
||||||
|
#
|
||||||
|
# If you want, you can have your log file in standard ftpd xferlog format.
|
||||||
|
# Note that the default log file location is /var/log/xferlog in this case.
|
||||||
|
#xferlog_std_format=YES
|
||||||
|
#
|
||||||
|
# You may change the default value for timing out an idle session.
|
||||||
|
#idle_session_timeout=600
|
||||||
|
#
|
||||||
|
# You may change the default value for timing out a data connection.
|
||||||
|
#data_connection_timeout=120
|
||||||
|
#
|
||||||
|
# It is recommended that you define on your system a unique user which the
|
||||||
|
# ftp server can use as a totally isolated and unprivileged user.
|
||||||
|
#nopriv_user=ftpsecure
|
||||||
|
#
|
||||||
|
# Enable this and the server will recognise asynchronous ABOR requests. Not
|
||||||
|
# recommended for security (the code is non-trivial). Not enabling it,
|
||||||
|
# however, may confuse older FTP clients.
|
||||||
|
#async_abor_enable=YES
|
||||||
|
#
|
||||||
|
# By default the server will pretend to allow ASCII mode but in fact ignore
|
||||||
|
# the request. Turn on the below options to have the server actually do ASCII
|
||||||
|
# mangling on files when in ASCII mode.
|
||||||
|
# Beware that on some FTP servers, ASCII support allows a denial of service
|
||||||
|
# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd
|
||||||
|
# predicted this attack and has always been safe, reporting the size of the
|
||||||
|
# raw file.
|
||||||
|
# ASCII mangling is a horrible feature of the protocol.
|
||||||
|
#ascii_upload_enable=YES
|
||||||
|
#ascii_download_enable=YES
|
||||||
|
#
|
||||||
|
# You may fully customise the login banner string:
|
||||||
|
#ftpd_banner=Welcome to blah FTP service.
|
||||||
|
#
|
||||||
|
# You may specify a file of disallowed anonymous e-mail addresses. Apparently
|
||||||
|
# useful for combatting certain DoS attacks.
|
||||||
|
#deny_email_enable=YES
|
||||||
|
# (default follows)
|
||||||
|
#banned_email_file=/etc/vsftpd.banned_emails
|
||||||
|
#
|
||||||
|
# You may restrict local users to their home directories. See the FAQ for
|
||||||
|
# the possible risks in this before using chroot_local_user or
|
||||||
|
# chroot_list_enable below.
|
||||||
|
#chroot_local_user=YES
|
||||||
|
#
|
||||||
|
# You may specify an explicit list of local users to chroot() to their home
|
||||||
|
# directory. If chroot_local_user is YES, then this list becomes a list of
|
||||||
|
# users to NOT chroot().
|
||||||
|
# (Warning! chroot'ing can be very dangerous. If using chroot, make sure that
|
||||||
|
# the user does not have write access to the top level directory within the
|
||||||
|
# chroot)
|
||||||
|
#chroot_local_user=YES
|
||||||
|
#chroot_list_enable=YES
|
||||||
|
# (default follows)
|
||||||
|
#chroot_list_file=/etc/vsftpd.chroot_list
|
||||||
|
#
|
||||||
|
# You may activate the "-R" option to the builtin ls. This is disabled by
|
||||||
|
# default to avoid remote users being able to cause excessive I/O on large
|
||||||
|
# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
|
||||||
|
# the presence of the "-R" option, so there is a strong case for enabling it.
|
||||||
|
#ls_recurse_enable=YES
|
||||||
|
#
|
||||||
|
# Customization
|
||||||
|
#
|
||||||
|
# Some of vsftpd's settings don't fit the filesystem layout by
|
||||||
|
# default.
|
||||||
|
#
|
||||||
|
# This option should be the name of a directory which is empty. Also, the
|
||||||
|
# directory should not be writable by the ftp user. This directory is used
|
||||||
|
# as a secure chroot() jail at times vsftpd does not require filesystem
|
||||||
|
# access.
|
||||||
|
secure_chroot_dir=/var/run/vsftpd/empty
|
||||||
|
#
|
||||||
|
# This string is the name of the PAM service vsftpd will use.
|
||||||
|
pam_service_name=vsftpd
|
||||||
|
#
|
||||||
|
# This option specifies the location of the RSA certificate to use for SSL
|
||||||
|
# encrypted connections.
|
||||||
|
rsa_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem
|
||||||
|
rsa_private_key_file=/etc/ssl/private/ssl-cert-snakeoil.key
|
||||||
|
ssl_enable=NO
|
||||||
|
|
||||||
|
#
|
||||||
|
# Uncomment this to indicate that vsftpd use a utf8 filesystem.
|
||||||
|
#utf8_filesystem=YES
|
||||||
20
raspberry-pi/readme
Normal file
20
raspberry-pi/readme
Normal file
@ -0,0 +1,20 @@
|
|||||||
|
# install raspberry-pi os
|
||||||
|
# debian 13 trixie
|
||||||
|
# https://www.raspberrypi.com/documentation/computers/getting-started.html#imager-install
|
||||||
|
|
||||||
|
# pi as usb storage
|
||||||
|
echo '# Enable USB OTG
|
||||||
|
dtoverlay=dwc2' >> /boot/firmware/config.txt
|
||||||
|
echo 'dwc2
|
||||||
|
g_mass_storage' > /etc/modules-load.d/talia.conf
|
||||||
|
|
||||||
|
dd if=/dev/zero of=/usb_share.img bs=1M count=8192
|
||||||
|
mkfs.ext4 /usb_share.img
|
||||||
|
mkdir /mnt/usb_share
|
||||||
|
|
||||||
|
# packages
|
||||||
|
apt install vsftpd inotify-tools
|
||||||
|
|
||||||
|
# enable service
|
||||||
|
systemctl enable talia-wait.service
|
||||||
|
systemctl start talia-wait.service
|
||||||
35
raspberry-pi/root/scripts/expose_usb.sh
Executable file
35
raspberry-pi/root/scripts/expose_usb.sh
Executable file
@ -0,0 +1,35 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
modprobe libcomposite
|
||||||
|
cd /sys/kernel/config/usb_gadget/
|
||||||
|
mkdir -p g1 && cd g1
|
||||||
|
|
||||||
|
# Standard USB descriptors
|
||||||
|
echo 0x1d6b > idVendor
|
||||||
|
echo 0x0104 > idProduct
|
||||||
|
echo 0x0100 > bcdDevice
|
||||||
|
echo 0x0200 > bcdUSB
|
||||||
|
|
||||||
|
mkdir -p strings/0x409
|
||||||
|
echo "TALIA003512M" > strings/0x409/serialnumber
|
||||||
|
echo "Debian" > strings/0x409/manufacturer
|
||||||
|
echo "EmulatedDrive" > strings/0x409/product
|
||||||
|
|
||||||
|
mkdir -p configs/c.1/strings/0x409
|
||||||
|
echo "Storage and Serial" > configs/c.1/strings/0x409/configuration
|
||||||
|
echo 500 > configs/c.1/MaxPower
|
||||||
|
|
||||||
|
mkdir -p functions/mass_storage.usb0
|
||||||
|
echo 1 > functions/mass_storage.usb0/stall
|
||||||
|
echo 1 > functions/mass_storage.usb0/lun.0/removable
|
||||||
|
# CRITICAL: Forces target PC to treat it as Read-Only
|
||||||
|
echo 1 > functions/mass_storage.usb0/lun.0/ro
|
||||||
|
|
||||||
|
echo /usb_share.img > functions/mass_storage.usb0/lun.0/file
|
||||||
|
ln -sf functions/mass_storage.usb0 configs/c.1/
|
||||||
|
|
||||||
|
# Serial connection
|
||||||
|
mkdir -p functions/acm.usb0
|
||||||
|
ln -sf functions/acm.usb0 configs/c.1/
|
||||||
|
|
||||||
|
# Bind to the physical controller to make it appear on the reading PC
|
||||||
|
echo $(ls /sys/class/udc/) > UDC
|
||||||
18
raspberry-pi/root/scripts/serial-wait.sh
Executable file
18
raspberry-pi/root/scripts/serial-wait.sh
Executable file
@ -0,0 +1,18 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
SERIAL_PORT="/dev/ttyGS0"
|
||||||
|
stty -F "$SERIAL_PORT" raw
|
||||||
|
|
||||||
|
while true
|
||||||
|
do
|
||||||
|
if read -r line < "$SERIAL_PORT"
|
||||||
|
then
|
||||||
|
# wait for done message
|
||||||
|
if [ "$line" = "DONE" ]
|
||||||
|
then
|
||||||
|
echo "" > /sys/kernel/config/usb_gadget/g1/UDC
|
||||||
|
exit
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
sleep 0.5
|
||||||
|
done
|
||||||
45
raspberry-pi/root/scripts/wait.sh
Executable file
45
raspberry-pi/root/scripts/wait.sh
Executable file
@ -0,0 +1,45 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
SERIAL_PORT="/dev/ttyGS0"
|
||||||
|
USB_FILE="/usb_share.img"
|
||||||
|
USB_MOUNT="/mnt/usb_share/"
|
||||||
|
LOCAL_DIR="/var/local/talia/"
|
||||||
|
FTP_DIR="/home/birikim/out/"
|
||||||
|
|
||||||
|
while sleep 3
|
||||||
|
do
|
||||||
|
if [ -z "$(cat /sys/kernel/config/usb_gadget/g1/UDC)" ] && \
|
||||||
|
[ -n "$(ls -A $FTP_DIR)" ]
|
||||||
|
then
|
||||||
|
mount $USB_FILE $USB_MOUNT
|
||||||
|
rm -rf $USB_MOUNT/talia-sd
|
||||||
|
mkdir $USB_MOUNT/talia-sd
|
||||||
|
|
||||||
|
# wait writes to be completed
|
||||||
|
while inotifywait -t 60 -r -e close_write -e moved_to "$FTP_DIR"
|
||||||
|
do
|
||||||
|
true
|
||||||
|
done
|
||||||
|
|
||||||
|
# lock dir and mv files to USB storage
|
||||||
|
chown -R root:root $FTP_DIR
|
||||||
|
cd $FTP_DIR
|
||||||
|
for i in $(ls -A $FTP_DIR)
|
||||||
|
do
|
||||||
|
mv "$i" $USB_MOUNT/talia-sd/
|
||||||
|
done
|
||||||
|
chown -R birikim:birikim $FTP_DIR
|
||||||
|
cd $USB_MOUNT/talia-sd/
|
||||||
|
# md5sum
|
||||||
|
find -type f -exec md5sum {} \; > /tmp/talia-md5sum.txt
|
||||||
|
sed -i "s/.\///" /tmp/talia-md5sum.txt
|
||||||
|
cd /tmp
|
||||||
|
mv talia-md5sum.txt $USB_MOUNT/talia-sd/
|
||||||
|
umount $USB_MOUNT
|
||||||
|
|
||||||
|
# expose USB storage
|
||||||
|
/root/scripts/expose_usb.sh
|
||||||
|
# wait serial
|
||||||
|
systemctl start talia-serial-wait.service
|
||||||
|
fi
|
||||||
|
done
|
||||||
Reference in New Issue
Block a user