ogrechkoandClaude Sonnet 5 ee4562530a Remove malware planted via exposed dev-mode frontend
The frontend container ran `next dev` bound to 0.0.0.0:3000 with the
host source directory bind-mounted rw into it. Over months this let
attackers write files directly onto the host filesystem, which then
got swept into git by an unrelated Gitea ZIP restore. Removes 4 UPX-
packed ELF binaries and a defacement marker (cox.txt/html).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Gh2UXUQUVBWroWEnn1FLFG
2026-09-03 04:03:32 +00:00

KKPAB Site

Modernized rebuild of kkpab26.ru using:

  • Django + Django REST Framework for content management API
  • Next.js for the public website
  • PostgreSQL for production data
  • Nginx for reverse proxy and static/media delivery

Structure

  • backend/ Django API and admin
  • frontend/ Next.js public website
  • deploy/ deployment templates

Local setup

Backend

cd backend
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
python manage.py migrate
python manage.py loaddata content/fixtures/initial_data.json
python manage.py createsuperuser
python manage.py runserver 0.0.0.0:7788

Frontend

cd frontend
npm install
cp .env.local.example .env.local
npm run dev

Frontend expects API at http://localhost:7788/api.

Production notes

  • build frontend with npm run build
  • run Django with gunicorn
  • route /api, /admin, /media, /static to Django
  • route / to Next.js
S
Description
No description provided
Readme
125 MiB
0 Stars 1 Watchers 0 Forks
Languages
Rich Text Format 67.6%
TypeScript 17.6%
Python 8.2%
CSS 6.2%
Dockerfile 0.4%