Secure bitcoin market built on PHP (developed as part of my bachelor studies about hidden marketplaces).
It provides only a basic set of marketplace features, but offers a significant higher level of security which would protect against a very strong adversary.
Plus, its bitcoin integration avoid the use of live wallets by using multisig transactions and BIP32 hierarchical keys. Neither valuable bitcoins nor user private keys are stored on the marketplace.
Why PHP? We use a custom, tiny MVC framework on top of a stripped-down php-core to keep the attack surface minimal. See Security & design decisions - PHP for more.
- Basic 'shop' features (create products, shipping options, order lifecycle)
- Bitcoin multisig transactions & BIP32 keys
- PGP encryption of shipping info
- Simple admin interface (disputes etc.)
See Features for more.
- Tested only on Linux for now, MAC OS X & other unices should work, too
- PHP 5.4+ (see Quickstart below) & MySQL 5+
- PHP dependencies as mentioned below (gnupg etc.) must compile on your platform
- ImageMagick (
identify,convert,mogrifyexecutables must be inPATH) - Bitcoind
These instructions are only suited for a quick & dirty setup for developers!
If you're planning to run it in a productive environment, please see Installation in the wiki.
install phpbrew itself:
curl -L -O https://github.com/phpbrew/phpbrew/raw/master/phpbrew
chmod +x phpbrew
sudo mv phpbrew /usr/bin/phpbrewinstall latest php 5.4 with minimal extensions (pdo, mysql, multibyte and PGP only required for now):
phpbrew install 5.4 +pdo +mb +mysql +gnupg +gmpinstall extensions needed for composer:
phpbrew ext install json
phpbrew ext install filter
phpbrew ext install hash
phpbrew ext install ctypeinstall composer
phpbrew install-composerclone repo from github (requires git):
git clone https://github.com/MatthiasWinzeler/scam.git
cd scaminstall dependencies using composer
composer installinstall MySQL (add a dedicated user for scam), then init database with the provided scripts:
for sql_file in app/install/*.sql; do mysql -uroot -p < $sql_file; doneInstall Bitcoind and modify the bitcoin.conf to contain at least:
rpcuser=bitcoinrpc
rpcpassword=set a password here
# scam is currently only tested on bitcoin testnet:
testnet=1
blocknotify=/path/to/.phpbrew/php/php-5.4.34/bin/php /path/to/scam/app/cli.php block-notify %s
server=1
daemon=1
txindex=1
checkblocks=5
rpcport=28332
rpcconnect=127.0.0.1
bitcoind will now notify SCAM for every new block seen on testnet.
SCAM stores the received transactions of the block in the database for later handling (checking for payments etc.).
This handling of transactions is done by another script that should be done periodically, i.e. with cron. Insert in your crontab:
*/10 * * * * /path/to/.phpbrew/php/php-5.4.34/bin/php /path/to/scam/app/run.php
Or run the script manually to check the transactions.
Now run bitcoind:
bitcoind
Set the connection details for MySQL and bitcoind in app/config/config.php:
define('BITCOIND_URL', 'http://bitcoinrpc:yourbitcoinpassword@127.0.0.1:28332');
define('DB_HOST', '127.0.0.1');
define('DB_NAME', 'scam');
define('DB_USER', 'your_mysql_user');
define('DB_PASS', 'your_mysql_password');At last, you have to define the admin bitcoin BIP32 extended public key M/k'/0 (used for multisig transactions - you can use bip32.org) and a bitcoin address, whose private key you own (used for admin auth):
php /path/to/scam/app/cli.php set-admin <BIP32_Extended_Public_Key_M/k'/0> <bitcoin-address>
For example:
php /path/to/scam/app/cli.php set-admin tpubDBvoSTTAJmqmqjkq5dPZLkk3rxMe4bdsJ1ZiKp4NkHh9xEf3yHqsNUfCZacdWLyejpFfqgRGQX1Moyd3xz2tpvfpYpRjeMbBwdiUKL6ccZi mpbbzJjE58afUMyS7MXnN9T4XaLQFM7dqX
Now, you can run the server:
php -S localhost:3000Access it with your webbrowser pointing to http://localhost:3000 or http://localhost:3000/?c=admin (admin interface)
To debug, install xdebug and configure it for your favorite IDE:
phpbrew ext install xdebug stable