API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
"""
+
API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
""" + how(["Your IP is auto-detected the moment the page loads — no input needed.","Type any other IP or hostname into the field for the same full report.","Everything is one GET away for agents: /api/ip and /api/ip?target=.","VPN/proxy/hosting flags come from IP-quality heuristics — if it says proxy, you are looking at a relay."])
return page("ip", body)
def ip_form():
@@ -302,7 +364,7 @@ def card():
result = f"""
{kv([("Brand",brand),("BIN",num[:8]),("Bank / Issuer",esc(bank)),("Country",esc(country)),("Type",str(ctype)),("Prepaid",str(prepaid))])}
Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.
"""
+
Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.
""" + how(["Paste the card number — it never leaves the request, nothing is stored.","Luhn checksum validates the digit structure instantly.","BIN (first 8 digits) reveals the issuer bank, brand, card type and country.","Prepaid BINs get flagged — merchants commonly reject them.","This CANNOT show balance or fraud-hold status; only the issuer knows that."])
body = f"""
API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
"""
+
API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
""" + how(["Pick a service and country, rent — the number is live for 30 minutes exactly.","Use it for any signup/verification. The code arrives as a text.","Poll the order (auto or manual) until the code shows.","Cancel before a code arrives and you get every satoshi back.","Each rental is logged in the recent-rentals table with a live countdown."])
return page("sms", body)
@app.route("/api/sms/rent", methods=["POST"])
def api_sms_rent():
guard = sms_guard()
if guard: return jsonify({"success": 0, "message": guard, "paused": True})
+ uid = key_user() or current_user_id()
+ if uid and not has_pass(uid) and get_balance(uid) < 50:
+ return jsonify({"ok": False, "error": "insufficient balance", "topup": SITE + "/keys"}), 402
st, b = sms_api("purchase/sms", service=param("service"), country=param("country"))
d = jf(b) or {}
if d.get("success") == 1:
@@ -419,6 +484,9 @@ def api_sms_rent():
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
(d.get("number"), param("service"), param("country"), str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
con.commit()
+ cost = int(d.get("cost_in_cents") or 5)
+ if uid and not has_pass(uid):
+ charge(uid, cost, f"sms rental +{d.get('number')}")
return jsonify(d)
@app.route("/api/sms/check", methods=["GET","POST"])
@@ -485,7 +553,7 @@ def proxy():
API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
"""
+
API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
""" + how(["Enter your Pleiades gateway user:pass — the same credentials work across the fleet.","The lab tunnels a CONNECT request through the gateway and reports the true egress IP, geo and ISP.","Use the geo builder to steer the exit: region, country, city, sticky 30-min sessions.","Need bandwidth? Buy GB plans at the Pleiades storefront."])
return page("proxy", body)
@app.route("/api/proxy/test", methods=["POST"])
@@ -534,7 +602,7 @@ def steg_hide(img_bytes, text, password="", bits=1, spread="sequential"):
return None, f"too big: need {len(data)*8} bits, image holds {capacity}"
if spread == "random":
import random as _r
- _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big"))
+ _r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big"))
order = list(range(w*h)); _r.shuffle(order)
else:
order = list(range(w*h))
@@ -566,7 +634,7 @@ def _pnginfo(bits, spread):
try:
from PIL.PngImagePlugin import PngInfo
info = PngInfo()
- info.add_text("auriga_meta", json.dumps({"bits": bits, "spread": spread, "v": 2}))
+ info.add_text("dark0rbits_meta", json.dumps({"bits": bits, "spread": spread, "v": 2}))
return info
except Exception:
return None
@@ -574,7 +642,7 @@ def _pnginfo(bits, spread):
def steg_extract(img_bytes, password="", bits=None, spread=None):
from PIL import Image
im = Image.open(io.BytesIO(img_bytes))
- meta = im.info.get("auriga_meta")
+ meta = im.info.get("dark0rbits_meta") or im.info.get("auriga_meta")
if meta:
try:
m = json.loads(meta)
@@ -588,7 +656,7 @@ def steg_extract(img_bytes, password="", bits=None, spread=None):
# replicate the shuffle used at hide time
if spread == "random":
import random as _r
- _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big"))
+ _r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big"))
order = list(range(w*h)); _r.shuffle(order)
else:
order = list(range(w*h))
@@ -610,13 +678,13 @@ def steg_extract(img_bytes, password="", bits=None, spread=None):
if need is not None and idx >= need: break
if need is None and idx >= 64:
if bytes(raw[:4]) != b"AUR1":
- return None, f"no AURIGA payload found with LSB depth {bits} (try other depth / randomized)"
+ return None, f"no DARK0RBITS payload found with LSB depth {bits} (try other depth / randomized)"
ln = struct.unpack(">I", bytes(raw[4:8]))[0]
need = 64 + ln * 8
data = bytes(raw)
if len(data) < 12: return None, "payload too small"
if bytes(data[:4]) != b"AUR1":
- return None, "no AURIGA payload found (wrong password or settings?)"
+ return None, "no DARK0RBITS payload found (wrong password or settings?)"
if password and hashlib.sha256(password.encode()).digest()[:4] != data[8:12]:
return None, "wrong password"
ln = struct.unpack(">I", data[4:8])[0]
@@ -663,7 +731,7 @@ d.addEventListener('change',function(){{}});
document.getElementById('ih').addEventListener('change',function(){{document.querySelector('.fnh').textContent=this.files[0].name}});
document.getElementById('ie').addEventListener('change',function(){{document.querySelector('.fne').textContent=this.files[0].name}});
-
API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
"""
+
API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
""" + how(["Drop a PNG — your words are written into the least-significant bits of its pixels.","Depth 1 = invisible and robust; depth 2-3 fits more text but is easier to detect.","Spread=randomized scatters bits across the image instead of top-down.","A password encrypts the payload AND derives the scatter pattern — wrong password = noise.","Extract reads the embedded metadata automatically — just drop the file and the words come back."])
return page("steg", body)
@app.route("/api/steg/hide", methods=["POST"])
@@ -678,7 +746,7 @@ def api_steg_hide():
except Exception as e:
return jsonify({"ok": False, "error": str(e)}), 400
if out is None: return jsonify({"ok": False, "error": meta}), 400
- return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="auriga-hidden.png")
+ return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="dark0rbits-hidden.png")
@app.route("/api/steg/extract", methods=["POST"])
def api_steg_extract():
@@ -712,19 +780,19 @@ def track():
BTCPay BTC only. After payment the upload opens automatically.
{mine}
How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. Login (no KYC) to see events.
-
API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
"""
+
API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
""" + how(["Pay $1 in BTC — the invoice settles and unlocks the upload instantly.","Upload your file or picture: you get a secret tracked link plus an email-ready HTML copy.","Email the HTML copy or share the link — every open fires back.","Each open reports: exact time, real IP, city/country, ISP, timezone, VPN flag, device, language, referrer.","Alerts land in your INBOX the second it happens."])
return page("track", body)
def btc_invoice(amount="1.00"):
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
- data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "auriga-track"}}).encode(), method="POST")
+ data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "dark0rbits-track"}}).encode(), method="POST")
return jf(b) or {}
@app.route("/api/track/create", methods=["POST"])
def api_track_create():
fn = param("filename") or "file"
- uid = current_user_id()
+ uid = key_user() or current_user_id()
token = secrets.token_urlsafe(16)
con = db()
if has_pass(uid):
@@ -732,6 +800,11 @@ def api_track_create():
(uid or 0, token, esc(fn[:100]), "file", "PASS", int(time.time())))
con.commit()
return jsonify({"ok": True, "free": True, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"})
+ if uid and charge(uid, 100, f"trackable file ({fn[:40]})"):
+ con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)",
+ (uid or 0, token, esc(fn[:100]), "file", "BALANCE", int(time.time())))
+ con.commit()
+ return jsonify({"ok": True, "balance_charged": 1.00, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"})
inv = btc_invoice()
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)",
@@ -762,7 +835,7 @@ def api_track_upload():
con = db()
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
if not t: return jsonify({"ok": False, "error": "unknown token"}), 400
- st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] != "PASS" else (200, '{"status":"settled"}')
+ st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] not in ("PASS", "BALANCE") else (200, '{"status":"settled"}')
inv = jf(b) or {}
paid = inv.get("status") in ("settled", "processing", "paid")
if not paid: return jsonify({"ok": False, "error": f"invoice not paid yet ({inv.get('status')})"}), 402
@@ -861,7 +934,7 @@ def api_track_events():
MAIL_PACKS = [("7","7 days — $3",3,7),("30","30 days — $8",8,30),("90","90 days — $20",20,90)]
MAIL_DOMAIN = "thetempleofdoom.com"
MAIL_RESERVED = {"indianaholmes","admin","operator","drjones","root","noreply","support","pass","mail"}
-MAIL_SECRET = "auriga-mail-relay-2026"
+MAIL_SECRET = "dark0rbits-mail-relay-2026"
@app.route("/mail", methods=["GET"])
def mail():
@@ -881,7 +954,7 @@ def mail():
{''.join(f'' for d,n,_,_ in MAIL_PACKS)}
Type your desired mailbox name, pick a length, pay the invoice — the mailbox activates the moment the payment settles.
{mine}
-
API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
"""
+
API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
""" + how(["Pick a name and a package — 7, 30 or 90 days, BTC priced.","Pay the invoice; the mailbox activates the second it settles.","The address is receive-only: verification codes, confirmations, one-off handouts.","The countdown runs in real time; when it hits zero the mailbox retires itself.","All mail shows on the site inbox — nothing touches any other identity."])
return page("steg", body)
@app.route("/api/mail/create", methods=["POST"])
@@ -897,6 +970,18 @@ def api_mail_create():
con = db()
if con.execute("SELECT 1 FROM mailboxes WHERE address=?", (addr,)).fetchone():
return jsonify({"ok": False, "error": "mailbox name taken"}), 400
+ uid = key_user() or current_user_id()
+ # metered: PASS = instant free; balance = instant paid; else BTC invoice
+ if uid and has_pass(uid):
+ con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
+ (uid, addr, "PASS", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3]))
+ con.commit()
+ return jsonify({"ok": True, "free": True, "address": addr, "expires_in_days": pack[3]})
+ if uid and charge(uid, pack[2]*100, f"burner mailbox {addr} ({pack[3]}d)"):
+ con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
+ (uid, addr, "BALANCE", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3]))
+ con.commit()
+ return jsonify({"ok": True, "balance_charged": pack[2], "address": addr, "expires_in_days": pack[3]})
inv = btc_invoice(f"{pack[2]:.2f}")
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
@@ -995,9 +1080,13 @@ def btcpay_webhook():
expect = "sha256=" + hmac.new(BTCPAY_WHSEC.encode(), body, hashlib.sha256).hexdigest()
if sig != expect: return jsonify({"ok": False, "error": "bad sig"}), 400
d = jf(body) or {}
+ iid = d.get("invoiceId") or ""
if d.get("type") == "InvoiceSettled" or (d.get("type") == "InvoicePaymentSettled"):
- iid = d.get("invoiceId")
con = db()
+ if iid:
+ if con.execute("SELECT 1 FROM wh_processed WHERE invoice_id=?", (iid,)).fetchone():
+ return jsonify({"ok": True, "dup": True})
+ con.execute("INSERT OR IGNORE INTO wh_processed(invoice_id,ts) VALUES(?,?)", (iid, int(time.time())))
con.execute("UPDATE trackables SET paid=1 WHERE invoice_id=?", (iid,))
r = con.execute("SELECT plan_days FROM mailboxes WHERE invoice_id=?", (iid,)).fetchone()
if r:
@@ -1005,9 +1094,83 @@ def btcpay_webhook():
r = con.execute("SELECT plan_days FROM passes WHERE invoice_id=?", (iid,)).fetchone()
if r:
con.execute("UPDATE passes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 30), iid))
+ # balance top-ups
+ try:
+ meta = d.get("metadata") or {}
+ if not meta:
+ st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{iid}", headers={"Authorization": "token " + BTCPAY_KEY})
+ meta = (jf(b) or {}).get("metadata", {}) or {}
+ if str(meta.get("orderId", "")).startswith("dark0rbits-topup"):
+ uid = int(meta["orderId"].split(":")[1]); cents = int(meta["orderId"].split(":")[2])
+ con.execute("INSERT OR IGNORE INTO balances(user_id, cents) VALUES(?, 0)", (uid,))
+ con.execute("UPDATE balances SET cents = cents + ? WHERE user_id=?", (cents, uid))
+ con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, cents, f"BTC topup {iid}", int(time.time())))
+ except Exception: pass
con.commit()
return jsonify({"ok": True})
+# ---------- 6h. API KEYS + BALANCE ----------
+@app.route("/keys", methods=["GET", "POST"])
+def keys():
+ uid = current_user_id()
+ if not uid:
+ return page("inbox", '
API KEYS
login on /inbox first — keys are bound to your account.
')
+ con = db()
+ if request.method == "POST" and request.form.get("act") == "mkkey":
+ label = (param("label") or "default")[:40]
+ key = "dk_" + secrets.token_urlsafe(24)
+ con.execute("INSERT INTO apikeys(user_id,key,label,created) VALUES(?,?,?,?)", (uid, key, esc(label), int(time.time())))
+ con.commit()
+ newkey = key
+ else:
+ newkey = None
+ rows = con.execute("SELECT * FROM apikeys WHERE user_id=? AND revoked=0 ORDER BY id DESC", (uid,)).fetchall()
+ bal = get_balance(uid)
+ led = con.execute("SELECT * FROM ledger WHERE user_id=? ORDER BY id DESC LIMIT 15", (uid,)).fetchall()
+ led_html = "".join(f"
Metered access for agents and humans. Every paid call deducts from your balance. $1 free trial credit on signup. No KYC, BTC top-ups only.
+
+
New API key
+{newkey_block}
+{keys_block}
+
+
Top up (BTC)
+{''.join(f'' for c,a in [(500,'$5'),(2000,'$20'),(10000,'$100')])}
+
Invoice settles → balance credited automatically via webhook.
+
+
Ledger
Δ
Reason
When
{led_html or '
no charges yet
'}
+
Use it: Authorization: Bearer dk_… header on any paid API call. Metered endpoints: /api/sms/rent (pass-through cost), /api/mail/create (package price), /api/track/create ($1). Everything else free. PASS = no metering.
"""
+ return page("inbox", body)
+
+@app.route("/api/balance/topup", methods=["POST"])
+def api_balance_topup():
+ uid = current_user_id()
+ if not uid: return jsonify({"ok": False, "error": "login required"}), 401
+ cents = int(param("cents") or 500)
+ if cents not in (500, 2000, 10000): return jsonify({"ok": False, "error": "bad amount"}), 400
+ # invoice created WITH topup metadata in one shot
+ st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
+ headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
+ data=json.dumps({"amount": f"{cents/100:.2f}", "currency": "USD",
+ "metadata": {"orderId": f"dark0rbits-topup:{uid}:{cents}", "itemDesc": "dark0rbits balance topup"}}).encode(), method="POST")
+ inv = jf(b) or {}
+ if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
+ con = db()
+ con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, 0, f"topup invoice {inv['id']} pending", int(time.time())))
+ con.commit()
+ return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink")})
+
+@app.route("/api/balance")
+def api_balance():
+ uid = key_user() or current_user_id()
+ if not uid: return jsonify({"ok": False, "error": "auth required"}), 401
+ return jsonify({"ok": True, "balance_cents": get_balance(uid), "pass_active": has_pass(uid)})
+
# ---------- 6d. EMAIL HEADER FORENSICS ----------
def parse_headers(raw):
import email as em
@@ -1060,7 +1223,7 @@ def eh():
EMAIL FORENSICS
Paste full raw email headers (View source → copy all) — get the real origin, SPF/DKIM/DMARC verdicts, and spoof flags.
-
API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.
"""
+
API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.
""" + how(["Open the suspicious email → View source → copy ALL headers.","Paste them here — the parser walks the full Received chain.","The real origin IP is pulled from the bottom-most relay hop and geolocated.","SPF/DKIM/DMARC verdicts are extracted and color-coded.","Spoof markers are flagged automatically: envelope≠From domain, Reply-To hijacks."])
return page("tools", body)
@app.route("/eh_result", methods=["POST"])
@@ -1091,7 +1254,7 @@ def forensics():
-
API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.
"""
+
API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.
""" + how(["Drop any image — EXIF and GPS get dumped instantly.","Error-level analysis (ELA) re-compresses and diffs: edited regions glow in the amplified view.","Edit-tool tags (Photoshop/GIMP) are flagged automatically.","EXIF-stripped images get flagged too — usually means scrubbed or generated.","If the image carries a DARK0RBITS stego payload, this tool sees it."])
return page("steg", body)
def _ela_score(img_bytes):
@@ -1136,7 +1299,7 @@ def forensics_result():
for k, v in rows:
if "software" in k.lower(): flags.append(f"software: {v}")
if "Photoshop" in v or "GIMP" in v: flags.append(f"⚠ EDITED IN {v}")
- stego = "auriga_meta" in im.info
+ stego = ("auriga_meta" in im.info or "dark0rbits_meta" in im.info)
ela_png, maxdiff = _ela_score(data)
fn = (f.filename or "image")[:60]
verdict = "CLEAN-ISH" if maxdiff < 12 and not flags else "SUSPECT — check ELA"
@@ -1146,7 +1309,7 @@ def forensics_result():
ela_b64 = b64mod.b64encode(ela_png).decode()
return page("steg", f"""
@@ -1170,7 +1333,7 @@ def api_forensics():
except Exception: pass
_, maxdiff = _ela_score(data)
return jsonify({"ok": True, "exif": ex, "gps_present": bool(exif.get_ifd(0x8825)) if hasattr(exif, "get_ifd") else False,
- "stego_auriga": "auriga_meta" in im.info, "ela_max_diff": maxdiff,
+ "stego_auriga": ("auriga_meta" in im.info or "dark0rbits_meta" in im.info), "ela_max_diff": maxdiff,
"flags": (["exif-stripped"] if not ex else [])})
# ---------- 6f. CANARY TRAPS ----------
@@ -1184,7 +1347,7 @@ def canary():
You get: a link (paste anywhere), a pixel URL (embed in docs/pages), and a fake credential line to drop in files.
{canary_list()}
-
API: POST /canary (tag) · GET /api/canary/list (login) · hits log like trackables.
"""
+
API: POST /canary (tag) · GET /api/canary/list (login) · hits log like trackables.
""" + how(["Create a trap and tag it with who/where it belongs.","Plant the link anywhere — or embed the pixel URL, or drop the fake credential line.","The moment ANYONE touches it: IP, geo, ISP, device fire into your inbox.","Each trap shows its hit count and armed/triggered status.","One trap per place — re-plant after it fires."])
return page("track", body)
def canary_list():
@@ -1252,10 +1415,10 @@ def passport():
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > (strftime('%s','now')-2592000)", ).fetchone()["c"]
pas = has_pass(uid)
badge = {"holder": u["username"], "issued": u["created"], "pass_active": pas,
- "tool_usage_30d": {"sms_rentals": n_sms}, "site": "auriga.thetempleofdoom.com", "v": 1,
+ "tool_usage_30d": {"sms_rentals": n_sms}, "site": "dark0rbits.thetempleofdoom.com", "v": 1,
"principles": ["no-KYC", "BTC-only", "agent-friendly"]}
body = f"""
-
AGENT PASSPORT
Machine-readable identity + trust badge for agents operating on AURIGA.
+
AGENT PASSPORT
Machine-readable identity + trust badge for agents operating on DARK0RBITS.
{kv([("Holder", esc(u['username'])), ("Issued", time.strftime("%b %d %Y", time.localtime(u["created"]))), ("PASS", "ACTIVE ✓" if pas else "none"), ("SMS rentals (30d)", n_sms)])}
Badge JSON
{json.dumps(badge, indent=1)}
API: GET /api/passport (cookie auth) → badge JSON. Embed in your agent's llms.txt / tool card.
"""
@@ -1267,13 +1430,13 @@ def api_passport():
if not uid: return jsonify({"ok": False, "error": "login required"})
con = db()
u = con.execute("SELECT * FROM users WHERE id=?", (uid,)).fetchone()
- return jsonify({"holder": u["username"], "issued": u["created"], "pass_active": has_pass(uid), "site": "auriga.thetempleofdoom.com"})
+ return jsonify({"holder": u["username"], "issued": u["created"], "pass_active": has_pass(uid), "site": "dark0rbits.thetempleofdoom.com"})
# ---------- 7. INBOX (no-KYC site-only messaging) ----------
-def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"auriga-salt", n=16384, r=8, p=1).hex()
+def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"dark0rbits-salt", n=16384, r=8, p=1).hex()
def current_user_id():
- tok = request.cookies.get("auriga_tok")
+ tok = request.cookies.get("dark0rbits_tok")
if not tok: return None
con = db()
s = con.execute("SELECT user_id FROM sessions WHERE token=?", (tok,)).fetchone()
@@ -1296,7 +1459,7 @@ def inbox():
tok = secrets.token_urlsafe(24)
con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, con.execute("SELECT id FROM users WHERE username=?", (u,)).fetchone()["id"], int(time.time())))
con.commit()
- resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True)
+ resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True)
return resp
elif action == "login":
u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or ""
@@ -1305,12 +1468,12 @@ def inbox():
tok = secrets.token_urlsafe(24)
con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, r["id"], int(time.time())))
con.commit()
- resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True)
+ resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True)
return resp
return page("inbox", "
INBOX
bad login
")
elif action == "logout":
- con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("auriga_tok"),)); con.commit()
- resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", "", max_age=0)
+ con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("dark0rbits_tok"),)); con.commit()
+ resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", "", max_age=0)
return resp
elif action == "send" and uid:
body = (request.form.get("body") or "").strip()[:4000]
@@ -1410,9 +1573,9 @@ def tools():
def admin():
if request.method == "POST" and request.form.get("pw") == ADMIN_PW:
resp = Response(status=302); resp.headers["Location"] = "/admin"
- resp.set_cookie("auriga_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True)
+ resp.set_cookie("dark0rbits_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True)
return resp
- if not request.cookies.get("auriga_admin"):
+ if not request.cookies.get("dark0rbits_admin"):
return page("ip", '
OPERATOR
')
con = db()
msgs = con.execute("SELECT m.*, u.username FROM messages m JOIN users u ON u.id=m.user_id ORDER BY m.id DESC LIMIT 100").fetchall()
@@ -1424,38 +1587,59 @@ def admin():
All customer messages{msgs_html}
File open events
File
IP
Device
When
{opens_html}
""")
-# ---------- INDEX ----------
+# ---------- INDEX (hacker landing) ----------
@app.route("/")
def index():
ip = request.headers.get("X-Real-IP") or request.remote_addr
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
d = jf(b) or {}
+ uid = current_user_id()
con = db()
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"]
n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"]
+ tools = [
+ ("ip","IP INTEL","Geo, ASN, ISP, VPN/hosting flags, rDNS — your IP auto-detected, any target on demand."),
+ ("card","CARD CHECK","Luhn + BIN: issuer bank, brand, type, country, prepaid risk flags. Nothing stored, nothing charged."),
+ ("sms","SMS RENTAL","Disposable numbers, 30-min windows, instant refund on cancel."),
+ ("proxy","PROXY LAB","Residential egress testing on the Pleiades rail — same gateway keys fleet-wide. Rent GB plans at the storefront."),
+ ("steg","STEGO LAB","Hide words inside pictures. LSB depth, randomized spread, password-encrypted payloads."),
+ ("track","TRACK FILE","$1 → tracked link + email pixel. Every open reports back: IP, location, ISP, device."),
+ ("mail","BURNER MAIL","Receive-only mailboxes, 7–90 days, live countdown. Codes & confirmations without an identity."),
+ ("eh","MAIL FORENSICS","Paste raw headers → real origin IP + geo, SPF/DKIM/DMARC verdicts, spoof flags."),
+ ("forensics","IMAGE FORENSICS","EXIF, GPS, edit-tool detection, error-level analysis — expose doctored photos."),
+ ("canary","CANARY TRAPS","Tripwire links and pixels — instant alert the moment anyone touches one."),
+ ("tools","FREE TOOLS","DNS resolver, HTTP header inspector, JWT decoder, hasher, generators."),
+ ("passport","AGENT PASSPORT","Machine-readable trust badge for your bots. Agents are first-class here."),
+ ]
+ cards = "".join(f'
' for href, name, desc in tools)
+ stat = f"You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))} · {esc(d.get('isp',''))}"
+ cta = ('' if uid else '')
body = f"""
-
AURIGA TOOLBOX
-
One page. Every network weapon you actually use. You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))}.
-
-
◈ IP Intel
Geo, ASN, ISP, VPN flags, rDNS — auto for you, any target on demand.
Real origin, SPF/DKIM/DMARC verdicts, spoof flags.
-
◈ Image Forensics
EXIF + GPS + ELA — expose edits and hidden stego.
-
◈ Canary Traps
Tripwire links & pixels — instant alerts when touched.
-
◈ Agent Passport
Machine-readable trust badge for agents.
-
◈ Free Tools
DNS, headers, JWT, hasher, generators.
-
"""
+
$ ./dark0rbits --intro▊
+DARK0RBITS — the toolbox that treats you like an operator, not a product.
+No KYC. No email required. No Stripe. BTC only. Agents welcome.
+{stat}
+