From 035b145f64c74aa76455b758b636e18dea262b9e Mon Sep 17 00:00:00 2001 From: drjones Date: Wed, 30 Sep 2026 16:55:31 -0700 Subject: [PATCH] =?UTF-8?q?REBRAND:=20Dark0rbits=20=E2=80=94=20billing=20e?= =?UTF-8?q?ngine=20(balances,=20dk=5F=20API=20keys,=20per-call=20metering,?= =?UTF-8?q?=20BTC=20topups=20idempotent),=20hacker=20landing,=20per-tool?= =?UTF-8?q?=20explainers,=20SEO=20kit=20(meta/sitemap/robots),=20auriga?= =?UTF-8?q?=E2=86=92dark0rbits=20301?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app.py | 326 ++++++++++++++++++++++++++++++++++++++++++++------------- 1 file changed, 255 insertions(+), 71 deletions(-) diff --git a/app.py b/app.py index 7c6413e..8b77836 100644 --- a/app.py +++ b/app.py @@ -1,13 +1,14 @@ #!/usr/bin/env python3 -"""AURIGA v2 — toolbox: IP intel, card validator, SMS rentals, proxy lab, stego lab, +"""Dark0rbits v2 — toolbox: IP intel, card validator, SMS rentals, proxy lab, stego lab, trackable files (BTCPay), no-KYC site-only messaging inbox. Single-file Flask + SQLite.""" import base64, binascii, hashlib, hmac, html, io, json, os, re, secrets, socket, sqlite3, struct, time, uuid import urllib.request, urllib.parse from flask import Flask, request, jsonify, render_template_string, Response, send_file +from flask import redirect app = Flask(__name__) -DB_PATH = os.environ.get("AURIGA_DB", "/opt/auriga/auriga.db") -UPLOAD_DIR = os.environ.get("AURIGA_UPLOADS", "/opt/auriga/uploads") +DB_PATH = os.environ.get("DARK0RBITS_DB", "/opt/dark0rbits/dark0rbits.db") +UPLOAD_DIR = os.environ.get("DARK0RBITS_UPLOADS", "/opt/dark0rbits/uploads") os.makedirs(UPLOAD_DIR, exist_ok=True) SMSP_KEY = os.environ.get("SMSP_KEY", "") PLEIADES_GW = os.environ.get("PLEIADES_GW", "10.30.20.178:8080") @@ -16,10 +17,10 @@ BTCPAY = "https://10.30.20.140/api/v1" BTCPAY_KEY = os.environ.get("BTCPAY_KEY", "6026288e2e315984661c748baafd509e81a75f22") BTCPAY_STORE = os.environ.get("BTCPAY_STORE", "7h79ndYyZX2yF6CPa12xt2uVGQ5Fd6nrSDG4Koy86x6u") WEBCHECK = os.environ.get("WEBCHECK", "http://10.30.20.13:3000") -ADMIN_PW = os.environ.get("AURIGA_ADMIN", "Czapiewski1!") +ADMIN_PW = os.environ.get("DARK0RBITS_ADMIN", "Czapiewski1!") BTCPAY_WHSEC = os.environ.get("BTCPAY_WHSEC", "TgJhmoBcNf9ATK2SFCg1VS") BMAC = "https://buymeacoffee.com/r26xrthzttg" -SITE = "https://auriga.thetempleofdoom.com" +SITE = "https://dark0rbits.thetempleofdoom.com" def db(): con = sqlite3.connect(DB_PATH); con.row_factory = sqlite3.Row @@ -34,16 +35,54 @@ def db(): CREATE TABLE IF NOT EXISTS mails(id INTEGER PRIMARY KEY, mailbox_id INTEGER, sender TEXT, subject TEXT, body TEXT, ts INTEGER); CREATE TABLE IF NOT EXISTS passes(id INTEGER PRIMARY KEY, user_id INTEGER, invoice_id TEXT, paid INTEGER DEFAULT 0, expires INTEGER DEFAULT 0, plan_days INTEGER DEFAULT 30); CREATE TABLE IF NOT EXISTS canaries(id INTEGER PRIMARY KEY, user_id INTEGER, token TEXT UNIQUE, tag TEXT, created INTEGER, armed INTEGER DEFAULT 1); - CREATE TABLE IF NOT EXISTS canary_hits(id INTEGER PRIMARY KEY, canary_id INTEGER, ts INTEGER, ip TEXT, ua TEXT);""") + CREATE TABLE IF NOT EXISTS canary_hits(id INTEGER PRIMARY KEY, canary_id INTEGER, ts INTEGER, ip TEXT, ua TEXT); + CREATE TABLE IF NOT EXISTS balances(user_id INTEGER PRIMARY KEY, cents INTEGER DEFAULT 0); + CREATE TABLE IF NOT EXISTS apikeys(id INTEGER PRIMARY KEY, user_id INTEGER, key TEXT UNIQUE, label TEXT, created INTEGER, revoked INTEGER DEFAULT 0); + CREATE TABLE IF NOT EXISTS ledger(id INTEGER PRIMARY KEY, user_id INTEGER, delta_cents INTEGER, reason TEXT, ts INTEGER); + CREATE TABLE IF NOT EXISTS wh_processed(invoice_id TEXT PRIMARY KEY, ts INTEGER);""") return con +# ---------- BILLING CORE (per-call metering for outside users) ---------- +def get_balance(uid): + con = db() + con.execute("INSERT OR IGNORE INTO balances(user_id, cents) VALUES(?, 100)", (uid,)) # $1 free trial credit + con.commit() + return con.execute("SELECT cents FROM balances WHERE user_id=?", (uid,)).fetchone()["cents"] + +def charge(uid, cents, reason): + """Deduct from balance; return False if insufficient.""" + if cents <= 0: return True + if get_balance(uid) < cents: return False + con = db() + con.execute("UPDATE balances SET cents = cents - ? WHERE user_id=?", (cents, uid)) + con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, -cents, reason, int(time.time()))) + con.commit() + return True + +def key_user(): + """API-key auth: Authorization: Bearer dk_... → user_id or None.""" + auth = request.headers.get("Authorization", "") + if not auth.startswith("Bearer dk_"): return None + con = db() + r = con.execute("SELECT user_id FROM apikeys WHERE key=? AND revoked=0", (auth[7:],)).fetchone() + return r["user_id"] if r else None + +def require_paid_key(cents, reason): + """For API calls: key or session auth; metered charge. Returns (uid, error_json).""" + uid = key_user() or current_user_id() + if not uid: return None, (jsonify({"ok": False, "error": "auth required: account session or Authorization: Bearer dk_… key"}), 401) + if has_pass(uid): return uid, None # PASS = unlimited tools (proxy excluded) + if not charge(uid, cents, reason): + return None, (jsonify({"ok": False, "error": "insufficient balance", "balance_cents": get_balance(uid), "topup": SITE + "/keys"}), 402) + return uid, None + import ssl as _ssl _CTX = _ssl.create_default_context() _CTX.check_hostname = False _CTX.verify_mode = _ssl.CERT_NONE def http(url, headers=None, data=None, method="GET", timeout=12): - h = {"User-Agent": "Mozilla/5.0 (Auriga toolbox)"} + h = {"User-Agent": "Mozilla/5.0 (Dark0rbits toolbox)"} h.update(headers or {}) req = urllib.request.Request(url, headers=h, data=data, method=method) try: @@ -64,7 +103,15 @@ def param(name): def esc(s): return html.escape(str(s)) BASE = """ -AURIGA — Toolbox +DARK0RBITS — No-KYC Network Toolbox: IP Intel, Stego, Burner Mail, SMS Rentals, Proxy Lab + + + + + + + +
{{body}}
@@ -123,9 +174,13 @@ def kv(pairs): rows = "".join(f"
{k}
{v}
" for k, v in pairs) return f'
{rows}
' +def how(steps): + lis = "".join(f"
  • {esc(s)}
  • " for s in steps) + return f'
    HOW IT WORKS
      {lis}
    ' + # ---------- AGENT DISCOVERY ---------- API_INDEX = { - "service": "AURIGA toolbox", + "service": "dark0rbits", "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.", "endpoints": [ {"method": "GET", "path": "/api/ip?target=", "desc": "Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS."}, @@ -149,22 +204,29 @@ API_INDEX = { def api_index(): return jsonify(API_INDEX) @app.route("/robots.txt") -def robots(): return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"} +def robots(): return "User-agent: *\nAllow: /\nSitemap: https://dark0rbits.thetempleofdoom.com/sitemap.xml\n", 200, {"Content-Type": "text/plain"} + +@app.route("/sitemap.xml") +def sitemap(): + S = "https://dark0rbits.thetempleofdoom.com" + pages = ["", "ip", "card", "sms", "proxy", "steg", "track", "eh", "forensics", "canary", "mail", "inbox", "passport", "pass", "keys", "tools"] + xml = '' + "".join(f"{S}/{p}weekly" for p in pages) + "" + return xml, 200, {"Content-Type": "application/xml"} @app.route("/llms.txt") def llms(): eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']}" for e in API_INDEX["endpoints"]) - return f"# AURIGA toolbox\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"} + return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"} @app.route("/ai-plugin.json") def aiplugin(): - return jsonify({"name_for_model": "auriga", "schema_version": "v1", + return jsonify({"name_for_model": "dark0rbits", "schema_version": "v1", "description_for_model": "IP intelligence, card BIN validation, SMS number rentals, proxy egress testing, LSB steganography, trackable file links with open-notifications, no-KYC site messaging.", "api": {"type": "openapi", "url": SITE + "/openapi.json"}, "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"}) @app.route("/openapi.json") def openapi(): - ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "2.0.0"}, "paths": {}} + ps = {"openapi": "3.0.0", "info": {"title": "DARK0RBITS", "version": "2.0.0"}, "paths": {}} def add(path, method, desc, params=None, req=False, files=None): item = {"summary": desc} if files: @@ -233,7 +295,7 @@ def ip_page(): {kv(rows)}
    {extra} -
    API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
    """ +
    API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
    """ + how(["Your IP is auto-detected the moment the page loads — no input needed.","Type any other IP or hostname into the field for the same full report.","Everything is one GET away for agents: /api/ip and /api/ip?target=.","VPN/proxy/hosting flags come from IP-quality heuristics — if it says proxy, you are looking at a relay."]) return page("ip", body) def ip_form(): @@ -302,7 +364,7 @@ def card(): result = f""" {kv([("Brand",brand),("BIN",num[:8]),("Bank / Issuer",esc(bank)),("Country",esc(country)),("Type",str(ctype)),("Prepaid",str(prepaid))])}
    Fraud & structure flags
    {' '.join(tags)}{'
    ⚠ ' + ' · '.join(flags) if flags else ''}
    -
    Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.
    """ +
    Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.
    """ + how(["Paste the card number — it never leaves the request, nothing is stored.","Luhn checksum validates the digit structure instantly.","BIN (first 8 digits) reveals the issuer bank, brand, card type and country.","Prepaid BINs get flagged — merchants commonly reject them.","This CANNOT show balance or fraud-hold status; only the issuer knows that."]) body = f"""

    CARD CHECK

    Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.

    @@ -405,13 +467,16 @@ def sms(): setInterval(function(){{var els=document.querySelectorAll('.cdown');var now=Math.floor(Date.now()/1000); els.forEach(function(e){{var s=e.dataset.exp-now;if(s>0)e.textContent=Math.floor(s/60)+'m '+(s%60)+'s left';else e.textContent='expired'}});}},1000); -
    API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
    """ +
    API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
    """ + how(["Pick a service and country, rent — the number is live for 30 minutes exactly.","Use it for any signup/verification. The code arrives as a text.","Poll the order (auto or manual) until the code shows.","Cancel before a code arrives and you get every satoshi back.","Each rental is logged in the recent-rentals table with a live countdown."]) return page("sms", body) @app.route("/api/sms/rent", methods=["POST"]) def api_sms_rent(): guard = sms_guard() if guard: return jsonify({"success": 0, "message": guard, "paused": True}) + uid = key_user() or current_user_id() + if uid and not has_pass(uid) and get_balance(uid) < 50: + return jsonify({"ok": False, "error": "insufficient balance", "topup": SITE + "/keys"}), 402 st, b = sms_api("purchase/sms", service=param("service"), country=param("country")) d = jf(b) or {} if d.get("success") == 1: @@ -419,6 +484,9 @@ def api_sms_rent(): con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)", (d.get("number"), param("service"), param("country"), str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800)) con.commit() + cost = int(d.get("cost_in_cents") or 5) + if uid and not has_pass(uid): + charge(uid, cost, f"sms rental +{d.get('number')}") return jsonify(d) @app.route("/api/sms/check", methods=["GET","POST"]) @@ -485,7 +553,7 @@ def proxy():
    yourpassword
    Rent more — storefront: {PLEIADES_APP}
    -
    API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
    """ +
    API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
    """ + how(["Enter your Pleiades gateway user:pass — the same credentials work across the fleet.","The lab tunnels a CONNECT request through the gateway and reports the true egress IP, geo and ISP.","Use the geo builder to steer the exit: region, country, city, sticky 30-min sessions.","Need bandwidth? Buy GB plans at the Pleiades storefront."]) return page("proxy", body) @app.route("/api/proxy/test", methods=["POST"]) @@ -534,7 +602,7 @@ def steg_hide(img_bytes, text, password="", bits=1, spread="sequential"): return None, f"too big: need {len(data)*8} bits, image holds {capacity}" if spread == "random": import random as _r - _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big")) + _r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big")) order = list(range(w*h)); _r.shuffle(order) else: order = list(range(w*h)) @@ -566,7 +634,7 @@ def _pnginfo(bits, spread): try: from PIL.PngImagePlugin import PngInfo info = PngInfo() - info.add_text("auriga_meta", json.dumps({"bits": bits, "spread": spread, "v": 2})) + info.add_text("dark0rbits_meta", json.dumps({"bits": bits, "spread": spread, "v": 2})) return info except Exception: return None @@ -574,7 +642,7 @@ def _pnginfo(bits, spread): def steg_extract(img_bytes, password="", bits=None, spread=None): from PIL import Image im = Image.open(io.BytesIO(img_bytes)) - meta = im.info.get("auriga_meta") + meta = im.info.get("dark0rbits_meta") or im.info.get("auriga_meta") if meta: try: m = json.loads(meta) @@ -588,7 +656,7 @@ def steg_extract(img_bytes, password="", bits=None, spread=None): # replicate the shuffle used at hide time if spread == "random": import random as _r - _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big")) + _r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big")) order = list(range(w*h)); _r.shuffle(order) else: order = list(range(w*h)) @@ -610,13 +678,13 @@ def steg_extract(img_bytes, password="", bits=None, spread=None): if need is not None and idx >= need: break if need is None and idx >= 64: if bytes(raw[:4]) != b"AUR1": - return None, f"no AURIGA payload found with LSB depth {bits} (try other depth / randomized)" + return None, f"no DARK0RBITS payload found with LSB depth {bits} (try other depth / randomized)" ln = struct.unpack(">I", bytes(raw[4:8]))[0] need = 64 + ln * 8 data = bytes(raw) if len(data) < 12: return None, "payload too small" if bytes(data[:4]) != b"AUR1": - return None, "no AURIGA payload found (wrong password or settings?)" + return None, "no DARK0RBITS payload found (wrong password or settings?)" if password and hashlib.sha256(password.encode()).digest()[:4] != data[8:12]: return None, "wrong password" ln = struct.unpack(">I", data[4:8])[0] @@ -663,7 +731,7 @@ d.addEventListener('change',function(){{}}); document.getElementById('ih').addEventListener('change',function(){{document.querySelector('.fnh').textContent=this.files[0].name}}); document.getElementById('ie').addEventListener('change',function(){{document.querySelector('.fne').textContent=this.files[0].name}}); -
    API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
    """ +
    API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
    """ + how(["Drop a PNG — your words are written into the least-significant bits of its pixels.","Depth 1 = invisible and robust; depth 2-3 fits more text but is easier to detect.","Spread=randomized scatters bits across the image instead of top-down.","A password encrypts the payload AND derives the scatter pattern — wrong password = noise.","Extract reads the embedded metadata automatically — just drop the file and the words come back."]) return page("steg", body) @app.route("/api/steg/hide", methods=["POST"]) @@ -678,7 +746,7 @@ def api_steg_hide(): except Exception as e: return jsonify({"ok": False, "error": str(e)}), 400 if out is None: return jsonify({"ok": False, "error": meta}), 400 - return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="auriga-hidden.png") + return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="dark0rbits-hidden.png") @app.route("/api/steg/extract", methods=["POST"]) def api_steg_extract(): @@ -712,19 +780,19 @@ def track():
    BTCPay BTC only. After payment the upload opens automatically.
    {mine}
    How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. Login (no KYC) to see events.
    -
    API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
    """ +
    API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
    """ + how(["Pay $1 in BTC — the invoice settles and unlocks the upload instantly.","Upload your file or picture: you get a secret tracked link plus an email-ready HTML copy.","Email the HTML copy or share the link — every open fires back.","Each open reports: exact time, real IP, city/country, ISP, timezone, VPN flag, device, language, referrer.","Alerts land in your INBOX the second it happens."]) return page("track", body) def btc_invoice(amount="1.00"): st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices", headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"}, - data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "auriga-track"}}).encode(), method="POST") + data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "dark0rbits-track"}}).encode(), method="POST") return jf(b) or {} @app.route("/api/track/create", methods=["POST"]) def api_track_create(): fn = param("filename") or "file" - uid = current_user_id() + uid = key_user() or current_user_id() token = secrets.token_urlsafe(16) con = db() if has_pass(uid): @@ -732,6 +800,11 @@ def api_track_create(): (uid or 0, token, esc(fn[:100]), "file", "PASS", int(time.time()))) con.commit() return jsonify({"ok": True, "free": True, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"}) + if uid and charge(uid, 100, f"trackable file ({fn[:40]})"): + con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)", + (uid or 0, token, esc(fn[:100]), "file", "BALANCE", int(time.time()))) + con.commit() + return jsonify({"ok": True, "balance_charged": 1.00, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"}) inv = btc_invoice() if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)", @@ -762,7 +835,7 @@ def api_track_upload(): con = db() t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() if not t: return jsonify({"ok": False, "error": "unknown token"}), 400 - st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] != "PASS" else (200, '{"status":"settled"}') + st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] not in ("PASS", "BALANCE") else (200, '{"status":"settled"}') inv = jf(b) or {} paid = inv.get("status") in ("settled", "processing", "paid") if not paid: return jsonify({"ok": False, "error": f"invoice not paid yet ({inv.get('status')})"}), 402 @@ -861,7 +934,7 @@ def api_track_events(): MAIL_PACKS = [("7","7 days — $3",3,7),("30","30 days — $8",8,30),("90","90 days — $20",20,90)] MAIL_DOMAIN = "thetempleofdoom.com" MAIL_RESERVED = {"indianaholmes","admin","operator","drjones","root","noreply","support","pass","mail"} -MAIL_SECRET = "auriga-mail-relay-2026" +MAIL_SECRET = "dark0rbits-mail-relay-2026" @app.route("/mail", methods=["GET"]) def mail(): @@ -881,7 +954,7 @@ def mail(): {''.join(f'
    ' for d,n,_,_ in MAIL_PACKS)}
    Type your desired mailbox name, pick a length, pay the invoice — the mailbox activates the moment the payment settles.
    {mine} -
    API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
    """ +
    API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
    """ + how(["Pick a name and a package — 7, 30 or 90 days, BTC priced.","Pay the invoice; the mailbox activates the second it settles.","The address is receive-only: verification codes, confirmations, one-off handouts.","The countdown runs in real time; when it hits zero the mailbox retires itself.","All mail shows on the site inbox — nothing touches any other identity."]) return page("steg", body) @app.route("/api/mail/create", methods=["POST"]) @@ -897,6 +970,18 @@ def api_mail_create(): con = db() if con.execute("SELECT 1 FROM mailboxes WHERE address=?", (addr,)).fetchone(): return jsonify({"ok": False, "error": "mailbox name taken"}), 400 + uid = key_user() or current_user_id() + # metered: PASS = instant free; balance = instant paid; else BTC invoice + if uid and has_pass(uid): + con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)", + (uid, addr, "PASS", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3])) + con.commit() + return jsonify({"ok": True, "free": True, "address": addr, "expires_in_days": pack[3]}) + if uid and charge(uid, pack[2]*100, f"burner mailbox {addr} ({pack[3]}d)"): + con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)", + (uid, addr, "BALANCE", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3])) + con.commit() + return jsonify({"ok": True, "balance_charged": pack[2], "address": addr, "expires_in_days": pack[3]}) inv = btc_invoice(f"{pack[2]:.2f}") if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)", @@ -995,9 +1080,13 @@ def btcpay_webhook(): expect = "sha256=" + hmac.new(BTCPAY_WHSEC.encode(), body, hashlib.sha256).hexdigest() if sig != expect: return jsonify({"ok": False, "error": "bad sig"}), 400 d = jf(body) or {} + iid = d.get("invoiceId") or "" if d.get("type") == "InvoiceSettled" or (d.get("type") == "InvoicePaymentSettled"): - iid = d.get("invoiceId") con = db() + if iid: + if con.execute("SELECT 1 FROM wh_processed WHERE invoice_id=?", (iid,)).fetchone(): + return jsonify({"ok": True, "dup": True}) + con.execute("INSERT OR IGNORE INTO wh_processed(invoice_id,ts) VALUES(?,?)", (iid, int(time.time()))) con.execute("UPDATE trackables SET paid=1 WHERE invoice_id=?", (iid,)) r = con.execute("SELECT plan_days FROM mailboxes WHERE invoice_id=?", (iid,)).fetchone() if r: @@ -1005,9 +1094,83 @@ def btcpay_webhook(): r = con.execute("SELECT plan_days FROM passes WHERE invoice_id=?", (iid,)).fetchone() if r: con.execute("UPDATE passes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 30), iid)) + # balance top-ups + try: + meta = d.get("metadata") or {} + if not meta: + st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{iid}", headers={"Authorization": "token " + BTCPAY_KEY}) + meta = (jf(b) or {}).get("metadata", {}) or {} + if str(meta.get("orderId", "")).startswith("dark0rbits-topup"): + uid = int(meta["orderId"].split(":")[1]); cents = int(meta["orderId"].split(":")[2]) + con.execute("INSERT OR IGNORE INTO balances(user_id, cents) VALUES(?, 0)", (uid,)) + con.execute("UPDATE balances SET cents = cents + ? WHERE user_id=?", (cents, uid)) + con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, cents, f"BTC topup {iid}", int(time.time()))) + except Exception: pass con.commit() return jsonify({"ok": True}) +# ---------- 6h. API KEYS + BALANCE ---------- +@app.route("/keys", methods=["GET", "POST"]) +def keys(): + uid = current_user_id() + if not uid: + return page("inbox", '

    API KEYS

    login on /inbox first — keys are bound to your account.
    ') + con = db() + if request.method == "POST" and request.form.get("act") == "mkkey": + label = (param("label") or "default")[:40] + key = "dk_" + secrets.token_urlsafe(24) + con.execute("INSERT INTO apikeys(user_id,key,label,created) VALUES(?,?,?,?)", (uid, key, esc(label), int(time.time()))) + con.commit() + newkey = key + else: + newkey = None + rows = con.execute("SELECT * FROM apikeys WHERE user_id=? AND revoked=0 ORDER BY id DESC", (uid,)).fetchall() + bal = get_balance(uid) + led = con.execute("SELECT * FROM ledger WHERE user_id=? ORDER BY id DESC LIMIT 15", (uid,)).fetchall() + led_html = "".join(f"{'$%.2f' % (l['delta_cents']/100)}{esc(l['reason'])}{time.strftime('%b %d %H:%M', time.localtime(l['ts']))}" for l in led) + keys_html = "".join(""+esc(k['key'][:14])+"… copy"+esc(k['label'])+""+time.strftime('%b %d', time.localtime(k['created']))+"" for k in rows) + newkey_block = ('
    NEW KEY (shown once)
    '+esc(newkey)+'
    ') if newkey else '' + keys_block = ('
    Keys'+keys_html+'
    KeyLabelCreated
    ') if rows else '' + body = f""" +

    API KEYS — balance: ${bal/100:.2f}

    +

    Metered access for agents and humans. Every paid call deducts from your balance. $1 free trial credit on signup. No KYC, BTC top-ups only.

    +
    +
    New API key
    +{newkey_block} +{keys_block} +
    +
    Top up (BTC) +{''.join(f'
    ' for c,a in [(500,'$5'),(2000,'$20'),(10000,'$100')])} +
    Invoice settles → balance credited automatically via webhook.
    +
    +
    Ledger{led_html or ''}
    ΔReasonWhen
    no charges yet
    +
    Use it: Authorization: Bearer dk_… header on any paid API call. Metered endpoints: /api/sms/rent (pass-through cost), /api/mail/create (package price), /api/track/create ($1). Everything else free. PASS = no metering.
    """ + return page("inbox", body) + +@app.route("/api/balance/topup", methods=["POST"]) +def api_balance_topup(): + uid = current_user_id() + if not uid: return jsonify({"ok": False, "error": "login required"}), 401 + cents = int(param("cents") or 500) + if cents not in (500, 2000, 10000): return jsonify({"ok": False, "error": "bad amount"}), 400 + # invoice created WITH topup metadata in one shot + st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices", + headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"}, + data=json.dumps({"amount": f"{cents/100:.2f}", "currency": "USD", + "metadata": {"orderId": f"dark0rbits-topup:{uid}:{cents}", "itemDesc": "dark0rbits balance topup"}}).encode(), method="POST") + inv = jf(b) or {} + if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 + con = db() + con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, 0, f"topup invoice {inv['id']} pending", int(time.time()))) + con.commit() + return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink")}) + +@app.route("/api/balance") +def api_balance(): + uid = key_user() or current_user_id() + if not uid: return jsonify({"ok": False, "error": "auth required"}), 401 + return jsonify({"ok": True, "balance_cents": get_balance(uid), "pass_active": has_pass(uid)}) + # ---------- 6d. EMAIL HEADER FORENSICS ---------- def parse_headers(raw): import email as em @@ -1060,7 +1223,7 @@ def eh():

    EMAIL FORENSICS

    Paste full raw email headers (View source → copy all) — get the real origin, SPF/DKIM/DMARC verdicts, and spoof flags.

    -
    API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.
    """ +
    API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.
    """ + how(["Open the suspicious email → View source → copy ALL headers.","Paste them here — the parser walks the full Received chain.","The real origin IP is pulled from the bottom-most relay hop and geolocated.","SPF/DKIM/DMARC verdicts are extracted and color-coded.","Spoof markers are flagged automatically: envelope≠From domain, Reply-To hijacks."]) return page("tools", body) @app.route("/eh_result", methods=["POST"]) @@ -1091,7 +1254,7 @@ def forensics():
    -
    API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.
    """ +
    API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.
    """ + how(["Drop any image — EXIF and GPS get dumped instantly.","Error-level analysis (ELA) re-compresses and diffs: edited regions glow in the amplified view.","Edit-tool tags (Photoshop/GIMP) are flagged automatically.","EXIF-stripped images get flagged too — usually means scrubbed or generated.","If the image carries a DARK0RBITS stego payload, this tool sees it."]) return page("steg", body) def _ela_score(img_bytes): @@ -1136,7 +1299,7 @@ def forensics_result(): for k, v in rows: if "software" in k.lower(): flags.append(f"software: {v}") if "Photoshop" in v or "GIMP" in v: flags.append(f"⚠ EDITED IN {v}") - stego = "auriga_meta" in im.info + stego = ("auriga_meta" in im.info or "dark0rbits_meta" in im.info) ela_png, maxdiff = _ela_score(data) fn = (f.filename or "image")[:60] verdict = "CLEAN-ISH" if maxdiff < 12 and not flags else "SUSPECT — check ELA" @@ -1146,7 +1309,7 @@ def forensics_result(): ela_b64 = b64mod.b64encode(ela_png).decode() return page("steg", f"""

    FORENSICS {esc(fn)}

    -{kv([("Verdict", f'{verdict}'), ("ELA max diff", f"{maxdiff} (low=uniform=re-saved clean)"), ("EXIF", f"{len(rows)} tags"), ("Stego", "AURIGA payload present ✓" if stego else "none detected")])} +{kv([("Verdict", f'{verdict}'), ("ELA max diff", f"{maxdiff} (low=uniform=re-saved clean)"), ("EXIF", f"{len(rows)} tags"), ("Stego", "DARK0RBITS payload present ✓" if stego else "none detected")])}
    Flags
    {'
    '.join(esc(x) for x in flags) or 'none'}
    ELA (amplified 15×)
    full PNG
    EXIF table{rows_html or ''}
    no EXIF
    @@ -1170,7 +1333,7 @@ def api_forensics(): except Exception: pass _, maxdiff = _ela_score(data) return jsonify({"ok": True, "exif": ex, "gps_present": bool(exif.get_ifd(0x8825)) if hasattr(exif, "get_ifd") else False, - "stego_auriga": "auriga_meta" in im.info, "ela_max_diff": maxdiff, + "stego_auriga": ("auriga_meta" in im.info or "dark0rbits_meta" in im.info), "ela_max_diff": maxdiff, "flags": (["exif-stripped"] if not ex else [])}) # ---------- 6f. CANARY TRAPS ---------- @@ -1184,7 +1347,7 @@ def canary():
    You get: a link (paste anywhere), a pixel URL (embed in docs/pages), and a fake credential line to drop in files.
    {canary_list()} -
    API: POST /canary (tag) · GET /api/canary/list (login) · hits log like trackables.
    """ +
    API: POST /canary (tag) · GET /api/canary/list (login) · hits log like trackables.
    """ + how(["Create a trap and tag it with who/where it belongs.","Plant the link anywhere — or embed the pixel URL, or drop the fake credential line.","The moment ANYONE touches it: IP, geo, ISP, device fire into your inbox.","Each trap shows its hit count and armed/triggered status.","One trap per place — re-plant after it fires."]) return page("track", body) def canary_list(): @@ -1252,10 +1415,10 @@ def passport(): n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > (strftime('%s','now')-2592000)", ).fetchone()["c"] pas = has_pass(uid) badge = {"holder": u["username"], "issued": u["created"], "pass_active": pas, - "tool_usage_30d": {"sms_rentals": n_sms}, "site": "auriga.thetempleofdoom.com", "v": 1, + "tool_usage_30d": {"sms_rentals": n_sms}, "site": "dark0rbits.thetempleofdoom.com", "v": 1, "principles": ["no-KYC", "BTC-only", "agent-friendly"]} body = f""" -

    AGENT PASSPORT

    Machine-readable identity + trust badge for agents operating on AURIGA.

    +

    AGENT PASSPORT

    Machine-readable identity + trust badge for agents operating on DARK0RBITS.

    {kv([("Holder", esc(u['username'])), ("Issued", time.strftime("%b %d %Y", time.localtime(u["created"]))), ("PASS", "ACTIVE ✓" if pas else "none"), ("SMS rentals (30d)", n_sms)])}
    Badge JSON
    {json.dumps(badge, indent=1)}
    API: GET /api/passport (cookie auth) → badge JSON. Embed in your agent's llms.txt / tool card.
    """ @@ -1267,13 +1430,13 @@ def api_passport(): if not uid: return jsonify({"ok": False, "error": "login required"}) con = db() u = con.execute("SELECT * FROM users WHERE id=?", (uid,)).fetchone() - return jsonify({"holder": u["username"], "issued": u["created"], "pass_active": has_pass(uid), "site": "auriga.thetempleofdoom.com"}) + return jsonify({"holder": u["username"], "issued": u["created"], "pass_active": has_pass(uid), "site": "dark0rbits.thetempleofdoom.com"}) # ---------- 7. INBOX (no-KYC site-only messaging) ---------- -def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"auriga-salt", n=16384, r=8, p=1).hex() +def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"dark0rbits-salt", n=16384, r=8, p=1).hex() def current_user_id(): - tok = request.cookies.get("auriga_tok") + tok = request.cookies.get("dark0rbits_tok") if not tok: return None con = db() s = con.execute("SELECT user_id FROM sessions WHERE token=?", (tok,)).fetchone() @@ -1296,7 +1459,7 @@ def inbox(): tok = secrets.token_urlsafe(24) con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, con.execute("SELECT id FROM users WHERE username=?", (u,)).fetchone()["id"], int(time.time()))) con.commit() - resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True) + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) return resp elif action == "login": u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or "" @@ -1305,12 +1468,12 @@ def inbox(): tok = secrets.token_urlsafe(24) con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, r["id"], int(time.time()))) con.commit() - resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True) + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) return resp return page("inbox", "

    INBOX

    bad login
    ") elif action == "logout": - con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("auriga_tok"),)); con.commit() - resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", "", max_age=0) + con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("dark0rbits_tok"),)); con.commit() + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", "", max_age=0) return resp elif action == "send" and uid: body = (request.form.get("body") or "").strip()[:4000] @@ -1410,9 +1573,9 @@ def tools(): def admin(): if request.method == "POST" and request.form.get("pw") == ADMIN_PW: resp = Response(status=302); resp.headers["Location"] = "/admin" - resp.set_cookie("auriga_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True) + resp.set_cookie("dark0rbits_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True) return resp - if not request.cookies.get("auriga_admin"): + if not request.cookies.get("dark0rbits_admin"): return page("ip", '

    OPERATOR

    ') con = db() msgs = con.execute("SELECT m.*, u.username FROM messages m JOIN users u ON u.id=m.user_id ORDER BY m.id DESC LIMIT 100").fetchall() @@ -1424,38 +1587,59 @@ def admin():
    All customer messages{msgs_html}
    File open events{opens_html}
    FileIPDeviceWhen
    """) -# ---------- INDEX ---------- +# ---------- INDEX (hacker landing) ---------- @app.route("/") def index(): ip = request.headers.get("X-Real-IP") or request.remote_addr st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719") d = jf(b) or {} + uid = current_user_id() con = db() n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"] n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"] + tools = [ + ("ip","IP INTEL","Geo, ASN, ISP, VPN/hosting flags, rDNS — your IP auto-detected, any target on demand."), + ("card","CARD CHECK","Luhn + BIN: issuer bank, brand, type, country, prepaid risk flags. Nothing stored, nothing charged."), + ("sms","SMS RENTAL","Disposable numbers, 30-min windows, instant refund on cancel."), + ("proxy","PROXY LAB","Residential egress testing on the Pleiades rail — same gateway keys fleet-wide. Rent GB plans at the storefront."), + ("steg","STEGO LAB","Hide words inside pictures. LSB depth, randomized spread, password-encrypted payloads."), + ("track","TRACK FILE","$1 → tracked link + email pixel. Every open reports back: IP, location, ISP, device."), + ("mail","BURNER MAIL","Receive-only mailboxes, 7–90 days, live countdown. Codes & confirmations without an identity."), + ("eh","MAIL FORENSICS","Paste raw headers → real origin IP + geo, SPF/DKIM/DMARC verdicts, spoof flags."), + ("forensics","IMAGE FORENSICS","EXIF, GPS, edit-tool detection, error-level analysis — expose doctored photos."), + ("canary","CANARY TRAPS","Tripwire links and pixels — instant alert the moment anyone touches one."), + ("tools","FREE TOOLS","DNS resolver, HTTP header inspector, JWT decoder, hasher, generators."), + ("passport","AGENT PASSPORT","Machine-readable trust badge for your bots. Agents are first-class here."), + ] + cards = "".join(f'

    ◈ {name}

    {desc}

    ' for href, name, desc in tools) + stat = f"You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))} · {esc(d.get('isp',''))}" + cta = (' ' if uid else ' ') body = f""" -

    AURIGA TOOLBOX

    -

    One page. Every network weapon you actually use. You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))}.

    -
    -

    ◈ IP Intel

    Geo, ASN, ISP, VPN flags, rDNS — auto for you, any target on demand.

    -

    ◈ Card Check

    Luhn + BIN: issuer, brand, type, prepaid risk flags.

    -

    ◈ SMS Rental

    30-min numbers, cancel = refund. {n_sms} served.

    -

    ◈ Proxy Lab

    Same gateway keys as the fleet. {n_px} checks.

    -

    ◈ Stego Lab

    Hide words in pictures. LSB depth, spread, passwords.

    -

    ◈ Track File

    $1 BTC → tracked link + email pixel → opens ping your inbox.

    -

    ◈ Burner Mail

    Receive-only mailboxes, 7d/$3 → 90d/$20, live countdown.

    -

    ◈ PASS

    $10/mo all-access (3mo $25 · 1yr $80) — every tool, proxy rentals excluded.

    -

    ◈ Inbox

    No-KYC site messaging with the operator.

    -

    ◈ Mail Forensics

    Real origin, SPF/DKIM/DMARC verdicts, spoof flags.

    -

    ◈ Image Forensics

    EXIF + GPS + ELA — expose edits and hidden stego.

    -

    ◈ Canary Traps

    Tripwire links & pixels — instant alerts when touched.

    -

    ◈ Agent Passport

    Machine-readable trust badge for agents.

    -

    ◈ Free Tools

    DNS, headers, JWT, hasher, generators.

    -
    """ +
    $ ./dark0rbits --intro▊ +DARK0RBITS — the toolbox that treats you like an operator, not a product. +No KYC. No email required. No Stripe. BTC only. Agents welcome. +{stat} +
    {cta}
    +
    {cards}
    +
    +NO KYC BTC ONLY AGENT-FIRST APIs {n_sms} SMS RENTALS SERVED {n_px} PROXY CHECKS
    +
    +For agents: machine catalog at /llms.txt, OpenAPI at /openapi.json, metered keys at /keys. +For humans: click a card. That's it.
    """ return page("home", body) @app.route("/health") -def health(): return jsonify({"ok": True, "service": "auriga", "version": "2.0"}) +def health(): return jsonify({"ok": True, "service": "dark0rbits", "version": "2.0"}) + + +# REDIRECT legacy auriga hostname → dark0rbits +@app.before_request +def _dr_legacy_redirect(): + host = (request.host or "").lower() + if host.startswith("auriga.") or host == "auriga.thetempleofdoom.com": + return redirect("https://dark0rbits.thetempleofdoom.com" + request.full_path.rstrip("?"), code=301) + return None +# REDACT-REDIRECT if __name__ == "__main__": app.run(host="0.0.0.0", port=5000, threaded=True)