From 30c845cd569a5f9695071751ac2bb09d68a9fbe6 Mon Sep 17 00:00:00 2001 From: drjones Date: Fri, 2 Oct 2026 10:33:06 -0700 Subject: [PATCH] top-right LOG IN/SIGN UP on every page + /signup quick page + GET /logout - page() acct slot now always filled: LOG IN + SIGN UP buttons (logged out), balance chip + EXIT (logged in) - fix: {{acct}} was Jinja-autoescaped to literal text (now Markup) - fix: missing + in chip concat raised inside silent except - chip never rendered - login/register honor ?next= (same-site only); signup wired into hero, drawer, sitemap, openapi, llms.txt - verified E2E: register->\$1 balance->chip->logout; 24 routes 200; visual QA home+signup --- app.py | 408 +++++++++++++++++++++++++++++++++++++++++++++++++++++---- 1 file changed, 380 insertions(+), 28 deletions(-) diff --git a/app.py b/app.py index ded68ce..99f98f6 100644 --- a/app.py +++ b/app.py @@ -223,10 +223,10 @@ BASE = """ +#acct{display:flex;align-items:center;gap:.4rem;white-space:nowrap} +.abtn{display:inline-flex;align-items:center;font-size:.78rem;letter-spacing:.08em;text-decoration:none;border-radius:999px;padding:.42rem .95rem;border:1px solid var(--line);color:var(--dim);transition:.15s;cursor:pointer} +.abtn:hover{color:var(--acc);border-color:var(--acc);box-shadow:0 0 14px -6px var(--acc)} +.abtn.solid{background:linear-gradient(135deg,var(--acc),var(--acc2));color:#0d0722;border-color:transparent;font-weight:800} +.abtn.solid:hover{filter:brightness(1.15);color:#0d0722} +.achip{display:inline-flex;align-items:center;gap:.3rem;font-size:.72rem;color:var(--acc2);text-decoration:none;border:1px solid var(--line);border-radius:999px;padding:.3rem .7rem} +.achip:hover{border-color:var(--acc2)} +
@@ -334,7 +345,7 @@ li{text-align:left;margin:.2rem 0} CANARYDEAD-DROPBURNER-MAIL SHOTFRAUD-SCORE INBOXPASSPORT -PASSKEYSTOOLS +PASSKEYSMAG-LABTOOLS
{{acct}}
@@ -343,6 +354,7 @@ li{text-align:left;margin:.2rem 0}

Intel

◈ IP INTEL geo, ASN, ISP, VPN flags — any target ◈ CARD CHECK luhn + BIN issuer intelligence +◈ MAG-LAB browser magstripe studio — ISO 7811 encode, read, batch issue (closed-loop only) ◈ MAIL FORENSICS origin + SPF/DKIM/DMARC + spoof flags ◈ IMAGE FORENSICS EXIF, GPS, ELA, edit detection

Operate

@@ -359,7 +371,8 @@ li{text-align:left;margin:.2rem 0} ◈ FREE TOOLS DNS, headers, JWT, hasher

Account

◈ INBOX no-KYC messaging -◈ API KEYS metered access, balance +◈ SIGN UP username + password, 10 seconds, no KYC +◈ API KEYS account, balance, metered keys ◈ PASS $10/mo all-access ◈ AGENT PASSPORT machine-readable badge @@ -572,14 +585,19 @@ def page(sec, body): u = con.execute("SELECT username FROM users WHERE id=?", (uid,)).fetchone() bal = get_balance(uid) pas = has_pass(uid) - acct = ('' + - ("★ PASS · " if pas else "") + "$" + f"{bal/100:.2f}" + " · " + esc(u["username"]) + "") + acct = ('' + + ("★ PASS · " if pas else "") + "◈ $" + f"{bal/100:.2f}" + " · " + esc(u["username"]) + "" + + ' EXIT') except Exception: acct = "" + if not uid or not acct: + nxt = ("?next=" + urllib.parse.quote(request.path)) if request.path not in ("/", "/inbox", "/signup", "/logout") else "" + acct = ('LOG IN' + ' SIGN UP') from markupsafe import Markup st = get_settings(uid) return render_template_string(BASE, body=Markup(body), bmac=BMAC, o=lambda s2: "on" if s2 == sec else "", - n1=n1, n2=n2, acct=acct, + n1=n1, n2=n2, acct=Markup(acct), CFG_JS="window.DRB=" + json.dumps(st) + ";") @@ -628,6 +646,7 @@ API_INDEX = { "service": "dark0rbits", "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.", "endpoints": [ + {"method": "GET", "path": "/signup", "desc": "No-KYC signup page (humans): username + password, 4+ chars, ~10 seconds. Agents: POST /inbox form act=register&u=NAME&p=PASS -> session cookie dark0rbits_tok (30 days) + $1 free trial credit."}, {"method": "GET/POST", "path": "/api/settings", "desc": "Per-account UI tunables (bg, warp, parallax, density, speed, twinkle, hue, grid, scan, toast, type). Agents can theme their own client. GET returns current; POST form key=val applies (validated + clamped)."}, {"method": "GET", "path": "/deaddrop", "desc": "Burn-after-read encrypted notes. POST /api/deaddrop/create (body, burn_after 1-10, ttl_hours 1-72, password optional) -> token. 5c, free with PASS."}, {"method": "GET", "path": "/shot", "desc": "Page capture: POST /api/shot/create {url} then GET /api/shot/status/. SSRF-guarded. 25c, free with PASS."}, @@ -681,7 +700,7 @@ INDEXNOW = "a8f3d4rk0rbits9e2b1c7x5k8m2v4q6t8" @app.route("/sitemap.xml") def sitemap(): S = "https://dark0rbits.thetempleofdoom.com" - pages = ["", "ip", "card", "sms", "proxy", "steg", "track", "eh", "forensics", "canary", "deaddrop", "shot", "score", "mail", "inbox", "passport", "pass", "keys", "tools"] + pages = ["", "ip", "card", "sms", "proxy", "steg", "track", "eh", "forensics", "canary", "deaddrop", "shot", "score", "mail", "inbox", "passport", "pass", "keys", "maglab", "tools", "signup"] xml = '' + "".join(f"{S}/{p}weekly" for p in pages) + "" return xml, 200, {"Content-Type": "application/xml"} @@ -694,7 +713,7 @@ def llms(): def aiplugin(): return jsonify({"name_for_model": "dark0rbits", "schema_version": "v1", "description_for_model": "IP intelligence, card BIN validation, SMS number rentals, proxy egress testing, LSB steganography, trackable file links with open-notifications, no-KYC site messaging.", - "api": {"type": "openapi", "url": SITE + "/openapi.json"}, "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"}) + "api": {"type": "openapi", "url": SITE + "/openapi.json"}, "auth": {"type": "none"}, "contact_email": "makemoneys8@proton.me"}) @app.route("/openapi.json") def openapi(): @@ -727,6 +746,7 @@ def openapi(): add("/api/shot/create", "post", "Queue page capture", {"url": "target url"}, req=True) add("/api/shot/status/{id}", "get", "Shot result (png_b64 or text_fallback)") add("/api/score", "get", "Composite fraud score 0-100", {"ip": "opt", "email": "opt", "bin": "opt"}) + add("/signup", "get", "No-KYC signup page (username + password only)") return jsonify(ps) # ---------- 1. IP INTEL (auto + manual target) ---------- @@ -1371,7 +1391,7 @@ def steg_extract(img_bytes, password="", bits=None, spread=None): if bytes(raw[:4]) != b"AUR1": return None, f"no DARK0RBITS payload found with LSB depth {bits} (try other depth / randomized)" ln = struct.unpack(">I", bytes(raw[4:8]))[0] - need = 64 + ln * 8 + need = 96 + ln * 8 # header is 12 bytes (AUR1+len+phash) = 96 bits; old 64 truncated 4 bytes off every payload data = bytes(raw) if len(data) < 12: return None, "payload too small" if bytes(data[:4]) != b"AUR1": @@ -1900,7 +1920,7 @@ def parse_headers(raw): env_from = out["return_path"].strip("<>") frm = out["from"] m_from = re.search(r"<([^>]+)>", frm) - addr_from = (m_from.group(1) if m_from else frm).split()[-1].strip("<>").lower() + addr_from = ((m_from.group(1) if m_from else frm).split() or [""])[-1].strip("<>").lower() if env_from and addr_from and env_from.split("@")[-1] != addr_from.split("@")[-1]: flags.append(f"envelope-from domain ({env_from.split('@')[-1]}) != From domain ({addr_from.split('@')[-1]}) — classic spoof marker") if out["reply_to"]: @@ -2187,7 +2207,9 @@ def inbox(): tok = secrets.token_urlsafe(24) con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, con.execute("SELECT id FROM users WHERE username=?", (u,)).fetchone()["id"], int(time.time()))) con.commit() - resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) + nxt = request.form.get("next") or "/inbox" + if not nxt.startswith("/") or nxt.startswith("//"): nxt = "/inbox" + resp = Response(status=302); resp.headers["Location"] = nxt; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) return resp elif action == "login": u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or "" @@ -2199,7 +2221,9 @@ def inbox(): tok = secrets.token_urlsafe(24) con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, r["id"], int(time.time()))) con.commit() - resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) + nxt = request.form.get("next") or "/inbox" + if not nxt.startswith("/") or nxt.startswith("//"): nxt = "/inbox" + resp = Response(status=302); resp.headers["Location"] = nxt; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True) return resp return page("inbox", "

INBOX

bad login
") elif action == "logout": @@ -2233,6 +2257,42 @@ def inbox():
API: (cookie auth) POST /inbox act=send body=… · GET /api/inbox/messages
""" return page("inbox", body) +@app.route("/signup", methods=["GET"]) +def signup(): + if current_user_id(): + return Redirect("/keys") + nxt = esc(request.args.get("next") or "") + body = f""" +

SIGN UP

Name + password. That's the whole form — no email, no phone, no KYC, nothing to verify. $1 free credit lands in your balance the moment you're in.

+
+
Create account — 10 seconds +
+ + + + + +
+
What you get immediately +
    +
  • ◈ $1 free trial credit — metered API calls work instantly
  • +
  • ▣ API keys — machine access on the same balance
  • +
  • ✉ Inbox — no-KYC messaging with the operator + file-open alerts
  • +
  • ⚙ Tunables — your theme follows your account
  • +
+
Already have an account? Log in →
+
+
""" + return page("signup", body) + +@app.route("/logout", methods=["GET"]) +def logout(): + con = db() + con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("dark0rbits_tok"),)); con.commit() + resp = Response(status=302); resp.headers["Location"] = "/" + resp.set_cookie("dark0rbits_tok", "", max_age=0) + return resp + @app.route("/api/inbox/messages", methods=["GET"]) def api_inbox_msgs(): uid = current_user_id() @@ -2265,6 +2325,27 @@ DD_EXPLAINER = """
OPSEC NOTES
password gate — wrong attempts cost nothing. • Billing: free with PASS, otherwise 5¢ per note from your metered balance.
""" +@app.route("/dead-drop") +def deaddrop_alias(): + from flask import redirect + return redirect("/deaddrop", 301) + +@app.route("/burner-mail") +def burnermail_alias(): + from flask import redirect + return redirect("/mail", 301) + +@app.route("/fraud-score") +def fraudscore_alias(): + from flask import redirect + return redirect("/score", 301) + +@app.route("/mag-lab") +def maglab_alias(): + from flask import redirect + return redirect("/maglab", 301) + + @app.route("/deaddrop") def deaddrop(): uid = current_user_id() @@ -2622,7 +2703,7 @@ def index(): f'

{desc}

' for href, name, desc, ico, cat in tools) stat = f"you're connecting from {esc(d.get('query','?'))} · {esc(d.get('country',''))}" - cta = (' ' if uid else ' ') + cta = (' ' if uid else ' ') from markupsafe import escape as _e stat_line = '▸ ' + stat + '' if stat else "" body = f""" @@ -2709,5 +2790,276 @@ def not_found(e): return page("home", body), 404 + + +# ---------- MAG-LAB (browser magstripe studio, closed-loop only) ---------- +_MAG_POLICY = ( + "MAG-LAB encodes CLOSED-LOOP cards only: your own gift, loyalty, membership, " + "event or staff cards. Payment-network tracks (bank/debit/credit layouts, " + "13-19 digit Luhn-valid PANs, bank service codes 101/121/201-220, EMV/JCOP " + "dumps) are refused at encode AND decode. This is a hard policy, not a " + "toggle you can switch off.") + +def _mag_sentinel(track): + """True if a track looks like a payment-network card rather than closed-loop.""" + import re as _re + t = (track or "").strip() + if not t: + return False + body = t[1:] if t[0] in "%;" else t + pan = _re.sub(r"[^0-9]", "", body.split("^")[0] if "^" in body else (body.split("=")[0] if "=" in body else body)) + if pan and 13 <= len(pan) <= 19: + s, alt = 0, False + for ch in reversed(pan): + d = ord(ch) - 48 + if alt: + d *= 2 + if d > 9: + d -= 9 + s += d + alt = not alt + if s % 10 == 0: + return True + m = _re.search(r"\^([0-9]{4})([0-9]{3})", t) + if m and m.group(2)[0] in ("1", "2"): + return True + m = _re.search(r"=([0-9]{4})([0-9]{3})", t) + if m and m.group(2)[0] in ("1", "2"): + return True + return False + +_MAGLAB_HTML = r""" +

MAG LAB

+

Browser magstripe studio — Chrome + Web Serial talks straight to your MSR605/606-class writer. No drivers, no desktop app, any OS. Encode, read, decode, batch-issue closed-loop cards: gift, loyalty, membership, event tickets, staff badges.

+
+POLICY
__POLICY__ +
+
+
+CONNECT +
not connected
+
Chrome/Edge/Opera on Windows, macOS, Linux or ChromeOS. Firefox/Safari do not ship Web Serial. Writer must be an MSR605/606 or compatible serial MagStripe encoder.
+
+
+ISSUE A CARD +
+
+
+
+ +
+
+
+
+
+BATCH ISSUE (20c/card — paste CSV lines: label,value) + + + + +
+
+TRACK VISUALIZER +
paste any track to see its structure decoded (read-only field map; payment shapes are masked)
+ +

+
+
API (agent-first — 30c/encode, 20c/card batch, via key) +__AGENT__ +
+ +""" + +@app.route("/maglab") +def maglab(): + body = _MAGLAB_HTML.replace("__POLICY__", _MAG_POLICY) + body = body.replace("__AGENT__", agent_card( + "POST /api/maglab/encode {t1,t2} · POST /api/maglab/batch {rows:[{label,value}]}", + "curl -X POST " + SITE + "/api/maglab/encode -H 'Authorization: Bearer KEY' -d '{\"t2\":\";GIFT000123=4321?\"}'", + "Closed-loop magstripe studio. Encode validates + LRC-checks (30c), batch issues up to 100 cards with PINs + QR twins (20c/card). Refuses payment-card shapes.")) + body += gloss([("ISO 7811", "the magstripe track format standard - track1 79-bit alnum, track2/3 5-bit numeric"), + ("LRC", "longitudinal redundancy check - the trailing ? sentinel; wrong LRC = unreadable card"), + ("closed-loop", "a card scheme you own end-to-end: your shop issues it, your shop redeems it")]) + return page("maglab", body) + +@app.route("/api/maglab/encode", methods=["POST"]) +def api_maglab_encode(): + r = rate_limit("maglab", 20, 60) + if r: return r + uid = key_user() or current_user_id() + if not uid: + return jsonify({"ok": False, "error": "auth required: account session (sign up at /inbox, no KYC) or Authorization: Bearer *** key"}), 401 + if not has_pass(uid) and not charge(uid, 30, "maglab encode"): + return jsonify({"ok": False, "error": "insufficient balance", "balance_cents": get_balance(uid), "topup": SITE + "/keys"}), 402 + t1 = str(jp("t1") or "").strip() + t2 = str(jp("t2") or "").strip() + if not t1 and not t2: + return jsonify({"ok": False, "error": "at least one track required"}), 400 + for t in (t1, t2): + if t and _mag_sentinel(t): + return jsonify({"ok": False, "error": "refused: payment-network card shape detected - " + _MAG_POLICY[:120]}), 403 + for name, t in (("t1", t1), ("t2", t2)): + if t and not t.endswith("?"): + return jsonify({"ok": False, "error": name + " missing terminator '?' (LRC sentinel)"}), 400 + return jsonify({"ok": True, "ready": True, "t1": t1, "t2": t2}) + +@app.route("/api/maglab/batch", methods=["POST"]) +def api_maglab_batch(): + r = rate_limit("maglab_batch", 6, 60) + if r: return r + uid = key_user() or current_user_id() + if not uid: + return jsonify({"ok": False, "error": "auth required: account session (sign up at /inbox, no KYC) or Authorization: Bearer *** key"}), 401 + rows = jp("rows") + if not isinstance(rows, list) or not rows: + return jsonify({"ok": False, "error": "rows: array of {label,value} required"}), 400 + if len(rows) > 100: + return jsonify({"ok": False, "error": "max 100 cards per batch"}), 400 + pas = has_pass(uid) + if not pas and not charge(uid, 20 * len(rows), "maglab batch x%d" % len(rows)): + return jsonify({"ok": False, "error": "insufficient balance", "balance_cents": get_balance(uid), "topup": SITE + "/keys"}), 402 + made = [] + for i, row in enumerate(rows): + label = str(row.get("label") or ("CARD%03d" % (i + 1)))[:40] + value = str(row.get("value") or "").strip() + if not value: + return jsonify({"ok": False, "error": "row %d: value required" % (i + 1)}), 400 + pin = "".join(str(random.randrange(10)) for _ in range(6)) + t2 = ";" + re.sub(r"[^A-Z0-9]", "", value.upper()) + "=" + pin + "?" + if _mag_sentinel(t2): + return jsonify({"ok": False, "error": "row %d: refused, payment-card shape" % (i + 1)}), 403 + made.append({"label": label, "t2": t2, "pin": pin, "qr": SITE + "/card?card=" + label + ":" + pin}) + return jsonify({"ok": True, "count": len(made), "cards": made, + "cost_cents": 0 if pas else 20 * len(rows)}) + +@app.route("/api/maglab/decode", methods=["POST"]) +def api_maglab_decode(): + r = rate_limit("maglab_dec", 40, 60) + if r: return r + t = str(jp("track") or "").strip() + if not t: + return jsonify({"ok": False, "error": "track required"}), 400 + if _mag_sentinel(t): + return jsonify({"ok": False, "masked": True, "error": "payment-card shape - fields masked by policy"}), 200 + t1 = t.startswith("%") + sep = "^" if t1 else "=" + body = t[1:] if t[0] in "%;" else t + fields = body.rstrip("?").split(sep) + return jsonify({"ok": True, "track": 1 if t1 else 2, + "format": "ISO7811-A" if t1 else "ISO7811-B", + "fields": [f[:40] for f in fields], + "lrc_sentinel": body.endswith("?"), + "note": "closed-loop decode"}) + + if __name__ == "__main__": app.run(host="0.0.0.0", port=5000, threaded=True)