diff --git a/app.py b/app.py index d4862d3..e1dfc0d 100644 --- a/app.py +++ b/app.py @@ -371,7 +371,7 @@ li::marker{color:var(--acc)} CANARYDEAD-DROPBURNER-MAIL SHOTFRAUD-SCORE INBOXPASSPORT -PASSKEYSMAG-LABPORT BEACONBSSID RADARHOOK-RELAYFACE TRACEROTATORSHELFUNFURLWARPTOOLS +PASSKEYSMAG-LABPORT BEACONBSSID RADARHOOK-RELAYFACE TRACEROTATORSHELFSNAPUNFURLWARPTOOLS
{{acct}}
@@ -407,6 +407,7 @@ li::marker{color:var(--acc)} ◈ FACE TRACE profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts ◈ ROTATOR consistent browser identity pools with replayable seeds ◈ SHELF every burner you own, with live countdowns +◈ SNAP server-free one-click short links — target lives in the #fragment ◈ UNFURL Follow every redirect hop manually and dissect the final page ◈ WARP Domain time machine — Wayback snapshots, previews, DNS drift

Account

@@ -567,6 +568,7 @@ var PAL=[ ["/face", "avatar pfp triangulation"], ["/rotator", "header rotator \u2014 identity pools + seeds"], ["/shelf", "identity shelf \u2014 every burner + countdowns"], +["/s", "snap \u2014 server-free short links + safety decoder"], ["/unfurl", "redirect chain + page dissection"], ["/warp", "domain time machine \u2014 wayback timeline, previews, DNS drift"], ['/llms.txt','machine catalog for agents'], @@ -620,6 +622,7 @@ NEBULAS = { "score": ("rgba(255,110,180,.10)", "rgba(66,232,164,.10)"), "warp": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "unfurl": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), + "s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), "shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"), "rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), "face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), @@ -750,6 +753,7 @@ API_INDEX = { {"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."}, {"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."}, {"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."}, + {"method": "POST", "path": "/api/snap/decode", "desc": "Decode a snap link fragment (raw = text after #) WITHOUT opening it: returns target URL + host + scheme check. The shortener itself is server-free — targets ride in the #fragment and nothing is stored. FREE 60/min."}, {"method": "GET", "path": "/unfurl", "desc": "URL unfurl: follows every redirect hop one at a time (scheme, host, status, Location) and dissects the final page (title, meta/og tags, iframes, forms). Detects loops and refuses non-http schemes. FREE."}, {"method": "GET", "path": "/api/unfurl", "params": {"url": "http(s):// target", "max_hops": "1-10 default 6", "extract": "0|1"}, "desc": "Full redirect chain + final-page metadata as JSON. 401 without session/key; rate-limited. FREE."}, {"method": "GET", "path": "/api/unfurl/history", "desc": "Your last 25 unfurl lookups (url, final_url, status, ts). Login required."}, @@ -857,6 +861,7 @@ def openapi(): add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"}) add("/api/rotator/pools", "get", "Pool inventory") add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)") + add("/api/snap/decode", "post", "Decode snap-link fragment safely (no visit)", {"raw": "fragment after #"}, req=True) add("/api/unfurl", "get", "Unfurl a URL: follow redirects hop-by-hop, dissect final page", {"url": "https://bit.ly/abc", "max_hops": "6"}, req=True) add("/api/unfurl/history", "get", "Your last 25 unfurl lookups", {}, req=True) add("/api/warp", "get", "Domain time machine: Wayback timeline, screenshot-preview links, DNS/whois drift, hosted paths. Cached 6h.", {"domain": "example.com"}, req=True) @@ -4720,6 +4725,144 @@ def api_shelf(): # ---------- END TOOL: IDENTITY SHELF ---------- +# ---------- TOOL: SNAP LINK (client-side shortener) ---------- +_SNAP_PAGE = r""" +▶ SNAP — one click more + +
+

▶ SNAP — one click more

+

This is a dark0rbits snap link. The destination lives in the part of the address after the # — which is never sent to any server, anywhere. It decoded right here in your browser.

+
JavaScript is off — snap links decode client-side, so this one can't open. The raw destination is visible in the address bar after the #.
+ + +
+ +""" + +@app.route("/snap") +@app.route("/s") +@app.route("/s/") +def snap(_any=None): + r = Response(_SNAP_PAGE, mimetype="text/html") + r.headers["Cache-Control"] = "no-store" + r.headers["X-Robots-Tag"] = "noindex" + return r + +@app.route("/api/snap/decode", methods=["POST"]) +def api_snap_decode(): + """Agents: decode a snap fragment server-side WITHOUT opening it. raw = text after #.""" + r = rate_limit("snap", 60, 60) + if r: return r + raw = (param("raw") or "").strip() + if not raw: return jsonify({"ok": False, "error": "raw (fragment after #) required"}), 400 + try: + s = raw.replace("-", "+").replace("_", "/") + s += "=" * (-len(s) % 4) + import base64 as _b + target = base64.b64decode(s).decode("utf-8", "replace") + except Exception: + return jsonify({"ok": False, "error": "not a valid snap fragment"}), 400 + import re as _re + m = _re.match(r"^https?://([^/]+)", target, _re.I) + return jsonify({"ok": True, "target": target, + "host": m.group(1) if m else None, + "scheme_safe": bool(m)}) +# ---------- END TOOL: SNAP LINK ---------- + + # ---------- TOOL: UNFURL ---------- def _unfurl_db(): con = db() @@ -5321,6 +5464,7 @@ def index(): ("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"), ("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"), ("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"), + ("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"), ("unfurl", "UNFURL", "Follow every redirect hop in a URL chain and dissect the page at the end.", "◈", "Hunt"), ("warp","WARP ARCHIVE","A domain time machine: snapshot timeline from the Wayback Machine, archived-page previews, and DNS/whois drift — watch a domain morph over years.","◈","INTEL"), ("passport","AGENT PASSPORT","Machine-readable trust badge for your bots. Agents are first-class here.","◈","ACCOUNT"),