Parse + intel on any number worldwide: validity, country, region, carrier, line type (mobile/landline/VOIP), timezones — plus free deep-dive lead links. No KYC, no logs.
+
+{res}
+
API: GET /api/phone?num=%2B14255550100 → JSON: valid, country, region, carrier, line_type, timezones, flags, lead links.
""" + how(["Type the number in any format — country code, spaces, dashes, all handled.",
+"Metadata comes from offline libphonenumber data — instant and private, nothing phoned home.",
+"Line type matters: VOIP/UAN numbers are the disposable, bulk-registered kind.",
+"Follow the lead links for the human layer: public mentions, directory listings, name lookups.",
+"Pair it with SMS RENTAL — know the number type before you verify with it."])
+ body += gloss([("E164","the international standard format: + and country code, no spaces"),("line type","mobile vs landline vs VOIP — carriers publish the ranges"),("VOIP","internet-based number — cheap, disposable, often spoofed")])
+ body += agent_card('GET /api/phone?num=%2B14255550100', 'curl "https://dark0rbits.thetempleofdoom.com/api/phone?num=%2B14255550100"', 'valid, country, region, carrier, line_type, timezones, flags + free lead links.')
+ return page("phone", body)
+
+@app.route("/api/phone", methods=["GET", "POST"])
+def api_phone():
+ r = rate_limit("phone", 30, 60)
+ if r: return r
+ raw = (param("num") or "").strip()
+ if not raw: return jsonify({"ok": False, "error": "num required (any format, country code encouraged)"}), 400
+ return jsonify(phone_report(raw))
+
+# ---------- 2c. USERNAME SLEUTH (OSINT profile probe) ----------
+USER_SITES = [
+ ("GitHub", "https://github.com/{u}"),
+ ("GitLab", "https://gitlab.com/{u}"),
+ ("Reddit", "https://www.reddit.com/user/{u}/"),
+ ("Telegram", "https://t.me/{u}"),
+ ("Medium", "https://medium.com/@{u}"),
+ ("Pastebin", "https://pastebin.com/u/{u}"),
+ ("Keybase", "https://keybase.io/{u}"),
+ ("About.me", "https://about.me/{u}"),
+ ("SoundCloud", "https://soundcloud.com/{u}"),
+ ("Vimeo", "https://vimeo.com/{u}"),
+ ("Steam", "https://steamcommunity.com/id/{u}"),
+ ("Last.fm", "https://www.last.fm/user/{u}"),
+ ("Dribbble", "https://dribbble.com/{u}"),
+ ("Imgur", "https://imgur.com/user/{u}"),
+ ("Chess.com", "https://www.chess.com/member/{u}"),
+ ("Twitch", "https://www.twitch.tv/{u}"),
+]
+def _probe_site(name, url):
+ st, b = http(url, timeout=10)
+ if st == 200:
+ return {"site": name, "url": url, "status": "found", "http": st}
+ if st == 404:
+ return {"site": name, "url": url, "status": "not found", "http": st}
+ return {"site": name, "url": url, "status": "unknown", "http": st, "note": "site blocked or rate-limited the probe — check manually"}
+
+def user_probe(u):
+ from concurrent.futures import ThreadPoolExecutor
+ with ThreadPoolExecutor(max_workers=8) as ex:
+ results = list(ex.map(lambda s: _probe_site(s[0], s[1].format(u=urllib.parse.quote(u))), USER_SITES))
+ found = [r for r in results if r["status"] == "found"]
+ return {"ok": True, "username": u, "found": found, "results": results,
+ "hits": len(found), "leads": {
+ "google": "https://www.google.com/search?q=%22" + urllib.parse.quote(u) + "%22",
+ "instantusername": "https://instantusername.com/#/" + urllib.parse.quote(u)}}
+
+@app.route("/user", methods=["GET", "POST"])
+def user_tool():
+ res = ""
+ if request.method == "POST":
+ u = (param("u") or "").strip()
+ if u and 2 <= len(u) <= 60 and all(c not in "<>\"'" for c in u):
+ d = user_probe(u)
+ rows = "".join(f'
Give it a handle — it probes {len(USER_SITES)} major platforms in parallel and reports where that username lives. Classic OSINT footwork, automated.
+
+{res}
+
API: GET /api/user?u=NAME → JSON with per-site found/not-found/unknown.
""" + how(["Type the handle — no @, no https, just the name.",
+"Sixteen sites get probed at once — GitHub, Reddit, Telegram, Steam and more.",
+"FOUND = a live profile answered on that exact URL. Unknown = the site blocked the probe (check manually).",
+"Follow the Google/InstantUsername leads for the long tail of smaller platforms.",
+"Same handle on multiple sites = the same human. That's the whole point."])
+ body += gloss([("probe","an HTTP GET that never logs in or scrapes private data"),("handle","the username part of a profile URL"),("correlation","linking profiles across sites by shared handle")])
+ body += agent_card('GET /api/user?u=somehandle', 'curl "https://dark0rbits.thetempleofdoom.com/api/user?u=somehandle"', 'Per-site found/not-found/unknown + lead links. ~8s, all probes in parallel.')
+ return page("user", body)
+
+@app.route("/api/user", methods=["GET", "POST"])
+def api_user():
+ r = rate_limit("user", 10, 60)
+ if r: return r
+ u = (param("u") or "").strip()
+ if not u or len(u) > 60 or any(c in "<>\"'" for c in u): return jsonify({"ok": False, "error": "u required (max 60 chars, no html)"}), 400
+ return jsonify(user_probe(u))
+
+# ---------- 2d. DOMAIN RECON (RDAP + DNS + subdomains) ----------
+def domain_report(d):
+ d = d.strip().lower().replace("https://", "").replace("http://", "").split("/")[0]
+ out = {"ok": True, "domain": d}
+ st, b = http("https://rdap.org/" + urllib.parse.quote(d), timeout=15)
+ rd = jf(b)
+ if rd:
+ out["rdap"] = {k: rd.get(k) for k in ("handle", "ldhName", "status", "events", "entities", "nameservers") if rd.get(k)}
+ evs = {}
+ for e in rd.get("events") or []:
+ evs[e.get("eventAction", "?")] = e.get("eventDate")
+ out["events"] = evs
+ ents = []
+ for e in rd.get("entities") or []:
+ roles = e.get("roles") or []
+ fn = ""
+ try:
+ v = e.get("vcardArray") or []
+ for item in (v[1] if len(v) > 1 else []):
+ if item and item[0] == "fn": fn = item[3]
+ except Exception: pass
+ if "registrar" in roles or "registrant" in roles: ents.append({"roles": roles, "name": fn})
+ out["entities"] = ents
+ else:
+ out["rdap_error"] = f"rdap.org returned {st}"
+ doh = "https://dns.google/resolve?name=" + urllib.parse.quote(d) + "&type="
+ recs = {}
+ for rt in ("A", "AAAA", "MX", "NS", "TXT", "CNAME"):
+ st, b = http(doh + rt, timeout=10)
+ j = jf(b)
+ if j and j.get("Answer"):
+ recs[rt] = [a.get("data") for a in j["Answer"]]
+ out["dns"] = recs
+ st, b = http("https://crt.sh/?q=%25." + urllib.parse.quote(d) + "&output=json", timeout=25)
+ subs = set()
+ j = jf(b)
+ if isinstance(j, list):
+ for row in j:
+ for nm in str(row.get("name_value", "")).split("\n"):
+ nm = nm.strip().lower().lstrip("*.")
+ if nm.endswith("." + d) and nm != d: subs.add(nm)
+ out["subdomains"] = sorted(subs)[:100]
+ out["subdomain_count"] = len(subs)
+ return out
+
+@app.route("/domain", methods=["GET", "POST"])
+def domain_tool():
+ res = ""
+ if request.method == "POST":
+ d = (param("d") or "").strip()
+ if d and len(d) <= 100:
+ try:
+ rep = domain_report(d)
+ evs = rep.get("events") or {}
+ ent = "; ".join(f'{"/".join(e["roles"])}: {e["name"]}' for e in (rep.get("entities") or [])) or "—"
+ ns = ", ".join(str(x.get("ldhName") or x) for x in (rep.get("nameservers") or rep.get("rdap", {}).get("nameservers") or [])) or (rep.get("dns", {}).get("NS") and ", ".join(rep["dns"]["NS"])) or "—"
+ dns_rows = "".join(f"
{esc(k)}
{esc(' '.join(v))}
" for k, v in (rep.get("dns") or {}).items())
+ subs = rep.get("subdomains") or []
+ res = kv([("Registrar info", esc(ent)), ("Registered", esc(evs.get("registration", "—"))), ("Expires", esc(evs.get("expiration", "—"))), ("Last changed", esc(evs.get("last changed", "—"))), ("Status", esc(", ".join(rep.get("rdap", {}).get("status") or []) or "—")), ("Nameservers", esc(ns))])
+ res += f'
Full passive recon on any domain: RDAP registration data (registrar, dates, status), live DNS records, and certificate-transparency subdomain discovery. Free, no keys.
+
+{res}
+
API: GET /api/domain?d=example.com → JSON: rdap, events, entities, dns, subdomains.
""" + how(["Type the bare domain — no scheme, no path.",
+"RDAP answers who runs it, when it was registered and when it expires.",
+"DNS shows A/AAAA/MX/NS/TXT/CNAME — where it lives and what mail it accepts.",
+"Certificate logs expose hostnames even when DNS tries to hide them — great for finding staging/hidden subdomains.",
+"All sources are public registries — passive, no packets touch the target."])
+ body += gloss([("RDAP","modern successor to WHOIS — structured registration data"),("CT log","certificate-transparency log: every TLS cert ever issued, public"),("TXT","DNS records used for SPF/verification claims")])
+ body += agent_card('GET /api/domain?d=example.com', 'curl "https://dark0rbits.thetempleofdoom.com/api/domain?d=example.com"', 'RDAP registration, DNS records, CT-log subdomains. Passive OSINT, free.')
+ return page("domain", body)
+
+@app.route("/api/domain", methods=["GET", "POST"])
+def api_domain():
+ r = rate_limit("domain", 10, 60)
+ if r: return r
+ d = (param("d") or "").strip()
+ if not d or len(d) > 100: return jsonify({"ok": False, "error": "d required"}), 400
+ return jsonify(domain_report(d))
+
@app.route("/card", methods=["GET", "POST"])
def card():
result = ""
@@ -1024,7 +1325,7 @@ if(sr.headings&&sr.headings.length)h+='
'+_esc(sr.text_preview)+'';body.innerHTML=h;return}}
if(sr.status==='error'){{body.innerHTML=''+_esc(sr.error)+'';return}}
body.textContent='rendering… (poll '+i+'/20)'}}}}catch(e){{body.textContent='error: '+e}}}}
-""" + SHOT_API + how(["Paste a URL — the job queues with a 25¢ charge (free with PASS).",
+""" + SHOT_API + how(["Paste a URL — the job queues instantly (free).",
"With a headless browser on the host you get a real PNG back as base64.",
"No browser installed? You get text_fallback: title, description, headings, first 400 words — honestly labeled.",
"Agents: POST /api/shot/create then poll /api/shot/status/ until status != queued.",
@@ -1139,7 +1440,7 @@ def sms():
hist = con.execute("SELECT * FROM sms_rentals WHERE user_id=? ORDER BY id DESC LIMIT 8", (uid,)).fetchall()
hist_rows = "".join(f"