@@ -405,6 +405,7 @@ li::marker{color:var(--acc)}
◈ BSSID RADAR WiFi router-MAC (BSSID) to approximate geolocation via crowdsourced DB — map links, accuracy radius, batch runs.◈ HOOK-RELAY instant public webhook inspector — capture, inspect, replay◈ FACE TRACE profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts
+◈ QR-FORGE QR codes for shortcut & intent launcher scripts — scan to execute◈ ROTATOR consistent browser identity pools with replayable seeds◈ SHELF every burner you own, with live countdowns◈ SNAP server-free one-click short links — target lives in the #fragment
@@ -566,6 +567,7 @@ var PAL=[
["/bssid", "WiFi router-MAC geolocation"],
["/hooks", "webhook inspector \u2014 capture, inspect, replay"],
["/face", "avatar pfp triangulation"],
+["/qrforge", "QR forge \u2014 shortcut & intent launcher codes"],
["/rotator", "header rotator \u2014 identity pools + seeds"],
["/shelf", "identity shelf \u2014 every burner + countdowns"],
["/s", "snap \u2014 server-free short links + safety decoder"],
@@ -625,6 +627,7 @@ NEBULAS = {
"s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
"shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"),
"rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
+ "qrforge": ("rgba(255,201,77,.11)", "rgba(66,232,164,.09)"),
"face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
"hooks": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
"bssid": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
@@ -750,6 +753,7 @@ API_INDEX = {
{"method": "GET", "path": "/api/hook/hits?token=", "params": {"token": "hook token", "limit": "1-500, default 100"}, "desc": "Captured hits for one endpoint: method, ts, ip, ua, content-type, source badge (Stripe/GitHub/Discord/Shopify/Telegram auto-detected), full headers, query, body. Login required."},
{"method": "POST", "path": "/api/hook/replay", "params": {"hit_id": "captured hit id", "target_url": "https:// destination"}, "desc": "Resend a captured hit (original method, headers, body) to any public URL via http(). SSRF-guarded: 10.x / 127. / 172.16-31 / 169.254 and reserved ranges refused. Login required."},
{"method": "POST", "path": "/api/face", "files": ["image"], "params": {"u": "username (optional)"}, "desc": "Face trace: fingerprint an uploaded avatar (dHash 9x8 + aHash 8x8 + sha256, computed locally), harvest the username's avatars (GitHub + Reddit APIs, Telegram/Steam/Twitch constructed links), compare via Hamming distance (<=10/64 = likely same image) + manual reverse-image lead links. No external reverse-image APIs called."},
+ {"method": "GET", "path": "/api/qr?data=", "desc": "Server-rendered QR PNG of any string (shortcuts://, intent://, market://, deep links, URLs). box=3-12 sizes. 900 char max, 60/min, no auth."},
{"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."},
{"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."},
{"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."},
@@ -858,6 +862,7 @@ def openapi():
add("/api/hook/hits", "get", "Captured hits for one hook (auto-detected source, headers, body)", {"token": "hook token", "limit": "opt 1-500"}, req=True)
add("/api/hook/replay", "post", "Replay a captured hit to any public URL (SSRF-guarded)", {"hit_id": "hit id", "target_url": "https:// target"}, req=True)
add("/api/face", "post", "Avatar fingerprint + username pfp harvest + Hamming verdict", {"u": "username (optional)"}, files=["image"])
+ add("/api/qr", "get", "QR PNG of any launcher script or URL", {"data": "text to encode", "box": "pixel size 3-12"}, req=True)
add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"})
add("/api/rotator/pools", "get", "Pool inventory")
add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)")
@@ -4432,6 +4437,109 @@ def api_face():
# ---------- END TOOL: FACE TRACE ----------
+# ---------- TOOL: QR FORGE (shortcut launcher codes) ----------
+_QR_STYLES_CSS = """
+.qrgrid{display:grid;grid-template-columns:1fr;gap:1.1rem}
+@media(min-width:700px){.qrgrid{grid-template-columns:repeat(2,1fr)}}
+.qrout{display:flex;flex-direction:column;align-items:center;gap:.6rem;min-height:240px;justify-content:center}
+.qrout img{background:#fff;padding:12px;border-radius:12px;max-width:260px;width:100%}
+.schemebox{border:1px solid var(--line);border-radius:10px;padding:.7rem .9rem;margin:.5rem 0;font-size:.85rem}
+.schemebox b{color:var(--acc2)}
+.preset{margin:.3rem .3rem .3rem 0}
+"""
+
+# Server-side QR renderer (no external service): tiny pure-python QR encoder
+def _qr_png(data, box=6, border=2):
+ """Minimal QR encoder (byte mode, ECC L, versions 1-10) — returns PNG bytes."""
+ try:
+ import qrcode as _q
+ img = _q.make(data, border=border, box_size=box)
+ buf = io.BytesIO(); img.save(buf, "PNG"); return buf.getvalue()
+ except ImportError:
+ pass
+ # fallback: delegate to local shot of the qrserver only if qrcode lib missing
+ raise RuntimeError("qrcode module unavailable")
+
+_GAL = 'https://icloud.com/shortcuts/'
+_SCHEME_DOCS = [
+ ("shortcuts://import-shortcut?url=", "Apple — installs a shortcut when scanned (iOS shows a one-tap Add confirmation)", "iOS"),
+ ("shortcuts://run-shortcut?name=&input=", "Apple — runs an installed shortcut by name, optional input", "iOS"),
+ ("shortcuts://create-shortcut", "Apple — opens a new empty shortcut editor", "iOS"),
+ ("intent://scan/#Intent;scheme=http;package=com.android.chrome;end", "Android — chrome intent: opens URL in Chrome when scanned", "Android"),
+ ("intent://#Intent;scheme=...;package=...;S.=;end", "Android — full intent form: scheme, target app package, string extras", "Android"),
+ ("market://details?id=", "Android — opens the Play Store page for an app", "Android"),
+ ("snackbar:// or any app deep link (spotify:, whatsapp://send?text=, tg://msg_url?url=)", "Any app's registered deep link — scannable like a URL", "both"),
+]
+
+@app.route("/qrforge")
+def qrforge():
+ body = f"""
+
QR FORGE
QR codes for launcher scripts: Apple Shortcuts install/run codes and Android intent codes. Scan with the right phone and it fires the shortcut — the phone's own confirm prompt is the only gate, nothing to type.
+
+
+
+
+
+
+
+
+
+
+
+
the phone that scans runs this — iOS/Android will show their own confirm dialog
+
+
+
+
+
+
+
your code renders here
+
Scan behavior cheat-sheet
+""" + "".join(f'
{esc(s)} {esc(d)} {p}
' for s, d, p in _SCHEME_DOCS) + """
+
+
API: GET /api/qr?data=&box=4-12 → PNG (works for agents: any text, any scheme). QRs render server-side — nothing about your script is stored.
""" + how([
+"Pick a preset or type any scheme command — shortcuts://, intent://, market://, or any app deep link.",
+"For iOS install-codes: make your shortcut in the Shortcuts app, share it, copy the icloud.com/shortcuts link, feed it to the import preset.",
+"For Android intents: name the target app package and scheme — the scanner hands it to the OS which routes it to the app.",
+"Hit Forge — the PNG renders server-side from your exact string, byte for byte.",
+"Print it, sticker it, slap it on something. The scanning phone shows its own native confirm prompt before anything runs.",
+"Agents: GET /api/qr?data=… returns the raw PNG — no auth, rate limited."])
+ body += flow("make a phone run a shortcut with one camera tap", [
+"you build a shortcut on your iPhone that texts your own number the phone's battery level.",
+"you share it → copy the icloud.com/shortcuts/… link → paste into QR FORGE with the install preset.",
+"you Forge, print the code, stick it on the fridge.",
+"anyone points their iPhone camera at it — iOS pops: 'Add Shortcut?' — one tap and it installs.",
+"them a second scan of a run-code fires it — battery text arrives.",
+"android same page, intent preset: the code hands a chrome intent to the OS and the page opens."] if False else [
+"you build a shortcut on your iPhone that texts your own number the battery level.",
+"you share it — copy the icloud.com/shortcuts link — paste it into QR FORGE with the install preset.",
+"you hit Forge and print the code on a sticker.",
+"them scans it: iOS shows its native 'Add Shortcut?' — one tap, installed.",
+"now the run-code variant fires it by name — no typing, no link, the phone just does the thing.",
+"android the intent presets do the same dance through Chrome and the Play Store."])
+ body += gloss([("scheme","the prefix that hands a command to the phone OS — shortcuts://, intent://, market://"),("intent","Android's inter-app command format: scheme + package + extras"),("deep link","an app's private URL scheme that opens it to a specific action"),("package","Android app identifier, e.g. com.android.chrome")])
+ body += agent_card('GET /api/qr?data=shortcuts%3A%2F%2F…', 'curl -o code.png "https://dark0rbits.thetempleofdoom.com/api/qr?data=intent%3A%2F%2Fscan%23Intent%3Bscheme%3Dhttp%3Bend"', 'Returns PNG bytes. Any scheme accepted — the phone OS is the executor.')
+ return page("qrforge", body + "")
+
+@app.route("/api/qr")
+def api_qr():
+ r = rate_limit("qr", 60, 60)
+ if r: return r
+ data = (param("data") or "").strip()
+ if not data: return jsonify({"ok": False, "error": "data required"}), 400
+ if len(data) > 900: return jsonify({"ok": False, "error": "data too long (900 max)"}), 400
+ try: box = min(12, max(3, int(param("box") or 6)))
+ except Exception: box = 6
+ try:
+ png = _qr_png(data, box=box)
+ except Exception as e:
+ return jsonify({"ok": False, "error": str(e)[:200]}), 500
+ resp = Response(png, mimetype="image/png")
+ resp.headers["Cache-Control"] = "public, max-age=86400"
+ return resp
+# ---------- END TOOL: QR FORGE ----------
+
+
# ---------- TOOL: ROTATOR ----------
import random as _rnd
import json as _json
@@ -5448,6 +5556,7 @@ def index():
("bssid","BSSID RADAR","Turn a WiFi router's MAC into an approximate place on Earth, with map links and accuracy radius.","◈","Hunt"),
("hooks", "HOOK RELAY", "Instant public webhook inspector: capture every callback, auto-detect the sender, replay it anywhere.", "◈", "Operate"),
("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"),
+ ("qrforge","QR FORGE","QR codes that fire shortcut & intent scripts on scan — Apple Shortcuts install/run, Android intents, deep links. Native phone confirm is the gate.","◈","OPERATE"),
("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"),
("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"),
("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"),