From 9645c00f38333d1806e455127447cdcfac260bb8 Mon Sep 17 00:00:00 2001 From: drjones Date: Wed, 7 Oct 2026 15:15:03 -0700 Subject: [PATCH] =?UTF-8?q?QR=20FORGE=20/qrforge=20=E2=80=94=20QR=20codes?= =?UTF-8?q?=20for=20launcher=20scripts:=20Apple=20Shortcuts=20import/run?= =?UTF-8?q?=20presets,=20Android=20chrome=20intents=20+=20market://,=20app?= =?UTF-8?q?=20deep=20links.=20Server-rendered=20PNG=20via=20/api/qr=20(no?= =?UTF-8?q?=20storage,=2060/min).=20Cheat-sheet=20+=20example=20flow.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app.py | 111 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 110 insertions(+), 1 deletion(-) diff --git a/app.py b/app.py index 4e2a73c..b38ce77 100644 --- a/app.py +++ b/app.py @@ -371,7 +371,7 @@ li::marker{color:var(--acc)} CANARYDEAD-DROPBURNER-MAIL SHOTFRAUD-SCORE INBOXPASSPORT -PASSKEYSMAG-LABPORT BEACONBSSID RADARHOOK-RELAYFACE TRACEROTATORSHELFSNAPUNFURLWARPTOOLS +PASSKEYSMAG-LABPORT BEACONBSSID RADARHOOK-RELAYFACE TRACEQR-FORGEROTATORSHELFSNAPUNFURLWARPTOOLS
{{acct}}
@@ -405,6 +405,7 @@ li::marker{color:var(--acc)} ◈ BSSID RADAR WiFi router-MAC (BSSID) to approximate geolocation via crowdsourced DB — map links, accuracy radius, batch runs. ◈ HOOK-RELAY instant public webhook inspector — capture, inspect, replay ◈ FACE TRACE profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts +◈ QR-FORGE QR codes for shortcut & intent launcher scripts — scan to execute ◈ ROTATOR consistent browser identity pools with replayable seeds ◈ SHELF every burner you own, with live countdowns ◈ SNAP server-free one-click short links — target lives in the #fragment @@ -566,6 +567,7 @@ var PAL=[ ["/bssid", "WiFi router-MAC geolocation"], ["/hooks", "webhook inspector \u2014 capture, inspect, replay"], ["/face", "avatar pfp triangulation"], +["/qrforge", "QR forge \u2014 shortcut & intent launcher codes"], ["/rotator", "header rotator \u2014 identity pools + seeds"], ["/shelf", "identity shelf \u2014 every burner + countdowns"], ["/s", "snap \u2014 server-free short links + safety decoder"], @@ -625,6 +627,7 @@ NEBULAS = { "s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), "shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"), "rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), + "qrforge": ("rgba(255,201,77,.11)", "rgba(66,232,164,.09)"), "face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "hooks": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "bssid": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), @@ -750,6 +753,7 @@ API_INDEX = { {"method": "GET", "path": "/api/hook/hits?token=", "params": {"token": "hook token", "limit": "1-500, default 100"}, "desc": "Captured hits for one endpoint: method, ts, ip, ua, content-type, source badge (Stripe/GitHub/Discord/Shopify/Telegram auto-detected), full headers, query, body. Login required."}, {"method": "POST", "path": "/api/hook/replay", "params": {"hit_id": "captured hit id", "target_url": "https:// destination"}, "desc": "Resend a captured hit (original method, headers, body) to any public URL via http(). SSRF-guarded: 10.x / 127. / 172.16-31 / 169.254 and reserved ranges refused. Login required."}, {"method": "POST", "path": "/api/face", "files": ["image"], "params": {"u": "username (optional)"}, "desc": "Face trace: fingerprint an uploaded avatar (dHash 9x8 + aHash 8x8 + sha256, computed locally), harvest the username's avatars (GitHub + Reddit APIs, Telegram/Steam/Twitch constructed links), compare via Hamming distance (<=10/64 = likely same image) + manual reverse-image lead links. No external reverse-image APIs called."}, + {"method": "GET", "path": "/api/qr?data=", "desc": "Server-rendered QR PNG of any string (shortcuts://, intent://, market://, deep links, URLs). box=3-12 sizes. 900 char max, 60/min, no auth."}, {"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."}, {"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."}, {"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."}, @@ -858,6 +862,7 @@ def openapi(): add("/api/hook/hits", "get", "Captured hits for one hook (auto-detected source, headers, body)", {"token": "hook token", "limit": "opt 1-500"}, req=True) add("/api/hook/replay", "post", "Replay a captured hit to any public URL (SSRF-guarded)", {"hit_id": "hit id", "target_url": "https:// target"}, req=True) add("/api/face", "post", "Avatar fingerprint + username pfp harvest + Hamming verdict", {"u": "username (optional)"}, files=["image"]) + add("/api/qr", "get", "QR PNG of any launcher script or URL", {"data": "text to encode", "box": "pixel size 3-12"}, req=True) add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"}) add("/api/rotator/pools", "get", "Pool inventory") add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)") @@ -4432,6 +4437,109 @@ def api_face(): # ---------- END TOOL: FACE TRACE ---------- +# ---------- TOOL: QR FORGE (shortcut launcher codes) ---------- +_QR_STYLES_CSS = """ +.qrgrid{display:grid;grid-template-columns:1fr;gap:1.1rem} +@media(min-width:700px){.qrgrid{grid-template-columns:repeat(2,1fr)}} +.qrout{display:flex;flex-direction:column;align-items:center;gap:.6rem;min-height:240px;justify-content:center} +.qrout img{background:#fff;padding:12px;border-radius:12px;max-width:260px;width:100%} +.schemebox{border:1px solid var(--line);border-radius:10px;padding:.7rem .9rem;margin:.5rem 0;font-size:.85rem} +.schemebox b{color:var(--acc2)} +.preset{margin:.3rem .3rem .3rem 0} +""" + +# Server-side QR renderer (no external service): tiny pure-python QR encoder +def _qr_png(data, box=6, border=2): + """Minimal QR encoder (byte mode, ECC L, versions 1-10) — returns PNG bytes.""" + try: + import qrcode as _q + img = _q.make(data, border=border, box_size=box) + buf = io.BytesIO(); img.save(buf, "PNG"); return buf.getvalue() + except ImportError: + pass + # fallback: delegate to local shot of the qrserver only if qrcode lib missing + raise RuntimeError("qrcode module unavailable") + +_GAL = 'https://icloud.com/shortcuts/' +_SCHEME_DOCS = [ + ("shortcuts://import-shortcut?url=", "Apple — installs a shortcut when scanned (iOS shows a one-tap Add confirmation)", "iOS"), + ("shortcuts://run-shortcut?name=&input=", "Apple — runs an installed shortcut by name, optional input", "iOS"), + ("shortcuts://create-shortcut", "Apple — opens a new empty shortcut editor", "iOS"), + ("intent://scan/#Intent;scheme=http;package=com.android.chrome;end", "Android — chrome intent: opens URL in Chrome when scanned", "Android"), + ("intent://#Intent;scheme=...;package=...;S.=;end", "Android — full intent form: scheme, target app package, string extras", "Android"), + ("market://details?id=", "Android — opens the Play Store page for an app", "Android"), + ("snackbar:// or any app deep link (spotify:, whatsapp://send?text=, tg://msg_url?url=)", "Any app's registered deep link — scannable like a URL", "both"), +] + +@app.route("/qrforge") +def qrforge(): + body = f""" +

QR FORGE

QR codes for launcher scripts: Apple Shortcuts install/run codes and Android intent codes. Scan with the right phone and it fires the shortcut — the phone's own confirm prompt is the only gate, nothing to type.

+
+ +
+ + + + + +
+ + +
the phone that scans runs this — iOS/Android will show their own confirm dialog
+
+ + +
+
+
+
your code renders here
+
Scan behavior cheat-sheet +""" + "".join(f'
{esc(s)}
{esc(d)} {p}
' for s, d, p in _SCHEME_DOCS) + """ +
+
API: GET /api/qr?data=&box=4-12 → PNG (works for agents: any text, any scheme). QRs render server-side — nothing about your script is stored.
""" + how([ +"Pick a preset or type any scheme command — shortcuts://, intent://, market://, or any app deep link.", +"For iOS install-codes: make your shortcut in the Shortcuts app, share it, copy the icloud.com/shortcuts link, feed it to the import preset.", +"For Android intents: name the target app package and scheme — the scanner hands it to the OS which routes it to the app.", +"Hit Forge — the PNG renders server-side from your exact string, byte for byte.", +"Print it, sticker it, slap it on something. The scanning phone shows its own native confirm prompt before anything runs.", +"Agents: GET /api/qr?data=… returns the raw PNG — no auth, rate limited."]) + body += flow("make a phone run a shortcut with one camera tap", [ +"you build a shortcut on your iPhone that texts your own number the phone's battery level.", +"you share it → copy the icloud.com/shortcuts/… link → paste into QR FORGE with the install preset.", +"you Forge, print the code, stick it on the fridge.", +"anyone points their iPhone camera at it — iOS pops: 'Add Shortcut?' — one tap and it installs.", +"them a second scan of a run-code fires it — battery text arrives.", +"android same page, intent preset: the code hands a chrome intent to the OS and the page opens."] if False else [ +"you build a shortcut on your iPhone that texts your own number the battery level.", +"you share it — copy the icloud.com/shortcuts link — paste it into QR FORGE with the install preset.", +"you hit Forge and print the code on a sticker.", +"them scans it: iOS shows its native 'Add Shortcut?' — one tap, installed.", +"now the run-code variant fires it by name — no typing, no link, the phone just does the thing.", +"android the intent presets do the same dance through Chrome and the Play Store."]) + body += gloss([("scheme","the prefix that hands a command to the phone OS — shortcuts://, intent://, market://"),("intent","Android's inter-app command format: scheme + package + extras"),("deep link","an app's private URL scheme that opens it to a specific action"),("package","Android app identifier, e.g. com.android.chrome")]) + body += agent_card('GET /api/qr?data=shortcuts%3A%2F%2F…', 'curl -o code.png "https://dark0rbits.thetempleofdoom.com/api/qr?data=intent%3A%2F%2Fscan%23Intent%3Bscheme%3Dhttp%3Bend"', 'Returns PNG bytes. Any scheme accepted — the phone OS is the executor.') + return page("qrforge", body + "") + +@app.route("/api/qr") +def api_qr(): + r = rate_limit("qr", 60, 60) + if r: return r + data = (param("data") or "").strip() + if not data: return jsonify({"ok": False, "error": "data required"}), 400 + if len(data) > 900: return jsonify({"ok": False, "error": "data too long (900 max)"}), 400 + try: box = min(12, max(3, int(param("box") or 6))) + except Exception: box = 6 + try: + png = _qr_png(data, box=box) + except Exception as e: + return jsonify({"ok": False, "error": str(e)[:200]}), 500 + resp = Response(png, mimetype="image/png") + resp.headers["Cache-Control"] = "public, max-age=86400" + return resp +# ---------- END TOOL: QR FORGE ---------- + + # ---------- TOOL: ROTATOR ---------- import random as _rnd import json as _json @@ -5448,6 +5556,7 @@ def index(): ("bssid","BSSID RADAR","Turn a WiFi router's MAC into an approximate place on Earth, with map links and accuracy radius.","◈","Hunt"), ("hooks", "HOOK RELAY", "Instant public webhook inspector: capture every callback, auto-detect the sender, replay it anywhere.", "◈", "Operate"), ("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"), + ("qrforge","QR FORGE","QR codes that fire shortcut & intent scripts on scan — Apple Shortcuts install/run, Android intents, deep links. Native phone confirm is the gate.","◈","OPERATE"), ("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"), ("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"), ("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"),