QR FORGE /qrforge — QR codes for launcher scripts: Apple Shortcuts import/run presets, Android chrome intents + market://, app deep links. Server-rendered PNG via /api/qr (no storage, 60/min). Cheat-sheet + example flow.

This commit is contained in:
drjones
2026-10-07 15:15:03 -07:00
parent e476675618
commit 9645c00f38

111
app.py
View File

@@ -371,7 +371,7 @@ li::marker{color:var(--acc)}
<a href=/canary class={{o('canary')}}>CANARY</a><a href=/deaddrop class={{o('deaddrop')}}>DEAD-DROP</a><a href=/mail class={{o('mail')}}>BURNER-MAIL</a> <a href=/canary class={{o('canary')}}>CANARY</a><a href=/deaddrop class={{o('deaddrop')}}>DEAD-DROP</a><a href=/mail class={{o('mail')}}>BURNER-MAIL</a>
<a href=/shot class={{o('shot')}}>SHOT</a><a href=/score class={{o('score')}}>FRAUD-SCORE</a> <a href=/shot class={{o('shot')}}>SHOT</a><a href=/score class={{o('score')}}>FRAUD-SCORE</a>
<a href=/inbox class={{o('inbox')}}>INBOX</a><a href=/passport class={{o('passport')}}>PASSPORT</a> <a href=/inbox class={{o('inbox')}}>INBOX</a><a href=/passport class={{o('passport')}}>PASSPORT</a>
<a href=/pass class={{o('pass')}}>PASS</a><a href=/keys class={{o('keys')}}>KEYS</a><a href=/maglab class={{o('maglab')}}>MAG-LAB</a><a href=/beacon class={{o('beacon')}}>PORT BEACON</a><a href=/bssid class={{o('bssid')}}>BSSID RADAR</a><a href=/hooks class={{o('hooks')}}>HOOK-RELAY</a><a href=/face class={{o('face')}}>FACE TRACE</a><a href=/rotator class={{o('rotator')}}>ROTATOR</a><a href=/shelf class={{o('shelf')}}>SHELF</a><a href=/s class={{o('s')}}>SNAP</a><a href=/unfurl class={{o('unfurl')}}>UNFURL</a><a href=/warp class={{o('warp')}}>WARP</a><a href=/tools class={{o('tools')}}>TOOLS</a> <a href=/pass class={{o('pass')}}>PASS</a><a href=/keys class={{o('keys')}}>KEYS</a><a href=/maglab class={{o('maglab')}}>MAG-LAB</a><a href=/beacon class={{o('beacon')}}>PORT BEACON</a><a href=/bssid class={{o('bssid')}}>BSSID RADAR</a><a href=/hooks class={{o('hooks')}}>HOOK-RELAY</a><a href=/face class={{o('face')}}>FACE TRACE</a><a href=/qrforge class={{o('qrforge')}}>QR-FORGE</a><a href=/rotator class={{o('rotator')}}>ROTATOR</a><a href=/shelf class={{o('shelf')}}>SHELF</a><a href=/s class={{o('s')}}>SNAP</a><a href=/unfurl class={{o('unfurl')}}>UNFURL</a><a href=/warp class={{o('warp')}}>WARP</a><a href=/tools class={{o('tools')}}>TOOLS</a>
</div> </div>
<div id="acct">{{acct}}</div><button class=burger id=burger onclick="drw()">☰</button> <div id="acct">{{acct}}</div><button class=burger id=burger onclick="drw()">☰</button>
</div></header> </div></header>
@@ -405,6 +405,7 @@ li::marker{color:var(--acc)}
<a class="dl {{o('bssid')}}" href=/bssid>◈ BSSID RADAR <small>WiFi router-MAC (BSSID) to approximate geolocation via crowdsourced DB — map links, accuracy radius, batch runs.</small></a> <a class="dl {{o('bssid')}}" href=/bssid>◈ BSSID RADAR <small>WiFi router-MAC (BSSID) to approximate geolocation via crowdsourced DB — map links, accuracy radius, batch runs.</small></a>
<a class="dl {{o('hooks')}}" href=/hooks>◈ HOOK-RELAY <small>instant public webhook inspector — capture, inspect, replay</small></a> <a class="dl {{o('hooks')}}" href=/hooks>◈ HOOK-RELAY <small>instant public webhook inspector — capture, inspect, replay</small></a>
<a class="dl {{o('face')}}" href=/face>◈ FACE TRACE <small>profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts</small></a> <a class="dl {{o('face')}}" href=/face>◈ FACE TRACE <small>profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts</small></a>
<a class="dl {{o('qrforge')}}" href=/qrforge>◈ QR-FORGE <small>QR codes for shortcut & intent launcher scripts — scan to execute</small></a>
<a class="dl {{o('rotator')}}" href=/rotator>◈ ROTATOR <small>consistent browser identity pools with replayable seeds</small></a> <a class="dl {{o('rotator')}}" href=/rotator>◈ ROTATOR <small>consistent browser identity pools with replayable seeds</small></a>
<a class="dl {{o('shelf')}}" href=/shelf>◈ SHELF <small>every burner you own, with live countdowns</small></a> <a class="dl {{o('shelf')}}" href=/shelf>◈ SHELF <small>every burner you own, with live countdowns</small></a>
<a class="dl {{o('s')}}" href=/s>◈ SNAP <small>server-free one-click short links — target lives in the #fragment</small></a> <a class="dl {{o('s')}}" href=/s>◈ SNAP <small>server-free one-click short links — target lives in the #fragment</small></a>
@@ -566,6 +567,7 @@ var PAL=[
["/bssid", "WiFi router-MAC geolocation"], ["/bssid", "WiFi router-MAC geolocation"],
["/hooks", "webhook inspector \u2014 capture, inspect, replay"], ["/hooks", "webhook inspector \u2014 capture, inspect, replay"],
["/face", "avatar pfp triangulation"], ["/face", "avatar pfp triangulation"],
["/qrforge", "QR forge \u2014 shortcut & intent launcher codes"],
["/rotator", "header rotator \u2014 identity pools + seeds"], ["/rotator", "header rotator \u2014 identity pools + seeds"],
["/shelf", "identity shelf \u2014 every burner + countdowns"], ["/shelf", "identity shelf \u2014 every burner + countdowns"],
["/s", "snap \u2014 server-free short links + safety decoder"], ["/s", "snap \u2014 server-free short links + safety decoder"],
@@ -625,6 +627,7 @@ NEBULAS = {
"s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), "s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
"shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"), "shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"),
"rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"), "rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
"qrforge": ("rgba(255,201,77,.11)", "rgba(66,232,164,.09)"),
"face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
"hooks": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "hooks": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
"bssid": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"), "bssid": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
@@ -750,6 +753,7 @@ API_INDEX = {
{"method": "GET", "path": "/api/hook/hits?token=", "params": {"token": "hook token", "limit": "1-500, default 100"}, "desc": "Captured hits for one endpoint: method, ts, ip, ua, content-type, source badge (Stripe/GitHub/Discord/Shopify/Telegram auto-detected), full headers, query, body. Login required."}, {"method": "GET", "path": "/api/hook/hits?token=", "params": {"token": "hook token", "limit": "1-500, default 100"}, "desc": "Captured hits for one endpoint: method, ts, ip, ua, content-type, source badge (Stripe/GitHub/Discord/Shopify/Telegram auto-detected), full headers, query, body. Login required."},
{"method": "POST", "path": "/api/hook/replay", "params": {"hit_id": "captured hit id", "target_url": "https:// destination"}, "desc": "Resend a captured hit (original method, headers, body) to any public URL via http(). SSRF-guarded: 10.x / 127. / 172.16-31 / 169.254 and reserved ranges refused. Login required."}, {"method": "POST", "path": "/api/hook/replay", "params": {"hit_id": "captured hit id", "target_url": "https:// destination"}, "desc": "Resend a captured hit (original method, headers, body) to any public URL via http(). SSRF-guarded: 10.x / 127. / 172.16-31 / 169.254 and reserved ranges refused. Login required."},
{"method": "POST", "path": "/api/face", "files": ["image"], "params": {"u": "username (optional)"}, "desc": "Face trace: fingerprint an uploaded avatar (dHash 9x8 + aHash 8x8 + sha256, computed locally), harvest the username's avatars (GitHub + Reddit APIs, Telegram/Steam/Twitch constructed links), compare via Hamming distance (<=10/64 = likely same image) + manual reverse-image lead links. No external reverse-image APIs called."}, {"method": "POST", "path": "/api/face", "files": ["image"], "params": {"u": "username (optional)"}, "desc": "Face trace: fingerprint an uploaded avatar (dHash 9x8 + aHash 8x8 + sha256, computed locally), harvest the username's avatars (GitHub + Reddit APIs, Telegram/Steam/Twitch constructed links), compare via Hamming distance (<=10/64 = likely same image) + manual reverse-image lead links. No external reverse-image APIs called."},
{"method": "GET", "path": "/api/qr?data=", "desc": "Server-rendered QR PNG of any string (shortcuts://, intent://, market://, deep links, URLs). box=3-12 sizes. 900 char max, 60/min, no auth."},
{"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."}, {"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."},
{"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."}, {"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."},
{"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."}, {"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."},
@@ -858,6 +862,7 @@ def openapi():
add("/api/hook/hits", "get", "Captured hits for one hook (auto-detected source, headers, body)", {"token": "hook token", "limit": "opt 1-500"}, req=True) add("/api/hook/hits", "get", "Captured hits for one hook (auto-detected source, headers, body)", {"token": "hook token", "limit": "opt 1-500"}, req=True)
add("/api/hook/replay", "post", "Replay a captured hit to any public URL (SSRF-guarded)", {"hit_id": "hit id", "target_url": "https:// target"}, req=True) add("/api/hook/replay", "post", "Replay a captured hit to any public URL (SSRF-guarded)", {"hit_id": "hit id", "target_url": "https:// target"}, req=True)
add("/api/face", "post", "Avatar fingerprint + username pfp harvest + Hamming verdict", {"u": "username (optional)"}, files=["image"]) add("/api/face", "post", "Avatar fingerprint + username pfp harvest + Hamming verdict", {"u": "username (optional)"}, files=["image"])
add("/api/qr", "get", "QR PNG of any launcher script or URL", {"data": "text to encode", "box": "pixel size 3-12"}, req=True)
add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"}) add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"})
add("/api/rotator/pools", "get", "Pool inventory") add("/api/rotator/pools", "get", "Pool inventory")
add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)") add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)")
@@ -4432,6 +4437,109 @@ def api_face():
# ---------- END TOOL: FACE TRACE ---------- # ---------- END TOOL: FACE TRACE ----------
# ---------- TOOL: QR FORGE (shortcut launcher codes) ----------
_QR_STYLES_CSS = """
.qrgrid{display:grid;grid-template-columns:1fr;gap:1.1rem}
@media(min-width:700px){.qrgrid{grid-template-columns:repeat(2,1fr)}}
.qrout{display:flex;flex-direction:column;align-items:center;gap:.6rem;min-height:240px;justify-content:center}
.qrout img{background:#fff;padding:12px;border-radius:12px;max-width:260px;width:100%}
.schemebox{border:1px solid var(--line);border-radius:10px;padding:.7rem .9rem;margin:.5rem 0;font-size:.85rem}
.schemebox b{color:var(--acc2)}
.preset{margin:.3rem .3rem .3rem 0}
"""
# Server-side QR renderer (no external service): tiny pure-python QR encoder
def _qr_png(data, box=6, border=2):
"""Minimal QR encoder (byte mode, ECC L, versions 1-10) — returns PNG bytes."""
try:
import qrcode as _q
img = _q.make(data, border=border, box_size=box)
buf = io.BytesIO(); img.save(buf, "PNG"); return buf.getvalue()
except ImportError:
pass
# fallback: delegate to local shot of the qrserver only if qrcode lib missing
raise RuntimeError("qrcode module unavailable")
_GAL = 'https://icloud.com/shortcuts/'
_SCHEME_DOCS = [
("shortcuts://import-shortcut?url=<galaxy link>", "Apple — installs a shortcut when scanned (iOS shows a one-tap Add confirmation)", "iOS"),
("shortcuts://run-shortcut?name=<name>&input=<text>", "Apple — runs an installed shortcut by name, optional input", "iOS"),
("shortcuts://create-shortcut", "Apple — opens a new empty shortcut editor", "iOS"),
("intent://scan/<path>#Intent;scheme=http;package=com.android.chrome;end", "Android — chrome intent: opens URL in Chrome when scanned", "Android"),
("intent://<path>#Intent;scheme=...;package=...;S.<extra>=<value>;end", "Android — full intent form: scheme, target app package, string extras", "Android"),
("market://details?id=<package>", "Android — opens the Play Store page for an app", "Android"),
("snackbar:// or any app deep link (spotify:, whatsapp://send?text=, tg://msg_url?url=)", "Any app's registered deep link — scannable like a URL", "both"),
]
@app.route("/qrforge")
def qrforge():
body = f"""
<h1>QR <span>FORGE</span></h1><p class=sub>QR codes for launcher scripts: Apple Shortcuts install/run codes and Android intent codes. Scan with the right phone and it fires the shortcut — the phone's own confirm prompt is the only gate, nothing to type.</p>
<div class=card>
<label>Pick a scheme preset — or write your own below</label>
<div>
<button class="ghost preset" onclick="preset(0)">⌘ install shortcut (iOS)</button>
<button class="ghost preset" onclick="preset(1)">⌘ run shortcut (iOS)</button>
<button class="ghost preset" onclick="preset(2)">▸ chrome intent (Android)</button>
<button class="ghost preset" onclick="preset(3)">▸ play store (Android)</button>
<button class="ghost preset" onclick="preset(4)">▸ deep link (spotify/wa/tg)</button>
</div>
<label>Your launcher script</label>
<input id=qin placeholder="shortcuts://import-shortcut?url=https://icloud.com/shortcuts/…" style=width:100% oninput="live()">
<div style=color:var(--dim);font-size:.8rem;margin:.3rem 0 id=hint>the phone that scans runs this — iOS/Android will show their own confirm dialog</div>
<div style=display:flex;gap:.8rem;flex-wrap:wrap;align-items:center>
<label style=margin:0>size</label><select id=qsz onchange="render()"><option value=4>small</option><option value=6 selected>normal</option><option value=9>big</option></select>
<label style=margin:0><input type=checkbox id=qdl style=width:auto checked> direct server-rendered PNG</label>
<button onclick="render()">Forge ▸</button></div>
</div>
<div class=qrgrid>
<div class="card qrout" id=qbox><span style=color:var(--dim)>your code renders here</span></div>
<div class=card><b>Scan behavior cheat-sheet</b>
""" + "".join(f'<div class=schemebox><b>{esc(s)}</b><br>{esc(d)} <span class="tag {"ok" if p=="iOS" else "warn"}">{p}</span></div>' for s, d, p in _SCHEME_DOCS) + """
</div></div>
<div class=card style=color:var(--dim)>API: GET /api/qr?data=<urlencoded>&box=4-12 → PNG (works for agents: any text, any scheme). QRs render server-side — nothing about your script is stored.</div>""" + how([
"Pick a preset or type any scheme command — shortcuts://, intent://, market://, or any app deep link.",
"For iOS install-codes: make your shortcut in the Shortcuts app, share it, copy the icloud.com/shortcuts link, feed it to the import preset.",
"For Android intents: name the target app package and scheme — the scanner hands it to the OS which routes it to the app.",
"Hit Forge — the PNG renders server-side from your exact string, byte for byte.",
"Print it, sticker it, slap it on something. The scanning phone shows its own native confirm prompt before anything runs.",
"Agents: GET /api/qr?data=… returns the raw PNG — no auth, rate limited."])
body += flow("make a phone run a shortcut with one camera tap", [
"<span class=flowrole>you</span> build a shortcut on your iPhone that texts your own number the phone's battery level.",
"<span class=flowrole>you</span> share it → copy the icloud.com/shortcuts/… link → paste into QR FORGE with the install preset.",
"<span class=flowrole>you</span> Forge, print the code, stick it on the fridge.",
"<span class=flowrole>anyone</span> points their iPhone camera at it — iOS pops: 'Add Shortcut?' — one tap and it installs.",
"<span class=flowrole>them</span> a second scan of a run-code fires it — battery text arrives.",
"<span class=flowrole>android</span> same page, intent preset: the code hands a chrome intent to the OS and the page opens."] if False else [
"<span class=flowrole>you</span> build a shortcut on your iPhone that texts your own number the battery level.",
"<span class=flowrole>you</span> share it — copy the icloud.com/shortcuts link — paste it into QR FORGE with the install preset.",
"<span class=flowrole>you</span> hit Forge and print the code on a sticker.",
"<span class=flowrole>them</span> scans it: iOS shows its native 'Add Shortcut?' — one tap, installed.",
"now the run-code variant fires it by name — no typing, no link, the phone just does the thing.",
"<span class=flowrole>android</span> the intent presets do the same dance through Chrome and the Play Store."])
body += gloss([("scheme","the prefix that hands a command to the phone OS — shortcuts://, intent://, market://"),("intent","Android's inter-app command format: scheme + package + extras"),("deep link","an app's private URL scheme that opens it to a specific action"),("package","Android app identifier, e.g. com.android.chrome")])
body += agent_card('GET /api/qr?data=shortcuts%3A%2F%2F…', 'curl -o code.png "https://dark0rbits.thetempleofdoom.com/api/qr?data=intent%3A%2F%2Fscan%23Intent%3Bscheme%3Dhttp%3Bend"', 'Returns PNG bytes. Any scheme accepted — the phone OS is the executor.')
return page("qrforge", body + "<style>" + _QR_STYLES_CSS + "</style>")
@app.route("/api/qr")
def api_qr():
r = rate_limit("qr", 60, 60)
if r: return r
data = (param("data") or "").strip()
if not data: return jsonify({"ok": False, "error": "data required"}), 400
if len(data) > 900: return jsonify({"ok": False, "error": "data too long (900 max)"}), 400
try: box = min(12, max(3, int(param("box") or 6)))
except Exception: box = 6
try:
png = _qr_png(data, box=box)
except Exception as e:
return jsonify({"ok": False, "error": str(e)[:200]}), 500
resp = Response(png, mimetype="image/png")
resp.headers["Cache-Control"] = "public, max-age=86400"
return resp
# ---------- END TOOL: QR FORGE ----------
# ---------- TOOL: ROTATOR ---------- # ---------- TOOL: ROTATOR ----------
import random as _rnd import random as _rnd
import json as _json import json as _json
@@ -5448,6 +5556,7 @@ def index():
("bssid","BSSID RADAR","Turn a WiFi router's MAC into an approximate place on Earth, with map links and accuracy radius.","◈","Hunt"), ("bssid","BSSID RADAR","Turn a WiFi router's MAC into an approximate place on Earth, with map links and accuracy radius.","◈","Hunt"),
("hooks", "HOOK RELAY", "Instant public webhook inspector: capture every callback, auto-detect the sender, replay it anywhere.", "◈", "Operate"), ("hooks", "HOOK RELAY", "Instant public webhook inspector: capture every callback, auto-detect the sender, replay it anywhere.", "◈", "Operate"),
("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"), ("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"),
("qrforge","QR FORGE","QR codes that fire shortcut & intent scripts on scan — Apple Shortcuts install/run, Android intents, deep links. Native phone confirm is the gate.","◈","OPERATE"),
("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"), ("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"),
("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"), ("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"),
("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"), ("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"),