QR FORGE /qrforge — QR codes for launcher scripts: Apple Shortcuts import/run presets, Android chrome intents + market://, app deep links. Server-rendered PNG via /api/qr (no storage, 60/min). Cheat-sheet + example flow.
This commit is contained in:
111
app.py
111
app.py
@@ -371,7 +371,7 @@ li::marker{color:var(--acc)}
|
||||
<a href=/canary class={{o('canary')}}>CANARY</a><a href=/deaddrop class={{o('deaddrop')}}>DEAD-DROP</a><a href=/mail class={{o('mail')}}>BURNER-MAIL</a>
|
||||
<a href=/shot class={{o('shot')}}>SHOT</a><a href=/score class={{o('score')}}>FRAUD-SCORE</a>
|
||||
<a href=/inbox class={{o('inbox')}}>INBOX</a><a href=/passport class={{o('passport')}}>PASSPORT</a>
|
||||
<a href=/pass class={{o('pass')}}>PASS</a><a href=/keys class={{o('keys')}}>KEYS</a><a href=/maglab class={{o('maglab')}}>MAG-LAB</a><a href=/beacon class={{o('beacon')}}>PORT BEACON</a><a href=/bssid class={{o('bssid')}}>BSSID RADAR</a><a href=/hooks class={{o('hooks')}}>HOOK-RELAY</a><a href=/face class={{o('face')}}>FACE TRACE</a><a href=/rotator class={{o('rotator')}}>ROTATOR</a><a href=/shelf class={{o('shelf')}}>SHELF</a><a href=/s class={{o('s')}}>SNAP</a><a href=/unfurl class={{o('unfurl')}}>UNFURL</a><a href=/warp class={{o('warp')}}>WARP</a><a href=/tools class={{o('tools')}}>TOOLS</a>
|
||||
<a href=/pass class={{o('pass')}}>PASS</a><a href=/keys class={{o('keys')}}>KEYS</a><a href=/maglab class={{o('maglab')}}>MAG-LAB</a><a href=/beacon class={{o('beacon')}}>PORT BEACON</a><a href=/bssid class={{o('bssid')}}>BSSID RADAR</a><a href=/hooks class={{o('hooks')}}>HOOK-RELAY</a><a href=/face class={{o('face')}}>FACE TRACE</a><a href=/qrforge class={{o('qrforge')}}>QR-FORGE</a><a href=/rotator class={{o('rotator')}}>ROTATOR</a><a href=/shelf class={{o('shelf')}}>SHELF</a><a href=/s class={{o('s')}}>SNAP</a><a href=/unfurl class={{o('unfurl')}}>UNFURL</a><a href=/warp class={{o('warp')}}>WARP</a><a href=/tools class={{o('tools')}}>TOOLS</a>
|
||||
</div>
|
||||
<div id="acct">{{acct}}</div><button class=burger id=burger onclick="drw()">☰</button>
|
||||
</div></header>
|
||||
@@ -405,6 +405,7 @@ li::marker{color:var(--acc)}
|
||||
<a class="dl {{o('bssid')}}" href=/bssid>◈ BSSID RADAR <small>WiFi router-MAC (BSSID) to approximate geolocation via crowdsourced DB — map links, accuracy radius, batch runs.</small></a>
|
||||
<a class="dl {{o('hooks')}}" href=/hooks>◈ HOOK-RELAY <small>instant public webhook inspector — capture, inspect, replay</small></a>
|
||||
<a class="dl {{o('face')}}" href=/face>◈ FACE TRACE <small>profile-picture triangulation — hash an avatar, harvest a username's pfps, Hamming verdicts</small></a>
|
||||
<a class="dl {{o('qrforge')}}" href=/qrforge>◈ QR-FORGE <small>QR codes for shortcut & intent launcher scripts — scan to execute</small></a>
|
||||
<a class="dl {{o('rotator')}}" href=/rotator>◈ ROTATOR <small>consistent browser identity pools with replayable seeds</small></a>
|
||||
<a class="dl {{o('shelf')}}" href=/shelf>◈ SHELF <small>every burner you own, with live countdowns</small></a>
|
||||
<a class="dl {{o('s')}}" href=/s>◈ SNAP <small>server-free one-click short links — target lives in the #fragment</small></a>
|
||||
@@ -566,6 +567,7 @@ var PAL=[
|
||||
["/bssid", "WiFi router-MAC geolocation"],
|
||||
["/hooks", "webhook inspector \u2014 capture, inspect, replay"],
|
||||
["/face", "avatar pfp triangulation"],
|
||||
["/qrforge", "QR forge \u2014 shortcut & intent launcher codes"],
|
||||
["/rotator", "header rotator \u2014 identity pools + seeds"],
|
||||
["/shelf", "identity shelf \u2014 every burner + countdowns"],
|
||||
["/s", "snap \u2014 server-free short links + safety decoder"],
|
||||
@@ -625,6 +627,7 @@ NEBULAS = {
|
||||
"s": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
|
||||
"shelf": ("rgba(66,232,164,.11)", "rgba(255,170,60,.09)"),
|
||||
"rotator": ("rgba(111,214,255,.12)", "rgba(167,139,250,.10)"),
|
||||
"qrforge": ("rgba(255,201,77,.11)", "rgba(66,232,164,.09)"),
|
||||
"face": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
|
||||
"hooks": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
|
||||
"bssid": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
|
||||
@@ -750,6 +753,7 @@ API_INDEX = {
|
||||
{"method": "GET", "path": "/api/hook/hits?token=", "params": {"token": "hook token", "limit": "1-500, default 100"}, "desc": "Captured hits for one endpoint: method, ts, ip, ua, content-type, source badge (Stripe/GitHub/Discord/Shopify/Telegram auto-detected), full headers, query, body. Login required."},
|
||||
{"method": "POST", "path": "/api/hook/replay", "params": {"hit_id": "captured hit id", "target_url": "https:// destination"}, "desc": "Resend a captured hit (original method, headers, body) to any public URL via http(). SSRF-guarded: 10.x / 127. / 172.16-31 / 169.254 and reserved ranges refused. Login required."},
|
||||
{"method": "POST", "path": "/api/face", "files": ["image"], "params": {"u": "username (optional)"}, "desc": "Face trace: fingerprint an uploaded avatar (dHash 9x8 + aHash 8x8 + sha256, computed locally), harvest the username's avatars (GitHub + Reddit APIs, Telegram/Steam/Twitch constructed links), compare via Hamming distance (<=10/64 = likely same image) + manual reverse-image lead links. No external reverse-image APIs called."},
|
||||
{"method": "GET", "path": "/api/qr?data=", "desc": "Server-rendered QR PNG of any string (shortcuts://, intent://, market://, deep links, URLs). box=3-12 sizes. 900 char max, 60/min, no auth."},
|
||||
{"method": "GET", "path": "/api/rotator?platform=&n=&seed=", "desc": "Spin 1-25 consistent browser identities (UA, referer, Accept-Language, DNT) from desktop/mobile/agent/stealth pools. Same seed = same rotation. Returns identities + ready-made curl. FREE, 20/min."},
|
||||
{"method": "GET", "path": "/api/rotator/pools", "desc": "Pool sizes: desktop, mobile, agent, stealth + referer/language counts."},
|
||||
{"method": "GET", "path": "/api/shelf", "desc": "Identity shelf: all your mailboxes, SMS numbers, dead-drops, canaries + expiry stats in one JSON. Login required. Perfect for expiry-monitoring crons."},
|
||||
@@ -858,6 +862,7 @@ def openapi():
|
||||
add("/api/hook/hits", "get", "Captured hits for one hook (auto-detected source, headers, body)", {"token": "hook token", "limit": "opt 1-500"}, req=True)
|
||||
add("/api/hook/replay", "post", "Replay a captured hit to any public URL (SSRF-guarded)", {"hit_id": "hit id", "target_url": "https:// target"}, req=True)
|
||||
add("/api/face", "post", "Avatar fingerprint + username pfp harvest + Hamming verdict", {"u": "username (optional)"}, files=["image"])
|
||||
add("/api/qr", "get", "QR PNG of any launcher script or URL", {"data": "text to encode", "box": "pixel size 3-12"}, req=True)
|
||||
add("/api/rotator", "get", "Spin consistent browser identities (UA+referer+language+DNT), optional deterministic seed", {"platform": "desktop|mobile|agent|stealth", "n": "1-25", "seed": "optional"})
|
||||
add("/api/rotator/pools", "get", "Pool inventory")
|
||||
add("/api/shelf", "get", "Identity shelf — all burners + expiry stats (login)")
|
||||
@@ -4432,6 +4437,109 @@ def api_face():
|
||||
# ---------- END TOOL: FACE TRACE ----------
|
||||
|
||||
|
||||
# ---------- TOOL: QR FORGE (shortcut launcher codes) ----------
|
||||
_QR_STYLES_CSS = """
|
||||
.qrgrid{display:grid;grid-template-columns:1fr;gap:1.1rem}
|
||||
@media(min-width:700px){.qrgrid{grid-template-columns:repeat(2,1fr)}}
|
||||
.qrout{display:flex;flex-direction:column;align-items:center;gap:.6rem;min-height:240px;justify-content:center}
|
||||
.qrout img{background:#fff;padding:12px;border-radius:12px;max-width:260px;width:100%}
|
||||
.schemebox{border:1px solid var(--line);border-radius:10px;padding:.7rem .9rem;margin:.5rem 0;font-size:.85rem}
|
||||
.schemebox b{color:var(--acc2)}
|
||||
.preset{margin:.3rem .3rem .3rem 0}
|
||||
"""
|
||||
|
||||
# Server-side QR renderer (no external service): tiny pure-python QR encoder
|
||||
def _qr_png(data, box=6, border=2):
|
||||
"""Minimal QR encoder (byte mode, ECC L, versions 1-10) — returns PNG bytes."""
|
||||
try:
|
||||
import qrcode as _q
|
||||
img = _q.make(data, border=border, box_size=box)
|
||||
buf = io.BytesIO(); img.save(buf, "PNG"); return buf.getvalue()
|
||||
except ImportError:
|
||||
pass
|
||||
# fallback: delegate to local shot of the qrserver only if qrcode lib missing
|
||||
raise RuntimeError("qrcode module unavailable")
|
||||
|
||||
_GAL = 'https://icloud.com/shortcuts/'
|
||||
_SCHEME_DOCS = [
|
||||
("shortcuts://import-shortcut?url=<galaxy link>", "Apple — installs a shortcut when scanned (iOS shows a one-tap Add confirmation)", "iOS"),
|
||||
("shortcuts://run-shortcut?name=<name>&input=<text>", "Apple — runs an installed shortcut by name, optional input", "iOS"),
|
||||
("shortcuts://create-shortcut", "Apple — opens a new empty shortcut editor", "iOS"),
|
||||
("intent://scan/<path>#Intent;scheme=http;package=com.android.chrome;end", "Android — chrome intent: opens URL in Chrome when scanned", "Android"),
|
||||
("intent://<path>#Intent;scheme=...;package=...;S.<extra>=<value>;end", "Android — full intent form: scheme, target app package, string extras", "Android"),
|
||||
("market://details?id=<package>", "Android — opens the Play Store page for an app", "Android"),
|
||||
("snackbar:// or any app deep link (spotify:, whatsapp://send?text=, tg://msg_url?url=)", "Any app's registered deep link — scannable like a URL", "both"),
|
||||
]
|
||||
|
||||
@app.route("/qrforge")
|
||||
def qrforge():
|
||||
body = f"""
|
||||
<h1>QR <span>FORGE</span></h1><p class=sub>QR codes for launcher scripts: Apple Shortcuts install/run codes and Android intent codes. Scan with the right phone and it fires the shortcut — the phone's own confirm prompt is the only gate, nothing to type.</p>
|
||||
<div class=card>
|
||||
<label>Pick a scheme preset — or write your own below</label>
|
||||
<div>
|
||||
<button class="ghost preset" onclick="preset(0)">⌘ install shortcut (iOS)</button>
|
||||
<button class="ghost preset" onclick="preset(1)">⌘ run shortcut (iOS)</button>
|
||||
<button class="ghost preset" onclick="preset(2)">▸ chrome intent (Android)</button>
|
||||
<button class="ghost preset" onclick="preset(3)">▸ play store (Android)</button>
|
||||
<button class="ghost preset" onclick="preset(4)">▸ deep link (spotify/wa/tg)</button>
|
||||
</div>
|
||||
<label>Your launcher script</label>
|
||||
<input id=qin placeholder="shortcuts://import-shortcut?url=https://icloud.com/shortcuts/…" style=width:100% oninput="live()">
|
||||
<div style=color:var(--dim);font-size:.8rem;margin:.3rem 0 id=hint>the phone that scans runs this — iOS/Android will show their own confirm dialog</div>
|
||||
<div style=display:flex;gap:.8rem;flex-wrap:wrap;align-items:center>
|
||||
<label style=margin:0>size</label><select id=qsz onchange="render()"><option value=4>small</option><option value=6 selected>normal</option><option value=9>big</option></select>
|
||||
<label style=margin:0><input type=checkbox id=qdl style=width:auto checked> direct server-rendered PNG</label>
|
||||
<button onclick="render()">Forge ▸</button></div>
|
||||
</div>
|
||||
<div class=qrgrid>
|
||||
<div class="card qrout" id=qbox><span style=color:var(--dim)>your code renders here</span></div>
|
||||
<div class=card><b>Scan behavior cheat-sheet</b>
|
||||
""" + "".join(f'<div class=schemebox><b>{esc(s)}</b><br>{esc(d)} <span class="tag {"ok" if p=="iOS" else "warn"}">{p}</span></div>' for s, d, p in _SCHEME_DOCS) + """
|
||||
</div></div>
|
||||
<div class=card style=color:var(--dim)>API: GET /api/qr?data=<urlencoded>&box=4-12 → PNG (works for agents: any text, any scheme). QRs render server-side — nothing about your script is stored.</div>""" + how([
|
||||
"Pick a preset or type any scheme command — shortcuts://, intent://, market://, or any app deep link.",
|
||||
"For iOS install-codes: make your shortcut in the Shortcuts app, share it, copy the icloud.com/shortcuts link, feed it to the import preset.",
|
||||
"For Android intents: name the target app package and scheme — the scanner hands it to the OS which routes it to the app.",
|
||||
"Hit Forge — the PNG renders server-side from your exact string, byte for byte.",
|
||||
"Print it, sticker it, slap it on something. The scanning phone shows its own native confirm prompt before anything runs.",
|
||||
"Agents: GET /api/qr?data=… returns the raw PNG — no auth, rate limited."])
|
||||
body += flow("make a phone run a shortcut with one camera tap", [
|
||||
"<span class=flowrole>you</span> build a shortcut on your iPhone that texts your own number the phone's battery level.",
|
||||
"<span class=flowrole>you</span> share it → copy the icloud.com/shortcuts/… link → paste into QR FORGE with the install preset.",
|
||||
"<span class=flowrole>you</span> Forge, print the code, stick it on the fridge.",
|
||||
"<span class=flowrole>anyone</span> points their iPhone camera at it — iOS pops: 'Add Shortcut?' — one tap and it installs.",
|
||||
"<span class=flowrole>them</span> a second scan of a run-code fires it — battery text arrives.",
|
||||
"<span class=flowrole>android</span> same page, intent preset: the code hands a chrome intent to the OS and the page opens."] if False else [
|
||||
"<span class=flowrole>you</span> build a shortcut on your iPhone that texts your own number the battery level.",
|
||||
"<span class=flowrole>you</span> share it — copy the icloud.com/shortcuts link — paste it into QR FORGE with the install preset.",
|
||||
"<span class=flowrole>you</span> hit Forge and print the code on a sticker.",
|
||||
"<span class=flowrole>them</span> scans it: iOS shows its native 'Add Shortcut?' — one tap, installed.",
|
||||
"now the run-code variant fires it by name — no typing, no link, the phone just does the thing.",
|
||||
"<span class=flowrole>android</span> the intent presets do the same dance through Chrome and the Play Store."])
|
||||
body += gloss([("scheme","the prefix that hands a command to the phone OS — shortcuts://, intent://, market://"),("intent","Android's inter-app command format: scheme + package + extras"),("deep link","an app's private URL scheme that opens it to a specific action"),("package","Android app identifier, e.g. com.android.chrome")])
|
||||
body += agent_card('GET /api/qr?data=shortcuts%3A%2F%2F…', 'curl -o code.png "https://dark0rbits.thetempleofdoom.com/api/qr?data=intent%3A%2F%2Fscan%23Intent%3Bscheme%3Dhttp%3Bend"', 'Returns PNG bytes. Any scheme accepted — the phone OS is the executor.')
|
||||
return page("qrforge", body + "<style>" + _QR_STYLES_CSS + "</style>")
|
||||
|
||||
@app.route("/api/qr")
|
||||
def api_qr():
|
||||
r = rate_limit("qr", 60, 60)
|
||||
if r: return r
|
||||
data = (param("data") or "").strip()
|
||||
if not data: return jsonify({"ok": False, "error": "data required"}), 400
|
||||
if len(data) > 900: return jsonify({"ok": False, "error": "data too long (900 max)"}), 400
|
||||
try: box = min(12, max(3, int(param("box") or 6)))
|
||||
except Exception: box = 6
|
||||
try:
|
||||
png = _qr_png(data, box=box)
|
||||
except Exception as e:
|
||||
return jsonify({"ok": False, "error": str(e)[:200]}), 500
|
||||
resp = Response(png, mimetype="image/png")
|
||||
resp.headers["Cache-Control"] = "public, max-age=86400"
|
||||
return resp
|
||||
# ---------- END TOOL: QR FORGE ----------
|
||||
|
||||
|
||||
# ---------- TOOL: ROTATOR ----------
|
||||
import random as _rnd
|
||||
import json as _json
|
||||
@@ -5448,6 +5556,7 @@ def index():
|
||||
("bssid","BSSID RADAR","Turn a WiFi router's MAC into an approximate place on Earth, with map links and accuracy radius.","◈","Hunt"),
|
||||
("hooks", "HOOK RELAY", "Instant public webhook inspector: capture every callback, auto-detect the sender, replay it anywhere.", "◈", "Operate"),
|
||||
("face","FACE TRACE","Hash an avatar, harvest a username's profile pictures across platforms, and get Hamming verdicts — no reverse-image APIs.","◈","Hunt"),
|
||||
("qrforge","QR FORGE","QR codes that fire shortcut & intent scripts on scan — Apple Shortcuts install/run, Android intents, deep links. Native phone confirm is the gate.","◈","OPERATE"),
|
||||
("rotator","ROTATOR","Spin consistent browser identities from four pools with replayable seeds.","◈","UTILITY"),
|
||||
("shelf","IDENTITY SHELF","Every burner you own on one page — mailboxes, numbers, drops, traps — with live countdowns so nothing dies silently.","◈","ACCOUNT"),
|
||||
("s","SNAP LINKS","One-click short links with zero server storage — the target rides in the #fragment, decodes in the opener's browser, with a safety preview and QR.","◈","UTILITY"),
|
||||
|
||||
Reference in New Issue
Block a user