diff --git a/app.py b/app.py index b5118af..f478686 100644 --- a/app.py +++ b/app.py @@ -25,6 +25,9 @@ BMAC = "https://buymeacoffee.com/r26xrthzttg" SITE = "https://dark0rbits.thetempleofdoom.com" def _migrate(con): + cols = [r[1] for r in con.execute("PRAGMA table_info(settings)")] + if not cols: + con.execute("CREATE TABLE IF NOT EXISTS settings(user_id INTEGER, key TEXT, val TEXT, PRIMARY KEY(user_id,key))") cols = [r[1] for r in con.execute("PRAGMA table_info(sms_rentals)")] if "user_id" not in cols: con.execute("ALTER TABLE sms_rentals ADD COLUMN user_id INTEGER DEFAULT 0") @@ -53,6 +56,47 @@ def db(): _migrate(con) return con + +# ---------- USER SETTINGS (visible tunables, agent-settable) ---------- +DEFAULT_SETTINGS = { + "bg": "1", "warp": "1", "parallax": "1", "density": "1.0", "speed": "1.0", "twinkle": "1.0", + "hue": "0", "grid": "1", "scan": "1", "toast": "1", "type": "1", +} +BOOL_SETTINGS = {"bg", "warp", "parallax", "grid", "scan", "toast", "type"} +RANGE_SETTINGS = {"density": (0, 2.5), "speed": (0, 3), "twinkle": (0, 3), "hue": (-180, 180)} + + +def get_settings(uid): + out = dict(DEFAULT_SETTINGS) + if not uid: + return out + con = db() + try: + for r in con.execute("SELECT key,val FROM settings WHERE user_id=?", (uid,)): + if r["key"] in out: + out[r["key"]] = r["val"] + except Exception: + pass + return out + + +def set_setting(uid, key, val): + if key not in DEFAULT_SETTINGS: + return False + if key in BOOL_SETTINGS: + val = "1" if str(val) in ("1", "true", "on", "yes") else "0" + elif key in RANGE_SETTINGS: + try: + lo, hi = RANGE_SETTINGS[key] + val = str(max(lo, min(hi, float(val)))) + except Exception: + return False + con = db() + con.execute("INSERT INTO settings(user_id,key,val) VALUES(?,?,?) ON CONFLICT(user_id,key) DO UPDATE SET val=excluded.val", (uid, key, str(val))) + con.commit() + return True + + # ---------- BILLING CORE (per-call metering for outside users) ---------- def get_balance(uid): con = db() @@ -194,6 +238,13 @@ header{position:sticky;top:0;z-index:40;background:rgba(7,10,19,.86);backdrop-fi .dnav a{color:var(--dim);text-decoration:none;font-size:.72rem;padding:.3rem .55rem;border:1px solid var(--line);border-radius:999px;white-space:nowrap;transition:.15s} .dnav a.on,.dnav a:hover{color:var(--acc);border-color:var(--acc)} .tchip{color:var(--fg);margin-right:.5rem;white-space:nowrap} +.srow{display:flex;align-items:center;gap:.5rem;margin:.45rem 0;font-size:.85rem;color:var(--fg)} +.srow input[type=range]{flex:1;accent-color:var(--acc)} +.srow input[type=checkbox]{accent-color:var(--acc);width:16px;height:16px} +#pinp{background:var(--card);border:1px solid var(--line);border-radius:8px;padding:.6rem;color:var(--fg)} +.pitem{display:block;padding:.5rem .6rem;border:1px solid transparent;border-radius:8px;color:var(--fg);text-decoration:none;cursor:pointer} +.pitem:hover,.pitem.sel{border-color:var(--acc);color:var(--acc)} +.pitem small{display:block;color:var(--dim)} :focus-visible{outline:2px solid var(--acc2);outline-offset:2px;border-radius:4px} .skip{position:absolute;left:-9999px;top:0;z-index:100;background:var(--acc);color:#0d0722;padding:.5rem 1rem;border-radius:0 0 8px 0;font-weight:800} .skip:focus{left:0} @@ -292,6 +343,30 @@ li{text-align:left;margin:.2rem 0}
{{body}}
✦ REACH THE DEV +{{ CFG_JS }} +
⚙
+ + + """ @@ -368,8 +540,10 @@ def page(sec, body): except Exception: acct = "" from markupsafe import Markup - return render_template_string(BASE, body=Markup(body), bmac=BMAC, o=lambda s: "on" if s == sec else "", - n1=n1, n2=n2, acct=acct) + st = get_settings(uid) + return render_template_string(BASE, body=Markup(body), bmac=BMAC, o=lambda s2: "on" if s2 == sec else "", + n1=n1, n2=n2, acct=acct, + CFG_JS="window.DRB=" + json.dumps(st) + ";") @@ -388,6 +562,15 @@ def Redirect(u): return _r(u) + +def agent_card(endpoint, example, notes): + """Interactive-for-LLMs card: exact curl + auth + link to openapi.""" + return ('
FOR AGENTS ' + '?
' + '' + esc(endpoint) + '
' + '' + esc(example) + '
' + esc(notes) + + ' · spec: /openapi.json · catalog: /llms.txt
') + def gloss(terms): chips = " ".join('' + esc(t) + '' for t, d in terms) return '
JARGON — hover any term: ' + chips + '
' @@ -397,10 +580,21 @@ def how(steps): return f'
HOW IT WORKS
    {lis}
' # ---------- AGENT DISCOVERY ---------- +LLMS_SETTINGS = """ +## ACCOUNT TUNABLES (machine-settable) +GET/POST /api/settings — keys: bg, warp, parallax, density (0-2.5), speed (0-3), twinkle (0-3), hue (-180-180), grid, scan, toast, type (1|0). +Agents driving browsers (or building clients) can persist a theme per API key: POST form-encoded key=value. Values validated server-side. +## KEYBOARD +Ctrl+K / Cmd+K — command palette on any page. Type tool name, Enter navigates. +""" API_INDEX = { "service": "dark0rbits", "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.", "endpoints": [ + {"method": "GET/POST", "path": "/api/settings", "desc": "Per-account UI tunables (bg, warp, parallax, density, speed, twinkle, hue, grid, scan, toast, type). Agents can theme their own client. GET returns current; POST form key=val applies (validated + clamped)."}, + {"method": "GET", "path": "/deaddrop", "desc": "Burn-after-read encrypted notes. POST /api/deaddrop/create (body, burn_after 1-10, ttl_hours 1-72, password optional) -> token. 5c, free with PASS."}, + {"method": "GET", "path": "/shot", "desc": "Page capture: POST /api/shot/create {url} then GET /api/shot/status/. SSRF-guarded. 25c, free with PASS."}, + {"method": "GET", "path": "/score", "desc": "Composite fraud score: IP 45% + disposable-email 25% + BIN 30%. 2c, free with PASS."}, {"method": "GET", "path": "/api/ip?target=", "desc": "Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS."}, {"method": "POST", "path": "/api/card", "params": {"num": "card number"}, "desc": "Luhn + BIN intel. Nothing stored/charged."}, {"method": "POST", "path": "/api/sms/rent", "params": {"service": "id/keyword", "country": "id"}, "desc": "Rent disposable number, 30 min, refundable."}, @@ -423,6 +617,19 @@ API_INDEX = { "payment": "BTCPay BTC only (no Stripe). SMS meters to house account; trackables $1 each.", } +@app.route("/api/settings", methods=["GET", "POST"]) +def api_settings(): + uid = key_user() or current_user_id() + if not uid: + return jsonify({"ok": False, "error": "auth required: account session or API key"}), 401 + if request.method == "GET": + return jsonify({"ok": True, "settings": get_settings(uid)}) + out = {} + for k in DEFAULT_SETTINGS: + if k in request.form: + out[k] = set_setting(uid, k, request.form[k]) + return jsonify({"ok": True, "applied": out, "settings": get_settings(uid)}) + @app.route("/api") def api_index(): return jsonify(API_INDEX) @@ -444,7 +651,7 @@ def sitemap(): @app.route("/llms.txt") def llms(): eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']}" for e in API_INDEX["endpoints"]) - return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"} + return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n{LLMS_SETTINGS}", 200, {"Content-Type": "text/plain"} @app.route("/ai-plugin.json") def aiplugin(): @@ -530,6 +737,7 @@ def ip_page(): {extra}
API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
""" + how(["Your IP is auto-detected the moment the page loads — no input needed.","Type any other IP or hostname into the field for the same full report.","Everything is one GET away for agents: /api/ip and /api/ip?target=.","VPN/proxy/hosting flags come from IP-quality heuristics — if it says proxy, you are looking at a relay."]) body += gloss([("ASN","Autonomous System Number — the network operator that owns this route"),("rDNS","reverse DNS — hostname pointer for an IP"),("hosting","datacenter/cloud IP, not a home connection"),("VPN/proxy","known tunnel or relay range")]) + body += agent_card('GET /api/ip?target=1.2.3.4', 'curl "https://dark0rbits.thetempleofdoom.com/api/ip?target=1.2.3.4" -H "Authorization: Bearer drb_..."', 'Auto-detects caller IP if target omitted.') return page("ip", body) def ip_form(): @@ -611,6 +819,7 @@ cn.addEventListener('input',function(){{var v=this.value.replace(/\\D/g,'').slic {result}""" body += gloss([("BIN","first 6-8 digits of a card — identifies issuer, country, brand"),("Luhn","checksum test every real card number passes"),("prepaid","issued as prepaid — elevated fraud risk")]) + body += agent_card('POST /api/card num=4539148803436467', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/card -d num=4539148803436467', 'Luhn + BIN intel. 2c/metered with API key, free with PASS.') return page("card", body) @app.route("/api/card", methods=["POST"]) @@ -1178,6 +1387,7 @@ document.getElementById('ie').addEventListener('change',function(){{document.que
API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
""" + how(["Drop a PNG — your words are written into the least-significant bits of its pixels.","Depth 1 = invisible and robust; depth 2-3 fits more text but is easier to detect.","Spread=randomized scatters bits across the image instead of top-down.","A password encrypts the payload AND derives the scatter pattern — wrong password = noise.","Extract reads the embedded metadata automatically — just drop the file and the words come back."]) body += gloss([("LSB","least significant bit — pixel bits that carry hidden data"),("depth","how many bit planes carry the payload"),("spread","payload dispersed across the image to survive edits")]) + body += agent_card('POST /api/steg/hide image= text=hi [password= bits= spread=]', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/steg/hide -F image=@x.png -F text=hi -F password=hunter2', 'Extract: POST /api/steg/extract. Free with PASS.') return page("steg", body) @app.route("/api/steg/hide", methods=["POST"]) @@ -1679,6 +1889,7 @@ def eh():
API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.
""" + how(["Open the suspicious email → View source → copy ALL headers.","Paste them here — the parser walks the full Received chain.","The real origin IP is pulled from the bottom-most relay hop and geolocated.","SPF/DKIM/DMARC verdicts are extracted and color-coded.","Spoof markers are flagged automatically: envelope≠From domain, Reply-To hijacks."]) body += gloss([("SPF","a domain's list of servers allowed to send its mail"),("DKIM","cryptographic signature on real mail from the domain"),("DMARC","policy for what receivers do when SPF/DKIM fail"),("envelope-from","actual SMTP sender — can differ from the visible From")]) + body += agent_card('POST /api/eh raw=', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/eh --data-urlencode raw@headers.txt', 'Returns origin IP, hop chain, SPF/DKIM/DMARC verdicts, spoof flags.') return page("eh", body) @app.route("/eh_result", methods=["POST"]) @@ -1713,6 +1924,7 @@ def forensics():
API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.
""" + how(["Drop any image — EXIF and GPS get dumped instantly.","Error-level analysis (ELA) re-compresses and diffs: edited regions glow in the amplified view.","Edit-tool tags (Photoshop/GIMP) are flagged automatically.","EXIF-stripped images get flagged too — usually means scrubbed or generated.","If the image carries a DARK0RBITS stego payload, this tool sees it."]) body += gloss([("ELA","error level analysis — regions re-saved after editing light up"),("EXIF","camera/software metadata embedded in the file"),("quantization","JPEG compression-table fingerprints")]) + body += agent_card('POST /api/forensics image=', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/forensics -F image=@img.jpg', 'EXIF dump, GPS, ELA score, editor flags.') return page("forensics", body) def _ela_score(img_bytes): @@ -2038,6 +2250,7 @@ setInterval(function(){{var n=Math.floor(Date.now()/1000);document.querySelector "Share only the /drop/ link — once, over a channel you trust.", "Every open burns a read; the remaining count shows live on the page.", "The final read deletes the row server-side. A tombstone is all that remains."]) + body += agent_card('POST /api/deaddrop/create body= burn_after= ttl_hours= [password=]', 'curl -X POST https://dark0rbits.thetempleofdoom.com/api/deaddrop/create -d body=secret -d burn_after=1 -d ttl_hours=24', 'Returns /drop/. Reader destroys the note at the last read.') return page("deaddrop", body) @app.route("/api/deaddrop/create", methods=["POST"]) @@ -2225,6 +2438,7 @@ def score_page(): "Email: matched against a hardcoded list of burner-mail domains.", "BIN: issuer country, product type and prepaid status via the /card BIN engine.", "Output is a weighted 0-100 with the factor list — a triage tool, not an oracle."]) + body += agent_card('GET /api/score?ip=&email=&bin=', 'curl "https://dark0rbits.thetempleofdoom.com/api/score?ip=1.2.3.4&email=a@mailinator.com&bin=453914" -H "Authorization: Bearer drb_..."', 'Weighted composite; re-normalizes on partial input.') return page("score", body) @app.route("/api/score")