" for k, v in hdrs.items())
+ extra = ""
+ if mine:
+ hdrs = {k: v for k, v in request.headers.items() if k.lower() in ("user-agent","accept-language","x-forwarded-for","cf-connecting-ip","cf-ipcountry")}
+ extra = '
Headers you sent
' + "".join(f"
{esc(k)}
{esc(v)}
" for k, v in hdrs.items()) + "
"
body = f"""
-
WHATS MY IP
Every drop of intel we can legally scrape, always on.
+
{heading}
Auto-detects your IP and shows everything. Want intel on another IP? Type it below — full report, any target.
{kv(rows)}
-
Headers you sent
{hdr_rows}
-
Live check — your browser also resolved this page in
-….
-
API: GET /api/ip → same data as JSON. Agent-friendly.
"""
+
+{extra}
+
API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
"""
return page("ip", body)
+def ip_form():
+ return ''
+
@app.route("/api/ip")
def api_ip():
+ target = param("target")
+ if target and target.strip():
+ return jsonify(ip_report(target.strip()))
ip = request.headers.get("X-Real-IP") or request.remote_addr or ""
- st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
- d = jf(b) or {}
- d["headers_seen"] = {k: v for k, v in request.headers.items()}
+ d = ip_report(ip)
+ d["headers_seen"] = dict(request.headers)
return jsonify(d)
# ---------- 2. CARD CHECK ----------
def luhn_ok(num):
digits = [int(c) for c in num]
- odd = digits[-1::-2]; even = digits[-2::-2]
- s = sum(odd)
- for d in even:
+ s = sum(digits[-1::-2])
+ for d in digits[-2::-2]:
d *= 2
if d > 9: d -= 9
s += d
@@ -213,48 +267,6 @@ def brand_of(num):
if num.startswith(pfx): return b
return "Unknown"
-@app.route("/card", methods=["GET", "POST"])
-def card():
- result = ""
- num = re.sub(r"\D", "", request.form.get("num", ""))[:19]
- if num:
- tags = []
- ok = luhn_ok(num)
- tags.append(('LUHN VALID' if ok else 'LUHN INVALID — fake/dead number'))
- brand = brand_of(num)
- bin8 = num[:8]
- bl = bin_lookup(bin8)
- bank = (bl.get("bank") or {}).get("name", "—")
- country = (bl.get("country") or {}).get("name", "—")
- ctype = bl.get("type", "—")
- prepaid = bl.get("prepaid", "—")
- if not bl: tags.append('BIN DB no data — structure-only result')
- flags = []
- if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants")
- if ctype == "debit": flags.append("DEBIT")
- if ctype == "credit": flags.append("CREDIT")
- length = len(num)
- rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,),}.get(brand, (13,15,16,19))
- if length not in rng: tags.append(f'LENGTH {length} WRONG for {brand}')
- else: tags.append(f'length {length} valid for {brand}')
- result = f"""
-{kv([("Brand",brand),("BIN",bin8),("Bank / Issuer",bank),("Country",country),("Type",str(ctype)),("Prepaid",str(prepaid))])}
-
Nothing is stored. No charge, no auth, no $0 check — this is BIN + math validation only.
-It cannot tell you if a card has available funds. Fraud "flagged" status lives at the issuer, not in any database we can legally query.
"""
- body = f"""
-
CARD CHECK
Is it real? Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.
-
-
Paste anything — spaces, dashes, junk all stripped. Nothing stored.
-
-{result}"""
- return page("card", body)
-
def bin_lookup(bin8):
st, b = http(f"https://lookup.binlist.net/{bin8}", headers={"Accept-Version": "3"})
bl = jf(b) or {}
@@ -262,10 +274,42 @@ def bin_lookup(bin8):
st, b = http(f"https://data.handyapi.com/bin/{bin8}")
h = jf(b) or {}
if h.get("Status") == "SUCCESS":
- return {"bank": {"name": h.get("Issuer")}, "country": {"name": h.get("Country", {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")},
+ return {"bank": {"name": h.get("Issuer")}, "country": {"name": (h.get("Country") or {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")},
"type": str(h.get("Type", "")).lower() or None, "prepaid": "prepaid" in str(h.get("Type","")).lower() or None, "scheme": h.get("Scheme")}
return bl
+@app.route("/card", methods=["GET", "POST"])
+def card():
+ result = ""
+ num = re.sub(r"\D", "", param("num") or "")[:19]
+ if num:
+ ok = luhn_ok(num)
+ tags = ['LUHN VALID' if ok else 'LUHN INVALID — fake/dead number']
+ brand = brand_of(num)
+ bl = bin_lookup(num[:8])
+ bank = (bl.get("bank") or {}).get("name", "—")
+ country = (bl.get("country") or {}).get("name", "—")
+ ctype = bl.get("type", "—")
+ prepaid = bl.get("prepaid", "—")
+ flags = []
+ if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants")
+ rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand,(13,15,16,19))
+ tags.append(f'length {len(num)} valid for {brand}' if len(num) in rng else f'LENGTH {len(num)} WRONG for {brand}')
+ result = f"""
+{kv([("Brand",brand),("BIN",num[:8]),("Bank / Issuer",esc(bank)),("Country",esc(country)),("Type",str(ctype)),("Prepaid",str(prepaid))])}
+
+
+{result}"""
+ return page("card", body)
+
@app.route("/api/card", methods=["POST"])
def api_card():
num = re.sub(r"\D", "", param("num") or "")[:19]
@@ -278,43 +322,36 @@ def api_card():
"type": bl.get("type"), "prepaid": bl.get("prepaid")},
"flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])})
-# ---------- SMS ABUSE GUARD ----------
-def sms_guard():
- """Return None if allowed, else a JSON-able reason string."""
- con = db(); now = int(time.time())
- ip = request.headers.get("X-Real-IP") or request.remote_addr or "?"
- # balance: refuse if house SMSPool balance below $5
- st, b = sms_api("request/balance")
- bal = jf(b) or {}
- try: bal = float(bal.get("balance", 0))
- except Exception: bal = 0
- if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused"
- # per-IP: max 1 active rental, 3/hour, 8/day
- row = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND purchase_id IN (SELECT purchase_id FROM sms_rentals WHERE created > ?)", (now-86400*7,)).fetchone()
- # active count overall (any IP) cap 3 concurrent
- act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"]
- if act >= 3: return "too many active rentals right now — try again later"
- h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"]
- if h >= 6: return "hourly rental cap reached"
- d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"]
- if d >= 15: return "daily rental cap reached"
- return None
-
# ---------- 3. SMS RENTALS ----------
SMSP = "https://api.smspool.net"
SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")]
COUNTRIES = [("1","United States"),("2","United Kingdom"),("4","Netherlands"),("22","Russia"),("150","Germany")]
def sms_api(path, **kw):
- if kw:
+ if kw:
kw["key"] = SMSP_KEY
- data = urllib.parse.urlencode(kw).encode()
- return http(f"{SMSP}/{path}", data=data, method="POST")
+ return http(f"{SMSP}/{path}", data=urllib.parse.urlencode(kw).encode(), method="POST")
return http(f"{SMSP}/{path}?key={SMSP_KEY}")
+def sms_guard():
+ con = db(); now = int(time.time())
+ uid = current_user_id()
+ st, b = sms_api("request/balance")
+ bal = jf(b) or {}
+ try: bal = float(bal.get("balance", 0))
+ except Exception: bal = 0
+ if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused"
+ act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"]
+ if act >= (5 if has_pass(uid) else 3): return "too many active rentals right now — try again later"
+ h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"]
+ if h >= (20 if has_pass(uid) else 6): return "hourly rental cap reached"
+ d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"]
+ if d >= (50 if has_pass(uid) else 15): return "daily rental cap reached"
+ return None
+
@app.route("/sms", methods=["GET", "POST"])
def sms():
- msg, listing = "", ""
+ msg = ""
if request.method == "POST":
act = request.form.get("act")
if act == "rent":
@@ -322,64 +359,47 @@ def sms():
if guard:
msg = f'
PAUSED {guard}
'
else:
- svc, ctry = request.form["service"], request.form["country"]
- st, b = sms_api("purchase/sms", service=svc, country=ctry)
+ st, b = sms_api("purchase/sms", service=request.form["service"], country=request.form["country"])
d = jf(b) or {}
if d.get("success") == 1:
- con = db()
- now = int(time.time())
+ con = db(); now = int(time.time())
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
- (d.get("number"), svc, ctry, str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
+ (d.get("number"), request.form["service"], request.form["country"], str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
con.commit()
- msg = f'
RENTED Your number: +{d.get("number")} · expires in 30 min · order #{d.get("purchase_id")}
'
+ msg = f'
RENTED Your number: +{d.get("number")} · 30 min · order #{d.get("purchase_id")}
'
else:
- msg = f'
RENT FAILED
{b[:400]}
'
+ msg = f'
RENT FAILED
{esc(b[:400])}
'
elif act == "check":
- pid = request.form["pid"]
- st, b = sms_api("sms/check", orderid=pid)
+ st, b = sms_api("sms/check", orderid=request.form["pid"])
d = jf(b) or {}
sms_txt = d.get("sms") or d.get("code") or ""
status = d.get("status", "?")
- color = "ok" if sms_txt else "warn"
- msg = f'
STATUS: {status} {"" + str(sms_txt) + "" if sms_txt else "no code yet — poll again in 10s"}
'
+ msg = f'
STATUS: {status} {"" + esc(sms_txt) + "" if sms_txt else "no code yet — poll again in 10s"}
'
elif act == "cancel":
- pid = request.form["pid"]
- st, b = sms_api("sms/cancel", orderid=pid)
+ st, b = sms_api("sms/cancel", orderid=request.form["pid"])
d = jf(b) or {}
ok = d.get("success") == 1
- con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", pid)); con.commit()
+ con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", request.form["pid"])); con.commit()
msg = f'
{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}
'
- st, b = sms_api("sms/instructions")
con = db()
hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall()
hist_rows = "".join(f"
'
else:
con = db()
con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], "", "", 0, int(time.time())))
con.commit()
- result = f'
AUTH/TUNNEL FAILED
{resp[:200]!r}
'
+ result = f'
AUTH/TUNNEL FAILED
{esc(resp[:200])}
'
except Exception as e:
- result = f'
ERROR {e}
'
+ result = f'
ERROR {esc(e)}
'
body = f"""
-
PROXY LAB
Rent residential proxies on the Pleiades rail — your existing gateway user:pass works here, same keys as everywhere.
+
PROXY LAB
Test + rent residential proxies on the Pleiades rail — same gateway keys as everywhere.
{result}
-
Geo session builder — append these to your password to steer the egress:
+
Geo session builder:
yourpassword
-
Chain them: pass_region-us_session-x9k2_lifetime-30m. Same gateway keys as the storefront.
-
-
Rent more — buy GB plans & geo-targeted sessions at the storefront:
-{PLEIADES_APP}.
Pay $1 BTC → upload a file or picture → get a tracked link + an email-ready version. Every open pings back into your INBOX.
+
+1 · Pay $1
+
BTCPay BTC only. After payment the upload opens automatically.
+{mine}
+
How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. Login (no KYC) to see events.
+
API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
"""
+ return page("track", body)
+
+def btc_invoice(amount="1.00"):
+ st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
+ headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
+ data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "auriga-track"}}).encode(), method="POST")
+ return jf(b) or {}
+
+@app.route("/api/track/create", methods=["POST"])
+def api_track_create():
+ fn = param("filename") or "file"
+ uid = current_user_id()
+ token = secrets.token_urlsafe(16)
+ con = db()
+ if has_pass(uid):
+ con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)",
+ (uid or 0, token, esc(fn[:100]), "file", "PASS", int(time.time())))
+ con.commit()
+ return jsonify({"ok": True, "free": True, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"})
+ inv = btc_invoice()
+ if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
+ con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)",
+ (uid or 0, token, esc(fn[:100]), "file", inv["id"], int(time.time())))
+ con.commit()
+ return jsonify({"ok": True, "invoice_id": inv["id"], "checkoutLink": inv.get("checkoutLink"), "token": token,
+ "after_payment_upload_url": f"{SITE}/track/pay?token={token}"})
+
+@app.route("/track/pay", methods=["GET"])
+def track_pay():
+ token = param("token") or ""
+ con = db()
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if not t: return page("track", "
TRACK FILE
unknown token
")
+ return page("track", f"""
+
TRACK FILE
Upload your file — then it's trackable.
+
+""")
+
+@app.route("/api/track/upload", methods=["POST"])
+def api_track_upload():
+ token = param("token")
+ f = request.files.get("file")
+ if not f: return jsonify({"ok": False, "error": "file required"}), 400
+ con = db()
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if not t: return jsonify({"ok": False, "error": "unknown token"}), 400
+ st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] != "PASS" else (200, '{"status":"settled"}')
+ inv = jf(b) or {}
+ paid = inv.get("status") in ("settled", "processing", "paid")
+ if not paid: return jsonify({"ok": False, "error": f"invoice not paid yet ({inv.get('status')})"}), 402
+ data = f.read()
+ open(os.path.join(UPLOAD_DIR, token + ".bin"), "wb").write(data)
+ kind = "image" if (f.content_type or "").startswith("image") else "file"
+ fn = (f.filename or t["filename"])[:100]
+ con.execute("UPDATE trackables SET paid=1, kind=?, filename=? WHERE token=?", (kind, fn, token))
+ con.commit()
+ b64 = base64.b64encode(data).decode()
+ pixel = f"{SITE}/t/{token}.png"
+ if kind == "image":
+ viewer = f''
+ else:
+ viewer = f'
'
+ open(os.path.join(UPLOAD_DIR, token + ".html"), "w").write(viewer)
+ con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)", (t["id"], int(time.time()), "created", "upload"))
+ con.commit()
+ return jsonify({"ok": True, "tracked_link": f"{SITE}/t/{token}", "pixel": pixel,
+ "email_html": f"{SITE}/t/{token}/html",
+ "note": "attach/email the HTML version — every view fires the pixel and lands in the inbox"})
+
+@app.route("/t/")
+def tracked_download(token):
+ con = db()
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if not t or not t["paid"]: return "not found", 404
+ con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)",
+ (t["id"], int(time.time()), request.headers.get("X-Real-IP") or request.remote_addr, request.headers.get("User-Agent","")))
+ uid = t["user_id"]
+ if uid:
+ con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)",
+ (uid, "operator-bot", f"👁 your tracked file '{esc(t['filename'])}' was just opened — IP {esc(request.headers.get('X-Real-IP') or request.remote_addr)}, device: {esc(request.headers.get('User-Agent','')[:80])}", int(time.time())))
+ con.commit()
+ path = os.path.join(UPLOAD_DIR, token + ".bin")
+ if not os.path.exists(path): return "file gone", 404
+ return send_file(path, as_attachment=True, download_name=t["filename"])
+
+@app.route("/t/.png")
+def tracked_pixel(token):
+ con = db()
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if t and t["paid"]:
+ con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)",
+ (t["id"], int(time.time()), request.headers.get("X-Real-IP") or request.remote_addr, request.headers.get("User-Agent","")))
+ uid = t["user_id"]
+ if uid:
+ con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)",
+ (uid, "operator-bot", f"👁 '{esc(t['filename'])}' was just viewed (email/pixel) — IP {esc(request.headers.get('X-Real-IP') or request.remote_addr)}", int(time.time())))
+ con.commit()
+ px = base64.b64decode("R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7")
+ return Response(px, mimetype="image/gif", headers={"Cache-Control": "no-store"})
+
+@app.route("/t//html")
+def tracked_html(token):
+ con = db()
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if not t or not t["paid"]: return "not found", 404
+ p = os.path.join(UPLOAD_DIR, token + ".html")
+ return send_file(p, mimetype="text/html") if os.path.exists(p) else ("no html wrapper", 404)
+
+@app.route("/api/track/events", methods=["GET"])
+def api_track_events():
+ con = db(); token = param("token")
+ t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
+ if not t: return jsonify({"ok": False, "error": "unknown token"})
+ uid = current_user_id()
+ if not uid or uid != t["user_id"]: return jsonify({"ok": False, "error": "auth required (login on /inbox)"})
+ return jsonify([dict(r) for r in con.execute("SELECT * FROM track_events WHERE trackable_id=? ORDER BY id DESC LIMIT 100", (t["id"],))])
+
+# ---------- 6b. BURNER MAIL (receive-only, BTC packages) ----------
+MAIL_PACKS = [("7","7 days — $3",3,7),("30","30 days — $8",8,30),("90","90 days — $20",20,90)]
+MAIL_DOMAIN = "thetempleofdoom.com"
+MAIL_RESERVED = {"indianaholmes","admin","operator","drjones","root","noreply","support","pass","mail"}
+MAIL_SECRET = "auriga-mail-relay-2026"
+
+@app.route("/mail", methods=["GET"])
+def mail():
+ uid = current_user_id()
+ mine = ""
+ if uid:
+ con = db(); now = int(time.time())
+ con.execute("UPDATE mailboxes SET paid=2 WHERE paid=1 AND expires < ?", (now,)) # expired
+ rows = con.execute("SELECT * FROM mailboxes WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall()
+ if rows:
+ trs = "".join(f"
Receive-only disposable mailboxes @thetempleofdoom.com. Counting down in real time. Anything you sign up for — codes, confirmations, one-off handouts — lands right here, no other identity attached.
+
+Pick a package (BTC)
+{''.join(f'' for d,n,_,_ in MAIL_PACKS)}
+
Type your desired mailbox name, pick a length, pay the invoice — the mailbox activates the moment the payment settles.
+{mine}
+
API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
"""
+ return page("steg", body)
+
+@app.route("/api/mail/create", methods=["POST"])
+def api_mail_create():
+ uid = current_user_id()
+ local = re.sub(r"[^a-z0-9._-]", "", (param("local") or "").lower())[:30]
+ days = param("days") or "7"
+ pack = next((p for p in MAIL_PACKS if p[0] == str(days)), None)
+ if not pack: return jsonify({"ok": False, "error": "bad package"}), 400
+ if not local: return jsonify({"ok": False, "error": "mailbox name required"}), 400
+ if local in MAIL_RESERVED: return jsonify({"ok": False, "error": "reserved name"}), 400
+ addr = f"{local}@{MAIL_DOMAIN}"
+ con = db()
+ if con.execute("SELECT 1 FROM mailboxes WHERE address=?", (addr,)).fetchone():
+ return jsonify({"ok": False, "error": "mailbox name taken"}), 400
+ inv = btc_invoice(f"{pack[2]:.2f}")
+ if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
+ con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
+ (uid or 0, addr, inv["id"], 0, 0, int(time.time()), pack[3]))
+ con.commit()
+ return jsonify({"ok": True, "address": addr, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
+
+@app.route("/api/mail/inbound", methods=["POST"])
+def api_mail_inbound():
+ d = request.get_json(silent=True) or {}
+ if d.get("secret") != MAIL_SECRET: return jsonify({"ok": False}), 403
+ addr = (d.get("mailbox") or "").lower().split("@")[0]
+ con = db()
+ m = con.execute("SELECT * FROM mailboxes WHERE address LIKE ? AND paid=1", (addr + "@%",)).fetchone()
+ if not m: return jsonify({"ok": False, "error": "unknown/expired mailbox"}), 404
+ con.execute("INSERT INTO mails(mailbox_id,sender,subject,body,ts) VALUES(?,?,?,?,?)",
+ (m["id"], esc(d.get("from") or "?"), esc(d.get("subject") or ""), esc(d.get("body") or ""), int(time.time())))
+ con.execute("UPDATE mailboxes SET cnt=cnt+1 WHERE id=?", (m["id"],))
+ con.commit()
+ return jsonify({"ok": True})
+
+@app.route("/mail/view")
+def mail_view():
+ uid = current_user_id()
+ if not uid: return page("inbox", "
login required
")
+ addr = param("addr") or ""
+ con = db()
+ m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr.lower(), uid)).fetchone()
+ if not m: return page("inbox", "
not your mailbox
")
+ mails = con.execute("SELECT * FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],)).fetchall()
+ rows = "".join(f'
+""")
+
+@app.route("/api/mail/inbox")
+def api_mail_inbox():
+ uid = current_user_id()
+ if not uid: return jsonify({"ok": False, "error": "login required (POST /inbox act=login)"})
+ con = db(); addr = (param("addr") or "").lower()
+ m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr, uid)).fetchone()
+ if not m: return jsonify({"ok": False, "error": "unknown mailbox"})
+ return jsonify([dict(r) for r in con.execute("SELECT sender,subject,body,ts FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],))])
+
+# ---------- 6c. PASS — all-tools subscription ----------
+PASS_PACKS = [("30","1 month — $10 BTC",10,30),("90","3 months — $25 (save 17%)",25,90),("365","1 year — $80 (save 33%)",80,365)]
+
+def has_pass(uid):
+ if not uid: return False
+ con = db()
+ r = con.execute("SELECT 1 FROM passes WHERE user_id=? AND expires > ? AND paid=1", (uid, int(time.time()))).fetchone()
+ return bool(r)
+
+@app.route("/pass", methods=["GET"])
+def pass_page():
+ uid = current_user_id()
+ mine = ""
+ if uid:
+ con = db()
+ r = con.execute("SELECT * FROM passes WHERE user_id=? AND paid=1 ORDER BY expires DESC LIMIT 1", (uid,)).fetchone()
+ if r and r["expires"] > int(time.time()):
+ left = r["expires"] - int(time.time())
+ mine = f'
PASS ACTIVE {left//86400} days {left%86400//3600}h left — all tools unlimited (proxy rentals still metered at the storefront), trackables free, burner mail discounts.
'
+ body = f"""
+
PASS — ALL ACCESS
One BTC payment. Near-unlimited everything on this site: unlimited SMS rentals (house caps still apply for sanity), free trackables, burner mail included, no per-tool payments.
+
+{''.join(f'' for d,n,_,_ in PASS_PACKS)}
+
Proxy rentals stay separate (they burn real upstream bandwidth — buy those at the storefront).
+{mine}
+
API: POST /api/pass/create (days=30|90|365) → invoice. Pass activates on payment settle via webhook.
"""
+ return page("sms", body)
+
+@app.route("/api/pass/create", methods=["POST"])
+def api_pass_create():
+ uid = current_user_id()
+ if not uid: return jsonify({"ok": False, "error": "login first (POST /inbox act=login)"}), 401
+ days = param("days") or "30"
+ pack = next((p for p in PASS_PACKS if p[0] == str(days)), None)
+ if not pack: return jsonify({"ok": False, "error": "bad package"}), 400
+ inv = btc_invoice(f"{pack[2]:.2f}")
+ if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
+ con = db()
+ con.execute("INSERT INTO passes(user_id,invoice_id,paid,expires,plan_days) VALUES(?,?,0,0,?)", (uid, inv["id"], pack[3]))
+ con.commit()
+ return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
+
+@app.route("/api/btcpay/webhook", methods=["POST"])
+def btcpay_webhook():
+ sig = request.headers.get("BTCPay-Sig", "")
+ body = request.get_data()
+ expect = "sha256=" + hmac.new(BTCPAY_WHSEC.encode(), body, hashlib.sha256).hexdigest()
+ if sig != expect: return jsonify({"ok": False, "error": "bad sig"}), 400
+ d = jf(body) or {}
+ if d.get("type") == "InvoiceSettled" or (d.get("type") == "InvoicePaymentSettled"):
+ iid = d.get("invoiceId")
+ con = db()
+ con.execute("UPDATE trackables SET paid=1 WHERE invoice_id=?", (iid,))
+ r = con.execute("SELECT plan_days FROM mailboxes WHERE invoice_id=?", (iid,)).fetchone()
+ if r:
+ con.execute("UPDATE mailboxes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 7), iid))
+ r = con.execute("SELECT plan_days FROM passes WHERE invoice_id=?", (iid,)).fetchone()
+ if r:
+ con.execute("UPDATE passes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 30), iid))
+ con.commit()
+ return jsonify({"ok": True})
+
+# ---------- 7. INBOX (no-KYC site-only messaging) ----------
+def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"auriga-salt", n=16384, r=8, p=1).hex()
+
+def current_user_id():
+ tok = request.cookies.get("auriga_tok")
+ if not tok: return None
+ con = db()
+ s = con.execute("SELECT user_id FROM sessions WHERE token=?", (tok,)).fetchone()
+ return s["user_id"] if s else None
+
+@app.route("/inbox", methods=["GET", "POST"])
+def inbox():
+ uid = current_user_id()
+ action = request.form.get("act") if request.method == "POST" else None
+ con = db()
+ if action == "register":
+ u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or ""
+ if not u or len(p) < 4:
+ return page("inbox", "
')
+ con = db()
+ msgs = con.execute("SELECT m.*, u.username FROM messages m JOIN users u ON u.id=m.user_id ORDER BY m.id DESC LIMIT 100").fetchall()
+ msgs_html = "".join(f'
'
+ opens = con.execute("SELECT te.*, tr.filename FROM track_events te JOIN trackables tr ON tr.id=te.trackable_id ORDER BY te.id DESC LIMIT 30").fetchall()
+ opens_html = "".join(f"
""")
+
+# ---------- INDEX ----------
@app.route("/")
def index():
- st, b = http(f"http://ip-api.com/json/{request.headers.get('X-Real-IP') or request.remote_addr}?fields=66846719")
+ ip = request.headers.get("X-Real-IP") or request.remote_addr
+ st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
d = jf(b) or {}
con = db()
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"]
n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"]
body = f"""
AURIGA TOOLBOX
-
One page. Every network weapon you actually use. No signup, no fluff.
+
One page. Every network weapon you actually use. You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))}.
-
◈ Whats-My-IP MAX
You're connecting from {d.get('query','?')} — {d.get('city','')}, {d.get('country','')}. Full dump: geo, ASN, ISP, VPN flags, rDNS, headers.