From f4ba7b4c772289037b81d70aa24efbd83b9a1614 Mon Sep 17 00:00:00 2001 From: drjones Date: Wed, 30 Sep 2026 16:12:08 -0700 Subject: [PATCH] =?UTF-8?q?v2:=20stego=20lab=20(LSB=20depth/spread/passwor?= =?UTF-8?q?d),=20trackable=20files=20(BTCPay=20$1,=20pixel=20+=20link,=20i?= =?UTF-8?q?nbox=20alerts),=20burner=20mail=20(CF=20Email=20Routing?= =?UTF-8?q?=E2=86=92worker,=207d/30d/90d=20BTC=20packs),=20PASS=20all-acce?= =?UTF-8?q?ss=20($10/mo,=203mo=20$25,=201yr=20$80),=20IP=20intel=20with=20?= =?UTF-8?q?manual=20target,=20no-KYC=20inbox,=20operator=20console?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app.py | 1080 +++++++++++++++++++++++++++++++++++++++++++------------- 1 file changed, 834 insertions(+), 246 deletions(-) diff --git a/app.py b/app.py index b8fe9a6..c52f8bb 100644 --- a/app.py +++ b/app.py @@ -1,31 +1,51 @@ #!/usr/bin/env python3 -"""AURIGA — homelab toolbox: IP intel, card validator, SMS rentals, proxy tools.""" -import base64, binascii, hashlib, json, os, re, secrets, socket, sqlite3, string, struct, time, uuid +"""AURIGA v2 — toolbox: IP intel, card validator, SMS rentals, proxy lab, stego lab, +trackable files (BTCPay), no-KYC site-only messaging inbox. Single-file Flask + SQLite.""" +import base64, binascii, hashlib, hmac, html, io, json, os, re, secrets, socket, sqlite3, struct, time, uuid import urllib.request, urllib.parse -from flask import Flask, request, jsonify, render_template_string, g +from flask import Flask, request, jsonify, render_template_string, Response, send_file app = Flask(__name__) DB_PATH = os.environ.get("AURIGA_DB", "/opt/auriga/auriga.db") +UPLOAD_DIR = os.environ.get("AURIGA_UPLOADS", "/opt/auriga/uploads") +os.makedirs(UPLOAD_DIR, exist_ok=True) SMSP_KEY = os.environ.get("SMSP_KEY", "") PLEIADES_GW = os.environ.get("PLEIADES_GW", "10.30.20.178:8080") -PLEIADES_APP = os.environ.get("PLEIADES_APP", "http://10.30.20.178:5000") +PLEIADES_APP = os.environ.get("PLEIADES_APP", "https://pleiades.thetempleofdoom.com") +BTCPAY = "https://10.30.20.140/api/v1" +BTCPAY_KEY = os.environ.get("BTCPAY_KEY", "6026288e2e315984661c748baafd509e81a75f22") +BTCPAY_STORE = os.environ.get("BTCPAY_STORE", "7h79ndYyZX2yF6CPa12xt2uVGQ5Fd6nrSDG4Koy86x6u") +WEBCHECK = os.environ.get("WEBCHECK", "http://10.30.20.13:3000") +ADMIN_PW = os.environ.get("AURIGA_ADMIN", "Czapiewski1!") +BTCPAY_WHSEC = os.environ.get("BTCPAY_WHSEC", "TgJhmoBcNf9ATK2SFCg1VS") BMAC = "https://buymeacoffee.com/r26xrthzttg" +SITE = "https://auriga.thetempleofdoom.com" def db(): con = sqlite3.connect(DB_PATH); con.row_factory = sqlite3.Row - con.execute("""CREATE TABLE IF NOT EXISTS sms_rentals( - id INTEGER PRIMARY KEY, phone TEXT, service TEXT, country TEXT, - purchase_id TEXT, cost REAL, status TEXT, created INTEGER, expires INTEGER)""") - con.execute("""CREATE TABLE IF NOT EXISTS proxy_checks( - id INTEGER PRIMARY KEY, user_key TEXT, egress_ip TEXT, geo TEXT, ok INTEGER, ts INTEGER)""") + con.executescript("""CREATE TABLE IF NOT EXISTS sms_rentals(id INTEGER PRIMARY KEY, phone TEXT, service TEXT, country TEXT, purchase_id TEXT, cost REAL, status TEXT, created INTEGER, expires INTEGER); + CREATE TABLE IF NOT EXISTS proxy_checks(id INTEGER PRIMARY KEY, user_key TEXT, egress_ip TEXT, geo TEXT, ok INTEGER, ts INTEGER); + CREATE TABLE IF NOT EXISTS users(id INTEGER PRIMARY KEY, username TEXT UNIQUE, passhash TEXT, created INTEGER); + CREATE TABLE IF NOT EXISTS sessions(id INTEGER PRIMARY KEY, token TEXT UNIQUE, user_id INTEGER, created INTEGER); + CREATE TABLE IF NOT EXISTS trackables(id INTEGER PRIMARY KEY, user_id INTEGER, token TEXT UNIQUE, filename TEXT, kind TEXT, invoice_id TEXT, paid INTEGER DEFAULT 0, created INTEGER); + CREATE TABLE IF NOT EXISTS track_events(id INTEGER PRIMARY KEY, trackable_id INTEGER, ts INTEGER, ip TEXT, ua TEXT); + CREATE TABLE IF NOT EXISTS messages(id INTEGER PRIMARY KEY, user_id INTEGER, sender TEXT, body TEXT, created INTEGER); + CREATE TABLE IF NOT EXISTS mailboxes(id INTEGER PRIMARY KEY, user_id INTEGER, address TEXT UNIQUE, invoice_id TEXT, paid INTEGER DEFAULT 0, expires INTEGER DEFAULT 0, created INTEGER, plan_days INTEGER DEFAULT 7, cnt INTEGER DEFAULT 0); + CREATE TABLE IF NOT EXISTS mails(id INTEGER PRIMARY KEY, mailbox_id INTEGER, sender TEXT, subject TEXT, body TEXT, ts INTEGER); + CREATE TABLE IF NOT EXISTS passes(id INTEGER PRIMARY KEY, user_id INTEGER, invoice_id TEXT, paid INTEGER DEFAULT 0, expires INTEGER DEFAULT 0, plan_days INTEGER DEFAULT 30);""") return con +import ssl as _ssl +_CTX = _ssl.create_default_context() +_CTX.check_hostname = False +_CTX.verify_mode = _ssl.CERT_NONE + def http(url, headers=None, data=None, method="GET", timeout=12): h = {"User-Agent": "Mozilla/5.0 (Auriga toolbox)"} h.update(headers or {}) req = urllib.request.Request(url, headers=h, data=data, method=method) try: - with urllib.request.urlopen(req, timeout=timeout) as r: + with urllib.request.urlopen(req, timeout=timeout, context=_CTX) as r: return r.status, r.read().decode("utf-8", "replace") except urllib.error.HTTPError as e: return e.code, e.read().decode("utf-8", "replace") @@ -36,41 +56,59 @@ def jf(b): try: return json.loads(b) except Exception: return None +def param(name): + return request.form.get(name) or request.args.get(name) + +def esc(s): return html.escape(str(s)) + BASE = """ -AURIGA — Toolbox +AURIGA — Toolbox
{{body}}
""" @@ -79,123 +117,139 @@ def page(sec, body): def kv(pairs): rows = "".join(f"
{k}
{v}
" for k, v in pairs) - return f'
{rows}
' + return f'
{rows}
' -# ---------- 0. AGENT DISCOVERY ---------- +# ---------- AGENT DISCOVERY ---------- API_INDEX = { "service": "AURIGA toolbox", - "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, free utilities. Human UI at /, all tools also JSON APIs.", + "description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.", "endpoints": [ - {"method": "GET", "path": "/api/ip", "desc": "Everything about the caller's IP: geo, ASN, ISP, VPN/proxy/hosting flags, rDNS, request headers."}, - {"method": "POST", "path": "/api/card", "params": {"num": "card number (digits or formatted)"}, "desc": "Luhn + BIN intel: brand, issuer, country, type, prepaid risk flags. Nothing stored/charged."}, - {"method": "POST", "path": "/api/sms/rent", "params": {"service": "SMSPool service id or keyword (273=discord, 395=google, telegram, whatsapp, other)", "country": "country id (1=US,2=UK,4=NL,150=DE)"}, "desc": "Rent a disposable number for 30 min. Returns number + orderid. Cancel before a code = full refund."}, - {"method": "GET", "path": "/api/sms/check", "params": {"pid": "orderid"}, "desc": "Poll for the received SMS code."}, - {"method": "GET", "path": "/api/sms/cancel", "params": {"pid": "orderid"}, "desc": "Cancel order + refund."}, - {"method": "GET", "path": "/api/sms/history", "desc": "Your rental history from this site."}, - {"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades gateway username", "pass": "password (geo suffixes allowed)"}, "desc": "Tunnel CONNECT through the Pleiades gateway, return real egress IP + geo."}, - {"method": "GET", "path": "/api/hash", "params": {"s": "string"}, "desc": "md5/sha1/sha256/sha512."}, - {"method": "GET", "path": "/api/hdr", "params": {"url": "target URL"}, "desc": "Fetch URL, return status + all response headers."}, + {"method": "GET", "path": "/api/ip?target=", "desc": "Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS."}, + {"method": "POST", "path": "/api/card", "params": {"num": "card number"}, "desc": "Luhn + BIN intel. Nothing stored/charged."}, + {"method": "POST", "path": "/api/sms/rent", "params": {"service": "id/keyword", "country": "id"}, "desc": "Rent disposable number, 30 min, refundable."}, + {"method": "GET", "path": "/api/sms/check?pid=", "desc": "Poll SMS code."}, + {"method": "GET", "path": "/api/sms/cancel?pid=", "desc": "Cancel + refund."}, + {"method": "GET", "path": "/api/sms/history", "desc": "Rental history."}, + {"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades user", "pass": "password"}, "desc": "Tunnel CONNECT via Pleiades gateway, return egress IP/geo."}, + {"method": "POST", "path": "/api/steg/hide", "params": {"image": "png file", "text": "secret", "password": "optional", "bits": "1-3", "spread": "sequential|random"}, "desc": "LSB steganography → PNG download."}, + {"method": "POST", "path": "/api/steg/extract", "params": {"image": "png file", "password": "optional"}, "desc": "Extract hidden text."}, + {"method": "POST", "path": "/api/track/create", "params": {"filename": "name"}, "desc": "Create $1 BTCPay invoice for a trackable file. Returns checkoutLink."}, + {"method": "GET", "path": "/api/track/events?token=", "desc": "Open events for a trackable (auth via account)."}, + {"method": "GET", "path": "/api/hash?s=", "desc": "md5/sha1/sha256/sha512."}, + {"method": "GET", "path": "/api/hdr?url=", "desc": "Fetch URL, return status + headers."}, ], - "payment": "SMS meters against the house SMSPool account; proxy plans at the Pleiades storefront. BTCPay BTC only — no Stripe.", + "payment": "BTCPay BTC only (no Stripe). SMS meters to house account; trackables $1 each.", } @app.route("/api") def api_index(): return jsonify(API_INDEX) @app.route("/robots.txt") -def robots(): - return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"} +def robots(): return "User-agent: *\nAllow: /\n", 200, {"Content-Type": "text/plain"} @app.route("/llms.txt") def llms(): - eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']} Params: {e.get('params','-')}" for e in API_INDEX["endpoints"]) - body = f"# AURIGA toolbox\n\nNetwork toolbox for humans and agents. Base: https://auriga.thetempleofdoom.com\n\n## API\n{eps}\n\nAll responses JSON. POST bodies are form-encoded. Human pages at /, /card, /sms, /proxy, /tools.\n" - return body, 200, {"Content-Type": "text/plain"} + eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']}" for e in API_INDEX["endpoints"]) + return f"# AURIGA toolbox\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"} @app.route("/ai-plugin.json") def aiplugin(): return jsonify({"name_for_model": "auriga", "schema_version": "v1", - "description_for_model": "IP intelligence, card BIN validation, disposable SMS number rentals (30 min, refundable), residential proxy egress testing, hashing/URL/DNS utilities.", - "api": {"type": "openapi", "url": "https://auriga.thetempleofdoom.com/openapi.json"}, - "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"}) + "description_for_model": "IP intelligence, card BIN validation, SMS number rentals, proxy egress testing, LSB steganography, trackable file links with open-notifications, no-KYC site messaging.", + "api": {"type": "openapi", "url": SITE + "/openapi.json"}, "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"}) @app.route("/openapi.json") def openapi(): - B = "https://auriga.thetempleofdoom.com" - ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "1.1.0"}, "paths": {}} - def add(path, method, desc, params=None, req=False): + ps = {"openapi": "3.0.0", "info": {"title": "AURIGA", "version": "2.0.0"}, "paths": {}} + def add(path, method, desc, params=None, req=False, files=None): item = {"summary": desc} - if params: + if files: + item["requestBody"] = {"content": {"multipart/form-data": {"schema": {"type": "object", "properties": {**{k: {"type": "string"} for k, v in (params or {}).items()}, **{f: {"type": "string", "format": "binary"} for f in files}}}}}} + elif params: if method == "get": - item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}, "description": v} for k, v in params.items()] + item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}} for k in params] else: - item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string", "description": v} for k, v in params.items()}, "required": [k for k in params] if req else []}}}} + item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string"} for k in params}}}}} ps["paths"][path] = ps["paths"].get(path, {}) | {method: {"responses": {"200": {"description": "ok"}}, **item}} - add("/api/ip", "get", "Caller IP intel: geo/ASN/ISP/VPN flags/headers") + add("/api/ip", "get", "IP intel (caller or ?target=)", {"target": "optional IP"}) add("/api/card", "post", "Luhn + BIN validation", {"num": "card number"}, req=True) - add("/api/sms/rent", "post", "Rent disposable number, 30 min", {"service": "service id/keyword", "country": "country id"}, req=True) + add("/api/sms/rent", "post", "Rent number 30 min", {"service": "id", "country": "id"}, req=True) add("/api/sms/check", "get", "Poll SMS code", {"pid": "orderid"}, req=True) add("/api/sms/cancel", "get", "Cancel + refund", {"pid": "orderid"}, req=True) add("/api/sms/history", "get", "Rental history") - add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "username", "pass": "password"}, req=True) - add("/api/hash", "get", "Hashes of s", {"s": "string"}, req=True) - add("/api/hdr", "get", "HTTP response headers of url", {"url": "url"}, req=True) + add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "user", "pass": "pass"}, req=True) + add("/api/steg/hide", "post", "LSB-hide text in PNG", {"text": "secret", "password": "opt"}, req=True, files=["image"]) + add("/api/steg/extract", "post", "Extract text from PNG", {"password": "opt"}, files=["image"]) + add("/api/track/create", "post", "Create $1 invoice for trackable", {"filename": "name"}, req=True) + add("/api/track/events", "get", "Trackable open events", {"token": "token"}, req=True) + add("/api/hash", "get", "Hashes", {"s": "string"}, req=True) + add("/api/hdr", "get", "HTTP headers", {"url": "url"}, req=True) return jsonify(ps) -def param(name): - return request.form.get(name) or request.args.get(name) or request.args.get("orderid") or request.form.get("orderid") - -def human(n): - return n - -# ---------- 1. WHAT'S MY IP ---------- -@app.route("/ip") -def ip_route(): return ip_lookup() - -def ip_lookup(): - ip = request.headers.get("X-Real-IP") or request.remote_addr or "" +# ---------- 1. IP INTEL (auto + manual target) ---------- +def ip_report(ip): st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719") d = jf(b) or {} - hdrs = {k: v for k, v in request.headers.items() if k.lower() in - ("user-agent","accept-language","x-forwarded-for","cf-connecting-ip","cf-ipcountry","x-real-ip")} - proxy_hint = any(k.lower().startswith(("x-forwarded","via","proxy")) for k in request.headers.keys()) + try: d["reverse"] = d.get("reverse") or socket.gethostbyaddr(ip)[0] + except Exception: pass + return d + +@app.route("/ip", methods=["GET", "POST"]) +def ip_page(): + target = param("target") if request.method == "POST" else param("target") + if target and target.strip(): + target = target.strip() + d = ip_report(target) + heading = f"INTEL FOR {esc(target)}" + mine = False + else: + ip = request.headers.get("X-Real-IP") or request.remote_addr or "" + d = ip_report(ip) + heading = "WHATS MY IP" + mine = True + if d.get("status") == "fail" or not d: + body = f"

{heading}

lookup failed
{ip_form()}" + return page("ip", body) rows = [ - ("YOUR IP", f"{d.get('query', ip)}"), - ("Country", f"{d.get('country','?')} ({d.get('countryCode','?')}) 🏴 {d.get('flag') if 'flag' in d else ''}".strip()), - ("Region / City", f"{d.get('regionName','?')} / {d.get('city','?')} {d.get('zip','')}"), - ("Lat, Lon", f"{d.get('lat','?')}, {d.get('lon','?')} · TZ: {d.get('timezone','?')} · UTC offset {d.get('offset','?')}s"), - ("ISP", d.get('isp','?')), ("Organization", d.get('org','?')), ("AS", d.get('as','?') if d.get('as') else d.get('asname','?')), - ("Reverse DNS", str(d.get('reverse','—'))), - ("Connection", f"mobile: {d.get('mobile')} · proxy/VPN: {d.get('proxy')} · hosting: {d.get('hosting')}"), - ("Local guess", d.get('district') or '—'), - ("Proxy headers seen", "YES ⚠ (you're behind a relay)" if proxy_hint else "none — looks direct"), - ("Currency", d.get('currency','?')), + ("IP", f"{esc(d.get('query'))}"), + ("Country", f"{esc(d.get('country'))} ({esc(d.get('countryCode'))})"), + ("Region / City", f"{esc(d.get('regionName'))} / {esc(d.get('city'))} {esc(d.get('zip'))}"), + ("Lat, Lon", f"{d.get('lat')}, {d.get('lon')} · TZ {esc(d.get('timezone'))}"), + ("ISP", esc(d.get("isp"))), ("Organization", esc(d.get("org"))), ("AS", esc(d.get("as") or d.get("asname"))), + ("Reverse DNS", esc(d.get("reverse") or "—")), + ("Flags", f"mobile: {d.get('mobile')} · proxy/VPN: {d.get('proxy')} · hosting: {d.get('hosting')}"), + ("Currency", esc(d.get("currency"))), ] - hdr_rows = "".join(f"{k}{v}" for k, v in hdrs.items()) + extra = "" + if mine: + hdrs = {k: v for k, v in request.headers.items() if k.lower() in ("user-agent","accept-language","x-forwarded-for","cf-connecting-ip","cf-ipcountry")} + extra = '
Headers you sent' + "".join(f"" for k, v in hdrs.items()) + "
{esc(k)}{esc(v)}
" body = f""" -

WHATS MY IP

Every drop of intel we can legally scrape, always on.

+

{heading}

Auto-detects your IP and shows everything. Want intel on another IP? Type it below — full report, any target.

{kv(rows)} -
Headers you sent{hdr_rows}
-
Live check — your browser also resolved this page in -….
-
API: GET /api/ip → same data as JSON. Agent-friendly.
""" +
+{extra} +
API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)
""" return page("ip", body) +def ip_form(): + return '
' + @app.route("/api/ip") def api_ip(): + target = param("target") + if target and target.strip(): + return jsonify(ip_report(target.strip())) ip = request.headers.get("X-Real-IP") or request.remote_addr or "" - st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719") - d = jf(b) or {} - d["headers_seen"] = {k: v for k, v in request.headers.items()} + d = ip_report(ip) + d["headers_seen"] = dict(request.headers) return jsonify(d) # ---------- 2. CARD CHECK ---------- def luhn_ok(num): digits = [int(c) for c in num] - odd = digits[-1::-2]; even = digits[-2::-2] - s = sum(odd) - for d in even: + s = sum(digits[-1::-2]) + for d in digits[-2::-2]: d *= 2 if d > 9: d -= 9 s += d @@ -213,48 +267,6 @@ def brand_of(num): if num.startswith(pfx): return b return "Unknown" -@app.route("/card", methods=["GET", "POST"]) -def card(): - result = "" - num = re.sub(r"\D", "", request.form.get("num", ""))[:19] - if num: - tags = [] - ok = luhn_ok(num) - tags.append(('LUHN VALID' if ok else 'LUHN INVALID — fake/dead number')) - brand = brand_of(num) - bin8 = num[:8] - bl = bin_lookup(bin8) - bank = (bl.get("bank") or {}).get("name", "—") - country = (bl.get("country") or {}).get("name", "—") - ctype = bl.get("type", "—") - prepaid = bl.get("prepaid", "—") - if not bl: tags.append('BIN DB no data — structure-only result') - flags = [] - if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants") - if ctype == "debit": flags.append("DEBIT") - if ctype == "credit": flags.append("CREDIT") - length = len(num) - rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,),}.get(brand, (13,15,16,19)) - if length not in rng: tags.append(f'LENGTH {length} WRONG for {brand}') - else: tags.append(f'length {length} valid for {brand}') - result = f""" -{kv([("Brand",brand),("BIN",bin8),("Bank / Issuer",bank),("Country",country),("Type",str(ctype)),("Prepaid",str(prepaid))])} -
Fraud & structure flags
{' '.join(tags)} -{'
⚠ ' + ' · '.join(flags) if flags else ''}
-
Nothing is stored. No charge, no auth, no $0 check — this is BIN + math validation only. -It cannot tell you if a card has available funds. Fraud "flagged" status lives at the issuer, not in any database we can legally query.
""" - body = f""" -

CARD CHECK

Is it real? Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.

-
-
Paste anything — spaces, dashes, junk all stripped. Nothing stored.
- -{result}""" - return page("card", body) - def bin_lookup(bin8): st, b = http(f"https://lookup.binlist.net/{bin8}", headers={"Accept-Version": "3"}) bl = jf(b) or {} @@ -262,10 +274,42 @@ def bin_lookup(bin8): st, b = http(f"https://data.handyapi.com/bin/{bin8}") h = jf(b) or {} if h.get("Status") == "SUCCESS": - return {"bank": {"name": h.get("Issuer")}, "country": {"name": h.get("Country", {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")}, + return {"bank": {"name": h.get("Issuer")}, "country": {"name": (h.get("Country") or {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")}, "type": str(h.get("Type", "")).lower() or None, "prepaid": "prepaid" in str(h.get("Type","")).lower() or None, "scheme": h.get("Scheme")} return bl +@app.route("/card", methods=["GET", "POST"]) +def card(): + result = "" + num = re.sub(r"\D", "", param("num") or "")[:19] + if num: + ok = luhn_ok(num) + tags = ['LUHN VALID' if ok else 'LUHN INVALID — fake/dead number'] + brand = brand_of(num) + bl = bin_lookup(num[:8]) + bank = (bl.get("bank") or {}).get("name", "—") + country = (bl.get("country") or {}).get("name", "—") + ctype = bl.get("type", "—") + prepaid = bl.get("prepaid", "—") + flags = [] + if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants") + rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand,(13,15,16,19)) + tags.append(f'length {len(num)} valid for {brand}' if len(num) in rng else f'LENGTH {len(num)} WRONG for {brand}') + result = f""" +{kv([("Brand",brand),("BIN",num[:8]),("Bank / Issuer",esc(bank)),("Country",esc(country)),("Type",str(ctype)),("Prepaid",str(prepaid))])} +
Fraud & structure flags
{' '.join(tags)}{'
⚠ ' + ' · '.join(flags) if flags else ''}
+
Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.
""" + body = f""" +

CARD CHECK

Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.

+
+
Paste anything — auto-formats. Nothing stored.
+ +{result}""" + return page("card", body) + @app.route("/api/card", methods=["POST"]) def api_card(): num = re.sub(r"\D", "", param("num") or "")[:19] @@ -278,43 +322,36 @@ def api_card(): "type": bl.get("type"), "prepaid": bl.get("prepaid")}, "flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])}) -# ---------- SMS ABUSE GUARD ---------- -def sms_guard(): - """Return None if allowed, else a JSON-able reason string.""" - con = db(); now = int(time.time()) - ip = request.headers.get("X-Real-IP") or request.remote_addr or "?" - # balance: refuse if house SMSPool balance below $5 - st, b = sms_api("request/balance") - bal = jf(b) or {} - try: bal = float(bal.get("balance", 0)) - except Exception: bal = 0 - if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused" - # per-IP: max 1 active rental, 3/hour, 8/day - row = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND purchase_id IN (SELECT purchase_id FROM sms_rentals WHERE created > ?)", (now-86400*7,)).fetchone() - # active count overall (any IP) cap 3 concurrent - act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"] - if act >= 3: return "too many active rentals right now — try again later" - h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"] - if h >= 6: return "hourly rental cap reached" - d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"] - if d >= 15: return "daily rental cap reached" - return None - # ---------- 3. SMS RENTALS ---------- SMSP = "https://api.smspool.net" SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")] COUNTRIES = [("1","United States"),("2","United Kingdom"),("4","Netherlands"),("22","Russia"),("150","Germany")] def sms_api(path, **kw): - if kw: + if kw: kw["key"] = SMSP_KEY - data = urllib.parse.urlencode(kw).encode() - return http(f"{SMSP}/{path}", data=data, method="POST") + return http(f"{SMSP}/{path}", data=urllib.parse.urlencode(kw).encode(), method="POST") return http(f"{SMSP}/{path}?key={SMSP_KEY}") +def sms_guard(): + con = db(); now = int(time.time()) + uid = current_user_id() + st, b = sms_api("request/balance") + bal = jf(b) or {} + try: bal = float(bal.get("balance", 0)) + except Exception: bal = 0 + if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused" + act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"] + if act >= (5 if has_pass(uid) else 3): return "too many active rentals right now — try again later" + h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"] + if h >= (20 if has_pass(uid) else 6): return "hourly rental cap reached" + d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"] + if d >= (50 if has_pass(uid) else 15): return "daily rental cap reached" + return None + @app.route("/sms", methods=["GET", "POST"]) def sms(): - msg, listing = "", "" + msg = "" if request.method == "POST": act = request.form.get("act") if act == "rent": @@ -322,64 +359,47 @@ def sms(): if guard: msg = f'
PAUSED {guard}
' else: - svc, ctry = request.form["service"], request.form["country"] - st, b = sms_api("purchase/sms", service=svc, country=ctry) + st, b = sms_api("purchase/sms", service=request.form["service"], country=request.form["country"]) d = jf(b) or {} if d.get("success") == 1: - con = db() - now = int(time.time()) + con = db(); now = int(time.time()) con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)", - (d.get("number"), svc, ctry, str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800)) + (d.get("number"), request.form["service"], request.form["country"], str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800)) con.commit() - msg = f'
RENTED Your number: +{d.get("number")} · expires in 30 min · order #{d.get("purchase_id")}
' + msg = f'
RENTED Your number: +{d.get("number")} · 30 min · order #{d.get("purchase_id")}
' else: - msg = f'
RENT FAILED
{b[:400]}
' + msg = f'
RENT FAILED
{esc(b[:400])}
' elif act == "check": - pid = request.form["pid"] - st, b = sms_api("sms/check", orderid=pid) + st, b = sms_api("sms/check", orderid=request.form["pid"]) d = jf(b) or {} sms_txt = d.get("sms") or d.get("code") or "" status = d.get("status", "?") - color = "ok" if sms_txt else "warn" - msg = f'
STATUS: {status} {"" + str(sms_txt) + "" if sms_txt else "no code yet — poll again in 10s"}
' + msg = f'
STATUS: {status} {"" + esc(sms_txt) + "" if sms_txt else "no code yet — poll again in 10s"}
' elif act == "cancel": - pid = request.form["pid"] - st, b = sms_api("sms/cancel", orderid=pid) + st, b = sms_api("sms/cancel", orderid=request.form["pid"]) d = jf(b) or {} ok = d.get("success") == 1 - con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", pid)); con.commit() + con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", request.form["pid"])); con.commit() msg = f'
{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}
' - st, b = sms_api("sms/instructions") con = db() hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall() hist_rows = "".join(f"+{h['phone']} copy{h['service']}{h['status']}#{h['purchase_id']}…" for h in hist) body = f""" -

SMS RENTAL

Disposable numbers, 30-minute windows. Cancel before a code arrives = full refund.

+

SMS RENTAL

Disposable numbers, 30-minute windows. Cancel before a code = full refund.

Rent a number
-
-
Numbers auto-appear below. Codes auto-poll every 10s.
+
Check / manage
{msg}
Recent rentals{hist_rows or ''}
NumberServiceStatusOrderWindow
none yet
API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history
""" return page("sms", body) @@ -397,23 +417,25 @@ def api_sms_rent(): con.commit() return jsonify(d) -@app.route("/api/sms/check", methods=["GET", "POST"]) +@app.route("/api/sms/check", methods=["GET","POST"]) def api_sms_check(): st, b = sms_api("sms/check", orderid=param("pid")) return jf(b) or jsonify({"error": b[:200]}) -@app.route("/api/sms/cancel", methods=["GET", "POST"]) +@app.route("/api/sms/cancel", methods=["GET","POST"]) def api_sms_cancel(): st, b = sms_api("sms/cancel", orderid=param("pid")) - return jf(b) or jsonify({"error": b[:200]}) + d = jf(b) or {} + if d.get("success") == 1: + con = db(); con.execute("UPDATE sms_rentals SET status='refunded' WHERE purchase_id=?", (param("pid"),)); con.commit() + return d @app.route("/api/sms/history") def api_sms_history(): con = db(); now = int(time.time()) con.execute("UPDATE sms_rentals SET status='expired' WHERE status='active' AND expires < ?", (now,)) con.commit() - rows = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 50").fetchall() - return jsonify([dict(r) for r in rows]) + return jsonify([dict(r) for r in con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 50")]) # ---------- 4. PROXY LAB ---------- @app.route("/proxy", methods=["GET", "POST"]) @@ -421,57 +443,50 @@ def proxy(): result = "" if request.method == "POST" and request.form.get("act") == "test": user, pw = request.form.get("user",""), request.form.get("pass","") - test_url = request.form.get("target", "http://ip-api.com/json/?fields=66846719") pauth = base64.b64encode(f"{user}:{pw}".encode()).decode() try: - pu = urllib.parse.urlparse(test_url if "://" in test_url else "http://"+test_url) - req_line = f"GET {pu.path or '/'} HTTP/1.1\r\nHost: {pu.hostname}\r\nConnection: close\r\n\r\n" s = socket.create_connection((PLEIADES_GW.split(":")[0], int(PLEIADES_GW.split(":")[1])), timeout=15) - s.sendall(f"CONNECT {pu.hostname}:80 HTTP/1.1\r\nHost: {pu.hostname}:80\r\nProxy-Authorization: Basic {pauth}\r\n\r\n".encode()) + s.sendall(f"CONNECT ip-api.com:80 HTTP/1.1\r\nHost: ip-api.com:80\r\nProxy-Authorization: Basic {pauth}\r\n\r\n".encode()) resp = s.recv(4096) if b"200" in resp.split(b"\r\n")[0]: - s.sendall(req_line.encode()) + s.sendall(b"GET /json/?fields=66846719 HTTP/1.1\r\nHost: ip-api.com\r\nConnection: close\r\n\r\n") data = b"" while True: c = s.recv(8192) if not c: break data += c s.close() - body = data.split(b"\r\n\r\n",1)[-1].decode("utf-8","replace") - j = jf(body) or {} + j = jf(data.split(b"\r\n\r\n",1)[-1].decode("utf-8","replace")) or {} con = db() - con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", - (user[:12], j.get("query","?"), f"{j.get('country')}/{j.get('city')}", 1, int(time.time()))) + con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], j.get("query","?"), f"{j.get('country')}/{j.get('city')}", 1, int(time.time()))) con.commit() - result = f'
PROXY LIVE Egress: {j.get("query")} — {j.get("country")} / {j.get("city")} · ISP {j.get("isp")} · tz {j.get("timezone")}
' + result = f'
PROXY LIVE Egress: {esc(j.get("query"))} — {esc(j.get("country"))} / {esc(j.get("city"))} · ISP {esc(j.get("isp"))} · tz {esc(j.get("timezone"))}
' else: con = db() con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], "", "", 0, int(time.time()))) con.commit() - result = f'
AUTH/TUNNEL FAILED
{resp[:200]!r}
' + result = f'
AUTH/TUNNEL FAILED
{esc(resp[:200])}
' except Exception as e: - result = f'
ERROR {e}
' + result = f'
ERROR {esc(e)}
' body = f""" -

PROXY LAB

Rent residential proxies on the Pleiades rail — your existing gateway user:pass works here, same keys as everywhere.

+

PROXY LAB

Test + rent residential proxies on the Pleiades rail — same gateway keys as everywhere.

-

+



{result} -
Geo session builder — append these to your password to steer the egress: +
Geo session builder:
yourpassword
-
Chain them: pass_region-us_session-x9k2_lifetime-30m. Same gateway keys as the storefront.
-
-
Rent more — buy GB plans & geo-targeted sessions at the storefront: -{PLEIADES_APP}.
+
+
Rent more — storefront: {PLEIADES_APP}
API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.
""" return page("proxy", body) @app.route("/api/proxy/test", methods=["POST"]) def api_proxy_test(): - user, pw = request.form.get("user",""), request.form.get("pass","") + user, pw = param("user") or "", param("pass") or "" pauth = base64.b64encode(f"{user}:{pw}".encode()).decode() try: s = socket.create_connection((PLEIADES_GW.split(":")[0], int(PLEIADES_GW.split(":")[1])), timeout=15) @@ -490,15 +505,564 @@ def api_proxy_test(): except Exception as e: return jsonify({"ok": False, "error": str(e)}) -# ---------- 5. FREE TOOLS ---------- +# ---------- 5. STEGO LAB ---------- +def _keystream(password, n): + ks = b""; seed = password.encode() + while len(ks) < n: + seed = hashlib.sha256(seed).digest() + ks += seed + return ks[:n] + +def steg_hide(img_bytes, text, password="", bits=1, spread="sequential"): + from PIL import Image + im = Image.open(io.BytesIO(img_bytes)).convert("RGBA") + px = im.load() + w, h = im.size + capacity = w * h * 3 * bits + payload = text.encode("utf-8") + phash = hashlib.sha256(password.encode()).digest()[:4] if password else b"\x00\x00\x00\x00" + header = b"AUR1" + struct.pack(">I", len(payload)) + phash + body = payload + if password: + body = bytes(a ^ b for a, b in zip(body, _keystream(password, len(body)))) + data = header + body + if len(data) * 8 > capacity: + return None, f"too big: need {len(data)*8} bits, image holds {capacity}" + if spread == "random": + import random as _r + _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big")) + order = list(range(w*h)); _r.shuffle(order) + else: + order = list(range(w*h)) + bits_needed = len(data) * 8 + idx = 0 + mask = (1 << bits) - 1 + for pos in order: + if idx >= bits_needed: break + x, y = pos % w, pos // w + r, g, b, a = px[x, y] + chs = [r, g, b] + for ch_i in range(3): + if idx >= bits_needed: break + chunk = 0 + taken = 0 + for k in range(bits): + if idx >= bits_needed: break + chunk = (chunk << 1) | ((data[idx >> 3] >> (7 - (idx & 7))) & 1) + idx += 1; taken += 1 + if taken < bits: chunk <<= (bits - taken) + chs[ch_i] = (chs[ch_i] & ~mask) | chunk + px[x, y] = tuple(chs) + (a,) + # also stash settings in a tEXt chunk for reliable extraction hints + out = io.BytesIO() + im.save(out, "PNG", pnginfo=_pnginfo(bits, spread)) + return out.getvalue(), {"bits": bits, "spread": spread} + +def _pnginfo(bits, spread): + try: + from PIL.PngImagePlugin import PngInfo + info = PngInfo() + info.add_text("auriga_meta", json.dumps({"bits": bits, "spread": spread, "v": 2})) + return info + except Exception: + return None + +def steg_extract(img_bytes, password="", bits=None, spread=None): + from PIL import Image + im = Image.open(io.BytesIO(img_bytes)) + meta = im.info.get("auriga_meta") + if meta: + try: + m = json.loads(meta) + bits = int(m.get("bits", bits or 1)); spread = m.get("spread", spread or "sequential") + except Exception: pass + bits = bits or 1 + im = im.convert("RGBA") + px = im.load() + w, h = im.size + mask = (1 << bits) - 1 + # replicate the shuffle used at hide time + if spread == "random": + import random as _r + _r.seed(int.from_bytes(hashlib.sha256((password + "auriga").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"auriga-random-no-pass").digest()[:4], "big")) + order = list(range(w*h)); _r.shuffle(order) + else: + order = list(range(w*h)) + raw = bytearray() + need = None + idx = 0 + for pos in order: + if need is not None and idx >= need: break + x, y = pos % w, pos // w + r, g, b, a = px[x, y] + for ch in (r, g, b): + chunk = ch & mask + for k in range(bits-1, -1, -1): + if need is not None and idx >= need: break + bit = (chunk >> k) & 1 + while len(raw) < (idx >> 3) + 1: raw.append(0) + if bit: raw[idx >> 3] |= (0x80 >> (idx & 7)) + idx += 1 + if need is not None and idx >= need: break + if need is None and idx >= 64: + if bytes(raw[:4]) != b"AUR1": + return None, f"no AURIGA payload found with LSB depth {bits} (try other depth / randomized)" + ln = struct.unpack(">I", bytes(raw[4:8]))[0] + need = 64 + ln * 8 + data = bytes(raw) + if len(data) < 12: return None, "payload too small" + if bytes(data[:4]) != b"AUR1": + return None, "no AURIGA payload found (wrong password or settings?)" + if password and hashlib.sha256(password.encode()).digest()[:4] != data[8:12]: + return None, "wrong password" + ln = struct.unpack(">I", data[4:8])[0] + body = data[12:12+ln] + if password: + body = bytes(a ^ b for a, b in zip(body, _keystream(password, len(body)))) + text = body.decode("utf-8", "replace") + return text, None + +@app.route("/steg", methods=["GET"]) +def steg(): + body = f""" +

STEGO LAB

Hide words inside pictures — LSB steganography with real settings. PNG in, PNG out, looks untouched.

+
+
Hide text +
+
📤 drop a PNG here or click
+
+ + +
+ + +
+
+
Extract text +
+
📥 drop the carrier PNG
+
+ +
+
+
+
+ +
API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
""" + return page("steg", body) + +@app.route("/api/steg/hide", methods=["POST"]) +def api_steg_hide(): + f = request.files.get("image") + text = param("text") or "" + if not f or not text: return jsonify({"ok": False, "error": "image + text required"}), 400 + bits = min(3, max(1, int(param("bits") or 1))) + spread = param("spread") or "sequential" + try: + out, meta = steg_hide(f.read(), text, param("password") or "", bits, spread) + except Exception as e: + return jsonify({"ok": False, "error": str(e)}), 400 + if out is None: return jsonify({"ok": False, "error": meta}), 400 + return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="auriga-hidden.png") + +@app.route("/api/steg/extract", methods=["POST"]) +def api_steg_extract(): + f = request.files.get("image") + if not f: return jsonify({"ok": False, "error": "image required"}), 400 + bits = param("bits") + bits = min(3, max(1, int(bits))) if bits else None + try: + text, err = steg_extract(f.read(), param("password") or "", bits, param("spread") or None) + except Exception as e: + return jsonify({"ok": False, "error": str(e)}), 400 + if err: return jsonify({"ok": False, "error": err}), 200 + return jsonify({"ok": True, "text": text}) + +# ---------- 6. TRACKABLE FILES ---------- +@app.route("/track", methods=["GET"]) +def track(): + uid = current_user_id() + mine = "" + if uid: + con = db() + rows = con.execute("SELECT * FROM trackables WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall() + if rows: + trs = "".join(f"{esc(t['filename'])}{'events' if t['paid'] else '—'}{'paid ✓' if t['paid'] else 'unpaid'}" for t in rows) + mine = f'
Your trackables{trs}
FileEventsStatus
' + body = f""" +

TRACK FILE

Pay $1 BTC → upload a file or picture → get a tracked link + an email-ready version. Every open pings back into your INBOX.

+
+1 · Pay $1
+
+
BTCPay BTC only. After payment the upload opens automatically.
+{mine} +
How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. Login (no KYC) to see events.
+
API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=
""" + return page("track", body) + +def btc_invoice(amount="1.00"): + st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices", + headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"}, + data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "auriga-track"}}).encode(), method="POST") + return jf(b) or {} + +@app.route("/api/track/create", methods=["POST"]) +def api_track_create(): + fn = param("filename") or "file" + uid = current_user_id() + token = secrets.token_urlsafe(16) + con = db() + if has_pass(uid): + con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)", + (uid or 0, token, esc(fn[:100]), "file", "PASS", int(time.time()))) + con.commit() + return jsonify({"ok": True, "free": True, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"}) + inv = btc_invoice() + if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 + con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)", + (uid or 0, token, esc(fn[:100]), "file", inv["id"], int(time.time()))) + con.commit() + return jsonify({"ok": True, "invoice_id": inv["id"], "checkoutLink": inv.get("checkoutLink"), "token": token, + "after_payment_upload_url": f"{SITE}/track/pay?token={token}"}) + +@app.route("/track/pay", methods=["GET"]) +def track_pay(): + token = param("token") or "" + con = db() + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if not t: return page("track", "

TRACK FILE

unknown token
") + return page("track", f""" +

TRACK FILE

Upload your file — then it's trackable.

+
+
📤 drop file / picture here
+
+
+""") + +@app.route("/api/track/upload", methods=["POST"]) +def api_track_upload(): + token = param("token") + f = request.files.get("file") + if not f: return jsonify({"ok": False, "error": "file required"}), 400 + con = db() + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if not t: return jsonify({"ok": False, "error": "unknown token"}), 400 + st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] != "PASS" else (200, '{"status":"settled"}') + inv = jf(b) or {} + paid = inv.get("status") in ("settled", "processing", "paid") + if not paid: return jsonify({"ok": False, "error": f"invoice not paid yet ({inv.get('status')})"}), 402 + data = f.read() + open(os.path.join(UPLOAD_DIR, token + ".bin"), "wb").write(data) + kind = "image" if (f.content_type or "").startswith("image") else "file" + fn = (f.filename or t["filename"])[:100] + con.execute("UPDATE trackables SET paid=1, kind=?, filename=? WHERE token=?", (kind, fn, token)) + con.commit() + b64 = base64.b64encode(data).decode() + pixel = f"{SITE}/t/{token}.png" + if kind == "image": + viewer = f'' + else: + viewer = f'

📎 {esc(fn)} ({len(data)} bytes)

Open / download the file

' + open(os.path.join(UPLOAD_DIR, token + ".html"), "w").write(viewer) + con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)", (t["id"], int(time.time()), "created", "upload")) + con.commit() + return jsonify({"ok": True, "tracked_link": f"{SITE}/t/{token}", "pixel": pixel, + "email_html": f"{SITE}/t/{token}/html", + "note": "attach/email the HTML version — every view fires the pixel and lands in the inbox"}) + +@app.route("/t/") +def tracked_download(token): + con = db() + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if not t or not t["paid"]: return "not found", 404 + con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)", + (t["id"], int(time.time()), request.headers.get("X-Real-IP") or request.remote_addr, request.headers.get("User-Agent",""))) + uid = t["user_id"] + if uid: + con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)", + (uid, "operator-bot", f"👁 your tracked file '{esc(t['filename'])}' was just opened — IP {esc(request.headers.get('X-Real-IP') or request.remote_addr)}, device: {esc(request.headers.get('User-Agent','')[:80])}", int(time.time()))) + con.commit() + path = os.path.join(UPLOAD_DIR, token + ".bin") + if not os.path.exists(path): return "file gone", 404 + return send_file(path, as_attachment=True, download_name=t["filename"]) + +@app.route("/t/.png") +def tracked_pixel(token): + con = db() + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if t and t["paid"]: + con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)", + (t["id"], int(time.time()), request.headers.get("X-Real-IP") or request.remote_addr, request.headers.get("User-Agent",""))) + uid = t["user_id"] + if uid: + con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)", + (uid, "operator-bot", f"👁 '{esc(t['filename'])}' was just viewed (email/pixel) — IP {esc(request.headers.get('X-Real-IP') or request.remote_addr)}", int(time.time()))) + con.commit() + px = base64.b64decode("R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7") + return Response(px, mimetype="image/gif", headers={"Cache-Control": "no-store"}) + +@app.route("/t//html") +def tracked_html(token): + con = db() + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if not t or not t["paid"]: return "not found", 404 + p = os.path.join(UPLOAD_DIR, token + ".html") + return send_file(p, mimetype="text/html") if os.path.exists(p) else ("no html wrapper", 404) + +@app.route("/api/track/events", methods=["GET"]) +def api_track_events(): + con = db(); token = param("token") + t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone() + if not t: return jsonify({"ok": False, "error": "unknown token"}) + uid = current_user_id() + if not uid or uid != t["user_id"]: return jsonify({"ok": False, "error": "auth required (login on /inbox)"}) + return jsonify([dict(r) for r in con.execute("SELECT * FROM track_events WHERE trackable_id=? ORDER BY id DESC LIMIT 100", (t["id"],))]) + +# ---------- 6b. BURNER MAIL (receive-only, BTC packages) ---------- +MAIL_PACKS = [("7","7 days — $3",3,7),("30","30 days — $8",8,30),("90","90 days — $20",20,90)] +MAIL_DOMAIN = "thetempleofdoom.com" +MAIL_RESERVED = {"indianaholmes","admin","operator","drjones","root","noreply","support","pass","mail"} +MAIL_SECRET = "auriga-mail-relay-2026" + +@app.route("/mail", methods=["GET"]) +def mail(): + uid = current_user_id() + mine = "" + if uid: + con = db(); now = int(time.time()) + con.execute("UPDATE mailboxes SET paid=2 WHERE paid=1 AND expires < ?", (now,)) # expired + rows = con.execute("SELECT * FROM mailboxes WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall() + if rows: + trs = "".join(f"{esc(m['address'])} copyview mail…{'live' if m['paid']==1 else 'expired'}{m['cnt']}" for m in rows) + mine = f'
Your mailboxes{trs}
AddressExpiresStatusMail
' + body = f""" +

BURNER MAIL

Receive-only disposable mailboxes @thetempleofdoom.com. Counting down in real time. Anything you sign up for — codes, confirmations, one-off handouts — lands right here, no other identity attached.

+
+Pick a package (BTC) +{''.join(f'
' for d,n,_,_ in MAIL_PACKS)} +
Type your desired mailbox name, pick a length, pay the invoice — the mailbox activates the moment the payment settles.
+{mine} +
API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.
""" + return page("steg", body) + +@app.route("/api/mail/create", methods=["POST"]) +def api_mail_create(): + uid = current_user_id() + local = re.sub(r"[^a-z0-9._-]", "", (param("local") or "").lower())[:30] + days = param("days") or "7" + pack = next((p for p in MAIL_PACKS if p[0] == str(days)), None) + if not pack: return jsonify({"ok": False, "error": "bad package"}), 400 + if not local: return jsonify({"ok": False, "error": "mailbox name required"}), 400 + if local in MAIL_RESERVED: return jsonify({"ok": False, "error": "reserved name"}), 400 + addr = f"{local}@{MAIL_DOMAIN}" + con = db() + if con.execute("SELECT 1 FROM mailboxes WHERE address=?", (addr,)).fetchone(): + return jsonify({"ok": False, "error": "mailbox name taken"}), 400 + inv = btc_invoice(f"{pack[2]:.2f}") + if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 + con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)", + (uid or 0, addr, inv["id"], 0, 0, int(time.time()), pack[3])) + con.commit() + return jsonify({"ok": True, "address": addr, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]}) + +@app.route("/api/mail/inbound", methods=["POST"]) +def api_mail_inbound(): + d = request.get_json(silent=True) or {} + if d.get("secret") != MAIL_SECRET: return jsonify({"ok": False}), 403 + addr = (d.get("mailbox") or "").lower().split("@")[0] + con = db() + m = con.execute("SELECT * FROM mailboxes WHERE address LIKE ? AND paid=1", (addr + "@%",)).fetchone() + if not m: return jsonify({"ok": False, "error": "unknown/expired mailbox"}), 404 + con.execute("INSERT INTO mails(mailbox_id,sender,subject,body,ts) VALUES(?,?,?,?,?)", + (m["id"], esc(d.get("from") or "?"), esc(d.get("subject") or ""), esc(d.get("body") or ""), int(time.time()))) + con.execute("UPDATE mailboxes SET cnt=cnt+1 WHERE id=?", (m["id"],)) + con.commit() + return jsonify({"ok": True}) + +@app.route("/mail/view") +def mail_view(): + uid = current_user_id() + if not uid: return page("inbox", "
login required
") + addr = param("addr") or "" + con = db() + m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr.lower(), uid)).fetchone() + if not m: return page("inbox", "
not your mailbox
") + mails = con.execute("SELECT * FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],)).fetchall() + rows = "".join(f'
{esc(x["sender"])} · {time.strftime("%b %d %H:%M", time.localtime(x["ts"]))}
{esc(x["subject"])}
{esc(x["body"])}
' for x in mails) or '
empty — waiting for mail…
' + left = max(0, m["expires"] - int(time.time())) + return page("steg", f""" +

{esc(m['address'])}

remaining — auto-refreshes every 15s.

+
{rows}
+""") + +@app.route("/api/mail/inbox") +def api_mail_inbox(): + uid = current_user_id() + if not uid: return jsonify({"ok": False, "error": "login required (POST /inbox act=login)"}) + con = db(); addr = (param("addr") or "").lower() + m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr, uid)).fetchone() + if not m: return jsonify({"ok": False, "error": "unknown mailbox"}) + return jsonify([dict(r) for r in con.execute("SELECT sender,subject,body,ts FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],))]) + +# ---------- 6c. PASS — all-tools subscription ---------- +PASS_PACKS = [("30","1 month — $10 BTC",10,30),("90","3 months — $25 (save 17%)",25,90),("365","1 year — $80 (save 33%)",80,365)] + +def has_pass(uid): + if not uid: return False + con = db() + r = con.execute("SELECT 1 FROM passes WHERE user_id=? AND expires > ? AND paid=1", (uid, int(time.time()))).fetchone() + return bool(r) + +@app.route("/pass", methods=["GET"]) +def pass_page(): + uid = current_user_id() + mine = "" + if uid: + con = db() + r = con.execute("SELECT * FROM passes WHERE user_id=? AND paid=1 ORDER BY expires DESC LIMIT 1", (uid,)).fetchone() + if r and r["expires"] > int(time.time()): + left = r["expires"] - int(time.time()) + mine = f'
PASS ACTIVE {left//86400} days {left%86400//3600}h left — all tools unlimited (proxy rentals still metered at the storefront), trackables free, burner mail discounts.
' + body = f""" +

PASS — ALL ACCESS

One BTC payment. Near-unlimited everything on this site: unlimited SMS rentals (house caps still apply for sanity), free trackables, burner mail included, no per-tool payments.

+
+{''.join(f'
' for d,n,_,_ in PASS_PACKS)} +
Proxy rentals stay separate (they burn real upstream bandwidth — buy those at the storefront).
+{mine} +
API: POST /api/pass/create (days=30|90|365) → invoice. Pass activates on payment settle via webhook.
""" + return page("sms", body) + +@app.route("/api/pass/create", methods=["POST"]) +def api_pass_create(): + uid = current_user_id() + if not uid: return jsonify({"ok": False, "error": "login first (POST /inbox act=login)"}), 401 + days = param("days") or "30" + pack = next((p for p in PASS_PACKS if p[0] == str(days)), None) + if not pack: return jsonify({"ok": False, "error": "bad package"}), 400 + inv = btc_invoice(f"{pack[2]:.2f}") + if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400 + con = db() + con.execute("INSERT INTO passes(user_id,invoice_id,paid,expires,plan_days) VALUES(?,?,0,0,?)", (uid, inv["id"], pack[3])) + con.commit() + return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]}) + +@app.route("/api/btcpay/webhook", methods=["POST"]) +def btcpay_webhook(): + sig = request.headers.get("BTCPay-Sig", "") + body = request.get_data() + expect = "sha256=" + hmac.new(BTCPAY_WHSEC.encode(), body, hashlib.sha256).hexdigest() + if sig != expect: return jsonify({"ok": False, "error": "bad sig"}), 400 + d = jf(body) or {} + if d.get("type") == "InvoiceSettled" or (d.get("type") == "InvoicePaymentSettled"): + iid = d.get("invoiceId") + con = db() + con.execute("UPDATE trackables SET paid=1 WHERE invoice_id=?", (iid,)) + r = con.execute("SELECT plan_days FROM mailboxes WHERE invoice_id=?", (iid,)).fetchone() + if r: + con.execute("UPDATE mailboxes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 7), iid)) + r = con.execute("SELECT plan_days FROM passes WHERE invoice_id=?", (iid,)).fetchone() + if r: + con.execute("UPDATE passes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 30), iid)) + con.commit() + return jsonify({"ok": True}) + +# ---------- 7. INBOX (no-KYC site-only messaging) ---------- +def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"auriga-salt", n=16384, r=8, p=1).hex() + +def current_user_id(): + tok = request.cookies.get("auriga_tok") + if not tok: return None + con = db() + s = con.execute("SELECT user_id FROM sessions WHERE token=?", (tok,)).fetchone() + return s["user_id"] if s else None + +@app.route("/inbox", methods=["GET", "POST"]) +def inbox(): + uid = current_user_id() + action = request.form.get("act") if request.method == "POST" else None + con = db() + if action == "register": + u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or "" + if not u or len(p) < 4: + return page("inbox", "

INBOX

username + password (4+ chars) required
") + try: + con.execute("INSERT INTO users(username,passhash,created) VALUES(?,?,?)", (u, hash_pw(p), int(time.time()))) + con.commit() + except sqlite3.IntegrityError: + return page("inbox", "

INBOX

name taken
") + tok = secrets.token_urlsafe(24) + con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, con.execute("SELECT id FROM users WHERE username=?", (u,)).fetchone()["id"], int(time.time()))) + con.commit() + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True) + return resp + elif action == "login": + u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or "" + r = con.execute("SELECT * FROM users WHERE username=?", (u,)).fetchone() + if r and r["passhash"] == hash_pw(p): + tok = secrets.token_urlsafe(24) + con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, r["id"], int(time.time()))) + con.commit() + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", tok, max_age=86400*30, httponly=True) + return resp + return page("inbox", "

INBOX

bad login
") + elif action == "logout": + con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("auriga_tok"),)); con.commit() + resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("auriga_tok", "", max_age=0) + return resp + elif action == "send" and uid: + body = (request.form.get("body") or "").strip()[:4000] + if body: + con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)", (uid, "user", esc(body), int(time.time()))) + con.commit() + if not uid: + return page("inbox", f""" +

INBOX — no KYC

Just a name + password. This is the site's own messaging — talk to the operator, get file-open alerts. Nothing leaves the site.

+
+
Login
+
Create account
+
""") + msgs = con.execute("SELECT * FROM messages WHERE user_id=? ORDER BY id DESC LIMIT 50", (uid,)).fetchall() + msgs_html = "".join(f'
{"you" if m["sender"]=="user" else esc(m["sender"])} · {time.strftime("%b %d %H:%M", time.localtime(m["created"]))}
{m["body"]}
' for m in reversed(msgs)) or '
no messages yet — say hi.
' + files = con.execute("SELECT * FROM trackables WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall() + files_html = "".join(f"{esc(f['filename'])}{'events' if f['paid'] else '—'}{'paid ✓' if f['paid'] else 'unpaid'}{time.strftime('%b %d', time.localtime(f['created']))}" for f in files) + body = f""" +

INBOX

Site-internal messaging with the operator + your file-open alerts.

+
+ +
+
Conversation{msgs_html}
+
Your tracked files{files_html or ''}
FileEventsStatusCreated
none yet
+
+
API: (cookie auth) POST /inbox act=send body=… · GET /api/inbox/messages
""" + return page("inbox", body) + +@app.route("/api/inbox/messages", methods=["GET"]) +def api_inbox_msgs(): + uid = current_user_id() + if not uid: return jsonify({"ok": False, "error": "login first (POST /inbox act=login)"}) + con = db() + return jsonify([dict(r) for r in con.execute("SELECT * FROM messages WHERE user_id=? ORDER BY id DESC LIMIT 100", (uid,))]) + +# ---------- 8. FREE TOOLS ---------- TOOLS_JS = """ -function tab(n){document.querySelectorAll('.pane').forEach(p=>p.style.display='none');document.getElementById(n).style.display='block'; -document.querySelectorAll('.tbtn').forEach(b=>b.classList.remove('on'));event.target.classList.add('on')} +function tab(n){document.querySelectorAll('.pane').forEach(p=>p.style.display='none');document.getElementById(n).style.display='block'} async function dns(){const d=document.getElementById('dq').value;const o=await (await fetch('https://dns.google/resolve?name='+encodeURIComponent(d)+'&type=A')).json();document.getElementById('do').textContent=JSON.stringify(o,null,1)} async function hdr(){const u=document.getElementById('hq').value;const r=await (await fetch('/api/hdr?url='+encodeURIComponent(u))).json();document.getElementById('ho').textContent=JSON.stringify(r,null,1)} -function jwt(){try{const t=document.getElementById('jq').value.trim().split('.');const d=s=>JSON.stringify(JSON.parse(atob(s.replace(/-/g,'+').replace(/_/g,'/'))),null,1);document.getElementById('jo').textContent='HEADER\\n'+d(t[0])+'\\n\\nPAYLOAD\\n'+d(t[1])+'\\n\\n(signature: '+t[2]+')'}catch(e){document.getElementById('jo').textContent='Invalid JWT: '+e}} -function genhash(){const i=document.getElementById('hq2').value;['md5','sha1','sha256','sha512'].forEach(a=>{document.getElementById('h_'+a).textContent=hashlib(a,i)})} -function hashlib(a,s){return a} +function jwt(){try{const t=document.getElementById('jq').value.trim().split('.');const d=s=>JSON.stringify(JSON.parse(atob(s.replace(/-/g,'+').replace(/_/g,'/'))),null,1);document.getElementById('jo').textContent='HEADER\\n'+d(t[0])+'\\n\\nPAYLOAD\\n'+d(t[1])}catch(e){document.getElementById('jo').textContent='Invalid JWT: '+e}} async function genhash2(){const i=document.getElementById('hq2').value;const r=await(await fetch('/api/hash?s='+encodeURIComponent(i))).json();for(const k of ['md5','sha1','sha256','sha512'])document.getElementById('h_'+k).textContent=r[k]} function uuids(){let o='';for(let i=0;i<5;i++)o+=crypto.randomUUID()+'\\n';document.getElementById('uo').textContent=o} function pwgen(){const l=+document.getElementById('pl').value||24;const cs='abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789!@#$%^&*-_=+';const a=new Uint32Array(l);crypto.getRandomValues(a);document.getElementById('po').textContent=Array.from(a,x=>cs[x%cs.length]).join('')} @@ -506,10 +1070,10 @@ function pwgen(){const l=+document.getElementById('pl').value||24;const cs='abcd @app.route("/api/hdr") def api_hdr(): - url = request.args.get("url","") + url = param("url") or "" if "://" not in url: url = "http://" + url try: - req = urllib.request.Request(url, headers={"User-Agent":"Auriga/1.0"}) + req = urllib.request.Request(url) with urllib.request.urlopen(req, timeout=12) as r: return jsonify({"status": r.status, "final_url": r.url, "headers": dict(r.headers)}) except Exception as e: @@ -517,64 +1081,88 @@ def api_hdr(): @app.route("/api/hash") def api_hash(): - s = request.args.get("s","").encode() + s = (param("s") or "").encode() return jsonify({"md5": hashlib.md5(s).hexdigest(), "sha1": hashlib.sha1(s).hexdigest(), "sha256": hashlib.sha256(s).hexdigest(), "sha512": hashlib.sha512(s).hexdigest()}) @app.route("/tools") def tools(): body = f""" -

FREE TOOLS

High-value, zero-cost, no signup. Agent-friendly APIs underneath each.

+

FREE TOOLS

High-value, zero-cost, no signup. APIs underneath each.

- - - - -
+ + + + +
DNS Lookup (Google DoH)
-
API: /api/hdr style JSON via dns.google
+

 
-
+
 
+sha256sha512
 """
     return page("tools", body)
 
+# ---------- 9. OPERATOR CONSOLE ----------
+@app.route("/admin", methods=["GET", "POST"])
+def admin():
+    if request.method == "POST" and request.form.get("pw") == ADMIN_PW:
+        resp = Response(status=302); resp.headers["Location"] = "/admin"
+        resp.set_cookie("auriga_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True)
+        return resp
+    if not request.cookies.get("auriga_admin"):
+        return page("ip", '

OPERATOR

') + con = db() + msgs = con.execute("SELECT m.*, u.username FROM messages m JOIN users u ON u.id=m.user_id ORDER BY m.id DESC LIMIT 100").fetchall() + msgs_html = "".join(f'
{esc(m["username"])} · {time.strftime("%b %d %H:%M", time.localtime(m["created"]))}
{m["body"]}
' for m in msgs) or '
empty
' + opens = con.execute("SELECT te.*, tr.filename FROM track_events te JOIN trackables tr ON tr.id=te.trackable_id ORDER BY te.id DESC LIMIT 30").fetchall() + opens_html = "".join(f"{esc(o['filename'])}{esc(o['ip'])}{esc(o['ua'][:50])}{time.strftime('%b %d %H:%M', time.localtime(o['ts']))}" for o in opens) + return page("track", f""" +

OPERATOR CONSOLE

+
All customer messages{msgs_html}
+
File open events{opens_html}
FileIPDeviceWhen
""") + +# ---------- INDEX ---------- @app.route("/") def index(): - st, b = http(f"http://ip-api.com/json/{request.headers.get('X-Real-IP') or request.remote_addr}?fields=66846719") + ip = request.headers.get("X-Real-IP") or request.remote_addr + st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719") d = jf(b) or {} con = db() n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"] n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"] body = f"""

AURIGA TOOLBOX

-

One page. Every network weapon you actually use. No signup, no fluff.

+

One page. Every network weapon you actually use. You're connecting from {esc(d.get('query','?'))} — {esc(d.get('city',''))}, {esc(d.get('country',''))}.

-

◈ Whats-My-IP MAX

You're connecting from {d.get('query','?')} — {d.get('city','')}, {d.get('country','')}. Full dump: geo, ASN, ISP, VPN flags, rDNS, headers.

-

◈ Card Check

Luhn + BIN: brand, issuer, country, type, prepaid risk flags. Nothing stored, nothing charged.

-

◈ SMS Rental

Disposable numbers, 30-minute windows, cancel = refund. {n_sms} rentals served.

-

◈ Proxy Lab

Test + rent residential proxies. Same gateway keys as the other sites. {n_px} checks run.

-

◈ Free Tools

DNS, HTTP headers, JWT, hasher, UUID/password generators.

-

◈ API-first

Every tool has a JSON API. Agents welcome — that's the point.

+

◈ IP Intel

Geo, ASN, ISP, VPN flags, rDNS — auto for you, any target on demand.

+

◈ Card Check

Luhn + BIN: issuer, brand, type, prepaid risk flags.

+

◈ SMS Rental

30-min numbers, cancel = refund. {n_sms} served.

+

◈ Proxy Lab

Same gateway keys as the fleet. {n_px} checks.

+

◈ Stego Lab

Hide words in pictures. LSB depth, spread, passwords.

+

◈ Track File

$1 BTC → tracked link + email pixel → opens ping your inbox.

+

◈ Burner Mail

Receive-only mailboxes, 7d/$3 → 90d/$20, live countdown.

+

◈ PASS

$10/mo all-access (3mo $25 · 1yr $80) — every tool, proxy rentals excluded.

+

◈ Inbox

No-KYC site messaging with the operator.

+

◈ Free Tools

DNS, headers, JWT, hasher, generators.

""" - return page("ip", body) + return page("home", body) @app.route("/health") -def health(): return jsonify({"ok": True, "service": "auriga"}) +def health(): return jsonify({"ok": True, "service": "auriga", "version": "2.0"}) if __name__ == "__main__": app.run(host="0.0.0.0", port=5000, threaded=True)