1756 lines
115 KiB
Python
1756 lines
115 KiB
Python
#!/usr/bin/env python3
|
||
"""Dark0rbits v2 — toolbox: IP intel, card validator, SMS rentals, proxy lab, stego lab,
|
||
trackable files (BTCPay), no-KYC site-only messaging inbox. Single-file Flask + SQLite."""
|
||
import base64, binascii, hashlib, hmac, html, io, json, os, re, secrets, socket, sqlite3, struct, time, uuid
|
||
import urllib.request, urllib.parse
|
||
from flask import Flask, request, jsonify, render_template_string, Response, send_file
|
||
|
||
from flask import redirect
|
||
app = Flask(__name__)
|
||
DB_PATH = os.environ.get("DARK0RBITS_DB", "/opt/dark0rbits/dark0rbits.db")
|
||
UPLOAD_DIR = os.environ.get("DARK0RBITS_UPLOADS", "/opt/dark0rbits/uploads")
|
||
os.makedirs(UPLOAD_DIR, exist_ok=True)
|
||
SMSP_KEY = os.environ.get("SMSP_KEY", "")
|
||
PLEIADES_GW = os.environ.get("PLEIADES_GW", "10.30.20.178:8080")
|
||
PLEIADES_APP = os.environ.get("PLEIADES_APP", "https://pleiades.thetempleofdoom.com")
|
||
BTCPAY = "https://10.30.20.140/api/v1"
|
||
BTCPAY_KEY = os.environ.get("BTCPAY_KEY", "6026288e2e315984661c748baafd509e81a75f22")
|
||
BTCPAY_STORE = os.environ.get("BTCPAY_STORE", "7h79ndYyZX2yF6CPa12xt2uVGQ5Fd6nrSDG4Koy86x6u")
|
||
WEBCHECK = os.environ.get("WEBCHECK", "http://10.30.20.13:3000")
|
||
ADMIN_PW = os.environ.get("DARK0RBITS_ADMIN", "Czapiewski1!")
|
||
BTCPAY_WHSEC = os.environ.get("BTCPAY_WHSEC", "TgJhmoBcNf9ATK2SFCg1VS")
|
||
BMAC = "https://buymeacoffee.com/r26xrthzttg"
|
||
SITE = "https://dark0rbits.thetempleofdoom.com"
|
||
|
||
def db():
|
||
con = sqlite3.connect(DB_PATH); con.row_factory = sqlite3.Row
|
||
con.executescript("""CREATE TABLE IF NOT EXISTS sms_rentals(id INTEGER PRIMARY KEY, phone TEXT, service TEXT, country TEXT, purchase_id TEXT, cost REAL, status TEXT, created INTEGER, expires INTEGER);
|
||
CREATE TABLE IF NOT EXISTS proxy_checks(id INTEGER PRIMARY KEY, user_key TEXT, egress_ip TEXT, geo TEXT, ok INTEGER, ts INTEGER);
|
||
CREATE TABLE IF NOT EXISTS users(id INTEGER PRIMARY KEY, username TEXT UNIQUE, passhash TEXT, created INTEGER);
|
||
CREATE TABLE IF NOT EXISTS sessions(id INTEGER PRIMARY KEY, token TEXT UNIQUE, user_id INTEGER, created INTEGER);
|
||
CREATE TABLE IF NOT EXISTS trackables(id INTEGER PRIMARY KEY, user_id INTEGER, token TEXT UNIQUE, filename TEXT, kind TEXT, invoice_id TEXT, paid INTEGER DEFAULT 0, created INTEGER);
|
||
CREATE TABLE IF NOT EXISTS track_events(id INTEGER PRIMARY KEY, trackable_id INTEGER, ts INTEGER, ip TEXT, ua TEXT);
|
||
CREATE TABLE IF NOT EXISTS messages(id INTEGER PRIMARY KEY, user_id INTEGER, sender TEXT, body TEXT, created INTEGER);
|
||
CREATE TABLE IF NOT EXISTS mailboxes(id INTEGER PRIMARY KEY, user_id INTEGER, address TEXT UNIQUE, invoice_id TEXT, paid INTEGER DEFAULT 0, expires INTEGER DEFAULT 0, created INTEGER, plan_days INTEGER DEFAULT 7, cnt INTEGER DEFAULT 0);
|
||
CREATE TABLE IF NOT EXISTS mails(id INTEGER PRIMARY KEY, mailbox_id INTEGER, sender TEXT, subject TEXT, body TEXT, ts INTEGER);
|
||
CREATE TABLE IF NOT EXISTS passes(id INTEGER PRIMARY KEY, user_id INTEGER, invoice_id TEXT, paid INTEGER DEFAULT 0, expires INTEGER DEFAULT 0, plan_days INTEGER DEFAULT 30);
|
||
CREATE TABLE IF NOT EXISTS canaries(id INTEGER PRIMARY KEY, user_id INTEGER, token TEXT UNIQUE, tag TEXT, created INTEGER, armed INTEGER DEFAULT 1);
|
||
CREATE TABLE IF NOT EXISTS canary_hits(id INTEGER PRIMARY KEY, canary_id INTEGER, ts INTEGER, ip TEXT, ua TEXT);
|
||
CREATE TABLE IF NOT EXISTS balances(user_id INTEGER PRIMARY KEY, cents INTEGER DEFAULT 0);
|
||
CREATE TABLE IF NOT EXISTS apikeys(id INTEGER PRIMARY KEY, user_id INTEGER, key TEXT UNIQUE, label TEXT, created INTEGER, revoked INTEGER DEFAULT 0);
|
||
CREATE TABLE IF NOT EXISTS ledger(id INTEGER PRIMARY KEY, user_id INTEGER, delta_cents INTEGER, reason TEXT, ts INTEGER);
|
||
CREATE TABLE IF NOT EXISTS wh_processed(invoice_id TEXT PRIMARY KEY, ts INTEGER);""")
|
||
return con
|
||
|
||
# ---------- BILLING CORE (per-call metering for outside users) ----------
|
||
def get_balance(uid):
|
||
con = db()
|
||
con.execute("INSERT OR IGNORE INTO balances(user_id, cents) VALUES(?, 100)", (uid,)) # $1 free trial credit
|
||
con.commit()
|
||
return con.execute("SELECT cents FROM balances WHERE user_id=?", (uid,)).fetchone()["cents"]
|
||
|
||
def charge(uid, cents, reason):
|
||
"""Deduct from balance; return False if insufficient."""
|
||
if cents <= 0: return True
|
||
if get_balance(uid) < cents: return False
|
||
con = db()
|
||
con.execute("UPDATE balances SET cents = cents - ? WHERE user_id=?", (cents, uid))
|
||
con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, -cents, reason, int(time.time())))
|
||
con.commit()
|
||
return True
|
||
|
||
def key_user():
|
||
"""API-key auth: Authorization: Bearer dk_... → user_id or None."""
|
||
auth = request.headers.get("Authorization", "")
|
||
if not auth.startswith("Bearer dk_"): return None
|
||
con = db()
|
||
r = con.execute("SELECT user_id FROM apikeys WHERE key=? AND revoked=0", (auth[7:],)).fetchone()
|
||
return r["user_id"] if r else None
|
||
|
||
def require_paid_key(cents, reason):
|
||
"""For API calls: key or session auth; metered charge. Returns (uid, error_json)."""
|
||
uid = key_user() or current_user_id()
|
||
if not uid: return None, (jsonify({"ok": False, "error": "auth required: account session or Authorization: Bearer dk_… key"}), 401)
|
||
if has_pass(uid): return uid, None # PASS = unlimited tools (proxy excluded)
|
||
if not charge(uid, cents, reason):
|
||
return None, (jsonify({"ok": False, "error": "insufficient balance", "balance_cents": get_balance(uid), "topup": SITE + "/keys"}), 402)
|
||
return uid, None
|
||
|
||
import ssl as _ssl
|
||
_CTX = _ssl.create_default_context()
|
||
_CTX.check_hostname = False
|
||
_CTX.verify_mode = _ssl.CERT_NONE
|
||
|
||
def http(url, headers=None, data=None, method="GET", timeout=12):
|
||
h = {"User-Agent": "Mozilla/5.0 (Dark0rbits toolbox)"}
|
||
h.update(headers or {})
|
||
req = urllib.request.Request(url, headers=h, data=data, method=method)
|
||
try:
|
||
with urllib.request.urlopen(req, timeout=timeout, context=_CTX) as r:
|
||
return r.status, r.read().decode("utf-8", "replace")
|
||
except urllib.error.HTTPError as e:
|
||
return e.code, e.read().decode("utf-8", "replace")
|
||
except Exception as e:
|
||
return 0, str(e)
|
||
|
||
def jf(b):
|
||
try: return json.loads(b)
|
||
except Exception: return None
|
||
|
||
def param(name):
|
||
return request.form.get(name) or request.args.get(name)
|
||
|
||
def esc(s): return html.escape(str(s))
|
||
|
||
BASE = """<!doctype html><html lang=en><head><meta charset=utf-8><meta name=viewport content="width=device-width,initial-scale=1">
|
||
<title>DARK0RBITS — No-KYC Network Toolbox: IP Intel, Stego, Burner Mail, SMS Rentals, Proxy Lab</title>
|
||
<meta name=description content="DARK0RBITS: a no-KYC toolbox for operators and AI agents. IP intelligence, card BIN validation, burner mail, SMS number rentals, steganography, trackable files, email & image forensics, canary traps, residential proxy testing. BTC only.">
|
||
<meta name=keywords content="dark0rbits, no kyc tools, ip lookup, bin check, burner email, sms rental, steganography, stego, email forensics, image forensics, canary trap, proxy, bitcoin only, agent api">
|
||
<meta property="og:title" content="DARK0RBITS — The Operator's Toolbox">
|
||
<meta property="og:description" content="No-KYC network toolbox for humans and AI agents. BTC only. 12 tools, every one with a JSON API.">
|
||
<meta property="og:type" content="website">
|
||
<meta property="og:url" content="https://dark0rbits.thetempleofdoom.com">
|
||
<meta name=robots content="index,follow">
|
||
<meta name=theme-color content="#070a13">
|
||
<link rel=canonical href="https://dark0rbits.thetempleofdoom.com">
|
||
<style>
|
||
:root{--bg:#070a13;--card:rgba(19,25,44,.82);--line:#242e4d;--fg:#e9edf8;--dim:#93a0c2;--acc:#ffc94d;--acc2:#6fd6ff;--acc3:#a78bfa;--ok:#42e8a4;--bad:#ff6161}
|
||
*{box-sizing:border-box}
|
||
html{scroll-behavior:smooth}
|
||
body{margin:0;min-height:100vh;color:var(--fg);font:16px/1.6 ui-monospace,Menlo,Consolas,monospace;text-align:center;overflow-x:hidden;background:var(--bg)}
|
||
#space{position:fixed;inset:0;z-index:0;display:block}
|
||
.vignette{position:fixed;inset:0;z-index:1;pointer-events:none;background:radial-gradient(ellipse at 50% -10%,var(--neb1,rgba(120,85,255,.16)),transparent 55%),radial-gradient(ellipse at 80% 110%,var(--neb2,rgba(0,190,255,.10)),transparent 50%),radial-gradient(ellipse at 50% 50%,transparent 60%,rgba(0,0,5,.55) 100%)}
|
||
main{position:relative;z-index:2;max-width:920px;margin:0 auto;padding:1.6rem 1.1rem 4rem;text-align:center}
|
||
#lbar{position:fixed;top:0;left:0;height:3px;width:0;background:linear-gradient(90deg,var(--acc),var(--acc3));z-index:50;transition:width .3s;box-shadow:0 0 10px var(--acc)}
|
||
#lbar.done{width:100%;opacity:0;transition:opacity .5s}
|
||
header{position:sticky;top:0;z-index:40;background:rgba(7,10,19,.86);backdrop-filter:blur(10px);border-bottom:1px solid var(--line)}
|
||
.hbar{max-width:920px;margin:0 auto;display:flex;align-items:center;justify-content:space-between;padding:.55rem 1rem}
|
||
.logo{color:var(--acc);text-decoration:none;font-weight:800;letter-spacing:.28em;font-size:1rem;text-shadow:0 0 18px rgba(255,201,77,.35)}
|
||
.burger{background:none;border:1px solid var(--line);color:var(--fg);font-size:1.15rem;border-radius:8px;padding:.35rem .7rem;cursor:pointer}
|
||
.burger:hover{border-color:var(--acc);color:var(--acc)}
|
||
.dnav{display:flex;flex-wrap:wrap;gap:.35rem;justify-content:center}
|
||
.dnav a{color:var(--dim);text-decoration:none;font-size:.72rem;padding:.3rem .55rem;border:1px solid var(--line);border-radius:999px;white-space:nowrap;transition:.15s}
|
||
.dnav a.on,.dnav a:hover{color:var(--acc);border-color:var(--acc)}
|
||
.drawer{position:fixed;inset:0;z-index:60;background:rgba(7,10,19,.96);backdrop-filter:blur(6px);display:none;flex-direction:column;padding:1.2rem;overflow-y:auto}
|
||
.drawer.open{display:flex}
|
||
.drawer .dhead{display:flex;justify-content:space-between;align-items:center;margin-bottom:.8rem}
|
||
.drawer h4{color:var(--dim);font-size:.75rem;letter-spacing:.25em;text-align:left;margin:1rem 0 .4rem;text-transform:uppercase}
|
||
.drawer a.dl{color:var(--fg);text-decoration:none;padding:.65rem .8rem;border:1px solid var(--line);border-radius:10px;margin:.25rem 0;text-align:left;font-size:.95rem}
|
||
.drawer a.dl:hover,.drawer a.dl.on{border-color:var(--acc);color:var(--acc)}
|
||
.drawer a.dl small{display:block;color:var(--dim);font-size:.72rem}
|
||
@media(min-width:860px){.burger{display:none}}
|
||
@media(max-width:859px){.dnav{display:none}}
|
||
h1{font-size:1.55rem;letter-spacing:.18em;margin:.8rem 0 .2rem}
|
||
h1 span{color:var(--acc)}
|
||
.sub{color:var(--dim);margin:.2rem 0 1.4rem;font-size:.95rem}
|
||
.card{background:var(--card);border:1px solid var(--line);border-radius:16px;padding:1.15rem 1.2rem;margin:.9rem 0;backdrop-filter:blur(4px)}
|
||
.card.glow{box-shadow:0 0 34px -16px var(--acc)}
|
||
.kv{display:grid;grid-template-columns:1fr;gap:.25rem;text-align:left}
|
||
.kv div:nth-child(odd){color:var(--dim);font-size:.78rem;letter-spacing:.12em;text-transform:uppercase;padding-top:.45rem}
|
||
.kv div:nth-child(even){background:rgba(255,255,255,.03);border-radius:8px;padding:.35rem .6rem}
|
||
@media(min-width:640px){.kv{grid-template-columns:180px 1fr}.kv div:nth-child(odd){padding-top:.35rem}}
|
||
input,select,button,textarea{font:inherit;background:rgba(10,15,30,.9);color:var(--fg);border:1px solid #2c3860;border-radius:10px;padding:.6rem .8rem;max-width:100%}
|
||
button{background:linear-gradient(135deg,var(--acc),#ff9d3c);color:#161000;border:0;font-weight:800;cursor:pointer;transition:.2s;letter-spacing:.05em}
|
||
button:hover{filter:brightness(1.12);box-shadow:0 0 18px -4px var(--acc)}
|
||
button.ghost{background:transparent;color:var(--acc);border:1px solid var(--acc)}
|
||
button.big{font-size:1.02rem;padding:.75rem 1.4rem;margin:.25rem}
|
||
.grid2{display:grid;grid-template-columns:1fr;gap:.9rem;text-align:center}
|
||
@media(min-width:700px){.grid2{grid-template-columns:1fr 1fr}}
|
||
.tag{display:inline-block;padding:.14rem .6rem;border-radius:999px;font-size:.74rem;border:1px solid;margin:.15rem}
|
||
.tag.ok{color:var(--ok);border-color:var(--ok)}.tag.bad{color:var(--bad);border-color:var(--bad)}.tag.warn{color:var(--acc);border-color:var(--acc)}
|
||
table{width:100%;border-collapse:collapse;font-size:.85rem}
|
||
td,th{padding:.4rem;border-bottom:1px solid var(--line);text-align:left}
|
||
th{color:var(--dim);text-transform:uppercase;font-size:.7rem;letter-spacing:.14em}
|
||
footer{color:var(--dim);padding:2.2rem 1rem 5rem;font-size:.8rem;position:relative;z-index:2;text-align:center}
|
||
footer a{color:var(--acc)}
|
||
code{background:rgba(10,15,30,.9);padding:.08rem .4rem;border-radius:5px;font-size:.86em;word-break:break-all}
|
||
a{color:var(--acc2)}
|
||
pre{text-align:left;white-space:pre-wrap;overflow-x:auto}
|
||
.drop{border:2px dashed #33406b;border-radius:14px;padding:1.8rem 1rem;cursor:pointer;transition:.2s}
|
||
.drop:hover,.drop.over{border-color:var(--acc);background:rgba(255,201,77,.05)}
|
||
.msg{background:rgba(10,15,30,.75);border-left:3px solid var(--acc);border-radius:0 10px 10px 0;padding:.6rem .9rem;margin:.55rem 0;text-align:left}
|
||
.msg.me{border-left-color:var(--acc2)}
|
||
.msg .who{color:var(--dim);font-size:.74rem}
|
||
.bar{height:7px;background:rgba(10,15,30,.9);border-radius:4px;overflow:hidden}.bar>i{display:block;height:100%;background:linear-gradient(90deg,var(--acc),var(--acc3));width:0;transition:width .5s}
|
||
#dev{position:fixed;bottom:14px;right:14px;z-index:45;background:rgba(19,25,44,.92);border:1px solid var(--acc);color:var(--acc);border-radius:999px;padding:.5rem .9rem;font-size:.8rem;text-decoration:none;box-shadow:0 0 18px -6px var(--acc)}
|
||
#dev:hover{background:var(--acc);color:#161000}
|
||
img{max-width:100%;border-radius:10px}
|
||
li{text-align:left;margin:.2rem 0}
|
||
</style></head><body>
|
||
<div id="lbar"></div>
|
||
<canvas id="space"></canvas><div class="vignette" style="--neb1:{{n1}};--neb2:{{n2}}"></div>
|
||
<header><div class="hbar">
|
||
<a class=logo href=/ >◈ DARK0RBITS</a>
|
||
<div class="dnav">
|
||
<a href=/ class={{o(home)}}>HOME</a><a href=/ip class={{o(ip)}}>IP</a><a href=/card class={{o(card)}}>CARD</a>
|
||
<a href=/sms class={{o(sms)}}>SMS</a><a href=/proxy class={{o(proxy)}}>PROXY</a>
|
||
<a href=/steg class={{o(steg)}}>STEGO</a><a href=/track class={{o(track)}}>TRACK</a>
|
||
<a href=/eh class={{o(eh)}}>MAIL-FORENSICS</a><a href=/forensics class={{o(forensics)}}>IMG-FORENSICS</a>
|
||
<a href=/canary class={{o(canary)}}>CANARY</a><a href=/mail class={{o(mail)}}>BURNER-MAIL</a>
|
||
<a href=/inbox class={{o(inbox)}}>INBOX</a><a href=/passport class={{o(passport)}}>PASSPORT</a>
|
||
<a href=/pass class={{o(pass)}}>PASS</a><a href=/keys class={{o(keys)}}>KEYS</a><a href=/tools class={{o(tools)}}>TOOLS</a>
|
||
</div>
|
||
<button class=burger id=burger onclick="drw()">☰</button>
|
||
</div></header>
|
||
<div class=drawer id=drawer>
|
||
<div class=dhead><span class=logo style=font-size:.85rem>DARK0RBITS — MAP</span><button class=burger onclick="drw()">✕</button></div>
|
||
<h4>Intel</h4>
|
||
<a class="dl {{o(ip)}}" href=/ip>◈ IP INTEL <small>geo, ASN, ISP, VPN flags — any target</small></a>
|
||
<a class="dl {{o(card)}}" href=/card>◈ CARD CHECK <small>luhn + BIN issuer intelligence</small></a>
|
||
<a class="dl {{o(eh)}}" href=/eh>◈ MAIL FORENSICS <small>origin + SPF/DKIM/DMARC + spoof flags</small></a>
|
||
<a class="dl {{o(forensics)}}" href=/forensics>◈ IMAGE FORENSICS <small>EXIF, GPS, ELA, edit detection</small></a>
|
||
<h4>Operate</h4>
|
||
<a class="dl {{o(sms)}}" href=/sms>◈ SMS RENTAL <small>30-min numbers, refundable</small></a>
|
||
<a class="dl {{o(proxy)}}" href=/proxy>◈ PROXY LAB <small>residential egress, geo builder</small></a>
|
||
<a class="dl {{o(steg)}}" href=/steg>◈ STEGO LAB <small>hide words in pictures</small></a>
|
||
<a class="dl {{o(mail)}}" href=/mail>◈ BURNER MAIL <small>receive-only mailboxes, countdown</small></a>
|
||
<h4>Hunt</h4>
|
||
<a class="dl {{o(track)}}" href=/track>◈ TRACK FILE <small>opens report back: IP, city, ISP</small></a>
|
||
<a class="dl {{o(canary)}}" href=/canary>◈ CANARY TRAPS <small>tripwires with instant alerts</small></a>
|
||
<a class="dl {{o(tools)}}" href=/tools>◈ FREE TOOLS <small>DNS, headers, JWT, hasher</small></a>
|
||
<h4>Account</h4>
|
||
<a class="dl {{o(inbox)}}" href=/inbox>◈ INBOX <small>no-KYC messaging</small></a>
|
||
<a class="dl {{o(keys)}}" href=/keys>◈ API KEYS <small>metered access, balance</small></a>
|
||
<a class="dl {{o(pass)}}" href=/pass>◈ PASS <small>$10/mo all-access</small></a>
|
||
<a class="dl {{o(passport)}}" href=/passport>◈ AGENT PASSPORT <small>machine-readable badge</small></a>
|
||
</div>
|
||
<main>{{body}}</main>
|
||
<footer>DARK0RBITS · built for agents & humans · <a href="{{bmac}}" target=_blank rel=noopener>☕ fuel the lab</a></footer>
|
||
<a id=dev href="#" onclick="location.href='mailto:'+atob('bWFrZW1vbmV5czhAcHJvdG9uLm1l')+'?subject=Dark0rbits%20support';return false">✦ REACH THE DEV</a>
|
||
<script defer src="https://analytics.thetempleofdoom.com/script.js" data-website-id="953c15df-ba4c-453a-a7c6-465fa9e3f202"></script>
|
||
<script>
|
||
function drw(){document.getElementById('drawer').classList.toggle('open')}
|
||
function cp(t){navigator.clipboard.writeText(t).then(function(){toast('Copied ✓')})}
|
||
function toast(m){var d=document.createElement('div');d.textContent=m;d.style.cssText='position:fixed;bottom:60px;left:50%;transform:translateX(-50%);background:var(--acc);color:#161000;padding:.55rem 1.1rem;border-radius:10px;font-weight:800;z-index:99';document.body.appendChild(d);setTimeout(function(){d.remove()},1800)}
|
||
var lb=document.getElementById('lbar');
|
||
function lbGo(){lb.classList.remove('done');lb.style.width='12%';var w=12;var t=setInterval(function(){w=Math.min(w+6,88);lb.style.width=w+'%'},250);window._lbt=t}
|
||
function lbDone(){if(window._lbt)clearInterval(window._lbt);lb.style.width='100%';setTimeout(function(){lb.style.width='0';lb.classList.remove('done')},600)}
|
||
document.addEventListener('submit',lbGo,true);
|
||
document.addEventListener('click',function(e){var a=e.target.closest('a[href]');if(a&&a.getAttribute('href')&&a.getAttribute('href').charAt(0)==='/'){lbGo();setTimeout(lbDone,1200)}},true);
|
||
window.addEventListener('load',lbDone);
|
||
(function(){
|
||
var c=document.getElementById('space'),x=c.getContext('2d'),W,H,stars=[],dust=[];
|
||
function rs(){W=c.width=innerWidth;H=c.height=innerHeight;
|
||
stars=[];var n=Math.min(220,Math.floor(W*H/7000));
|
||
for(var i=0;i<n;i++)stars.push({x:Math.random()*W,y:Math.random()*H,z:Math.random()+.3,tw:Math.random()*6.28});
|
||
dust=[];for(i=0;i<14;i++)dust.push({x:Math.random()*W,y:Math.random()*H,r:40+Math.random()*90,vx:(Math.random()-.5)*.08,vy:(Math.random()-.5)*.06,h:Math.random()<.5?120:265,a:.05+Math.random()*.05});}
|
||
rs();addEventListener('resize',rs);
|
||
var mx=0,my=0,tx=0,ty=0;
|
||
addEventListener('mousemove',function(e){tx=(e.clientX/W-.5);ty=(e.clientY/H-.5)});
|
||
addEventListener('touchmove',function(e){if(e.touches[0]){tx=(e.touches[0].clientX/W-.5);ty=(e.touches[0].clientY/H-.5)}},{passive:true});
|
||
function frame(){
|
||
x.clearRect(0,0,W,H);
|
||
for(var i=0;i<dust.length;i++){var d=dust[i];d.x+=d.vx;d.y+=d.vy;
|
||
if(d.x<-100)d.x=W+80;if(d.x>W+100)d.x=-80;if(d.y<-100)d.y=H+80;if(d.y>H+100)d.y=-80;
|
||
var g=x.createRadialGradient(d.x,d.y,0,d.x,d.y,d.r);
|
||
g.addColorStop(0,'hsla('+d.h+',70%,60%,'+d.a+')');g.addColorStop(1,'transparent');
|
||
x.fillStyle=g;x.beginPath();x.arc(d.x,d.y,d.r,0,6.29);x.fill();}
|
||
mx+=(tx-mx)*.03;my+=(ty-my)*.03;
|
||
for(i=0;i<stars.length;i++){var s=stars[i];s.tw+=.02;
|
||
var px=s.x+mx*s.z*40, py=s.y+my*s.z*40;
|
||
var a=.35+.45*Math.abs(Math.sin(s.tw));
|
||
x.fillStyle='rgba(220,228,255,'+(a*s.z)+')';
|
||
x.beginPath();x.arc(px,py,s.z*1.25,0,6.29);x.fill();}
|
||
requestAnimationFrame(frame);}
|
||
frame();
|
||
})();
|
||
</script>
|
||
</body></html>
|
||
"""
|
||
|
||
NEBULAS = {
|
||
"home": ("rgba(120,85,255,.17)", "rgba(0,190,255,.10)"),
|
||
"ip": ("rgba(255,170,60,.13)", "rgba(120,85,255,.10)"),
|
||
"card": ("rgba(66,232,164,.10)", "rgba(0,190,255,.09)"),
|
||
"sms": ("rgba(0,190,255,.13)", "rgba(167,139,250,.10)"),
|
||
"proxy": ("rgba(167,139,250,.14)", "rgba(255,170,60,.08)"),
|
||
"steg": ("rgba(255,110,180,.11)", "rgba(120,85,255,.11)"),
|
||
"track": ("rgba(255,90,90,.11)", "rgba(255,170,60,.08)"),
|
||
"mail": ("rgba(66,232,164,.10)", "rgba(0,190,255,.08)"),
|
||
"forensics": ("rgba(0,210,255,.12)", "rgba(255,110,180,.07)"),
|
||
"canary": ("rgba(255,201,77,.12)", "rgba(255,90,90,.08)"),
|
||
}
|
||
def kv(pairs):
|
||
rows = "".join(f"<div>{k}</div><div>{v}</div>" for k, v in pairs)
|
||
return '<div class="card glow"><div class="kv">' + rows + "</div></div>"
|
||
|
||
def page(sec, body):
|
||
n1, n2 = NEBULAS.get(sec, ("rgba(120,85,255,.16)", "rgba(0,190,255,.10)"))
|
||
return render_template_string(BASE, body=body, bmac=BMAC, o=lambda s: "on" if s == sec else "",
|
||
n1=n1, n2=n2)
|
||
|
||
def how(steps):
|
||
lis = "".join(f"<li>{esc(s)}</li>" for s in steps)
|
||
return f'<div class=card><b>HOW IT WORKS</b><ol style="color:var(--dim);margin:.4rem 0 0;padding-left:1.2rem">{lis}</ol></div>'
|
||
|
||
# ---------- AGENT DISCOVERY ----------
|
||
API_INDEX = {
|
||
"service": "dark0rbits",
|
||
"description": "IP intel, card BIN validation, 30-min SMS rentals, residential proxy lab, steganography, trackable files, no-KYC messaging, utilities.",
|
||
"endpoints": [
|
||
{"method": "GET", "path": "/api/ip?target=", "desc": "Caller IP intel (auto) or any IP you pass: geo, ASN, ISP, VPN/hosting flags, rDNS."},
|
||
{"method": "POST", "path": "/api/card", "params": {"num": "card number"}, "desc": "Luhn + BIN intel. Nothing stored/charged."},
|
||
{"method": "POST", "path": "/api/sms/rent", "params": {"service": "id/keyword", "country": "id"}, "desc": "Rent disposable number, 30 min, refundable."},
|
||
{"method": "GET", "path": "/api/sms/check?pid=", "desc": "Poll SMS code."},
|
||
{"method": "GET", "path": "/api/sms/cancel?pid=", "desc": "Cancel + refund."},
|
||
{"method": "GET", "path": "/api/sms/history", "desc": "Rental history."},
|
||
{"method": "POST", "path": "/api/proxy/test", "params": {"user": "Pleiades user", "pass": "password"}, "desc": "Tunnel CONNECT via Pleiades gateway, return egress IP/geo."},
|
||
{"method": "POST", "path": "/api/steg/hide", "params": {"image": "png file", "text": "secret", "password": "optional", "bits": "1-3", "spread": "sequential|random"}, "desc": "LSB steganography → PNG download."},
|
||
{"method": "POST", "path": "/api/steg/extract", "params": {"image": "png file", "password": "optional"}, "desc": "Extract hidden text."},
|
||
{"method": "POST", "path": "/api/track/create", "params": {"filename": "name"}, "desc": "Create $1 BTCPay invoice for a trackable file. Returns checkoutLink."},
|
||
{"method": "GET", "path": "/api/track/events?token=", "desc": "Open events for a trackable (auth via account)."},
|
||
{"method": "GET", "path": "/api/hash?s=", "desc": "md5/sha1/sha256/sha512."},
|
||
{"method": "GET", "path": "/api/hdr?url=", "desc": "Fetch URL, return status + headers."},
|
||
],
|
||
"payment": "BTCPay BTC only (no Stripe). SMS meters to house account; trackables $1 each.",
|
||
}
|
||
|
||
@app.route("/api")
|
||
def api_index(): return jsonify(API_INDEX)
|
||
|
||
@app.route("/robots.txt")
|
||
def robots(): return "User-agent: *\nAllow: /\nSitemap: https://dark0rbits.thetempleofdoom.com/sitemap.xml\n", 200, {"Content-Type": "text/plain"}
|
||
|
||
@app.route("/a8f3dark0rbitskey.txt")
|
||
def indexnow_key(): return "a8f3d4rk0rbits9e2b1c7x5k8m2v4q6t8", 200, {"Content-Type": "text/plain"}
|
||
|
||
INDEXNOW = "a8f3d4rk0rbits9e2b1c7x5k8m2v4q6t8"
|
||
|
||
@app.route("/sitemap.xml")
|
||
def sitemap():
|
||
S = "https://dark0rbits.thetempleofdoom.com"
|
||
pages = ["", "ip", "card", "sms", "proxy", "steg", "track", "eh", "forensics", "canary", "mail", "inbox", "passport", "pass", "keys", "tools"]
|
||
xml = '<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">' + "".join(f"<url><loc>{S}/{p}</loc><changefreq>weekly</changefreq></url>" for p in pages) + "</urlset>"
|
||
return xml, 200, {"Content-Type": "application/xml"}
|
||
|
||
@app.route("/llms.txt")
|
||
def llms():
|
||
eps = "\n".join(f"- `{e['method']} {e['path']}` — {e['desc']}" for e in API_INDEX["endpoints"])
|
||
return f"# Dark0rbits\n\nBase: {SITE}\n\n## API\n{eps}\n", 200, {"Content-Type": "text/plain"}
|
||
|
||
@app.route("/ai-plugin.json")
|
||
def aiplugin():
|
||
return jsonify({"name_for_model": "dark0rbits", "schema_version": "v1",
|
||
"description_for_model": "IP intelligence, card BIN validation, SMS number rentals, proxy egress testing, LSB steganography, trackable file links with open-notifications, no-KYC site messaging.",
|
||
"api": {"type": "openapi", "url": SITE + "/openapi.json"}, "auth": {"type": "none"}, "contact_email": "indianaholmes1@icloud.com"})
|
||
|
||
@app.route("/openapi.json")
|
||
def openapi():
|
||
ps = {"openapi": "3.0.0", "info": {"title": "DARK0RBITS", "version": "2.0.0"}, "paths": {}}
|
||
def add(path, method, desc, params=None, req=False, files=None):
|
||
item = {"summary": desc}
|
||
if files:
|
||
item["requestBody"] = {"content": {"multipart/form-data": {"schema": {"type": "object", "properties": {**{k: {"type": "string"} for k, v in (params or {}).items()}, **{f: {"type": "string", "format": "binary"} for f in files}}}}}}
|
||
elif params:
|
||
if method == "get":
|
||
item["parameters"] = [{"name": k, "in": "query", "required": req, "schema": {"type": "string"}} for k in params]
|
||
else:
|
||
item["requestBody"] = {"content": {"application/x-www-form-urlencoded": {"schema": {"type": "object", "properties": {k: {"type": "string"} for k in params}}}}}
|
||
ps["paths"][path] = ps["paths"].get(path, {}) | {method: {"responses": {"200": {"description": "ok"}}, **item}}
|
||
add("/api/ip", "get", "IP intel (caller or ?target=)", {"target": "optional IP"})
|
||
add("/api/card", "post", "Luhn + BIN validation", {"num": "card number"}, req=True)
|
||
add("/api/sms/rent", "post", "Rent number 30 min", {"service": "id", "country": "id"}, req=True)
|
||
add("/api/sms/check", "get", "Poll SMS code", {"pid": "orderid"}, req=True)
|
||
add("/api/sms/cancel", "get", "Cancel + refund", {"pid": "orderid"}, req=True)
|
||
add("/api/sms/history", "get", "Rental history")
|
||
add("/api/proxy/test", "post", "Test Pleiades gateway creds", {"user": "user", "pass": "pass"}, req=True)
|
||
add("/api/steg/hide", "post", "LSB-hide text in PNG", {"text": "secret", "password": "opt"}, req=True, files=["image"])
|
||
add("/api/steg/extract", "post", "Extract text from PNG", {"password": "opt"}, files=["image"])
|
||
add("/api/track/create", "post", "Create $1 invoice for trackable", {"filename": "name"}, req=True)
|
||
add("/api/track/events", "get", "Trackable open events", {"token": "token"}, req=True)
|
||
add("/api/hash", "get", "Hashes", {"s": "string"}, req=True)
|
||
add("/api/hdr", "get", "HTTP headers", {"url": "url"}, req=True)
|
||
return jsonify(ps)
|
||
|
||
# ---------- 1. IP INTEL (auto + manual target) ----------
|
||
def ip_report(ip):
|
||
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
|
||
d = jf(b) or {}
|
||
try: d["reverse"] = d.get("reverse") or socket.gethostbyaddr(ip)[0]
|
||
except Exception: pass
|
||
return d
|
||
|
||
@app.route("/ip", methods=["GET", "POST"])
|
||
def ip_page():
|
||
target = param("target") if request.method == "POST" else param("target")
|
||
if target and target.strip():
|
||
target = target.strip()
|
||
d = ip_report(target)
|
||
heading = f"INTEL FOR <span>{esc(target)}</span>"
|
||
mine = False
|
||
else:
|
||
ip = request.headers.get("X-Real-IP") or request.remote_addr or ""
|
||
d = ip_report(ip)
|
||
heading = "WHATS <span>MY IP</span>"
|
||
mine = True
|
||
if d.get("status") == "fail" or not d:
|
||
body = f"<h1>{heading}</h1><div class=card><span class=tag bad>lookup failed</span></div>{ip_form()}"
|
||
return page("ip", body)
|
||
rows = [
|
||
("IP", f"<b style='font-size:1.3rem;color:var(--acc)'>{esc(d.get('query'))}</b>"),
|
||
("Country", f"{esc(d.get('country'))} ({esc(d.get('countryCode'))})"),
|
||
("Region / City", f"{esc(d.get('regionName'))} / {esc(d.get('city'))} {esc(d.get('zip'))}"),
|
||
("Lat, Lon", f"{d.get('lat')}, {d.get('lon')} · TZ {esc(d.get('timezone'))}"),
|
||
("ISP", esc(d.get("isp"))), ("Organization", esc(d.get("org"))), ("AS", esc(d.get("as") or d.get("asname"))),
|
||
("Reverse DNS", esc(d.get("reverse") or "—")),
|
||
("Flags", f"mobile: {d.get('mobile')} · proxy/VPN: {d.get('proxy')} · hosting: {d.get('hosting')}"),
|
||
("Currency", esc(d.get("currency"))),
|
||
]
|
||
extra = ""
|
||
if mine:
|
||
hdrs = {k: v for k, v in request.headers.items() if k.lower() in ("user-agent","accept-language","x-forwarded-for","cf-connecting-ip","cf-ipcountry")}
|
||
extra = '<div class=card><b>Headers you sent</b><table>' + "".join(f"<tr><td>{esc(k)}</td><td>{esc(v)}</td></tr>" for k, v in hdrs.items()) + "</table></div>"
|
||
body = f"""
|
||
<h1>{heading}</h1><p class=sub>Auto-detects your IP and shows everything. Want intel on another IP? Type it below — full report, any target.</p>
|
||
{kv(rows)}
|
||
<div class=card><form method=post><input name=target placeholder="any IP or hostname" style="width:70%" value="{esc(param('target') or '')}"> <button>Look up</button></form></div>
|
||
{extra}
|
||
<div class=card style=color:var(--dim)>API: GET /api/ip (caller) · GET /api/ip?target=1.2.3.4 (any target)</div>""" + how(["Your IP is auto-detected the moment the page loads — no input needed.","Type any other IP or hostname into the field for the same full report.","Everything is one GET away for agents: /api/ip and /api/ip?target=.","VPN/proxy/hosting flags come from IP-quality heuristics — if it says proxy, you are looking at a relay."])
|
||
return page("ip", body)
|
||
|
||
def ip_form():
|
||
return '<div class=card><form method=post><input name=target placeholder="IP or hostname"><button>Look up</button></form></div>'
|
||
|
||
@app.route("/api/ip")
|
||
def api_ip():
|
||
target = param("target")
|
||
if target and target.strip():
|
||
return jsonify(ip_report(target.strip()))
|
||
ip = request.headers.get("X-Real-IP") or request.remote_addr or ""
|
||
d = ip_report(ip)
|
||
d["headers_seen"] = dict(request.headers)
|
||
return jsonify(d)
|
||
|
||
# ---------- 2. CARD CHECK ----------
|
||
def luhn_ok(num):
|
||
digits = [int(c) for c in num]
|
||
s = sum(digits[-1::-2])
|
||
for d in digits[-2::-2]:
|
||
d *= 2
|
||
if d > 9: d -= 9
|
||
s += d
|
||
return s % 10 == 0
|
||
|
||
BRANDS = [("4","Visa"),("51","Mastercard"),("52","Mastercard"),("53","Mastercard"),("54","Mastercard"),("55","Mastercard"),
|
||
("22","Mastercard"),("23","Mastercard"),("24","Mastercard"),("25","Mastercard"),("26","Mastercard"),("27","Mastercard"),
|
||
("34","Amex"),("37","Amex"),("6011","Discover"),("65","Discover"),("644","Discover"),("645","Discover"),("646","Discover"),("647","Discover"),("648","Discover"),("649","Discover"),
|
||
("50","Maestro"),("56","Maestro"),("57","Maestro"),("58","Maestro"),("63","Maestro"),("67","Maestro"),
|
||
("30","Diners"),("36","Diners"),("38","Diners"),("39","Diners"),
|
||
("35","JCB"),("62","UnionPay"),("7","Mir")]
|
||
|
||
def brand_of(num):
|
||
for pfx, b in BRANDS:
|
||
if num.startswith(pfx): return b
|
||
return "Unknown"
|
||
|
||
def bin_lookup(bin8):
|
||
st, b = http(f"https://lookup.binlist.net/{bin8}", headers={"Accept-Version": "3"})
|
||
bl = jf(b) or {}
|
||
if not bl.get("bank") and not bl.get("type") and not bl.get("scheme"):
|
||
st, b = http(f"https://data.handyapi.com/bin/{bin8}")
|
||
h = jf(b) or {}
|
||
if h.get("Status") == "SUCCESS":
|
||
return {"bank": {"name": h.get("Issuer")}, "country": {"name": (h.get("Country") or {}).get("Name") if isinstance(h.get("Country"), dict) else h.get("Country")},
|
||
"type": str(h.get("Type", "")).lower() or None, "prepaid": "prepaid" in str(h.get("Type","")).lower() or None, "scheme": h.get("Scheme")}
|
||
return bl
|
||
|
||
@app.route("/card", methods=["GET", "POST"])
|
||
def card():
|
||
result = ""
|
||
num = re.sub(r"\D", "", param("num") or "")[:19]
|
||
if num:
|
||
ok = luhn_ok(num)
|
||
tags = ['<span class="tag ok">LUHN VALID</span>' if ok else '<span class="tag bad">LUHN INVALID — fake/dead number</span>']
|
||
brand = brand_of(num)
|
||
bl = bin_lookup(num[:8])
|
||
bank = (bl.get("bank") or {}).get("name", "—")
|
||
country = (bl.get("country") or {}).get("name", "—")
|
||
ctype = bl.get("type", "—")
|
||
prepaid = bl.get("prepaid", "—")
|
||
flags = []
|
||
if ctype == "prepaid" or prepaid is True: flags.append("PREPAID — commonly flagged by merchants")
|
||
rng = {"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand,(13,15,16,19))
|
||
tags.append(f'<span class="tag ok">length {len(num)} valid for {brand}</span>' if len(num) in rng else f'<span class="tag bad">LENGTH {len(num)} WRONG for {brand}</span>')
|
||
result = f"""
|
||
{kv([("Brand",brand),("BIN",num[:8]),("Bank / Issuer",esc(bank)),("Country",esc(country)),("Type",str(ctype)),("Prepaid",str(prepaid))])}
|
||
<div class=card><b>Fraud & structure flags</b><br>{' '.join(tags)}{'<br>⚠ ' + ' · '.join(flags) if flags else ''}</div>
|
||
<div class=card style=color:var(--dim)>Nothing stored. No charge, no auth — BIN + math validation only. Fraud "flagged" status lives at the issuer.</div>""" + how(["Paste the card number — it never leaves the request, nothing is stored.","Luhn checksum validates the digit structure instantly.","BIN (first 8 digits) reveals the issuer bank, brand, card type and country.","Prepaid BINs get flagged — merchants commonly reject them.","This CANNOT show balance or fraud-hold status; only the issuer knows that."])
|
||
body = f"""
|
||
<h1>CARD <span>CHECK</span></h1><p class=sub>Luhn + BIN intelligence: issuer, brand, type, country, prepaid risk flags.</p>
|
||
<div class=card><form method=post><input id=cardnum name=num placeholder="4539 1488 0343 6467" style="width:70%" value="{esc(' '.join(num[i:i+4] for i in range(0,len(num),4))) if num else ''}" autocomplete=off inputmode=numeric> <button>Check</button></form>
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.4rem>Paste anything — auto-formats. Nothing stored.</div></div>
|
||
<script>
|
||
var cn=document.getElementById('cardnum');
|
||
cn.addEventListener('input',function(){{var v=this.value.replace(/\\D/g,'').slice(0,19);this.value=v.replace(/(.{{4}})/g,'$1 ').trim()}});
|
||
</script>
|
||
{result}"""
|
||
return page("card", body)
|
||
|
||
@app.route("/api/card", methods=["POST"])
|
||
def api_card():
|
||
num = re.sub(r"\D", "", param("num") or "")[:19]
|
||
if not num: return jsonify({"ok": False, "error": "num required"})
|
||
ok = luhn_ok(num)
|
||
bl = bin_lookup(num[:8])
|
||
return jsonify({"ok": True, "luhn": ok, "brand": brand_of(num), "length_ok": len(num) in
|
||
{"Visa":(13,16,19),"Mastercard":(16,),"Amex":(15,)}.get(brand_of(num),(13,15,16,19)),
|
||
"bin": {"issuer": (bl.get("bank") or {}).get("name"), "country": (bl.get("country") or {}).get("name"),
|
||
"type": bl.get("type"), "prepaid": bl.get("prepaid")},
|
||
"flags": (["prepaid-risk"] if (bl.get("type")=="prepaid" or bl.get("prepaid") is True) else []) + (["luhn-invalid"] if not ok else [])})
|
||
|
||
# ---------- 3. SMS RENTALS ----------
|
||
SMSP = "https://api.smspool.net"
|
||
SERVICES = [("google","Google"),("discord","Discord"),("telegram","Telegram"),("whatsapp","WhatsApp"),("other","Other/Any")]
|
||
COUNTRIES = [("1","United States"),("2","United Kingdom"),("4","Netherlands"),("22","Russia"),("150","Germany")]
|
||
|
||
def sms_api(path, **kw):
|
||
if kw:
|
||
kw["key"] = SMSP_KEY
|
||
return http(f"{SMSP}/{path}", data=urllib.parse.urlencode(kw).encode(), method="POST")
|
||
return http(f"{SMSP}/{path}?key={SMSP_KEY}")
|
||
|
||
def sms_guard():
|
||
con = db(); now = int(time.time())
|
||
uid = current_user_id()
|
||
st, b = sms_api("request/balance")
|
||
bal = jf(b) or {}
|
||
try: bal = float(bal.get("balance", 0))
|
||
except Exception: bal = 0
|
||
if bal < 5: return f"house balance too low (${bal:.2f}) — rentals paused"
|
||
act = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE status='active' AND expires > ?", (now,)).fetchone()["c"]
|
||
if act >= (5 if has_pass(uid) else 3): return "too many active rentals right now — try again later"
|
||
h = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-3600,)).fetchone()["c"]
|
||
if h >= (20 if has_pass(uid) else 6): return "hourly rental cap reached"
|
||
d = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > ?", (now-86400,)).fetchone()["c"]
|
||
if d >= (50 if has_pass(uid) else 15): return "daily rental cap reached"
|
||
return None
|
||
|
||
@app.route("/sms", methods=["GET", "POST"])
|
||
def sms():
|
||
msg = ""
|
||
if request.method == "POST":
|
||
act = request.form.get("act")
|
||
if act == "rent":
|
||
guard = sms_guard()
|
||
if guard:
|
||
msg = f'<div class="card"><span class="tag warn">PAUSED</span> {guard}</div>'
|
||
else:
|
||
st, b = sms_api("purchase/sms", service=request.form["service"], country=request.form["country"])
|
||
d = jf(b) or {}
|
||
if d.get("success") == 1:
|
||
con = db(); now = int(time.time())
|
||
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
|
||
(d.get("number"), request.form["service"], request.form["country"], str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
|
||
con.commit()
|
||
msg = f'<div class="card"><span class="tag ok">RENTED</span> Your number: <b style="font-size:1.2rem;color:var(--acc)">+{d.get("number")}</b> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(\'+{d.get("number")}\')">copy</button> · 30 min · order #{d.get("purchase_id")}</div>'
|
||
else:
|
||
msg = f'<div class="card"><span class="tag bad">RENT FAILED</span><br><pre>{esc(b[:400])}</pre></div>'
|
||
elif act == "check":
|
||
st, b = sms_api("sms/check", orderid=request.form["pid"])
|
||
d = jf(b) or {}
|
||
sms_txt = d.get("sms") or d.get("code") or ""
|
||
status = d.get("status", "?")
|
||
msg = f'<div class="card"><span class="tag {"ok" if sms_txt else "warn"}">STATUS: {status}</span> {"<b style=color:var(--ok)>" + esc(sms_txt) + "</b>" if sms_txt else "no code yet — poll again in 10s"}</div>'
|
||
elif act == "cancel":
|
||
st, b = sms_api("sms/cancel", orderid=request.form["pid"])
|
||
d = jf(b) or {}
|
||
ok = d.get("success") == 1
|
||
con = db(); con.execute("UPDATE sms_rentals SET status=? WHERE purchase_id=?", ("refunded" if ok else "cancel-failed", request.form["pid"])); con.commit()
|
||
msg = f'<div class="card"><span class="tag {"ok" if ok else "bad"}">{"CANCELLED + REFUNDED" if ok else "CANCEL FAILED"}</span></div>'
|
||
con = db()
|
||
hist = con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 8").fetchall()
|
||
hist_rows = "".join(f"<tr><td>+{h['phone']} <a href=# onclick=\"cp('+{h['phone']});return false\" style=color:var(--acc)>copy</a></td><td>{h['service']}</td><td>{h['status']}</td><td>#{h['purchase_id']}</td><td class=cdown data-exp={h['expires']}>…</td></tr>" for h in hist)
|
||
body = f"""
|
||
<h1>SMS <span>RENTAL</span></h1><p class=sub>Disposable numbers, 30-minute windows. Cancel before a code = full refund.</p>
|
||
<div class="grid2">
|
||
<div class=card><b>Rent a number</b>
|
||
<form method=post><input type=hidden name=act value=rent>
|
||
<select name=service style="width:100%">{''.join(f'<option value={v}>{n}</option>' for v,n in SERVICES)}</select>
|
||
<select name=country style="width:100%;margin:.5rem 0">{''.join(f'<option value={v}>{n}</option>' for v,n in COUNTRIES)}</select>
|
||
<button>Rent — 30 min</button></form></div>
|
||
<div class=card><b>Check / manage</b>
|
||
<form method=post><input type=hidden name=act value=check><input name=pid placeholder="order #" style="width:100%"><button style="margin:.5rem 0">Poll for code</button></form>
|
||
<form method=post><input type=hidden name=act value=cancel><input name=pid placeholder="order #" style="width:100%"><button style="background:var(--bad);color:#fff">Cancel & refund</button></form></div>
|
||
</div>{msg}
|
||
<div class=card><b>Recent rentals</b><table><tr><th>Number</th><th>Service</th><th>Status</th><th>Order</th><th>Window</th></tr>{hist_rows or '<tr><td colspan=5 style=color:var(--dim)>none yet</td></tr>'}</table></div>
|
||
<script>
|
||
setInterval(function(){{var els=document.querySelectorAll('.cdown');var now=Math.floor(Date.now()/1000);
|
||
els.forEach(function(e){{var s=e.dataset.exp-now;if(s>0)e.textContent=Math.floor(s/60)+'m '+(s%60)+'s left';else e.textContent='expired'}});}},1000);
|
||
</script>
|
||
<div class=card style=color:var(--dim)>API: POST /api/sms/rent (service,country) · GET /api/sms/check?pid= · GET /api/sms/cancel?pid= · GET /api/sms/history</div>""" + how(["Pick a service and country, rent — the number is live for 30 minutes exactly.","Use it for any signup/verification. The code arrives as a text.","Poll the order (auto or manual) until the code shows.","Cancel before a code arrives and you get every satoshi back.","Each rental is logged in the recent-rentals table with a live countdown."])
|
||
return page("sms", body)
|
||
|
||
@app.route("/api/sms/rent", methods=["POST"])
|
||
def api_sms_rent():
|
||
guard = sms_guard()
|
||
if guard: return jsonify({"success": 0, "message": guard, "paused": True})
|
||
uid = key_user() or current_user_id()
|
||
if uid and not has_pass(uid) and get_balance(uid) < 50:
|
||
return jsonify({"ok": False, "error": "insufficient balance", "topup": SITE + "/keys"}), 402
|
||
st, b = sms_api("purchase/sms", service=param("service"), country=param("country"))
|
||
d = jf(b) or {}
|
||
if d.get("success") == 1:
|
||
con = db(); now = int(time.time())
|
||
con.execute("INSERT INTO sms_rentals(phone,service,country,purchase_id,cost,status,created,expires) VALUES(?,?,?,?,?,?,?,?)",
|
||
(d.get("number"), param("service"), param("country"), str(d.get("purchase_id")), d.get("cost",0), "active", now, now+1800))
|
||
con.commit()
|
||
cost = int(d.get("cost_in_cents") or 5)
|
||
if uid and not has_pass(uid):
|
||
charge(uid, cost, f"sms rental +{d.get('number')}")
|
||
return jsonify(d)
|
||
|
||
@app.route("/api/sms/check", methods=["GET","POST"])
|
||
def api_sms_check():
|
||
st, b = sms_api("sms/check", orderid=param("pid"))
|
||
return jf(b) or jsonify({"error": b[:200]})
|
||
|
||
@app.route("/api/sms/cancel", methods=["GET","POST"])
|
||
def api_sms_cancel():
|
||
st, b = sms_api("sms/cancel", orderid=param("pid"))
|
||
d = jf(b) or {}
|
||
if d.get("success") == 1:
|
||
con = db(); con.execute("UPDATE sms_rentals SET status='refunded' WHERE purchase_id=?", (param("pid"),)); con.commit()
|
||
return d
|
||
|
||
@app.route("/api/sms/history")
|
||
def api_sms_history():
|
||
con = db(); now = int(time.time())
|
||
con.execute("UPDATE sms_rentals SET status='expired' WHERE status='active' AND expires < ?", (now,))
|
||
con.commit()
|
||
return jsonify([dict(r) for r in con.execute("SELECT * FROM sms_rentals ORDER BY id DESC LIMIT 50")])
|
||
|
||
# ---------- 4. PROXY LAB ----------
|
||
@app.route("/proxy", methods=["GET", "POST"])
|
||
def proxy():
|
||
result = ""
|
||
if request.method == "POST" and request.form.get("act") == "test":
|
||
user, pw = request.form.get("user",""), request.form.get("pass","")
|
||
pauth = base64.b64encode(f"{user}:{pw}".encode()).decode()
|
||
try:
|
||
s = socket.create_connection((PLEIADES_GW.split(":")[0], int(PLEIADES_GW.split(":")[1])), timeout=15)
|
||
s.sendall(f"CONNECT ip-api.com:80 HTTP/1.1\r\nHost: ip-api.com:80\r\nProxy-Authorization: Basic {pauth}\r\n\r\n".encode())
|
||
resp = s.recv(4096)
|
||
if b"200" in resp.split(b"\r\n")[0]:
|
||
s.sendall(b"GET /json/?fields=66846719 HTTP/1.1\r\nHost: ip-api.com\r\nConnection: close\r\n\r\n")
|
||
data = b""
|
||
while True:
|
||
c = s.recv(8192)
|
||
if not c: break
|
||
data += c
|
||
s.close()
|
||
j = jf(data.split(b"\r\n\r\n",1)[-1].decode("utf-8","replace")) or {}
|
||
con = db()
|
||
con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], j.get("query","?"), f"{j.get('country')}/{j.get('city')}", 1, int(time.time())))
|
||
con.commit()
|
||
result = f'<div class="card"><span class="tag ok">PROXY LIVE</span> Egress: <b style=color:var(--acc)>{esc(j.get("query"))}</b> — {esc(j.get("country"))} / {esc(j.get("city"))} · ISP {esc(j.get("isp"))} · tz {esc(j.get("timezone"))} <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(\'{esc(j.get("query"))}\')">copy</button></div>'
|
||
else:
|
||
con = db()
|
||
con.execute("INSERT INTO proxy_checks(user_key,egress_ip,geo,ok,ts) VALUES(?,?,?,?,?)", (user[:12], "", "", 0, int(time.time())))
|
||
con.commit()
|
||
result = f'<div class="card"><span class="tag bad">AUTH/TUNNEL FAILED</span><pre>{esc(resp[:200])}</pre></div>'
|
||
except Exception as e:
|
||
result = f'<div class="card"><span class="tag bad">ERROR</span> {esc(e)}</div>'
|
||
body = f"""
|
||
<h1>PROXY <span>LAB</span></h1><p class=sub>Test + rent residential proxies on the Pleiades rail — same gateway keys as everywhere.</p>
|
||
<div class=card><form method=post><input type=hidden name=act value=test>
|
||
<label>Gateway user</label><br><input name=user style="width:100%" placeholder="your Pleiades username"><br>
|
||
<label style=color:var(--dim)>Password</label><br><input name=pass type=password style="width:100%"><br>
|
||
<button style=margin-top:.6rem>Test egress now</button></form></div>
|
||
{result}
|
||
<div class=card><b>Geo session builder</b>:
|
||
<select id=geoK onchange="gb()"><option value="">none</option><option value="_region-us">region US</option><option value="_region-eu">region EU</option><option value="_country-gb">country GB</option><option value="_country-de">country DE</option><option value="_city-london">city London</option></select>
|
||
<select id=geoS onchange="gb()"><option value="">rotating</option><option value="_session-a7x9_lifetime-30m">sticky 30-min</option></select>
|
||
<div style=margin-top:.5rem><code id=geoOut style=color:var(--acc)>yourpassword</code> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(document.getElementById('geoOut').textContent)">copy</button></div>
|
||
<script>function gb(){{document.getElementById('geoOut').textContent='yourpassword'+document.getElementById('geoK').value+document.getElementById('geoS').value}}</script></div>
|
||
<div class=card><b>Rent more</b> — storefront: <a href="{PLEIADES_APP}">{PLEIADES_APP}</a></div>
|
||
<div class=card style=color:var(--dim)>API: POST /api/proxy/test (user, pass) → egress IP + geo JSON.</div>""" + how(["Enter your Pleiades gateway user:pass — the same credentials work across the fleet.","The lab tunnels a CONNECT request through the gateway and reports the true egress IP, geo and ISP.","Use the geo builder to steer the exit: region, country, city, sticky 30-min sessions.","Need bandwidth? Buy GB plans at the Pleiades storefront."])
|
||
return page("proxy", body)
|
||
|
||
@app.route("/api/proxy/test", methods=["POST"])
|
||
def api_proxy_test():
|
||
user, pw = param("user") or "", param("pass") or ""
|
||
pauth = base64.b64encode(f"{user}:{pw}".encode()).decode()
|
||
try:
|
||
s = socket.create_connection((PLEIADES_GW.split(":")[0], int(PLEIADES_GW.split(":")[1])), timeout=15)
|
||
s.sendall(f"CONNECT ip-api.com:80 HTTP/1.1\r\nHost: ip-api.com:80\r\nProxy-Authorization: Basic {pauth}\r\n\r\n".encode())
|
||
resp = s.recv(4096)
|
||
if b"200" not in resp.split(b"\r\n")[0]: return jsonify({"ok": False, "raw": resp[:120].decode("utf-8","replace")})
|
||
s.sendall(b"GET /json/?fields=66846719 HTTP/1.1\r\nHost: ip-api.com\r\nConnection: close\r\n\r\n")
|
||
data = b""
|
||
while True:
|
||
c = s.recv(8192)
|
||
if not c: break
|
||
data += c
|
||
s.close()
|
||
j = jf(data.split(b"\r\n\r\n",1)[-1].decode("utf-8","replace")) or {}
|
||
return jsonify({"ok": True, "egress": j})
|
||
except Exception as e:
|
||
return jsonify({"ok": False, "error": str(e)})
|
||
|
||
# ---------- 5. STEGO LAB ----------
|
||
def _keystream(password, n):
|
||
ks = b""; seed = password.encode()
|
||
while len(ks) < n:
|
||
seed = hashlib.sha256(seed).digest()
|
||
ks += seed
|
||
return ks[:n]
|
||
|
||
def steg_hide(img_bytes, text, password="", bits=1, spread="sequential"):
|
||
from PIL import Image
|
||
im = Image.open(io.BytesIO(img_bytes)).convert("RGBA")
|
||
px = im.load()
|
||
w, h = im.size
|
||
capacity = w * h * 3 * bits
|
||
payload = text.encode("utf-8")
|
||
phash = hashlib.sha256(password.encode()).digest()[:4] if password else b"\x00\x00\x00\x00"
|
||
header = b"AUR1" + struct.pack(">I", len(payload)) + phash
|
||
body = payload
|
||
if password:
|
||
body = bytes(a ^ b for a, b in zip(body, _keystream(password, len(body))))
|
||
data = header + body
|
||
if len(data) * 8 > capacity:
|
||
return None, f"too big: need {len(data)*8} bits, image holds {capacity}"
|
||
if spread == "random":
|
||
import random as _r
|
||
_r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big"))
|
||
order = list(range(w*h)); _r.shuffle(order)
|
||
else:
|
||
order = list(range(w*h))
|
||
bits_needed = len(data) * 8
|
||
idx = 0
|
||
mask = (1 << bits) - 1
|
||
for pos in order:
|
||
if idx >= bits_needed: break
|
||
x, y = pos % w, pos // w
|
||
r, g, b, a = px[x, y]
|
||
chs = [r, g, b]
|
||
for ch_i in range(3):
|
||
if idx >= bits_needed: break
|
||
chunk = 0
|
||
taken = 0
|
||
for k in range(bits):
|
||
if idx >= bits_needed: break
|
||
chunk = (chunk << 1) | ((data[idx >> 3] >> (7 - (idx & 7))) & 1)
|
||
idx += 1; taken += 1
|
||
if taken < bits: chunk <<= (bits - taken)
|
||
chs[ch_i] = (chs[ch_i] & ~mask) | chunk
|
||
px[x, y] = tuple(chs) + (a,)
|
||
# also stash settings in a tEXt chunk for reliable extraction hints
|
||
out = io.BytesIO()
|
||
im.save(out, "PNG", pnginfo=_pnginfo(bits, spread))
|
||
return out.getvalue(), {"bits": bits, "spread": spread}
|
||
|
||
def _pnginfo(bits, spread):
|
||
try:
|
||
from PIL.PngImagePlugin import PngInfo
|
||
info = PngInfo()
|
||
info.add_text("dark0rbits_meta", json.dumps({"bits": bits, "spread": spread, "v": 2}))
|
||
return info
|
||
except Exception:
|
||
return None
|
||
|
||
def steg_extract(img_bytes, password="", bits=None, spread=None):
|
||
from PIL import Image
|
||
im = Image.open(io.BytesIO(img_bytes))
|
||
meta = im.info.get("dark0rbits_meta") or im.info.get("auriga_meta")
|
||
if meta:
|
||
try:
|
||
m = json.loads(meta)
|
||
bits = int(m.get("bits", bits or 1)); spread = m.get("spread", spread or "sequential")
|
||
except Exception: pass
|
||
bits = bits or 1
|
||
im = im.convert("RGBA")
|
||
px = im.load()
|
||
w, h = im.size
|
||
mask = (1 << bits) - 1
|
||
# replicate the shuffle used at hide time
|
||
if spread == "random":
|
||
import random as _r
|
||
_r.seed(int.from_bytes(hashlib.sha256((password + "dark0rbits").encode()).digest()[:4], "big") if password else int.from_bytes(hashlib.sha256(b"dark0rbits-random-no-pass").digest()[:4], "big"))
|
||
order = list(range(w*h)); _r.shuffle(order)
|
||
else:
|
||
order = list(range(w*h))
|
||
raw = bytearray()
|
||
need = None
|
||
idx = 0
|
||
for pos in order:
|
||
if need is not None and idx >= need: break
|
||
x, y = pos % w, pos // w
|
||
r, g, b, a = px[x, y]
|
||
for ch in (r, g, b):
|
||
chunk = ch & mask
|
||
for k in range(bits-1, -1, -1):
|
||
if need is not None and idx >= need: break
|
||
bit = (chunk >> k) & 1
|
||
while len(raw) < (idx >> 3) + 1: raw.append(0)
|
||
if bit: raw[idx >> 3] |= (0x80 >> (idx & 7))
|
||
idx += 1
|
||
if need is not None and idx >= need: break
|
||
if need is None and idx >= 64:
|
||
if bytes(raw[:4]) != b"AUR1":
|
||
return None, f"no DARK0RBITS payload found with LSB depth {bits} (try other depth / randomized)"
|
||
ln = struct.unpack(">I", bytes(raw[4:8]))[0]
|
||
need = 64 + ln * 8
|
||
data = bytes(raw)
|
||
if len(data) < 12: return None, "payload too small"
|
||
if bytes(data[:4]) != b"AUR1":
|
||
return None, "no DARK0RBITS payload found (wrong password or settings?)"
|
||
if password and hashlib.sha256(password.encode()).digest()[:4] != data[8:12]:
|
||
return None, "wrong password"
|
||
ln = struct.unpack(">I", data[4:8])[0]
|
||
body = data[12:12+ln]
|
||
if password:
|
||
body = bytes(a ^ b for a, b in zip(body, _keystream(password, len(body))))
|
||
text = body.decode("utf-8", "replace")
|
||
return text, None
|
||
|
||
@app.route("/steg", methods=["GET"])
|
||
def steg():
|
||
body = f"""
|
||
<h1>STEGO <span>LAB</span></h1><p class=sub>Hide words inside pictures — LSB steganography with real settings. PNG in, PNG out, looks untouched.</p>
|
||
<div class="grid2">
|
||
<div class=card><b>Hide text</b>
|
||
<form action=/api/steg/hide method=post enctype=multipart/form-data target=stegout>
|
||
<div class=drop onclick="document.getElementById('ih').click()">📤 drop a PNG here or click<input id=ih type=file name=image accept="image/png" style=display:none required></div>
|
||
<div class=fnh style=color:var(--dim);font-size:.85rem></div>
|
||
<textarea name=text rows=3 style="width:100%;margin:.6rem 0" placeholder="the words to hide"></textarea>
|
||
<input name=password placeholder="password (optional)" style="width:100%">
|
||
<div style=margin:.6rem 0>
|
||
<label>LSB depth</label> <select name=bits><option>1</option><option>2</option><option>3</option></select>
|
||
<label style=margin-left:.8rem>Spread</label> <select name=spread><option value=sequential>sequential</option><option value=random>randomized</option></select>
|
||
</div>
|
||
<button>Hide & download</button></form></div>
|
||
<div class=card><b>Extract text</b>
|
||
<form action=/api/steg/extract method=post enctype=multipart/form-data target=stegout>
|
||
<div class=drop onclick="document.getElementById('ie').click()">📥 drop the carrier PNG<input id=ie type=file name=image accept="image/png" style=display:none required></div>
|
||
<div class=fne style=color:var(--dim);font-size:.85rem></div>
|
||
<input name=password placeholder="password if used" style="width:100%;margin:.6rem 0">
|
||
<div style=margin:.6rem 0><label>LSB depth</label> <select name=bits><option value="">auto (reads metadata)</option><option>1</option><option>2</option><option>3</option></select>
|
||
<label style=margin-left:.8rem>Spread</label> <select name=spread><option value="">auto</option><option value=sequential>sequential</option><option value=random>randomized</option></select></div>
|
||
<button>Extract</button></form></div>
|
||
</div>
|
||
<script>
|
||
document.querySelectorAll('.drop').forEach(function(d){{
|
||
d.addEventListener('dragover',function(e){{e.preventDefault();d.classList.add('over')}});
|
||
d.addEventListener('dragleave',function(){{d.classList.remove('over')}});
|
||
d.addEventListener('drop',function(e){{e.preventDefault();d.classList.remove('over');
|
||
var inp=d.querySelector('input[type=file]');if(e.dataTransfer.files.length){{inp.files=e.dataTransfer.files;
|
||
var fn=d.parentElement.querySelector('.fnh, .fne');if(fn)fn.textContent=e.dataTransfer.files[0].name}}}});
|
||
d.addEventListener('change',function(){{}});
|
||
}});
|
||
document.getElementById('ih').addEventListener('change',function(){{document.querySelector('.fnh').textContent=this.files[0].name}});
|
||
document.getElementById('ie').addEventListener('change',function(){{document.querySelector('.fne').textContent=this.files[0].name}});
|
||
</script>
|
||
<div class=card style=color:var(--dim)>API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON</div>""" + how(["Drop a PNG — your words are written into the least-significant bits of its pixels.","Depth 1 = invisible and robust; depth 2-3 fits more text but is easier to detect.","Spread=randomized scatters bits across the image instead of top-down.","A password encrypts the payload AND derives the scatter pattern — wrong password = noise.","Extract reads the embedded metadata automatically — just drop the file and the words come back."])
|
||
return page("steg", body)
|
||
|
||
@app.route("/api/steg/hide", methods=["POST"])
|
||
def api_steg_hide():
|
||
f = request.files.get("image")
|
||
text = param("text") or ""
|
||
if not f or not text: return jsonify({"ok": False, "error": "image + text required"}), 400
|
||
bits = min(3, max(1, int(param("bits") or 1)))
|
||
spread = param("spread") or "sequential"
|
||
try:
|
||
out, meta = steg_hide(f.read(), text, param("password") or "", bits, spread)
|
||
except Exception as e:
|
||
return jsonify({"ok": False, "error": str(e)}), 400
|
||
if out is None: return jsonify({"ok": False, "error": meta}), 400
|
||
return send_file(io.BytesIO(out), mimetype="image/png", as_attachment=True, download_name="dark0rbits-hidden.png")
|
||
|
||
@app.route("/api/steg/extract", methods=["POST"])
|
||
def api_steg_extract():
|
||
f = request.files.get("image")
|
||
if not f: return jsonify({"ok": False, "error": "image required"}), 400
|
||
bits = param("bits")
|
||
bits = min(3, max(1, int(bits))) if bits else None
|
||
try:
|
||
text, err = steg_extract(f.read(), param("password") or "", bits, param("spread") or None)
|
||
except Exception as e:
|
||
return jsonify({"ok": False, "error": str(e)}), 400
|
||
if err: return jsonify({"ok": False, "error": err}), 200
|
||
return jsonify({"ok": True, "text": text})
|
||
|
||
# ---------- 6. TRACKABLE FILES ----------
|
||
@app.route("/track", methods=["GET"])
|
||
def track():
|
||
uid = current_user_id()
|
||
mine = ""
|
||
if uid:
|
||
con = db()
|
||
rows = con.execute("SELECT * FROM trackables WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall()
|
||
if rows:
|
||
trs = "".join(f"<tr><td>{esc(t['filename'])}</td><td>{'<a href=/api/track/events?token='+t['token']+'>events</a>' if t['paid'] else '—'}</td><td>{'paid ✓' if t['paid'] else 'unpaid'}</td></tr>" for t in rows)
|
||
mine = f'<div class=card><b>Your trackables</b><table><tr><th>File</th><th>Events</th><th>Status</th></tr>{trs}</table></div>'
|
||
body = f"""
|
||
<h1>TRACK <span>FILE</span></h1><p class=sub>Pay $1 BTC → upload a file or picture → get a tracked link + an email-ready version. Every open pings back into your INBOX.</p>
|
||
<div class=card>
|
||
<b>1 · Pay $1</b><form action=/api/track/create method=post>
|
||
<input name=filename placeholder="file name e.g. flyer.jpg" style="width:70%" required> <button>Create invoice</button></form>
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.4rem>BTCPay BTC only. After payment the upload opens automatically.</div></div>
|
||
{mine}
|
||
<div class=card style=color:var(--dim)>How it works: your file gets a secret link — every open is logged (time, IP, device) and lands in your inbox. You also get an HTML copy with an embedded tracking pixel: email THAT and every view fires too. <a href=/inbox>Login (no KYC)</a> to see events.</div>
|
||
<div class=card style=color:var(--dim)>API: POST /api/track/create (filename) → invoice · POST /api/track/upload?token= (file) → link · GET /api/track/events?token=</div>""" + how(["Pay $1 in BTC — the invoice settles and unlocks the upload instantly.","Upload your file or picture: you get a secret tracked link plus an email-ready HTML copy.","Email the HTML copy or share the link — every open fires back.","Each open reports: exact time, real IP, city/country, ISP, timezone, VPN flag, device, language, referrer.","Alerts land in your INBOX the second it happens."])
|
||
return page("track", body)
|
||
|
||
def btc_invoice(amount="1.00"):
|
||
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
|
||
headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
|
||
data=json.dumps({"amount": amount, "currency": "USD", "metadata": {"orderId": "dark0rbits-track"}}).encode(), method="POST")
|
||
return jf(b) or {}
|
||
|
||
@app.route("/api/track/create", methods=["POST"])
|
||
def api_track_create():
|
||
fn = param("filename") or "file"
|
||
uid = key_user() or current_user_id()
|
||
token = secrets.token_urlsafe(16)
|
||
con = db()
|
||
if has_pass(uid):
|
||
con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)",
|
||
(uid or 0, token, esc(fn[:100]), "file", "PASS", int(time.time())))
|
||
con.commit()
|
||
return jsonify({"ok": True, "free": True, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"})
|
||
if uid and charge(uid, 100, f"trackable file ({fn[:40]})"):
|
||
con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,1,?)",
|
||
(uid or 0, token, esc(fn[:100]), "file", "BALANCE", int(time.time())))
|
||
con.commit()
|
||
return jsonify({"ok": True, "balance_charged": 1.00, "token": token, "upload_url": f"{SITE}/track/pay?token={token}"})
|
||
inv = btc_invoice()
|
||
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
|
||
con.execute("INSERT INTO trackables(user_id,token,filename,kind,invoice_id,paid,created) VALUES(?,?,?,?,?,0,?)",
|
||
(uid or 0, token, esc(fn[:100]), "file", inv["id"], int(time.time())))
|
||
con.commit()
|
||
return jsonify({"ok": True, "invoice_id": inv["id"], "checkoutLink": inv.get("checkoutLink"), "token": token,
|
||
"after_payment_upload_url": f"{SITE}/track/pay?token={token}"})
|
||
|
||
@app.route("/track/pay", methods=["GET"])
|
||
def track_pay():
|
||
token = param("token") or ""
|
||
con = db()
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if not t: return page("track", "<h1>TRACK <span>FILE</span></h1><div class=card><span class=tag bad>unknown token</span></div>")
|
||
return page("track", f"""
|
||
<h1>TRACK <span>FILE</span></h1><p class=sub>Upload your file — then it's trackable.</p>
|
||
<div class=card><form action=/api/track/upload?token={esc(token)} method=post enctype=multipart/form-data>
|
||
<div class=drop onclick="document.getElementById('tf').click()">📤 drop file / picture here<input id=tf type=file name=file style=display:none required></div>
|
||
<div id=tfname style=color:var(--dim);font-size:.85rem;margin:.4rem 0></div>
|
||
<button>Upload & make trackable</button></form></div>
|
||
<script>document.getElementById('tf').addEventListener('change',function(){{document.getElementById('tfname').textContent=this.files[0].name}})</script>""")
|
||
|
||
@app.route("/api/track/upload", methods=["POST"])
|
||
def api_track_upload():
|
||
token = param("token")
|
||
f = request.files.get("file")
|
||
if not f: return jsonify({"ok": False, "error": "file required"}), 400
|
||
con = db()
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if not t: return jsonify({"ok": False, "error": "unknown token"}), 400
|
||
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{t['invoice_id']}", headers={"Authorization": "token " + BTCPAY_KEY}) if t["invoice_id"] not in ("PASS", "BALANCE") else (200, '{"status":"settled"}')
|
||
inv = jf(b) or {}
|
||
paid = inv.get("status") in ("settled", "processing", "paid")
|
||
if not paid: return jsonify({"ok": False, "error": f"invoice not paid yet ({inv.get('status')})"}), 402
|
||
data = f.read()
|
||
open(os.path.join(UPLOAD_DIR, token + ".bin"), "wb").write(data)
|
||
kind = "image" if (f.content_type or "").startswith("image") else "file"
|
||
fn = (f.filename or t["filename"])[:100]
|
||
con.execute("UPDATE trackables SET paid=1, kind=?, filename=? WHERE token=?", (kind, fn, token))
|
||
con.commit()
|
||
b64 = base64.b64encode(data).decode()
|
||
pixel = f"{SITE}/t/{token}.png"
|
||
if kind == "image":
|
||
viewer = f'<!doctype html><meta charset=utf-8><body style="margin:0;background:#111;text-align:center"><img src="data:image;base64,{b64}" style="max-width:100%"><img src="{pixel}" width=1 height=1></body>'
|
||
else:
|
||
viewer = f'<!doctype html><meta charset=utf-8><body style="background:#111;color:#eee;font-family:monospace;padding:2rem"><p>📎 {esc(fn)} ({len(data)} bytes)</p><p><a href="{SITE}/t/{token}" style="color:#f0b429">Open / download the file</a></p><img src="{pixel}" width=1 height=1></body>'
|
||
open(os.path.join(UPLOAD_DIR, token + ".html"), "w").write(viewer)
|
||
con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)", (t["id"], int(time.time()), "created", "upload"))
|
||
con.commit()
|
||
return jsonify({"ok": True, "tracked_link": f"{SITE}/t/{token}", "pixel": pixel,
|
||
"email_html": f"{SITE}/t/{token}/html",
|
||
"note": "attach/email the HTML version — every view fires the pixel and lands in the inbox"})
|
||
|
||
def _geo_cache():
|
||
con = db()
|
||
con.execute("CREATE TABLE IF NOT EXISTS geo_cache(ip TEXT PRIMARY KEY, geo TEXT, ts INTEGER)")
|
||
return con
|
||
|
||
def enrich_ip(ip):
|
||
"""geo/ISP/ASN for an IP, cached 24h."""
|
||
if not ip or ip == "created" or ip.startswith(("10.30.20.", "127.", "172.17.")): return {}
|
||
con = _geo_cache()
|
||
r = con.execute("SELECT geo FROM geo_cache WHERE ip=? AND ts > ?", (ip, int(time.time())-86400)).fetchone()
|
||
if r: return json.loads(r["geo"])
|
||
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
|
||
d = jf(b) or {}
|
||
geo = {k: d.get(k) for k in ("country","countryCode","regionName","city","zip","lat","lon","timezone","isp","org","as","asname","mobile","proxy","hosting","reverse","query") if d.get(k) is not None}
|
||
con.execute("INSERT OR REPLACE INTO geo_cache(ip,geo,ts) VALUES(?,?,?)", (ip, json.dumps(geo), int(time.time())))
|
||
con.commit()
|
||
return geo
|
||
|
||
def _log_open(t, extra=""):
|
||
con = db()
|
||
ip = request.headers.get("X-Real-IP") or request.remote_addr or "?"
|
||
ua = request.headers.get("User-Agent","")
|
||
lang = request.headers.get("Accept-Language","")
|
||
ref = request.headers.get("Referer","")
|
||
geo = enrich_ip(ip)
|
||
where = ""
|
||
if geo: where = f" — {geo.get('city','')}, {geo.get('regionName','')} {geo.get('countryCode','')} · {geo.get('isp','')} · tz {geo.get('timezone','')}"
|
||
if geo.get("proxy"): where += " · VPN/proxy ⚠"
|
||
con.execute("INSERT INTO track_events(trackable_id,ts,ip,ua) VALUES(?,?,?,?)",
|
||
(t["id"], int(time.time()), ip + (" " + json.dumps(geo) if geo else ""), ua[:200] + (f" | lang={lang}" if lang else "") + (f" | ref={ref[:100]}" if ref else "")))
|
||
uid = t["user_id"]
|
||
if uid:
|
||
con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)",
|
||
(uid, "operator-bot", f"👁 '{esc(t['filename'])}' just opened{extra} — IP <b>{esc(ip)}</b>{esc(where)}<br>device: {esc(ua[:100])}{'<br>lang: ' + esc(lang) if lang else ''}{'<br>from: ' + esc(ref[:120]) if ref else ''}", int(time.time())))
|
||
con.commit()
|
||
|
||
@app.route("/t/<token>")
|
||
def tracked_download(token):
|
||
con = db()
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if not t or not t["paid"]: return "not found", 404
|
||
_log_open(t, " (link)")
|
||
path = os.path.join(UPLOAD_DIR, token + ".bin")
|
||
if not os.path.exists(path): return "file gone", 404
|
||
return send_file(path, as_attachment=True, download_name=t["filename"])
|
||
|
||
@app.route("/t/<token>.png")
|
||
def tracked_pixel(token):
|
||
con = db()
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if t and t["paid"]:
|
||
_log_open(t, " (email/pixel)")
|
||
px = base64.b64decode("R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7")
|
||
return Response(px, mimetype="image/gif", headers={"Cache-Control": "no-store"})
|
||
|
||
@app.route("/t/<token>/html")
|
||
def tracked_html(token):
|
||
con = db()
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if not t or not t["paid"]: return "not found", 404
|
||
p = os.path.join(UPLOAD_DIR, token + ".html")
|
||
return send_file(p, mimetype="text/html") if os.path.exists(p) else ("no html wrapper", 404)
|
||
|
||
@app.route("/api/track/events", methods=["GET"])
|
||
def api_track_events():
|
||
con = db(); token = param("token")
|
||
t = con.execute("SELECT * FROM trackables WHERE token=?", (token,)).fetchone()
|
||
if not t: return jsonify({"ok": False, "error": "unknown token"})
|
||
uid = current_user_id()
|
||
if not uid or uid != t["user_id"]: return jsonify({"ok": False, "error": "auth required (login on /inbox)"})
|
||
return jsonify([dict(r) for r in con.execute("SELECT * FROM track_events WHERE trackable_id=? ORDER BY id DESC LIMIT 100", (t["id"],))])
|
||
|
||
# ---------- 6b. BURNER MAIL (receive-only, BTC packages) ----------
|
||
MAIL_PACKS = [("7","7 days — $3",3,7),("30","30 days — $8",8,30),("90","90 days — $20",20,90)]
|
||
MAIL_DOMAIN = "thetempleofdoom.com"
|
||
MAIL_RESERVED = {"indianaholmes","admin","operator","drjones","root","noreply","support","pass","mail"}
|
||
MAIL_SECRET = "dark0rbits-mail-relay-2026"
|
||
|
||
@app.route("/mail", methods=["GET"])
|
||
def mail():
|
||
uid = current_user_id()
|
||
mine = ""
|
||
if uid:
|
||
con = db(); now = int(time.time())
|
||
con.execute("UPDATE mailboxes SET paid=2 WHERE paid=1 AND expires < ?", (now,)) # expired
|
||
rows = con.execute("SELECT * FROM mailboxes WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall()
|
||
if rows:
|
||
trs = "".join(f"<tr><td>{esc(m['address'])} <a href=# onclick=\"cp('{esc(m['address'])}');return false\" style=color:var(--acc)>copy</a></td><td><a href=/mail/view?addr={esc(m['address'])}>view mail</a></td><td class=mcd data-exp={m['expires']}>…</td><td>{'live' if m['paid']==1 else 'expired'}</td><td>{m['cnt']}</td></tr>" for m in rows)
|
||
mine = f'<div class=card><b>Your mailboxes</b><table><tr><th>Address</th><th></th><th>Expires</th><th>Status</th><th>Mail</th></tr>{trs}</table></div>'
|
||
body = f"""
|
||
<h1>BURNER <span>MAIL</span></h1><p class=sub>Receive-only disposable mailboxes @thetempleofdoom.com. Counting down in real time. Anything you sign up for — codes, confirmations, one-off handouts — lands right here, no other identity attached.</p>
|
||
<div class=card>
|
||
<b>Pick a package (BTC)</b>
|
||
{''.join(f'<form action=/api/mail/create method=post style=display:inline;margin:0 0.5rem><input type=hidden name=days value={d}><input name=local placeholder="mailbox name" required style=width:140px><button>{n}</button></form>' for d,n,_,_ in MAIL_PACKS)}
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.6rem>Type your desired mailbox name, pick a length, pay the invoice — the mailbox activates the moment the payment settles.</div></div>
|
||
{mine}
|
||
<div class=card style=color:var(--dim)>API: POST /api/mail/create (local, days) → invoice · GET /api/mail/inbox?addr= (needs login) — inbound via Cloudflare Email Routing → worker relay.</div>""" + how(["Pick a name and a package — 7, 30 or 90 days, BTC priced.","Pay the invoice; the mailbox activates the second it settles.","The address is receive-only: verification codes, confirmations, one-off handouts.","The countdown runs in real time; when it hits zero the mailbox retires itself.","All mail shows on the site inbox — nothing touches any other identity."])
|
||
return page("steg", body)
|
||
|
||
@app.route("/api/mail/create", methods=["POST"])
|
||
def api_mail_create():
|
||
uid = current_user_id()
|
||
local = re.sub(r"[^a-z0-9._-]", "", (param("local") or "").lower())[:30]
|
||
days = param("days") or "7"
|
||
pack = next((p for p in MAIL_PACKS if p[0] == str(days)), None)
|
||
if not pack: return jsonify({"ok": False, "error": "bad package"}), 400
|
||
if not local: return jsonify({"ok": False, "error": "mailbox name required"}), 400
|
||
if local in MAIL_RESERVED: return jsonify({"ok": False, "error": "reserved name"}), 400
|
||
addr = f"{local}@{MAIL_DOMAIN}"
|
||
con = db()
|
||
if con.execute("SELECT 1 FROM mailboxes WHERE address=?", (addr,)).fetchone():
|
||
return jsonify({"ok": False, "error": "mailbox name taken"}), 400
|
||
uid = key_user() or current_user_id()
|
||
# metered: PASS = instant free; balance = instant paid; else BTC invoice
|
||
if uid and has_pass(uid):
|
||
con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
|
||
(uid, addr, "PASS", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3]))
|
||
con.commit()
|
||
return jsonify({"ok": True, "free": True, "address": addr, "expires_in_days": pack[3]})
|
||
if uid and charge(uid, pack[2]*100, f"burner mailbox {addr} ({pack[3]}d)"):
|
||
con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
|
||
(uid, addr, "BALANCE", 1, int(time.time())+86400*pack[3], int(time.time()), pack[3]))
|
||
con.commit()
|
||
return jsonify({"ok": True, "balance_charged": pack[2], "address": addr, "expires_in_days": pack[3]})
|
||
inv = btc_invoice(f"{pack[2]:.2f}")
|
||
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
|
||
con.execute("INSERT INTO mailboxes(user_id,address,invoice_id,paid,expires,created,plan_days) VALUES(?,?,?,?,?,?,?)",
|
||
(uid or 0, addr, inv["id"], 0, 0, int(time.time()), pack[3]))
|
||
con.commit()
|
||
return jsonify({"ok": True, "address": addr, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
|
||
|
||
@app.route("/api/mail/inbound", methods=["POST"])
|
||
def api_mail_inbound():
|
||
d = request.get_json(silent=True) or {}
|
||
if d.get("secret") != MAIL_SECRET: return jsonify({"ok": False}), 403
|
||
addr = (d.get("mailbox") or "").lower().split("@")[0]
|
||
con = db()
|
||
m = con.execute("SELECT * FROM mailboxes WHERE address LIKE ? AND paid=1", (addr + "@%",)).fetchone()
|
||
if not m: return jsonify({"ok": False, "error": "unknown/expired mailbox"}), 404
|
||
con.execute("INSERT INTO mails(mailbox_id,sender,subject,body,ts) VALUES(?,?,?,?,?)",
|
||
(m["id"], esc(d.get("from") or "?"), esc(d.get("subject") or ""), esc(d.get("body") or ""), int(time.time())))
|
||
con.execute("UPDATE mailboxes SET cnt=cnt+1 WHERE id=?", (m["id"],))
|
||
con.commit()
|
||
return jsonify({"ok": True})
|
||
|
||
@app.route("/mail/view")
|
||
def mail_view():
|
||
uid = current_user_id()
|
||
if not uid: return page("inbox", "<div class=card>login required</div>")
|
||
addr = param("addr") or ""
|
||
con = db()
|
||
m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr.lower(), uid)).fetchone()
|
||
if not m: return page("inbox", "<div class=card>not your mailbox</div>")
|
||
mails = con.execute("SELECT * FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],)).fetchall()
|
||
rows = "".join(f'<div class=msg><div class=who>{esc(x["sender"])} · {time.strftime("%b %d %H:%M", time.localtime(x["ts"]))}</div><b>{esc(x["subject"])}</b><br>{esc(x["body"])}</div>' for x in mails) or '<div style=color:var(--dim)>empty — waiting for mail…</div>'
|
||
left = max(0, m["expires"] - int(time.time()))
|
||
return page("steg", f"""
|
||
<h1>{esc(m['address'])}</h1><p class=sub><span id=cd style=color:var(--acc)></span> remaining — auto-refreshes every 15s.</p>
|
||
<div class=card>{rows}</div>
|
||
<script>
|
||
function tick(){{var s={left}-Math.floor((Date.now()-loaded)/1000);s=Math.max(0,s);var d=Math.floor(s/86400);document.getElementById('cd').textContent=d+'d '+Math.floor((s%86400)/3600)+'h '+Math.floor((s%3600)/60)+'m';}}
|
||
var loaded=Date.now();tick();setInterval(tick,1000);setInterval(function(){{location.reload()}},15000);
|
||
</script>""")
|
||
|
||
@app.route("/api/mail/inbox")
|
||
def api_mail_inbox():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login required (POST /inbox act=login)"})
|
||
con = db(); addr = (param("addr") or "").lower()
|
||
m = con.execute("SELECT * FROM mailboxes WHERE address=? AND user_id=?", (addr, uid)).fetchone()
|
||
if not m: return jsonify({"ok": False, "error": "unknown mailbox"})
|
||
return jsonify([dict(r) for r in con.execute("SELECT sender,subject,body,ts FROM mails WHERE mailbox_id=? ORDER BY id DESC LIMIT 100", (m["id"],))])
|
||
|
||
# ---------- 6c. PASS — all-tools subscription ----------
|
||
PASS_PACKS = [("30","1 month — $10 BTC",10,30),("90","3 months — $25 (save 17%)",25,90),("365","1 year — $80 (save 33%)",80,365)]
|
||
|
||
def has_pass(uid):
|
||
if not uid: return False
|
||
con = db()
|
||
r = con.execute("SELECT 1 FROM passes WHERE user_id=? AND expires > ? AND paid=1", (uid, int(time.time()))).fetchone()
|
||
return bool(r)
|
||
|
||
@app.route("/pass", methods=["GET"])
|
||
def pass_page():
|
||
uid = current_user_id()
|
||
mine = ""
|
||
if uid:
|
||
con = db()
|
||
r = con.execute("SELECT * FROM passes WHERE user_id=? AND paid=1 ORDER BY expires DESC LIMIT 1", (uid,)).fetchone()
|
||
if r and r["expires"] > int(time.time()):
|
||
left = r["expires"] - int(time.time())
|
||
mine = f'<div class="card glow"><span class="tag ok">PASS ACTIVE</span> {left//86400} days {left%86400//3600}h left — all tools unlimited (proxy rentals still metered at the storefront), trackables free, burner mail discounts.</div>'
|
||
body = f"""
|
||
<h1>PASS <span>— ALL ACCESS</span></h1><p class=sub>One BTC payment. Near-unlimited everything on this site: unlimited SMS rentals (house caps still apply for sanity), free trackables, burner mail included, no per-tool payments.</p>
|
||
<div class=card>
|
||
{''.join(f'<form action=/api/pass/create method=post style=display:inline;margin:0 .4rem><input type=hidden name=days value={d}><button class=ghost>{n}</button></form>' for d,n,_,_ in PASS_PACKS)}
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.6rem>Proxy rentals stay separate (they burn real upstream bandwidth — buy those at the storefront).</div></div>
|
||
{mine}
|
||
<div class=card style=color:var(--dim)>API: POST /api/pass/create (days=30|90|365) → invoice. Pass activates on payment settle via webhook.</div>"""
|
||
return page("sms", body)
|
||
|
||
@app.route("/api/pass/create", methods=["POST"])
|
||
def api_pass_create():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login first (POST /inbox act=login)"}), 401
|
||
days = param("days") or "30"
|
||
pack = next((p for p in PASS_PACKS if p[0] == str(days)), None)
|
||
if not pack: return jsonify({"ok": False, "error": "bad package"}), 400
|
||
inv = btc_invoice(f"{pack[2]:.2f}")
|
||
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
|
||
con = db()
|
||
con.execute("INSERT INTO passes(user_id,invoice_id,paid,expires,plan_days) VALUES(?,?,0,0,?)", (uid, inv["id"], pack[3]))
|
||
con.commit()
|
||
return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink"), "invoice_id": inv["id"]})
|
||
|
||
@app.route("/api/btcpay/webhook", methods=["POST"])
|
||
def btcpay_webhook():
|
||
sig = request.headers.get("BTCPay-Sig", "")
|
||
body = request.get_data()
|
||
expect = "sha256=" + hmac.new(BTCPAY_WHSEC.encode(), body, hashlib.sha256).hexdigest()
|
||
if sig != expect: return jsonify({"ok": False, "error": "bad sig"}), 400
|
||
d = jf(body) or {}
|
||
iid = d.get("invoiceId") or ""
|
||
if d.get("type") == "InvoiceSettled" or (d.get("type") == "InvoicePaymentSettled"):
|
||
con = db()
|
||
if iid:
|
||
if con.execute("SELECT 1 FROM wh_processed WHERE invoice_id=?", (iid,)).fetchone():
|
||
return jsonify({"ok": True, "dup": True})
|
||
con.execute("INSERT OR IGNORE INTO wh_processed(invoice_id,ts) VALUES(?,?)", (iid, int(time.time())))
|
||
con.execute("UPDATE trackables SET paid=1 WHERE invoice_id=?", (iid,))
|
||
r = con.execute("SELECT plan_days FROM mailboxes WHERE invoice_id=?", (iid,)).fetchone()
|
||
if r:
|
||
con.execute("UPDATE mailboxes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 7), iid))
|
||
r = con.execute("SELECT plan_days FROM passes WHERE invoice_id=?", (iid,)).fetchone()
|
||
if r:
|
||
con.execute("UPDATE passes SET paid=1, expires=? WHERE invoice_id=?", (int(time.time()) + 86400*int(r["plan_days"] or 30), iid))
|
||
# balance top-ups
|
||
try:
|
||
meta = d.get("metadata") or {}
|
||
if not meta:
|
||
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices/{iid}", headers={"Authorization": "token " + BTCPAY_KEY})
|
||
meta = (jf(b) or {}).get("metadata", {}) or {}
|
||
if str(meta.get("orderId", "")).startswith("dark0rbits-topup"):
|
||
uid = int(meta["orderId"].split(":")[1]); cents = int(meta["orderId"].split(":")[2])
|
||
con.execute("INSERT OR IGNORE INTO balances(user_id, cents) VALUES(?, 0)", (uid,))
|
||
con.execute("UPDATE balances SET cents = cents + ? WHERE user_id=?", (cents, uid))
|
||
con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, cents, f"BTC topup {iid}", int(time.time())))
|
||
except Exception: pass
|
||
con.commit()
|
||
return jsonify({"ok": True})
|
||
|
||
# ---------- 6h. API KEYS + BALANCE ----------
|
||
@app.route("/keys", methods=["GET", "POST"])
|
||
def keys():
|
||
uid = current_user_id()
|
||
if not uid:
|
||
return page("inbox", '<h1>API <span>KEYS</span></h1><div class=card>login on /inbox first — keys are bound to your account.</div><a href=/inbox><button>Login</button></a>')
|
||
con = db()
|
||
if request.method == "POST" and request.form.get("act") == "mkkey":
|
||
label = (param("label") or "default")[:40]
|
||
key = "dk_" + secrets.token_urlsafe(24)
|
||
con.execute("INSERT INTO apikeys(user_id,key,label,created) VALUES(?,?,?,?)", (uid, key, esc(label), int(time.time())))
|
||
con.commit()
|
||
newkey = key
|
||
else:
|
||
newkey = None
|
||
rows = con.execute("SELECT * FROM apikeys WHERE user_id=? AND revoked=0 ORDER BY id DESC", (uid,)).fetchall()
|
||
bal = get_balance(uid)
|
||
led = con.execute("SELECT * FROM ledger WHERE user_id=? ORDER BY id DESC LIMIT 15", (uid,)).fetchall()
|
||
led_html = "".join(f"<tr><td>{'$%.2f' % (l['delta_cents']/100)}</td><td>{esc(l['reason'])}</td><td>{time.strftime('%b %d %H:%M', time.localtime(l['ts']))}</td></tr>" for l in led)
|
||
keys_html = "".join("<tr><td><code>"+esc(k['key'][:14])+"…</code> <a href=# onclick=\"cp('"+k['key']+"');return false\" style=color:var(--acc)>copy</a></td><td>"+esc(k['label'])+"</td><td>"+time.strftime('%b %d', time.localtime(k['created']))+"</td></tr>" for k in rows)
|
||
newkey_block = ('<div class="card glow" style="margin-top:.8rem"><span class="tag ok">NEW KEY (shown once)</span><br><code id=nk style="font-size:1.1rem">'+esc(newkey)+'</code> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(\''+newkey+'\')">copy</button></div>') if newkey else ''
|
||
keys_block = ('<div class=card><b>Keys</b><table><tr><th>Key</th><th>Label</th><th>Created</th></tr>'+keys_html+'</table></div>') if rows else ''
|
||
body = f"""
|
||
<h1>API <span>KEYS</span> — balance: <span style=color:var(--acc)>${bal/100:.2f}</span></h1>
|
||
<p class=sub>Metered access for agents and humans. Every paid call deducts from your balance. $1 free trial credit on signup. No KYC, BTC top-ups only.</p>
|
||
<div class="grid2">
|
||
<div class=card><b>New API key</b><form method=post><input type=hidden name=act value=mkkey><input name=label placeholder="key label (e.g. my-bot)" style=width:100%><button style=margin-top:.5rem>Generate key</button></form>
|
||
{newkey_block}
|
||
{keys_block}
|
||
</div>
|
||
<div class=card><b>Top up (BTC)</b>
|
||
{''.join(f'<form action=/api/balance/topup method=post style=display:inline;margin:0 .3rem><input type=hidden name=cents value={c}><button class=ghost>${a}</button></form>' for c,a in [(500,'$5'),(2000,'$20'),(10000,'$100')])}
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.5rem>Invoice settles → balance credited automatically via webhook.</div></div>
|
||
</div>
|
||
<div class=card><b>Ledger</b><table><tr><th>Δ</th><th>Reason</th><th>When</th></tr>{led_html or '<tr><td colspan=3 style=color:var(--dim)>no charges yet</td></tr>'}</table></div>
|
||
<div class=card style=color:var(--dim)>Use it: <code>Authorization: Bearer dk_…</code> header on any paid API call. Metered endpoints: /api/sms/rent (pass-through cost), /api/mail/create (package price), /api/track/create ($1). Everything else free. PASS = no metering.</div>"""
|
||
return page("inbox", body)
|
||
|
||
@app.route("/api/balance/topup", methods=["POST"])
|
||
def api_balance_topup():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login required"}), 401
|
||
cents = int(param("cents") or 500)
|
||
if cents not in (500, 2000, 10000): return jsonify({"ok": False, "error": "bad amount"}), 400
|
||
# invoice created WITH topup metadata in one shot
|
||
st, b = http(f"{BTCPAY}/stores/{BTCPAY_STORE}/invoices",
|
||
headers={"Authorization": "token " + BTCPAY_KEY, "Content-Type": "application/json"},
|
||
data=json.dumps({"amount": f"{cents/100:.2f}", "currency": "USD",
|
||
"metadata": {"orderId": f"dark0rbits-topup:{uid}:{cents}", "itemDesc": "dark0rbits balance topup"}}).encode(), method="POST")
|
||
inv = jf(b) or {}
|
||
if not inv.get("id"): return jsonify({"ok": False, "error": str(inv)[:200]}), 400
|
||
con = db()
|
||
con.execute("INSERT INTO ledger(user_id,delta_cents,reason,ts) VALUES(?,?,?,?)", (uid, 0, f"topup invoice {inv['id']} pending", int(time.time())))
|
||
con.commit()
|
||
return jsonify({"ok": True, "checkoutLink": inv.get("checkoutLink")})
|
||
|
||
@app.route("/api/balance")
|
||
def api_balance():
|
||
uid = key_user() or current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "auth required"}), 401
|
||
return jsonify({"ok": True, "balance_cents": get_balance(uid), "pass_active": has_pass(uid)})
|
||
|
||
# ---------- 6d. EMAIL HEADER FORENSICS ----------
|
||
def parse_headers(raw):
|
||
import email as em
|
||
msg = em.message_from_string(raw)
|
||
out = {"from": msg.get("From",""), "to": msg.get("To",""), "subject": msg.get("Subject",""),
|
||
"date": msg.get("Date",""), "return_path": msg.get("Return-Path",""),
|
||
"reply_to": msg.get("Reply-To",""), "message_id": msg.get("Message-ID","")}
|
||
hops = []
|
||
for h in msg.get_all("Received", []) or []:
|
||
hop = h.strip().replace("\n", " ")
|
||
hops.append(hop[:300])
|
||
out["hops"] = list(reversed(hops)) # first-hop origin first
|
||
auth = msg.get_all("Authentication-Results", []) or []
|
||
out["auth_results"] = [a.strip()[:300] for a in auth]
|
||
out["dkim"] = [d.strip()[:200] for d in (msg.get_all("DKIM-Signature", []) or [])][:3]
|
||
# spoof flags
|
||
flags = []
|
||
env_from = out["return_path"].strip("<>")
|
||
frm = out["from"]
|
||
m_from = re.search(r"<([^>]+)>", frm)
|
||
addr_from = (m_from.group(1) if m_from else frm).split()[-1].strip("<>").lower()
|
||
if env_from and addr_from and env_from.split("@")[-1] != addr_from.split("@")[-1]:
|
||
flags.append(f"envelope-from domain ({env_from.split('@')[-1]}) != From domain ({addr_from.split('@')[-1]}) — classic spoof marker")
|
||
if out["reply_to"]:
|
||
m_rt = re.search(r"<([^>]+)>", out["reply_to"]) or None
|
||
addr_rt = ((m_rt.group(1) if m_rt else out["reply_to"]).strip()).lower()
|
||
if addr_rt.split("@")[-1] != addr_from.split("@")[-1]:
|
||
flags.append(f"Reply-To ({addr_rt}) differs from From — possible reply-hijack")
|
||
# origin IP = the bottom-most Received header (original sender); in reversed list it's index 0
|
||
origin_ip = None
|
||
for h in hops: # reversed order → origin first
|
||
m = re.search(r"\[(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\]", h) or re.search(r"\b(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\b", h)
|
||
if m:
|
||
origin_ip = m.group(1); break
|
||
out["origin_ip"] = origin_ip
|
||
if origin_ip: out["origin_geo"] = enrich_ip(origin_ip)
|
||
out["flags"] = flags
|
||
# dmarc/spf/dkim verdict parse from Authentication-Results
|
||
verdicts = {}
|
||
blob = " ".join(out["auth_results"]).lower()
|
||
for k in ("spf","dkim","dmarc"):
|
||
m = re.search(k + r"=(\w+)", blob)
|
||
verdicts[k] = m.group(1) if m else "not present"
|
||
out["verdicts"] = verdicts
|
||
return out
|
||
|
||
@app.route("/eh")
|
||
def eh():
|
||
body = f"""
|
||
<h1>EMAIL <span>FORENSICS</span></h1><p class=sub>Paste full raw email headers (View source → copy all) — get the real origin, SPF/DKIM/DMARC verdicts, and spoof flags.</p>
|
||
<div class=card><form method=post action=/eh_result><textarea name=raw rows=10 style="width:100%" placeholder="Received: from … Authentication-Results: …"></textarea>
|
||
<button style=margin-top:.5rem>Analyze</button></form></div>
|
||
<div class=card style=color:var(--dim)>API: POST /api/eh (raw=…) → JSON: origin IP+geo, hop chain, verdicts, spoof flags.</div>""" + how(["Open the suspicious email → View source → copy ALL headers.","Paste them here — the parser walks the full Received chain.","The real origin IP is pulled from the bottom-most relay hop and geolocated.","SPF/DKIM/DMARC verdicts are extracted and color-coded.","Spoof markers are flagged automatically: envelope≠From domain, Reply-To hijacks."])
|
||
return page("tools", body)
|
||
|
||
@app.route("/eh_result", methods=["POST"])
|
||
def eh_result():
|
||
d = parse_headers(request.form.get("raw") or "")
|
||
hops = "".join(f"<div class=msg><div class=who>hop {i+1}</div>{esc(h)}</div>" for i, h in enumerate(d["hops"]))
|
||
verdicts = " ".join(f'<span class="tag {"ok" if v=="pass" else ("bad" if v in ("fail","softfail") else "warn")}">{k.upper()}: {v}</span>' for k, v in d["verdicts"].items())
|
||
flags = "".join(f"<div class=tag bad style=margin:.2rem>{esc(f)}</div><br>" for f in d["flags"]) or '<span style=color:var(--ok)>no spoof markers found</span>'
|
||
og = d.get("origin_geo") or {}
|
||
origin = f"{esc(d.get('origin_ip'))}" + (f" — {esc(og.get('city'))}, {esc(og.get('country'))} · {esc(og.get('isp'))}" if og else "")
|
||
return page("tools", f"""
|
||
<h1>VERDICT <span>{esc(d.get('subject') or '(no subject)')}</span></h1>
|
||
{kv([("From", esc(d.get('from'))), ("Envelope-from", esc(d.get('return_path'))), ("Reply-To", esc(d.get('reply_to') or '—')), ("Origin IP", origin)])}
|
||
<div class=card><b>Authentication</b><br>{verdicts}<br><br><b>Spoof flags</b><br>{flags}</div>
|
||
<div class=card><b>Relay chain (origin first)</b>{hops or '<i style=color:var(--dim)>no Received headers</i>'}</div>""")
|
||
|
||
@app.route("/api/eh", methods=["POST"])
|
||
def api_eh():
|
||
return jsonify(parse_headers(param("raw") or ""))
|
||
|
||
# ---------- 6e. IMAGE FORENSICS ----------
|
||
@app.route("/forensics")
|
||
def forensics():
|
||
body = f"""
|
||
<h1>IMAGE <span>FORENSICS</span></h1><p class=sub>EXIF dump, GPS extraction, date/software flags, error-level analysis (ELA) — spot edits, and sniff out OTHER people's stego.</p>
|
||
<div class=card><form action=/forensics_result method=post enctype=multipart/form-data>
|
||
<div class=drop onclick="document.getElementById('fi').click()">🖼 drop an image<input id=fi type=file name=image accept="image/*" style=display:none required></div>
|
||
<div id=fifn style=color:var(--dim);font-size:.85rem></div>
|
||
<button style=margin-top:.5rem>Analyze</button></form></div>
|
||
<script>document.getElementById('fi').addEventListener('change',function(){{document.getElementById('fifn').textContent=this.files[0].name}})</script>
|
||
<div class=card style=color:var(--dim)>API: POST /api/forensics (image) → JSON: exif, gps, flags, ELA score.</div>""" + how(["Drop any image — EXIF and GPS get dumped instantly.","Error-level analysis (ELA) re-compresses and diffs: edited regions glow in the amplified view.","Edit-tool tags (Photoshop/GIMP) are flagged automatically.","EXIF-stripped images get flagged too — usually means scrubbed or generated.","If the image carries a DARK0RBITS stego payload, this tool sees it."])
|
||
return page("steg", body)
|
||
|
||
def _ela_score(img_bytes):
|
||
from PIL import Image, ImageChops, ImageEnhance
|
||
im = Image.open(io.BytesIO(img_bytes)).convert("RGB")
|
||
resaved = io.BytesIO(); im.save(resaved, "JPEG", quality=90)
|
||
ela = ImageChops.difference(im, Image.open(resaved))
|
||
extrema = ela.getextrema()
|
||
maxdiff = max(e[1] for e in extrema)
|
||
enh = ImageEnhance.Brightness(ela).enhance(15)
|
||
out = io.BytesIO(); enh.save(out, "PNG")
|
||
return out.getvalue(), maxdiff
|
||
|
||
@app.route("/forensics_result", methods=["POST"])
|
||
def forensics_result():
|
||
f = request.files.get("image")
|
||
if not f: return page("steg", "no image")
|
||
data = f.read()
|
||
from PIL import Image
|
||
im = Image.open(io.BytesIO(data))
|
||
exif = im.getexif()
|
||
rows = []
|
||
gps = {}
|
||
try:
|
||
from PIL.ExifTags import TAGS, GPSTAGS
|
||
except Exception:
|
||
TAGS, GPSTAGS = {}, {}
|
||
for k, v in exif.items():
|
||
name = TAGS.get(k, k) if isinstance(k, int) else k
|
||
try: rows.append((str(name), str(v)[:120]))
|
||
except Exception: pass
|
||
# GPS
|
||
try:
|
||
gifd = exif.get_ifd(0x8825)
|
||
if gifd:
|
||
for k, v in gifd.items():
|
||
gps[GPSTAGS.get(k, k)] = str(v)[:60]
|
||
except Exception: pass
|
||
flags = []
|
||
if not rows: flags.append("EXIF stripped/absent — edited or privacy-scrubbed")
|
||
else:
|
||
for k, v in rows:
|
||
if "software" in k.lower(): flags.append(f"software: {v}")
|
||
if "Photoshop" in v or "GIMP" in v: flags.append(f"⚠ EDITED IN {v}")
|
||
stego = ("auriga_meta" in im.info or "dark0rbits_meta" in im.info)
|
||
ela_png, maxdiff = _ela_score(data)
|
||
fn = (f.filename or "image")[:60]
|
||
verdict = "CLEAN-ISH" if maxdiff < 12 and not flags else "SUSPECT — check ELA"
|
||
rows_html = "".join(f"<tr><td>{esc(k)}</td><td>{esc(v)}</td></tr>" for k, v in rows)
|
||
gps_html = " ".join(f"<div>{esc(k)}: {esc(v)}</div>" for k, v in gps.items()) or "—"
|
||
import base64 as b64mod
|
||
ela_b64 = b64mod.b64encode(ela_png).decode()
|
||
return page("steg", f"""
|
||
<h1>FORENSICS <span>{esc(fn)}</span></h1>
|
||
{kv([("Verdict", f'<span class="tag {"ok" if verdict.startswith("CLEAN") else "bad"}">{verdict}</span>'), ("ELA max diff", f"{maxdiff} (low=uniform=re-saved clean)"), ("EXIF", f"{len(rows)} tags"), ("Stego", "DARK0RBITS payload present ✓" if stego else "none detected")])}
|
||
<div class=card><b>Flags</b><br>{'<br>'.join(esc(x) for x in flags) or '<span style=color:var(--ok)>none</span>'}</div>
|
||
<div class=card><b>ELA (amplified 15×)</b><br><img src="data:image/png;base64,{ela_b64}" style="max-width:100%;border-radius:8px"> <a href=/api/forensics/ela?download=1 style=color:var(--acc)>full PNG</a> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(document.querySelector('img').src)">copy data-uri</button></div>
|
||
<div class=card><b>EXIF table</b><table>{rows_html or '<tr><td colspan=2 style=color:var(--dim)>no EXIF</td></tr>'}</table></div>
|
||
<div class=card><b>GPS</b>{gps_html}</div>""")
|
||
|
||
@app.route("/api/forensics", methods=["POST"])
|
||
def api_forensics():
|
||
f = request.files.get("image")
|
||
if not f: return jsonify({"ok": False, "error": "image required"}), 400
|
||
data = f.read()
|
||
from PIL import Image
|
||
im = Image.open(io.BytesIO(data))
|
||
exif = im.getexif()
|
||
ex = {}
|
||
try:
|
||
from PIL.ExifTags import TAGS
|
||
except Exception:
|
||
TAGS = {}
|
||
for k, v in exif.items():
|
||
try: ex[str(TAGS.get(k, k) if isinstance(k, int) else k)] = str(v)[:200]
|
||
except Exception: pass
|
||
_, maxdiff = _ela_score(data)
|
||
return jsonify({"ok": True, "exif": ex, "gps_present": bool(exif.get_ifd(0x8825)) if hasattr(exif, "get_ifd") else False,
|
||
"stego_auriga": ("auriga_meta" in im.info or "dark0rbits_meta" in im.info), "ela_max_diff": maxdiff,
|
||
"flags": (["exif-stripped"] if not ex else [])})
|
||
|
||
# ---------- 6f. CANARY TRAPS ----------
|
||
@app.route("/canary")
|
||
def canary():
|
||
uid = current_user_id()
|
||
body = f"""
|
||
<h1>CANARY <span>TRAPS</span></h1><p class=sub>Plant tripwires. Anyone who touches one — clicks the link, loads the pixel — fires an instant alert into your inbox. Tag each trap with who it belongs to.</p>
|
||
<div class=card><b>New trap</b><form method=post>
|
||
<input name=tag placeholder="tag: who/where (e.g. 'resume-dropbox', 'backup-folder')" style="width:70%" required>
|
||
<button style=margin-left:.5rem>Create trap</button></form>
|
||
<div style=color:var(--dim);font-size:.85rem;margin-top:.5rem>You get: a link (paste anywhere), a pixel URL (embed in docs/pages), and a fake credential line to drop in files.</div></div>
|
||
{canary_list()}
|
||
<div class=card style=color:var(--dim)>API: POST /canary (tag) · GET /api/canary/list (login) · hits log like trackables.</div>""" + how(["Create a trap and tag it with who/where it belongs.","Plant the link anywhere — or embed the pixel URL, or drop the fake credential line.","The moment ANYONE touches it: IP, geo, ISP, device fire into your inbox.","Each trap shows its hit count and armed/triggered status.","One trap per place — re-plant after it fires."])
|
||
return page("track", body)
|
||
|
||
def canary_list():
|
||
uid = current_user_id()
|
||
if not uid: return ""
|
||
con = db()
|
||
rows = con.execute("SELECT * FROM canaries WHERE user_id=? ORDER BY id DESC LIMIT 20", (uid,)).fetchall()
|
||
trs = ""
|
||
for c in rows:
|
||
hits = con.execute("SELECT COUNT(*) c FROM canary_hits WHERE canary_id=?", (c["id"],)).fetchone()["c"]
|
||
trs += f"<tr><td>{esc(c['tag'])}</td><td><code>{SITE}/c/{c['token']}</code> <a href=# onclick=\"cp('{SITE}/c/{c['token']}');return false\" style=color:var(--acc)>copy</a></td><td>{SITE}/c/{c['token']}.png</td><td><b>{hits}</b></td><td>{'armed' if c['armed'] else 'triggered ⚠'}</td></tr>"
|
||
return f'<div class=card><b>Your traps</b><table><tr><th>Tag</th><th>Link</th><th>Pixel</th><th>Hits</th><th>Status</th></tr>{trs or "<tr><td colspan=5 style=color:var(--dim)>none yet</td></tr>"}</table></div>'
|
||
|
||
@app.route("/canary", methods=["POST"])
|
||
def canary_create():
|
||
uid = current_user_id()
|
||
if not uid: return page("track", "<div class=card>login required</div>")
|
||
tag = (param("tag") or "untagged")[:80]
|
||
con = db()
|
||
token = secrets.token_urlsafe(12)
|
||
con.execute("INSERT INTO canaries(user_id,token,tag,created,armed) VALUES(?,?,?,?,1)", (uid, token, esc(tag), int(time.time())))
|
||
con.commit()
|
||
resp = Response(status=302); resp.headers["Location"] = "/canary"
|
||
return resp
|
||
|
||
@app.route("/c/<token>")
|
||
def canary_hit(token):
|
||
con = db()
|
||
c = con.execute("SELECT * FROM canaries WHERE token=?", (token,)).fetchone()
|
||
if not c: return "not found", 404
|
||
con.execute("INSERT INTO canary_hits(canary_id,ts,ip,ua) VALUES(?,?,?,?)",
|
||
(c["id"], int(time.time()), request.headers.get("X-Real-IP") or request.remote_addr, request.headers.get("User-Agent","")))
|
||
con.execute("UPDATE canaries SET armed=0 WHERE id=?", (c["id"],))
|
||
if c["user_id"]:
|
||
ip = request.headers.get("X-Real-IP") or request.remote_addr
|
||
geo = enrich_ip(ip)
|
||
where = f" — {geo.get('city','')}, {geo.get('countryCode','')} · {geo.get('isp','')}" if geo else ""
|
||
con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)",
|
||
(c["user_id"], "operator-bot", f"🚨 CANARY TRIGGERED: '{c['tag']}' — IP <b>{esc(ip)}</b>{esc(where)} · device {esc(request.headers.get('User-Agent','')[:80])}", int(time.time())))
|
||
con.commit()
|
||
return "Not Found", 404
|
||
|
||
@app.route("/c/<token>.png")
|
||
def canary_pixel(token):
|
||
canary_hit(token)
|
||
px = base64.b64decode("R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7")
|
||
return Response(px, mimetype="image/gif", headers={"Cache-Control": "no-store"})
|
||
|
||
@app.route("/api/canary/list")
|
||
def api_canary_list():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login required"})
|
||
con = db()
|
||
rows = [dict(r) | {"hits": con.execute("SELECT COUNT(*) c FROM canary_hits WHERE canary_id=?", (r["id"],)).fetchone()["c"]} for r in con.execute("SELECT * FROM canaries WHERE user_id=? ORDER BY id DESC LIMIT 50", (uid,))]
|
||
return jsonify(rows)
|
||
|
||
# ---------- 6g. AGENT PASSPORT ----------
|
||
@app.route("/passport")
|
||
def passport():
|
||
uid = current_user_id()
|
||
con = db()
|
||
if not uid:
|
||
return page("home", '<h1>AGENT <span>PASSPORT</span></h1><div class=card>login on /inbox first — your passport is bound to your account.</div>')
|
||
u = con.execute("SELECT * FROM users WHERE id=?", (uid,)).fetchone()
|
||
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals WHERE created > (strftime('%s','now')-2592000)", ).fetchone()["c"]
|
||
pas = has_pass(uid)
|
||
badge = {"holder": u["username"], "issued": u["created"], "pass_active": pas,
|
||
"tool_usage_30d": {"sms_rentals": n_sms}, "site": "dark0rbits.thetempleofdoom.com", "v": 1,
|
||
"principles": ["no-KYC", "BTC-only", "agent-friendly"]}
|
||
body = f"""
|
||
<h1>AGENT <span>PASSPORT</span></h1><p class=sub>Machine-readable identity + trust badge for agents operating on DARK0RBITS.</p>
|
||
{kv([("Holder", esc(u['username'])), ("Issued", time.strftime("%b %d %Y", time.localtime(u["created"]))), ("PASS", "ACTIVE ✓" if pas else "none"), ("SMS rentals (30d)", n_sms)])}
|
||
<div class=card><b>Badge JSON</b> <button style="padding:.2rem .6rem;font-size:.8rem" onclick="cp(document.getElementById('bp').textContent)">copy</button><br><pre id=bp style=white-space:pre-wrap>{json.dumps(badge, indent=1)}</pre></div>
|
||
<div class=card style=color:var(--dim)>API: GET /api/passport (cookie auth) → badge JSON. Embed in your agent's llms.txt / tool card.</div>"""
|
||
return page("home", body)
|
||
|
||
@app.route("/api/passport")
|
||
def api_passport():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login required"})
|
||
con = db()
|
||
u = con.execute("SELECT * FROM users WHERE id=?", (uid,)).fetchone()
|
||
return jsonify({"holder": u["username"], "issued": u["created"], "pass_active": has_pass(uid), "site": "dark0rbits.thetempleofdoom.com"})
|
||
|
||
# ---------- 7. INBOX (no-KYC site-only messaging) ----------
|
||
def hash_pw(pw): return hashlib.scrypt(pw.encode(), salt=b"dark0rbits-salt", n=16384, r=8, p=1).hex()
|
||
|
||
def current_user_id():
|
||
tok = request.cookies.get("dark0rbits_tok")
|
||
if not tok: return None
|
||
con = db()
|
||
s = con.execute("SELECT user_id FROM sessions WHERE token=?", (tok,)).fetchone()
|
||
return s["user_id"] if s else None
|
||
|
||
@app.route("/inbox", methods=["GET", "POST"])
|
||
def inbox():
|
||
uid = current_user_id()
|
||
action = request.form.get("act") if request.method == "POST" else None
|
||
con = db()
|
||
if action == "register":
|
||
u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or ""
|
||
if not u or len(p) < 4:
|
||
return page("inbox", "<h1>INBOX</h1><div class=card><span class=tag bad>username + password (4+ chars) required</span></div>")
|
||
try:
|
||
con.execute("INSERT INTO users(username,passhash,created) VALUES(?,?,?)", (u, hash_pw(p), int(time.time())))
|
||
con.commit()
|
||
except sqlite3.IntegrityError:
|
||
return page("inbox", "<h1>INBOX</h1><div class=card><span class=tag bad>name taken</span></div>")
|
||
tok = secrets.token_urlsafe(24)
|
||
con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, con.execute("SELECT id FROM users WHERE username=?", (u,)).fetchone()["id"], int(time.time())))
|
||
con.commit()
|
||
resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True)
|
||
return resp
|
||
elif action == "login":
|
||
u, p = (request.form.get("u") or "").strip()[:32], request.form.get("p") or ""
|
||
r = con.execute("SELECT * FROM users WHERE username=?", (u,)).fetchone()
|
||
if r and r["passhash"] == hash_pw(p):
|
||
tok = secrets.token_urlsafe(24)
|
||
con.execute("INSERT INTO sessions(token,user_id,created) VALUES(?,?,?)", (tok, r["id"], int(time.time())))
|
||
con.commit()
|
||
resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", tok, max_age=86400*30, httponly=True)
|
||
return resp
|
||
return page("inbox", "<h1>INBOX</h1><div class=card><span class=tag bad>bad login</span></div>")
|
||
elif action == "logout":
|
||
con.execute("DELETE FROM sessions WHERE token=?", (request.cookies.get("dark0rbits_tok"),)); con.commit()
|
||
resp = Response(status=302); resp.headers["Location"] = "/inbox"; resp.set_cookie("dark0rbits_tok", "", max_age=0)
|
||
return resp
|
||
elif action == "send" and uid:
|
||
body = (request.form.get("body") or "").strip()[:4000]
|
||
if body:
|
||
con.execute("INSERT INTO messages(user_id,sender,body,created) VALUES(?,?,?,?)", (uid, "user", esc(body), int(time.time())))
|
||
con.commit()
|
||
if not uid:
|
||
return page("inbox", f"""
|
||
<h1>INBOX <span>— no KYC</span></h1><p class=sub>Just a name + password. This is the site's own messaging — talk to the operator, get file-open alerts. Nothing leaves the site.</p>
|
||
<div class="grid2">
|
||
<div class=card><b>Login</b><form method=post><input type=hidden name=act value=login><input name=u placeholder=username style=width:100%><input name=p type=password placeholder=password style="width:100%;margin:.5rem 0"><button>Login</button></form></div>
|
||
<div class=card><b>Create account</b><form method=post><input type=hidden name=act value=register><input name=u placeholder=username style=width:100%><input name=p type=password placeholder="password (4+ chars)" style="width:100%;margin:.5rem 0"><button class=ghost>Create</button></form></div>
|
||
</div>""")
|
||
msgs = con.execute("SELECT * FROM messages WHERE user_id=? ORDER BY id DESC LIMIT 50", (uid,)).fetchall()
|
||
msgs_html = "".join(f'<div class="msg {"me" if m["sender"]=="user" else ""}"><div class=who>{"you" if m["sender"]=="user" else esc(m["sender"])} · {time.strftime("%b %d %H:%M", time.localtime(m["created"]))}</div>{m["body"]}</div>' for m in reversed(msgs)) or '<div style=color:var(--dim)>no messages yet — say hi.</div>'
|
||
files = con.execute("SELECT * FROM trackables WHERE user_id=? ORDER BY id DESC LIMIT 10", (uid,)).fetchall()
|
||
files_html = "".join(f"<tr><td>{esc(f['filename'])}</td><td>{'<a href=/api/track/events?token='+f['token']+'>events</a>' if f['paid'] else '—'}</td><td>{'paid ✓' if f['paid'] else 'unpaid'}</td><td>{time.strftime('%b %d', time.localtime(f['created']))}</td></tr>" for f in files)
|
||
body = f"""
|
||
<h1>INBOX</h1><p class=sub>Site-internal messaging with the operator + your file-open alerts.</p>
|
||
<div class=card><form method=post><input type=hidden name=act value=send>
|
||
<textarea name=body rows=3 style="width:100%" placeholder="message to the operator…"></textarea>
|
||
<button style=margin-top:.5rem>Send</button></form></div>
|
||
<div class=card><b>Conversation</b>{msgs_html}</div>
|
||
<div class=card><b>Your tracked files</b><table><tr><th>File</th><th>Events</th><th>Status</th><th>Created</th></tr>{files_html or '<tr><td colspan=4 style=color:var(--dim)>none yet</td></tr>'}</table></div>
|
||
<div class=card style="text-align:right"><form method=post><input type=hidden name=act value=logout><button class=ghost>Log out</button></form></div>
|
||
<div class=card style=color:var(--dim)>API: (cookie auth) POST /inbox act=send body=… · GET /api/inbox/messages</div>"""
|
||
return page("inbox", body)
|
||
|
||
@app.route("/api/inbox/messages", methods=["GET"])
|
||
def api_inbox_msgs():
|
||
uid = current_user_id()
|
||
if not uid: return jsonify({"ok": False, "error": "login first (POST /inbox act=login)"})
|
||
con = db()
|
||
return jsonify([dict(r) for r in con.execute("SELECT * FROM messages WHERE user_id=? ORDER BY id DESC LIMIT 100", (uid,))])
|
||
|
||
# ---------- 8. FREE TOOLS ----------
|
||
TOOLS_JS = """
|
||
function tab(n){document.querySelectorAll('.pane').forEach(p=>p.style.display='none');document.getElementById(n).style.display='block'}
|
||
async function dns(){const d=document.getElementById('dq').value;const o=await (await fetch('https://dns.google/resolve?name='+encodeURIComponent(d)+'&type=A')).json();document.getElementById('do').textContent=JSON.stringify(o,null,1)}
|
||
async function hdr(){const u=document.getElementById('hq').value;const r=await (await fetch('/api/hdr?url='+encodeURIComponent(u))).json();document.getElementById('ho').textContent=JSON.stringify(r,null,1)}
|
||
function jwt(){try{const t=document.getElementById('jq').value.trim().split('.');const d=s=>JSON.stringify(JSON.parse(atob(s.replace(/-/g,'+').replace(/_/g,'/'))),null,1);document.getElementById('jo').textContent='HEADER\\n'+d(t[0])+'\\n\\nPAYLOAD\\n'+d(t[1])}catch(e){document.getElementById('jo').textContent='Invalid JWT: '+e}}
|
||
async function genhash2(){const i=document.getElementById('hq2').value;const r=await(await fetch('/api/hash?s='+encodeURIComponent(i))).json();for(const k of ['md5','sha1','sha256','sha512'])document.getElementById('h_'+k).textContent=r[k]}
|
||
function uuids(){let o='';for(let i=0;i<5;i++)o+=crypto.randomUUID()+'\\n';document.getElementById('uo').textContent=o}
|
||
function pwgen(){const l=+document.getElementById('pl').value||24;const cs='abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ23456789!@#$%^&*-_=+';const a=new Uint32Array(l);crypto.getRandomValues(a);document.getElementById('po').textContent=Array.from(a,x=>cs[x%cs.length]).join('')}
|
||
"""
|
||
|
||
@app.route("/api/hdr")
|
||
def api_hdr():
|
||
url = param("url") or ""
|
||
if "://" not in url: url = "http://" + url
|
||
try:
|
||
req = urllib.request.Request(url)
|
||
with urllib.request.urlopen(req, timeout=12) as r:
|
||
return jsonify({"status": r.status, "final_url": r.url, "headers": dict(r.headers)})
|
||
except Exception as e:
|
||
return jsonify({"error": str(e)})
|
||
|
||
@app.route("/api/hash")
|
||
def api_hash():
|
||
s = (param("s") or "").encode()
|
||
return jsonify({"md5": hashlib.md5(s).hexdigest(), "sha1": hashlib.sha1(s).hexdigest(),
|
||
"sha256": hashlib.sha256(s).hexdigest(), "sha512": hashlib.sha512(s).hexdigest()})
|
||
|
||
@app.route("/tools")
|
||
def tools():
|
||
body = f"""
|
||
<h1>FREE <span>TOOLS</span></h1><p class=sub>High-value, zero-cost, no signup. APIs underneath each.</p>
|
||
<style>.tbtn.on{{background:var(--acc);color:#111}}</style>
|
||
<div style=margin-bottom:1rem>
|
||
<button class="tbtn on" onclick="tab('dns_p');this.classList.add('on')">DNS Lookup</button>
|
||
<button class=tbtn onclick="tab('hdr_p');this.classList.add('on')">HTTP Headers</button>
|
||
<button class=tbtn onclick="tab('jwt_p');this.classList.add('on')">JWT Decoder</button>
|
||
<button class=tbtn onclick="tab('hash_p');this.classList.add('on')">Hasher</button>
|
||
<button class=tbtn onclick="tab('gen_p');this.classList.add('on')">Generators</button></div>
|
||
<script>{TOOLS_JS}</script>
|
||
<div id=dns_p class="card pane"><b>DNS Lookup</b> <span style=color:var(--dim)>(Google DoH)</span><br>
|
||
<input id=dq placeholder=thetempleofdoom.com style=width:70%><button onclick=dns()>Resolve</button>
|
||
<pre id=do style=white-space:pre-wrap></pre></div>
|
||
<div id=hdr_p class="card pane" style=display:none><b>HTTP Header Inspector</b><br>
|
||
<input id=hq placeholder=https://lynx.thetempleofdoom.com style=width:70%><button onclick=hdr()>Inspect</button>
|
||
<pre id=ho style=white-space:pre-wrap></pre></div>
|
||
<div id=jwt_p class="card pane" style=display:none><b>JWT Decoder</b> (token never leaves your browser)<br>
|
||
<textarea id=jq rows=3 style="width:100%">paste eyJ…</textarea><button onclick=jwt()>Decode</button>
|
||
<pre id=jo style=white-space:pre-wrap></pre></div>
|
||
<div id=hash_p class="card pane" style=display:none><b>Hasher</b><br>
|
||
<input id=hq2 placeholder="any string" style=width:70%><button onclick=genhash2()>Hash</button>
|
||
<table><tr><th>md5</th><td id=h_md5></td></tr><tr><th>sha1</th><td id=h_sha1></td></tr>
|
||
<tr><th>sha256</th><td id=h_sha256></td></tr><tr><th>sha512</th><td id=h_sha512></td></tr></table></div>
|
||
<div id=gen_p class="card pane" style=display:none><b>Generators</b><br>
|
||
<button onclick=uuids()>5× UUIDv4</button><pre id=uo></pre>
|
||
<label>password length</label> <input id=pl value=24 style=width:80px><button onclick=pwgen()>Generate</button>
|
||
<pre id=po style="font-size:1.2rem;color:var(--acc)"></pre></div>"""
|
||
return page("tools", body)
|
||
|
||
# ---------- 9. OPERATOR CONSOLE ----------
|
||
@app.route("/admin", methods=["GET", "POST"])
|
||
def admin():
|
||
if request.method == "POST" and request.form.get("pw") == ADMIN_PW:
|
||
resp = Response(status=302); resp.headers["Location"] = "/admin"
|
||
resp.set_cookie("dark0rbits_admin", secrets.token_urlsafe(16), max_age=86400, httponly=True)
|
||
return resp
|
||
if not request.cookies.get("dark0rbits_admin"):
|
||
return page("ip", '<h1>OPERATOR</h1><div class=card><form method=post><input name=pw type=password placeholder="operator password"><button>In</button></form></div>')
|
||
con = db()
|
||
msgs = con.execute("SELECT m.*, u.username FROM messages m JOIN users u ON u.id=m.user_id ORDER BY m.id DESC LIMIT 100").fetchall()
|
||
msgs_html = "".join(f'<div class=msg><div class=who>{esc(m["username"])} · {time.strftime("%b %d %H:%M", time.localtime(m["created"]))}</div>{m["body"]}</div>' for m in msgs) or '<div style=color:var(--dim)>empty</div>'
|
||
opens = con.execute("SELECT te.*, tr.filename FROM track_events te JOIN trackables tr ON tr.id=te.trackable_id ORDER BY te.id DESC LIMIT 30").fetchall()
|
||
opens_html = "".join(f"<tr><td>{esc(o['filename'])}</td><td>{esc(o['ip'])}</td><td>{esc(o['ua'][:50])}</td><td>{time.strftime('%b %d %H:%M', time.localtime(o['ts']))}</td></tr>" for o in opens)
|
||
return page("track", f"""
|
||
<h1>OPERATOR <span>CONSOLE</span></h1>
|
||
<div class=card><b>All customer messages</b>{msgs_html}</div>
|
||
<div class=card><b>File open events</b><table><tr><th>File</th><th>IP</th><th>Device</th><th>When</th></tr>{opens_html}</table></div>""")
|
||
|
||
# ---------- INDEX (hacker landing) ----------
|
||
@app.route("/")
|
||
def index():
|
||
ip = request.headers.get("X-Real-IP") or request.remote_addr
|
||
st, b = http(f"http://ip-api.com/json/{ip}?fields=66846719")
|
||
d = jf(b) or {}
|
||
uid = current_user_id()
|
||
con = db()
|
||
n_sms = con.execute("SELECT COUNT(*) c FROM sms_rentals").fetchone()["c"]
|
||
n_px = con.execute("SELECT COUNT(*) c FROM proxy_checks").fetchone()["c"]
|
||
tools = [
|
||
("ip","IP INTEL","Geo, ASN, ISP, VPN/hosting flags, rDNS — your IP auto-detected, any target on demand."),
|
||
("card","CARD CHECK","Luhn + BIN: issuer bank, brand, type, country, prepaid risk flags. Nothing stored, nothing charged."),
|
||
("sms","SMS RENTAL","Disposable numbers, 30-min windows, instant refund on cancel."),
|
||
("proxy","PROXY LAB","Residential egress testing on the Pleiades rail — same gateway keys fleet-wide. Rent GB plans at the storefront."),
|
||
("steg","STEGO LAB","Hide words inside pictures. LSB depth, randomized spread, password-encrypted payloads."),
|
||
("track","TRACK FILE","$1 → tracked link + email pixel. Every open reports back: IP, location, ISP, device."),
|
||
("mail","BURNER MAIL","Receive-only mailboxes, 7–90 days, live countdown. Codes & confirmations without an identity."),
|
||
("eh","MAIL FORENSICS","Paste raw headers → real origin IP + geo, SPF/DKIM/DMARC verdicts, spoof flags."),
|
||
("forensics","IMAGE FORENSICS","EXIF, GPS, edit-tool detection, error-level analysis — expose doctored photos."),
|
||
("canary","CANARY TRAPS","Tripwire links and pixels — instant alert the moment anyone touches one."),
|
||
("tools","FREE TOOLS","DNS resolver, HTTP header inspector, JWT decoder, hasher, generators."),
|
||
("passport","AGENT PASSPORT","Machine-readable trust badge for your bots. Agents are first-class here."),
|
||
]
|
||
cards = "".join(f'<div class=card><h3><a href=/{href} style="color:var(--acc);text-decoration:none">◈ {name}</a></h3><p style=color:var(--dim)>{desc}</p><a href=/{href}><button>Open</button></a></div>' for href, name, desc in tools)
|
||
stat = f"You're connecting from <b style=color:var(--acc)>{esc(d.get('query','?'))}</b> — {esc(d.get('city',''))}, {esc(d.get('country',''))} · {esc(d.get('isp',''))}"
|
||
cta = ('<a href=/inbox><button class=big>◈ INBOX</button></a> <a href=/keys><button class="big ghost">▣ API KEYS</button></a> <a href=/pass><button class=big>★ GET PASS</button></a>' if uid else '<a href=/inbox><button class=big>▸ SIGN UP — NO KYC</button></a> <a href=/inbox><button class="big ghost">◈ LOG IN</button></a> <a href=/pass><button class="big ghost">★ GET PASS</button></a>')
|
||
body = f"""
|
||
<div class="term card glow">$ ./dark0rbits --intro<span class="crt">▊</span>
|
||
DARK0RBITS — the toolbox that treats you like an operator, not a product.
|
||
No KYC. No email required. No Stripe. BTC only. Agents welcome.
|
||
{stat}
|
||
<div class="cta">{cta}</div></div>
|
||
<div class=grid2>{cards}</div>
|
||
<div class=card style=text-align:center>
|
||
<span class="tag ok">NO KYC</span> <span class="tag ok">BTC ONLY</span> <span class="tag ok">AGENT-FIRST APIs</span> <span class="tag warn">{n_sms} SMS RENTALS SERVED</span> <span class="tag warn">{n_px} PROXY CHECKS</span></div>
|
||
<div class=card style=color:var(--dim)>
|
||
<b>For agents</b>: machine catalog at <a href=/llms.txt>/llms.txt</a>, OpenAPI at <a href=/openapi.json>/openapi.json</a>, metered keys at <a href=/keys>/keys</a>.
|
||
For humans: click a card. That's it.</div>"""
|
||
return page("home", body)
|
||
|
||
@app.route("/health")
|
||
def health(): return jsonify({"ok": True, "service": "dark0rbits", "version": "2.0"})
|
||
|
||
|
||
# REDIRECT legacy auriga hostname → dark0rbits
|
||
@app.before_request
|
||
def _dr_legacy_redirect():
|
||
host = (request.host or "").lower()
|
||
if host.startswith("auriga.") or host == "auriga.thetempleofdoom.com":
|
||
return redirect("https://dark0rbits.thetempleofdoom.com" + request.full_path.rstrip("?"), code=301)
|
||
return None
|
||
# REDACT-REDIRECT
|
||
|
||
if __name__ == "__main__":
|
||
app.run(host="0.0.0.0", port=5000, threaded=True)
|