LYNX — no-KYC inspection/steg/forensics/recon API (initial release)
This commit is contained in:
70
README.md
Normal file
70
README.md
Normal file
@@ -0,0 +1,70 @@
|
||||
# LYNX — the sharp-eyed inspector 🔭
|
||||
|
||||
No-KYC, Bitcoin-paid API for **file inspection, steganography, forensics, and recon**.
|
||||
Public: https://lynx.thetempleofdoom.com
|
||||
|
||||
## What it does
|
||||
|
||||
| Class | Tools | Credits |
|
||||
|---|---|---|
|
||||
| 🔬 File inspection | md5/sha1/sha256/ssdeep, entropy, strings, exiftool, PE, OLE macros, PDF, binwalk | 1 |
|
||||
| 🕵️ Steganography | steghide extract, stegcracker, zsteg LSB | 2–4 |
|
||||
| 🧬 Forensics | Sleuth Kit (mmls/fls/fsstat/tsk_recover), volatility3 | 3 |
|
||||
| 📡 Recon | nmap, subfinder, nuclei, theHarvester, dnsrecon (isolated Kali egress) | 2–4 |
|
||||
|
||||
## Quick start
|
||||
|
||||
```bash
|
||||
# 1. no-KYC key
|
||||
curl -X POST https://lynx.thetempleofdoom.com/api/signup -H 'Content-Type: application/json' -d '{"email":"you@proton.me"}'
|
||||
|
||||
# 2. buy credits (bitcoin)
|
||||
curl -X POST https://lynx.thetempleofdoom.com/api/order -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"usd":5}'
|
||||
|
||||
# 3. inspect a file
|
||||
curl -X POST https://lynx.thetempleofdoom.com/api/inspect/file -H 'X-API-Key: sk-lynx-…' -F 'file=@suspicious.pdf'
|
||||
|
||||
# 4. decode hidden data
|
||||
curl -X POST https://lynx.thetempleofdoom.com/api/steg/extract -H 'X-API-Key: sk-lynx-…' -F 'file=@hidden.png' -F 'passphrase=secret'
|
||||
|
||||
# 5. recon an external target
|
||||
curl -X POST https://lynx.thetempleofdoom.com/api/recon/nmap -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"target":"example.com"}'
|
||||
```
|
||||
|
||||
## Architecture
|
||||
|
||||
- **Host:** CT707 (Debian 12), Flask + gunicorn `:5059`
|
||||
- **File/steg/forensics:** run locally on CT707 (fast, no binary-transfer issues)
|
||||
- **Recon:** dispatched to Kali (`10.30.30.177`, isolated vmbr1 segment) — egress never touches the production network
|
||||
- **Billing:** BTCPay store + webhook, SQLite credits, no subscriptions, credits never expire
|
||||
- **Agent-native:** `/mcp` JSON-RPC 2.0 endpoint — 6 tools (`lynx_signup`, `lynx_me`, `lynx_order`, `lynx_inspect_file`, `lynx_steg_extract`, `lynx_recon`)
|
||||
|
||||
## API surface
|
||||
|
||||
REST: `/api/signup`, `/api/order`, `/api/order/<id>`, `/webhook/btcpay`, `/api/me`, `/api/pricing`,
|
||||
`/api/inspect/file`, `/api/steg/extract`, `/api/steg/crack`, `/api/forensics/disk`, `/api/recon/<tool>`,
|
||||
`/stats`, `/admin`, `/docs`, `/openapi.json`.
|
||||
MCP: `/mcp` (JSON-RPC 2.0).
|
||||
|
||||
Auth: `X-API-Key` header or `?api_key=` query. 0 credits → 402. Rate-limited per key/IP.
|
||||
|
||||
## Pricing (USD → credits)
|
||||
|
||||
$2=20 · $5=60 · $10=150 · $20=400
|
||||
|
||||
## Deploy
|
||||
|
||||
```bash
|
||||
# from the repo root
|
||||
tar czf /tmp/lynx.tar.gz app.py lynx.service
|
||||
scp /tmp/lynx.tar.gz root@10.30.20.85:/tmp/
|
||||
ssh root@10.30.20.85 'pct push 707 /tmp/lynx.tar.gz /tmp/ && \
|
||||
pct exec 707 -- bash -c "cd /opt/lynx && tar xzf /tmp/lynx.tar.gz && \
|
||||
cp lynx.service /etc/systemd/system/ && systemctl daemon-reload && systemctl restart lynx"'
|
||||
```
|
||||
|
||||
## Notes
|
||||
|
||||
- Kali's `write_file` API is text-only (corrupts binaries) — that's why file tools run on CT707.
|
||||
- Recon targets are sanitized (`[A-Za-z0-9.\-_:/]+`) and tool args are server-constructed (no shell injection).
|
||||
- Cloudflare `enable_js` JS-challenge blocks bare `Python-urllib` UAs; curl/requests/MCP SDKs pass fine.
|
||||
Reference in New Issue
Block a user