LYNX — the sharp-eyed inspector 🔭

No-KYC, Bitcoin-paid API for file inspection, steganography, forensics, and recon. Public: https://lynx.thetempleofdoom.com

What it does

Class Tools Credits
🔬 File inspection md5/sha1/sha256/ssdeep, entropy, strings, exiftool, PE, OLE macros, PDF, binwalk 1
🕵️ Steganography steghide extract, stegcracker, zsteg LSB 2–4
🧬 Forensics Sleuth Kit (mmls/fls/fsstat/tsk_recover), volatility3 3
📡 Recon nmap, subfinder, nuclei, theHarvester, dnsrecon (isolated Kali egress) 2–4

Quick start

# 1. no-KYC key
curl -X POST https://lynx.thetempleofdoom.com/api/signup -H 'Content-Type: application/json' -d '{"email":"you@proton.me"}'

# 2. buy credits (bitcoin)
curl -X POST https://lynx.thetempleofdoom.com/api/order -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"usd":5}'

# 3. inspect a file
curl -X POST https://lynx.thetempleofdoom.com/api/inspect/file -H 'X-API-Key: sk-lynx-…' -F 'file=@suspicious.pdf'

# 4. decode hidden data
curl -X POST https://lynx.thetempleofdoom.com/api/steg/extract -H 'X-API-Key: sk-lynx-…' -F 'file=@hidden.png' -F 'passphrase=secret'

# 5. recon an external target
curl -X POST https://lynx.thetempleofdoom.com/api/recon/nmap -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"target":"example.com"}'

Architecture

  • Host: CT707 (Debian 12), Flask + gunicorn :5059
  • File/steg/forensics: run locally on CT707 (fast, no binary-transfer issues)
  • Recon: dispatched to Kali (10.30.30.177, isolated vmbr1 segment) — egress never touches the production network
  • Billing: BTCPay store + webhook, SQLite credits, no subscriptions, credits never expire
  • Agent-native: /mcp JSON-RPC 2.0 endpoint — 6 tools (lynx_signup, lynx_me, lynx_order, lynx_inspect_file, lynx_steg_extract, lynx_recon)

API surface

REST: /api/signup, /api/order, /api/order/<id>, /webhook/btcpay, /api/me, /api/pricing, /api/inspect/file, /api/steg/extract, /api/steg/crack, /api/forensics/disk, /api/recon/<tool>, /stats, /admin, /docs, /openapi.json. MCP: /mcp (JSON-RPC 2.0).

Auth: X-API-Key header or ?api_key= query. 0 credits → 402. Rate-limited per key/IP.

Pricing (USD → credits)

$2=20 · $5=60 · $10=150 · $20=400

Deploy

# from the repo root
tar czf /tmp/lynx.tar.gz app.py lynx.service
scp /tmp/lynx.tar.gz root@10.30.20.85:/tmp/
ssh root@10.30.20.85 'pct push 707 /tmp/lynx.tar.gz /tmp/ && \
  pct exec 707 -- bash -c "cd /opt/lynx && tar xzf /tmp/lynx.tar.gz && \
  cp lynx.service /etc/systemd/system/ && systemctl daemon-reload && systemctl restart lynx"'

Notes

  • Kali's write_file API is text-only (corrupts binaries) — that's why file tools run on CT707.
  • Recon targets are sanitized ([A-Za-z0-9.\-_:/]+) and tool args are server-constructed (no shell injection).
  • Cloudflare enable_js JS-challenge blocks bare Python-urllib UAs; curl/requests/MCP SDKs pass fine.
Description
LYNX — no-KYC Bitcoin-paid inspection/steganography/forensics/recon API
Readme 44 KiB
Languages
Python 100%