Files
lynx/README.md

71 lines
3.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# LYNX — the sharp-eyed inspector 🔭
No-KYC, Bitcoin-paid API for **file inspection, steganography, forensics, and recon**.
Public: https://lynx.thetempleofdoom.com
## What it does
| Class | Tools | Credits |
|---|---|---|
| 🔬 File inspection | md5/sha1/sha256/ssdeep, entropy, strings, exiftool, PE, OLE macros, PDF, binwalk | 1 |
| 🕵️ Steganography | steghide extract, stegcracker, zsteg LSB | 2–4 |
| 🧬 Forensics | Sleuth Kit (mmls/fls/fsstat/tsk_recover), volatility3 | 3 |
| 📡 Recon | nmap, subfinder, nuclei, theHarvester, dnsrecon (isolated Kali egress) | 2–4 |
## Quick start
```bash
# 1. no-KYC key
curl -X POST https://lynx.thetempleofdoom.com/api/signup -H 'Content-Type: application/json' -d '{"email":"you@proton.me"}'
# 2. buy credits (bitcoin)
curl -X POST https://lynx.thetempleofdoom.com/api/order -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"usd":5}'
# 3. inspect a file
curl -X POST https://lynx.thetempleofdoom.com/api/inspect/file -H 'X-API-Key: sk-lynx-…' -F 'file=@suspicious.pdf'
# 4. decode hidden data
curl -X POST https://lynx.thetempleofdoom.com/api/steg/extract -H 'X-API-Key: sk-lynx-…' -F 'file=@hidden.png' -F 'passphrase=secret'
# 5. recon an external target
curl -X POST https://lynx.thetempleofdoom.com/api/recon/nmap -H 'X-API-Key: sk-lynx-…' -H 'Content-Type: application/json' -d '{"target":"example.com"}'
```
## Architecture
- **Host:** CT707 (Debian 12), Flask + gunicorn `:5059`
- **File/steg/forensics:** run locally on CT707 (fast, no binary-transfer issues)
- **Recon:** dispatched to Kali (`10.30.30.177`, isolated vmbr1 segment) — egress never touches the production network
- **Billing:** BTCPay store + webhook, SQLite credits, no subscriptions, credits never expire
- **Agent-native:** `/mcp` JSON-RPC 2.0 endpoint — 6 tools (`lynx_signup`, `lynx_me`, `lynx_order`, `lynx_inspect_file`, `lynx_steg_extract`, `lynx_recon`)
## API surface
REST: `/api/signup`, `/api/order`, `/api/order/<id>`, `/webhook/btcpay`, `/api/me`, `/api/pricing`,
`/api/inspect/file`, `/api/steg/extract`, `/api/steg/crack`, `/api/forensics/disk`, `/api/recon/<tool>`,
`/stats`, `/admin`, `/docs`, `/openapi.json`.
MCP: `/mcp` (JSON-RPC 2.0).
Auth: `X-API-Key` header or `?api_key=` query. 0 credits → 402. Rate-limited per key/IP.
## Pricing (USD → credits)
$2=20 · $5=60 · $10=150 · $20=400
## Deploy
```bash
# from the repo root
tar czf /tmp/lynx.tar.gz app.py lynx.service
scp /tmp/lynx.tar.gz root@10.30.20.85:/tmp/
ssh root@10.30.20.85 'pct push 707 /tmp/lynx.tar.gz /tmp/ && \
pct exec 707 -- bash -c "cd /opt/lynx && tar xzf /tmp/lynx.tar.gz && \
cp lynx.service /etc/systemd/system/ && systemctl daemon-reload && systemctl restart lynx"'
```
## Notes
- Kali's `write_file` API is text-only (corrupts binaries) — that's why file tools run on CT707.
- Recon targets are sanitized (`[A-Za-z0-9.\-_:/]+`) and tool args are server-constructed (no shell injection).
- Cloudflare `enable_js` JS-challenge blocks bare `Python-urllib` UAs; curl/requests/MCP SDKs pass fine.