𝘼𝙗𝙝𝙞𝙜𝙮𝙖𝙣 𝙏𝙤𝙤𝙡𝙨 𝙇𝙖𝙗
Закрытый канал
Personal research tools • APIs • bots Updates • demos • limited access drops Not for illegal use
БольшеСтрана не указанаКатегория не указана
1 049
Подписчики
+7924 часа
+2557 дней
+72230 дней
Архив постов
1 049
Repost from N/a
"""
Email Info API - Flask
GET /email?email=user@example.com
Returns info about an email address using free services & Python modules:
- Syntax validation (email-validator)
- MX record lookup (dnspython)
- SMTP reachability check (smtplib)
- Disposable email detection (disposable-email-domains list)
- Domain WHOIS info (python-whois)
- Gravatar avatar hash (hashlib)
- Email breach check via HaveIBeenPwned public API (requests)
Install dependencies:
pip install flask email-validator dnspython python-whois requests
"""
import hashlib
import smtplib
import socket
import re
import dns.resolver
import whois
import requests
from flask import Flask, jsonify, request
from email_validator import validate_email, EmailNotValidError
app = Flask(name)
# ── Disposable domain list (fetched once from a free public source) ──────────
DISPOSABLE_DOMAINS: set[str] = set()
def load_disposable_domains():
url = (
"https://raw.githubusercontent.com/disposable-email-domains/"
"disposable-email-domains/master/disposable_email_blocklist.conf"
)
try:
resp = requests.get(url, timeout=10)
if resp.ok:
DISPOSABLE_DOMAINS.update(
line.strip().lower()
for line in resp.text.splitlines()
if line.strip() and not line.startswith("#")
)
except Exception:
pass # fail silently; disposable check will just return unknown
load_disposable_domains()
# ── Helpers ──────────────────────────────────────────────────────────────────
def check_syntax(email: str) -> dict:
"""Validate email syntax and normalise it."""
try:
info = validate_email(email, check_deliverability=False)
return {
"valid": True,
"normalized": info.normalized,
"local_part": info.local_part,
"domain": info.domain,
}
except EmailNotValidError as e:
return {"valid": False, "error": str(e)}
def get_mx_records(domain: str) -> dict:
"""Look up MX records for the domain."""
try:
answers = dns.resolver.resolve(domain, "MX")
records = sorted(
[{"priority": r.preference, "host": str(r.exchange).rstrip(".")} for r in answers],
key=lambda x: x["priority"],
)
return {"found": True, "records": records}
except (dns.resolver.NXDOMAIN, dns.resolver.NoAnswer, dns.exception.DNSException) as e:
return {"found": False, "error": str(e)}
def check_smtp(email: str, mx_host: str) -> dict:
"""Try to verify the mailbox exists via SMTP RCPT TO (no mail sent)."""
try:
with smtplib.SMTP(timeout=10) as smtp:
smtp.connect(mx_host, 25)
smtp.helo("check.example.com")
smtp.mail("check@example.com")
code, msg = smtp.rcpt(email)
return {
"reachable": code == 250,
"smtp_code": code,
"smtp_message": msg.decode(errors="replace"),
}
except smtplib.SMTPConnectError as e:
return {"reachable": None, "error": f"SMTP connect failed: {e}"}
except smtplib.SMTPServerDisconnected as e:
return {"reachable": None, "error": f"Server disconnected: {e}"}
except (socket.timeout, OSError) as e:
return {"reachable": None, "error": f"Network error: {e}"}
except Exception as e:
return {"reachable": None, "error": str(e)}
def check_disposable(domain: str) -> dict:
"""Check if domain is a known disposable / temporary email provider."""
is_disposable = domain.lower() in DISPOSABLE_DOMAINS
return {
"is_disposable": is_disposable,
"database_loaded": len(DISPOSABLE_DOMAINS) > 0,
}
def get_whois_info(domain: str) -> dict:
"""Fetch WHOIS data for the domain (free, no key required)."""
try:
w = whois.whois(domain)
def _first(val):
return val[0] if isinstance(val, list) else val
1 049
🔥 REAL TEMP MAIL BOT
Asli temporary email milta hai.
OTP / verification ke liye use karo.
Steps:
1. Bot start
2. Channels join + Verify
3. Generate Email
4. Check Inbox
No fake • No referral • Free
@GET_FREE_TEMP_MAIL_BOT
@GET_FREE_TEMP_MAIL_BOT
@GET_FREE_TEMP_MAIL_BOT
@GET_FREE_TEMP_MAIL_BOT
1 049
🔥 FREE VIRTUAL NUMBER BOT
Temporary numbers from India, USA, UK, UAE & more.
Kaise use kare:
1. Bot start karo
2. Channels join + Verify
3. Country select karo
4. 5 friends refer karke OTP unlock lo
Bot 👉 @GetFreeVirtualNumber_Bot
1 049
🚨 FREE VPS BOT LIVE
Ab free VPS claim kar sakte ho.
✅ Features:
• Free VPS allocation
• Force join system
• 5 referral = full unlock
• Clean professional interface
Steps:
1. @Indian_Free_VPS_bot pe jao
2. /start dabao
3. Channels join + Verify
4. Referral link share karke unlock karo
Link 👉 @Indian_Free_VPS_bot
1 049
🚨 NEW TOOL DROPPED
Instagram se Phone Number nikaalne wala bot aa gaya.
🔥 Features:
• Instagram → Number lookup
• Force join system
• Referral based unlock
• 5 referrals = Unlimited searches
Kaise start kare:
1. @INSTA_TO_PHONE_OSINT_BOT pe jao
2. /start dabao
3. Saare channels join karo
4. Verify karo
5. Referral link share karke unlock lo
Link 👉 @INSTA_TO_PHONE_OSINT_BOT
1 049
NEW SERVICE ADDED
1. Aadhaar To All Data Info ₹30
2. Aadhaar to Name ₹5
3. Aadhaar to Father Name ₹5
4. Aadhaar to Address ₹15
5. Aadhaar To Mobile ₹15
6. Aadhaar To Ration Card ₹20
7. Aadhaar PAN Link Check ₹5
8. Aadhaar to NPCI Bank Link Check ₹15
9. Aadhaar To Pan Find ₹30
10. PAN To Name & DOB Info ₹15
11. PAN To GST ₹10
12. PAN to Aadhaar ₹70
13. Vehicle To Mobile Number ₹25
14. Vehicle Info Server 1 ₹10
15. Vehicle RC Info 2 ₹15
16. Driving License Info ₹15
17. DL 2 Number ₹30
18. Passport Info ₹20
19. Vehicle to Challan ₹10
20. Vehicle Rc Pdf ₹30
21. DL to PDF ₹30
22. Agriculture to Detail ₹25
23. Agriculture to PDF V2 ₹15
24. Bank IFSC Details ₹5
25. GST Advance 2.0 ₹10
26. Mobile Number Info ₹20
27. Email Info / Leaks ₹50
28. Telegram To Number ₹15
29. Pincode Details ₹5
30. Post Office Info ₹5
31. Aadhaar To PDF ₹100
32. Aadhaar to Ration PDF ₹30
33. PAN To Name & DOB ₹15
34. PAN To GST Lookup ₹10
35. Mobile to PAN ₹30
36. Mobile To Vehicle Number ₹100
37. LL to PDF ₹25
38. Chassis 2 Vehicle Number ₹100
39. Engine 2 Vehicle Number ₹100
40. Vehicle to Challan V2 ₹30
41. Agriculture to PDF V4 ₹20
42. Agriculture to PDF V5 ₹25
43. Agriculture to Status ₹15
44. Voter to Detail ₹15
45. Voter Mobile Link OTP Send ₹20
46. Voter Mobile Link No OTP Instant ₹30
47. Ayushman to PNG ₹50
48. Ration to Aadhaar All State ₹250
49. Ration to PDF ₹50
Note this is real price according to main panel but I will give you very high discountMessage here @ykguycyber
1 049
Ye bahut usefull hai 75% kaam yahi karega keys find krne ke liye
Ration info
Lpg info all
Eshram
Uidai
Sab isi se Banega
1 049
inline_content = "\n".join(s.string for s in BeautifulSoup(html, 'html.parser').find_all('script') if s.string)
if inline_content:
findings = analyze_content(inline_content, "INLINE_SCRIPTS")
per_file["INLINE_SCRIPTS"] = findings
for k, v in findings.items():
all_findings.setdefault(k, set()).update(v)
# Analyze each downloaded file
for filepath, content, url in downloaded_files:
filename = os.path.basename(filepath)
print(f"{C.W}Analyzing: {filename}...{C.END}")
findings = analyze_content(content, filename)
per_file[filename] = findings
# Merge into global
for k, v in findings.items():
all_findings.setdefault(k, set()).update(v)
# Print file summary
if findings:
total = sum(len(v) for v in findings.values())
print(f" {C.G}✓ {total} findings{C.END}")
# Convert sets to sorted lists
all_findings = {k: sorted(v) for k, v in all_findings.items()}
# ========== STEP 5: PRINT FULL REPORT ==========
print_report(all_findings, js_urls, output_dir, target_url)
# ========== STEP 6: SAVE REPORT ==========
print_section("💾 STEP 6: Saving Report")
report_path = save_report(all_findings, js_urls, output_dir, target_url)
print(f"{C.G}[+] Report saved: {report_path}{C.END}")
print(f"{C.G}[+] JS files saved: {output_dir}/{C.END}")
# ========== STEP 7: EXTRACT FUNCTION CODE ==========
print_section("⚙️ STEP 7: Crypto Functions Code")
crypto_keywords = ['encrypt', 'decrypt', 'cipher', 'hash', 'sign']
function_count = 0
for filepath, content, url in downloaded_files:
# Find crypto functions
func_pattern = r'function\s+(\w*(?:' + '|'.join(crypto_keywords) + r')\w*)\s*\([^)]*\)\s*\{'
for m in re.finditer(func_pattern, content, re.IGNORECASE):
func_name = m.group(1)
code = extract_function_code(content, func_name)
if code and function_count < 10:
print(f"\n{C.Y}📄 File: {os.path.basename(filepath)}{C.END}")
print(f"{C.CY}Function: {func_name}{C.END}")
print(f"{C.W}{code[:800]}{C.END}")
if len(code) > 800:
print(f"{C.Y}... (truncated){C.END}")
function_count += 1
if function_count == 0:
print(f"{C.Y}[!] No crypto functions found{C.END}")
# ========== FINAL ==========
print_section("✅ ANALYSIS COMPLETE", C.G)
print(f"""
{C.G}✓ Total JS files: {len(js_urls)}
{C.G}✓ Downloaded: {len(downloaded_files)}
{C.G}✓ Report: {report_path}
{C.G}✓ JS folder: {output_dir}/{C.END}
""")
# Summary of what was found
print(f"{C.Y}{C.BOLD}📊 QUICK SUMMARY:{C.END}")
for category in ["AES_KEY", "SECRET_KEY", "API_KEY", "PUBLIC_KEY",
"API_ENDPOINTS", "CRYPTO_FUNCTIONS", "SALT"]:
if category in all_findings:
count = len(all_findings[category])
print(f" {C.G}• {category}: {count} found{C.END}")
if name == "main":
try:
import urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
except:
pass
try:
main()
except KeyboardInterrupt:
print(f"\n{C.Y}[!] Interrupted by user{C.END}")
except Exception as e:
print(f"\n{C.R}[!] Error: {e}{C.END}")
import traceback
traceback.print_exc()
`1 049
def save_report(all_findings, js_files, output_dir, target_url):
"""Save detailed report to file"""
report_path = os.path.join(output_dir, "_ANALYSIS_REPORT.txt")
with open(report_path, 'w', encoding='utf-8') as f:
f.write("="*70 + "\n")
f.write(" UNIVERSAL JS ANALYZER - FULL REPORT\n")
f.write("="*70 + "\n\n")
f.write(f"Target URL: {target_url}\n")
f.write(f"Analysis Time: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')}\n")
f.write(f"JS Files Analyzed: {len(js_files)}\n\n")
f.write("="*70 + "\n")
f.write(" ALL FINDINGS\n")
f.write("="*70 + "\n\n")
for category, values in all_findings.items():
if category == "_global":
continue
if values:
f.write(f"\n[{category}] ({len(values)} found)\n")
f.write("-"*70 + "\n")
for v in values:
f.write(f" • {v}\n")
f.write("\n\n" + "="*70 + "\n")
f.write(" JS FILES LIST\n")
f.write("="*70 + "\n\n")
for url in js_files:
f.write(f" {url}\n")
return report_path
# ==================== MAIN ====================
def main():
print_banner()
# ========== GET URL ==========
target_url = input(f"\n{C.Y}🌐 Enter website URL: {C.END}").strip()
if not target_url:
print(f"{C.R}[!] URL required!{C.END}")
return
target_url = normalize_url(target_url)
# Create output directory
domain = urlparse(target_url).netloc.replace(':', '_')
output_dir = f"js_analysis_{domain}_{datetime.now().strftime('%Y%m%d_%H%M%S')}"
os.makedirs(output_dir, exist_ok=True)
print(f"\n{C.G}[+] Target: {target_url}{C.END}")
print(f"{C.G}[+] Output: {output_dir}/{C.END}")
# ========== STEP 1: FETCH PAGE ==========
print_section("📥 STEP 1: Fetching Main Page")
html = get_page(target_url)
if not html:
print(f"{C.R}[!] Failed to fetch page{C.END}")
return
print(f"{C.G}[+] Page fetched: {len(html)} bytes{C.END}")
# ========== STEP 2: EXTRACT JS URLS ==========
print_section("🔗 STEP 2: Extracting JS URLs")
js_urls = extract_js_urls(html, target_url)
print(f"{C.G}[+] Found {len(js_urls)} JS files{C.END}")
if not js_urls:
print(f"{C.Y}[!] No JS files found. Website might use inline JS.{C.END}")
# Still analyze inline scripts
soup = BeautifulSoup(html, 'html.parser')
inline = "\n".join(s.string for s in soup.find_all('script') if s.string)
if inline:
print(f"{C.G}[+] Analyzing {len(inline)} bytes of inline JS{C.END}")
# Limit
js_urls = js_urls[:MAX_FILES]
for i, url in enumerate(js_urls[:20], 1):
print(f" {C.W}{i}. {url}{C.END}")
if len(js_urls) > 20:
print(f" {C.Y}... and {len(js_urls)-20} more{C.END}")
# ========== STEP 3: DOWNLOAD JS ==========
print_section("⬇️ STEP 3: Downloading JS Files")
downloaded_files = []
for i, js_url in enumerate(js_urls, 1):
print(f"{C.W}[{i}/{len(js_urls)}] {os.path.basename(js_url)[:60]}{C.END}")
filepath, content = download_js(js_url, output_dir)
if filepath and content:
downloaded_files.append((filepath, content, js_url))
print(f" {C.G}✓ {len(content)} bytes{C.END}")
print(f"\n{C.G}[+] Downloaded {len(downloaded_files)} files{C.END}")
# ========== STEP 4: ANALYZE ==========
print_section("🔍 STEP 4: Analyzing for Keys & Secrets")
all_findings = {} # Global findings (combined)
per_file = {} # Per-file findings
# Analyze inline scripts first
if js_urls == []:
1 049
else:
val = m
# Clean value
val = val.strip()
if 3 < len(val) < 5000:
matches.add(val)
except re.error:
continue
if matches:
findings[category] = sorted(matches)
return findings
def extract_function_code(content, func_name):
"""Extract function body"""
# Different patterns
patterns = [
rf'function\s+{re.escape(func_name)}\s*\([^)]*\)\s*\{{([\s\S]{{0,2000}}?)\n\}}',
rf'{re.escape(func_name)}\s*[:=]\s*(?:async\s*)?(?:function\s*)?\([^)]*\)\s*(?:=>)?\s*\{{([\s\S]{{0,2000}}?)\n\}}',
]
for pattern in patterns:
m = re.search(pattern, content)
if m:
return m.group(0)[:1500]
return None
# ==================== REPORT ====================
def print_report(all_findings, js_files, output_dir, target_url):
"""Print full report"""
print_section("📊 FINAL REPORT", C.M)
print(f"\n{C.W}Target: {C.Y}{target_url}{C.END}")
print(f"{C.W}JS Files: {C.Y}{len(js_files)}{C.END}")
print(f"{C.W}Saved to: {C.Y}{output_dir}/{C.END}")
print(f"{C.W}Time: {C.Y}{datetime.now().strftime('%Y-%m-%d %H:%M:%S')}{C.END}")
# ========== GROUP BY CATEGORY ==========
categories = {
"🔐 ENCRYPTION KEYS": [
"AES_KEY", "AES_IV", "SECRET_KEY", "SECRET_CODE",
"ENCRYPTION_KEY", "HMAC_KEY", "SALT"
],
"🔑 API KEYS & TOKENS": [
"API_KEY", "ACCESS_TOKEN", "BEARER_TOKEN", "JWT_SECRET"
],
"🔏 RSA KEYS": [
"PUBLIC_KEY", "PRIVATE_KEY", "BASIC_AUTH"
],
"🌐 API ENDPOINTS": [
"API_ENDPOINTS", "FULL_URLS", "WEBSOCKET_URLS"
],
"⚙️ CRYPTO FUNCTIONS": [
"CRYPTO_FUNCTIONS", "CRYPTOJS_USAGE", "AES_USAGE",
"RSA_USAGE", "PBKDF2_USAGE", "BASE64_USAGE"
],
"👤 CREDENTIALS": [
"USERNAME", "PASSWORD"
],
"🔍 THIRD-PARTY KEYS": [
"GITHUB_TOKENS", "GOOGLE_API_KEY", "FIREBASE_URL",
"AWS_KEY", "STRIPE_KEY", "TWILIO_KEY", "SENDGRID_KEY", "SLACK_TOKEN"
],
"📞 OTHER": [
"EMAIL", "PHONE", "IP_ADDRESS", "AADHAAR_LIKE"
],
}
for group_name, group_keys in categories.items():
group_has_data = False
for key in group_keys:
if key in all_findings and all_findings[key]:
if not group_has_data:
print_section(group_name, C.CY)
group_has_data = True
values = all_findings[key]
print(f"\n{C.Y}{C.BOLD}[{key}]{C.END} ({len(values)} found)")
for i, val in enumerate(values[:15]): # Max 15 per category
# Truncate long values
display = val if len(val) <= 150 else val[:150] + "..."
# Color based on type
if 'KEY' in key or 'SECRET' in key or 'TOKEN' in key:
color = C.R
elif 'URL' in key or 'ENDPOINT' in key:
color = C.B
else:
color = C.G
print(f" {color}→ {display}{C.END}")
if len(values) > 15:
print(f" {C.Y}... and {len(values)-15} more{C.END}")
# ========== FILE-WISE BREAKDOWN ==========
print_section("📁 PER-FILE BREAKDOWN", C.CY)
for fname, findings in all_findings.items():
if fname == "_global":
continue
total = sum(len(v) for v in findings.values())
if total > 0:
print(f"\n{C.W}📄 {fname}{C.END}")
for key, vals in findings.items():
if vals:
print(f" {C.G}• {key}: {len(vals)} found{C.END}")
1 049
def decode_base64_safely(s):
"""Safely decode base64"""
try:
if len(s) % 4:
s += '=' * (4 - len(s) % 4)
decoded = base64.b64decode(s)
return decoded.decode('utf-8', errors='ignore')
except:
return None
def is_js_url(url):
"""Check if URL is a JS file"""
parsed = urlparse(url)
path = parsed.path.lower()
return path.endswith('.js') or path.endswith('.mjs') or 'javascript' in path
def normalize_url(url):
"""Add https:// if missing"""
if not url.startswith(('http://', 'https://')):
url = 'https://' + url
return url
# ==================== FETCH & EXTRACT ====================
def get_page(url):
"""Fetch main page"""
try:
r = requests.get(url, headers=HEADERS, timeout=30, verify=False)
return r.text
except Exception as e:
print(f"{C.R}[!] Failed to fetch page: {e}{C.END}")
return None
def extract_js_urls(html, base_url):
"""Extract all JS URLs from HTML"""
soup = BeautifulSoup(html, 'html.parser')
js_urls = set()
# <script src="...">
for script in soup.find_all('script', src=True):
js_urls.add(urljoin(base_url, script['src']))
# Inline scripts se bhi URLs
for script in soup.find_all('script'):
if script.string:
# Relative URLs
for m in re.findall(r'["\']([^"\']*\.js(?:\?[^"\']*)?)["\']', script.string):
js_urls.add(urljoin(base_url, m))
# Absolute URLs
for m in re.findall(r'["\'](https?://[^"\']+\.js(?:\?[^"\']*)?)["\']', script.string):
js_urls.add(m)
# <link rel="modulepreload" href="...">
for link in soup.find_all('link'):
href = link.get('href', '')
if href.endswith('.js') or href.endswith('.mjs'):
js_urls.add(urljoin(base_url, href))
# Filter only valid JS
js_urls = {u for u in js_urls if is_js_url(u)}
return list(js_urls)
def download_js(js_url, output_dir):
"""Download JS file"""
try:
filename = os.path.basename(urlparse(js_url).path) or "script.js"
# Remove query string from filename
if '?' in filename:
filename = filename.split('?')[0]
filepath = os.path.join(output_dir, filename)
# Check if already downloaded
if os.path.exists(filepath):
with open(filepath, 'r', encoding='utf-8', errors='ignore') as f:
return filepath, f.read()
r = requests.get(js_url, headers=HEADERS, timeout=DOWNLOAD_TIMEOUT,
verify=False, stream=True)
if r.status_code != 200:
return None, None
# Size check
content_length = int(r.headers.get('Content-Length', 0))
if content_length > MAX_JS_SIZE:
print(f"{C.Y} [skip] Too large ({content_length} bytes): {filename}{C.END}")
return None, None
content = r.content
if len(content) > MAX_JS_SIZE:
return None, None
with open(filepath, 'wb') as f:
f.write(content)
return filepath, content.decode('utf-8', errors='ignore')
except Exception as e:
print(f"{C.R} [err] {js_url}: {str(e)[:100]}{C.END}")
return None, None
# ==================== ANALYSIS ====================
def analyze_content(content, filename):
"""Analyze JS content for all patterns"""
findings = {}
for category, patterns in SEARCH_PATTERNS.items():
matches = set()
for pattern in patterns:
try:
for m in re.finditer(pattern, content, re.IGNORECASE | re.DOTALL):
if isinstance(m, re.Match):
val = m.group(1) if m.groups() else m.group(0)
1 049
"API_ENDPOINTS": [
r'["\']((?:https?://)?[a-zA-Z0-9\-\.]+/(?:api|v\d|rest|graphql)/[^"\'\s]{3,100})["\']',
r'["\'](/api/[^"\'\s]{3,100})["\']',
r'["\'](/v\d/[^"\'\s]{3,100})["\']',
r'["\'](/[a-z\-]+/api/[^"\'\s]{3,100})["\']',
],
"FULL_URLS": [
r'["\'](https?://[a-zA-Z0-9\-\._/]+(?:\?[^"\'\s]*)?)["\']',
],
"WEBSOCKET_URLS": [
r'["\'](wss?://[a-zA-Z0-9\-\._/:]+)["\']',
],
# ========== CRYPTO FUNCTIONS ==========
"CRYPTO_FUNCTIONS": [
r'function\s+(\w*(?:encrypt|decrypt|cipher|hash|sign|verify)\w*)\s*\([^)]*\)\s*\{[^}]{0,2000}\}',
r'(\w*(?:encrypt|decrypt)\w*)\s*[:=]\s*(?:async\s*)?(?:function\s*)?\([^)]*\)\s*(?:=>)?\s*\{[^}]{0,2000}\}',
],
"CRYPTOJS_USAGE": [
r'CryptoJS\.(\w+)\.(encrypt|decrypt|hash|sign)\s*\([^)]{0,200}\)',
r'(?:CryptoJS|crypto)\.(AES|DES|TripleDES|RC4|SHA256|SHA1|MD5|HmacSHA256)',
],
"BASE64_USAGE": [
r'\b(?:atob|btoa)\s*\([^)]{0,200}\)',
],
"PBKDF2_USAGE": [
r'PBKDF2\s*\([^)]{0,200}\)[^;]{0,300}',
],
"AES_USAGE": [
r'\.AES\.(?:encrypt|decrypt)\s*\([^)]{0,300}\)',
],
"RSA_USAGE": [
r'\.(?:RSA|PublicKey|PrivateKey)\.(?:encrypt|decrypt|sign|verify)\s*\([^)]{0,300}\)',
],
# ========== CREDENTIALS ==========
"USERNAME": [
r'(?:username|userName|USERNAME|user_name)\s*[:=]\s*["\']([^"\']{3,64})["\']',
],
"PASSWORD": [
r'(?:password|passwd|pwd|PASSWORD)\s*[:=]\s*["\']([^"\']{4,64})["\']',
],
# ========== INTERESTING ==========
"GITHUB_TOKENS": [
r'gh[pousr]_[A-Za-z0-9]{36,255}',
],
"GOOGLE_API_KEY": [
r'AIza[0-9A-Za-z\-_]{35}',
],
"FIREBASE_URL": [
r'https://[a-z0-9\-]+\.firebaseio\.com',
r'https://[a-z0-9\-]+\.firebaseapp\.com',
],
"AWS_KEY": [
r'AKIA[0-9A-Z]{16}',
],
"STRIPE_KEY": [
r'sk_live_[0-9a-zA-Z]{24,}',
r'pk_live_[0-9a-zA-Z]{24,}',
],
"TWILIO_KEY": [
r'SK[0-9a-fA-F]{32}',
],
"SENDGRID_KEY": [
r'SG\.[A-Za-z0-9_\-]{22}\.[A-Za-z0-9_\-]{43}',
],
"SLACK_TOKEN": [
r'xox[baprs]-[0-9A-Za-z\-]{10,}',
],
"IP_ADDRESS": [
r'\b(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\b',
],
"EMAIL": [
r'[a-zA-Z0-9._%+\-]+@[a-zA-Z0-9.\-]+\.[a-zA-Z]{2,}',
],
"PHONE": [
r'(?:\+91[\-\s]?)?[6-9]\d{9}\b',
],
"AADHAAR_LIKE": [
r'\b[2-9]\d{3}\s?\d{4}\s?\d{4}\b',
],
}
# ==================== UTILITY FUNCTIONS ====================
def print_banner():
print(f"""{C.CY}{C.BOLD}
╔══════════════════════════════════════════════════════════════════╗
║ 🔍 UNIVERSAL JS ANALYZER 🔍 ║
║ ║
║ Website URL do aur ye script: ║
║ ✓ Saari JS files download karegi ║
║ ✓ Encryption keys nikaalegi ║
║ ✓ API endpoints dhundhegi ║
║ ✓ Crypto functions dikhayegi ║
║ ✓ Full report dega ║
╚══════════════════════════════════════════════════════════════════╝
{C.END}""")
def print_section(title, color=C.CY):
width = 70
print(f"\n{color}{C.BOLD}{'='*width}{C.END}")
print(f"{color}{C.BOLD} {title}{C.END}")
print(f"{color}{C.BOLD}{'='*width}{C.END}")
def print_finding(label, value, color=C.G):
"""Print a single finding with truncation"""
display = value if len(value) <= 200 else value[:200] + "..."
print(f" {color}[+] {label}{C.END}")
print(f" {C.W}{display}{C.END}")
1 049
`╔══════════════════════════════════════════════════════════════════╗
║ UNIVERSAL JS ANALYZER - By Abhigyan ║
║ ║
║ Run karo, website URL do, aur ye script: ║
║ ✓ Saari JS files download karegi ║
║ ✓ Encryption keys nikaalegi (AES, RSA, HMAC, etc.) ║
║ ✓ API endpoints dhundhegi ║
║ ✓ Crypto functions ka code dikhayegi ║
║ ✓ Secrets, salts, tokens extract karegi ║
║ ✓ Full report console me print karegi ║
╚══════════════════════════════════════════════════════════════════╝
"""
import requests
import re
import os
import json
import base64
from urllib.parse import urljoin, urlparse
from datetime import datetime
try:
from bs4 import BeautifulSoup
except ImportError:
print("[!] Installing beautifulsoup4...")
os.system("pip install beautifulsoup4")
from bs4 import BeautifulSoup
# ==================== COLORS (ANSI) ====================
class C:
R = '\033[91m' # Red
G = '\033[92m' # Green
Y = '\033[93m' # Yellow
B = '\033[94m' # Blue
M = '\033[95m' # Magenta
CY = '\033[96m' # Cyan
W = '\033[97m' # White
BOLD = '\033[1m'
END = '\033[0m'
# ==================== CONFIG ====================
USER_AGENT = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
HEADERS = {
"User-Agent": USER_AGENT,
"Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8",
"Accept-Language": "en-US,en;q=0.9",
"Connection": "keep-alive",
}
DOWNLOAD_TIMEOUT = 30
MAX_JS_SIZE = 20 * 1024 * 1024 # 20 MB per file
MAX_FILES = 200
# ==================== SEARCH PATTERNS ====================
SEARCH_PATTERNS = {
# ========== ENCRYPTION KEYS ==========
"AES_KEY": [
r'(?:AES_KEY|aesKey|AesKey|AESKEY)\s*[:=]\s*["\']([A-Za-z0-9+/=_\-]{16,64})["\']',
r'(?:AES_KEY|aesKey)\s*[:=]\s*[`"\']([^`"\']{16,64})[`"\']',
],
"AES_IV": [
r'(?:AES_IV|aesIv|AesIV|iv|IV)\s*[:=]\s*["\']([A-Za-z0-9+/=]{16})["\']',
],
"SECRET_KEY": [
r'(?:SECRET_KEY|secretKey|SecretKey|secret_key)\s*[:=]\s*["\']([^"\']{8,128})["\']',
],
"SECRET_CODE": [
r'(?:SECRET_CODE|secretCode|SecretCode)\s*[:=]\s*["\']([^"\']{8,128})["\']',
],
"API_KEY": [
r'(?:API_KEY|apiKey|ApiKey|api_key|apikey)\s*[:=]\s*["\']([A-Za-z0-9_\-]{16,128})["\']',
],
"ACCESS_TOKEN": [
r'(?:ACCESS_TOKEN|accessToken|access_token)\s*[:=]\s*["\']([A-Za-z0-9_\-\.]{20,})["\']',
],
"BEARER_TOKEN": [
r'(?:BEARER|bearer|Bearer)\s*[:=]\s*["\']([A-Za-z0-9_\-\.]{20,})["\']',
],
"JWT_SECRET": [
r'(?:JWT_SECRET|jwtSecret|JWT_KEY|jwtKey)\s*[:=]\s*["\']([^"\']{8,128})["\']',
],
"SALT": [
r'(?:salt|SALT|Sault|SAULT|saltValue|salt_value)\s*[:=]\s*["\']([^"\']{4,128})["\']',
],
"PRIVATE_KEY": [
r'-----BEGIN (?:RSA |EC |DSA )?PRIVATE KEY-----[\s\S]{100,3000}?-----END (?:RSA |EC |DSA )?PRIVATE KEY-----',
],
"PUBLIC_KEY": [
r'-----BEGIN PUBLIC KEY-----[\s\S]{100,3000}?-----END PUBLIC KEY-----',
],
"HMAC_KEY": [
r'(?:HMAC|hmac|HMAC_KEY)\s*[:=]\s*["\']([A-Za-z0-9+/=]{16,128})["\']',
],
"ENCRYPTION_KEY": [
r'(?:ENCRYPTION_KEY|encryptionKey|encryption_key)\s*[:=]\s*["\']([A-Za-z0-9+/=_\-]{16,128})["\']',
],
"SECRET_KEY_GENERIC": [
r'(?:secret|Secret)\s*[:=]\s*["\']([A-Za-z0-9+/=_\-#@!$%^&*]{8,128})["\']',
],
"BASIC_AUTH": [
r'Basic\s+([A-Za-z0-9+/=]{20,})',
],
# ========== API ENDPOINTS ==========