Initial verion.
This commit is contained in:
23
.dockerignore
Normal file
23
.dockerignore
Normal file
@@ -0,0 +1,23 @@
|
||||
# Git
|
||||
.git
|
||||
.gitignore
|
||||
|
||||
# Python
|
||||
__pycache__/
|
||||
*.py[cod]
|
||||
venv/
|
||||
|
||||
# IDE
|
||||
.vscode/
|
||||
.idea/
|
||||
|
||||
# Uploads
|
||||
uploads/*
|
||||
|
||||
# Docs
|
||||
README.md
|
||||
|
||||
# Docker
|
||||
Dockerfile
|
||||
docker-compose.yml
|
||||
.dockerignore
|
||||
26
.gitignore
vendored
Normal file
26
.gitignore
vendored
Normal file
@@ -0,0 +1,26 @@
|
||||
# Python
|
||||
__pycache__/
|
||||
*.py[cod]
|
||||
*$py.class
|
||||
*.so
|
||||
.Python
|
||||
venv/
|
||||
ENV/
|
||||
|
||||
# IDE
|
||||
.vscode/
|
||||
.idea/
|
||||
*.swp
|
||||
*.swo
|
||||
|
||||
# Uploads (user data)
|
||||
uploads/*
|
||||
!uploads/.gitkeep
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.local
|
||||
|
||||
# OS
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
39
Dockerfile
Normal file
39
Dockerfile
Normal file
@@ -0,0 +1,39 @@
|
||||
FROM python:3.11-slim
|
||||
|
||||
# Set environment variables
|
||||
ENV PYTHONDONTWRITEBYTECODE=1
|
||||
ENV PYTHONUNBUFFERED=1
|
||||
|
||||
# Set work directory
|
||||
WORKDIR /app
|
||||
|
||||
# Install system dependencies
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
gcc \
|
||||
libc-dev \
|
||||
libffi-dev \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Install Python dependencies
|
||||
COPY requirements.txt .
|
||||
RUN pip install --no-cache-dir -r requirements.txt
|
||||
|
||||
# Copy application
|
||||
COPY . .
|
||||
|
||||
# Create upload directory
|
||||
RUN mkdir -p /tmp/stego_uploads
|
||||
|
||||
# Create non-root user for security
|
||||
RUN useradd -m -u 1000 stego && chown -R stego:stego /app /tmp/stego_uploads
|
||||
USER stego
|
||||
|
||||
# Expose port
|
||||
EXPOSE 5000
|
||||
|
||||
# Health check
|
||||
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
|
||||
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:5000/')" || exit 1
|
||||
|
||||
# Run with gunicorn in production
|
||||
CMD ["gunicorn", "--bind", "0.0.0.0:5000", "--workers", "2", "--threads", "4", "--timeout", "60", "app:app"]
|
||||
149
README.md
Normal file
149
README.md
Normal file
@@ -0,0 +1,149 @@
|
||||
# Stegasoo Web Service
|
||||
|
||||
A containerized Flask + Bootstrap web UI for hybrid Photo + Day-Phrase + PIN steganography.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
## Features
|
||||
|
||||
- 🔐 **AES-256-GCM** authenticated encryption
|
||||
- 🧠 **Argon2id** memory-hard key derivation (256MB)
|
||||
- 🎲 **Pseudo-random pixel selection** defeats steganalysis
|
||||
- 📅 **Daily key rotation** with 3-word phrases
|
||||
- 🔢 **Static PIN** for additional entropy
|
||||
- 🖼️ **Reference photo** as "something you have"
|
||||
- 🌐 **Web UI** with Bootstrap 5 dark theme
|
||||
|
||||
## Quick Start
|
||||
|
||||
### Docker (Recommended)
|
||||
|
||||
```bash
|
||||
# Build and run
|
||||
docker-compose up -d
|
||||
|
||||
# Access at http://localhost:5000
|
||||
```
|
||||
|
||||
### Manual Installation
|
||||
|
||||
```bash
|
||||
# Create virtual environment
|
||||
python -m venv venv
|
||||
source venv/bin/activate # Linux/Mac
|
||||
# or: venv\Scripts\activate # Windows
|
||||
|
||||
# Install dependencies
|
||||
pip install -r requirements.txt
|
||||
|
||||
# Run development server
|
||||
python app.py
|
||||
|
||||
# Or production with gunicorn
|
||||
gunicorn --bind 0.0.0.0:5000 app:app
|
||||
```
|
||||
|
||||
## Usage
|
||||
|
||||
### 1. Generate Credentials
|
||||
|
||||
Visit `/generate` to create:
|
||||
- **7 three-word phrases** (one per day of week)
|
||||
- **1 six-digit PIN** (same every day)
|
||||
|
||||
Memorize these! Don't save them.
|
||||
|
||||
### 2. Encode a Message
|
||||
|
||||
Visit `/encode` and provide:
|
||||
- **Reference photo** - A photo both parties have (NOT transmitted)
|
||||
- **Carrier image** - The image to hide your message in
|
||||
- **Message** - Your secret text
|
||||
- **Day phrase** - Today's 3-word phrase
|
||||
- **PIN** - Your static 6-digit PIN
|
||||
|
||||
Download the stego image and share it through any channel.
|
||||
|
||||
### 3. Decode a Message
|
||||
|
||||
Visit `/decode` and provide:
|
||||
- **Reference photo** - Same photo used for encoding
|
||||
- **Stego image** - The image containing the hidden message
|
||||
- **Day phrase** - The phrase for the day it was encoded
|
||||
- **PIN** - Your static PIN
|
||||
|
||||
## Security Model
|
||||
|
||||
| Component | Entropy | Purpose |
|
||||
|-----------|---------|---------|
|
||||
| Reference Photo | ~80-256 bits | Something you have |
|
||||
| 3-Word Phrase | ~33 bits | Something you know (rotates daily) |
|
||||
| 6-Digit PIN | ~20 bits | Something you know (static) |
|
||||
| **Combined** | **133+ bits** | **Beyond brute force** |
|
||||
|
||||
### Attack Resistance
|
||||
|
||||
| Attack | Result |
|
||||
|--------|--------|
|
||||
| Brute force | 2^133 combinations = impossible |
|
||||
| Rainbow tables | Random salt per message |
|
||||
| Steganalysis | Random pixel selection defeats detection |
|
||||
| GPU cracking | Argon2 requires 256MB RAM per attempt |
|
||||
|
||||
## API Endpoints
|
||||
|
||||
| Endpoint | Method | Description |
|
||||
|----------|--------|-------------|
|
||||
| `/` | GET | Home page |
|
||||
| `/generate` | GET/POST | Generate phrase card + PIN |
|
||||
| `/encode` | GET/POST | Encode message in image |
|
||||
| `/decode` | GET/POST | Decode message from image |
|
||||
| `/about` | GET | Security information |
|
||||
|
||||
## Configuration
|
||||
|
||||
Environment variables:
|
||||
|
||||
| Variable | Default | Description |
|
||||
|----------|---------|-------------|
|
||||
| `FLASK_ENV` | production | Flask environment |
|
||||
| `SECRET_KEY` | random | Session secret (auto-generated) |
|
||||
|
||||
## Production Deployment
|
||||
|
||||
For production, consider:
|
||||
|
||||
1. **HTTPS** - Use nginx reverse proxy with SSL
|
||||
2. **Rate limiting** - Prevent abuse
|
||||
3. **Logging** - Monitor for security events
|
||||
4. **Memory** - Allocate at least 512MB (Argon2 needs 256MB)
|
||||
|
||||
Example nginx config:
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name stegocrypt.example.com;
|
||||
|
||||
ssl_certificate /path/to/cert.pem;
|
||||
ssl_certificate_key /path/to/key.pem;
|
||||
|
||||
location / {
|
||||
proxy_pass http://stegocrypt:5000;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
client_max_body_size 50M;
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## License
|
||||
|
||||
MIT License - Use responsibly.
|
||||
|
||||
## ⚠️ Disclaimer
|
||||
|
||||
This tool is for educational and legitimate privacy purposes only. Users are responsible for complying with applicable laws in their jurisdiction.
|
||||
149
STEGASOO_WEB_README.md
Normal file
149
STEGASOO_WEB_README.md
Normal file
@@ -0,0 +1,149 @@
|
||||
# Stegasoo Web Service
|
||||
|
||||
A containerized Flask + Bootstrap web UI for hybrid Photo + Day-Phrase + PIN steganography.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
## Features
|
||||
|
||||
- 🔐 **AES-256-GCM** authenticated encryption
|
||||
- 🧠 **Argon2id** memory-hard key derivation (256MB)
|
||||
- 🎲 **Pseudo-random pixel selection** defeats steganalysis
|
||||
- 📅 **Daily key rotation** with 3-word phrases
|
||||
- 🔢 **Static PIN** for additional entropy
|
||||
- 🖼️ **Reference photo** as "something you have"
|
||||
- 🌐 **Web UI** with Bootstrap 5 dark theme
|
||||
|
||||
## Quick Start
|
||||
|
||||
### Docker (Recommended)
|
||||
|
||||
```bash
|
||||
# Build and run
|
||||
docker-compose up -d
|
||||
|
||||
# Access at http://localhost:5000
|
||||
```
|
||||
|
||||
### Manual Installation
|
||||
|
||||
```bash
|
||||
# Create virtual environment
|
||||
python -m venv venv
|
||||
source venv/bin/activate # Linux/Mac
|
||||
# or: venv\Scripts\activate # Windows
|
||||
|
||||
# Install dependencies
|
||||
pip install -r requirements.txt
|
||||
|
||||
# Run development server
|
||||
python app.py
|
||||
|
||||
# Or production with gunicorn
|
||||
gunicorn --bind 0.0.0.0:5000 app:app
|
||||
```
|
||||
|
||||
## Usage
|
||||
|
||||
### 1. Generate Credentials
|
||||
|
||||
Visit `/generate` to create:
|
||||
- **7 three-word phrases** (one per day of week)
|
||||
- **1 six-digit PIN** (same every day)
|
||||
|
||||
Memorize these! Don't save them.
|
||||
|
||||
### 2. Encode a Message
|
||||
|
||||
Visit `/encode` and provide:
|
||||
- **Reference photo** - A photo both parties have (NOT transmitted)
|
||||
- **Carrier image** - The image to hide your message in
|
||||
- **Message** - Your secret text
|
||||
- **Day phrase** - Today's 3-word phrase
|
||||
- **PIN** - Your static 6-digit PIN
|
||||
|
||||
Download the stego image and share it through any channel.
|
||||
|
||||
### 3. Decode a Message
|
||||
|
||||
Visit `/decode` and provide:
|
||||
- **Reference photo** - Same photo used for encoding
|
||||
- **Stego image** - The image containing the hidden message
|
||||
- **Day phrase** - The phrase for the day it was encoded
|
||||
- **PIN** - Your static PIN
|
||||
|
||||
## Security Model
|
||||
|
||||
| Component | Entropy | Purpose |
|
||||
|-----------|---------|---------|
|
||||
| Reference Photo | ~80-256 bits | Something you have |
|
||||
| 3-Word Phrase | ~33 bits | Something you know (rotates daily) |
|
||||
| 6-Digit PIN | ~20 bits | Something you know (static) |
|
||||
| **Combined** | **133+ bits** | **Beyond brute force** |
|
||||
|
||||
### Attack Resistance
|
||||
|
||||
| Attack | Result |
|
||||
|--------|--------|
|
||||
| Brute force | 2^133 combinations = impossible |
|
||||
| Rainbow tables | Random salt per message |
|
||||
| Steganalysis | Random pixel selection defeats detection |
|
||||
| GPU cracking | Argon2 requires 256MB RAM per attempt |
|
||||
|
||||
## API Endpoints
|
||||
|
||||
| Endpoint | Method | Description |
|
||||
|----------|--------|-------------|
|
||||
| `/` | GET | Home page |
|
||||
| `/generate` | GET/POST | Generate phrase card + PIN |
|
||||
| `/encode` | GET/POST | Encode message in image |
|
||||
| `/decode` | GET/POST | Decode message from image |
|
||||
| `/about` | GET | Security information |
|
||||
|
||||
## Configuration
|
||||
|
||||
Environment variables:
|
||||
|
||||
| Variable | Default | Description |
|
||||
|----------|---------|-------------|
|
||||
| `FLASK_ENV` | production | Flask environment |
|
||||
| `SECRET_KEY` | random | Session secret (auto-generated) |
|
||||
|
||||
## Production Deployment
|
||||
|
||||
For production, consider:
|
||||
|
||||
1. **HTTPS** - Use nginx reverse proxy with SSL
|
||||
2. **Rate limiting** - Prevent abuse
|
||||
3. **Logging** - Monitor for security events
|
||||
4. **Memory** - Allocate at least 512MB (Argon2 needs 256MB)
|
||||
|
||||
Example nginx config:
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name stegocrypt.example.com;
|
||||
|
||||
ssl_certificate /path/to/cert.pem;
|
||||
ssl_certificate_key /path/to/key.pem;
|
||||
|
||||
location / {
|
||||
proxy_pass http://stegocrypt:5000;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
client_max_body_size 50M;
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
## License
|
||||
|
||||
MIT License - Use responsibly.
|
||||
|
||||
## ⚠️ Disclaimer
|
||||
|
||||
This tool is for educational and legitimate privacy purposes only. Users are responsible for complying with applicable laws in their jurisdiction.
|
||||
602
app.py
Normal file
602
app.py
Normal file
@@ -0,0 +1,602 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Steganography Web Service v3.1
|
||||
Flask + Bootstrap web UI for the hybrid Photo + Day-Phrase + PIN system
|
||||
"""
|
||||
|
||||
import os
|
||||
import io
|
||||
import secrets
|
||||
import hashlib
|
||||
import struct
|
||||
from datetime import datetime
|
||||
from flask import Flask, render_template, request, send_file, jsonify, flash, redirect, url_for
|
||||
from werkzeug.utils import secure_filename
|
||||
from PIL import Image
|
||||
from secureDeleter import SecureDeleter
|
||||
|
||||
from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes
|
||||
from cryptography.hazmat.backends import default_backend
|
||||
|
||||
try:
|
||||
from argon2.low_level import hash_secret_raw, Type
|
||||
HAS_ARGON2 = True
|
||||
except ImportError:
|
||||
HAS_ARGON2 = False
|
||||
from cryptography.hazmat.primitives.kdf.pbkdf2 import PBKDF2HMAC
|
||||
from cryptography.hazmat.primitives import hashes
|
||||
|
||||
# ============================================================================
|
||||
# FLASK APP CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
app = Flask(__name__)
|
||||
app.secret_key = secrets.token_hex(32)
|
||||
app.config['MAX_CONTENT_LENGTH'] = 5 * 1024 * 1024 # 5MB max upload per file
|
||||
app.config['UPLOAD_FOLDER'] = '/tmp/stego_uploads'
|
||||
|
||||
# Limits
|
||||
MAX_IMAGE_PIXELS = 4000000 # 4 megapixels max (e.g., 2000x2000)
|
||||
MAX_MESSAGE_SIZE = 50000 # 50KB message max
|
||||
|
||||
os.makedirs(app.config['UPLOAD_FOLDER'], exist_ok=True)
|
||||
|
||||
ALLOWED_EXTENSIONS = {'png', 'jpg', 'jpeg', 'bmp', 'gif'}
|
||||
|
||||
# ============================================================================
|
||||
# CRYPTO CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
MAGIC_HEADER = b'\x89ST3'
|
||||
VERSION = 3
|
||||
SALT_SIZE = 32
|
||||
IV_SIZE = 12
|
||||
TAG_SIZE = 16
|
||||
ARGON2_TIME_COST = 4
|
||||
ARGON2_MEMORY_COST = 256 * 1024
|
||||
ARGON2_PARALLELISM = 4
|
||||
|
||||
DAY_NAMES = ['Mon', 'Tue', 'Wed', 'Thu', 'Fri', 'Sat', 'Sun']
|
||||
|
||||
# BIP-39 wordlist (loaded from file)
|
||||
BIP39_FILE = os.path.join(os.path.dirname(__file__), 'bip39-words.txt')
|
||||
with open(BIP39_FILE, 'r') as f:
|
||||
BIP39_WORDS = [line.strip() for line in f if line.strip()]
|
||||
|
||||
# ============================================================================
|
||||
# SECURE CLEANUP
|
||||
# ============================================================================
|
||||
|
||||
def secure_cleanup_uploads():
|
||||
"""Securely delete any stray files in uploads directory."""
|
||||
upload_dir = app.config['UPLOAD_FOLDER']
|
||||
if os.path.exists(upload_dir):
|
||||
for filename in os.listdir(upload_dir):
|
||||
filepath = os.path.join(upload_dir, filename)
|
||||
if os.path.isfile(filepath) and not filename.startswith('.'):
|
||||
try:
|
||||
deleter = SecureDeleter(filepath)
|
||||
deleter.execute()
|
||||
except Exception as e:
|
||||
# Fallback to regular delete
|
||||
os.remove(filepath)
|
||||
|
||||
# ============================================================================
|
||||
# HELPER FUNCTIONS
|
||||
# ============================================================================
|
||||
|
||||
def allowed_file(filename):
|
||||
return '.' in filename and filename.rsplit('.', 1)[1].lower() in ALLOWED_EXTENSIONS
|
||||
|
||||
|
||||
def generate_pin(length=6):
|
||||
"""Generate a random PIN of specified length (6-8 digits)."""
|
||||
return ''.join(str(secrets.randbelow(10)) for _ in range(length))
|
||||
|
||||
|
||||
def generate_day_phrases(words_per_phrase=3):
|
||||
phrases = {}
|
||||
for day in DAY_NAMES:
|
||||
words = [secrets.choice(BIP39_WORDS) for _ in range(words_per_phrase)]
|
||||
phrases[day] = ' '.join(words)
|
||||
return phrases
|
||||
|
||||
|
||||
def hash_photo(image_data):
|
||||
"""Compute deterministic hash of photo content."""
|
||||
img = Image.open(io.BytesIO(image_data))
|
||||
img = img.convert('RGB')
|
||||
pixels = img.tobytes()
|
||||
h = hashlib.sha256(pixels).digest()
|
||||
h = hashlib.sha256(h + pixels[:1024]).digest()
|
||||
return h
|
||||
|
||||
|
||||
def derive_hybrid_key(photo_data, day_phrase, date_str, salt, pin=""):
|
||||
"""Derive encryption key from photo + phrase + PIN + date + salt."""
|
||||
photo_hash = hash_photo(photo_data)
|
||||
|
||||
key_material = (
|
||||
photo_hash +
|
||||
day_phrase.lower().encode() +
|
||||
pin.encode() +
|
||||
date_str.encode() +
|
||||
salt
|
||||
)
|
||||
|
||||
if HAS_ARGON2:
|
||||
key = hash_secret_raw(
|
||||
secret=key_material,
|
||||
salt=salt[:32],
|
||||
time_cost=ARGON2_TIME_COST,
|
||||
memory_cost=ARGON2_MEMORY_COST,
|
||||
parallelism=ARGON2_PARALLELISM,
|
||||
hash_len=32,
|
||||
type=Type.ID
|
||||
)
|
||||
else:
|
||||
kdf = PBKDF2HMAC(
|
||||
algorithm=hashes.SHA512(),
|
||||
length=32,
|
||||
salt=salt,
|
||||
iterations=600000,
|
||||
backend=default_backend()
|
||||
)
|
||||
key = kdf.derive(key_material)
|
||||
|
||||
return key
|
||||
|
||||
|
||||
def derive_pixel_key(photo_data, day_phrase, date_str, pin=""):
|
||||
"""Derive key for pixel selection."""
|
||||
photo_hash = hash_photo(photo_data)
|
||||
material = photo_hash + day_phrase.lower().encode() + pin.encode() + date_str.encode()
|
||||
return hashlib.sha256(material + b"pixel_selection").digest()
|
||||
|
||||
|
||||
def encrypt_message(message, photo_data, day_phrase, date_str, pin=""):
|
||||
"""Encrypt message using hybrid key derivation."""
|
||||
salt = secrets.token_bytes(SALT_SIZE)
|
||||
key = derive_hybrid_key(photo_data, day_phrase, date_str, salt, pin)
|
||||
iv = secrets.token_bytes(IV_SIZE)
|
||||
|
||||
# Random padding
|
||||
if isinstance(message, str):
|
||||
message = message.encode()
|
||||
|
||||
padding_len = secrets.randbelow(256) + 64
|
||||
padded_len = ((len(message) + padding_len + 255) // 256) * 256
|
||||
padding_needed = padded_len - len(message)
|
||||
padding = secrets.token_bytes(padding_needed - 4) + struct.pack('>I', len(message))
|
||||
padded_message = message + padding
|
||||
|
||||
cipher = Cipher(algorithms.AES(key), modes.GCM(iv), backend=default_backend())
|
||||
encryptor = cipher.encryptor()
|
||||
encryptor.authenticate_additional_data(MAGIC_HEADER + bytes([VERSION]))
|
||||
ciphertext = encryptor.update(padded_message) + encryptor.finalize()
|
||||
|
||||
date_bytes = date_str.encode()
|
||||
|
||||
return (
|
||||
MAGIC_HEADER +
|
||||
bytes([VERSION]) +
|
||||
bytes([len(date_bytes)]) +
|
||||
date_bytes +
|
||||
salt +
|
||||
iv +
|
||||
encryptor.tag +
|
||||
ciphertext
|
||||
)
|
||||
|
||||
|
||||
def generate_pixel_indices(key, num_pixels, num_needed):
|
||||
"""
|
||||
Generate pseudo-random pixel indices.
|
||||
|
||||
Optimized: Instead of shuffling ALL pixels (slow for large images),
|
||||
we generate indices directly using PRNG and handle collisions.
|
||||
"""
|
||||
if num_needed >= num_pixels // 2:
|
||||
# If we need many pixels, fall back to shuffle (rare case)
|
||||
nonce = b'\x00' * 16
|
||||
cipher = Cipher(algorithms.ChaCha20(key, nonce), mode=None, backend=default_backend())
|
||||
encryptor = cipher.encryptor()
|
||||
|
||||
indices = list(range(num_pixels))
|
||||
random_bytes = encryptor.update(b'\x00' * (num_pixels * 4))
|
||||
|
||||
for i in range(num_pixels - 1, 0, -1):
|
||||
j_bytes = random_bytes[(num_pixels - 1 - i) * 4:(num_pixels - i) * 4]
|
||||
j = int.from_bytes(j_bytes, 'big') % (i + 1)
|
||||
indices[i], indices[j] = indices[j], indices[i]
|
||||
|
||||
return indices[:num_needed]
|
||||
|
||||
# Optimized path: generate indices directly
|
||||
# Use key to seed selection, ensuring deterministic results
|
||||
selected = []
|
||||
used = set()
|
||||
|
||||
# Generate random bytes for index selection
|
||||
nonce = b'\x00' * 16
|
||||
cipher = Cipher(algorithms.ChaCha20(key, nonce), mode=None, backend=default_backend())
|
||||
encryptor = cipher.encryptor()
|
||||
|
||||
# Generate more than needed to handle collisions
|
||||
bytes_needed = (num_needed * 2) * 4 # 4 bytes per index, 2x for collisions
|
||||
random_bytes = encryptor.update(b'\x00' * bytes_needed)
|
||||
|
||||
byte_offset = 0
|
||||
while len(selected) < num_needed and byte_offset < len(random_bytes) - 4:
|
||||
idx = int.from_bytes(random_bytes[byte_offset:byte_offset + 4], 'big') % num_pixels
|
||||
byte_offset += 4
|
||||
|
||||
if idx not in used:
|
||||
used.add(idx)
|
||||
selected.append(idx)
|
||||
|
||||
# If we still need more (very unlikely), generate additional
|
||||
while len(selected) < num_needed:
|
||||
extra_bytes = encryptor.update(b'\x00' * 4)
|
||||
idx = int.from_bytes(extra_bytes, 'big') % num_pixels
|
||||
if idx not in used:
|
||||
used.add(idx)
|
||||
selected.append(idx)
|
||||
|
||||
return selected
|
||||
|
||||
|
||||
def embed_in_image(carrier_data, encrypted_data, pixel_key, bits_per_channel=1):
|
||||
"""Embed encrypted data in carrier image. Returns PNG bytes."""
|
||||
img = Image.open(io.BytesIO(carrier_data))
|
||||
if img.mode != 'RGB':
|
||||
img = img.convert('RGB')
|
||||
|
||||
pixels = list(img.getdata())
|
||||
num_pixels = len(pixels)
|
||||
|
||||
bits_per_pixel = 3 * bits_per_channel
|
||||
max_bytes = (num_pixels * bits_per_pixel) // 8
|
||||
|
||||
data_with_len = struct.pack('>I', len(encrypted_data)) + encrypted_data
|
||||
|
||||
if len(data_with_len) > max_bytes:
|
||||
raise ValueError(f"Carrier too small. Need {len(data_with_len)} bytes, have {max_bytes}")
|
||||
|
||||
binary_data = ''.join(format(b, '08b') for b in data_with_len)
|
||||
pixels_needed = (len(binary_data) + bits_per_pixel - 1) // bits_per_pixel
|
||||
|
||||
selected_indices = generate_pixel_indices(pixel_key, num_pixels, pixels_needed)
|
||||
|
||||
new_pixels = list(pixels)
|
||||
clear_mask = 0xFF ^ ((1 << bits_per_channel) - 1)
|
||||
|
||||
bit_idx = 0
|
||||
for pixel_idx in selected_indices:
|
||||
if bit_idx >= len(binary_data):
|
||||
break
|
||||
|
||||
r, g, b = new_pixels[pixel_idx]
|
||||
|
||||
for channel_idx, channel_val in enumerate([r, g, b]):
|
||||
if bit_idx >= len(binary_data):
|
||||
break
|
||||
bits = binary_data[bit_idx:bit_idx + bits_per_channel].ljust(bits_per_channel, '0')
|
||||
new_val = (channel_val & clear_mask) | int(bits, 2)
|
||||
|
||||
if channel_idx == 0:
|
||||
r = new_val
|
||||
elif channel_idx == 1:
|
||||
g = new_val
|
||||
else:
|
||||
b = new_val
|
||||
|
||||
bit_idx += bits_per_channel
|
||||
|
||||
new_pixels[pixel_idx] = (r, g, b)
|
||||
|
||||
stego_img = Image.new('RGB', img.size)
|
||||
stego_img.putdata(new_pixels)
|
||||
|
||||
output = io.BytesIO()
|
||||
stego_img.save(output, 'PNG')
|
||||
output.seek(0)
|
||||
|
||||
return output.getvalue(), {
|
||||
'pixels_modified': len(selected_indices),
|
||||
'total_pixels': num_pixels,
|
||||
'capacity_used': len(data_with_len) / max_bytes
|
||||
}
|
||||
|
||||
|
||||
def extract_from_image(image_data, pixel_key, bits_per_channel=1):
|
||||
"""Extract hidden data from image."""
|
||||
img = Image.open(io.BytesIO(image_data))
|
||||
if img.mode != 'RGB':
|
||||
img = img.convert('RGB')
|
||||
|
||||
pixels = list(img.getdata())
|
||||
num_pixels = len(pixels)
|
||||
bits_per_pixel = 3 * bits_per_channel
|
||||
|
||||
# First extract enough to get length
|
||||
initial_pixels = (32 + bits_per_pixel - 1) // bits_per_pixel + 10
|
||||
initial_indices = generate_pixel_indices(pixel_key, num_pixels, initial_pixels)
|
||||
|
||||
binary_data = ''
|
||||
for pixel_idx in initial_indices:
|
||||
r, g, b = pixels[pixel_idx]
|
||||
for channel in [r, g, b]:
|
||||
for bit_pos in range(bits_per_channel - 1, -1, -1):
|
||||
binary_data += str((channel >> bit_pos) & 1)
|
||||
|
||||
try:
|
||||
length_bits = binary_data[:32]
|
||||
data_length = struct.unpack('>I', int(length_bits, 2).to_bytes(4, 'big'))[0]
|
||||
except:
|
||||
return None
|
||||
|
||||
max_possible = (num_pixels * bits_per_pixel) // 8 - 4
|
||||
if data_length > max_possible or data_length < 10:
|
||||
return None
|
||||
|
||||
total_bits = (4 + data_length) * 8
|
||||
pixels_needed = (total_bits + bits_per_pixel - 1) // bits_per_pixel
|
||||
|
||||
selected_indices = generate_pixel_indices(pixel_key, num_pixels, pixels_needed)
|
||||
|
||||
binary_data = ''
|
||||
for pixel_idx in selected_indices:
|
||||
r, g, b = pixels[pixel_idx]
|
||||
for channel in [r, g, b]:
|
||||
for bit_pos in range(bits_per_channel - 1, -1, -1):
|
||||
binary_data += str((channel >> bit_pos) & 1)
|
||||
|
||||
data_bits = binary_data[32:32 + (data_length * 8)]
|
||||
|
||||
data_bytes = bytearray()
|
||||
for i in range(0, len(data_bits), 8):
|
||||
byte_bits = data_bits[i:i+8]
|
||||
if len(byte_bits) == 8:
|
||||
data_bytes.append(int(byte_bits, 2))
|
||||
|
||||
return bytes(data_bytes)
|
||||
|
||||
|
||||
def parse_header(encrypted_data):
|
||||
"""Parse v3 header."""
|
||||
if len(encrypted_data) < 10 or encrypted_data[:4] != MAGIC_HEADER:
|
||||
return None
|
||||
|
||||
date_len = encrypted_data[5]
|
||||
date_str = encrypted_data[6:6+date_len].decode()
|
||||
|
||||
offset = 6 + date_len
|
||||
salt = encrypted_data[offset:offset+SALT_SIZE]
|
||||
offset += SALT_SIZE
|
||||
iv = encrypted_data[offset:offset+IV_SIZE]
|
||||
offset += IV_SIZE
|
||||
tag = encrypted_data[offset:offset+TAG_SIZE]
|
||||
offset += TAG_SIZE
|
||||
ciphertext = encrypted_data[offset:]
|
||||
|
||||
return {'date': date_str, 'salt': salt, 'iv': iv, 'tag': tag, 'ciphertext': ciphertext}
|
||||
|
||||
|
||||
def decrypt_message(encrypted_data, photo_data, day_phrase, pin=""):
|
||||
"""Decrypt message."""
|
||||
header = parse_header(encrypted_data)
|
||||
if not header:
|
||||
return None
|
||||
|
||||
key = derive_hybrid_key(photo_data, day_phrase, header['date'], header['salt'], pin)
|
||||
|
||||
cipher = Cipher(
|
||||
algorithms.AES(key),
|
||||
modes.GCM(header['iv'], header['tag']),
|
||||
backend=default_backend()
|
||||
)
|
||||
decryptor = cipher.decryptor()
|
||||
decryptor.authenticate_additional_data(MAGIC_HEADER + bytes([VERSION]))
|
||||
|
||||
try:
|
||||
padded_plaintext = decryptor.update(header['ciphertext']) + decryptor.finalize()
|
||||
original_length = struct.unpack('>I', padded_plaintext[-4:])[0]
|
||||
return padded_plaintext[:original_length].decode('utf-8')
|
||||
except:
|
||||
return None
|
||||
|
||||
|
||||
# ============================================================================
|
||||
# FLASK ROUTES
|
||||
# ============================================================================
|
||||
|
||||
@app.route('/')
|
||||
def index():
|
||||
return render_template('index.html')
|
||||
|
||||
|
||||
@app.route('/generate', methods=['GET', 'POST'])
|
||||
def generate():
|
||||
if request.method == 'POST':
|
||||
words_per_phrase = int(request.form.get('words_per_phrase', 3))
|
||||
pin_length = int(request.form.get('pin_length', 6))
|
||||
|
||||
# Clamp values to valid ranges
|
||||
words_per_phrase = max(3, min(12, words_per_phrase))
|
||||
pin_length = max(6, min(8, pin_length))
|
||||
|
||||
phrases = generate_day_phrases(words_per_phrase)
|
||||
pin = generate_pin(pin_length)
|
||||
|
||||
# Calculate entropy
|
||||
phrase_entropy = words_per_phrase * 11 # ~11 bits per BIP-39 word
|
||||
pin_entropy = int(pin_length * 3.32) # log2(10) ≈ 3.32 bits per digit
|
||||
total_entropy = phrase_entropy + pin_entropy
|
||||
|
||||
return render_template('generate.html',
|
||||
phrases=phrases,
|
||||
pin=pin,
|
||||
days=DAY_NAMES,
|
||||
generated=True,
|
||||
words_per_phrase=words_per_phrase,
|
||||
pin_length=pin_length,
|
||||
phrase_entropy=phrase_entropy,
|
||||
pin_entropy=pin_entropy,
|
||||
total_entropy=total_entropy)
|
||||
return render_template('generate.html', generated=False)
|
||||
|
||||
|
||||
@app.route('/encode', methods=['GET', 'POST'])
|
||||
def encode():
|
||||
|
||||
# Get day of week
|
||||
day_of_week = datetime.now().strftime("%A")
|
||||
|
||||
if request.method == 'POST':
|
||||
try:
|
||||
|
||||
|
||||
# Get files
|
||||
ref_photo = request.files.get('reference_photo')
|
||||
carrier = request.files.get('carrier')
|
||||
|
||||
if not ref_photo or not carrier:
|
||||
flash('Both reference photo and carrier image are required', 'error')
|
||||
return render_template('encode.html')
|
||||
|
||||
if not allowed_file(ref_photo.filename) or not allowed_file(carrier.filename):
|
||||
flash('Invalid file type. Use PNG, JPG, or BMP', 'error')
|
||||
return render_template('encode.html')
|
||||
|
||||
# Get form data
|
||||
message = request.form.get('message', '')
|
||||
day_phrase = request.form.get('day_phrase', '')
|
||||
pin = request.form.get('pin', '')
|
||||
|
||||
if not message or not day_phrase:
|
||||
flash('Message and day phrase are required', 'error')
|
||||
return render_template('encode.html')
|
||||
|
||||
# Check message size
|
||||
if len(message) > MAX_MESSAGE_SIZE:
|
||||
flash(f'Message too long. Max {MAX_MESSAGE_SIZE // 1000}KB allowed.', 'error')
|
||||
return render_template('encode.html')
|
||||
|
||||
# Read files
|
||||
ref_data = ref_photo.read()
|
||||
carrier_data = carrier.read()
|
||||
|
||||
# Validate carrier image dimensions
|
||||
try:
|
||||
carrier_img = Image.open(io.BytesIO(carrier_data))
|
||||
width, height = carrier_img.size
|
||||
num_pixels = width * height
|
||||
|
||||
if num_pixels > MAX_IMAGE_PIXELS:
|
||||
max_dim = int(MAX_IMAGE_PIXELS ** 0.5)
|
||||
flash(f'Carrier image too large ({width}x{height} = {num_pixels:,} pixels). '
|
||||
f'Max ~{MAX_IMAGE_PIXELS:,} pixels ({max_dim}x{max_dim}). '
|
||||
f'Please resize your image.', 'error')
|
||||
return render_template('encode.html')
|
||||
except Exception as e:
|
||||
flash(f'Could not read carrier image: {str(e)}', 'error')
|
||||
return render_template('encode.html')
|
||||
|
||||
# Get date
|
||||
date_str = datetime.now().strftime('%Y-%m-%d')
|
||||
|
||||
# Encrypt
|
||||
encrypted = encrypt_message(message, ref_data, day_phrase, date_str, pin)
|
||||
|
||||
# Get pixel key
|
||||
pixel_key = derive_pixel_key(ref_data, day_phrase, date_str, pin)
|
||||
|
||||
# Embed
|
||||
stego_data, stats = embed_in_image(carrier_data, encrypted, pixel_key)
|
||||
|
||||
# Return as download
|
||||
return send_file(
|
||||
io.BytesIO(stego_data),
|
||||
mimetype='image/png',
|
||||
as_attachment=True,
|
||||
#download_name='stego_image.png'
|
||||
download_name=f'{secrets.token_hex(4)}_{datetime.now().strftime("%Y%m%d")}.png'
|
||||
)
|
||||
|
||||
except Exception as e:
|
||||
flash(f'Error: {str(e)}', 'error')
|
||||
return render_template('encode.html', day_of_week=day_of_week)
|
||||
|
||||
return render_template('encode.html', day_of_week=day_of_week)
|
||||
|
||||
|
||||
@app.route('/decode', methods=['GET', 'POST'])
|
||||
def decode():
|
||||
if request.method == 'POST':
|
||||
try:
|
||||
# Get files
|
||||
ref_photo = request.files.get('reference_photo')
|
||||
stego_image = request.files.get('stego_image')
|
||||
|
||||
if not ref_photo or not stego_image:
|
||||
flash('Both reference photo and stego image are required', 'error')
|
||||
return render_template('decode.html')
|
||||
|
||||
# Get form data
|
||||
day_phrase = request.form.get('day_phrase', '')
|
||||
pin = request.form.get('pin', '')
|
||||
|
||||
if not day_phrase:
|
||||
flash('Day phrase is required', 'error')
|
||||
return render_template('decode.html')
|
||||
|
||||
# Read files
|
||||
ref_data = ref_photo.read()
|
||||
stego_data = stego_image.read()
|
||||
|
||||
# Try to extract and decrypt
|
||||
# We need to try with today's date first for pixel key
|
||||
date_str = datetime.now().strftime('%Y-%m-%d')
|
||||
pixel_key = derive_pixel_key(ref_data, day_phrase, date_str, pin)
|
||||
|
||||
encrypted = extract_from_image(stego_data, pixel_key)
|
||||
|
||||
if encrypted:
|
||||
# Parse to get actual date
|
||||
header = parse_header(encrypted)
|
||||
if header and header['date'] != date_str:
|
||||
# Re-extract with correct date
|
||||
pixel_key = derive_pixel_key(ref_data, day_phrase, header['date'], pin)
|
||||
encrypted = extract_from_image(stego_data, pixel_key)
|
||||
|
||||
if not encrypted:
|
||||
flash('Could not extract data. Check your inputs.', 'error')
|
||||
return render_template('decode.html')
|
||||
|
||||
message = decrypt_message(encrypted, ref_data, day_phrase, pin)
|
||||
|
||||
if message:
|
||||
return render_template('decode.html', decoded_message=message)
|
||||
else:
|
||||
flash('Decryption failed. Wrong phrase, PIN, or reference photo.', 'error')
|
||||
return render_template('decode.html')
|
||||
|
||||
except Exception as e:
|
||||
flash(f'Error: {str(e)}', 'error')
|
||||
return render_template('decode.html')
|
||||
|
||||
return render_template('decode.html')
|
||||
|
||||
|
||||
@app.route('/about')
|
||||
def about():
|
||||
return render_template('about.html', has_argon2=HAS_ARGON2)
|
||||
|
||||
|
||||
# ============================================================================
|
||||
# MAIN
|
||||
# ============================================================================
|
||||
|
||||
if __name__ == '__main__':
|
||||
app.run(host='0.0.0.0', port=5000, debug=False)
|
||||
2048
bip39-words.txt
Normal file
2048
bip39-words.txt
Normal file
File diff suppressed because it is too large
Load Diff
33
docker-compose.yml
Normal file
33
docker-compose.yml
Normal file
@@ -0,0 +1,33 @@
|
||||
version: '3.8'
|
||||
|
||||
services:
|
||||
stegocrypt:
|
||||
build: .
|
||||
container_name: stegocrypt
|
||||
ports:
|
||||
- "5000:5000"
|
||||
environment:
|
||||
- FLASK_ENV=production
|
||||
# Uncomment to persist uploads between restarts:
|
||||
# volumes:
|
||||
# - ./uploads:/tmp/stego_uploads
|
||||
restart: unless-stopped
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 512M # Argon2 needs 256MB per operation
|
||||
reservations:
|
||||
memory: 256M
|
||||
|
||||
# Optional: Add nginx reverse proxy for production
|
||||
# nginx:
|
||||
# image: nginx:alpine
|
||||
# ports:
|
||||
# - "80:80"
|
||||
# - "443:443"
|
||||
# volumes:
|
||||
# - ./nginx.conf:/etc/nginx/nginx.conf:ro
|
||||
# - ./certs:/etc/nginx/certs:ro
|
||||
# depends_on:
|
||||
# - stegocrypt
|
||||
# restart: unless-stopped
|
||||
11
requirements.txt
Normal file
11
requirements.txt
Normal file
@@ -0,0 +1,11 @@
|
||||
# Core dependencies
|
||||
flask>=3.0.0
|
||||
gunicorn>=21.0.0
|
||||
pillow>=10.0.0
|
||||
cryptography>=41.0.0
|
||||
|
||||
# Memory-hard key derivation (highly recommended)
|
||||
argon2-cffi>=23.0.0
|
||||
|
||||
# Optional: For production deployment
|
||||
# gevent>=23.0.0
|
||||
65
secureDeleter.py
Normal file
65
secureDeleter.py
Normal file
@@ -0,0 +1,65 @@
|
||||
import os
|
||||
import shutil
|
||||
import random
|
||||
|
||||
class SecureDeleter:
|
||||
def __init__(self, path):
|
||||
self.path = path
|
||||
|
||||
def overwrite_file(self, file_path, passes=7):
|
||||
"""Overwrites the file with multiple patterns and random data."""
|
||||
patterns = [b'\x00', b'\xFF', random.randbytes(1)]
|
||||
print(patterns)
|
||||
length = os.path.getsize(file_path)
|
||||
for _ in range(passes):
|
||||
with open(file_path, "r+b") as file:
|
||||
for pattern in patterns:
|
||||
file.seek(0)
|
||||
for _ in range(length):
|
||||
file.write(pattern)
|
||||
# Final pass with random data for each byte
|
||||
file.seek(0)
|
||||
file.write(random.randbytes(length))
|
||||
|
||||
def delete_file(self, file_path):
|
||||
"""Securely deletes a file."""
|
||||
if os.path.isfile(file_path):
|
||||
self.overwrite_file(file_path)
|
||||
os.remove(file_path)
|
||||
|
||||
def delete_folder(self, folder_path):
|
||||
"""Securely deletes a folder and its contents."""
|
||||
if os.path.isdir(folder_path):
|
||||
for root, dirs, files in os.walk(folder_path, topdown=False):
|
||||
for name in files:
|
||||
file_path = os.path.join(root, name)
|
||||
self.delete_file(file_path)
|
||||
for name in dirs:
|
||||
os.rmdir(os.path.join(root, name))
|
||||
shutil.rmtree(folder_path)\
|
||||
|
||||
def wipe_free_space(self, drive, size=1024*1024*10): # 10MB default file size
|
||||
"""Writes temporary files with random data to overwrite free disk space."""
|
||||
temp_files = []
|
||||
try:
|
||||
while True:
|
||||
temp_file = os.path.join(drive, f"temp_{random.randint(0, 999999)}.dat")
|
||||
with open(temp_file, "wb") as file:
|
||||
file.write(random.randbytes(size))
|
||||
temp_files.append(temp_file)
|
||||
except OSError: # Typically disk full
|
||||
for temp_file in temp_files:
|
||||
os.remove(temp_file)
|
||||
|
||||
def execute(self):
|
||||
"""Determines whether the path is a file or folder and deletes it securely."""
|
||||
if os.path.isfile(self.path):
|
||||
self.delete_file(self.path)
|
||||
elif os.path.isdir(self.path):
|
||||
self.delete_folder(self.path)
|
||||
else:
|
||||
print("Path does not exist.")
|
||||
|
||||
# Usage example:
|
||||
#deleter = SecureDeleter("/path/to/your/file_or_folder")
|
||||
#deleter.execute()
|
||||
0
static/.gitkeep
Normal file
0
static/.gitkeep
Normal file
180
templates/about.html
Normal file
180
templates/about.html
Normal file
@@ -0,0 +1,180 @@
|
||||
{% extends "base.html" %}
|
||||
|
||||
{% block title %}About - Stegasoo{% endblock %}
|
||||
|
||||
{% block content %}
|
||||
<div class="row justify-content-center">
|
||||
<div class="col-lg-10">
|
||||
<div class="card mb-4">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-info-circle me-2"></i>About Stegasoo</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<p>
|
||||
Stegasoo is a hybrid steganography system that hides encrypted messages inside
|
||||
ordinary images. It combines multiple security layers to create a system that is
|
||||
both highly secure and practical to use.
|
||||
</p>
|
||||
|
||||
<h6 class="mt-4 mb-3">System Status</h6>
|
||||
<div class="row g-3">
|
||||
<div class="col-md-6">
|
||||
<div class="d-flex align-items-center p-3 rounded"
|
||||
style="background: rgba(0,0,0,0.2);">
|
||||
{% if has_argon2 %}
|
||||
<i class="bi bi-check-circle-fill text-success fs-4 me-3"></i>
|
||||
<div>
|
||||
<strong>Argon2id Available</strong>
|
||||
<div class="small text-muted">Memory-hard key derivation (256MB)</div>
|
||||
</div>
|
||||
{% else %}
|
||||
<i class="bi bi-exclamation-triangle-fill text-warning fs-4 me-3"></i>
|
||||
<div>
|
||||
<strong>Using PBKDF2 Fallback</strong>
|
||||
<div class="small text-muted">Install argon2-cffi for better security</div>
|
||||
</div>
|
||||
{% endif %}
|
||||
</div>
|
||||
</div>
|
||||
<div class="col-md-6">
|
||||
<div class="d-flex align-items-center p-3 rounded"
|
||||
style="background: rgba(0,0,0,0.2);">
|
||||
<i class="bi bi-shield-fill-check text-success fs-4 me-3"></i>
|
||||
<div>
|
||||
<strong>AES-256-GCM</strong>
|
||||
<div class="small text-muted">Authenticated encryption enabled</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card mb-4">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-shield-lock me-2"></i>Security Model</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<div class="table-responsive">
|
||||
<table class="table table-dark">
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Component</th>
|
||||
<th>Entropy</th>
|
||||
<th>Purpose</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td><i class="bi bi-image text-info me-2"></i>Reference Photo</td>
|
||||
<td>~80-256 bits</td>
|
||||
<td>Something you have (plausible deniability)</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><i class="bi bi-chat-quote text-info me-2"></i>3-Word Phrase</td>
|
||||
<td>~33 bits</td>
|
||||
<td>Something you know (changes daily)</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><i class="bi bi-123 text-info me-2"></i>6-Digit PIN</td>
|
||||
<td>~20 bits</td>
|
||||
<td>Something you know (static)</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><i class="bi bi-calendar text-info me-2"></i>Date</td>
|
||||
<td>N/A</td>
|
||||
<td>Automatic key rotation</td>
|
||||
</tr>
|
||||
<tr class="table-active">
|
||||
<td><strong>Combined</strong></td>
|
||||
<td><strong>133+ bits</strong></td>
|
||||
<td><strong>Beyond brute force</strong></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card mb-4">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-cpu me-2"></i>Attack Resistance</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<div class="row g-4">
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-danger"><i class="bi bi-x-circle me-2"></i>What Attackers Can't Do</h6>
|
||||
<ul class="list-unstyled">
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shield-x text-muted me-2"></i>
|
||||
Brute force the passphrase (2<sup>133</sup> combinations)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shield-x text-muted me-2"></i>
|
||||
Use rainbow tables (random salt per message)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shield-x text-muted me-2"></i>
|
||||
Detect hidden data (random pixel selection)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shield-x text-muted me-2"></i>
|
||||
Use GPU farms (Argon2 requires 256MB RAM per attempt)
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-warning"><i class="bi bi-exclamation-triangle me-2"></i>Real Threats</h6>
|
||||
<ul class="list-unstyled">
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-person-x text-muted me-2"></i>
|
||||
Social engineering (someone tricks you)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-door-open text-muted me-2"></i>
|
||||
Physical access to your devices
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-bug text-muted me-2"></i>
|
||||
Malware/keyloggers on your system
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-camera-video text-muted me-2"></i>
|
||||
Shoulder surfing while you type
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-book me-2"></i>Best Practices</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<div class="row">
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-success"><i class="bi bi-check-lg me-2"></i>Do</h6>
|
||||
<ul>
|
||||
<li>Memorize your phrases and PIN, never write them down</li>
|
||||
<li>Use a reference photo that both parties already have</li>
|
||||
<li>Use different carrier images for each message</li>
|
||||
<li>Share stego images through normal channels (looks innocent)</li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-danger"><i class="bi bi-x-lg me-2"></i>Don't</h6>
|
||||
<ul>
|
||||
<li>Don't transmit the reference photo</li>
|
||||
<li>Don't reuse the same carrier image</li>
|
||||
<li>Don't store phrases or PIN digitally</li>
|
||||
<li>Don't resize or recompress stego images</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
180
templates/base.html
Normal file
180
templates/base.html
Normal file
@@ -0,0 +1,180 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en" data-bs-theme="dark">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>{% block title %}Stegasoo{% endblock %}</title>
|
||||
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/css/bootstrap.min.css" rel="stylesheet">
|
||||
<link href="https://cdn.jsdelivr.net/npm/bootstrap-icons@1.11.1/font/bootstrap-icons.css" rel="stylesheet">
|
||||
<style>
|
||||
:root {
|
||||
--gradient-start: #667eea;
|
||||
--gradient-end: #764ba2;
|
||||
}
|
||||
|
||||
body {
|
||||
min-height: 100vh;
|
||||
background: linear-gradient(135deg, #1a1a2e 0%, #16213e 50%, #0f3460 100%);
|
||||
}
|
||||
|
||||
.navbar {
|
||||
background: rgba(0, 0, 0, 0.3) !important;
|
||||
backdrop-filter: blur(10px);
|
||||
}
|
||||
|
||||
.card {
|
||||
background: rgba(255, 255, 255, 0.05);
|
||||
backdrop-filter: blur(10px);
|
||||
border: 1px solid rgba(255, 255, 255, 0.1);
|
||||
}
|
||||
|
||||
.card-header {
|
||||
background: linear-gradient(135deg, var(--gradient-start), var(--gradient-end));
|
||||
border-bottom: none;
|
||||
}
|
||||
|
||||
.btn-primary {
|
||||
background: linear-gradient(135deg, var(--gradient-start), var(--gradient-end));
|
||||
border: none;
|
||||
}
|
||||
|
||||
.btn-primary:hover {
|
||||
background: linear-gradient(135deg, var(--gradient-end), var(--gradient-start));
|
||||
transform: translateY(-2px);
|
||||
box-shadow: 0 5px 20px rgba(102, 126, 234, 0.4);
|
||||
}
|
||||
|
||||
.hero-icon {
|
||||
font-size: 4rem;
|
||||
background: linear-gradient(135deg, var(--gradient-start), var(--gradient-end));
|
||||
-webkit-background-clip: text;
|
||||
-webkit-text-fill-color: transparent;
|
||||
background-clip: text;
|
||||
}
|
||||
|
||||
.feature-card {
|
||||
transition: transform 0.3s ease, box-shadow 0.3s ease;
|
||||
}
|
||||
|
||||
.feature-card:hover {
|
||||
transform: translateY(-5px);
|
||||
box-shadow: 0 10px 40px rgba(102, 126, 234, 0.2);
|
||||
}
|
||||
|
||||
.form-control, .form-select {
|
||||
background: rgba(255, 255, 255, 0.05);
|
||||
border: 1px solid rgba(255, 255, 255, 0.1);
|
||||
color: #fff;
|
||||
}
|
||||
|
||||
.form-control:focus, .form-select:focus {
|
||||
background: rgba(255, 255, 255, 0.1);
|
||||
border-color: var(--gradient-start);
|
||||
box-shadow: 0 0 0 0.25rem rgba(102, 126, 234, 0.25);
|
||||
color: #fff;
|
||||
}
|
||||
|
||||
.form-control::placeholder {
|
||||
color: rgba(255, 255, 255, 0.5);
|
||||
}
|
||||
|
||||
/* Fix dropdown options for dark theme */
|
||||
.form-select option {
|
||||
background: #1a1a2e;
|
||||
color: #fff;
|
||||
}
|
||||
|
||||
.phrase-display {
|
||||
font-family: 'Courier New', monospace;
|
||||
font-size: 1.1rem;
|
||||
background: rgba(0, 0, 0, 0.3);
|
||||
padding: 0.5rem 1rem;
|
||||
border-radius: 0.5rem;
|
||||
border-left: 4px solid var(--gradient-start);
|
||||
}
|
||||
|
||||
.pin-display {
|
||||
font-family: 'Courier New', monospace;
|
||||
font-size: 2rem;
|
||||
letter-spacing: 0.5rem;
|
||||
background: linear-gradient(135deg, var(--gradient-start), var(--gradient-end));
|
||||
-webkit-background-clip: text;
|
||||
-webkit-text-fill-color: transparent;
|
||||
background-clip: text;
|
||||
}
|
||||
|
||||
.alert-message {
|
||||
background: rgba(0, 0, 0, 0.3);
|
||||
border: 1px solid rgba(255, 255, 255, 0.1);
|
||||
border-radius: 0.5rem;
|
||||
padding: 1.5rem;
|
||||
white-space: pre-wrap;
|
||||
font-family: 'Courier New', monospace;
|
||||
}
|
||||
|
||||
footer {
|
||||
background: rgba(0, 0, 0, 0.2);
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<nav class="navbar navbar-expand-lg navbar-dark">
|
||||
<div class="container">
|
||||
<a class="navbar-brand d-flex align-items-center" href="/">
|
||||
<i class="bi bi-shield-lock-fill me-2"></i>
|
||||
<span class="fw-bold">Stegasoo</span>
|
||||
</a>
|
||||
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarNav">
|
||||
<span class="navbar-toggler-icon"></span>
|
||||
</button>
|
||||
<div class="collapse navbar-collapse" id="navbarNav">
|
||||
<ul class="navbar-nav ms-auto">
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/"><i class="bi bi-house me-1"></i> Home</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/generate"><i class="bi bi-key me-1"></i> Generate</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/encode"><i class="bi bi-lock me-1"></i> Encode</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/decode"><i class="bi bi-unlock me-1"></i> Decode</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/about"><i class="bi bi-info-circle me-1"></i> About</a>
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<main class="container py-5">
|
||||
{% with messages = get_flashed_messages(with_categories=true) %}
|
||||
{% if messages %}
|
||||
{% for category, message in messages %}
|
||||
<div class="alert alert-{{ 'danger' if category == 'error' else 'success' }} alert-dismissible fade show" role="alert">
|
||||
<i class="bi bi-{{ 'exclamation-triangle' if category == 'error' else 'check-circle' }} me-2"></i>
|
||||
{{ message }}
|
||||
<button type="button" class="btn-close" data-bs-dismiss="alert"></button>
|
||||
</div>
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endwith %}
|
||||
|
||||
{% block content %}{% endblock %}
|
||||
</main>
|
||||
|
||||
<footer class="py-4 mt-5">
|
||||
<div class="container text-center text-muted">
|
||||
<small>
|
||||
<i class="bi bi-shield-check me-1"></i>
|
||||
Stegasoo v3.1 — Hybrid Photo + Day-Phrase + PIN Steganography
|
||||
</small>
|
||||
</div>
|
||||
</footer>
|
||||
|
||||
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/js/bootstrap.bundle.min.js"></script>
|
||||
{% block scripts %}{% endblock %}
|
||||
</body>
|
||||
</html>
|
||||
122
templates/decode.html
Normal file
122
templates/decode.html
Normal file
@@ -0,0 +1,122 @@
|
||||
{% extends "base.html" %}
|
||||
|
||||
{% block title %}Decode Message - Stegasoo{% endblock %}
|
||||
|
||||
{% block content %}
|
||||
<div class="row justify-content-center">
|
||||
<div class="col-lg-8">
|
||||
<div class="card">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-unlock-fill me-2"></i>Decode Secret Message</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
{% if decoded_message %}
|
||||
<div class="alert alert-success">
|
||||
<h6><i class="bi bi-check-circle me-2"></i>Message Decrypted Successfully!</h6>
|
||||
</div>
|
||||
|
||||
<div class="mb-4">
|
||||
<label class="form-label text-muted">Decoded Message:</label>
|
||||
<div class="alert-message">{{ decoded_message }}</div>
|
||||
</div>
|
||||
|
||||
<a href="/decode" class="btn btn-outline-light w-100">
|
||||
<i class="bi bi-arrow-repeat me-2"></i>Decode Another Message
|
||||
</a>
|
||||
|
||||
{% else %}
|
||||
|
||||
<form method="POST" enctype="multipart/form-data" id="decodeForm">
|
||||
<div class="row">
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-image me-1"></i> Reference Photo
|
||||
</label>
|
||||
<input type="file" name="reference_photo" class="form-control"
|
||||
accept="image/*" required>
|
||||
<div class="form-text">
|
||||
The same reference photo used for encoding
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-file-earmark-image me-1"></i> Stego Image
|
||||
</label>
|
||||
<input type="file" name="stego_image" class="form-control"
|
||||
accept="image/*" required>
|
||||
<div class="form-text">
|
||||
The image containing the hidden message
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row">
|
||||
<div class="col-md-8 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-chat-quote me-1"></i> Day Phrase
|
||||
</label>
|
||||
<input type="text" name="day_phrase" class="form-control"
|
||||
placeholder="e.g., correct horse battery" required>
|
||||
<div class="form-text">
|
||||
The phrase for the day the message was encoded
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-4 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-123 me-1"></i> PIN
|
||||
</label>
|
||||
<input type="password" name="pin" class="form-control"
|
||||
placeholder="123456" maxlength="10">
|
||||
<div class="form-text">
|
||||
Your static 6-digit PIN
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<button type="submit" class="btn btn-primary btn-lg w-100" id="decodeBtn">
|
||||
<i class="bi bi-unlock me-2"></i>Decode Message
|
||||
</button>
|
||||
</form>
|
||||
|
||||
{% endif %}
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card mt-4">
|
||||
<div class="card-body">
|
||||
<h6 class="text-muted mb-3"><i class="bi bi-question-circle me-2"></i>Troubleshooting</h6>
|
||||
<ul class="list-unstyled text-muted small mb-0">
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-dot"></i>
|
||||
Make sure you're using the <strong>exact same reference photo</strong> file
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-dot"></i>
|
||||
Use the phrase for the <strong>day the message was encoded</strong>, not today
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-dot"></i>
|
||||
Ensure the stego image hasn't been <strong>resized or recompressed</strong>
|
||||
</li>
|
||||
<li class="mb-0">
|
||||
<i class="bi bi-dot"></i>
|
||||
Double-check your <strong>PIN</strong> is correct
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
|
||||
{% block scripts %}
|
||||
<script>
|
||||
document.getElementById('decodeForm')?.addEventListener('submit', function() {
|
||||
const btn = document.getElementById('decodeBtn');
|
||||
btn.innerHTML = '<span class="spinner-border spinner-border-sm me-2"></span>Decoding...';
|
||||
btn.disabled = true;
|
||||
});
|
||||
</script>
|
||||
{% endblock %}
|
||||
130
templates/encode.html
Normal file
130
templates/encode.html
Normal file
@@ -0,0 +1,130 @@
|
||||
{% extends "base.html" %}
|
||||
|
||||
{% block title %}Encode Message - Stegasoo{% endblock %}
|
||||
|
||||
{% block content %}
|
||||
<div class="row justify-content-center">
|
||||
<div class="col-lg-8">
|
||||
<div class="card">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-lock-fill me-2"></i>Encode Secret Message</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<form method="POST" enctype="multipart/form-data" id="encodeForm">
|
||||
<div class="row">
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-image me-1"></i> Reference Photo
|
||||
</label>
|
||||
<input type="file" name="reference_photo" class="form-control"
|
||||
accept="image/*" required>
|
||||
<div class="form-text">
|
||||
The secret photo both parties have (NOT transmitted)
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-file-image me-1"></i> Carrier Image
|
||||
</label>
|
||||
<input type="file" name="carrier" class="form-control"
|
||||
accept="image/*" required>
|
||||
<div class="form-text">
|
||||
The image to hide your message in (e.g., a meme)
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-chat-left-text me-1"></i> Secret Message
|
||||
</label>
|
||||
<textarea name="message" class="form-control" rows="4"
|
||||
placeholder="Enter your secret message here..." required></textarea>
|
||||
</div>
|
||||
|
||||
<div class="row">
|
||||
<div class="col-md-8 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-chat-quote me-1"></i> {{ day_of_week }}'s Phrase
|
||||
</label>
|
||||
<input type="text" name="day_phrase" class="form-control"
|
||||
placeholder="e.g., correct horse battery" required>
|
||||
<div class="form-text">
|
||||
Your 3-word phrase for today (from your phrase card)
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-4 mb-3">
|
||||
<label class="form-label">
|
||||
<i class="bi bi-123 me-1"></i> PIN
|
||||
</label>
|
||||
<input type="password" name="pin" class="form-control"
|
||||
placeholder="123456" maxlength="10">
|
||||
<div class="form-text">
|
||||
Your static 6-digit PIN
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<button type="submit" class="btn btn-primary btn-lg w-100" id="encodeBtn">
|
||||
<i class="bi bi-lock me-2"></i>Encode & Download
|
||||
</button>
|
||||
</form>
|
||||
|
||||
<hr class="my-4">
|
||||
|
||||
<div class="row text-center text-muted small">
|
||||
<div class="col-4">
|
||||
<i class="bi bi-shield-check fs-4 d-block mb-1 text-success"></i>
|
||||
AES-256-GCM Encryption
|
||||
</div>
|
||||
<div class="col-4">
|
||||
<i class="bi bi-shuffle fs-4 d-block mb-1 text-info"></i>
|
||||
Random Pixel Embedding
|
||||
</div>
|
||||
<div class="col-4">
|
||||
<i class="bi bi-eye-slash fs-4 d-block mb-1 text-warning"></i>
|
||||
Undetectable by Analysis
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="alert alert-secondary mt-4 small">
|
||||
<i class="bi bi-info-circle me-1"></i>
|
||||
<strong>Limits:</strong>
|
||||
Carrier image max ~4 megapixels (2000×2000).
|
||||
Files max 5MB each.
|
||||
Message max 50KB.
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
|
||||
{% block scripts %}
|
||||
<script>
|
||||
document.getElementById('encodeForm').addEventListener('submit', function(e) {
|
||||
const btn = document.getElementById('encodeBtn');
|
||||
|
||||
btn.innerHTML = '<span class="spinner-border spinner-border-sm me-2"></span>Encoding...';
|
||||
btn.disabled = true;
|
||||
|
||||
// Argon2 key derivation can take a few seconds
|
||||
// Reset button after encoding completes (file downloads don't navigate)
|
||||
setTimeout(function() {
|
||||
btn.innerHTML = '<i class="bi bi-check-circle me-2"></i>Done! Encode Another?';
|
||||
btn.disabled = false;
|
||||
btn.classList.remove('btn-primary');
|
||||
btn.classList.add('btn-success');
|
||||
|
||||
// Reset to original state after a moment
|
||||
setTimeout(function() {
|
||||
btn.innerHTML = '<i class="bi bi-lock me-2"></i>Encode & Download';
|
||||
btn.classList.remove('btn-success');
|
||||
btn.classList.add('btn-primary');
|
||||
}, 2000);
|
||||
}, 4000); // 4 seconds for Argon2 + embedding
|
||||
});
|
||||
</script>
|
||||
{% endblock %}
|
||||
181
templates/generate.html
Normal file
181
templates/generate.html
Normal file
@@ -0,0 +1,181 @@
|
||||
{% extends "base.html" %}
|
||||
|
||||
{% block title %}Generate Phrase Card - Stegasoo{% endblock %}
|
||||
|
||||
{% block content %}
|
||||
<div class="row justify-content-center">
|
||||
<div class="col-lg-8">
|
||||
<div class="card">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-key-fill me-2"></i>Generate Phrase Card + PIN</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
{% if not generated %}
|
||||
<p class="text-muted mb-4">
|
||||
Generate your weekly phrase card and static PIN. Customize your security level:
|
||||
</p>
|
||||
|
||||
<form method="POST">
|
||||
<div class="row">
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">Words per phrase</label>
|
||||
<select name="words_per_phrase" class="form-select" id="wordsSelect">
|
||||
<option value="3" selected>3 words (~33 bits)</option>
|
||||
<option value="4">4 words (~44 bits)</option>
|
||||
<option value="5">5 words (~55 bits)</option>
|
||||
<option value="6">6 words (~66 bits)</option>
|
||||
<option value="7">7 words (~77 bits)</option>
|
||||
<option value="8">8 words (~88 bits)</option>
|
||||
<option value="9">9 words (~99 bits)</option>
|
||||
<option value="10">10 words (~110 bits)</option>
|
||||
<option value="11">11 words (~121 bits)</option>
|
||||
<option value="12">12 words (~132 bits)</option>
|
||||
</select>
|
||||
<div class="form-text">More words = more security, harder to memorize</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-6 mb-3">
|
||||
<label class="form-label">PIN length</label>
|
||||
<select name="pin_length" class="form-select" id="pinSelect">
|
||||
<option value="6" selected>6 digits (~20 bits)</option>
|
||||
<option value="7">7 digits (~23 bits)</option>
|
||||
<option value="8">8 digits (~27 bits)</option>
|
||||
</select>
|
||||
<div class="form-text">Same PIN used every day</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="alert alert-info mb-4">
|
||||
<div class="d-flex justify-content-between align-items-center">
|
||||
<span><i class="bi bi-calculator me-2"></i>Estimated phrase+PIN entropy:</span>
|
||||
<strong id="entropyDisplay">~53 bits</strong>
|
||||
</div>
|
||||
<div class="progress mt-2" style="height: 8px;">
|
||||
<div class="progress-bar bg-success" id="entropyBar" style="width: 40%"></div>
|
||||
</div>
|
||||
<small class="text-muted mt-1 d-block">
|
||||
<span id="entropyDesc">Good for most use cases</span>
|
||||
• Reference photo adds ~80-256 bits more
|
||||
</small>
|
||||
</div>
|
||||
|
||||
<button type="submit" class="btn btn-primary btn-lg w-100">
|
||||
<i class="bi bi-shuffle me-2"></i>Generate New Credentials
|
||||
</button>
|
||||
</form>
|
||||
{% else %}
|
||||
|
||||
<div class="alert alert-warning">
|
||||
<i class="bi bi-exclamation-triangle me-2"></i>
|
||||
<strong>Memorize this information, then close this page!</strong>
|
||||
Do not save or screenshot. Refresh to generate new credentials.
|
||||
</div>
|
||||
|
||||
<div class="text-center mb-4">
|
||||
<h6 class="text-muted mb-2">YOUR STATIC PIN</h6>
|
||||
<div class="pin-display">{{ pin }}</div>
|
||||
<small class="text-muted">Use this {{ pin_length }}-digit PIN every day</small>
|
||||
</div>
|
||||
|
||||
<hr class="my-4">
|
||||
|
||||
<h6 class="text-muted mb-3">DAILY PHRASES ({{ words_per_phrase }} words each)</h6>
|
||||
|
||||
<div class="table-responsive">
|
||||
<table class="table table-dark table-hover">
|
||||
<thead>
|
||||
<tr>
|
||||
<th style="width: 120px;">Day</th>
|
||||
<th>Phrase</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{% for day in days %}
|
||||
<tr>
|
||||
<td>
|
||||
<i class="bi bi-calendar-day me-2"></i>{{ day }}
|
||||
</td>
|
||||
<td>
|
||||
<span class="phrase-display">{{ phrases[day] }}</span>
|
||||
</td>
|
||||
</tr>
|
||||
{% endfor %}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<div class="alert alert-success mt-4">
|
||||
<h6><i class="bi bi-shield-check me-2"></i>Security Summary</h6>
|
||||
<div class="row text-center mt-3">
|
||||
<div class="col-4">
|
||||
<div class="fs-4 fw-bold">{{ phrase_entropy }}</div>
|
||||
<small class="text-muted">bits/phrase</small>
|
||||
</div>
|
||||
<div class="col-4">
|
||||
<div class="fs-4 fw-bold">{{ pin_entropy }}</div>
|
||||
<small class="text-muted">bits/PIN</small>
|
||||
</div>
|
||||
<div class="col-4">
|
||||
<div class="fs-4 fw-bold text-success">{{ total_entropy }}</div>
|
||||
<small class="text-muted">bits total</small>
|
||||
</div>
|
||||
</div>
|
||||
<small class="d-block mt-2 text-center text-muted">
|
||||
+ reference photo (~80-256 bits) = <strong>{{ total_entropy + 80 }}+ bits combined</strong>
|
||||
</small>
|
||||
</div>
|
||||
|
||||
<div class="alert alert-info mt-4">
|
||||
<h6><i class="bi bi-lightbulb me-2"></i>Memorization Tip</h6>
|
||||
<p class="mb-1">
|
||||
<strong>Total to memorize:</strong> {{ words_per_phrase * 7 }} words + {{ pin_length }} digits
|
||||
</p>
|
||||
<p class="mb-0 small">
|
||||
Create a story for each day: "On Monday, the <em>[word1]</em> and <em>[word2]</em> went to see <em>[word3]</em>..."
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<a href="/generate" class="btn btn-outline-light btn-lg w-100 mt-3">
|
||||
<i class="bi bi-arrow-repeat me-2"></i>Generate New Credentials
|
||||
</a>
|
||||
|
||||
{% endif %}
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
|
||||
{% block scripts %}
|
||||
{% if not generated %}
|
||||
<script>
|
||||
function updateEntropy() {
|
||||
const words = parseInt(document.getElementById('wordsSelect').value);
|
||||
const pinLen = parseInt(document.getElementById('pinSelect').value);
|
||||
|
||||
const phraseEntropy = words * 11;
|
||||
const pinEntropy = Math.floor(pinLen * 3.32);
|
||||
const total = phraseEntropy + pinEntropy;
|
||||
|
||||
document.getElementById('entropyDisplay').textContent = '~' + total + ' bits';
|
||||
|
||||
// Update progress bar (scale: 50 bits = 40%, 150 bits = 100%)
|
||||
const pct = Math.min(100, Math.max(10, (total - 30) * 0.7));
|
||||
document.getElementById('entropyBar').style.width = pct + '%';
|
||||
|
||||
// Update description
|
||||
let desc;
|
||||
if (total < 50) desc = 'Basic security';
|
||||
else if (total < 70) desc = 'Good for most use cases';
|
||||
else if (total < 100) desc = 'Strong security';
|
||||
else if (total < 130) desc = 'Very strong security';
|
||||
else desc = 'Extreme security (hard to memorize!)';
|
||||
|
||||
document.getElementById('entropyDesc').textContent = desc;
|
||||
}
|
||||
|
||||
document.getElementById('wordsSelect').addEventListener('change', updateEntropy);
|
||||
document.getElementById('pinSelect').addEventListener('change', updateEntropy);
|
||||
</script>
|
||||
{% endif %}
|
||||
{% endblock %}
|
||||
108
templates/index.html
Normal file
108
templates/index.html
Normal file
@@ -0,0 +1,108 @@
|
||||
{% extends "base.html" %}
|
||||
|
||||
{% block title %}Stegasoo - Secure Steganography{% endblock %}
|
||||
|
||||
{% block content %}
|
||||
<div class="text-center mb-5">
|
||||
<i class="bi bi-shield-lock-fill hero-icon"></i>
|
||||
<h1 class="display-4 fw-bold mt-3">Stegasoo</h1>
|
||||
<p class="lead text-muted">Hide encrypted messages in plain sight using advanced steganography</p>
|
||||
</div>
|
||||
|
||||
<div class="row g-4 mb-5">
|
||||
<div class="col-md-4">
|
||||
<div class="card h-100 feature-card">
|
||||
<div class="card-header text-center py-3">
|
||||
<i class="bi bi-key-fill fs-1"></i>
|
||||
</div>
|
||||
<div class="card-body text-center">
|
||||
<h5 class="card-title">Generate Keys</h5>
|
||||
<p class="card-text text-muted">
|
||||
Create your weekly phrase card and PIN. Memorize 21 words + 6 digits for maximum security.
|
||||
</p>
|
||||
<a href="/generate" class="btn btn-primary">
|
||||
<i class="bi bi-plus-circle me-1"></i> Generate
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-4">
|
||||
<div class="card h-100 feature-card">
|
||||
<div class="card-header text-center py-3">
|
||||
<i class="bi bi-lock-fill fs-1"></i>
|
||||
</div>
|
||||
<div class="card-body text-center">
|
||||
<h5 class="card-title">Encode Message</h5>
|
||||
<p class="card-text text-muted">
|
||||
Hide your secret message inside an innocent-looking image using your phrase + PIN.
|
||||
</p>
|
||||
<a href="/encode" class="btn btn-primary">
|
||||
<i class="bi bi-upload me-1"></i> Encode
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="col-md-4">
|
||||
<div class="card h-100 feature-card">
|
||||
<div class="card-header text-center py-3">
|
||||
<i class="bi bi-unlock-fill fs-1"></i>
|
||||
</div>
|
||||
<div class="card-body text-center">
|
||||
<h5 class="card-title">Decode Message</h5>
|
||||
<p class="card-text text-muted">
|
||||
Extract and decrypt hidden messages from stego images using your credentials.
|
||||
</p>
|
||||
<a href="/decode" class="btn btn-primary">
|
||||
<i class="bi bi-download me-1"></i> Decode
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card">
|
||||
<div class="card-header">
|
||||
<h5 class="mb-0"><i class="bi bi-diagram-3 me-2"></i>How It Works</h5>
|
||||
</div>
|
||||
<div class="card-body">
|
||||
<div class="row">
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-primary"><i class="bi bi-1-circle me-2"></i>Key Components</h6>
|
||||
<ul class="list-unstyled">
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-image text-info me-2"></i>
|
||||
<strong>Reference Photo</strong> — Any photo you and recipient both have
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-chat-quote text-info me-2"></i>
|
||||
<strong>Day Phrase</strong> — 3 words, different each day of the week
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-123 text-info me-2"></i>
|
||||
<strong>Static PIN</strong> — 6 digits, same every day
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="col-md-6">
|
||||
<h6 class="text-primary"><i class="bi bi-2-circle me-2"></i>Security Features</h6>
|
||||
<ul class="list-unstyled">
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shield-check text-success me-2"></i>
|
||||
Argon2id memory-hard key derivation (256MB)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-shuffle text-success me-2"></i>
|
||||
Pseudo-random pixel selection (defeats steganalysis)
|
||||
</li>
|
||||
<li class="mb-2">
|
||||
<i class="bi bi-lock text-success me-2"></i>
|
||||
AES-256-GCM authenticated encryption
|
||||
</li>
|
||||
</ul>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
{% endblock %}
|
||||
0
uploads/.gitkeep
Normal file
0
uploads/.gitkeep
Normal file
Reference in New Issue
Block a user