____ _ ____ _
/ ___| ___ __ _ _ __ / \ | _ \ _ __ __ _ _ __ | |_
\___ \ / __/ _` | '_ \ / _ \ | |_) | '__/ _` | '_ \| __|
___) | (_| (_| | | | / ___ \| __/| | | (_| | |_) | |_
|____/ \___\__,_|_| |_/_/ \_\_| |_| \__,_| .__/ \__|
|_|
A live QR-code social-engineering demo. A QR code is just a URL encoded as pixels. ScanTrap shows an audience, in real time, how much an attacker can harvest from a single unverified scan. No typing, no visible prompt, nothing the target would notice.
- A QR code is projected on a screen. People scan it with their own phones.
- The landing page opens and silently collects a device fingerprint.
- One tap on "Verify my attendance" records consent and a location fix, using the venue coordinates baked into the page. No permission prompt.
- The "Guest WiFi" step captures whatever the visitor types in.
- The "Win Prizes" step asks for a camera check-in and a photo picker.
- Every event streams live to the operator dashboard over WebSocket.
Two screens: the projected QR page and the operator dashboard at /dashboard,
behind a username and secret-key login.
- Passive, the moment the page loads: IP and ISP, approximate country and city, device model and OS version, browser and engine version, CPU cores, device memory, screen size and orientation, timezone, languages, battery state, network type and speed, WebGL/WebGPU adapter, audio sample rate, camera and microphone counts, storage quotas, permission states, Bluetooth/USB/Serial API availability, canvas fingerprint hash, LAN IPs leaked by WebRTC, and Client-Hints headers.
- After "Verify my attendance": the venue coordinates baked into the QR link, recorded once as the target's location. No location permission is requested.
- After tapping "Allow access": the target's recorded consent.
- After typing into the WiFi form: the name, phone and email typed there.
- After the camera check-in: a live front-camera feed and a simultaneous rear-camera feed, streamed frame by frame, plus the camera track settings (facing mode, resolution, frame rate, device ID).
- From the photo picker: only the files the visitor actually picks are sent, with their names and sizes, and any EXIF they carry, including embedded GPS coordinates. Pixels are downscaled thumbnails only, and the browser's own picker is the final gate.
- Clipboard: text read on a user gesture during the WiFi step, only if the browser allows it.
The dashboard is protected by a username and secret key. Defaults, overridable
with the DASH_USERNAME and DASH_SECRET environment variables:
| Username | Secret key |
|---|---|
opsec |
scantrap-demo-2026 |
git clone https://github.com/nummbee01/scantrap.git
cd scantrap
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
# One-time self-signed cert (camera + clipboard need HTTPS on LAN IPs)
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
.venv/bin/python app.py --tlsEnvironment variables:
| Variable | Default | Purpose |
|---|---|---|
PORT |
5000 |
HTTP port |
HOST |
0.0.0.0 |
Bind address |
EVENT_NAME |
DemoCon 2026 |
Event name shown on pages |
QR_BASE_URL |
auto-detected | Public base for QR links |
DASH_USERNAME |
opsec |
Dashboard login username |
DASH_SECRET |
scantrap-demo-2026 |
Dashboard login secret |
VENUE_LAT / VENUE_LON / VENUE_NAME |
Softwarica College, Kathmandu | The fixed venue location |
Pages: http://<laptop-ip>:5000/ (QR screen), /disclosure (consent
screen), and /dashboard (operator terminal).
This is an awareness demo, not a tool. It runs inside the browser and only
collects data the browser hands over voluntarily. Before anyone scans, show
/disclosure on the projector so the room knows what is being demonstrated
and that scanning is their choice.
- Everything is stored in memory. The dashboard's "wipe sessions" button clears it instantly; a restart wipes everything.
- The WiFi step uses a made-up network (
DemoEvent-WiFi) and mimics no real brand. - Targets are shown as
SCAN-01,SCAN-02, never tied to a name. - Only run this against people who agreed to take part.
ScanTrap v1.0 · Flask + Flask-SocketIO + qrcode + vanilla JS · no database, sessions live in memory only.