Skip to content

Latest commit

 

History

16 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

  ____                   _    ____                  _
 / ___|  ___ __ _ _ __  / \  |  _ \ _ __ __ _ _ __ | |_
 \___ \ / __/ _` | '_ \ / _ \ | |_) | '__/ _` | '_ \| __|
  ___) | (_| (_| | | | / ___ \|  __/| | | (_| | |_) | |_
 |____/ \___\__,_|_| |_/_/   \_\_|   |_|  \__,_| .__/ \__|
                                               |_|

A live QR-code social-engineering demo. A QR code is just a URL encoded as pixels. ScanTrap shows an audience, in real time, how much an attacker can harvest from a single unverified scan. No typing, no visible prompt, nothing the target would notice.

Python Flask Socket.IO Status


How the demo works

  1. A QR code is projected on a screen. People scan it with their own phones.
  2. The landing page opens and silently collects a device fingerprint.
  3. One tap on "Verify my attendance" records consent and a location fix, using the venue coordinates baked into the page. No permission prompt.
  4. The "Guest WiFi" step captures whatever the visitor types in.
  5. The "Win Prizes" step asks for a camera check-in and a photo picker.
  6. Every event streams live to the operator dashboard over WebSocket.

Two screens: the projected QR page and the operator dashboard at /dashboard, behind a username and secret-key login.


What data points are collected

  • Passive, the moment the page loads: IP and ISP, approximate country and city, device model and OS version, browser and engine version, CPU cores, device memory, screen size and orientation, timezone, languages, battery state, network type and speed, WebGL/WebGPU adapter, audio sample rate, camera and microphone counts, storage quotas, permission states, Bluetooth/USB/Serial API availability, canvas fingerprint hash, LAN IPs leaked by WebRTC, and Client-Hints headers.
  • After "Verify my attendance": the venue coordinates baked into the QR link, recorded once as the target's location. No location permission is requested.
  • After tapping "Allow access": the target's recorded consent.
  • After typing into the WiFi form: the name, phone and email typed there.
  • After the camera check-in: a live front-camera feed and a simultaneous rear-camera feed, streamed frame by frame, plus the camera track settings (facing mode, resolution, frame rate, device ID).
  • From the photo picker: only the files the visitor actually picks are sent, with their names and sizes, and any EXIF they carry, including embedded GPS coordinates. Pixels are downscaled thumbnails only, and the browser's own picker is the final gate.
  • Clipboard: text read on a user gesture during the WiFi step, only if the browser allows it.

Operator credentials

The dashboard is protected by a username and secret key. Defaults, overridable with the DASH_USERNAME and DASH_SECRET environment variables:

Username Secret key
opsec scantrap-demo-2026

Run it

git clone https://github.com/nummbee01/scantrap.git
cd scantrap

python3 -m venv .venv
.venv/bin/pip install -r requirements.txt

# One-time self-signed cert (camera + clipboard need HTTPS on LAN IPs)
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes

.venv/bin/python app.py --tls

Environment variables:

Variable Default Purpose
PORT 5000 HTTP port
HOST 0.0.0.0 Bind address
EVENT_NAME DemoCon 2026 Event name shown on pages
QR_BASE_URL auto-detected Public base for QR links
DASH_USERNAME opsec Dashboard login username
DASH_SECRET scantrap-demo-2026 Dashboard login secret
VENUE_LAT / VENUE_LON / VENUE_NAME Softwarica College, Kathmandu The fixed venue location

Pages: http://<laptop-ip>:5000/ (QR screen), /disclosure (consent screen), and /dashboard (operator terminal).


Disclaimer

This is an awareness demo, not a tool. It runs inside the browser and only collects data the browser hands over voluntarily. Before anyone scans, show /disclosure on the projector so the room knows what is being demonstrated and that scanning is their choice.

  • Everything is stored in memory. The dashboard's "wipe sessions" button clears it instantly; a restart wipes everything.
  • The WiFi step uses a made-up network (DemoEvent-WiFi) and mimics no real brand.
  • Targets are shown as SCAN-01, SCAN-02, never tied to a name.
  • Only run this against people who agreed to take part.

ScanTrap v1.0 · Flask + Flask-SocketIO + qrcode + vanilla JS · no database, sessions live in memory only.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages