针对任何 IP、域名或 ASN 的 OSINT 情报
如果这个项目对你的工作有帮助,请支持持续的维护和新功能。
ETH 捐赠钱包
0x11282eE5726B3370c8B480e321b3B2aA13686582
扫描二维码或复制上面的钱包地址。
统一的主机情报,涵盖 15 个来源 — 查询任何 IP、域名或 ASN,获取即时安全态势、基础设施详情和威胁关联信息。完全在 Cloudflare 免费套餐上运行。
在线访问: swiy.co/seekyou``` $ curl "https://seekyou.seekyou.workers.dev/api/lookup?q=1.1.1.1"
{ "query": { "raw": "1.1.1.1", "type": "ip", "normalised": "1.1.1.1" }, "core": { "internetdb": { "status": "ok", "data": { "ports": [80,443], "vulns": [] } }, "geo": { "status": "cached", "data": { "country": "US", "org": "AS13335 Cloudflare" } }, "bgp": { "status": "ok", "data": { "name": "CLOUDFLARENET", "rir": "ARIN" } }, ... }, "meta": { "durationMs": 312, "cacheHits": 4, "sourcesQueried": 15, "sourcesFailed": 0 } }
## 截图
<div align="center">
### 首页
<img src="https://assets.kitploit.com/production/public/readmes/7467/e00ec4ba8b3e5460ae1e03360cf6540e58d92acc5522c8693445512b591fed29.png" alt="SeekYou 结果页" width="800" />
### 结果页
<img src="https://assets.kitploit.com/production/public/readmes/7467/09b165feca9927ad4cd50c3ebd28c72e09a0355d72b9ca14d795bf1d04448c92.png" alt="SeekYou 首页" width="800" />
### 演示
<a href="https://www.youtube.com/watch?v=b86tAUUqd34">
<img src="https://assets.kitploit.com/production/public/readmes/7467/8762e8b464816b9a69d929514441f8c7ee9f9ee9719f95b9c5e33ac1672575f8.jpg" alt="SeekYou 演示" width="800" />
</a>
</div>
---
## 目录
- [SeekYou](#seekyou)
- [截图](#screenshots)
- [首页](#landing-page)
- [结果页](#results-page)
- [演示](#demo)
- [目录](#table-of-contents)
- [SeekYou 的功能](#what-seekyou-does)
- [使用场景](#use-cases)
- [合法使用政策](#lawful-use-policy)
- [相关工具](#related-tools)
- [架构概览](#architecture-overview)
- [执行模型](#execution-model)
- [数据源](#data-sources)
- [项目结构](#project-structure)
- [关键设计决策](#key-design-decisions)
- [优先边缘计算,无需 Node.js](#edge-first-no-nodejs)
- [分层并行执行](#layered-parallel-execution)
- [优雅降级](#graceful-degradation)
- [分离 D1 与 KV 存储](#split-d1--kv-storage)
- [免费层优化](#free-tier-optimization)
- [即发即弃的 D1 写入](#fire-and-forget-d1-writes)
- [缓存策略](#caching-strategy)
- [速率限制](#rate-limiting)
- [断路器](#circuit-breakers)
- [密钥轮换 — GrayHatWarfare](#key-rotation--grayhatwarfare)
- [D1 持久化](#d1-persistence)
- [模式 (`schema.sql`)](#schema-schemasql)
- [应用模式](#apply-schema)
- [辅助函数](#helper-functions)
- [Cron 工作器](#cron-worker)
- [类型化差异 (`lib/diff.ts`)](#typed-diff-libdiffts)
- [Webhook 负载](#webhook-payload)
- [开发环境配置](#development-setup)
- [前提条件](#prerequisites)
- [本地开发](#local-development)
- [创建 Cloudflare 资源(首次)](#create-cloudflare-resources-first-time)
- [部署](#deployment)
- [构建并部署](#build-and-deploy)
- [Wrangler 配置 (`wrangler.toml`)](#wrangler-configuration-wranglertoml)
- [密钥与环境变量](#secrets-and-environment-variables)
- [必需密钥](#required-secrets)
- [`.env.example`(仅本地开发)](#envexample-local-dev-only)
- [许可证](#license)
- [作者](#author)
- [致谢](#acknowledgments)
---
## SeekYou 的功能
SeekYou 是一个**主机情报工具**——输入 IP 地址、域名或 ASN,即可获得涵盖以下内容的统一报告:
| 类别 | 涵盖内容 |
|---|---|
| 网络 | 开放端口、CPE、BGP 前缀、上游、对等体、RIR |
| 身份 | RDAP 注册、联系人、注册商、域名服务器 |
| 地理位置 | 国家、城市、ISP、代理/托管/移动标识 |
| 证书 | crt.sh 历史、SAN、颁发者链 |
| DNS | 被动 DNS 记录、Robtex 反向/正向 DNS |
| 威胁 | URLhaus、ThreatFox、MalwareBazaar、Feodo、SSLBL |
| CVE | 针对 InternetDB 报告的每个 CVE ID 进行 NVD + CIRCL 丰富 |
| 侦察 | GrayHatWarfare 暴露的存储桶、Wayback CDX 快照 |
每个来源并行查询。故障来源会降级为“不可用”徽章——绝不会破坏页面。
---
## 使用场景
**安全运维** — 从日志中快速分析可疑 IP,关联 IOC,识别暴露的服务和 CVE,追踪恶意域名。
**网络运维** — 检查 BGP 路由、RDAP/WHOIS 分配数据、历史 DNS 记录、SSL 证书变更。
**渗透测试** — 枚举端口/服务/CPE,发现暴露的存储桶、归档页面、子域名和 ASN 关系。
**威胁情报** — 一次查询即可检查 C2 基础设施与五个威胁情报源。
**合规与风险** — 分析供应商基础设施,检测暴露的云存储,识别影子 IT。
---
## 合法使用政策
SeekYou 旨在用于**合法的安全研究、网络运维和威胁情报**。使用本工具即表示您同意:
**允许的用途:**
- 对您拥有或授权监控的网络进行安全运维和事件响应
- 威胁情报研究与 IOC 关联
- 组织内部的网络故障排除与基础设施审计
- 经目标组织明确书面授权的渗透测试
- 网络安全学术研究与教育
- 经适当授权的合规审计与供应商风险评估
**禁止的用途:**
- 未经授权访问、侦察或攻击您不拥有或明确允许测试的系统
- 骚扰、跟踪或侵犯个人或组织的隐私
- 促进非法活动,包括欺诈、身份盗窃或网络犯罪
- 未经授权绕过安全控制或访问限制
- 违反适用法律,包括美国 CFAA、英国计算机滥用法、欧盟 GDPR 或您所在司法管辖区的同等法律
**您的责任:**
- 确保在查询不属于自己的基础设施前获得适当授权
- 尊重速率限制,不滥用服务或上游数据源
- 遵守您所在司法管辖区的所有适用法律
- 负责任地使用数据,未经协调披露不得将发现武器化
- 理解查询主机并不授予访问或利用它的权限
**免责声明:**
作者和贡献者不对本工具的滥用承担任何责任。用户自行负责确保其活动符合适用法律。从公开来源聚合的数据可能不完整、过时或不准确——在采取行动前请务必通过权威渠道验证。
如果您通过 SeekYou 发现漏洞,请遵循负责任的披露实践,在公开披露前通知受影响方。
---
## 相关工具
SeekYou 是注重隐私的安全工具包的一部分。探索完整套件:
| 工具 | 描述 | 在线链接 |
|---|---|---|
| **TimeSeal** | 加密时间戳服务——在不泄露内容的情况下证明文档在特定时间存在 | [timeseal.online](https://timeseal.online) |
| **SanctumVault** | 零知识加密保管库——针对敏感数据存储的客户端加密 | [sanctumvault.online](https://sanctumvault.online) |
| **GhostChat** | 短暂加密消息——自毁对话,无服务器日志 | [ghost-chat.pages.dev](https://ghost-chat.pages.dev) |
| **XMRProof** | 门罗币支付验证——生成 XMR 交易的加密证明 | [xmrproof.pages.dev](https://xmrproof.pages.dev) |
| **GhostReceipt** | 匿名收据生成——在不暴露身份的情况下创建可验证的交易记录 | [ghostreceipt.pages.dev](https://ghostreceipt.pages.dev) |
| **SeekYou** | 主机情报聚合器——对 IP、域名和 ASN 的 15 个来源进行统一 OSINT | [seekyou.seekyou.workers.dev](https://seekyou.seekyou.workers.dev) |
| **HoneypotScan** | 蜜罐检测服务——识别诱饵系统,避免安全研究中的误报 | [honeypotscan.pages.dev](https://honeypotscan.pages.dev) |
所有工具均运行在 Cloudflare 边缘网络上,遵循隐私优先的设计原则。
---
## 架构概览```
Browser / curl
│
▼
┌─────────────────────────────────────┐
│ Cloudflare Pages │
│ Next.js App Router (SSR) │
│ │
│ app/page.tsx search form │
│ app/host/[query]/page.tsx │
│ └─ streams /api/stream?q=… │
│ app/api/recent/route.ts │
│ └─ recent searches for homepage │
│ app/targets/page.tsx │
│ └─ monitoring dashboard │
│ app/api/targets/route.ts │
│ └─ saved targets CRUD │
│ returns riskScore + lastDiff │
└──────────────┬──────────────────────┘
│
▼
┌─────────────────────────────────────┐
│ app/api/lookup/route.ts │
│ (Workers runtime via opennextjs) │
│ • input validation │
│ • per-IP rate limiting (KV) │
│ • ctx.waitUntil(recordSearch()) │
└──────────────┬──────────────────────┘
│ runLookup()
▼
┌─────────────────────────────────────┐
│ worker/lookup.ts — orchestrator │
│ 4-layer Promise.allSettled │
└──┬──────────────────────────────────┘
│
├─► Layer 1+2 (parallel, 12 sources):
│ InternetDB · IPinfo · RIPE stat · RDAP · crt.sh · HackerTarget · Robtex
│ URLhaus · ThreatFox · MalwareBazaar · Feodo · SSLBL
├─► Layer 3 (after L1): NVD CVE enrichment (only if vulns found, batched 10-at-a-time)
└─► Layer 4 (parallel): GrayHatWarfare · Wayback (domain queries only)
│
▼
┌──────────────────────┐ ┌──────────────────────┐
│ D1 │ │ KV │
│ source response cache│ │ rate limiting │
│ (TTL per source) │ │ circuit breakers │
│ searches │ │ concurrency counters │
│ saved_targets │ │ │
└──────────────────────┘ └──────────────────────┘
│
▼
┌─────────────────────────────────────┐
│ seekyou-cron (Worker) │
│ wrangler.cron.toml │
│ • hourly blocklist refresh │
│ • hourly saved-target re-query │
│ + typed diff (lib/diff.ts) │
│ + webhook on hasChanges │
└─────────────────────────────────────┘
第1层和第2层同时触发(一个Promise.allSettled中包含12个数据源)。第3层在第1层完成后启动——来自InternetDB的CVE ID驱动NVD丰富化处理,每次批量处理10个以避免对API造成冲击。第4层与第3层并行触发,但仅用于域名查询;IP/ASN完全跳过。总墙上时钟时间 ≈ max(第1+2层) + max(第3+4层)。
使用?refresh=1强制刷新任何查询,以绕过D1缓存并从每个上游获取实时数据。
Feodo and SSLBL 作为批量黑名单获取,并由cron任务每小时刷新——无需每次查询都调用上游。
SeekYou/ ├── app/ │ ├── page.tsx # Homepage — search form + recent searches │ ├── layout.tsx # Root layout │ ├── globals.css │ ├── about/ # About page │ ├── faq/ # FAQ page │ ├── targets/ │ │ └── page.tsx # /targets — monitoring dashboard (risk + diffs) │ ├── host/[query]/ │ │ └── page.tsx # SSR host report page (streams via /api/stream) │ ├── api/ │ │ ├── lookup/route.ts # GET /api/lookup?q=&refresh=1 │ │ ├── stream/route.ts # GET /api/stream?q= (SSE streaming) │ │ ├── recent/route.ts # GET /api/recent?limit=5 │ │ ├── batch/route.ts # POST /api/batch (multi-query) │ │ ├── targets/route.ts # GET /api/targets (+ riskScore, lastDiff) · POST │ │ ├── targets/[id]/route.ts # DELETE /api/targets/:id │ │ └── admin/reset-breaker/ # POST — manual circuit-breaker reset │ └── components/ │ ├── AnimatedTagline.tsx │ ├── Card.tsx │ ├── CopyButton.tsx │ ├── CveDrawer.tsx │ ├── DecryptedText.tsx │ ├── ExportButton.tsx # JSON export (client, zero backend) │ ├── Footer.tsx │ ├── RecentSearches.tsx # Recent queries from D1 (client) │ ├── RiskBadge.tsx # Risk score pill with breakdown tooltip │ ├── SaveButton.tsx # Save/unsave target │ ├── ScrollProgress.tsx │ ├── ShareButton.tsx │ ├── VulnsStream.tsx # Streaming CVE results │ └── ui/ # Shared UI primitives ├── worker/ │ ├── lookup.ts # 4-layer orchestrator │ ├── cron.ts # Hourly blocklist refresh + target sweep w/ typed diff │ ├── index.ts │ └── sources/ │ ├── internetdb.ts │ ├── ipapi.ts │ ├── bgpview.ts │ ├── rdap.ts │ ├── crtsh.ts │ ├── passivedns.ts │ ├── robtex.ts │ ├── abusech.ts # URLhaus + ThreatFox + MalwareBazaar │ ├── nvd.ts # NVD + CIRCL CVE enrichment │ ├── osv.ts # OSV.dev re-export (via nvd.ts) │ ├── grayhatwarfare.ts │ └── wayback.ts ├── lib/ │ ├── types.ts # All TypeScript interfaces │ ├── cache.ts # D1 cache wrapper (cacheGet/cachePut, bypass on forceRefresh) │ ├── config.ts # All magic numbers: TTLs, timeouts, limits │ ├── diff.ts # TargetDiff — typed change detection between snapshots │ ├── errors.ts # Unified error format + ErrorCode enum │ ├── hooks.ts # Shared React hooks │ ├── keyring.ts # GHW 18-key rotation │ ├── logger.ts # Structured logging │ ├── merge.ts # Result merging │ ├── normalize.ts # Threat indicator normalization │ ├── ratelimit.ts # KV-based per-IP rate limiter + circuit breakers │ ├── results.ts # SourceResult helpers │ ├── risk.ts # computeRiskScore — scored 0–100 with breakdown │ ├── searches.ts # D1 helpers: recordSearch, getRecentSearches │ ├── targets.ts # D1 helpers: saveTarget, listTargets, removeTarget │ ├── textAnimation.ts # Text animation utility │ ├── useHostStream.ts # SSE streaming hook for host results │ ├── validate.ts # Query parsing (IPv4/v6/domain/ASN) │ └── utils.ts ├── test/ │ ├── cache.test.ts │ ├── diff.test.ts # Tests for diffHostResults + summariseDiff │ ├── keyring.test.ts │ ├── logger.test.ts │ ├── merge.test.ts │ ├── normalize.test.ts │ ├── results.test.ts │ ├── risk.test.ts │ ├── validate.test.ts │ └── sources/ ├── docs/ │ ├── ROADMAP.md │ ├── Spec.md │ └── LICENSE.md ├── public/ │ └── publiceth.svg # Donation QR code ├── schema.sql # D1 schema (apply with wrangler d1 execute) ├── wrangler.toml # Pages build config (KV + D1 bindings) ├── wrangler.cron.toml # Cron worker config (separate deploy) ├── next.config.ts ├── open-next.config.ts └── vitest.config.ts
---
## 关键设计决策
### 边缘优先,无Node.js
通过 `@opennextjs/cloudflare` 的工作器运行时 — 无需 `runtime = 'edge'` 导出。全程使用纯 Web API。全球冷启动时间低于 50 毫秒。
### 分层并行执行
第 1 层和第 2 层一起触发(共 12 个来源)。第 3 层(CVE 丰富化)仅在 InternetDB 发现漏洞时运行,每次批处理 10 个。第 4 层(GHW + Wayback)与第 3 层并行运行,但对于 IP/ASN 查询完全跳过。总时间 ≈ 每波中最慢的来源,而不是所有来源的总和。
### 优雅降级
每个来源都被包裹在断路器 + try/catch 中。失败的来源会变成 `{ status: 'error' }` 徽章。页面始终渲染。
### 拆分 D1 + KV 存储
源响应缓存存储在 **D1** 中(而非 KV)— 值只写入一次,偶尔读取,并且足够大以至于 KV 的写入配额成本会迅速增加。**KV** 仅保留用于热路径计数器:速率限制、断路器和正在进行的并发跟踪。每个来源都有自己的 TTL(CVE 为 30 天,BGP/RDAP 为 24 小时,核心地理/端口为 1 小时,abuse.ch 为 30 分钟)。`?refresh=1` 通过每个获取器传递 `forceRefresh: true` 以按需绕过 D1 缓存。
### 免费层优化
GrayHatWarfare 有 18 个密钥轮换(每天 1,800 个请求)。NVD 使用请求批处理(最多 10 个并发)。Feodo/SSLBL 由 cron 工作器以批量列表方式获取并缓存到 KV 中 — 每次查询的上游成本为零。
### 即发即弃的 D1 写入
`recordSearch()` 在 `ctx.waitUntil()` 中调用 — 它不会增加 API 响应的延迟。D1 写入在响应刷新后进行。
---
## 缓存策略
源响应缓存在 **D1** 中,通过 `expires_at` 列强制执行手动 TTL。KV 不用于响应缓存 — 它保留用于速率限制、断路器和正在进行的并发计数器,这些场景需要低延迟原子增量。```typescript
// lib/cache.ts
export async function cacheGet<T>(
db: D1Database,
key: string,
bypass?: boolean, // true when ?refresh=1
): Promise<T | null>
export async function cachePut<T>(
db: D1Database,
key: string,
value: T,
ttl: number, // seconds
): Promise<void>
缓存键遵循模式 source:normalised_query — 例如 internetdb:1.1.1.1、crtsh:example.com。
按来源的TTL(来自 lib/cache.ts):
错误从不缓存 — 失败的请求会在下一次请求时重新尝试。过期的行作为未命中返回,并惰性覆盖;无需后台清理。
基于KV的滑动窗口:每个IP每小时100个请求。在 lib/ratelimit.ts 中实现,在 app/api/lookup/route.ts 中执行,在每次查询运行之前执行。
每个响应都会返回速率限制头:``` X-RateLimit-Limit: 100 X-RateLimit-Remaining: 87 X-RateLimit-Reset: 1716912000
当耗尽时,API 返回 `429` 及 `Retry-After`。
---
## 断路器
每个来源都有一个在 KV 中跟踪的断路器。如果某个来源在 5 分钟窗口内(至少 4 个请求)超过 **50% 的故障率**,断路器将断开,该来源被跳过(返回 `{ status: 'skipped' }`)持续 **15 分钟**,然后自动恢复。
每个 API 响应中都包含所有断路器的当前状态,位于 `meta.circuitBreakers` 中。
要在生产环境中手动重置断路器:```bash
curl -X POST https://seekyou.seekyou.workers.dev/api/admin/reset-breaker \
-H "Authorization: Bearer $ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"source": "nvd"}'
GrayHatWarfare 允许每个 API 密钥每天 100 次请求。SeekYou 可轮换多达 18 个密钥,实际有效请求量为每天 1,800 次:```typescript // lib/keyring.ts — round-robin across keys with remaining quota const key = await keyRing.next(env, 'GRAYHATWARFARE_API_KEY')
密钥命名为 `GRAYHATWARFARE_API_KEY_1` 至 `GRAYHATWARFARE_API_KEY_18`,并作为 Wrangler secrets 存储。
---
## D1 持久化
### 模式(`schema.sql`)```sql
CREATE TABLE IF NOT EXISTS searches (
id TEXT PRIMARY KEY DEFAULT (lower(hex(randomblob(8)))),
query TEXT NOT NULL,
query_type TEXT NOT NULL CHECK (query_type IN ('ip','domain','asn')),
result_json TEXT NOT NULL,
duration_ms INTEGER,
created_at INTEGER NOT NULL DEFAULT (unixepoch())
);
CREATE INDEX IF NOT EXISTS idx_searches_query
ON searches (query, created_at DESC);
CREATE TABLE IF NOT EXISTS saved_targets (
id TEXT PRIMARY KEY DEFAULT (lower(hex(randomblob(8)))),
query TEXT NOT NULL UNIQUE,
label TEXT,
notes TEXT,
result_json TEXT, -- snapshot of last cron lookup
checked_at INTEGER, -- unix seconds — when cron last re-queried
created_at INTEGER NOT NULL DEFAULT (unixepoch())
);
CREATE INDEX IF NOT EXISTS idx_saved_targets_created
ON saved_targets (created_at DESC);
wrangler d1 execute seekyou --file=schema.sql
### Helper functions
**`lib/searches.ts`** — 搜索历史:```typescript
// Write a search row (fire-and-forget safe)
await recordSearch(db, query, queryType, resultJson, durationMs)
// Read last N distinct queries for the homepage (default 5)
const recent = await getRecentSearches(db, 5)
// → [{ query: '1.1.1.1', query_type: 'ip', created_at: 1716912000 }, ...]
lib/targets.ts — 已保存的目标:```typescript
// Upsert a target (idempotent on query)
const id = await saveTarget(db, query, label, notes)
// List all saved targets const targets = await listTargets(db)
// Remove by id await removeTarget(db, id)
// Fetch one (used by cron before re-querying) const target = await getTarget(db, id)
// Write latest snapshot after cron re-query await updateTargetSnapshot(db, id, resultJson)
---
## Cron 工作线程
一个独立的工作线程 (`worker/cron.ts`) 通过 `wrangler.cron.toml` 单独部署。它基于**每小时触发器**运行,并执行两个任务:
1. **黑名单刷新** — 检查 Feodo/SSLBL 批量列表是否过期,并在需要时重新下载。
2. **已保存目标扫描** — 对每个已保存的目标重新查询,计算带有类型信息的 `TargetDiff`,将最新的快照持久化到 D1,并在检测到变化时发送 webhook 负载。
### 类型化差异 (`lib/diff.ts`)
每次重新查询后,`diffHostResults(prev, next)` 会生成结构化的 `TargetDiff`,涵盖以下内容:
| 信号 | 检测内容 |
|---|---|
| `ports` | 打开/关闭的端口(每个端口的方向) |
| `cves` | 出现/解决的 CVE,附带 CVSS 严重性和评分 |
| `threats` | URLhaus、Feodo、SSLBL、ThreatFox 源的变化 |
| `geo` | 国家、ASN 或主要主机名变更 |
| `certExpiry` | 30 天内到期或新近过期的证书(每个证书触发一次) |
| `risk` | 风险评分变化 — 仅在 Δ ≥ 5 分时于 `hasChanges` 中体现 |
`summariseDiff(diff, query)` 将结构转换为人类可读的字符串,用于日志和 webhook 转发。
### Webhook 负载
当 `diff.hasChanges` 为真且设置了 `WEBHOOK_URL` 时,cron 会 POST 以下内容:```json
{
"sentAt": 1716912000,
"events": [
{
"targetId": "abc123",
"query": "1.2.3.4",
"checkedAt": 1716912000,
"summary": "1.2.3.4:\n port 3389 opened\n CVE-2021-44228 appeared [CRITICAL 10]",
"diff": {
"diffedAt": 1716912000,
"hasChanges": true,
"ports": [{ "port": 3389, "direction": "opened" }],
"cves": [{ "id": "CVE-2021-44228", "direction": "appeared", "severity": "CRITICAL", "score": 10 }],
"threats": [],
"geo": [],
"certExpiry": [],
"risk": { "prev": 20, "next": 55, "delta": 35 }
}
}
]
}
diff 字段是完全结构化的——消费者可以根据特定的变更类型进行分支,而无需解析字符串行。summary 字段预先格式化为 Slack/Discord 转发。
部署 cron 工作器:```bash wrangler deploy --config wrangler.cron.toml
Cron 工作器的密钥是单独设置的:```bash
wrangler secret put NVD_KEY --config wrangler.cron.toml
wrangler secret put ABUSECH_KEY --config wrangler.cron.toml
wrangler secret put WEBHOOK_URL --config wrangler.cron.toml # optional — fires on any hasChanges
npm i -g wrangler)git clone https://github.com/Teycir/SeekYou cd SeekYou npm install
cp .env.example .env
npm run dev
该应用程序可在 `http://localhost:3000` 访问。在本地开发中,KV 和 D1 使用 Wrangler 的本地 SQLite 支持模拟——基本测试无需 Cloudflare 账户访问。
### 创建 Cloudflare 资源(首次)```bash
# Create KV namespace — copy the ID into wrangler.toml
wrangler kv namespace create KV
# Create D1 database — copy the ID into wrangler.toml
wrangler d1 create seekyou
# Apply schema
wrangler d1 execute seekyou --file=schema.sql
bash scripts/deploy.sh
该脚本运行 `opennextjs-cloudflare build`,准备 Pages 输出目录,并调用 `wrangler pages deploy .open-next`。**不要**使用 `npm run deploy` 或单独的 `wrangler deploy`——这些命令针对 Workers(非 Pages)运行时,将会失败。
要单独部署 cron worker:```bash
wrangler deploy --config wrangler.cron.toml
wrangler.toml)```tomlname = "seekyou" pages_build_output_dir = ".open-next" compatibility_date = "2025-05-01" compatibility_flags = ["nodejs_compat"]
[[kv_namespaces]] binding = "KV" id = ""
[[d1_databases]] binding = "DB" database_name = "seekyou" database_id = ""
---
## 机密与环境变量
所有机密均以 Wrangler 机密的形式存储——绝不存储在源代码或 `.env` 文件中。
### 必需的机密```bash
wrangler secret put NVD_KEY # NVD API key (optional — higher rate limits)
wrangler secret put ABUSECH_KEY # abuse.ch API key (URLhaus/ThreatFox/MalwareBazaar)
wrangler secret put ADMIN_TOKEN # Bearer token for /api/admin/* endpoints
# GrayHatWarfare — repeat for each key you have (1–18)
wrangler secret put GRAYHATWARFARE_API_KEY_1
wrangler secret put GRAYHATWARFARE_API_KEY_2
# ... up to GRAYHATWARFARE_API_KEY_18
.env.example(仅限本地开发)```bashNVD_KEY=your_nvd_key_here ABUSECH_KEY=your_abusech_key_here ADMIN_TOKEN=change_me GRAYHATWARFARE_API_KEY_1=your_ghw_key_here
> **安全提示:** 切勿提交 `.env` 文件。已将其加入 `.gitignore`。如果密钥曾被提交过,请轮换所有密钥并使用 BFG 清理 Git 历史记录(`bfg --delete-files .env`)。
---
## 许可证
**商业源码许可证 1.1 (BSL)**
版权所有 © 2026 Teycir Ben Soltane <[email protected]>
允许:个人使用、研究、教育、非商业项目、内部业务工具。
限制:商业 SaaS 服务、转售服务、竞争性产品。
自发布之日起 4 年后,本软件将转换为 Apache 2.0 许可。
完整条款见 [docs/LICENSE.md](https://github.com/teycir/seekyou/blob/master/docs/LICENSE.md)。
---
## 作者
**Teycir Ben Soltane**
邮箱:[email protected]
GitHub:[@Teycir](https://github.com/Teycir)
---
## 致谢
- [InternetDB](https://internetdb.shodan.io) (Shodan)
- [IPinfo](https://ipinfo.io)
- [RIPE stat](https://stat.ripe.net)
- [RDAP](https://rdap.org)
- [crt.sh](https://crt.sh)
- [HackerTarget](https://hackertarget.com)
- [Robtex](https://www.robtex.com)
- [abuse.ch](https://abuse.ch) — URLhaus、ThreatFox、MalwareBazaar、Feodo、SSLBL
- [NVD](https://nvd.nist.gov) (NIST)
- [CIRCL](https://www.circl.lu/services/cve-search/)
- [OSV.dev](https://osv.dev)
- [GrayHatWarfare](https://grayhatwarfare.com)
- [Internet Archive](https://web.archive.org) (Wayback Machine)
---
## 🌐 相关项目
探索更多注重隐私和安全的工具:
### 隐私与加密
- **[Timeseal](https://github.com/Teycir/Timeseal)** — 具有死神开关功能的定时锁定加密保险库。AES-256 分割密钥加密,临时印章。
- **[Sanctum](https://github.com/Teycir/Sanctum)** — 零信任加密保险库,支持密码学可行否认性。采用 XChaCha20-Poly1305、Argon2id。
- **[GhostChat](https://github.com/Teycir/GhostChat)** — 基于 WebRTC 的真正点对点加密聊天。无服务器、无存储、消息自毁。
- **[xmrproof](https://github.com/Teycir/xmrproof)** — 门罗币支付验证,完全客户端执行。
- **[GhostReceipt](https://github.com/Teycir/GhostReceipt)** — 使用零知识证明的匿名收据生成。
### 安全工具
- **[BurpAPISecuritySuite](https://github.com/Teycir/BurpAPISecuritySuite)** — 用于 API 安全测试的 Burp Suite 扩展。15 种攻击类型、108 个以上载荷、BOLA/IDOR 检测。
- **[Mcpwn](https://github.com/Teycir/Mcpwn)** — 针对 Model Context Protocol 服务器的自动化安全扫描器。可检测 RCE、路径遍历、提示注入。
- **[DiffCatcher](https://github.com/Teycir/DiffCatcher)** — Git 仓库发现、差异捕获、代码元素提取。
- **[HoneypotScan](https://github.com/Teycir/HoneypotScan)** — 用于安全研究的蜜罐检测服务。
- **[CheckAPI](https://github.com/Teycir/CheckAPI)** — 支持多个提供商的 LLM API 密钥验证器。隐私优先,客户端验证。
### MCP 安全服务器
- **[burp-mcp-server](https://github.com/Teycir/burp-mcp-server)** — 用于 Burp Suite Professional 的 MCP 服务器。通过 AI 助手进行漏洞扫描。
- **[nuclei-mcp](https://github.com/Teycir/nuclei-mcp)** — 用于 Nuclei 的 MCP 服务器。多目标扫描,严重级别过滤。
- **[nmap-mcp](https://github.com/Teycir/nmap-mcp)** — 用于 Nmap 的 MCP 服务器。隐蔽侦查、漏洞/NSE 扫描。
- **[frida-mcp](https://github.com/Teycir/frida-mcp)** — 用于 Frida 的 MCP 服务器。动态插桩、SSL 证书固定绕过。
---
## 💼 提供的服务
- 🔒 **隐私优先开发** — P2P 应用、加密通信、零知识系统
- 🚀 **Web 应用开发** — 基于 Next.js、React、TypeScript 的全栈开发
- 🔧 **边缘计算解决方案** — Cloudflare Workers、Pages、D1、KV、Durable Objects
- 🛡️ **安全工具开发** — Burp 扩展、渗透测试工具、自动化框架
- 🤖 **AI 集成** — 基于 LLM 的应用、智能自动化、定制 AI 解决方案
- 🔍 **OSINT 与威胁情报** — 定制侦察工具、威胁情报源聚合、IOC 关联
**联系方式**: [teycirbensoltane.tn](https://teycirbensoltane.tn) | 接受自由职业项目与咨询
---
<div align="center">
**由 [Teycir Ben Soltane](https://teycirbensoltane.tn) 用 💚 构建**
</div>
| 层 | 数据源 | 提供内容 | 需要的认证 |
|---|
| 1 | InternetDB | 开放端口, CPE, CVE ID | 否 |
| 1 | IPinfo | 地理位置, ISP, ASN, Anycast标志 | 否 |
| 1 | RIPE stat | BGP前缀, ASN持有者, RIR | 否 |
| 1 | RDAP | 注册信息, 联系人, 名称服务器, CIDR | 否 |
| 2 | crt.sh | 证书历史, SAN, 签发者链 | 否 |
| 2 | HackerTarget | 被动DNS — 反向IP与主机搜索 | 否 |
| 2 | Robtex | 反向/正向DNS, AS信息 | 否 |
| 2 | URLhaus | 恶意软件分发URL | ABUSECH_KEY |
| 2 | ThreatFox | IOC数据库 | ABUSECH_KEY |
| 2 | MalwareBazaar | 恶意软件样本元数据 | ABUSECH_KEY |
| 2 | Feodo Tracker | 僵尸网络C2 IP | 否 (批量下载) |
| 2 | SSLBL | 恶意SSL证书 | 否 (批量下载) |
| 3 | NVD + CIRCL | CVE详情, CVSS v2/v3评分 | NVD_KEY (可选) |
| 4 | GrayHatWarfare | 暴露的S3/Azure/GCS存储桶 | GRAYHATWARFARE_API_KEY_1..18 |
| 4 | Wayback | 历史CDX快照 | 否 |
| 来源 | TTL |
|---|
| CVE (NVD/CIRCL) | 30天 |
| Wayback | 7天 |
| BGP、RDAP、Robtex | 24小时 |
| crt.sh、HackerTarget 被动DNS | 12小时 |
| GrayHatWarfare | 6小时 |
| InternetDB、IPinfo | 1小时 |
| Feodo、SSLBL(批量) | 1小时 |
| URLhaus、ThreatFox、MalwareBazaar | 30分钟 |