WiFiScan.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327
  1. #ifndef WiFiScan_h
  2. #define WiFiScan_h
  3. #include "configs.h"
  4. //#include <BLEDevice.h>
  5. //#include <BLEUtils.h>
  6. //#include <BLEScan.h>
  7. //#include <BLEAdvertisedDevice.h>
  8. #include <ArduinoJson.h>
  9. // Testing NimBLE
  10. #ifdef HAS_BT
  11. #include <NimBLEDevice.h>
  12. #endif
  13. #include <WiFi.h>
  14. #include <math.h>
  15. #include "esp_wifi.h"
  16. #include "esp_wifi_types.h"
  17. #ifdef HAS_BT
  18. #include "esp_bt.h"
  19. #endif
  20. #ifdef HAS_SCREEN
  21. #include "Display.h"
  22. #endif
  23. #include "SDInterface.h"
  24. #include "Buffer.h"
  25. #include "BatteryInterface.h"
  26. #include "TemperatureInterface.h"
  27. #include "settings.h"
  28. #include "Assets.h"
  29. #include "flipperLED.h"
  30. //#include "MenuFunctions.h"
  31. #define bad_list_length 3
  32. #define OTA_UPDATE 100
  33. #define SHOW_INFO 101
  34. #define ESP_UPDATE 102
  35. #define WIFI_SCAN_OFF 0
  36. #define WIFI_SCAN_PROBE 1
  37. #define WIFI_SCAN_AP 2
  38. #define WIFI_SCAN_PWN 3
  39. #define WIFI_SCAN_EAPOL 4
  40. #define WIFI_SCAN_DEAUTH 5
  41. #define WIFI_SCAN_ALL 6
  42. #define WIFI_PACKET_MONITOR 7
  43. #define WIFI_ATTACK_BEACON_SPAM 8
  44. #define WIFI_ATTACK_RICK_ROLL 9
  45. #define BT_SCAN_ALL 10
  46. #define BT_SCAN_SKIMMERS 11
  47. #define WIFI_SCAN_ESPRESSIF 12
  48. #define LV_JOIN_WIFI 13
  49. #define LV_ADD_SSID 14
  50. #define WIFI_ATTACK_BEACON_LIST 15
  51. #define WIFI_SCAN_TARGET_AP 16
  52. #define LV_SELECT_AP 17
  53. #define WIFI_ATTACK_AUTH 18
  54. #define WIFI_ATTACK_MIMIC 19
  55. #define WIFI_ATTACK_DEAUTH 20
  56. #define WIFI_ATTACK_AP_SPAM 21
  57. #define WIFI_SCAN_TARGET_AP_FULL 22
  58. #define WIFI_SCAN_ACTIVE_EAPOL 23
  59. #define GRAPH_REFRESH 100
  60. #define MAX_CHANNEL 14
  61. #ifdef HAS_SCREEN
  62. extern Display display_obj;
  63. #endif
  64. extern SDInterface sd_obj;
  65. extern Buffer buffer_obj;
  66. extern BatteryInterface battery_obj;
  67. extern TemperatureInterface temp_obj;
  68. extern Settings settings_obj;
  69. extern flipperLED flipper_led;
  70. esp_err_t esp_wifi_80211_tx(wifi_interface_t ifx, const void *buffer, int len, bool en_sys_seq);
  71. //int ieee80211_raw_frame_sanity_check(int32_t arg, int32_t arg2, int32_t arg3);
  72. struct ssid {
  73. String essid;
  74. int bssid[6];
  75. bool selected;
  76. };
  77. struct AccessPoint {
  78. String essid;
  79. int channel;
  80. int bssid[6];
  81. bool selected;
  82. LinkedList<char>* beacon;
  83. int rssi;
  84. };
  85. class WiFiScan
  86. {
  87. private:
  88. // Settings
  89. int channel_hop_delay = 1;
  90. bool force_pmkid = false;
  91. bool force_probe = false;
  92. bool save_pcap = false;
  93. int x_pos; //position along the graph x axis
  94. float y_pos_x; //current graph y axis position of X value
  95. float y_pos_x_old = 120; //old y axis position of X value
  96. float y_pos_y; //current graph y axis position of Y value
  97. float y_pos_y_old = 120; //old y axis position of Y value
  98. float y_pos_z; //current graph y axis position of Z value
  99. float y_pos_z_old = 120; //old y axis position of Z value
  100. int midway = 0;
  101. byte x_scale = 1; //scale of graph x axis, controlled by touchscreen buttons
  102. byte y_scale = 1;
  103. bool do_break = false;
  104. bool wsl_bypass_enabled = false;
  105. //int num_beacon = 0; // GREEN
  106. //int num_probe = 0; // BLUE
  107. //int num_deauth = 0; // RED
  108. uint32_t initTime = 0;
  109. bool run_setup = true;
  110. void initWiFi(uint8_t scan_mode);
  111. int bluetoothScanTime = 5;
  112. int packets_sent = 0;
  113. const wifi_promiscuous_filter_t filt = {.filter_mask=WIFI_PROMIS_FILTER_MASK_MGMT | WIFI_PROMIS_FILTER_MASK_DATA};
  114. #ifdef HAS_BT
  115. NimBLEScan* pBLEScan;
  116. #endif
  117. //String connected_network = "";
  118. String alfa = "1234567890qwertyuiopasdfghjkklzxcvbnm QWERTYUIOPASDFGHJKLZXCVBNM_";
  119. char* rick_roll[8] = {
  120. "01 Never gonna give you up",
  121. "02 Never gonna let you down",
  122. "03 Never gonna run around",
  123. "04 and desert you",
  124. "05 Never gonna make you cry",
  125. "06 Never gonna say goodbye",
  126. "07 Never gonna tell a lie",
  127. "08 and hurt you"
  128. };
  129. char* prefix = "G";
  130. typedef struct
  131. {
  132. int16_t fctl;
  133. int16_t duration;
  134. uint8_t da;
  135. uint8_t sa;
  136. uint8_t bssid;
  137. int16_t seqctl;
  138. unsigned char payload[];
  139. } __attribute__((packed)) WifiMgmtHdr;
  140. typedef struct {
  141. uint8_t payload[0];
  142. WifiMgmtHdr hdr;
  143. } wifi_ieee80211_packet_t;
  144. // barebones packet
  145. uint8_t packet[128] = { 0x80, 0x00, 0x00, 0x00, //Frame Control, Duration
  146. /*4*/ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, //Destination address
  147. /*10*/ 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, //Source address - overwritten later
  148. /*16*/ 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, //BSSID - overwritten to the same as the source address
  149. /*22*/ 0xc0, 0x6c, //Seq-ctl
  150. /*24*/ 0x83, 0x51, 0xf7, 0x8f, 0x0f, 0x00, 0x00, 0x00, //timestamp - the number of microseconds the AP has been active
  151. /*32*/ 0x64, 0x00, //Beacon interval
  152. /*34*/ 0x01, 0x04, //Capability info
  153. /* SSID */
  154. /*36*/ 0x00
  155. };
  156. /*uint8_t auth_packet[128] = {0xB0, 0x00, 0x3C, 0x00, // Frame Control, Duration
  157. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, // Dest
  158. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, // Source
  159. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, // Dest BSSID
  160. 0x00, 0x01, // Sequence number
  161. 0x00, 0x00, // Algo
  162. 0x01, 0x00, // Auth sequence number
  163. 0x00, 0x00, // Status Code
  164. 0x7F, 0x08,
  165. 0x00, 0x00, 0x08, 0x00, 0x00, 0x00, 0x00, 0x40,
  166. 0xDD, 0x0B, 0x00, 0x17, 0xF2, 0x0A, 0x00, 0x01, // Say it was Apple
  167. 0x04, 0x00, 0x00, 0x00, 0x00, 0xDD, 0x0A, 0x00,
  168. 0x10, 0x18, 0x02, 0x00, 0x00, 0x10, 0x00, 0x00,
  169. 0x00
  170. };*/
  171. uint8_t auth_packet[65] = {0xb0, 0x00, 0x3c, 0x00,
  172. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06,
  173. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06,
  174. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06,
  175. 0x01, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00,
  176. 0x7f, 0x08, 0x00, 0x00, 0x08, 0x00, 0x00, 0x00,
  177. 0x00, 0x40, 0xdd, 0x0b, 0x00, 0x17, 0xf2, 0x0a,
  178. 0x00, 0x01, 0x04, 0x00, 0x00, 0x00, 0x00, 0xdd,
  179. 0x0a, 0x00, 0x10, 0x18, 0x02, 0x00, 0x00, 0x10,
  180. 0x00, 0x00, 0x00};
  181. uint8_t prob_req_packet[128] = {0x40, 0x00, 0x00, 0x00,
  182. 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, // Destination
  183. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, // Source
  184. 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, // Dest
  185. 0x01, 0x00, // Sequence
  186. 0x00, // SSID Parameter
  187. 0x00, // SSID Length
  188. /* SSID */
  189. };
  190. uint8_t deauth_frame_default[26] = {
  191. 0xc0, 0x00, 0x3a, 0x01,
  192. 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
  193. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  194. 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
  195. 0xf0, 0xff, 0x02, 0x00
  196. };
  197. void startWiFiAttacks(uint8_t scan_mode, uint16_t color, String title_string);
  198. void packetMonitorMain(uint32_t currentTime);
  199. void eapolMonitorMain(uint32_t currentTime);
  200. void updateMidway();
  201. void tftDrawXScalButtons();
  202. void tftDrawYScaleButtons();
  203. void tftDrawChannelScaleButtons();
  204. void tftDrawColorKey();
  205. void tftDrawGraphObjects();
  206. void sendProbeAttack(uint32_t currentTime);
  207. void sendDeauthAttack(uint32_t currentTime);
  208. void sendDeauthFrame(uint8_t bssid[6], int channel);
  209. void broadcastRandomSSID(uint32_t currentTime);
  210. void broadcastCustomBeacon(uint32_t current_time, ssid custom_ssid);
  211. void broadcastCustomBeacon(uint32_t current_time, AccessPoint custom_ssid);
  212. void broadcastSetSSID(uint32_t current_time, char* ESSID);
  213. void RunAPScan(uint8_t scan_mode, uint16_t color);
  214. //void RunRickRoll(uint8_t scan_mode, uint16_t color);
  215. //void RunBeaconSpam(uint8_t scan_mode, uint16_t color);
  216. //void RunProbeFlood(uint8_t scan_mode, uint16_t color);
  217. //void RunDeauthFlood(uint8_t scan_mode, uint16_t color);
  218. void RunMimicFlood(uint8_t scan_mode, uint16_t color);
  219. //void RunBeaconList(uint8_t scan_mode, uint16_t color);
  220. void RunEspressifScan(uint8_t scan_mode, uint16_t color);
  221. void RunPwnScan(uint8_t scan_mode, uint16_t color);
  222. void RunBeaconScan(uint8_t scan_mode, uint16_t color);
  223. void RunDeauthScan(uint8_t scan_mode, uint16_t color);
  224. void RunEapolScan(uint8_t scan_mode, uint16_t color);
  225. void RunProbeScan(uint8_t scan_mode, uint16_t color);
  226. void RunPacketMonitor(uint8_t scan_mode, uint16_t color);
  227. void RunBluetoothScan(uint8_t scan_mode, uint16_t color);
  228. void RunLvJoinWiFi(uint8_t scan_mode, uint16_t color);
  229. #ifdef HAS_BT
  230. static void scanCompleteCB(BLEScanResults scanResults);
  231. #endif
  232. //int ieee80211_raw_frame_sanity_check(int32_t arg, int32_t arg2, int32_t arg3);
  233. public:
  234. WiFiScan();
  235. //AccessPoint ap_list;
  236. //LinkedList<ssid>* ssids;
  237. int set_channel = 1;
  238. int old_channel = 0;
  239. bool orient_display = false;
  240. bool wifi_initialized = false;
  241. bool ble_initialized = false;
  242. String free_ram = "";
  243. String old_free_ram = "";
  244. String connected_network = "";
  245. //lv_obj_t * scr = lv_cont_create(NULL, NULL);
  246. wifi_init_config_t cfg = WIFI_INIT_CONFIG_DEFAULT();
  247. char* stringToChar(String string);
  248. void RunSetup();
  249. int clearSSIDs();
  250. int clearAPs();
  251. bool addSSID(String essid);
  252. int generateSSIDs(int count = 20);
  253. bool shutdownWiFi();
  254. bool shutdownBLE();
  255. bool scanning();
  256. void joinWiFi(String ssid, String password);
  257. String getStaMAC();
  258. String getApMAC();
  259. String freeRAM();
  260. void changeChannel();
  261. void changeChannel(int chan);
  262. void RunInfo();
  263. void RunShutdownWiFi();
  264. void RunShutdownBLE();
  265. void RunGenerateSSIDs(int count = 20);
  266. void RunClearSSIDs();
  267. void RunClearAPs();
  268. void channelHop();
  269. uint8_t currentScanMode = 0;
  270. void main(uint32_t currentTime);
  271. void StartScan(uint8_t scan_mode, uint16_t color = 0);
  272. void StopScan(uint8_t scan_mode);
  273. static void getMAC(char *addr, uint8_t* data, uint16_t offset);
  274. static void espressifSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  275. static void pwnSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  276. static void beaconSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  277. static void apSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  278. static void apSnifferCallbackFull(void* buf, wifi_promiscuous_pkt_type_t type);
  279. static void deauthSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  280. static void probeSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  281. static void beaconListSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  282. static void activeEapolSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  283. static void eapolSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  284. static void wifiSnifferCallback(void* buf, wifi_promiscuous_pkt_type_t type);
  285. };
  286. #endif