nrfsniff.c 17 KB


  1. #include <furi.h>
  2. #include <furi_hal.h>
  3. #include <gui/gui.h>
  4. #include <input/input.h>
  5. #include <notification/notification_messages.h>
  6. #include <stdlib.h>
  7. #include <nrf24.h>
  8. #include <toolbox/stream/file_stream.h>
  9. #define LOGITECH_MAX_CHANNEL 85
  10. #define COUNT_THRESHOLD 2
  11. #define DEFAULT_SAMPLE_TIME 4000
  12. #define MAX_ADDRS 100
  13. #define MAX_CONFIRMED 32
  14. #define NRFSNIFF_APP_PATH_FOLDER STORAGE_APP_DATA_PATH_PREFIX
  15. #define NRFSNIFF_APP_FILENAME "addresses.txt"
  16. #define TAG "nrfsniff"
  17. typedef enum {
  18. EventTypeTick,
  19. EventTypeKey,
  20. } EventType;
  21. typedef struct {
  22. EventType type;
  23. InputEvent input;
  24. } PluginEvent;
  25. typedef struct {
  26. FuriMutex* mutex;
  27. } PluginState;
  28. char rate_text_fmt[] = "Transfer rate: %dMbps";
  29. char sample_text_fmt[] = "Sample Time: %d ms";
  30. char channel_text_fmt[] = "Channel: %d Sniffing: %s";
  31. char preamble_text_fmt[] = "Preamble: %02X";
  32. char sniff_text_fmt[] = "Found: %d Unique: %u";
  33. char addresses_header_text[] = "Address,rate";
  34. char sniffed_address_fmt[] = "%s,%d";
  35. char rate_text[46];
  36. char channel_text[38];
  37. char sample_text[32];
  38. char preamble_text[14];
  39. char sniff_text[38];
  40. char sniffed_address[14];
  41. uint8_t target_channel = 0;
  42. uint32_t found_count = 0;
  43. uint32_t unique_saved_count = 0;
  44. uint32_t sample_time = DEFAULT_SAMPLE_TIME;
  45. uint8_t target_rate = 8; // rate can be either 8 (2Mbps) or 0 (1Mbps)
  46. uint8_t target_preamble[] = {0xAA, 0x00};
  47. uint8_t sniffing_state = false;
  48. char top_address[12];
  49. uint8_t candidates[MAX_ADDRS][5] = {0}; // last 100 sniffed addresses
  50. uint32_t counts[MAX_ADDRS];
  51. uint8_t confirmed[MAX_CONFIRMED][5] = {0}; // first 32 confirmed addresses
  52. uint8_t confirmed_idx = 0;
  53. uint32_t total_candidates = 0;
  54. uint32_t candidate_idx = 0;
  55. static int get_addr_index(uint8_t* addr, uint8_t addr_size) {
  56. for(uint32_t i = 0; i < total_candidates; i++) {
  57. uint8_t* arr_item = candidates[i];
  58. if(!memcmp(arr_item, addr, addr_size)) return i;
  59. }
  60. return -1;
  61. }
  62. static int get_highest_idx() {
  63. uint32_t highest = 0;
  64. int highest_idx = 0;
  65. for(uint32_t i = 0; i < total_candidates; i++) {
  66. if(counts[i] > highest) {
  67. highest = counts[i];
  68. highest_idx = i;
  69. }
  70. }
  71. return highest_idx;
  72. }
  73. // if array is full, start over from beginning
  74. static void insert_addr(uint8_t* addr, uint8_t addr_size) {
  75. if(candidate_idx >= MAX_ADDRS) candidate_idx = 0;
  76. memcpy(candidates[candidate_idx], addr, addr_size);
  77. counts[candidate_idx] = 1;
  78. if(total_candidates < MAX_ADDRS) total_candidates++;
  79. candidate_idx++;
  80. }
  81. static void render_callback(Canvas* const canvas, void* ctx) {
  82. furi_assert(ctx);
  83. const PluginState* plugin_state = ctx;
  84. furi_mutex_acquire(plugin_state->mutex, FuriWaitForever);
  85. uint8_t rate = 2;
  86. char sniffing[] = "Yes";
  87. // border around the edge of the screen
  88. canvas_draw_frame(canvas, 0, 0, 128, 64);
  89. canvas_set_font(canvas, FontSecondary);
  90. if(target_rate == 0) rate = 1;
  91. if(!sniffing_state) strcpy(sniffing, "No");
  92. snprintf(rate_text, sizeof(rate_text), rate_text_fmt, (int)rate);
  93. snprintf(channel_text, sizeof(channel_text), channel_text_fmt, (int)target_channel, sniffing);
  94. snprintf(sample_text, sizeof(sample_text), sample_text_fmt, (int)sample_time);
  95. //snprintf(preamble_text, sizeof(preamble_text), preamble_text_fmt, target_preamble[0]);
  96. snprintf(sniff_text, sizeof(sniff_text), sniff_text_fmt, found_count, unique_saved_count);
  97. snprintf(
  98. sniffed_address, sizeof(sniffed_address), sniffed_address_fmt, top_address, (int)rate);
  99. canvas_draw_str_aligned(canvas, 10, 10, AlignLeft, AlignBottom, rate_text);
  100. canvas_draw_str_aligned(canvas, 10, 20, AlignLeft, AlignBottom, sample_text);
  101. canvas_draw_str_aligned(canvas, 10, 30, AlignLeft, AlignBottom, channel_text);
  102. //canvas_draw_str_aligned(canvas, 10, 30, AlignLeft, AlignBottom, preamble_text);
  103. canvas_draw_str_aligned(canvas, 10, 40, AlignLeft, AlignBottom, sniff_text);
  104. canvas_draw_str_aligned(canvas, 30, 50, AlignLeft, AlignBottom, addresses_header_text);
  105. canvas_draw_str_aligned(canvas, 30, 60, AlignLeft, AlignBottom, sniffed_address);
  106. furi_mutex_release(plugin_state->mutex);
  107. }
  108. static void input_callback(InputEvent* input_event, void* ctx) {
  109. FuriMessageQueue* event_queue = ctx;
  110. furi_assert(event_queue);
  111. PluginEvent event = {.type = EventTypeKey, .input = *input_event};
  112. furi_message_queue_put(event_queue, &event, FuriWaitForever);
  113. }
  114. static void hexlify(uint8_t* in, uint8_t size, char* out) {
  115. memset(out, 0, size * 2);
  116. for(int i = 0; i < size; i++)
  117. snprintf(out + strlen(out), sizeof(out + strlen(out)), "%02X", in[i]);
  118. }
  119. static bool save_addr_to_file(
  120. Storage* storage,
  121. uint8_t* data,
  122. uint8_t size,
  123. NotificationApp* notification) {
  124. size_t file_size = 0;
  125. uint8_t linesize = 0;
  126. char filepath[42] = {0};
  127. char addrline[14] = {0};
  128. char ending[4];
  129. uint8_t* file_contents;
  130. uint8_t rate = 1;
  131. Stream* stream = file_stream_alloc(storage);
  132. if(target_rate == 8) rate = 2;
  133. snprintf(ending, sizeof(ending), ",%d\n", rate);
  134. hexlify(data, size, addrline);
  135. strcat(addrline, ending);
  136. linesize = strlen(addrline);
  137. strcpy(filepath, NRFSNIFF_APP_PATH_FOLDER);
  138. strcat(filepath, "/");
  139. strcat(filepath, NRFSNIFF_APP_FILENAME);
  140. stream_seek(stream, 0, StreamOffsetFromStart);
  141. // check if address already exists in file
  142. if(file_stream_open(stream, filepath, FSAM_READ_WRITE, FSOM_OPEN_APPEND)) {
  143. bool found = false;
  144. file_size = stream_size(stream);
  145. stream_seek(stream, 0, StreamOffsetFromStart);
  146. if(file_size > 0) {
  147. file_contents = malloc(file_size + 1);
  148. memset(file_contents, 0, file_size + 1);
  149. if(stream_read(stream, file_contents, file_size) > 0) {
  150. char* line = strtok((char*)file_contents, "\n");
  151. while(line != NULL) {
  152. if(!memcmp(line, addrline, 12)) {
  153. found = true;
  154. break;
  155. }
  156. line = strtok(NULL, "\n");
  157. }
  158. }
  159. free(file_contents);
  160. }
  161. if(found) {
  162. FURI_LOG_I(TAG, "Address exists in file. Ending save process.");
  163. stream_free(stream);
  164. return false;
  165. } else {
  166. if(stream_write(stream, (uint8_t*)addrline, linesize) != linesize) {
  167. FURI_LOG_I(TAG, "Failed to write bytes to file stream.");
  168. stream_free(stream);
  169. return false;
  170. } else {
  171. FURI_LOG_I(TAG, "Found a new address: %s", addrline);
  172. FURI_LOG_I(TAG, "Save successful!");
  173. notification_message(notification, &sequence_success);
  174. stream_free(stream);
  175. unique_saved_count++;
  176. return true;
  177. }
  178. }
  179. } else {
  180. FURI_LOG_I(TAG, "Cannot open file \"%s\"", filepath);
  181. stream_free(stream);
  182. return false;
  183. }
  184. }
  185. void alt_address(uint8_t* addr, uint8_t* altaddr) {
  186. uint8_t macmess_hi_b[4];
  187. uint32_t macmess_hi;
  188. uint8_t macmess_lo;
  189. uint8_t preserved;
  190. uint8_t tmpaddr[5];
  191. // swap bytes
  192. for(int i = 0; i < 5; i++) tmpaddr[i] = addr[4 - i];
  193. // get address into 32-bit and 8-bit variables
  194. memcpy(macmess_hi_b, tmpaddr, 4);
  195. macmess_lo = tmpaddr[4];
  196. macmess_hi = bytes_to_int32(macmess_hi_b, true);
  197. //preserve lowest bit from hi to shift to low
  198. preserved = macmess_hi & 1;
  199. macmess_hi >>= 1;
  200. macmess_lo >>= 1;
  201. macmess_lo = (preserved << 7) | macmess_lo;
  202. int32_to_bytes(macmess_hi, macmess_hi_b, true);
  203. memcpy(tmpaddr, macmess_hi_b, 4);
  204. tmpaddr[4] = macmess_lo;
  205. // swap bytes back
  206. for(int i = 0; i < 5; i++) altaddr[i] = tmpaddr[4 - i];
  207. }
  208. static bool previously_confirmed(uint8_t* addr) {
  209. bool found = false;
  210. for(int i = 0; i < MAX_CONFIRMED; i++) {
  211. if(!memcmp(confirmed[i], addr, 5)) {
  212. found = true;
  213. break;
  214. }
  215. }
  216. return found;
  217. }
  218. static void wrap_up(Storage* storage, NotificationApp* notification) {
  219. uint8_t ch;
  220. uint8_t addr[5];
  221. uint8_t altaddr[5];
  222. char trying[12];
  223. int idx;
  224. uint8_t rate = 0;
  225. if(target_rate == 8) rate = 2;
  226. nrf24_set_idle(nrf24_HANDLE);
  227. while(true) {
  228. idx = get_highest_idx();
  229. if(counts[idx] < COUNT_THRESHOLD) break;
  230. counts[idx] = 0;
  231. memcpy(addr, candidates[idx], 5);
  232. hexlify(addr, 5, trying);
  233. FURI_LOG_I(TAG, "trying address %s", trying);
  234. ch = nrf24_find_channel(nrf24_HANDLE, addr, addr, 5, rate, 2, LOGITECH_MAX_CHANNEL, false);
  235. FURI_LOG_I(TAG, "find_channel returned %d", (int)ch);
  236. if(ch > LOGITECH_MAX_CHANNEL) {
  237. alt_address(addr, altaddr);
  238. hexlify(altaddr, 5, trying);
  239. FURI_LOG_I(TAG, "trying alternate address %s", trying);
  240. ch = nrf24_find_channel(
  241. nrf24_HANDLE, altaddr, altaddr, 5, rate, 2, LOGITECH_MAX_CHANNEL, false);
  242. FURI_LOG_I(TAG, "find_channel returned %d", (int)ch);
  243. memcpy(addr, altaddr, 5);
  244. }
  245. if(ch <= LOGITECH_MAX_CHANNEL) {
  246. hexlify(addr, 5, top_address);
  247. found_count++;
  248. save_addr_to_file(storage, addr, 5, notification);
  249. if(confirmed_idx < MAX_CONFIRMED) memcpy(confirmed[confirmed_idx++], addr, 5);
  250. break;
  251. }
  252. }
  253. }
  254. static void clear_cache() {
  255. found_count = 0;
  256. unique_saved_count = 0;
  257. confirmed_idx = 0;
  258. candidate_idx = 0;
  259. target_channel = 2;
  260. total_candidates = 0;
  261. memset(candidates, 0, sizeof(candidates));
  262. memset(counts, 0, sizeof(counts));
  263. memset(confirmed, 0, sizeof(confirmed));
  264. }
  265. static void start_sniffing() {
  266. nrf24_init_promisc_mode(nrf24_HANDLE, target_channel, target_rate);
  267. }
  268. int32_t nrfsniff_app(void* p) {
  269. UNUSED(p);
  270. uint8_t address[5] = {0};
  271. uint32_t start = 0;
  272. hexlify(address, 5, top_address);
  273. FuriMessageQueue* event_queue = furi_message_queue_alloc(8, sizeof(PluginEvent));
  274. PluginState* plugin_state = malloc(sizeof(PluginState));
  275. plugin_state->mutex = furi_mutex_alloc(FuriMutexTypeNormal);
  276. if(!plugin_state->mutex) {
  277. furi_message_queue_free(event_queue);
  278. FURI_LOG_E(TAG, "cannot create mutex\r\n");
  279. free(plugin_state);
  280. return 255;
  281. }
  282. uint8_t attempts = 0;
  283. bool otg_was_enabled = furi_hal_power_is_otg_enabled();
  284. while(!furi_hal_power_is_otg_enabled() && attempts++ < 5) {
  285. furi_hal_power_enable_otg();
  286. furi_delay_ms(10);
  287. }
  288. furi_delay_ms(100);
  289. nrf24_init();
  290. bool nrf_ready = false;
  291. if(nrf24_check_connected(nrf24_HANDLE)) {
  292. nrf_ready = true;
  293. } else {
  294. nrf_ready = false;
  295. FURI_LOG_E(TAG, "NRF24 not connected");
  296. }
  297. // Set system callbacks
  298. ViewPort* view_port = view_port_alloc();
  299. view_port_draw_callback_set(view_port, render_callback, plugin_state);
  300. view_port_input_callback_set(view_port, input_callback, event_queue);
  301. // Open GUI and register view_port
  302. Gui* gui = furi_record_open(RECORD_GUI);
  303. gui_add_view_port(gui, view_port, GuiLayerFullscreen);
  304. NotificationApp* notification = furi_record_open(RECORD_NOTIFICATION);
  305. Storage* storage = furi_record_open(RECORD_STORAGE);
  306. storage_common_migrate(storage, EXT_PATH("nrfsniff"), NRFSNIFF_APP_PATH_FOLDER);
  307. storage_common_mkdir(storage, NRFSNIFF_APP_PATH_FOLDER);
  308. PluginEvent event;
  309. for(bool processing = true; processing;) {
  310. FuriStatus event_status = furi_message_queue_get(event_queue, &event, 100);
  311. furi_mutex_acquire(plugin_state->mutex, FuriWaitForever);
  312. if(event_status == FuriStatusOk) {
  313. // press events
  314. if(event.type == EventTypeKey) {
  315. if(event.input.type == InputTypePress ||
  316. (event.input.type == InputTypeLong && event.input.key == InputKeyBack)) {
  317. switch(event.input.key) {
  318. case InputKeyUp:
  319. // toggle rate 1/2Mbps
  320. if(!sniffing_state) {
  321. if(target_rate == 0)
  322. target_rate = 8;
  323. else
  324. target_rate = 0;
  325. }
  326. break;
  327. case InputKeyDown:
  328. // toggle preamble
  329. if(!sniffing_state) {
  330. if(target_preamble[0] == 0x55)
  331. target_preamble[0] = 0xAA;
  332. else
  333. target_preamble[0] = 0x55;
  334. nrf24_set_src_mac(nrf24_HANDLE, target_preamble, 2);
  335. }
  336. break;
  337. case InputKeyRight:
  338. // increment channel
  339. //if(!sniffing_state && target_channel <= LOGITECH_MAX_CHANNEL)
  340. // target_channel++;
  341. sample_time += 500;
  342. break;
  343. case InputKeyLeft:
  344. // decrement channel
  345. //if(!sniffing_state && target_channel > 0) target_channel--;
  346. if(sample_time > 500) sample_time -= 500;
  347. break;
  348. case InputKeyOk:
  349. // toggle sniffing
  350. if(nrf_ready) {
  351. sniffing_state = !sniffing_state;
  352. if(sniffing_state) {
  353. clear_cache();
  354. start_sniffing();
  355. start = furi_get_tick();
  356. } else {
  357. wrap_up(storage, notification);
  358. }
  359. } else {
  360. notification_message(notification, &sequence_error);
  361. if(nrf24_check_connected(nrf24_HANDLE)) {
  362. nrf_ready = true;
  363. } else {
  364. nrf_ready = false;
  365. FURI_LOG_E(TAG, "NRF24 not connected");
  366. }
  367. }
  368. break;
  369. case InputKeyBack:
  370. if(nrf_ready) {
  371. if(sniffing_state) {
  372. wrap_up(storage, notification);
  373. }
  374. } else {
  375. if(nrf24_check_connected(nrf24_HANDLE)) {
  376. nrf_ready = true;
  377. } else {
  378. nrf_ready = false;
  379. FURI_LOG_E(TAG, "NRF24 not connected");
  380. }
  381. }
  382. processing = false;
  383. break;
  384. default:
  385. break;
  386. }
  387. }
  388. }
  389. }
  390. if(sniffing_state) {
  391. if(nrf24_sniff_address(nrf24_HANDLE, 5, address)) {
  392. int idx;
  393. uint8_t* top_addr;
  394. if(!previously_confirmed(address)) {
  395. idx = get_addr_index(address, 5);
  396. if(idx == -1)
  397. insert_addr(address, 5);
  398. else
  399. counts[idx]++;
  400. top_addr = candidates[get_highest_idx()];
  401. hexlify(top_addr, 5, top_address);
  402. }
  403. }
  404. if(furi_get_tick() - start >= sample_time) {
  405. target_channel++;
  406. if(target_channel > LOGITECH_MAX_CHANNEL) target_channel = 2;
  407. {
  408. wrap_up(storage, notification);
  409. start_sniffing();
  410. }
  411. start = furi_get_tick();
  412. }
  413. }
  414. furi_mutex_release(plugin_state->mutex);
  415. view_port_update(view_port);
  416. }
  417. clear_cache();
  418. sample_time = DEFAULT_SAMPLE_TIME;
  419. target_rate = 8; // rate can be either 8 (2Mbps) or 0 (1Mbps)
  420. sniffing_state = false;
  421. nrf24_deinit();
  422. if(furi_hal_power_is_otg_enabled() && !otg_was_enabled) {
  423. furi_hal_power_disable_otg();
  424. }
  425. view_port_enabled_set(view_port, false);
  426. gui_remove_view_port(gui, view_port);
  427. furi_record_close(RECORD_GUI);
  428. furi_record_close(RECORD_NOTIFICATION);
  429. furi_record_close(RECORD_STORAGE);
  430. view_port_free(view_port);
  431. furi_message_queue_free(event_queue);
  432. furi_mutex_free(plugin_state->mutex);
  433. free(plugin_state);
  434. return 0;
  435. }