bad_usb_script.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463
  1. #include <furi.h>
  2. #include <furi-hal.h>
  3. #include <gui/gui.h>
  4. #include <input/input.h>
  5. #include <lib/toolbox/args.h>
  6. #include <furi-hal-usb-hid.h>
  7. #include <storage/storage.h>
  8. #include "bad_usb_script.h"
  9. #define TAG "BadUSB"
  10. #define WORKER_TAG TAG "Worker"
  11. #define FILE_BUFFER_LEN 16
  12. typedef enum {
  13. WorkerEvtReserved = (1 << 0),
  14. WorkerEvtToggle = (1 << 1),
  15. WorkerEvtEnd = (1 << 2),
  16. WorkerEvtConnect = (1 << 3),
  17. WorkerEvtDisconnect = (1 << 4),
  18. } WorkerEvtFlags;
  19. struct BadUsbScript {
  20. BadUsbState st;
  21. string_t file_path;
  22. uint32_t defdelay;
  23. FuriThread* thread;
  24. uint8_t file_buf[FILE_BUFFER_LEN + 1];
  25. uint8_t buf_start;
  26. uint8_t buf_len;
  27. bool file_end;
  28. string_t line;
  29. string_t line_prev;
  30. uint32_t repeat_cnt;
  31. };
  32. typedef struct {
  33. char* name;
  34. uint16_t keycode;
  35. } DuckyKey;
  36. static const DuckyKey ducky_keys[] = {
  37. {"CTRL", KEY_MOD_LEFT_CTRL},
  38. {"CONTROL", KEY_MOD_LEFT_CTRL},
  39. {"SHIFT", KEY_MOD_LEFT_SHIFT},
  40. {"ALT", KEY_MOD_LEFT_ALT},
  41. {"GUI", KEY_MOD_LEFT_GUI},
  42. {"WINDOWS", KEY_MOD_LEFT_GUI},
  43. {"DOWNARROW", KEY_DOWN_ARROW},
  44. {"DOWN", KEY_DOWN_ARROW},
  45. {"LEFTARROW", KEY_LEFT_ARROW},
  46. {"LEFT", KEY_LEFT_ARROW},
  47. {"RIGHTARROW", KEY_RIGHT_ARROW},
  48. {"RIGHT", KEY_RIGHT_ARROW},
  49. {"UPARROW", KEY_UP_ARROW},
  50. {"UP", KEY_UP_ARROW},
  51. {"ENTER", KEY_ENTER},
  52. {"BREAK", KEY_PAUSE},
  53. {"PAUSE", KEY_PAUSE},
  54. {"CAPSLOCK", KEY_CAPS_LOCK},
  55. {"DELETE", KEY_DELETE},
  56. {"BACKSPACE", KEY_BACKSPACE},
  57. {"END", KEY_END},
  58. {"ESC", KEY_ESC},
  59. {"ESCAPE", KEY_ESC},
  60. {"HOME", KEY_HOME},
  61. {"INSERT", KEY_INSERT},
  62. {"NUMLOCK", KEY_NUM_LOCK},
  63. {"PAGEUP", KEY_PAGE_UP},
  64. {"PAGEDOWN", KEY_PAGE_DOWN},
  65. {"PRINTSCREEN", KEY_PRINT},
  66. {"SCROLLOCK", KEY_SCROLL_LOCK},
  67. {"SPACE", KEY_SPACE},
  68. {"TAB", KEY_TAB},
  69. {"MENU", KEY_APPLICATION},
  70. {"APP", KEY_APPLICATION},
  71. {"F1", KEY_F1},
  72. {"F2", KEY_F2},
  73. {"F3", KEY_F3},
  74. {"F4", KEY_F4},
  75. {"F5", KEY_F5},
  76. {"F6", KEY_F6},
  77. {"F7", KEY_F7},
  78. {"F8", KEY_F8},
  79. {"F9", KEY_F9},
  80. {"F10", KEY_F10},
  81. {"F11", KEY_F11},
  82. {"F12", KEY_F12},
  83. };
  84. static const char ducky_cmd_comment[] = {"REM"};
  85. static const char ducky_cmd_delay[] = {"DELAY"};
  86. static const char ducky_cmd_string[] = {"STRING"};
  87. static const char ducky_cmd_defdelay_1[] = {"DEFAULT_DELAY"};
  88. static const char ducky_cmd_defdelay_2[] = {"DEFAULTDELAY"};
  89. static const char ducky_cmd_repeat[] = {"REPEAT"};
  90. static bool ducky_get_number(char* param, uint32_t* val) {
  91. uint32_t value = 0;
  92. if(sscanf(param, "%lu", &value) == 1) {
  93. *val = value;
  94. return true;
  95. }
  96. return false;
  97. }
  98. static uint32_t ducky_get_command_len(char* line) {
  99. uint32_t len = strlen(line);
  100. for(uint32_t i = 0; i < len; i++) {
  101. if(line[i] == ' ') return i;
  102. }
  103. return 0;
  104. }
  105. static bool ducky_string(char* param) {
  106. uint32_t i = 0;
  107. while(param[i] != '\0') {
  108. furi_hal_hid_kb_press(HID_ASCII_TO_KEY(param[i]));
  109. furi_hal_hid_kb_release(HID_ASCII_TO_KEY(param[i]));
  110. i++;
  111. }
  112. return true;
  113. }
  114. static uint16_t ducky_get_keycode(char* param, bool accept_chars) {
  115. for(uint8_t i = 0; i < (sizeof(ducky_keys) / sizeof(ducky_keys[0])); i++) {
  116. if(strncmp(param, ducky_keys[i].name, strlen(ducky_keys[i].name)) == 0)
  117. return ducky_keys[i].keycode;
  118. }
  119. if((accept_chars) && (strlen(param) > 0)) {
  120. return (HID_ASCII_TO_KEY(param[0]) & 0xFF);
  121. }
  122. return 0;
  123. }
  124. static int32_t ducky_parse_line(BadUsbScript* bad_usb, string_t line) {
  125. uint32_t line_len = string_size(line);
  126. char* line_t = (char*)string_get_cstr(line);
  127. bool state = false;
  128. for(uint32_t i = 0; i < line_len; i++) {
  129. if((line_t[i] != ' ') && (line_t[i] != '\t') && (line_t[i] != '\n')) {
  130. line_t = &line_t[i];
  131. break; // Skip spaces and tabs
  132. }
  133. if(i == line_len - 1) return 0; // Skip empty lines
  134. }
  135. FURI_LOG_I(WORKER_TAG, "line:%s", line_t);
  136. // General commands
  137. if(strncmp(line_t, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  138. // REM - comment line
  139. return (0);
  140. } else if(strncmp(line_t, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  141. // DELAY
  142. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  143. uint32_t delay_val = 0;
  144. state = ducky_get_number(line_t, &delay_val);
  145. if((state) && (delay_val > 0)) {
  146. return (int32_t)delay_val;
  147. }
  148. return (-1);
  149. } else if(
  150. (strncmp(line_t, ducky_cmd_defdelay_1, strlen(ducky_cmd_defdelay_1)) == 0) ||
  151. (strncmp(line_t, ducky_cmd_defdelay_2, strlen(ducky_cmd_defdelay_2)) == 0)) {
  152. // DEFAULT_DELAY
  153. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  154. state = ducky_get_number(line_t, &bad_usb->defdelay);
  155. return (state) ? (0) : (-1);
  156. } else if(strncmp(line_t, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  157. // STRING
  158. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  159. state = ducky_string(line_t);
  160. return (state) ? (0) : (-1);
  161. } else if(strncmp(line_t, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  162. // REPEAT
  163. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  164. state = ducky_get_number(line_t, &bad_usb->repeat_cnt);
  165. return (state) ? (0) : (-1);
  166. } else {
  167. // Special keys + modifiers
  168. uint16_t key = ducky_get_keycode(line_t, false);
  169. if(key == KEY_NONE) return (-1);
  170. if((key & 0xFF00) != 0) {
  171. // It's a modifier key
  172. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  173. key |= ducky_get_keycode(line_t, true);
  174. }
  175. furi_hal_hid_kb_press(key);
  176. furi_hal_hid_kb_release(key);
  177. return (0);
  178. }
  179. return (-1);
  180. }
  181. static bool ducky_script_preload(BadUsbScript* bad_usb, File* script_file) {
  182. uint8_t ret = 0;
  183. uint32_t line_len = 0;
  184. do {
  185. ret = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  186. for(uint16_t i = 0; i < ret; i++) {
  187. if(bad_usb->file_buf[i] == '\n' && line_len > 0) {
  188. bad_usb->st.line_nb++;
  189. line_len = 0;
  190. } else {
  191. line_len++;
  192. }
  193. }
  194. if(storage_file_eof(script_file)) {
  195. if(line_len > 0) {
  196. bad_usb->st.line_nb++;
  197. break;
  198. }
  199. }
  200. } while(ret > 0);
  201. storage_file_seek(script_file, 0, true);
  202. return true;
  203. }
  204. static int32_t ducky_script_execute_next(BadUsbScript* bad_usb, File* script_file) {
  205. int32_t delay_val = 0;
  206. if(bad_usb->repeat_cnt > 0) {
  207. bad_usb->repeat_cnt--;
  208. delay_val = ducky_parse_line(bad_usb, bad_usb->line_prev);
  209. if(delay_val < 0) {
  210. bad_usb->st.error_line = bad_usb->st.line_cur - 1;
  211. FURI_LOG_E(WORKER_TAG, "Unknown command at line %lu", bad_usb->st.line_cur - 1);
  212. return (-1);
  213. } else {
  214. return (delay_val + bad_usb->defdelay);
  215. }
  216. }
  217. string_set(bad_usb->line_prev, bad_usb->line);
  218. string_reset(bad_usb->line);
  219. while(1) {
  220. if(bad_usb->buf_len == 0) {
  221. bad_usb->buf_len = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  222. if(storage_file_eof(script_file)) {
  223. if((bad_usb->buf_len < FILE_BUFFER_LEN) && (bad_usb->file_end == false)) {
  224. bad_usb->file_buf[bad_usb->buf_len] = '\n';
  225. bad_usb->buf_len++;
  226. bad_usb->file_end = true;
  227. }
  228. }
  229. bad_usb->buf_start = 0;
  230. if(bad_usb->buf_len == 0) return (-2);
  231. }
  232. for(uint8_t i = bad_usb->buf_start; i < (bad_usb->buf_start + bad_usb->buf_len); i++) {
  233. if(bad_usb->file_buf[i] == '\n' && string_size(bad_usb->line) > 0) {
  234. bad_usb->st.line_cur++;
  235. bad_usb->buf_len = bad_usb->buf_len + bad_usb->buf_start - (i + 1);
  236. bad_usb->buf_start = i + 1;
  237. delay_val = ducky_parse_line(bad_usb, bad_usb->line);
  238. if(delay_val < 0) {
  239. bad_usb->st.error_line = bad_usb->st.line_cur;
  240. FURI_LOG_E(WORKER_TAG, "Unknown command at line %lu", bad_usb->st.line_cur);
  241. return (-1);
  242. } else {
  243. return (delay_val + bad_usb->defdelay);
  244. }
  245. } else {
  246. string_push_back(bad_usb->line, bad_usb->file_buf[i]);
  247. }
  248. }
  249. bad_usb->buf_len = 0;
  250. if(bad_usb->file_end) return (-2);
  251. }
  252. return 0;
  253. }
  254. static void bad_usb_hid_state_callback(bool state, void* context) {
  255. furi_assert(context);
  256. BadUsbScript* bad_usb = context;
  257. if(state == true)
  258. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtConnect);
  259. else
  260. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtDisconnect);
  261. }
  262. static int32_t bad_usb_worker(void* context) {
  263. BadUsbScript* bad_usb = context;
  264. BadUsbWorkerState worker_state = BadUsbStateInit;
  265. int32_t delay_val = 0;
  266. FURI_LOG_I(WORKER_TAG, "Init");
  267. File* script_file = storage_file_alloc(furi_record_open("storage"));
  268. string_init(bad_usb->line);
  269. string_init(bad_usb->line_prev);
  270. furi_hal_hid_set_state_callback(bad_usb_hid_state_callback, bad_usb);
  271. while(1) {
  272. if(worker_state == BadUsbStateInit) { // State: initialization
  273. if(storage_file_open(
  274. script_file,
  275. string_get_cstr(bad_usb->file_path),
  276. FSAM_READ,
  277. FSOM_OPEN_EXISTING)) {
  278. if((ducky_script_preload(bad_usb, script_file)) && (bad_usb->st.line_nb > 0)) {
  279. if(furi_hal_hid_is_connected()) {
  280. worker_state = BadUsbStateIdle; // Ready to run
  281. } else {
  282. worker_state = BadUsbStateNotConnected; // USB not connected
  283. }
  284. } else {
  285. worker_state = BadUsbStateScriptError; // Script preload error
  286. }
  287. } else {
  288. FURI_LOG_E(WORKER_TAG, "File open error");
  289. worker_state = BadUsbStateFileError; // File open error
  290. }
  291. bad_usb->st.state = worker_state;
  292. } else if(worker_state == BadUsbStateNotConnected) { // State: USB not connected
  293. uint32_t flags =
  294. osThreadFlagsWait(WorkerEvtEnd | WorkerEvtConnect, osFlagsWaitAny, osWaitForever);
  295. furi_check((flags & osFlagsError) == 0);
  296. if(flags & WorkerEvtEnd) {
  297. break;
  298. } else if(flags & WorkerEvtConnect) {
  299. worker_state = BadUsbStateIdle; // Ready to run
  300. }
  301. bad_usb->st.state = worker_state;
  302. } else if(worker_state == BadUsbStateIdle) { // State: ready to start
  303. uint32_t flags = osThreadFlagsWait(
  304. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect,
  305. osFlagsWaitAny,
  306. osWaitForever);
  307. furi_check((flags & osFlagsError) == 0);
  308. if(flags & WorkerEvtEnd) {
  309. break;
  310. } else if(flags & WorkerEvtToggle) { // Start executing script
  311. delay_val = 0;
  312. bad_usb->buf_len = 0;
  313. bad_usb->st.line_cur = 0;
  314. bad_usb->defdelay = 0;
  315. bad_usb->repeat_cnt = 0;
  316. bad_usb->file_end = false;
  317. storage_file_seek(script_file, 0, true);
  318. worker_state = BadUsbStateRunning;
  319. } else if(flags & WorkerEvtDisconnect) {
  320. worker_state = BadUsbStateNotConnected; // USB disconnected
  321. }
  322. bad_usb->st.state = worker_state;
  323. } else if(worker_state == BadUsbStateRunning) { // State: running
  324. uint16_t delay_cur = (delay_val > 1000) ? (1000) : (delay_val);
  325. uint32_t flags = osThreadFlagsWait(
  326. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect, osFlagsWaitAny, delay_cur);
  327. delay_val -= delay_cur;
  328. if(!(flags & osFlagsError)) {
  329. if(flags & WorkerEvtEnd) {
  330. break;
  331. } else if(flags & WorkerEvtToggle) {
  332. worker_state = BadUsbStateIdle; // Stop executing script
  333. furi_hal_hid_kb_release_all();
  334. } else if(flags & WorkerEvtDisconnect) {
  335. worker_state = BadUsbStateNotConnected; // USB disconnected
  336. furi_hal_hid_kb_release_all();
  337. }
  338. bad_usb->st.state = worker_state;
  339. continue;
  340. } else if((flags == osFlagsErrorTimeout) || (flags == osFlagsErrorResource)) {
  341. if(delay_val > 0) {
  342. bad_usb->st.delay_remain--;
  343. continue;
  344. }
  345. bad_usb->st.state = BadUsbStateRunning;
  346. delay_val = ducky_script_execute_next(bad_usb, script_file);
  347. if(delay_val == -1) { // Script error
  348. delay_val = 0;
  349. worker_state = BadUsbStateScriptError;
  350. bad_usb->st.state = worker_state;
  351. } else if(delay_val == -2) { // End of script
  352. delay_val = 0;
  353. worker_state = BadUsbStateIdle;
  354. bad_usb->st.state = BadUsbStateDone;
  355. furi_hal_hid_kb_release_all();
  356. continue;
  357. } else if(delay_val > 1000) {
  358. bad_usb->st.state = BadUsbStateDelay; // Show long delays
  359. bad_usb->st.delay_remain = delay_val / 1000;
  360. }
  361. } else {
  362. furi_check((flags & osFlagsError) == 0);
  363. }
  364. } else if(
  365. (worker_state == BadUsbStateFileError) ||
  366. (worker_state == BadUsbStateScriptError)) { // State: error
  367. uint32_t flags = osThreadFlagsWait(
  368. WorkerEvtEnd, osFlagsWaitAny, osWaitForever); // Waiting for exit command
  369. furi_check((flags & osFlagsError) == 0);
  370. if(flags & WorkerEvtEnd) {
  371. break;
  372. }
  373. }
  374. }
  375. furi_hal_hid_set_state_callback(NULL, NULL);
  376. storage_file_close(script_file);
  377. storage_file_free(script_file);
  378. string_clear(bad_usb->line);
  379. string_clear(bad_usb->line_prev);
  380. FURI_LOG_I(WORKER_TAG, "End");
  381. return 0;
  382. }
  383. BadUsbScript* bad_usb_script_open(string_t file_path) {
  384. furi_assert(file_path);
  385. BadUsbScript* bad_usb = furi_alloc(sizeof(BadUsbScript));
  386. string_init(bad_usb->file_path);
  387. string_set(bad_usb->file_path, file_path);
  388. bad_usb->st.state = BadUsbStateInit;
  389. bad_usb->thread = furi_thread_alloc();
  390. furi_thread_set_name(bad_usb->thread, "BadUsbWorker");
  391. furi_thread_set_stack_size(bad_usb->thread, 2048);
  392. furi_thread_set_context(bad_usb->thread, bad_usb);
  393. furi_thread_set_callback(bad_usb->thread, bad_usb_worker);
  394. furi_thread_start(bad_usb->thread);
  395. return bad_usb;
  396. }
  397. void bad_usb_script_close(BadUsbScript* bad_usb) {
  398. furi_assert(bad_usb);
  399. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtEnd);
  400. furi_thread_join(bad_usb->thread);
  401. furi_thread_free(bad_usb->thread);
  402. string_clear(bad_usb->file_path);
  403. free(bad_usb);
  404. }
  405. void bad_usb_script_toggle(BadUsbScript* bad_usb) {
  406. furi_assert(bad_usb);
  407. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtToggle);
  408. }
  409. BadUsbState* bad_usb_script_get_state(BadUsbScript* bad_usb) {
  410. furi_assert(bad_usb);
  411. return &(bad_usb->st);
  412. }