subbrute_device.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512
  1. #include "subbrute_device.h"
  2. #include <stdint.h>
  3. #include <storage/storage.h>
  4. #include <lib/toolbox/stream/stream.h>
  5. #include <lib/flipper_format/flipper_format.h>
  6. #include <lib/flipper_format/flipper_format_i.h>
  7. #include <lib/subghz/protocols/protocol_items.h>
  8. #define TAG "SubBruteDevice"
  9. SubBruteDevice* subbrute_device_alloc() {
  10. SubBruteDevice* instance = malloc(sizeof(SubBruteDevice));
  11. instance->key_index = 0;
  12. instance->protocol_info = NULL;
  13. instance->file_protocol_info = NULL;
  14. instance->decoder_result = NULL;
  15. instance->receiver = NULL;
  16. instance->environment = subghz_environment_alloc();
  17. subghz_environment_set_protocol_registry(
  18. instance->environment, (void*)&subghz_protocol_registry);
  19. #ifdef FURI_DEBUG
  20. subbrute_device_attack_set_default_values(instance, SubBruteAttackCAME12bit433);
  21. #else
  22. subbrute_device_attack_set_default_values(instance, SubBruteAttackLoadFile);
  23. #endif
  24. return instance;
  25. }
  26. void subbrute_device_free(SubBruteDevice* instance) {
  27. furi_assert(instance);
  28. // I don't know how to free this
  29. instance->decoder_result = NULL;
  30. if(instance->receiver != NULL) {
  31. subghz_receiver_free(instance->receiver);
  32. instance->receiver = NULL;
  33. }
  34. subghz_environment_free(instance->environment);
  35. instance->environment = NULL;
  36. subbrute_device_free_protocol_info(instance);
  37. free(instance);
  38. }
  39. uint64_t subbrute_device_add_step(SubBruteDevice* instance, int8_t step) {
  40. if(step > 0) {
  41. if((instance->key_index + step) - instance->max_value == 1) {
  42. instance->key_index = 0x00;
  43. } else {
  44. uint64_t value = instance->key_index + step;
  45. if(value == instance->max_value) {
  46. instance->key_index = value;
  47. } else {
  48. instance->key_index = value % instance->max_value;
  49. }
  50. }
  51. } else {
  52. if(instance->key_index + step == 0) {
  53. instance->key_index = 0x00;
  54. } else if(instance->key_index == 0) {
  55. instance->key_index = instance->max_value;
  56. } else {
  57. uint64_t value = ((instance->key_index + step) + instance->max_value);
  58. if(value == instance->max_value) {
  59. instance->key_index = value;
  60. } else {
  61. instance->key_index = value % instance->max_value;
  62. }
  63. }
  64. }
  65. return instance->key_index;
  66. }
  67. bool subbrute_device_save_file(SubBruteDevice* instance, const char* dev_file_name) {
  68. furi_assert(instance);
  69. #ifdef FURI_DEBUG
  70. FURI_LOG_D(TAG, "subbrute_device_save_file: %s", dev_file_name);
  71. #endif
  72. Storage* storage = furi_record_open(RECORD_STORAGE);
  73. FlipperFormat* file = flipper_format_file_alloc(storage);
  74. bool result = false;
  75. do {
  76. if(!flipper_format_file_open_always(file, dev_file_name)) {
  77. FURI_LOG_E(TAG, "Failed to open file: %s", dev_file_name);
  78. break;
  79. }
  80. Stream* stream = flipper_format_get_raw_stream(file);
  81. if(instance->attack == SubBruteAttackLoadFile) {
  82. subbrute_protocol_file_generate_file(
  83. stream,
  84. instance->file_protocol_info->frequency,
  85. instance->file_protocol_info->preset,
  86. instance->file_protocol_info->file,
  87. instance->key_index,
  88. instance->file_protocol_info->bits,
  89. instance->file_protocol_info->te,
  90. instance->file_protocol_info->repeat,
  91. instance->load_index,
  92. instance->file_key);
  93. } else {
  94. subbrute_protocol_default_generate_file(
  95. stream,
  96. instance->protocol_info->frequency,
  97. instance->protocol_info->preset,
  98. instance->protocol_info->file,
  99. instance->key_index,
  100. instance->protocol_info->bits,
  101. instance->protocol_info->te,
  102. instance->protocol_info->repeat);
  103. }
  104. result = true;
  105. } while(false);
  106. if(!result) {
  107. FURI_LOG_E(TAG, "subbrute_device_save_file failed!");
  108. }
  109. flipper_format_file_close(file);
  110. flipper_format_free(file);
  111. furi_record_close(RECORD_STORAGE);
  112. return result;
  113. }
  114. SubBruteFileResult subbrute_device_attack_set(
  115. SubBruteDevice* instance,
  116. SubBruteAttacks type,
  117. uint8_t extra_repeats) {
  118. furi_assert(instance);
  119. #ifdef FURI_DEBUG
  120. FURI_LOG_D(TAG, "subbrute_device_attack_set: %d, extra_repeats: %d", type, extra_repeats);
  121. #endif
  122. subbrute_device_attack_set_default_values(instance, type);
  123. if(type != SubBruteAttackLoadFile) {
  124. subbrute_device_free_protocol_info(instance);
  125. instance->protocol_info = subbrute_protocol(type);
  126. }
  127. instance->extra_repeats = extra_repeats;
  128. // For non-file types we didn't set SubGhzProtocolDecoderBase
  129. instance->receiver = subghz_receiver_alloc_init(instance->environment);
  130. subghz_receiver_set_filter(instance->receiver, SubGhzProtocolFlag_Decodable);
  131. furi_hal_subghz_reset();
  132. uint8_t protocol_check_result = SubBruteFileResultProtocolNotFound;
  133. #ifdef FURI_DEBUG
  134. uint8_t bits;
  135. uint8_t te;
  136. uint8_t repeat;
  137. FuriHalSubGhzPreset preset;
  138. SubBruteFileProtocol file;
  139. #endif
  140. if(type != SubBruteAttackLoadFile) {
  141. instance->decoder_result = subghz_receiver_search_decoder_base_by_name(
  142. instance->receiver, subbrute_protocol_file(instance->protocol_info->file));
  143. if(!instance->decoder_result ||
  144. instance->decoder_result->protocol->type == SubGhzProtocolTypeDynamic) {
  145. FURI_LOG_E(TAG, "Can't load SubGhzProtocolDecoderBase in phase non-file decoder set");
  146. } else {
  147. protocol_check_result = SubBruteFileResultOk;
  148. // Calc max value
  149. instance->max_value =
  150. subbrute_protocol_calc_max_value(instance->attack, instance->protocol_info->bits);
  151. }
  152. #ifdef FURI_DEBUG
  153. bits = instance->protocol_info->bits;
  154. te = instance->protocol_info->te;
  155. repeat = instance->protocol_info->repeat + instance->extra_repeats;
  156. preset = instance->protocol_info->preset;
  157. file = instance->protocol_info->file;
  158. #endif
  159. } else {
  160. // And here we need to set preset enum
  161. protocol_check_result = SubBruteFileResultOk;
  162. // Calc max value
  163. instance->max_value =
  164. subbrute_protocol_calc_max_value(instance->attack, instance->file_protocol_info->bits);
  165. #ifdef FURI_DEBUG
  166. bits = instance->file_protocol_info->bits;
  167. te = instance->file_protocol_info->te;
  168. repeat = instance->file_protocol_info->repeat + instance->extra_repeats;
  169. preset = instance->file_protocol_info->preset;
  170. file = instance->file_protocol_info->file;
  171. #endif
  172. }
  173. subghz_receiver_free(instance->receiver);
  174. instance->receiver = NULL;
  175. if(protocol_check_result != SubBruteFileResultOk) {
  176. return SubBruteFileResultProtocolNotFound;
  177. }
  178. #ifdef FURI_DEBUG
  179. FURI_LOG_I(
  180. TAG,
  181. "subbrute_device_attack_set: %s, bits: %d, preset: %s, file: %s, te: %d, repeat: %d, max_value: %lld",
  182. subbrute_protocol_name(instance->attack),
  183. bits,
  184. subbrute_protocol_preset(preset),
  185. subbrute_protocol_file(file),
  186. te,
  187. repeat,
  188. instance->max_value);
  189. #endif
  190. return SubBruteFileResultOk;
  191. }
  192. uint8_t subbrute_device_load_from_file(SubBruteDevice* instance, const char* file_path) {
  193. furi_assert(instance);
  194. #ifdef FURI_DEBUG
  195. FURI_LOG_D(TAG, "subbrute_device_load_from_file: %s", file_path);
  196. #endif
  197. SubBruteFileResult result = SubBruteFileResultUnknown;
  198. Storage* storage = furi_record_open(RECORD_STORAGE);
  199. FlipperFormat* fff_data_file = flipper_format_file_alloc(storage);
  200. subbrute_device_free_protocol_info(instance);
  201. instance->file_protocol_info = malloc(sizeof(SubBruteProtocol));
  202. FuriString* temp_str;
  203. temp_str = furi_string_alloc();
  204. uint32_t temp_data32;
  205. instance->receiver = subghz_receiver_alloc_init(instance->environment);
  206. subghz_receiver_set_filter(instance->receiver, SubGhzProtocolFlag_Decodable);
  207. furi_hal_subghz_reset();
  208. do {
  209. if(!flipper_format_file_open_existing(fff_data_file, file_path)) {
  210. FURI_LOG_E(TAG, "Error open file %s", file_path);
  211. result = SubBruteFileResultErrorOpenFile;
  212. break;
  213. }
  214. if(!flipper_format_read_header(fff_data_file, temp_str, &temp_data32)) {
  215. FURI_LOG_E(TAG, "Missing or incorrect header");
  216. result = SubBruteFileResultMissingOrIncorrectHeader;
  217. break;
  218. }
  219. // Frequency
  220. if(flipper_format_read_uint32(fff_data_file, "Frequency", &temp_data32, 1)) {
  221. instance->file_protocol_info->frequency = temp_data32;
  222. if(!furi_hal_subghz_is_tx_allowed(instance->file_protocol_info->frequency)) {
  223. result = SubBruteFileResultFrequencyNotAllowed;
  224. break;
  225. }
  226. } else {
  227. FURI_LOG_E(TAG, "Missing or incorrect Frequency");
  228. result = SubBruteFileResultMissingOrIncorrectFrequency;
  229. break;
  230. }
  231. // Preset
  232. if(!flipper_format_read_string(fff_data_file, "Preset", temp_str)) {
  233. FURI_LOG_E(TAG, "Preset FAIL");
  234. result = SubBruteFileResultPresetInvalid;
  235. } else {
  236. instance->file_protocol_info->preset = subbrute_protocol_convert_preset(temp_str);
  237. }
  238. const char* protocol_file = NULL;
  239. // Protocol
  240. if(!flipper_format_read_string(fff_data_file, "Protocol", temp_str)) {
  241. FURI_LOG_E(TAG, "Missing Protocol");
  242. result = SubBruteFileResultMissingProtocol;
  243. break;
  244. } else {
  245. instance->file_protocol_info->file = subbrute_protocol_file_protocol_name(temp_str);
  246. protocol_file = subbrute_protocol_file(instance->file_protocol_info->file);
  247. #ifdef FURI_DEBUG
  248. FURI_LOG_D(TAG, "Protocol: %s", protocol_file);
  249. #endif
  250. }
  251. instance->decoder_result = subghz_receiver_search_decoder_base_by_name(
  252. instance->receiver, furi_string_get_cstr(temp_str));
  253. if((!instance->decoder_result) || (strcmp(protocol_file, "RAW") == 0) ||
  254. (strcmp(protocol_file, "Unknown") == 0)) {
  255. FURI_LOG_E(TAG, "Protocol unsupported");
  256. result = SubBruteFileResultProtocolNotSupported;
  257. break;
  258. }
  259. if(instance->decoder_result->protocol->type == SubGhzProtocolTypeDynamic) {
  260. FURI_LOG_E(TAG, "Protocol is dynamic - not supported");
  261. result = SubBruteFileResultDynamicProtocolNotValid;
  262. break;
  263. }
  264. #ifdef FURI_DEBUG
  265. else {
  266. FURI_LOG_D(TAG, "Decoder: %s", instance->decoder_result->protocol->name);
  267. }
  268. #endif
  269. // Bit
  270. if(!flipper_format_read_uint32(fff_data_file, "Bit", &temp_data32, 1)) {
  271. FURI_LOG_E(TAG, "Missing or incorrect Bit");
  272. result = SubBruteFileResultMissingOrIncorrectBit;
  273. break;
  274. } else {
  275. instance->file_protocol_info->bits = temp_data32;
  276. #ifdef FURI_DEBUG
  277. FURI_LOG_D(TAG, "Bit: %d", instance->file_protocol_info->bits);
  278. #endif
  279. }
  280. // Key
  281. if(!flipper_format_read_string(fff_data_file, "Key", temp_str)) {
  282. FURI_LOG_E(TAG, "Missing or incorrect Key");
  283. result = SubBruteFileResultMissingOrIncorrectKey;
  284. break;
  285. } else {
  286. snprintf(
  287. instance->file_key,
  288. sizeof(instance->file_key),
  289. "%s",
  290. furi_string_get_cstr(temp_str));
  291. #ifdef FURI_DEBUG
  292. FURI_LOG_D(TAG, "Key: %s", instance->file_key);
  293. #endif
  294. }
  295. flipper_format_rewind(fff_data_file);
  296. uint8_t key_data[sizeof(uint64_t)] = {0};
  297. if(!flipper_format_read_hex(fff_data_file, "Key", key_data, sizeof(uint64_t))) {
  298. FURI_LOG_E(TAG, "Missing Key");
  299. result = SubBruteFileResultMissingOrIncorrectKey;
  300. break;
  301. }
  302. uint64_t data = 0;
  303. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  304. data = (data << 8) | key_data[i];
  305. }
  306. instance->key_from_file = data;
  307. uint16_t add_value = 0x0001;
  308. uint8_t bit_index = 7;
  309. bool two_bytes = true;
  310. uint8_t p[8];
  311. for(int i = 0; i < 8; i++) {
  312. p[i] = (uint8_t)(instance->key_from_file >> 8 * (7 - i)) & 0xFF;
  313. }
  314. uint16_t num = two_bytes ? (p[bit_index - 1] << 8) | p[bit_index] : p[bit_index];
  315. FURI_LOG_D(TAG, "num: 0x%04X", num);
  316. num += add_value;
  317. FURI_LOG_D(TAG, "num added: 0x%04X", num);
  318. uint8_t low_byte = num & (0xff);
  319. uint8_t high_byte = (num >> 8) & 0xff;
  320. data = 0;
  321. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  322. if(i == bit_index - 1 && two_bytes) {
  323. data = (data << 8) | high_byte;
  324. data = (data << 8) | low_byte;
  325. i++;
  326. } else if(i == bit_index) {
  327. data = (data << 8) | low_byte;
  328. } else {
  329. data = (data << 8) | p[i];
  330. }
  331. }
  332. furi_string_printf(temp_str, "Key: %lX", (uint32_t)(data & 0xFFFFFFFF));
  333. FURI_LOG_D(
  334. TAG, "H: 0x%02X, L: 0x%02X, %s", high_byte, low_byte, furi_string_get_cstr(temp_str));
  335. // TE
  336. if(!flipper_format_read_uint32(fff_data_file, "TE", &temp_data32, 1)) {
  337. FURI_LOG_E(TAG, "Missing or incorrect TE");
  338. //result = SubBruteFileResultMissingOrIncorrectTe;
  339. //break;
  340. } else {
  341. instance->file_protocol_info->te = temp_data32 != 0 ? temp_data32 : 0;
  342. }
  343. // Repeat
  344. if(flipper_format_read_uint32(fff_data_file, "Repeat", &temp_data32, 1)) {
  345. #ifdef FURI_DEBUG
  346. FURI_LOG_D(TAG, "Repeat: %ld", temp_data32);
  347. #endif
  348. instance->file_protocol_info->repeat = (uint8_t)temp_data32;
  349. } else {
  350. #ifdef FURI_DEBUG
  351. FURI_LOG_D(TAG, "Repeat: 3 (default)");
  352. #endif
  353. instance->file_protocol_info->repeat = 3;
  354. }
  355. result = SubBruteFileResultOk;
  356. } while(0);
  357. furi_string_free(temp_str);
  358. flipper_format_file_close(fff_data_file);
  359. flipper_format_free(fff_data_file);
  360. furi_record_close(RECORD_STORAGE);
  361. subghz_receiver_free(instance->receiver);
  362. instance->decoder_result = NULL;
  363. instance->receiver = NULL;
  364. if(result == SubBruteFileResultOk) {
  365. #ifdef FURI_DEBUG
  366. FURI_LOG_D(TAG, "Loaded successfully");
  367. #endif
  368. } else {
  369. subbrute_device_free_protocol_info(instance);
  370. }
  371. return result;
  372. }
  373. void subbrute_device_attack_set_default_values(
  374. SubBruteDevice* instance,
  375. SubBruteAttacks default_attack) {
  376. furi_assert(instance);
  377. #ifdef FURI_DEBUG
  378. FURI_LOG_D(TAG, "subbrute_device_attack_set_default_values");
  379. #endif
  380. instance->attack = default_attack;
  381. instance->key_index = 0x00;
  382. instance->load_index = 0x00;
  383. instance->extra_repeats = 0;
  384. memset(instance->current_key, 0, sizeof(instance->current_key));
  385. if(default_attack != SubBruteAttackLoadFile) {
  386. memset(instance->file_key, 0, sizeof(instance->file_key));
  387. instance->max_value = (uint64_t)0x00;
  388. }
  389. }
  390. const char* subbrute_device_error_get_desc(SubBruteFileResult error_id) {
  391. const char* result;
  392. switch(error_id) {
  393. case(SubBruteFileResultOk):
  394. result = "OK";
  395. break;
  396. case(SubBruteFileResultErrorOpenFile):
  397. result = "invalid name/path";
  398. break;
  399. case(SubBruteFileResultMissingOrIncorrectHeader):
  400. result = "Missing or incorrect header";
  401. break;
  402. case(SubBruteFileResultFrequencyNotAllowed):
  403. result = "Invalid frequency!";
  404. break;
  405. case(SubBruteFileResultMissingOrIncorrectFrequency):
  406. result = "Missing or incorrect Frequency";
  407. break;
  408. case(SubBruteFileResultPresetInvalid):
  409. result = "Preset FAIL";
  410. break;
  411. case(SubBruteFileResultMissingProtocol):
  412. result = "Missing Protocol";
  413. break;
  414. case(SubBruteFileResultProtocolNotSupported):
  415. result = "Protocol unsupported";
  416. break;
  417. case(SubBruteFileResultDynamicProtocolNotValid):
  418. result = "Dynamic protocol unsupported";
  419. break;
  420. case(SubBruteFileResultProtocolNotFound):
  421. result = "Protocol not found";
  422. break;
  423. case(SubBruteFileResultMissingOrIncorrectBit):
  424. result = "Missing or incorrect Bit";
  425. break;
  426. case(SubBruteFileResultMissingOrIncorrectKey):
  427. result = "Missing or incorrect Key";
  428. break;
  429. case(SubBruteFileResultMissingOrIncorrectTe):
  430. result = "Missing or incorrect TE";
  431. break;
  432. case SubBruteFileResultUnknown:
  433. default:
  434. result = "Unknown error";
  435. break;
  436. }
  437. return result;
  438. }
  439. void subbrute_device_free_protocol_info(SubBruteDevice* instance) {
  440. furi_assert(instance);
  441. instance->protocol_info = NULL;
  442. if(instance->file_protocol_info) {
  443. free(instance->file_protocol_info);
  444. }
  445. instance->file_protocol_info = NULL;
  446. }