subbrute_device.c 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561
  1. #include "subbrute_device.h"
  2. #include <stdint.h>
  3. #include <storage/storage.h>
  4. #include <lib/toolbox/stream/stream.h>
  5. #include <lib/flipper_format/flipper_format.h>
  6. #include <lib/flipper_format/flipper_format_i.h>
  7. #include <lib/subghz/protocols/protocol_items.h>
  8. #define TAG "SubBruteDevice"
  9. SubBruteDevice* subbrute_device_alloc() {
  10. SubBruteDevice* instance = malloc(sizeof(SubBruteDevice));
  11. instance->current_step = 0;
  12. instance->protocol_info = NULL;
  13. instance->file_protocol_info = NULL;
  14. instance->decoder_result = NULL;
  15. instance->receiver = NULL;
  16. instance->environment = subghz_environment_alloc();
  17. subghz_environment_set_protocol_registry(
  18. instance->environment, (void*)&subghz_protocol_registry);
  19. #ifdef FURI_DEBUG
  20. subbrute_device_attack_set_default_values(instance, SubBruteAttackCAME12bit433);
  21. #else
  22. subbrute_device_attack_set_default_values(instance, SubBruteAttackLoadFile);
  23. #endif
  24. return instance;
  25. }
  26. void subbrute_device_free(SubBruteDevice* instance) {
  27. furi_assert(instance);
  28. // I don't know how to free this
  29. instance->decoder_result = NULL;
  30. if(instance->receiver != NULL) {
  31. subghz_receiver_free(instance->receiver);
  32. instance->receiver = NULL;
  33. }
  34. subghz_environment_free(instance->environment);
  35. instance->environment = NULL;
  36. subbrute_device_free_protocol_info(instance);
  37. free(instance);
  38. }
  39. uint64_t subbrute_device_add_step(SubBruteDevice* instance, int8_t step) {
  40. if(step > 0) {
  41. if((instance->current_step + step) - instance->max_value == 1) {
  42. instance->current_step = 0x00;
  43. } else {
  44. uint64_t value = instance->current_step + step;
  45. if(value == instance->max_value) {
  46. instance->current_step = value;
  47. } else {
  48. instance->current_step = value % instance->max_value;
  49. }
  50. }
  51. } else {
  52. if(instance->current_step + step == 0) {
  53. instance->current_step = 0x00;
  54. } else if(instance->current_step == 0) {
  55. instance->current_step = instance->max_value;
  56. } else {
  57. uint64_t value = ((instance->current_step + step) + instance->max_value);
  58. if(value == instance->max_value) {
  59. instance->current_step = value;
  60. } else {
  61. instance->current_step = value % instance->max_value;
  62. }
  63. }
  64. }
  65. return instance->current_step;
  66. }
  67. bool subbrute_device_save_file(SubBruteDevice* instance, const char* dev_file_name) {
  68. furi_assert(instance);
  69. #ifdef FURI_DEBUG
  70. FURI_LOG_D(TAG, "subbrute_device_save_file: %s", dev_file_name);
  71. #endif
  72. Storage* storage = furi_record_open(RECORD_STORAGE);
  73. FlipperFormat* file = flipper_format_file_alloc(storage);
  74. bool result = false;
  75. do {
  76. if(!flipper_format_file_open_always(file, dev_file_name)) {
  77. FURI_LOG_E(TAG, "Failed to open file: %s", dev_file_name);
  78. break;
  79. }
  80. Stream* stream = flipper_format_get_raw_stream(file);
  81. if(instance->attack == SubBruteAttackLoadFile) {
  82. subbrute_protocol_file_generate_file(
  83. stream,
  84. instance->file_protocol_info->frequency,
  85. instance->file_protocol_info->preset,
  86. instance->file_protocol_info->file,
  87. instance->current_step,
  88. instance->file_protocol_info->bits,
  89. instance->file_protocol_info->te,
  90. instance->file_protocol_info->repeat,
  91. instance->bit_index,
  92. instance->key_from_file,
  93. instance->two_bytes);
  94. } else {
  95. subbrute_protocol_default_generate_file(
  96. stream,
  97. instance->protocol_info->frequency,
  98. instance->protocol_info->preset,
  99. instance->protocol_info->file,
  100. instance->current_step,
  101. instance->protocol_info->bits,
  102. instance->protocol_info->te,
  103. instance->protocol_info->repeat);
  104. }
  105. result = true;
  106. } while(false);
  107. if(!result) {
  108. FURI_LOG_E(TAG, "subbrute_device_save_file failed!");
  109. }
  110. flipper_format_file_close(file);
  111. flipper_format_free(file);
  112. furi_record_close(RECORD_STORAGE);
  113. return result;
  114. }
  115. SubBruteFileResult subbrute_device_attack_set(
  116. SubBruteDevice* instance,
  117. SubBruteAttacks type,
  118. uint8_t extra_repeats) {
  119. furi_assert(instance);
  120. #ifdef FURI_DEBUG
  121. FURI_LOG_D(TAG, "subbrute_device_attack_set: %d, extra_repeats: %d", type, extra_repeats);
  122. #endif
  123. subbrute_device_attack_set_default_values(instance, type);
  124. if(type != SubBruteAttackLoadFile) {
  125. subbrute_device_free_protocol_info(instance);
  126. instance->protocol_info = subbrute_protocol(type);
  127. }
  128. instance->extra_repeats = extra_repeats;
  129. // For non-file types we didn't set SubGhzProtocolDecoderBase
  130. instance->receiver = subghz_receiver_alloc_init(instance->environment);
  131. subghz_receiver_set_filter(instance->receiver, SubGhzProtocolFlag_Decodable);
  132. furi_hal_subghz_reset();
  133. uint8_t protocol_check_result = SubBruteFileResultProtocolNotFound;
  134. #ifdef FURI_DEBUG
  135. uint8_t bits;
  136. uint8_t te;
  137. uint8_t repeat;
  138. FuriHalSubGhzPreset preset;
  139. SubBruteFileProtocol file;
  140. #endif
  141. if(type != SubBruteAttackLoadFile) {
  142. instance->decoder_result = subghz_receiver_search_decoder_base_by_name(
  143. instance->receiver, subbrute_protocol_file(instance->protocol_info->file));
  144. if(!instance->decoder_result ||
  145. instance->decoder_result->protocol->type == SubGhzProtocolTypeDynamic) {
  146. FURI_LOG_E(TAG, "Can't load SubGhzProtocolDecoderBase in phase non-file decoder set");
  147. } else {
  148. protocol_check_result = SubBruteFileResultOk;
  149. // Calc max value
  150. instance->max_value =
  151. subbrute_protocol_calc_max_value(instance->attack, instance->protocol_info->bits);
  152. }
  153. #ifdef FURI_DEBUG
  154. bits = instance->protocol_info->bits;
  155. te = instance->protocol_info->te;
  156. repeat = instance->protocol_info->repeat + instance->extra_repeats;
  157. preset = instance->protocol_info->preset;
  158. file = instance->protocol_info->file;
  159. #endif
  160. } else {
  161. // And here we need to set preset enum
  162. protocol_check_result = SubBruteFileResultOk;
  163. // Calc max value
  164. instance->max_value =
  165. subbrute_protocol_calc_max_value(instance->attack, instance->file_protocol_info->bits);
  166. #ifdef FURI_DEBUG
  167. bits = instance->file_protocol_info->bits;
  168. te = instance->file_protocol_info->te;
  169. repeat = instance->file_protocol_info->repeat + instance->extra_repeats;
  170. preset = instance->file_protocol_info->preset;
  171. file = instance->file_protocol_info->file;
  172. #endif
  173. }
  174. subghz_receiver_free(instance->receiver);
  175. instance->receiver = NULL;
  176. if(protocol_check_result != SubBruteFileResultOk) {
  177. return SubBruteFileResultProtocolNotFound;
  178. }
  179. #ifdef FURI_DEBUG
  180. FURI_LOG_I(
  181. TAG,
  182. "subbrute_device_attack_set: %s, bits: %d, preset: %s, file: %s, te: %d, repeat: %d, max_value: %lld",
  183. subbrute_protocol_name(instance->attack),
  184. bits,
  185. subbrute_protocol_preset(preset),
  186. subbrute_protocol_file(file),
  187. te,
  188. repeat,
  189. instance->max_value);
  190. #endif
  191. return SubBruteFileResultOk;
  192. }
  193. uint8_t subbrute_device_load_from_file(SubBruteDevice* instance, const char* file_path) {
  194. furi_assert(instance);
  195. #ifdef FURI_DEBUG
  196. FURI_LOG_D(TAG, "subbrute_device_load_from_file: %s", file_path);
  197. #endif
  198. SubBruteFileResult result = SubBruteFileResultUnknown;
  199. Storage* storage = furi_record_open(RECORD_STORAGE);
  200. FlipperFormat* fff_data_file = flipper_format_file_alloc(storage);
  201. subbrute_device_free_protocol_info(instance);
  202. instance->file_protocol_info = malloc(sizeof(SubBruteProtocol));
  203. FuriString* temp_str;
  204. temp_str = furi_string_alloc();
  205. uint32_t temp_data32;
  206. instance->receiver = subghz_receiver_alloc_init(instance->environment);
  207. subghz_receiver_set_filter(instance->receiver, SubGhzProtocolFlag_Decodable);
  208. furi_hal_subghz_reset();
  209. do {
  210. if(!flipper_format_file_open_existing(fff_data_file, file_path)) {
  211. FURI_LOG_E(TAG, "Error open file %s", file_path);
  212. result = SubBruteFileResultErrorOpenFile;
  213. break;
  214. }
  215. if(!flipper_format_read_header(fff_data_file, temp_str, &temp_data32)) {
  216. FURI_LOG_E(TAG, "Missing or incorrect header");
  217. result = SubBruteFileResultMissingOrIncorrectHeader;
  218. break;
  219. }
  220. // Frequency
  221. if(flipper_format_read_uint32(fff_data_file, "Frequency", &temp_data32, 1)) {
  222. instance->file_protocol_info->frequency = temp_data32;
  223. if(!furi_hal_subghz_is_tx_allowed(instance->file_protocol_info->frequency)) {
  224. result = SubBruteFileResultFrequencyNotAllowed;
  225. break;
  226. }
  227. } else {
  228. FURI_LOG_E(TAG, "Missing or incorrect Frequency");
  229. result = SubBruteFileResultMissingOrIncorrectFrequency;
  230. break;
  231. }
  232. // Preset
  233. if(!flipper_format_read_string(fff_data_file, "Preset", temp_str)) {
  234. FURI_LOG_E(TAG, "Preset FAIL");
  235. result = SubBruteFileResultPresetInvalid;
  236. } else {
  237. instance->file_protocol_info->preset = subbrute_protocol_convert_preset(temp_str);
  238. }
  239. const char* protocol_file = NULL;
  240. // Protocol
  241. if(!flipper_format_read_string(fff_data_file, "Protocol", temp_str)) {
  242. FURI_LOG_E(TAG, "Missing Protocol");
  243. result = SubBruteFileResultMissingProtocol;
  244. break;
  245. } else {
  246. instance->file_protocol_info->file = subbrute_protocol_file_protocol_name(temp_str);
  247. protocol_file = subbrute_protocol_file(instance->file_protocol_info->file);
  248. #ifdef FURI_DEBUG
  249. FURI_LOG_D(TAG, "Protocol: %s", protocol_file);
  250. #endif
  251. }
  252. instance->decoder_result = subghz_receiver_search_decoder_base_by_name(
  253. instance->receiver, furi_string_get_cstr(temp_str));
  254. if((!instance->decoder_result) || (strcmp(protocol_file, "RAW") == 0) ||
  255. (strcmp(protocol_file, "Unknown") == 0)) {
  256. FURI_LOG_E(TAG, "Protocol unsupported");
  257. result = SubBruteFileResultProtocolNotSupported;
  258. break;
  259. }
  260. if(instance->decoder_result->protocol->type == SubGhzProtocolTypeDynamic) {
  261. FURI_LOG_E(TAG, "Protocol is dynamic - not supported");
  262. result = SubBruteFileResultDynamicProtocolNotValid;
  263. break;
  264. }
  265. #ifdef FURI_DEBUG
  266. else {
  267. FURI_LOG_D(TAG, "Decoder: %s", instance->decoder_result->protocol->name);
  268. }
  269. #endif
  270. // Bit
  271. if(!flipper_format_read_uint32(fff_data_file, "Bit", &temp_data32, 1)) {
  272. FURI_LOG_E(TAG, "Missing or incorrect Bit");
  273. result = SubBruteFileResultMissingOrIncorrectBit;
  274. break;
  275. } else {
  276. instance->file_protocol_info->bits = temp_data32;
  277. #ifdef FURI_DEBUG
  278. FURI_LOG_D(TAG, "Bit: %d", instance->file_protocol_info->bits);
  279. #endif
  280. }
  281. // TODO: Delete this
  282. // Key
  283. // if(!flipper_format_read_string(fff_data_file, "Key", temp_str)) {
  284. // FURI_LOG_E(TAG, "Missing or incorrect Key");
  285. // result = SubBruteFileResultMissingOrIncorrectKey;
  286. // break;
  287. // } else {
  288. // snprintf(
  289. // instance->file_key,
  290. // sizeof(instance->file_key),
  291. // "%s",
  292. // furi_string_get_cstr(temp_str));
  293. // #ifdef FURI_DEBUG
  294. // FURI_LOG_D(TAG, "Key: %s", instance->file_key);
  295. // #endif
  296. // }
  297. //
  298. // flipper_format_rewind(fff_data_file);
  299. uint8_t key_data[sizeof(uint64_t)] = {0};
  300. if(!flipper_format_read_hex(fff_data_file, "Key", key_data, sizeof(uint64_t))) {
  301. FURI_LOG_E(TAG, "Missing Key");
  302. result = SubBruteFileResultMissingOrIncorrectKey;
  303. break;
  304. }
  305. uint64_t data = 0;
  306. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  307. data = (data << 8) | key_data[i];
  308. }
  309. instance->key_from_file = data;
  310. uint16_t add_value = 0x0001;
  311. uint8_t bit_index = 7;
  312. bool two_bytes = true;
  313. uint8_t p[8];
  314. for(int i = 0; i < 8; i++) {
  315. p[i] = (uint8_t)(instance->key_from_file >> 8 * (7 - i)) & 0xFF;
  316. }
  317. uint16_t num = two_bytes ? (p[bit_index - 1] << 8) | p[bit_index] : p[bit_index];
  318. FURI_LOG_D(TAG, "num: 0x%04X", num);
  319. num += add_value;
  320. FURI_LOG_D(TAG, "num added: 0x%04X", num);
  321. uint8_t low_byte = num & (0xff);
  322. uint8_t high_byte = (num >> 8) & 0xff;
  323. data = 0;
  324. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  325. if(i == bit_index - 1 && two_bytes) {
  326. data = (data << 8) | high_byte;
  327. data = (data << 8) | low_byte;
  328. i++;
  329. } else if(i == bit_index) {
  330. data = (data << 8) | low_byte;
  331. } else {
  332. data = (data << 8) | p[i];
  333. }
  334. }
  335. furi_string_printf(temp_str, "Key: %lX", (uint32_t)(data & 0xFFFFFFFF));
  336. FURI_LOG_D(
  337. TAG, "H: 0x%02X, L: 0x%02X, %s", high_byte, low_byte, furi_string_get_cstr(temp_str));
  338. flipper_format_rewind(fff_data_file);
  339. uint8_t key_data[sizeof(uint64_t)] = {0};
  340. if(!flipper_format_read_hex(fff_data_file, "Key", key_data, sizeof(uint64_t))) {
  341. FURI_LOG_E(TAG, "Missing Key");
  342. result = SubBruteFileResultMissingOrIncorrectKey;
  343. break;
  344. }
  345. uint64_t data = 0;
  346. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  347. data = (data << 8) | key_data[i];
  348. }
  349. instance->key_from_file = data;
  350. uint16_t add_value = 0x0001;
  351. uint8_t bit_index = 7;
  352. bool two_bytes = true;
  353. uint8_t p[8];
  354. for(int i = 0; i < 8; i++) {
  355. p[i] = (uint8_t)(instance->key_from_file >> 8 * (7 - i)) & 0xFF;
  356. }
  357. uint16_t num = two_bytes ? (p[bit_index - 1] << 8) | p[bit_index] : p[bit_index];
  358. FURI_LOG_D(TAG, "num: 0x%04X", num);
  359. num += add_value;
  360. FURI_LOG_D(TAG, "num added: 0x%04X", num);
  361. uint8_t low_byte = num & (0xff);
  362. uint8_t high_byte = (num >> 8) & 0xff;
  363. data = 0;
  364. for(uint8_t i = 0; i < sizeof(uint64_t); i++) {
  365. if(i == bit_index - 1 && two_bytes) {
  366. data = (data << 8) | high_byte;
  367. data = (data << 8) | low_byte;
  368. i++;
  369. } else if(i == bit_index) {
  370. data = (data << 8) | low_byte;
  371. } else {
  372. data = (data << 8) | p[i];
  373. }
  374. }
  375. furi_string_printf(temp_str, "Key: %lX", (uint32_t)(data & 0xFFFFFFFF));
  376. FURI_LOG_D(
  377. TAG, "H: 0x%02X, L: 0x%02X, %s", high_byte, low_byte, furi_string_get_cstr(temp_str));
  378. // TE
  379. if(!flipper_format_read_uint32(fff_data_file, "TE", &temp_data32, 1)) {
  380. FURI_LOG_E(TAG, "Missing or incorrect TE");
  381. //result = SubBruteFileResultMissingOrIncorrectTe;
  382. //break;
  383. } else {
  384. instance->file_protocol_info->te = temp_data32 != 0 ? temp_data32 : 0;
  385. }
  386. // Repeat
  387. if(flipper_format_read_uint32(fff_data_file, "Repeat", &temp_data32, 1)) {
  388. #ifdef FURI_DEBUG
  389. FURI_LOG_D(TAG, "Repeat: %ld", temp_data32);
  390. #endif
  391. instance->file_protocol_info->repeat = (uint8_t)temp_data32;
  392. } else {
  393. #ifdef FURI_DEBUG
  394. FURI_LOG_D(TAG, "Repeat: 3 (default)");
  395. #endif
  396. instance->file_protocol_info->repeat = 3;
  397. }
  398. result = SubBruteFileResultOk;
  399. } while(0);
  400. furi_string_free(temp_str);
  401. flipper_format_file_close(fff_data_file);
  402. flipper_format_free(fff_data_file);
  403. furi_record_close(RECORD_STORAGE);
  404. subghz_receiver_free(instance->receiver);
  405. instance->decoder_result = NULL;
  406. instance->receiver = NULL;
  407. if(result == SubBruteFileResultOk) {
  408. #ifdef FURI_DEBUG
  409. FURI_LOG_D(TAG, "Loaded successfully");
  410. #endif
  411. } else {
  412. subbrute_device_free_protocol_info(instance);
  413. }
  414. return result;
  415. }
  416. void subbrute_device_attack_set_default_values(
  417. SubBruteDevice* instance,
  418. SubBruteAttacks default_attack) {
  419. furi_assert(instance);
  420. #ifdef FURI_DEBUG
  421. FURI_LOG_D(TAG, "subbrute_device_attack_set_default_values");
  422. #endif
  423. instance->attack = default_attack;
  424. instance->current_step = 0x00;
  425. instance->bit_index = 0x00;
  426. instance->extra_repeats = 0;
  427. instance->two_bytes = false;
  428. memset(instance->current_key, 0, sizeof(instance->current_key));
  429. if(default_attack != SubBruteAttackLoadFile) {
  430. memset(instance->file_key, 0, sizeof(instance->file_key));
  431. instance->max_value = (uint64_t)0x00;
  432. }
  433. }
  434. const char* subbrute_device_error_get_desc(SubBruteFileResult error_id) {
  435. const char* result;
  436. switch(error_id) {
  437. case(SubBruteFileResultOk):
  438. result = "OK";
  439. break;
  440. case(SubBruteFileResultErrorOpenFile):
  441. result = "invalid name/path";
  442. break;
  443. case(SubBruteFileResultMissingOrIncorrectHeader):
  444. result = "Missing or incorrect header";
  445. break;
  446. case(SubBruteFileResultFrequencyNotAllowed):
  447. result = "Invalid frequency!";
  448. break;
  449. case(SubBruteFileResultMissingOrIncorrectFrequency):
  450. result = "Missing or incorrect Frequency";
  451. break;
  452. case(SubBruteFileResultPresetInvalid):
  453. result = "Preset FAIL";
  454. break;
  455. case(SubBruteFileResultMissingProtocol):
  456. result = "Missing Protocol";
  457. break;
  458. case(SubBruteFileResultProtocolNotSupported):
  459. result = "Protocol unsupported";
  460. break;
  461. case(SubBruteFileResultDynamicProtocolNotValid):
  462. result = "Dynamic protocol unsupported";
  463. break;
  464. case(SubBruteFileResultProtocolNotFound):
  465. result = "Protocol not found";
  466. break;
  467. case(SubBruteFileResultMissingOrIncorrectBit):
  468. result = "Missing or incorrect Bit";
  469. break;
  470. case(SubBruteFileResultMissingOrIncorrectKey):
  471. result = "Missing or incorrect Key";
  472. break;
  473. case(SubBruteFileResultMissingOrIncorrectTe):
  474. result = "Missing or incorrect TE";
  475. break;
  476. case SubBruteFileResultUnknown:
  477. default:
  478. result = "Unknown error";
  479. break;
  480. }
  481. return result;
  482. }
  483. void subbrute_device_free_protocol_info(SubBruteDevice* instance) {
  484. furi_assert(instance);
  485. instance->protocol_info = NULL;
  486. if(instance->file_protocol_info) {
  487. free(instance->file_protocol_info);
  488. }
  489. instance->file_protocol_info = NULL;
  490. }