bad_usb_script.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468
  1. #include <furi.h>
  2. #include <furi-hal.h>
  3. #include <gui/gui.h>
  4. #include <input/input.h>
  5. #include <lib/toolbox/args.h>
  6. #include <furi-hal-usb-hid.h>
  7. #include <storage/storage.h>
  8. #include "bad_usb_script.h"
  9. #define TAG "BadUSB"
  10. #define WORKER_TAG TAG "Worker"
  11. #define FILE_BUFFER_LEN 16
  12. typedef enum {
  13. WorkerEvtReserved = (1 << 0),
  14. WorkerEvtToggle = (1 << 1),
  15. WorkerEvtEnd = (1 << 2),
  16. WorkerEvtConnect = (1 << 3),
  17. WorkerEvtDisconnect = (1 << 4),
  18. } WorkerEvtFlags;
  19. struct BadUsbScript {
  20. BadUsbState st;
  21. string_t file_path;
  22. uint32_t defdelay;
  23. FuriThread* thread;
  24. uint8_t file_buf[FILE_BUFFER_LEN + 1];
  25. uint8_t buf_start;
  26. uint8_t buf_len;
  27. bool file_end;
  28. string_t line;
  29. string_t line_prev;
  30. uint32_t repeat_cnt;
  31. };
  32. typedef struct {
  33. char* name;
  34. uint16_t keycode;
  35. } DuckyKey;
  36. static const DuckyKey ducky_keys[] = {
  37. {"CTRL-ALT", KEY_MOD_LEFT_CTRL | KEY_MOD_LEFT_ALT},
  38. {"CTRL-SHIFT", KEY_MOD_LEFT_CTRL | KEY_MOD_LEFT_SHIFT},
  39. {"ALT-SHIFT", KEY_MOD_LEFT_ALT | KEY_MOD_LEFT_SHIFT},
  40. {"ALT-GUI", KEY_MOD_LEFT_ALT | KEY_MOD_LEFT_GUI},
  41. {"CTRL", KEY_MOD_LEFT_CTRL},
  42. {"CONTROL", KEY_MOD_LEFT_CTRL},
  43. {"SHIFT", KEY_MOD_LEFT_SHIFT},
  44. {"ALT", KEY_MOD_LEFT_ALT},
  45. {"GUI", KEY_MOD_LEFT_GUI},
  46. {"WINDOWS", KEY_MOD_LEFT_GUI},
  47. {"DOWNARROW", KEY_DOWN_ARROW},
  48. {"DOWN", KEY_DOWN_ARROW},
  49. {"LEFTARROW", KEY_LEFT_ARROW},
  50. {"LEFT", KEY_LEFT_ARROW},
  51. {"RIGHTARROW", KEY_RIGHT_ARROW},
  52. {"RIGHT", KEY_RIGHT_ARROW},
  53. {"UPARROW", KEY_UP_ARROW},
  54. {"UP", KEY_UP_ARROW},
  55. {"ENTER", KEY_ENTER},
  56. {"BREAK", KEY_PAUSE},
  57. {"PAUSE", KEY_PAUSE},
  58. {"CAPSLOCK", KEY_CAPS_LOCK},
  59. {"DELETE", KEY_DELETE},
  60. {"BACKSPACE", KEY_BACKSPACE},
  61. {"END", KEY_END},
  62. {"ESC", KEY_ESC},
  63. {"ESCAPE", KEY_ESC},
  64. {"HOME", KEY_HOME},
  65. {"INSERT", KEY_INSERT},
  66. {"NUMLOCK", KEY_NUM_LOCK},
  67. {"PAGEUP", KEY_PAGE_UP},
  68. {"PAGEDOWN", KEY_PAGE_DOWN},
  69. {"PRINTSCREEN", KEY_PRINT},
  70. {"SCROLLOCK", KEY_SCROLL_LOCK},
  71. {"SPACE", KEY_SPACE},
  72. {"TAB", KEY_TAB},
  73. {"MENU", KEY_APPLICATION},
  74. {"APP", KEY_APPLICATION},
  75. {"F1", KEY_F1},
  76. {"F2", KEY_F2},
  77. {"F3", KEY_F3},
  78. {"F4", KEY_F4},
  79. {"F5", KEY_F5},
  80. {"F6", KEY_F6},
  81. {"F7", KEY_F7},
  82. {"F8", KEY_F8},
  83. {"F9", KEY_F9},
  84. {"F10", KEY_F10},
  85. {"F11", KEY_F11},
  86. {"F12", KEY_F12},
  87. };
  88. static const char ducky_cmd_comment[] = {"REM"};
  89. static const char ducky_cmd_delay[] = {"DELAY"};
  90. static const char ducky_cmd_string[] = {"STRING"};
  91. static const char ducky_cmd_defdelay_1[] = {"DEFAULT_DELAY"};
  92. static const char ducky_cmd_defdelay_2[] = {"DEFAULTDELAY"};
  93. static const char ducky_cmd_repeat[] = {"REPEAT"};
  94. static bool ducky_get_number(char* param, uint32_t* val) {
  95. uint32_t value = 0;
  96. if(sscanf(param, "%lu", &value) == 1) {
  97. *val = value;
  98. return true;
  99. }
  100. return false;
  101. }
  102. static uint32_t ducky_get_command_len(char* line) {
  103. uint32_t len = strlen(line);
  104. for(uint32_t i = 0; i < len; i++) {
  105. if(line[i] == ' ') return i;
  106. }
  107. return 0;
  108. }
  109. static bool ducky_string(char* param) {
  110. uint32_t i = 0;
  111. while(param[i] != '\0') {
  112. furi_hal_hid_kb_press(HID_ASCII_TO_KEY(param[i]));
  113. furi_hal_hid_kb_release(HID_ASCII_TO_KEY(param[i]));
  114. i++;
  115. }
  116. return true;
  117. }
  118. static uint16_t ducky_get_keycode(char* param, bool accept_chars) {
  119. for(uint8_t i = 0; i < (sizeof(ducky_keys) / sizeof(ducky_keys[0])); i++) {
  120. if(strncmp(param, ducky_keys[i].name, strlen(ducky_keys[i].name)) == 0)
  121. return ducky_keys[i].keycode;
  122. }
  123. if((accept_chars) && (strlen(param) > 0)) {
  124. return (HID_ASCII_TO_KEY(param[0]) & 0xFF);
  125. }
  126. return 0;
  127. }
  128. static int32_t ducky_parse_line(BadUsbScript* bad_usb, string_t line) {
  129. uint32_t line_len = string_size(line);
  130. char* line_t = (char*)string_get_cstr(line);
  131. bool state = false;
  132. for(uint32_t i = 0; i < line_len; i++) {
  133. if((line_t[i] != ' ') && (line_t[i] != '\t') && (line_t[i] != '\n')) {
  134. line_t = &line_t[i];
  135. break; // Skip spaces and tabs
  136. }
  137. if(i == line_len - 1) return 0; // Skip empty lines
  138. }
  139. FURI_LOG_I(WORKER_TAG, "line:%s", line_t);
  140. // General commands
  141. if(strncmp(line_t, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  142. // REM - comment line
  143. return (0);
  144. } else if(strncmp(line_t, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  145. // DELAY
  146. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  147. uint32_t delay_val = 0;
  148. state = ducky_get_number(line_t, &delay_val);
  149. if((state) && (delay_val > 0)) {
  150. return (int32_t)delay_val;
  151. }
  152. return (-1);
  153. } else if(
  154. (strncmp(line_t, ducky_cmd_defdelay_1, strlen(ducky_cmd_defdelay_1)) == 0) ||
  155. (strncmp(line_t, ducky_cmd_defdelay_2, strlen(ducky_cmd_defdelay_2)) == 0)) {
  156. // DEFAULT_DELAY
  157. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  158. state = ducky_get_number(line_t, &bad_usb->defdelay);
  159. return (state) ? (0) : (-1);
  160. } else if(strncmp(line_t, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  161. // STRING
  162. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  163. state = ducky_string(line_t);
  164. return (state) ? (0) : (-1);
  165. } else if(strncmp(line_t, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  166. // REPEAT
  167. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  168. state = ducky_get_number(line_t, &bad_usb->repeat_cnt);
  169. return (state) ? (0) : (-1);
  170. } else {
  171. // Special keys + modifiers
  172. uint16_t key = ducky_get_keycode(line_t, false);
  173. if(key == KEY_NONE) return (-1);
  174. if((key & 0xFF00) != 0) {
  175. // It's a modifier key
  176. line_t = &line_t[ducky_get_command_len(line_t) + 1];
  177. key |= ducky_get_keycode(line_t, true);
  178. }
  179. furi_hal_hid_kb_press(key);
  180. furi_hal_hid_kb_release(key);
  181. return (0);
  182. }
  183. return (-1);
  184. }
  185. static bool ducky_script_preload(BadUsbScript* bad_usb, File* script_file) {
  186. uint8_t ret = 0;
  187. uint32_t line_len = 0;
  188. do {
  189. ret = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  190. for(uint16_t i = 0; i < ret; i++) {
  191. if(bad_usb->file_buf[i] == '\n' && line_len > 0) {
  192. bad_usb->st.line_nb++;
  193. line_len = 0;
  194. } else {
  195. line_len++;
  196. }
  197. }
  198. if(storage_file_eof(script_file)) {
  199. if(line_len > 0) {
  200. bad_usb->st.line_nb++;
  201. break;
  202. }
  203. }
  204. } while(ret > 0);
  205. storage_file_seek(script_file, 0, true);
  206. return true;
  207. }
  208. static int32_t ducky_script_execute_next(BadUsbScript* bad_usb, File* script_file) {
  209. int32_t delay_val = 0;
  210. if(bad_usb->repeat_cnt > 0) {
  211. bad_usb->repeat_cnt--;
  212. delay_val = ducky_parse_line(bad_usb, bad_usb->line_prev);
  213. if(delay_val < 0) {
  214. bad_usb->st.error_line = bad_usb->st.line_cur - 1;
  215. FURI_LOG_E(WORKER_TAG, "Unknown command at line %lu", bad_usb->st.line_cur - 1);
  216. return (-1);
  217. } else {
  218. return (delay_val + bad_usb->defdelay);
  219. }
  220. }
  221. string_set(bad_usb->line_prev, bad_usb->line);
  222. string_reset(bad_usb->line);
  223. while(1) {
  224. if(bad_usb->buf_len == 0) {
  225. bad_usb->buf_len = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  226. if(storage_file_eof(script_file)) {
  227. if((bad_usb->buf_len < FILE_BUFFER_LEN) && (bad_usb->file_end == false)) {
  228. bad_usb->file_buf[bad_usb->buf_len] = '\n';
  229. bad_usb->buf_len++;
  230. bad_usb->file_end = true;
  231. }
  232. }
  233. bad_usb->buf_start = 0;
  234. if(bad_usb->buf_len == 0) return (-2);
  235. }
  236. for(uint8_t i = bad_usb->buf_start; i < (bad_usb->buf_start + bad_usb->buf_len); i++) {
  237. if(bad_usb->file_buf[i] == '\n' && string_size(bad_usb->line) > 0) {
  238. bad_usb->st.line_cur++;
  239. bad_usb->buf_len = bad_usb->buf_len + bad_usb->buf_start - (i + 1);
  240. bad_usb->buf_start = i + 1;
  241. delay_val = ducky_parse_line(bad_usb, bad_usb->line);
  242. if(delay_val < 0) {
  243. bad_usb->st.error_line = bad_usb->st.line_cur;
  244. FURI_LOG_E(WORKER_TAG, "Unknown command at line %lu", bad_usb->st.line_cur);
  245. return (-1);
  246. } else {
  247. return (delay_val + bad_usb->defdelay);
  248. }
  249. } else {
  250. string_push_back(bad_usb->line, bad_usb->file_buf[i]);
  251. }
  252. }
  253. bad_usb->buf_len = 0;
  254. if(bad_usb->file_end) return (-2);
  255. }
  256. return 0;
  257. }
  258. static void bad_usb_hid_state_callback(bool state, void* context) {
  259. furi_assert(context);
  260. BadUsbScript* bad_usb = context;
  261. if(state == true)
  262. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtConnect);
  263. else
  264. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtDisconnect);
  265. }
  266. static int32_t bad_usb_worker(void* context) {
  267. BadUsbScript* bad_usb = context;
  268. BadUsbWorkerState worker_state = BadUsbStateInit;
  269. int32_t delay_val = 0;
  270. FURI_LOG_I(WORKER_TAG, "Init");
  271. File* script_file = storage_file_alloc(furi_record_open("storage"));
  272. string_init(bad_usb->line);
  273. string_init(bad_usb->line_prev);
  274. furi_hal_hid_set_state_callback(bad_usb_hid_state_callback, bad_usb);
  275. while(1) {
  276. if(worker_state == BadUsbStateInit) { // State: initialization
  277. if(storage_file_open(
  278. script_file,
  279. string_get_cstr(bad_usb->file_path),
  280. FSAM_READ,
  281. FSOM_OPEN_EXISTING)) {
  282. if((ducky_script_preload(bad_usb, script_file)) && (bad_usb->st.line_nb > 0)) {
  283. if(furi_hal_hid_is_connected()) {
  284. worker_state = BadUsbStateIdle; // Ready to run
  285. } else {
  286. worker_state = BadUsbStateNotConnected; // USB not connected
  287. }
  288. } else {
  289. worker_state = BadUsbStateScriptError; // Script preload error
  290. }
  291. } else {
  292. FURI_LOG_E(WORKER_TAG, "File open error");
  293. worker_state = BadUsbStateFileError; // File open error
  294. }
  295. bad_usb->st.state = worker_state;
  296. } else if(worker_state == BadUsbStateNotConnected) { // State: USB not connected
  297. uint32_t flags =
  298. osThreadFlagsWait(WorkerEvtEnd | WorkerEvtConnect, osFlagsWaitAny, osWaitForever);
  299. furi_check((flags & osFlagsError) == 0);
  300. if(flags & WorkerEvtEnd) {
  301. break;
  302. } else if(flags & WorkerEvtConnect) {
  303. worker_state = BadUsbStateIdle; // Ready to run
  304. }
  305. bad_usb->st.state = worker_state;
  306. } else if(worker_state == BadUsbStateIdle) { // State: ready to start
  307. uint32_t flags = osThreadFlagsWait(
  308. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect,
  309. osFlagsWaitAny,
  310. osWaitForever);
  311. furi_check((flags & osFlagsError) == 0);
  312. if(flags & WorkerEvtEnd) {
  313. break;
  314. } else if(flags & WorkerEvtToggle) { // Start executing script
  315. delay_val = 0;
  316. bad_usb->buf_len = 0;
  317. bad_usb->st.line_cur = 0;
  318. bad_usb->defdelay = 0;
  319. bad_usb->repeat_cnt = 0;
  320. bad_usb->file_end = false;
  321. storage_file_seek(script_file, 0, true);
  322. worker_state = BadUsbStateRunning;
  323. } else if(flags & WorkerEvtDisconnect) {
  324. worker_state = BadUsbStateNotConnected; // USB disconnected
  325. }
  326. bad_usb->st.state = worker_state;
  327. } else if(worker_state == BadUsbStateRunning) { // State: running
  328. uint16_t delay_cur = (delay_val > 1000) ? (1000) : (delay_val);
  329. uint32_t flags = osThreadFlagsWait(
  330. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect, osFlagsWaitAny, delay_cur);
  331. delay_val -= delay_cur;
  332. if(!(flags & osFlagsError)) {
  333. if(flags & WorkerEvtEnd) {
  334. break;
  335. } else if(flags & WorkerEvtToggle) {
  336. worker_state = BadUsbStateIdle; // Stop executing script
  337. furi_hal_hid_kb_release_all();
  338. } else if(flags & WorkerEvtDisconnect) {
  339. worker_state = BadUsbStateNotConnected; // USB disconnected
  340. furi_hal_hid_kb_release_all();
  341. }
  342. bad_usb->st.state = worker_state;
  343. continue;
  344. } else if((flags == osFlagsErrorTimeout) || (flags == osFlagsErrorResource)) {
  345. if(delay_val > 0) {
  346. bad_usb->st.delay_remain--;
  347. continue;
  348. }
  349. bad_usb->st.state = BadUsbStateRunning;
  350. delay_val = ducky_script_execute_next(bad_usb, script_file);
  351. if(delay_val == -1) { // Script error
  352. delay_val = 0;
  353. worker_state = BadUsbStateScriptError;
  354. bad_usb->st.state = worker_state;
  355. } else if(delay_val == -2) { // End of script
  356. delay_val = 0;
  357. worker_state = BadUsbStateIdle;
  358. bad_usb->st.state = BadUsbStateDone;
  359. furi_hal_hid_kb_release_all();
  360. continue;
  361. } else if(delay_val > 1000) {
  362. bad_usb->st.state = BadUsbStateDelay; // Show long delays
  363. bad_usb->st.delay_remain = delay_val / 1000;
  364. }
  365. } else {
  366. furi_check((flags & osFlagsError) == 0);
  367. }
  368. } else if(
  369. (worker_state == BadUsbStateFileError) ||
  370. (worker_state == BadUsbStateScriptError)) { // State: error
  371. uint32_t flags = osThreadFlagsWait(
  372. WorkerEvtEnd, osFlagsWaitAny, osWaitForever); // Waiting for exit command
  373. furi_check((flags & osFlagsError) == 0);
  374. if(flags & WorkerEvtEnd) {
  375. break;
  376. }
  377. }
  378. }
  379. furi_hal_hid_set_state_callback(NULL, NULL);
  380. storage_file_close(script_file);
  381. storage_file_free(script_file);
  382. string_clear(bad_usb->line);
  383. string_clear(bad_usb->line_prev);
  384. FURI_LOG_I(WORKER_TAG, "End");
  385. return 0;
  386. }
  387. BadUsbScript* bad_usb_script_open(string_t file_path) {
  388. furi_assert(file_path);
  389. BadUsbScript* bad_usb = furi_alloc(sizeof(BadUsbScript));
  390. string_init(bad_usb->file_path);
  391. string_set(bad_usb->file_path, file_path);
  392. bad_usb->st.state = BadUsbStateInit;
  393. bad_usb->thread = furi_thread_alloc();
  394. furi_thread_set_name(bad_usb->thread, "BadUsbWorker");
  395. furi_thread_set_stack_size(bad_usb->thread, 2048);
  396. furi_thread_set_context(bad_usb->thread, bad_usb);
  397. furi_thread_set_callback(bad_usb->thread, bad_usb_worker);
  398. furi_thread_start(bad_usb->thread);
  399. return bad_usb;
  400. }
  401. void bad_usb_script_close(BadUsbScript* bad_usb) {
  402. furi_assert(bad_usb);
  403. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtEnd);
  404. furi_thread_join(bad_usb->thread);
  405. furi_thread_free(bad_usb->thread);
  406. string_clear(bad_usb->file_path);
  407. free(bad_usb);
  408. }
  409. void bad_usb_script_toggle(BadUsbScript* bad_usb) {
  410. furi_assert(bad_usb);
  411. osThreadFlagsSet(furi_thread_get_thread_id(bad_usb->thread), WorkerEvtToggle);
  412. }
  413. BadUsbState* bad_usb_script_get_state(BadUsbScript* bad_usb) {
  414. furi_assert(bad_usb);
  415. return &(bad_usb->st);
  416. }