'goodfet.nrf sniffnike' for sniffing Nike+iPod packets.
[goodfet] / client / goodfet.cc
index 20b0405..e58ec68 100755 (executable)
@@ -16,23 +16,17 @@ from intelhex import IntelHex;
 def printpacket(packet):
     s="";
     i=0;
-    #print "Printing packet."
     for foo in packet:
         i=i+1;
-        #if i>packet[0]+1: break;
         s="%s %02x" % (s,foo);
-    print "%s" %s;
+    print "%s" %s;
 
+simplepacketcount=0;
 def handlesimplicitipacket(packet):
     s="";
     i=0;
-    
-    for foo in packet:
-        i=i+1;
-        #if i>packet[0]+1: break;
-        s="%s %02x" % (s,foo);
-    print "\n%s" %s;
-    
+    global simplepacketcount;
+    simplepacketcount=simplepacketcount+1;
     
     len=packet[0];
     if len<12: return;
@@ -50,33 +44,64 @@ def handlesimplicitipacket(packet):
     seq=packet[11];
     #payload begins at byte 10.
     
-    
-    if port==0x20:
+    if packet[len+2]&0x80==0:
+        print "# Dropped broken packet.";
+    elif port==0x20:
         #data packet
-        x=packet[11];
-        y=packet[13];
+        counter=packet[11];
+        button=packet[12];
+        x=packet[13];
+        if x>=128: x=0-(x^0xFF)-1;
+        y=packet[14];
+        if y>=128: y=0-(y^0xFF)-1;
         z=packet[15];
-        print "%02x: %i %i %i" % (seq,x,y,z);
+        if z>=128: z=0-(z^0xFF)-1;
+        
+        print "%09i %03i %4i %4i %4i" % (simplepacketcount,button,x,y,z);
+        sys.stdout.flush();
+    elif port==0x02:
+        #Link request.  Gotta send a proper reply to get data.
+        tid=packet[13];
+        #14 ff ff ff ff 3c b7 e3 98 
+        #02 03 c9
+        #01 97
+        #ef be ad de 3d 00 02 
+        reply=[0x10,
+               src[0], src[1], src[2], src[3],
+               0x78,0x56,0x34,0x10, #my address.
+               port, 0x21, seq,
+               0x81, tid,         #reply, tid
+               
+               0x20,0x00,0xad,0xde, #link token
+               0x00];               #no security
+        #printpacket(reply);
+        print "#FIXME FAST: repeatedly broadcasting ACK to catch LINK on the next attempt.";
+        for foo in range(1,50):
+            client.RF_txpacket(reply);
+        
+        pass;
     elif port==0x03:
         #print "Join request.";
+        #printpacket(packet);
         if packet[12]!=1:
             print "Not a join request.  WTF?";
             return;
         tid=packet[13];
         reply=[0x12, #reply is one byte shorter
                src[0], src[1], src[2], src[3],
-               1,1,1,1,           #my address
+               0x78,0x56,0x34,0x10, #my address.
                port, 0x21, seq,
                0x81, tid,         #reply, tid
                
-               1,1,1,1,
-               #4,3,2,1,           #default join token
-               #8,7,6,5,          #default link token
-               #0xFF,0xFF,0xFF,0xFF,
+               0xef,0xbe,0xad,0xde, #Join token
                0x00];             #no security
-        printpacket(reply);
-        client.RF_txpacket(reply);
-
+        #printpacket(reply);
+        print "#FIXME FAST: repeatedly broadcasting ACK to catch JOIN on the next attempt.";
+        #printpacket(reply);
+        for foo in range(1,50):
+            client.RF_txpacket(reply);
+        
+        
     elif port==0x04:
         print "Security request.";
     elif port==0x05:
@@ -93,6 +118,7 @@ if(len(sys.argv)==1):
     print "%s test" % sys.argv[0];
     print "%s term" % sys.argv[0];
     print "%s info" % sys.argv[0];
+    print "%s infotest" % sys.argv[0];
     print "%s halt"  % sys.argv[0];
     print "%s regs" % sys.argv[0];
     print "%s dumpcode $foo.hex [0x$start 0x$stop]" % sys.argv[0];
@@ -109,6 +135,11 @@ if(len(sys.argv)==1):
     print "%s carrier [freq]\n\tHolds a carrier on [freq] Hz." % sys.argv[0];
     print "%s reflex [freq]\n\tJams on [freq] Hz." % sys.argv[0];
     print "%s sniffsimpliciti [us|eu|lf]\n\tSniffs SimpliciTI packets." % sys.argv[0];
+    print "%s sniffdash7 [lf]\n\tSniffs Dash7. (untested)" % sys.argv[0];
+    print "%s snifficlicker [us]\n\tSniffs iClicker." % sys.argv[0];
+    print "\n";
+    print "%s simpliciti [us|eu|lf]\n\tSimpliciti access point for Chronos watch." % sys.argv[0];
+    print "%s iclicker [us|eu|lf]\n\tSniffs iClicker packets as ASCII." % sys.argv[0];
     
     sys.exit();
 
@@ -153,27 +184,7 @@ if(sys.argv[1]=="reflex"):
         #client.CCdebuginstr([0x02, 0xf0, 0x00]); #ljmp 0xF000
         client.resume();
     
-    RFST=0xDFE1
-    client.CC_RFST_CAL(); #SCAL
-    time.sleep(1);
-    
-    maxrssi=0;
-    while 1:
-        client.CC_RFST_RX(); #SRX
-        rssi=client.RF_getrssi();
-        client.CC_RFST_IDLE(); #idle
-        time.sleep(0.01);
-        string="";
-        for foo in range(0,rssi>>2):
-            string=("%s."%string);
-        print "%02x %04i %04i %s" % (rssi,rssi, maxrssi, string); 
-        if rssi>maxrssi:
-            maxrssi=(rssi);
-        if rssi>threshold:
-            #print "Triggered jamming for 1s.";
-            client.RF_carrier();
-            time.sleep(1);
-            print "JAMMING JAMMING JAMMING JAMMING";
+
 if(sys.argv[1]=="rssi"):
     client.CC1110_crystal();
     client.RF_idle();
@@ -199,8 +210,23 @@ if(sys.argv[1]=="rssi"):
             string=("%s."%string);
         print "%02x %04i %s" % (rssi,rssi, string); 
 
+if(sys.argv[1]=="sniff"):
+    client.CC1110_crystal();
+    client.RF_idle();
+    
+    #client.config_simpliciti(region);
+    
+    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
+                                           client.RF_getfreq()/10.0**6);
+    #Now we're ready to get packets.
+    while 1:
+        packet=None;
+        while packet==None:
+            packet=client.RF_rxpacket();
+        printpacket(packet);
+        sys.stdout.flush();
+
 if(sys.argv[1]=="sniffsimpliciti"):
-    #TODO remove all poke() calls.
     region="us";
     if len(sys.argv)>2:
         region=sys.argv[2];
@@ -219,9 +245,88 @@ if(sys.argv[1]=="sniffsimpliciti"):
             packet=client.RF_rxpacket();
         printpacket(packet);
         sys.stdout.flush();
+if(sys.argv[1]=="sniffook"):
+    region="lf";
+    if len(sys.argv)>2:
+        region=sys.argv[2];
+    
+    client.CC1110_crystal();
+    client.RF_idle();
+    
+    client.config_ook(region);
+    
+    print "Listening for OOK on %f MHz" % (client.RF_getfreq()/10.0**6);
+    #Now we're ready to get packets.
+    while 1:
+        packet=None;
+        while packet==None:
+            packet=client.RF_rxpacket();
+        printpacket(packet);
+        sys.stdout.flush();
+if(sys.argv[1]=="sniffdash7"):
+    region="lf";
+    if len(sys.argv)>2:
+        region=sys.argv[2];
+    
+    client.CC1110_crystal();
+    client.RF_idle();
+    
+    client.config_dash7(region);
+    
+    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
+                                           client.RF_getfreq()/10.0**6);
+    #Now we're ready to get packets.
+    while 1:
+        packet=None;
+        while packet==None:
+            packet=client.RF_rxpacket();
+        printpacket(packet);
+        sys.stdout.flush();
+if(sys.argv[1]=="snifficlicker"):
+    region="us";
+    if len(sys.argv)>2:
+        region=sys.argv[2];
+    
+    client.CC1110_crystal();
+    client.RF_idle();
+    
+    client.config_iclicker(region);
+    
+    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
+                                           client.RF_getfreq()/10.0**6);
+    #Now we're ready to get packets.
+    while 1:
+        packet=None;
+        while packet==None:
+            packet=client.RF_rxpacket();
+        printpacket(packet);
+        sys.stdout.flush();
+if(sys.argv[1]=="iclicker"):
+    buttons=[0, 'A', 'j', 3, 4, 'B',
+             6, 7, 8, 9, 'E', 0xB, 0xC,
+             'C', 'D', 0xF];
+    region="us";
+    if len(sys.argv)>2:
+        region=sys.argv[2];
+    
+    client.CC1110_crystal();
+    client.RF_idle();
+    
+    client.config_iclicker(region);
+    
+    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
+                                           client.RF_getfreq()/10.0**6);
+    #Now we're ready to get packets.
+    while 1:
+        packet=None;
+        while packet==None:
+            packet=client.RF_rxpacket();
+        printpacket(packet);
+        button=((packet[5]&1)<<3) | (packet[6]>>5);
+        print "Button %c" % buttons[button];
+        sys.stdout.flush();
 
 if(sys.argv[1]=="simpliciti"):
-    #TODO remove all poke() calls.
     region="us";
     if len(sys.argv)>2:
         region=sys.argv[2];
@@ -231,7 +336,7 @@ if(sys.argv[1]=="simpliciti"):
     
     client.config_simpliciti(region);
     
-    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
+    print "Listening as %x on %f MHz" % (client.RF_getsmac(),
                                            client.RF_getfreq()/10.0**6);
     #Now we're ready to get packets.
     while 1:
@@ -291,6 +396,11 @@ if(sys.argv[1]=="status"):
 if(sys.argv[1]=="halt"):
     print "Halting CPU."
     client.halt();
+
+if(sys.argv[1]=="infotest"):
+    while 1:
+        client.start();
+        print "Ident   %s" % client.CCidentstr();
 if(sys.argv[1]=="info"):
     print "Ident   %s" % client.CCidentstr();