hacktricks/todo/radio-hacking/flipper-zero/fz-sub-ghz.md

138 lines
8.1 KiB
Markdown
Raw Normal View History

2022-12-25 19:08:07 +00:00
# FZ - Sub-GHz
2022-12-24 23:50:44 +00:00
{% hint style="success" %}
Jifunze na fanya mazoezi ya AWS Hacking:<img src="/.gitbook/assets/arte.png" alt="" data-size="line">[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)<img src="/.gitbook/assets/arte.png" alt="" data-size="line">\
Jifunze na fanya mazoezi ya GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-size="line">[**HackTricks Training GCP Red Team Expert (GRTE)**<img src="/.gitbook/assets/grte.png" alt="" data-size="line">](https://training.hacktricks.xyz/courses/grte)
2022-12-24 23:50:44 +00:00
<details>
2022-12-24 23:50:44 +00:00
<summary>Support HackTricks</summary>
2024-01-02 18:28:27 +00:00
* Angalia [**mpango wa usajili**](https://github.com/sponsors/carlospolop)!
* **Jiunge na** 💬 [**kikundi cha Discord**](https://discord.gg/hRep4RUj7f) au [**kikundi cha telegram**](https://t.me/peass) au **tufuatilie** kwenye **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.**
* **Shiriki mbinu za hacking kwa kuwasilisha PRs kwa** [**HackTricks**](https://github.com/carlospolop/hacktricks) na [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) repos za github.
2022-12-24 23:50:44 +00:00
</details>
{% endhint %}
2022-12-24 23:50:44 +00:00
## Intro <a href="#kfpn7" id="kfpn7"></a>
2022-12-24 23:56:40 +00:00
Flipper Zero inaweza **kupokea na kutuma masafa ya redio katika anuwai ya 300-928 MHz** kwa moduli yake iliyojengwa, ambayo inaweza kusoma, kuhifadhi, na kuiga remote controls. Remote hizi zinatumika kwa mwingiliano na milango, vizuizi, funguo za redio, swichi za remote control, kengele za mlango zisizo na waya, mwanga wa smart, na zaidi. Flipper Zero inaweza kukusaidia kujifunza ikiwa usalama wako umeathirika.
2022-12-24 23:56:40 +00:00
<figure><img src="../../../.gitbook/assets/image (714).png" alt=""><figcaption></figcaption></figure>
2022-12-24 23:56:40 +00:00
## Sub-GHz hardware <a href="#kfpn7" id="kfpn7"></a>
2022-12-24 23:56:40 +00:00
Flipper Zero ina moduli ya sub-1 GHz iliyojengwa inayotegemea [](https://www.st.com/en/nfc/st25r3916.html#overview)[CC1101 chip](https://www.ti.com/lit/ds/symlink/cc1101.pdf) na antenna ya redio (anuwai ya juu ni mita 50). Chip ya CC1101 na antenna zimeundwa kufanya kazi katika masafa ya 300-348 MHz, 387-464 MHz, na 779-928 MHz.
2022-12-24 23:56:40 +00:00
<figure><img src="../../../.gitbook/assets/image (923).png" alt=""><figcaption></figcaption></figure>
2022-12-24 23:50:44 +00:00
## Actions
2022-12-24 23:50:44 +00:00
### Frequency Analyser
2022-12-24 23:50:44 +00:00
{% hint style="info" %}
Jinsi ya kupata ni masafa gani remote inatumia
2022-12-24 23:50:44 +00:00
{% endhint %}
Wakati wa kuchambua, Flipper Zero inachanganua nguvu za ishara (RSSI) katika masafa yote yanayopatikana katika usanidi wa masafa. Flipper Zero inaonyesha masafa yenye thamani ya juu ya RSSI, ikiwa na nguvu ya ishara zaidi ya -90 [dBm](https://en.wikipedia.org/wiki/DBm).
2022-12-24 23:50:44 +00:00
Ili kubaini masafa ya remote, fanya yafuatayo:
2022-12-24 23:50:44 +00:00
1. Weka remote control karibu sana na kushoto ya Flipper Zero.
2. Nenda kwenye **Main Menu** **→ Sub-GHz**.
3. Chagua **Frequency Analyzer**, kisha bonyeza na ushikilie kitufe kwenye remote control unayotaka kuchambua.
4. Kagua thamani ya masafa kwenye skrini.
2022-12-24 23:50:44 +00:00
### Read
2022-12-24 23:50:44 +00:00
{% hint style="info" %}
Pata habari kuhusu masafa yanayotumika (pia njia nyingine ya kupata ni masafa gani yanayotumika)
2022-12-24 23:50:44 +00:00
{% endhint %}
Chaguo la **Read** **linasikiliza kwenye masafa yaliyosanidiwa** kwenye moduli iliyotajwa: 433.92 AM kwa chaguo-msingi. Ikiwa **kitu kinapatikana** wakati wa kusoma, **habari inatolewa** kwenye skrini. Habari hii inaweza kutumika kuiga ishara siku zijazo.
2022-12-24 23:50:44 +00:00
Wakati Read inatumika, inawezekana kubonyeza **kitufe cha kushoto** na **kuisakinisha**.\
Katika wakati huu ina **modulations 4** (AM270, AM650, FM328 na FM476), na **masafa kadhaa muhimu** yaliyohifadhiwa:
2022-12-24 23:50:44 +00:00
<figure><img src="../../../.gitbook/assets/image (947).png" alt=""><figcaption></figcaption></figure>
2022-12-24 23:50:44 +00:00
Unaweza kuweka **yoyote inayokuvutia**, hata hivyo, ikiwa **hujui ni masafa gani** yanaweza kuwa yanayotumiwa na remote ulionayo, **weka Hopping kuwa ON** (Off kwa chaguo-msingi), na bonyeza kitufe mara kadhaa hadi Flipper ikiteka na kukupa habari unayohitaji kuweka masafa.
2022-12-24 23:50:44 +00:00
{% hint style="danger" %}
Kubadilisha kati ya masafa kunachukua muda, kwa hivyo ishara zinazotumwa wakati wa kubadilisha zinaweza kupuuziliwa mbali. Kwa kupokea ishara bora, weka masafa thabiti yaliyopangwa na Frequency Analyzer.
2022-12-24 23:50:44 +00:00
{% endhint %}
### **Read Raw**
2022-12-24 23:50:44 +00:00
{% hint style="info" %}
Pora (na rudia) ishara katika masafa yaliyosanidiwa
2022-12-24 23:50:44 +00:00
{% endhint %}
Chaguo la **Read Raw** **linarekodi ishara** zinazotumwa katika masafa yanayosikilizwa. Hii inaweza kutumika **kuiba** ishara na **kurudia** hiyo.
2022-12-24 23:50:44 +00:00
Kwa chaguo-msingi **Read Raw pia iko katika 433.92 katika AM650**, lakini ikiwa kwa chaguo la Read umepata kuwa ishara inayokuvutia iko katika **masafa/modulation tofauti, unaweza pia kubadilisha hiyo** kwa kubonyeza kushoto (wakati uko ndani ya chaguo la Read Raw).
2022-12-24 23:50:44 +00:00
### Brute-Force
2022-12-25 19:26:35 +00:00
Ikiwa unajua itifaki inayotumiwa kwa mfano na mlango wa garaji inawezekana **kuunda nambari zote na kuzituma kwa Flipper Zero.** Hii ni mfano unaounga mkono aina za kawaida za garages: [**https://github.com/tobiabocchi/flipperzero-bruteforce**](https://github.com/tobiabocchi/flipperzero-bruteforce)
2022-12-25 19:26:35 +00:00
### Add Manually
2022-12-24 23:50:44 +00:00
{% hint style="info" %}
Ongeza ishara kutoka orodha iliyosanidiwa ya itifaki
2022-12-24 23:50:44 +00:00
{% endhint %}
#### Orodha ya [itifaki zinazoungwa mkono](https://docs.flipperzero.one/sub-ghz/add-new-remote) <a href="#id-3iglu" id="id-3iglu"></a>
| Princeton\_433 (inafanya kazi na mfumo wa nambari za statiki nyingi) | 433.92 | Statiki |
| --------------------------------------------------------------- | ------ | ------- |
| Nice Flo 12bit\_433 | 433.92 | Statiki |
| Nice Flo 24bit\_433 | 433.92 | Statiki |
| CAME 12bit\_433 | 433.92 | Statiki |
| CAME 24bit\_433 | 433.92 | Statiki |
| Linear\_300 | 300.00 | Statiki |
| CAME TWEE | 433.92 | Statiki |
| Gate TX\_433 | 433.92 | Statiki |
| DoorHan\_315 | 315.00 | Dinamiki |
| DoorHan\_433 | 433.92 | Dinamiki |
| LiftMaster\_315 | 315.00 | Dinamiki |
| LiftMaster\_390 | 390.00 | Dinamiki |
| Security+2.0\_310 | 310.00 | Dinamiki |
| Security+2.0\_315 | 315.00 | Dinamiki |
| Security+2.0\_390 | 390.00 | Dinamiki |
### Wauzaji wa Sub-GHz wanaoungwa mkono
Angalia orodha katika [https://docs.flipperzero.one/sub-ghz/supported-vendors](https://docs.flipperzero.one/sub-ghz/supported-vendors)
### Masafa yanayoungwa mkono kwa eneo
Angalia orodha katika [https://docs.flipperzero.one/sub-ghz/frequencies](https://docs.flipperzero.one/sub-ghz/frequencies)
### Test
2022-12-24 23:50:44 +00:00
{% hint style="info" %}
Pata dBms za masafa yaliyohifadhiwa
2022-12-24 23:50:44 +00:00
{% endhint %}
## Reference
2022-12-24 23:50:44 +00:00
2022-12-24 23:56:40 +00:00
* [https://docs.flipperzero.one/sub-ghz](https://docs.flipperzero.one/sub-ghz)
{% hint style="success" %}
Jifunze na fanya mazoezi ya AWS Hacking:<img src="/.gitbook/assets/arte.png" alt="" data-size="line">[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)<img src="/.gitbook/assets/arte.png" alt="" data-size="line">\
Jifunze na fanya mazoezi ya GCP Hacking: <img src="/.gitbook/assets/grte.png" alt="" data-size="line">[**HackTricks Training GCP Red Team Expert (GRTE)**<img src="/.gitbook/assets/grte.png" alt="" data-size="line">](https://training.hacktricks.xyz/courses/grte)
<details>
<summary>Support HackTricks</summary>
* Angalia [**mpango wa usajili**](https://github.com/sponsors/carlospolop)!
* **Jiunge na** 💬 [**kikundi cha Discord**](https://discord.gg/hRep4RUj7f) au [**kikundi cha telegram**](https://t.me/peass) au **tufuatilie** kwenye **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.**
* **Shiriki mbinu za hacking kwa kuwasilisha PRs kwa** [**HackTricks**](https://github.com/carlospolop/hacktricks) na [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) repos za github.
</details>
{% endhint %}