diff --git a/Code/espthief/HelpText.h b/Code/espthief/HelpText.h new file mode 100644 index 0000000..40d7d32 --- /dev/null +++ b/Code/espthief/HelpText.h @@ -0,0 +1,141 @@ +const char HelpText[] PROGMEM = R"=====( + + +ESP-RFID-Thief Help Page + +<- BACK TO INDEX

+-----
+HELP
+-----
+
+ESP-RFID-Thief
+
+Created by Corey Harding
+www.LegacySecurityGroup.com / www.Exploit.Agency
+https://github.com/exploitagency/ESP-RFID-Thief
+Software is based off the work of Fran Brown from Bishop Fox: https://www.bishopfox.com/resources/tools/rfid-hacking/attack-tools/
+
+The ESP-RFID-Thief is a port of the Tastic RFID Thief(Originally created by Fran Brown from Bishop Fox) to the ESP12S chip with the addition of a web interface and various new features.
+
+The ESP-RFID-Thief software is distributed under the MIT License. The license and copyright notice can not be removed and must be distributed alongside all future copies of the software.
+
+-----
+Accessing ESP-RFID-Thief Web Interface
+-----
+
+SSID: "ESP-RFID-Thief"
+URL: http://192.168.1.1
+
+-----
+Configure ESP-RFID-Thief
+-----
+
+Default credentials to access the configuration page:
+Username: "admin"
+Password: "hacktheplanet"
+
+Default credentials for ftp server:
+Username: "ftp-admin"
+Password: "hacktheplanet"
+
+WiFi Configuration:
+
+Network Type:
+Access Point Mode: Create a standalone access point(No Internet Connectivity-Requires Close Proximity)
+Join Existing Network: Join an existing network(Possible Internet Connectivity-Could use Device Remotely)
+
+Hidden: Choose whether or not to use a hidden SSID when creating an access point
+
+SSID: SSID of the access point to create or of the network you are choosing to join
+Password: Password of the access point which you wish to create or of the network you are choosing to join
+Channel: Channel of the access point you are creating
+
+IP: IP to set for device
+Gateway: Gateway to use, make it the same as ESP-RFID-Thief's IP if an access point or the same as the router if joining a network
+Subnet: Typically set to 255.255.255.0
+
+Web Interface Administration Settings:
+
+Username: Username to configure/upgrade ESP-RFID-Thief
+Password: Password to configure/upgrade ESP-RFID-Thief
+
+FTP Server Settings:
+
+Note: Supports Passive(PASV) Mode Only!
+Enabled: Turn FTP Server ON
+Disabled: Turn FTP Server OFF
+Username: Username to login to ftp server
+Password: Password to login to ftp server
+
+Power LED:
+
+Enabled: Turn ON Power LED
+Disabled: Turn OFF Power LED
+
+RFID Capture Log:
+
+Useful to change this value to differentiate between facilities during various security assessments.
+File Name: File name to save captured RFID tags to for the current security assessment.
+
+-----
+List Exfiltrated Data
+-----
+
+Displays all log files containing RFID tag captures.
+
+-----
+Format File System
+-----
+
+This will erase the contents of the SPIFFS file system including ALL RFID tag captures.
+Formatting may take up to 90 seconds.
+All current settings will be retained unless you reboot your device during this process.
+
+-----
+Upgrade ESP-RFID-Thief Firmware
+-----
+
+Authenticate using your username and password set in the configuration page.
+
+Default credentials to access the firmware upgrade page:
+Username: "admin"
+Password: "hacktheplanet"
+
+Select "Browse" choose the new firmware to be uploaded and then click "Upgrade".
+
+You will need to manually reset the device upon the browser alerting you that the upgrade was successful.
+
+-----
+Licensing Information
+-----
+
+Created by Corey Harding
+https://github.com/exploitagency/ESP-RFID-Thief
+ESP-RFID-Thief software is licensed under the MIT License
+/*
+ MIT License
+
+ Copyright (c) [2017] [Corey Harding]
+
+ Permission is hereby granted, free of charge, to any person obtaining a copy
+ of this software and associated documentation files (the "Software"), to deal
+ in the Software without restriction, including without limitation the rights
+ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ copies of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be included in all
+ copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ SOFTWARE.
+*/

+Click here for additional licensing information + + +)====="; diff --git a/Code/espthief/License.h b/Code/espthief/License.h new file mode 100644 index 0000000..9a6e25b --- /dev/null +++ b/Code/espthief/License.h @@ -0,0 +1,300 @@ +const char License[] PROGMEM = R"=====( + + +ESP-RFID-Thief Licensing Page + +<- BACK TO INDEX

+
+ESP-RFID-Thief by Corey Harding: https://www.LegacySecurityGroup.com
+Software is based off the work of Fran Brown from Bishop Fox: https://www.bishopfox.com/resources/tools/rfid-hacking/attack-tools/
+Code available at: https://github.com/exploitagency/ESP-RFID-Thief
+
+ESP-RFID-Thief Hardware was created by Corey Harding and is licensed under the Creative Commons Attribution-ShareAlike 3.0 Unported License
+/*
+  Human Readable License: https://creativecommons.org/licenses/by-sa/3.0/
+  Creative Commons
+  Attribution-ShareAlike 3.0 Unported
+  
+      CREATIVE COMMONS CORPORATION IS NOT A LAW FIRM AND DOES NOT PROVIDE LEGAL SERVICES. DISTRIBUTION OF THIS LICENSE DOES NOT CREATE AN ATTORNEY-CLIENT RELATIONSHIP. CREATIVE COMMONS PROVIDES THIS INFORMATION ON AN "AS-IS" BASIS. CREATIVE COMMONS MAKES NO WARRANTIES REGARDING THE INFORMATION PROVIDED, AND DISCLAIMS LIABILITY FOR DAMAGES RESULTING FROM ITS USE. 
+  
+  License
+  
+  THE WORK (AS DEFINED BELOW) IS PROVIDED UNDER THE TERMS OF THIS CREATIVE COMMONS PUBLIC LICENSE ("CCPL" OR "LICENSE"). THE WORK IS PROTECTED BY COPYRIGHT AND/OR OTHER APPLICABLE LAW. ANY USE OF THE WORK OTHER THAN AS AUTHORIZED UNDER THIS LICENSE OR COPYRIGHT LAW IS PROHIBITED.
+  
+  BY EXERCISING ANY RIGHTS TO THE WORK PROVIDED HERE, YOU ACCEPT AND AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE. TO THE EXTENT THIS LICENSE MAY BE CONSIDERED TO BE A CONTRACT, THE LICENSOR GRANTS YOU THE RIGHTS CONTAINED HERE IN CONSIDERATION OF YOUR ACCEPTANCE OF SUCH TERMS AND CONDITIONS.
+  
+  1. Definitions
+  
+      "Adaptation" means a work based upon the Work, or upon the Work and other pre-existing works, such as a translation, adaptation, derivative work, arrangement of music or other alterations of a literary or artistic work, or phonogram or performance and includes cinematographic adaptations or any other form in which the Work may be recast, transformed, or adapted including in any form recognizably derived from the original, except that a work that constitutes a Collection will not be considered an Adaptation for the purpose of this License. For the avoidance of doubt, where the Work is a musical work, performance or phonogram, the synchronization of the Work in timed-relation with a moving image ("synching") will be considered an Adaptation for the purpose of this License.
+      "Collection" means a collection of literary or artistic works, such as encyclopedias and anthologies, or performances, phonograms or broadcasts, or other works or subject matter other than works listed in Section 1(f) below, which, by reason of the selection and arrangement of their contents, constitute intellectual creations, in which the Work is included in its entirety in unmodified form along with one or more other contributions, each constituting separate and independent works in themselves, which together are assembled into a collective whole. A work that constitutes a Collection will not be considered an Adaptation (as defined below) for the purposes of this License.
+      "Creative Commons Compatible License" means a license that is listed at https://creativecommons.org/compatiblelicenses that has been approved by Creative Commons as being essentially equivalent to this License, including, at a minimum, because that license: (i) contains terms that have the same purpose, meaning and effect as the License Elements of this License; and, (ii) explicitly permits the relicensing of adaptations of works made available under that license under this License or a Creative Commons jurisdiction license with the same License Elements as this License.
+      "Distribute" means to make available to the public the original and copies of the Work or Adaptation, as appropriate, through sale or other transfer of ownership.
+      "License Elements" means the following high-level license attributes as selected by Licensor and indicated in the title of this License: Attribution, ShareAlike.
+      "Licensor" means the individual, individuals, entity or entities that offer(s) the Work under the terms of this License.
+      "Original Author" means, in the case of a literary or artistic work, the individual, individuals, entity or entities who created the Work or if no individual or entity can be identified, the publisher; and in addition (i) in the case of a performance the actors, singers, musicians, dancers, and other persons who act, sing, deliver, declaim, play in, interpret or otherwise perform literary or artistic works or expressions of folklore; (ii) in the case of a phonogram the producer being the person or legal entity who first fixes the sounds of a performance or other sounds; and, (iii) in the case of broadcasts, the organization that transmits the broadcast.
+      "Work" means the literary and/or artistic work offered under the terms of this License including without limitation any production in the literary, scientific and artistic domain, whatever may be the mode or form of its expression including digital form, such as a book, pamphlet and other writing; a lecture, address, sermon or other work of the same nature; a dramatic or dramatico-musical work; a choreographic work or entertainment in dumb show; a musical composition with or without words; a cinematographic work to which are assimilated works expressed by a process analogous to cinematography; a work of drawing, painting, architecture, sculpture, engraving or lithography; a photographic work to which are assimilated works expressed by a process analogous to photography; a work of applied art; an illustration, map, plan, sketch or three-dimensional work relative to geography, topography, architecture or science; a performance; a broadcast; a phonogram; a compilation of data to the extent it is protected as a copyrightable work; or a work performed by a variety or circus performer to the extent it is not otherwise considered a literary or artistic work.
+      "You" means an individual or entity exercising rights under this License who has not previously violated the terms of this License with respect to the Work, or who has received express permission from the Licensor to exercise rights under this License despite a previous violation.
+      "Publicly Perform" means to perform public recitations of the Work and to communicate to the public those public recitations, by any means or process, including by wire or wireless means or public digital performances; to make available to the public Works in such a way that members of the public may access these Works from a place and at a place individually chosen by them; to perform the Work to the public by any means or process and the communication to the public of the performances of the Work, including by public digital performance; to broadcast and rebroadcast the Work by any means including signs, sounds or images.
+      "Reproduce" means to make copies of the Work by any means including without limitation by sound or visual recordings and the right of fixation and reproducing fixations of the Work, including storage of a protected performance or phonogram in digital form or other electronic medium.
+  
+  2. Fair Dealing Rights. Nothing in this License is intended to reduce, limit, or restrict any uses free from copyright or rights arising from limitations or exceptions that are provided for in connection with the copyright protection under copyright law or other applicable laws.
+  
+  3. License Grant. Subject to the terms and conditions of this License, Licensor hereby grants You a worldwide, royalty-free, non-exclusive, perpetual (for the duration of the applicable copyright) license to exercise the rights in the Work as stated below:
+  
+      to Reproduce the Work, to incorporate the Work into one or more Collections, and to Reproduce the Work as incorporated in the Collections;
+      to create and Reproduce Adaptations provided that any such Adaptation, including any translation in any medium, takes reasonable steps to clearly label, demarcate or otherwise identify that changes were made to the original Work. For example, a translation could be marked "The original work was translated from English to Spanish," or a modification could indicate "The original work has been modified.";
+      to Distribute and Publicly Perform the Work including as incorporated in Collections; and,
+      to Distribute and Publicly Perform Adaptations.
+  
+      For the avoidance of doubt:
+          Non-waivable Compulsory License Schemes. In those jurisdictions in which the right to collect royalties through any statutory or compulsory licensing scheme cannot be waived, the Licensor reserves the exclusive right to collect such royalties for any exercise by You of the rights granted under this License;
+          Waivable Compulsory License Schemes. In those jurisdictions in which the right to collect royalties through any statutory or compulsory licensing scheme can be waived, the Licensor waives the exclusive right to collect such royalties for any exercise by You of the rights granted under this License; and,
+          Voluntary License Schemes. The Licensor waives the right to collect royalties, whether individually or, in the event that the Licensor is a member of a collecting society that administers voluntary licensing schemes, via that society, from any exercise by You of the rights granted under this License.
+  
+  The above rights may be exercised in all media and formats whether now known or hereafter devised. The above rights include the right to make such modifications as are technically necessary to exercise the rights in other media and formats. Subject to Section 8(f), all rights not expressly granted by Licensor are hereby reserved.
+  
+  4. Restrictions. The license granted in Section 3 above is expressly made subject to and limited by the following restrictions:
+  
+      You may Distribute or Publicly Perform the Work only under the terms of this License. You must include a copy of, or the Uniform Resource Identifier (URI) for, this License with every copy of the Work You Distribute or Publicly Perform. You may not offer or impose any terms on the Work that restrict the terms of this License or the ability of the recipient of the Work to exercise the rights granted to that recipient under the terms of the License. You may not sublicense the Work. You must keep intact all notices that refer to this License and to the disclaimer of warranties with every copy of the Work You Distribute or Publicly Perform. When You Distribute or Publicly Perform the Work, You may not impose any effective technological measures on the Work that restrict the ability of a recipient of the Work from You to exercise the rights granted to that recipient under the terms of the License. This Section 4(a) applies to the Work as incorporated in a Collection, but this does not require the Collection apart from the Work itself to be made subject to the terms of this License. If You create a Collection, upon notice from any Licensor You must, to the extent practicable, remove from the Collection any credit as required by Section 4(c), as requested. If You create an Adaptation, upon notice from any Licensor You must, to the extent practicable, remove from the Adaptation any credit as required by Section 4(c), as requested.
+      You may Distribute or Publicly Perform an Adaptation only under the terms of: (i) this License; (ii) a later version of this License with the same License Elements as this License; (iii) a Creative Commons jurisdiction license (either this or a later license version) that contains the same License Elements as this License (e.g., Attribution-ShareAlike 3.0 US)); (iv) a Creative Commons Compatible License. If you license the Adaptation under one of the licenses mentioned in (iv), you must comply with the terms of that license. If you license the Adaptation under the terms of any of the licenses mentioned in (i), (ii) or (iii) (the "Applicable License"), you must comply with the terms of the Applicable License generally and the following provisions: (I) You must include a copy of, or the URI for, the Applicable License with every copy of each Adaptation You Distribute or Publicly Perform; (II) You may not offer or impose any terms on the Adaptation that restrict the terms of the Applicable License or the ability of the recipient of the Adaptation to exercise the rights granted to that recipient under the terms of the Applicable License; (III) You must keep intact all notices that refer to the Applicable License and to the disclaimer of warranties with every copy of the Work as included in the Adaptation You Distribute or Publicly Perform; (IV) when You Distribute or Publicly Perform the Adaptation, You may not impose any effective technological measures on the Adaptation that restrict the ability of a recipient of the Adaptation from You to exercise the rights granted to that recipient under the terms of the Applicable License. This Section 4(b) applies to the Adaptation as incorporated in a Collection, but this does not require the Collection apart from the Adaptation itself to be made subject to the terms of the Applicable License.
+      If You Distribute, or Publicly Perform the Work or any Adaptations or Collections, You must, unless a request has been made pursuant to Section 4(a), keep intact all copyright notices for the Work and provide, reasonable to the medium or means You are utilizing: (i) the name of the Original Author (or pseudonym, if applicable) if supplied, and/or if the Original Author and/or Licensor designate another party or parties (e.g., a sponsor institute, publishing entity, journal) for attribution ("Attribution Parties") in Licensor's copyright notice, terms of service or by other reasonable means, the name of such party or parties; (ii) the title of the Work if supplied; (iii) to the extent reasonably practicable, the URI, if any, that Licensor specifies to be associated with the Work, unless such URI does not refer to the copyright notice or licensing information for the Work; and (iv) , consistent with Ssection 3(b), in the case of an Adaptation, a credit identifying the use of the Work in the Adaptation (e.g., "French translation of the Work by Original Author," or "Screenplay based on original Work by Original Author"). The credit required by this Section 4(c) may be implemented in any reasonable manner; provided, however, that in the case of a Adaptation or Collection, at a minimum such credit will appear, if a credit for all contributing authors of the Adaptation or Collection appears, then as part of these credits and in a manner at least as prominent as the credits for the other contributing authors. For the avoidance of doubt, You may only use the credit required by this Section for the purpose of attribution in the manner set out above and, by exercising Your rights under this License, You may not implicitly or explicitly assert or imply any connection with, sponsorship or endorsement by the Original Author, Licensor and/or Attribution Parties, as appropriate, of You or Your use of the Work, without the separate, express prior written permission of the Original Author, Licensor and/or Attribution Parties.
+      Except as otherwise agreed in writing by the Licensor or as may be otherwise permitted by applicable law, if You Reproduce, Distribute or Publicly Perform the Work either by itself or as part of any Adaptations or Collections, You must not distort, mutilate, modify or take other derogatory action in relation to the Work which would be prejudicial to the Original Author's honor or reputation. Licensor agrees that in those jurisdictions (e.g. Japan), in which any exercise of the right granted in Section 3(b) of this License (the right to make Adaptations) would be deemed to be a distortion, mutilation, modification or other derogatory action prejudicial to the Original Author's honor and reputation, the Licensor will waive or not assert, as appropriate, this Section, to the fullest extent permitted by the applicable national law, to enable You to reasonably exercise Your right under Section 3(b) of this License (right to make Adaptations) but not otherwise.
+  
+  5. Representations, Warranties and Disclaimer
+  
+  UNLESS OTHERWISE MUTUALLY AGREED TO BY THE PARTIES IN WRITING, LICENSOR OFFERS THE WORK AS-IS AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE WORK, EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTIBILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT, OR THE ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OF ABSENCE OF ERRORS, WHETHER OR NOT DISCOVERABLE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO SUCH EXCLUSION MAY NOT APPLY TO YOU.
+  
+  6. Limitation on Liability. EXCEPT TO THE EXTENT REQUIRED BY APPLICABLE LAW, IN NO EVENT WILL LICENSOR BE LIABLE TO YOU ON ANY LEGAL THEORY FOR ANY SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES ARISING OUT OF THIS LICENSE OR THE USE OF THE WORK, EVEN IF LICENSOR HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
+  
+  7. Termination
+  
+      This License and the rights granted hereunder will terminate automatically upon any breach by You of the terms of this License. Individuals or entities who have received Adaptations or Collections from You under this License, however, will not have their licenses terminated provided such individuals or entities remain in full compliance with those licenses. Sections 1, 2, 5, 6, 7, and 8 will survive any termination of this License.
+      Subject to the above terms and conditions, the license granted here is perpetual (for the duration of the applicable copyright in the Work). Notwithstanding the above, Licensor reserves the right to release the Work under different license terms or to stop distributing the Work at any time; provided, however that any such election will not serve to withdraw this License (or any other license that has been, or is required to be, granted under the terms of this License), and this License will continue in full force and effect unless terminated as stated above.
+  
+  8. Miscellaneous
+  
+      Each time You Distribute or Publicly Perform the Work or a Collection, the Licensor offers to the recipient a license to the Work on the same terms and conditions as the license granted to You under this License.
+      Each time You Distribute or Publicly Perform an Adaptation, Licensor offers to the recipient a license to the original Work on the same terms and conditions as the license granted to You under this License.
+      If any provision of this License is invalid or unenforceable under applicable law, it shall not affect the validity or enforceability of the remainder of the terms of this License, and without further action by the parties to this agreement, such provision shall be reformed to the minimum extent necessary to make such provision valid and enforceable.
+      No term or provision of this License shall be deemed waived and no breach consented to unless such waiver or consent shall be in writing and signed by the party to be charged with such waiver or consent.
+      This License constitutes the entire agreement between the parties with respect to the Work licensed here. There are no understandings, agreements or representations with respect to the Work not specified here. Licensor shall not be bound by any additional provisions that may appear in any communication from You. This License may not be modified without the mutual written agreement of the Licensor and You.
+      The rights granted under, and the subject matter referenced, in this License were drafted utilizing the terminology of the Berne Convention for the Protection of Literary and Artistic Works (as amended on September 28, 1979), the Rome Convention of 1961, the WIPO Copyright Treaty of 1996, the WIPO Performances and Phonograms Treaty of 1996 and the Universal Copyright Convention (as revised on July 24, 1971). These rights and subject matter take effect in the relevant jurisdiction in which the License terms are sought to be enforced according to the corresponding provisions of the implementation of those treaty provisions in the applicable national law. If the standard suite of rights granted under applicable copyright law includes additional rights not granted under this License, such additional rights are deemed to be included in the License; this License is not intended to restrict the license of any rights under applicable law.
+  
+      Creative Commons Notice
+  
+      Creative Commons is not a party to this License, and makes no warranty whatsoever in connection with the Work. Creative Commons will not be liable to You or any party on any legal theory for any damages whatsoever, including without limitation any general, special, incidental or consequential damages arising in connection to this license. Notwithstanding the foregoing two (2) sentences, if Creative Commons has expressly identified itself as the Licensor hereunder, it shall have all rights and obligations of Licensor.
+  
+      Except for the limited purpose of indicating to the public that the Work is licensed under the CCPL, Creative Commons does not authorize the use by either party of the trademark "Creative Commons" or any related trademark or logo of Creative Commons without the prior written consent of Creative Commons. Any permitted use will be in compliance with Creative Commons' then-current trademark usage guidelines, as may be published on its website or otherwise made available upon request from time to time. For the avoidance of doubt, this trademark restriction does not form part of the License.
+  
+  Creative Commons may be contacted at https://creativecommons.org/.
+*/
+
+ESP-RFID-Thief software is licensed under the MIT License
+/*
+ MIT License
+
+ Copyright (c) [2017] [Corey Harding]
+
+ Permission is hereby granted, free of charge, to any person obtaining a copy
+ of this software and associated documentation files (the "Software"), to deal
+ in the Software without restriction, including without limitation the rights
+ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ copies of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be included in all
+ copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ SOFTWARE.
+*/
+
+Core libraries used:
+
+/*
+ Arduino.h - Main include file for the Arduino SDK
+ Copyright (c) 2005-2013 Arduino Team. All right reserved.
+ This library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+ This library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+ You should have received a copy of the GNU Lesser General Public
+ License along with this library; if not, write to the Free Software
+ Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
+*/
+
+/*
+ ESP8266WiFi.h - esp8266 Wifi support.
+ Based on WiFi.h from Arduino WiFi shield library.
+ Copyright (c) 2011-2014 Arduino. All right reserved.
+ Modified by Ivan Grokhotkov, December 2014
+ This library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+ This library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+ You should have received a copy of the GNU Lesser General Public
+ License along with this library; if not, write to the Free Software
+ Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
+*/
+
+/*
+ WiFiClient.h - Library for Arduino Wifi shield.
+ Copyright (c) 2011-2014 Arduino. All right reserved.
+ This library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+ This library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+ You should have received a copy of the GNU Lesser General Public
+ License along with this library; if not, write to the Free Software
+ Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
+ Modified by Ivan Grokhotkov, December 2014 - esp8266 support
+*/
+
+/*
+ ESP8266WebServer.h - Dead simple web-server.
+ Supports only one simultaneous client, knows how to handle GET and POST.
+ Copyright (c) 2014 Ivan Grokhotkov. All rights reserved.
+ This library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+ This library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+ You should have received a copy of the GNU Lesser General Public
+ License along with this library; if not, write to the Free Software
+ Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
+ Modified 8 May 2015 by Hristo Gochkov (proper post and file upload handling)
+*/
+
+/*
+ Esp8266httpupdateserver.h No license information available.
+*/
+
+/*
+ ESP8266mDNS.h
+ ESP8266 Multicast DNS (port of CC3000 Multicast DNS library)
+ Version 1.1
+ Copyright (c) 2013 Tony DiCola (tony@tonydicola.com)
+ ESP8266 port (c) 2015 Ivan Grokhotkov (ivan@esp8266.com)
+ Extended MDNS-SD support 2016 Lars Englund (lars.englund@gmail.com)
+ This is a simple implementation of multicast DNS query support for an Arduino
+ running on ESP8266 chip. Only support for resolving address queries is currently
+ implemented.
+ License (MIT license):
+ Permission is hereby granted, free of charge, to any person obtaining a copy
+ of this software and associated documentation files (the "Software"), to deal
+ in the Software without restriction, including without limitation the rights
+ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ copies of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+ The above copyright notice and this permission notice shall be included in
+ all copies or substantial portions of the Software.
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
+ THE SOFTWARE.
+*/
+
+/*
+ FS.h - file system wrapper
+ Copyright (c) 2015 Ivan Grokhotkov. All rights reserved.
+ This file is part of the esp8266 core for Arduino environment.
+ This library is free software; you can redistribute it and/or
+ modify it under the terms of the GNU Lesser General Public
+ License as published by the Free Software Foundation; either
+ version 2.1 of the License, or (at your option) any later version.
+ This library is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ Lesser General Public License for more details.
+ You should have received a copy of the GNU Lesser General Public
+ License along with this library; if not, write to the Free Software
+ Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
+*/
+
+/*
+ ArduinoJson.h
+ The MIT License (MIT)
+ ---------------------
+
+ Copyright (c) 2014-2017 Benoit BLANCHON
+
+ Permission is hereby granted, free of charge, to any person obtaining a copy
+ of this software and associated documentation files (the "Software"), to deal
+ in the Software without restriction, including without limitation the rights
+ to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ copies of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be included in all
+ copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ SOFTWARE.
+*/
+
+/*
+ ESP8266FtpServer.h - by nailbuster, later modified by bbx10 and apullin
+                   GNU LESSER GENERAL PUBLIC LICENSE
+                       Version 2.1, February 1999
+ https://github.com/apullin/esp8266FTPServer/blob/feature/bbx10_speedup/LICENSE
+*/
+
+/*
+  DoubleResetDetector.h by Stephen Denne
+  MIT License
+  
+  Copyright (c) 2017 Stephen Denne
+  
+  Permission is hereby granted, free of charge, to any person obtaining a copy
+  of this software and associated documentation files (the "Software"), to deal
+  in the Software without restriction, including without limitation the rights
+  to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+  copies of the Software, and to permit persons to whom the Software is
+  furnished to do so, subject to the following conditions:
+  
+  The above copyright notice and this permission notice shall be included in all
+  copies or substantial portions of the Software.
+  
+  THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+  IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+  FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+  AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+  LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+  OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+  SOFTWARE.
+*/
+
+This is not a comprehensive list, these "Core Libraries" may depend on additional
+libraries, more information can be obtained by viewing the source code of the main libraries.
+
+ + +)====="; diff --git a/Code/espthief/espthief.ino b/Code/espthief/espthief.ino index 4c861e3..23afc85 100644 --- a/Code/espthief/espthief.ino +++ b/Code/espthief/espthief.ino @@ -1,38 +1,78 @@ +/* + * ESP-RFID-Thief + * Original Tastic RFID Thief by Fran Brown of Bishop Fox + * Ported to the ESP12S by Corey Harding of www.Exploit.Agency / www.LegacySecurityGroup.com + * ESP-RFID-Thief Software is distributed under the MIT License. The license and copyright notice can not be removed and must be distributed alongside all future copies of the software. + * MIT License + + Copyright (c) [2017] [Corey Harding] + + Permission is hereby granted, free of charge, to any person obtaining a copy + of this software and associated documentation files (the "Software"), to deal + in the Software without restriction, including without limitation the rights + to use, copy, modify, merge, publish, distribute, sublicense, and/or sell + copies of the Software, and to permit persons to whom the Software is + furnished to do so, subject to the following conditions: + + The above copyright notice and this permission notice shall be included in all + copies or substantial portions of the Software. + + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE + SOFTWARE. +*/ +#include "HelpText.h" +#include "License.h" +#include "version.h" #include #include #include +#include +#include +#include +#include #include -// Library Documentation available at https://github.com/esp8266/Arduino/ -// Install Library via Board Manager URL for Arduino IDE http://arduino.esp8266.com/stable/package_esp8266com_index.json -// Tastic RFID Thief Originally by Bishop Fox https://www.bishopfox.com/resources/tools/rfid-hacking/ -// Remix of Code and Port to ESP8266 by Corey Harding from LegacySecurityGroup - https://www.legacysecuritygroup.com/ http://www.exploit.agency/ - - -// Begin WiFi Configuration - -const int accesspointmode = 1; // set to 0 to connect to an existing network or leave it set to 1 to use the esp8266 as an access point +#include // ArduinoJson library 5.11.0 by Benoit Blanchon https://github.com/bblanchon/ArduinoJson +#include // https://github.com/exploitagency/esp8266FTPServer/tree/feature/bbx10_speedup +#include +#include +#include // Double Reset Detector library VERSION: 1.0.0 by Stephen Denne https://github.com/datacute/DoubleResetDetector -// SSID and PASSWORD of network go below -const char ssid[] = "RFID"; -const char password[] = ""; -// channel and hidden are for when using the esp8266 as an access point -const int channel = 6; -const int hidden = 0; // set int hidden to 0 to broadcast SSID of access point or leave as 1 to hide SSID - -// Configure the Network -IPAddress local_IP(192,168,1,1); //IP of the esp8266 server -IPAddress gateway(192,168,1,1); -IPAddress subnet(255,255,255,0); +#define DRD_TIMEOUT 3 +#define DRD_ADDRESS 0 +DoubleResetDetector drd(DRD_TIMEOUT, DRD_ADDRESS); // Port for web server ESP8266WebServer server(80); - -// End of WiFi Configuration block - +ESP8266WebServer httpServer(1337); +ESP8266HTTPUpdateServer httpUpdater; +FtpServer ftpSrv; +const byte DNS_PORT = 53; +DNSServer dnsServer; + +HTTPClient http; + +const char* update_path = "/update"; +int accesspointmode; +char ssid[32]; +char password[64]; +int channel; +int hidden; +char local_IPstr[16]; +char gatewaystr[16]; +char subnetstr[16]; +char update_username[32]; +char update_password[64]; +char ftp_username[32]; +char ftp_password[64]; +int ftpenabled; +int ledenabled; +char logname[31]; // Begin RFID Thief Config - - #define MAX_BITS 100 // max number of bits #define WEIGAND_WAIT_TIME 3000 // time to wait for another weigand pulse. @@ -93,110 +133,495 @@ void ISR_INT1() } // End RFID Thief Config -// Dish out Root Web Page -void handle_root() { - server.send(200, "text/html", "ESP-RFID-Thief
A Tastic RFID Thief Port/Remix by:
Corey Harding from www.LegacySecurityGroup.com
-----
View /log.txt
-
Wipe /log.txt
-
Format File System"); +void settingsPage() +{ + if(!server.authenticate(update_username, update_password)) + return server.requestAuthentication(); + String accesspointmodeyes; + String accesspointmodeno; + if (accesspointmode==1){ + accesspointmodeyes=" checked=\"checked\""; + accesspointmodeno=""; + } + else { + accesspointmodeyes=""; + accesspointmodeno=" checked=\"checked\""; + } + String ftpenabledyes; + String ftpenabledno; + if (ftpenabled==1){ + ftpenabledyes=" checked=\"checked\""; + ftpenabledno=""; + } + else { + ftpenabledyes=""; + ftpenabledno=" checked=\"checked\""; + } + String ledenabledyes; + String ledenabledno; + if (ledenabled==1){ + ledenabledyes=" checked=\"checked\""; + ledenabledno=""; + } + else { + ledenabledyes=""; + ledenabledno=" checked=\"checked\""; + } + String hiddenyes; + String hiddenno; + if (hidden==1){ + hiddenyes=" checked=\"checked\""; + hiddenno=""; + } + else { + hiddenyes=""; + hiddenno=" checked=\"checked\""; + } + server.send(200, "text/html", + String()+ + F( + "" + "" + "" + "" + "ESP-RFID-Thief Settings" + "" + "" + "" + "<- BACK TO INDEX

" + "

ESP-RFID-Thief Settings

" + "" + "
" + "
" + "

" + "WiFi Configuration:

" + "Network Type
" + )+ + F("Access Point Mode:
" + "Join Existing Network:

" + "Hidden
" + "Yes
" + "No

" + "SSID:
" + "Password:
" + "Channel:

" + "IP:
" + "Gateway:
" + "Subnet:

" + "


" + "Web Interface Administration Settings:

" + "Username:
" + "Password:

" + "
" + "FTP Server Settings
" + "Changes require a reboot.
" + "Enabled
" + "Disabled
" + "FTP Username:
" + "FTP Password:

" + "
" + "Power LED:
" + "Changes require a reboot.
" + "Enabled
" + "Disabled

" + "
" + "RFID Capture Log:
" + "Useful to change this value to differentiate between facilities during various security assessments.
" + "File Name:
" + "
" + "" + "" + "
" + "
" + "

" + "" + "" + ) + ); } -String webString=""; -// End of Dish +void handleSettings() +{ + if (server.hasArg("SETTINGS")) { + handleSubmitSettings(); + } + else { + settingsPage(); + } +} -// Start Networking -void setup() +void returnFail(String msg) { - Serial.begin(9600); - Serial.println(); + server.sendHeader("Connection", "close"); + server.sendHeader("Access-Control-Allow-Origin", "*"); + server.send(500, "text/plain", msg + "\r\n"); +} + +void handleSubmitSettings() +{ + String SETTINGSvalue; + + if (!server.hasArg("SETTINGS")) return returnFail("BAD ARGS"); + + SETTINGSvalue = server.arg("SETTINGS"); + accesspointmode = server.arg("accesspointmode").toInt(); + server.arg("ssid").toCharArray(ssid, 32); + server.arg("password").toCharArray(password, 64); + channel = server.arg("channel").toInt(); + hidden = server.arg("hidden").toInt(); + server.arg("local_IPstr").toCharArray(local_IPstr, 16); + server.arg("gatewaystr").toCharArray(gatewaystr, 16); + server.arg("subnetstr").toCharArray(subnetstr, 16); + server.arg("update_username").toCharArray(update_username, 32); + server.arg("update_password").toCharArray(update_password, 64); + server.arg("ftp_username").toCharArray(ftp_username, 32); + server.arg("ftp_password").toCharArray(ftp_password, 64); + ftpenabled = server.arg("ftpenabled").toInt(); + ledenabled = server.arg("ledenabled").toInt(); + server.arg("logname").toCharArray(logname, 31); + + if (SETTINGSvalue == "1") { + saveConfig(); + server.send(200, "text/html", F("<- BACK TO INDEX



Settings have been saved.
Some setting may require manually rebooting before taking effect.
If network configuration has changed then be sure to connect to the new network first in order to access the web interface.")); + loadConfig(); + } + else if (SETTINGSvalue == "0") { + settingsPage(); + } + else { + returnFail("Bad SETTINGS value"); + } +} + +bool loadDefaults() { + StaticJsonBuffer<500> jsonBuffer; + JsonObject& json = jsonBuffer.createObject(); + json["version"] = version; + json["accesspointmode"] = "1"; + json["ssid"] = "ESP-RFID-Thief"; + json["password"] = ""; + json["channel"] = "6"; + json["hidden"] = "0"; + json["local_IP"] = "192.168.1.1"; + json["gateway"] = "192.168.1.1"; + json["subnet"] = "255.255.255.0"; + json["update_username"] = "admin"; + json["update_password"] = "hacktheplanet"; + json["ftp_username"] = "ftp-admin"; + json["ftp_password"] = "hacktheplanet"; + json["ftpenabled"] = "0"; + json["ledenabled"] = "1"; + json["logname"] = "log.txt"; + File configFile = SPIFFS.open("/esprfidthief.json", "w"); + json.printTo(configFile); + loadConfig(); +} + +bool loadConfig() { + File configFile = SPIFFS.open("/esprfidthief.json", "r"); + if (!configFile) { + delay(3500); + loadDefaults(); + } + + size_t size = configFile.size(); + + std::unique_ptr buf(new char[size]); + configFile.readBytes(buf.get(), size); + StaticJsonBuffer<500> jsonBuffer; + JsonObject& json = jsonBuffer.parseObject(buf.get()); + + if (!json["version"]) { + delay(3500); + loadDefaults(); + ESP.restart(); + } + //Resets config to factory defaults on an update. + if (json["version"]!=version) { + delay(3500); + loadDefaults(); + ESP.restart(); + } + + strcpy(ssid, (const char*)json["ssid"]); + strcpy(password, (const char*)json["password"]); + channel = json["channel"]; + hidden = json["hidden"]; + accesspointmode = json["accesspointmode"]; + strcpy(local_IPstr, (const char*)json["local_IP"]); + strcpy(gatewaystr, (const char*)json["gateway"]); + strcpy(subnetstr, (const char*)json["subnet"]); + + strcpy(update_username, (const char*)json["update_username"]); + strcpy(update_password, (const char*)json["update_password"]); + + strcpy(ftp_username, (const char*)json["ftp_username"]); + strcpy(ftp_password, (const char*)json["ftp_password"]); + ftpenabled = json["ftpenabled"]; + ledenabled = json["ledenabled"]; + strcpy(logname, (const char*)json["logname"]); + + IPAddress local_IP; + local_IP.fromString(local_IPstr); + IPAddress gateway; + gateway.fromString(gatewaystr); + IPAddress subnet; + subnet.fromString(subnetstr); + +/* + Serial.println(accesspointmode); + Serial.println(ssid); + Serial.println(password); + Serial.println(channel); + Serial.println(hidden); + Serial.println(local_IP); + Serial.println(gateway); + Serial.println(subnet); +*/ + WiFi.persistent(false); + //ESP.eraseConfig(); // Determine if set to Access point mode if (accesspointmode == 1) { - Serial.print("Setting up Network Configuration ... "); - Serial.println(WiFi.softAPConfig(local_IP, gateway, subnet) ? "Success" : "Failed!"); + WiFi.disconnect(true); + WiFi.mode(WIFI_AP); + +// Serial.print("Starting Access Point ... "); +// Serial.println(WiFi.softAP(ssid, password, channel, hidden) ? "Success" : "Failed!"); + WiFi.softAP(ssid, password, channel, hidden); - Serial.print("Starting Access Point ... "); - Serial.println(WiFi.softAP(ssid, password, channel, hidden) ? "Success" : "Failed!"); +// Serial.print("Setting up Network Configuration ... "); +// Serial.println(WiFi.softAPConfig(local_IP, gateway, subnet) ? "Success" : "Failed!"); + WiFi.softAPConfig(local_IP, gateway, subnet); - Serial.print("IP address = "); - Serial.println(WiFi.softAPIP()); +// WiFi.reconnect(); + +// Serial.print("IP address = "); +// Serial.println(WiFi.softAPIP()); } // or Join existing network else if (accesspointmode != 1) { - Serial.print("Setting up Network Configuration ... "); - Serial.println(WiFi.config(local_IP, gateway, subnet) ? "Success" : "Failed!"); + WiFi.disconnect(true); + WiFi.mode(WIFI_STA); +// Serial.print("Setting up Network Configuration ... "); + WiFi.config(local_IP, gateway, subnet); +// WiFi.config(local_IP, gateway, subnet); + +// Serial.print("Connecting to network ... "); +// WiFi.begin(ssid, password); + WiFi.begin(ssid, password); + WiFi.reconnect(); + +// Serial.print("IP address = "); +// Serial.println(WiFi.localIP()); + } - Serial.print("Connecting to network ... "); - Serial.println(WiFi.begin(ssid, password) ? "Success" : "Failed!"); + return true; +} - Serial.print("IP address = "); - Serial.println(WiFi.localIP()); +bool saveConfig() { + StaticJsonBuffer<500> jsonBuffer; + JsonObject& json = jsonBuffer.createObject(); + json["version"] = version; + json["accesspointmode"] = accesspointmode; + json["ssid"] = ssid; + json["password"] = password; + json["channel"] = channel; + json["hidden"] = hidden; + json["local_IP"] = local_IPstr; + json["gateway"] = gatewaystr; + json["subnet"] = subnetstr; + json["update_username"] = update_username; + json["update_password"] = update_password; + json["ftp_username"] = ftp_username; + json["ftp_password"] = ftp_password; + json["ftpenabled"] = ftpenabled; + json["ledenabled"] = ledenabled; + json["logname"] = logname; + + File configFile = SPIFFS.open("/esprfidthief.json", "w"); + json.printTo(configFile); + return true; +} + +File fsUploadFile; +String webString; + +void ListLogs(){ + String directory; + directory="/"; + FSInfo fs_info; + SPIFFS.info(fs_info); + String total; + total=fs_info.totalBytes; + String used; + used=fs_info.usedBytes; + String freespace; + freespace=fs_info.totalBytes-fs_info.usedBytes; + Dir dir = SPIFFS.openDir(directory); + String FileList = String()+F("<- BACK TO INDEX

File System Info Calculated in Bytes
Total: ")+total+" Free: "+freespace+" "+" Used: "+used+"

"; + while (dir.next()) { + String FileName = dir.fileName(); + File f = dir.openFile("r"); + FileList += " "; + if((!FileName.startsWith("/payloads/"))&&(!FileName.startsWith("/esploit.json"))&&(!FileName.startsWith("/esportal.json"))&&(!FileName.startsWith("/esprfidthief.json"))&&(!FileName.startsWith("/config.json"))) FileList += ""+""; + } + FileList += "
Display File ContentsSize in BytesDownload FileDelete File
"+FileName+""+f.size()+"
"; + server.send(200, "text/html", FileList); +} + +bool RawFile(String rawfile) { + if (SPIFFS.exists(rawfile)) { + if(!server.authenticate(update_username, update_password)){ + server.requestAuthentication();} + File file = SPIFFS.open(rawfile, "r"); + size_t sent = server.streamFile(file, "application/octet-stream"); + file.close(); + return true; } + return false; +} +void ViewLog(){ + webString=""; + String payload; + String ShowPL; + payload += server.arg(0); + File f = SPIFFS.open(payload, "r"); + String webString = f.readString(); + f.close(); + ShowPL = String()+F("<- BACK TO INDEX

List Exfiltrated Data

-
"+payload+"\n-----\n"+webString+"
"; + webString=""; + server.send(200, "text/html", ShowPL); +} -// Initialize file system and log file +// Start Networking +void setup() { + Serial.begin(9600); + //SPIFFS.format(); SPIFFS.begin(); - // this opens the file "log.txt" in read-mode - File f = SPIFFS.open("/log.txt", "r"); - if (!f) { - Serial.println("File doesn't exist yet. Creating it"); - // open the file in write mode - File f = SPIFFS.open("/log.txt", "w"); - if (!f) { - Serial.println("File creation failed!"); - } - f.println("File: /log.txt"); - f.println("Captured Cards:"); + //loadDefaults(); //uncomment to restore default settings if double reset fails for some reason + + if (drd.detectDoubleReset()) { + Serial.println("Double Reset Detected"); + Serial.println("Loading default config..."); + loadDefaults(); } - f.close(); -// End file system block - -// Begin Web Pages - server.on("/", handle_root); - server.on("/log", [](){ - webString=""; - File f = SPIFFS.open("/log.txt", "r"); - String webString = f.readString(); - f.close(); - server.send(200, "text/plain", webString); - Serial.println(webString); - webString=""; + loadConfig(); + +//Set up Web Pages + server.on("/",[]() { + FSInfo fs_info; + SPIFFS.info(fs_info); + String total; + total=fs_info.totalBytes; + String used; + used=fs_info.usedBytes; + String freespace; + freespace=fs_info.totalBytes-fs_info.usedBytes; + server.send(200, "text/html", String()+F("ESP-RFID-Thief v")+version+F("

by Corey Harding
www.LegacySecurityGroup.com / www.Exploit.Agency

-----
File System Info Calculated in Bytes
Total: ")+total+" Free: "+freespace+" "+" Used: "+used+F("
-----
List Exfiltrated Data
-
Configure Settings
-
Format File System
-
Upgrade Firmware
-
Help")); + }); + + server.onNotFound([]() { + if (!RawFile(server.uri())) + server.send(404, "text/plain", F("Error 404 File Not Found")); }); + server.on("/settings", handleSettings); - server.on("/wipe", [](){ - server.send(200, "text/html", "This will wipe all your captures from /log.txt file.

Are you sure?

YES - NO"); + server.on("/firmware", [](){ + server.send(200, "text/html", String()+F("<- BACK TO INDEX

Open Arduino IDE.
Pull down \"Sketch\" Menu then select \"Export Compiled Binary\".
On this page click \"Browse\", select the binary you exported earlier, then click \"Update\".
You may need to manually reboot the device to reconnect.
")); }); - server.on("/wipe/yes", [](){ - server.send(200, "text/html", "Logs have been wiped.

<- BACK TO INDEX"); - File f = SPIFFS.open("/log.txt", "w"); - f.println("File: /log.txt"); - f.println("Captured Cards:"); - f.close(); - Serial.println("Logs wiped"); + server.on("/restoredefaults", [](){ + server.send(200, "text/html", F("This will restore the device to the default configuration.

Are you sure?

YES - NO")); + }); + + server.on("/restoredefaults/yes", [](){ + if(!server.authenticate(update_username, update_password)) + return server.requestAuthentication(); + server.send(200, "text/html", F("<- BACK TO INDEX

Network
---
SSID: ESP-RFID-Thief

Administration
---
USER: admin PASS: hacktheplanet")); + loadDefaults(); + ESP.restart(); + }); + + server.on("/deletelog", [](){ + String deletelog; + deletelog += server.arg(0); + server.send(200, "text/html", String()+F("This will delete the file: ")+deletelog+F(".

Are you sure?

YES - NO")); + }); + + server.on("/viewlog", ViewLog); + + server.on("/deletelog/yes", [](){ + if(!server.authenticate(update_username, update_password)) + return server.requestAuthentication(); + String deletelog; + deletelog += server.arg(0); + if (!deletelog.startsWith("/payloads/")) server.send(200, "text/html", String()+F("<- BACK TO INDEX

List Exfiltrated Data

Deleting file: ")+deletelog); + SPIFFS.remove(deletelog); }); server.on("/format", [](){ - server.send(200, "text/html", "This will reformat the SPIFFS File System.

Are you sure?

YES - NO"); + server.send(200, "text/html", F("<- BACK TO INDEX

This will reformat the SPIFFS File System.

Are you sure?

YES - NO")); }); + server.on("/logs", ListLogs); + + server.on("/reboot", [](){ + if(!server.authenticate(update_username, update_password)) + return server.requestAuthentication(); + server.send(200, "text/html", F("<- BACK TO INDEX

Rebooting Device...")); + ESP.restart(); + }); + server.on("/format/yes", [](){ - server.send(200, "text/html", "Formatting file system
This may take up to 90 seconds

<- BACK TO INDEX"); - Serial.print("Formatting file system..."); + if(!server.authenticate(update_username, update_password)) + return server.requestAuthentication(); + server.send(200, "text/html", F("<- BACK TO INDEX

Formatting file system: This may take up to 90 seconds")); +// Serial.print("Formatting file system..."); SPIFFS.format(); - Serial.println(" Success"); +// Serial.println(" Success"); + saveConfig(); }); - + + server.on("/help", []() { + server.send_P(200, "text/html", HelpText); + }); + + server.on("/license", []() { + server.send_P(200, "text/html", License); + }); + server.begin(); - Serial.println("HTTP Server Started"); -// End of Web Pages + WiFiClient client; + client.setNoDelay(1); + +// Serial.println("Web Server Started"); + + MDNS.begin("ESP"); + + httpUpdater.setup(&httpServer, update_path, update_username, update_password); + httpServer.begin(); + + MDNS.addService("http", "tcp", 1337); + + if (ftpenabled==1){ + ftpSrv.begin(String(ftp_username),String(ftp_password)); + } //Start RFID Reader - pinMode(2, OUTPUT); // LED + if (ledenabled==1){ + pinMode(2, OUTPUT); // LED + } pinMode(14, INPUT); // DATA0 (INT0) pinMode(12, INPUT); // DATA1 (INT1) - Serial.println("RFID Reader Started"); + //Serial.println("RFID Reader Started"); // binds the ISR functions to the falling edge of INTO and INT1 attachInterrupt(14, ISR_INT0, FALLING); @@ -212,6 +637,22 @@ void setup() // LOOP function void loop() { + if (ftpenabled==1){ + ftpSrv.handleFTP(); + } + server.handleClient(); + httpServer.handleClient(); + while (Serial.available()) { + String cmd = Serial.readStringUntil(':'); + if(cmd == "ResetDefaultConfig"){ + loadDefaults(); + ESP.restart(); + } + } + drd.loop(); + +//Serial.print("Free heap-"); +//Serial.println(ESP.getFreeHeap(),DEC); // This waits to make sure that there have been no more data pulses before processing data if (!flagDone) { @@ -252,7 +693,7 @@ void printBits() { // open the file in append mode - File f = SPIFFS.open("/log.txt", "a"); + File f = SPIFFS.open("/"+String(logname), "a"); f.print(bitCount); f.print(" bit card : "); //f.print(facilityCode); diff --git a/Code/espthief/espthief.ino.generic.bin b/Code/espthief/espthief.ino.generic.bin index 205bd76..0887497 100644 Binary files a/Code/espthief/espthief.ino.generic.bin and b/Code/espthief/espthief.ino.generic.bin differ diff --git a/Code/espthief/version.h b/Code/espthief/version.h new file mode 100644 index 0000000..4595da0 --- /dev/null +++ b/Code/espthief/version.h @@ -0,0 +1 @@ +String version = "1.0.0"; diff --git a/README.md b/README.md index 5e89791..4238ac0 100644 --- a/README.md +++ b/README.md @@ -1,5 +1,5 @@ # ESP-RFID-Thief -The ESP-RFID-Thief is a port of the Tastic RFID Thief(Originally created by Fran Brown from Bishop Fox) to the ESP12S chip. One of the benefits the ESP-RFID-Thief has over the original Tastic RFID Thief is the addition of WiFi and a web interface to review captured credentials. The on board flash also eliminates the need for an SD card. The device can be combined with a RFID reader that outputs Weigand data along with a battery pack to create a standalone RFID reader that saves all scanned cards to a log file accessible through the web interface. The HID MaxiProx 5375 running on 12V(8xAA Batteries) can capture cards from up to two feet away when combined with this device. This device can also be planted inside existing RFID reader installations to capture card data. +The ESP-RFID-Thief is a port of the Tastic RFID Thief(Originally created by Fran Brown from Bishop Fox) to the ESP12S chip. One of the benefits the ESP-RFID-Thief has over the original Tastic RFID Thief is the addition of WiFi and a web interface to review captured credentials. The on board flash also eliminates the need for an SD card. The device can be combined with a RFID reader that outputs Wiegand data along with a battery pack to create a standalone RFID reader that saves all scanned cards to a log file accessible through the web interface. The HID MaxiProx 5375 running on 12V(8xAA Batteries) can capture cards from up to two feet away when combined with this device. This device can also be planted inside existing RFID reader installations to capture card data. # Hardware License Attribution-ShareAlike 3.0 Unported (CC BY-SA 3.0) Hardware by Corey Harding @@ -7,12 +7,119 @@ Hardware by Corey Harding MIT License Based off the work of Fran Brown from Bishop Fox Ported to the ESP12S with a web interface by Corey Harding -# Instructions -(INCOMPLETE) +# Instructions Gather parts +-See BOM under Board Folder Assemble board +-Simple surface mount assembly when using low temp solder paste and a hot air rework station. Program board using FTDI +-FTDI must supply 3V3 and have 6 pins(DTR,RXD,TXD,VC,CTS,GND) and a reset button +-Be sure to press the reset button on the FTDI or hit the reset jumper on the ESP-RFID-Thief board to start flashing +-Linux: https://github.com/exploitagency/esptool +`python esptool.py --port=/dev/ttyUSB1 --baud 115000 write_flash 0x00000 espthief.ino.generic.bin --flash_size 32m` +-Windows: https://github.com/nodemcu/nodemcu-flasher Install into RFID reader +Make sure it outputs data in the Wiegand format +-Connect D0 on device to D0 on reader +-Connect D1 on device to D1 on reader +-Connect + on device to + on reader +-Connect - on device to - on reader +-Connect ~7-18V battery into the same + and - Configure settings +-See Below -Current software is taken from my original https://github.com/exploitagency/github-ESP_RFID_Thief project and will be brought up to speed using the same web interface you are used to in ESPloitV2 and ESPortalV2 shortly. Please be patient and wait for the updated version. This repo is mainly a placeholder for now. There may be minor hardware modifications but for now the hardware appears to be functional in my prototype units and I will mainly be focusing on software development and documentation for now. +# Software Help +----- +Accessing ESP-RFID-Thief Web Interface +----- + +SSID: "ESP-RFID-Thief" +URL: http://192.168.1.1 + +----- +Configure ESP-RFID-Thief +----- + +Default credentials to access the configuration page: +Username: "admin" +Password: "hacktheplanet" + +Default credentials for ftp server: +Username: "ftp-admin" +Password: "hacktheplanet" + +WiFi Configuration: + +Network Type: +Access Point Mode: Create a standalone access point(No Internet Connectivity-Requires Close Proximity) +Join Existing Network: Join an existing network(Possible Internet Connectivity-Could use Device Remotely) + +Hidden: Choose whether or not to use a hidden SSID when creating an access point + +SSID: SSID of the access point to create or of the network you are choosing to join +Password: Password of the access point which you wish to create or of the network you are choosing to join +Channel: Channel of the access point you are creating + +IP: IP to set for device +Gateway: Gateway to use, make it the same as ESP-RFID-Thief's IP if an access point or the same as the router if joining a network +Subnet: Typically set to 255.255.255.0 + +Web Interface Administration Settings: + +Username: Username to configure/upgrade ESP-RFID-Thief +Password: Password to configure/upgrade ESP-RFID-Thief + +FTP Server Settings: + +Note: Supports Passive(PASV) Mode Only! +Enabled: Turn FTP Server ON +Disabled: Turn FTP Server OFF +Username: Username to login to ftp server +Password: Password to login to ftp server + +Power LED: + +Enabled: Turn ON Power LED +Disabled: Turn OFF Power LED + +RFID Capture Log: + +Useful to change this value to differentiate between facilities during various security assessments. +File Name: File name to save captured RFID tags to for the current security assessment. + +----- +List Exfiltrated Data +----- + +Displays all log files containing RFID tag captures. + +----- +Format File System +----- + +This will erase the contents of the SPIFFS file system including ALL RFID tag captures. +Formatting may take up to 90 seconds. +All current settings will be retained unless you reboot your device during this process. + +----- +Upgrade ESP-RFID-Thief Firmware +----- + +Authenticate using your username and password set in the configuration page. + +Default credentials to access the firmware upgrade page: +Username: "admin" +Password: "hacktheplanet" + +Select "Browse" choose the new firmware to be uploaded and then click "Upgrade". + +You will need to manually reset the device upon the browser alerting you that the upgrade was successful. + +----- +Licensing Information +----- + +Created by Corey Harding +https://github.com/exploitagency/ESP-RFID-Thief +ESP-RFID-Thief software is licensed under the MIT License +ESP-RFID-Thief hardware is licensed under the Attribution-ShareAlike 3.0 Unported (CC BY-SA 3.0) License \ No newline at end of file