
Long Range Pager Systems: Pager und Coaster – Informations- und Brute-Force-Tool für URH und YS1 (Yardstick One / cc11xx)
Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool
Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool Inspiriert von Tony Tigers früherer Arbeit mit dem HackRF One
Ich habe das LRS Transmitter Tuneup Handbuch verwendet, um die Mittenfrequenz, den Hub, die Modulation und zu überprüfen
Dieses Skript benötigt nichts weiter als RfCat und console-menu
pip install -r requirements.txt
Frequency: 467.75 Mhz
Modulation: FSK
Encoding: Manchester
Rate: 626 baud
Samples/Symble: 3200
Sample Rate: 2M
Dieses Skript brute-forct alle Restaurant-IDs und sendet an alle Pager (Pager-ID 0) den Befehl, 30 Sekunden lang zu blinken.
Alert Commands
1 Flash 30 Seconds
2 Flash 5 Minutes
3 Flash/Beep 5X5
4 Beep 3 Times
5 Beep 5 Minutes
6 Glow 5 Minutes
7 Glow/Vib 15 Times
10 Flash Vib 1 Second
68 beep 3 times
Sie können sowohl die Restaurant-ID als auch die Pager-Nummer mit einem einzigen Befehl neu programmieren. Bitte verwenden Sie diesen Befehl NICHT gegen ein System, das nicht Ihnen gehört. Ja, es mag lustig sein, alle Pager in einem Restaurant auszulösen, aber sie neu zu programmieren ist nicht cool.
The protocol generating a pager alert packet is:
preamble header restaurant_id system_id pager_number 0000 0000 alert_type crc
The crc is given by taking the sum of the hex values and then taking the modulus of the sum by 255
For restaurant 0 and pager 0 (all) with an alert type of 1 the value would be
aaaaaafc2d0000000000000000012b
Flipper Zero custom preset modulation for decoding LRS pagers:
Custom_preset_name: Pagers
Custom_preset_module: CC1101
Custom_preset_data: 02 0D 07 04 08 32 0B 06 10 64 11 93 12 0C 13 02 14 00 15 15 18 18 19 16 1B 07 1C 00 1D 91 20 FB 21 56 22 10 00 00 C0 00 00 00 00 00 00 00