Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Android-PIN-Bruteforce — Desbloquea un teléfono Android (o dispositivo) mediante fuerza bruta en el PIN de la pantalla de bloqueo. ¡Convierte tu teléfono Kali Nethunter en un cracker de PIN por fuerza bruta para dispositivos Android! (sin root, sin adb) | Kitploit
Herramientas/GitHubGitHub/urbanadventurer/android-pin-bruteforce
Seguridad AndroidAtaques de ContraseñasHacking de HardwareSeguridad Móvil
GitHuburbanadventurer/android-pin-bruteforce

Android-PIN-Bruteforce

Desbloquea un teléfono Android (o dispositivo) mediante fuerza bruta en el PIN de la pantalla de bloqueo. ¡Convierte tu teléfono Kali Nethunter en un cracker de PIN por fuerza bruta para dispositivos Android! (sin root, sin adb)

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
4.8k832118hace 4 añosRevisado por Kitploit

🔓📱 Android-PIN-Bruteforce

Desbloquea un teléfono Android (o dispositivo) mediante fuerza bruta en el PIN de la pantalla de bloqueo.

Convierte tu teléfono Kali Nethunter en un cracker de PIN por fuerza bruta para dispositivos Android!

📱 Cómo funciona

Usa un cable USB OTG para conectar el teléfono bloqueado al dispositivo Nethunter. Emula un teclado, prueba automáticamente PINs y espera después de intentar demasiadas conjeturas incorrectas.

Cómo conectar teléfonos

[Teléfono Nethunter] <--> [Cable USB] <--> [Adaptador USB OTG] <--> [Teléfono Android bloqueado]

El controlador USB HID Gadget proporciona emulación de dispositivos de interfaz humana (HID) USB. Esto permite que un dispositivo Android Nethunter emule la entrada del teclado al teléfono bloqueado. Es como conectar un teclado al teléfono bloqueado y presionar teclas.

⏱ Esto toma un poco más de 16.6 horas con un Samsung S5 para probar todos los PINs posibles de 4 dígitos, pero con la lista optimizada de PINs debería tomarte mucho menos tiempo.

Necesitarás

  • Un teléfono Android bloqueado
  • Un teléfono Nethunter (o cualquier Android rooteado con soporte de kernel HID)
  • Cable/adaptador USB OTG (On The Go) (USB macho Micro-B a hembra USB A), y un cable de carga estándar (USB macho Micro-B a macho A).
  • ¡Eso es todo!

🌟 Beneficios

  • Convierte tu teléfono NetHunter en una máquina de descifrado de PIN Android
  • A diferencia de otros métodos, no necesitas ADB o depuración USB habilitada en el teléfono bloqueado
  • El teléfono Android bloqueado no necesita estar rooteado
  • No necesitas comprar hardware especial, por ejemplo, Rubber Ducky, Teensy, Cellebrite, XPIN Clip, etc.
  • Puedes modificar fácilmente el tiempo de retroceso para descifrar otros tipos de dispositivos
  • ¡Funciona!

⭐ Características

  • Descifra PINs de cualquier longitud de 1 a 10 dígitos
  • Usa archivos de configuración para soportar diferentes teléfonos
  • Listas optimizadas de PINs para PINs de 3,4,5 y 6 dígitos
  • Evita las ventanas emergentes del teléfono, incluyendo la advertencia de batería baja
  • Detecta cuando el teléfono está desconectado o apagado, y espera reintentando cada 5 segundos
  • Retrasos configurables de N segundos después de cada X intentos de PIN
  • Archivo de registro

Instalación

TBC

Ejecutando el script

Si instalaste el script en /sdcard/, puedes ejecutarlo con el siguiente comando.bash ./android-pin-bruteforce

Note that Android mounts /sdcard with the noexec flag. You can verify this with mount.

Usage

Android-PIN-Bruteforce (0.2) se utiliza para desbloquear un teléfono Android (o dispositivo) mediante la fuerza bruta del PIN de la pantalla de bloqueo.
  Encuentre más información en: https://github.com/urbanadventurer/Android-PIN-Bruteforce

Commands:
  crack                Comenzar a descifrar PINs
  resume               Reanudar desde un PIN elegido
  rewind               Descifrar PINs en orden inverso desde un PIN elegido
  diag                 Mostrar información de diagnóstico
  version              Mostrar información de versión y salir

Options:
  -f, --from PIN       Reanudar desde este PIN
  -a, --attempts       Comenzar desde NUM intentos incorrectos
  -m, --mask REGEX     Usar una máscara para dígitos conocidos en el PIN
  -t, --type TYPE      Seleccionar descifrado de PIN o PATRÓN
  -l, --length NUM     Descifrar PINs de longitud NUM
  -c, --config FILE    Especificar archivo de configuración a cargar
  -p, --pinlist FILE   Especificar una lista de PINs personalizada
  -d, --dry-run        Simulación para pruebas. No envía ninguna tecla.
  -v, --verbose        Mostrar registros detallados

Usage:
  android-pin-bruteforce <comando> [opciones]```


## Supported Android Phones/Devices

This has been successfully tested with various phones including the Samsung S5, S7, Motorola G4 Plus and G5 Plus.

It can unlock Android versions 6.0.1 through to 10.0. The ability to perform a bruteforce attack doesn't depend on the Android version in use. It depends on how the device vendor developed their own lockscreen.

Check the Phone Database for more details
https://github.com/urbanadventurer/Android-PIN-Bruteforce/wiki/Phone-Database

## 🎳 PIN Lists

Optimised PIN lists are used by default unless the user selects a custom PIN list.  

### Cracking PINs of different lengths

Use the `--length` commandline option.

Use this command to crack a 3 digit PIN, 
`./android-pin-bruteforce crack --length 3`

Use this command to crack a 6 digit PIN
`./android-pin-bruteforce crack --length 6`

### Where did the optimised PIN lists come from?

The optimised PIN lists were generated by extracting numeric passwords from database leaks then sorting by frequency. All PINs that did not appear in the password leaks were appended to the list. 

The optimised PIN lists were generated from *Ga$$Pacc DB Leak* (21GB decompressed, 688M Accounts, 243 Databases, 138920 numeric passwords).

#### The 4 digit PIN list

The reason that the 4 digit PIN list is used from a different source is because it gives better results than the generated list from *Ga$$Pacc DB Leak*.

`optimised-pin-length-4.txt` is an optimised list of all possible 4 digit PINs, sorted by order of likelihood.
It can be found with the filename `pinlist.txt` at https://github.com/mandatoryprogrammer/droidbrute

This list is used with permission from Justin Engler & Paul Vines from Senior Security Engineer, iSEC Partners,
and was used in their Defcon talk, [Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO)](https://www.defcon.org/html/defcon-21/dc-21-speakers.html#Engler)

### Cracking with Masks

Masks use regular expressions with the standard grep extended format.

`./android-pin-bruteforce crack --mask "...[45]" --dry-run`

- To try all years from 1900 to 1999, use a mask of `19..`
- To try PINs that have a 1 in the first digit, and a 1 in the last digit, use a mask of `1..1`
- To try PINs that end in 4 or 5, use `...[45]`

## 📱 Configuration for different phones

Device manufacturers create their own lock screens that are different to the default or stock Android. 
To find out what keys your phone needs, plug a keyboard into the phone and try out different combinations.

Load a different configuration file, with the `--config FILE` commandline parameter.

Example:
`./android-pin-bruteforce --config ./config.samsung.s5 crack`

You can also edit the `config` file by customising the timing and keys sent.

The following configuration variables can be used to support a different phone's lockscreen.

Tiempos

DELAY_BETWEEN_KEYS es el período de tiempo en segundos que se espera después de enviar cada tecla

DELAY_BETWEEN_KEYS=0.25

Las variables PROGRESSIVE_COOLDOWN_ARRAY actúan como un arreglo multidimensional para personalizar el enfriamiento progresivo

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________ es el número de intento

PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN es cuántos intentos hacer antes de enfriar

PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____ es el enfriamiento en segundos

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________=(1 11 41) PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN=(5 1 1) PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____=(30 30 60)

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END define cuántos segundos antes del final del período de enfriamiento se enviarán las teclas

establecer a 0 para deshabilitar

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END=5

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END configura las teclas que se envían para descartar mensajes y ventanas emergentes antes del final del período de enfriamiento

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END="enter enter enter"

Descargar herramienta