Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Android-PIN-Bruteforce — Androidスマートフォン(またはデバイス)のロック画面PINをブルートフォースで解除します。お使いのKali Nethunterスマホを、Androidデバイス向けブルートフォースPINクラッカーに変身させましょう!(root不要、adb不要) | Kitploit
ツール/GitHubGitHub/urbanadventurer/android-pin-bruteforce
Androidセキュリティパスワード攻撃ハードウェアハッキングモバイルセキュリティ
GitHuburbanadventurer/android-pin-bruteforce

Android-PIN-Bruteforce

Androidスマートフォン(またはデバイス)のロック画面PINをブルートフォースで解除します。お使いのKali Nethunterスマホを、Androidデバイス向けブルートフォースPINクラッカーに変身させましょう!(root不要、adb不要)

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
4.8k8321184年前Kitploit レビュー済み

🔓📱 Android-PIN-Bruteforce

ロック画面のPINをブルートフォースしてAndroidスマートフォン(またはデバイス)のロックを解除します。

Kali Nethunterスマートフォンを、Androidデバイス向けのPINブルートフォースクラッカーに変えましょう!

📱 仕組み

ロックされたスマートフォンをNethunterデバイスに接続するためにUSB OTGケーブルを使用します。キーボードをエミュレートし、自動的にPINを試行し、誤った推測を多く試行した後に待機します。

How to Connect Phones

[Nethunterスマートフォン] <--> [USBケーブル] <--> [USB OTGアダプター] <--> [ロックされたAndroidスマートフォン]

USB HID Gadgetドライバーは、USBヒューマンインターフェースデバイス(HID)のエミュレーションを提供します。これにより、Android Nethunterデバイスがロックされたスマートフォンへのキーボード入力をエミュレートできます。ロックされたスマートフォンにキーボードを差し込んでキーを押すのと同じです。

⏱ Samsung S5で4桁のPINをすべて試すには約16.6時間かかりますが、最適化されたPINリストを使用すれば、はるかに短い時間で済みます。

必要なもの

  • ロックされたAndroidスマートフォン
  • Nethunterスマートフォン(またはHIDカーネル対応のroot化されたAndroid端末)
  • USB OTG(On The Go)ケーブル/アダプター(USBオスMicro-BからメスUSB A)と、標準の充電ケーブル(USBオスMicro-BからオスA)。
  • 以上です!

🌟 利点

  • NetHunterスマートフォンをAndroid PINクラッキングマシンに変える
  • 他の方法とは異なり、ロックされたスマートフォンでADBやUSBデバッグを有効にする必要はありません
  • ロックされたAndroidスマートフォンのroot化は不要
  • Rubber Ducky、Teensy、Cellebrite、XPIN Clipなどの特別なハードウェアを購入する必要はありません
  • バックオフ時間を簡単に変更して、他の種類のデバイスをクラックできます
  • 動作します!

⭐ 機能

  • 1桁から10桁までの任意の長さのPINをクラック
  • 設定ファイルを使用して異なるスマートフォンをサポート
  • 3桁、4桁、5桁、6桁のPIN向けに最適化されたPINリスト
  • 低電力警告を含むスマートフォンのポップアップをバイパス
  • スマートフォンが抜かれたり電源が切れたりしたことを検出し、5秒ごとに再試行しながら待機
  • X回のPIN試行ごとにN秒の遅延を設定可能
  • ログファイル

インストール

TBC

スクリプトの実行

スクリプトを /sdcard/ にインストールした場合、以下のコマンドで実行できます。bash ./android-pin-bruteforce

Note that Android mounts /sdcard with the noexec flag. You can verify this with mount.

Usage

Android-PIN-Bruteforce (0.2) は、ロック画面のPINをブルートフォース(総当たり)してAndroid端末のロックを解除するために使用されます。
  詳細情報: https://github.com/urbanadventurer/Android-PIN-Bruteforce

Commands:
  crack                PINの解錠を開始する
  resume               選択したPINから再開する
  rewind               選択したPINから逆順に解錠する
  diag                 診断情報を表示する
  version              バージョン情報を表示して終了する

Options:
  -f, --from PIN       このPINから再開する
  -a, --attempts       開始時の誤った試行回数NUM
  -m, --mask REGEX     PIN内の既知の桁にマスクを使用する
  -t, --type TYPE      PINまたはパターン解錠を選択する
  -l, --length NUM     NUM桁のPINを解錠する
  -c, --config FILE    読み込む設定ファイルを指定する
  -p, --pinlist FILE   カスタムPINリストを指定する
  -d, --dry-run        テスト用のドライラン。キーは送信しない。
  -v, --verbose        詳細なログを出力する

Usage:
  android-pin-bruteforce <command> [options]```


## Supported Android Phones/Devices

This has been successfully tested with various phones including the Samsung S5, S7, Motorola G4 Plus and G5 Plus.

It can unlock Android versions 6.0.1 through to 10.0. The ability to perform a bruteforce attack doesn't depend on the Android version in use. It depends on how the device vendor developed their own lockscreen.

Check the Phone Database for more details
https://github.com/urbanadventurer/Android-PIN-Bruteforce/wiki/Phone-Database

## 🎳 PIN Lists

Optimised PIN lists are used by default unless the user selects a custom PIN list.  

### Cracking PINs of different lengths

Use the `--length` commandline option.

Use this command to crack a 3 digit PIN, 
`./android-pin-bruteforce crack --length 3`

Use this command to crack a 6 digit PIN
`./android-pin-bruteforce crack --length 6`

### Where did the optimised PIN lists come from?

The optimised PIN lists were generated by extracting numeric passwords from database leaks then sorting by frequency. All PINs that did not appear in the password leaks were appended to the list. 

The optimised PIN lists were generated from *Ga$$Pacc DB Leak* (21GB decompressed, 688M Accounts, 243 Databases, 138920 numeric passwords).

#### The 4 digit PIN list

The reason that the 4 digit PIN list is used from a different source is because it gives better results than the generated list from *Ga$$Pacc DB Leak*.

`optimised-pin-length-4.txt` is an optimised list of all possible 4 digit PINs, sorted by order of likelihood.
It can be found with the filename `pinlist.txt` at https://github.com/mandatoryprogrammer/droidbrute

This list is used with permission from Justin Engler & Paul Vines from Senior Security Engineer, iSEC Partners,
and was used in their Defcon talk, [Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO)](https://www.defcon.org/html/defcon-21/dc-21-speakers.html#Engler)

### Cracking with Masks

Masks use regular expressions with the standard grep extended format.

`./android-pin-bruteforce crack --mask "...[45]" --dry-run`

- To try all years from 1900 to 1999, use a mask of `19..`
- To try PINs that have a 1 in the first digit, and a 1 in the last digit, use a mask of `1..1`
- To try PINs that end in 4 or 5, use `...[45]`

## 📱 Configuration for different phones

Device manufacturers create their own lock screens that are different to the default or stock Android. 
To find out what keys your phone needs, plug a keyboard into the phone and try out different combinations.

Load a different configuration file, with the `--config FILE` commandline parameter.

Example:
`./android-pin-bruteforce --config ./config.samsung.s5 crack`

You can also edit the `config` file by customising the timing and keys sent.

The following configuration variables can be used to support a different phone's lockscreen.

タイミング

DELAY_BETWEEN_KEYS は、各キーが送信された後に待機する秒数です

DELAY_BETWEEN_KEYS=0.25

PROGRESSIVE_COOLDOWN_ARRAY 変数は、プログレッシブクールダウンをカスタマイズするための多次元配列として機能します

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________ は試行番号です

PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN はクールダウンするまでに試行する回数です

PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____ はクールダウンの秒数です

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________=(1 11 41) PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN=(5 1 1) PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____=(30 30 60)

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END は、クールダウン期間終了の何秒前にキーを送信するかを定義します

0 に設定すると無効になります

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END=5

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END は、クールダウン期間終了前にメッセージやポップアップを閉じるために送信されるキーを設定します

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END="enter enter enter"

KEYS_BEFORE_EACH_PIN は、ロック画面を表示させるために送信されるキーを設定します。これは各 PIN の前に送信されます。

デフォルトでは "escape enter" を送信しますが、一部の端末では他のキーに反応する場合があります。

例:

KEYS_BEFORE_EACH_PIN="ctrl_escape enter"

KEYS_BEFORE_EACH_PIN="escape space"

KEYS_BEFORE_EACH_PIN="escape enter"

KEYS_STAY_AWAKE_DURING_COOLDOWN は、クールダウン期間中に端末を起動状態に保つために送信されるキーです

KEYS_STAY_AWAKE_DURING_COOLDOWN="enter"

SEND_KEYS_STAY_AWAKE_DURING_COOLDOWN_EVERY_N_SECONDS は、キーが送信される頻度(秒単位)です

SEND_KEYS_STAY_AWAKE_DURING_COOLDOWN_EVERY_N_SECONDS=5

DELAY_BEFORE_STARTING は、ブルートフォースを開始する前に待機する秒数です

DELAY_BEFORE_STARTING=2

KEYS_BEFORE_STARTING は、ブルートフォース開始前に送信されるキーを設定します

KEYS_BEFORE_STARTING="enter"```

Popups

We send keys before the end of the cooldown period, or optionally during the cooldown period. This is to keep the lockscreen app active and to dismiss any popups about the number of incorrect PIN attempts or a low battery warning.

Test sending keys from the NetHunter phone

Test sending keys from the terminal

Use ssh from your laptop to the NetHunter phone, and use this command to test sending keys:

In this example, the enter key is sent.

echo "enter" | /system/xbin/hid-keyboard /dev/hidg0 keyboard

In this example, ctrl-escape is sent.

echo "left-ctrl escape" | /system/xbin/hid-keyboard /dev/hidg0 keyboard

Note: Sending combinations of keys in config file variables is different. Currently only ctrl_escape is supported.

In this example, keys a, b, c are sent.

echo a b c | /system/xbin/hid-keyboard /dev/hidg0 keyboard

Test sending keys from an app

This Android app is a virtual USB Keyboard that you can use to test sending keys.

https://store.nethunter.com/en/packages/remote.hid.keyboard.client/

How to send special keys

Use this list for the following variables:

  • KEYS_BEFORE_EACH_PIN
  • KEYS_STAY_AWAKE_DURING_COOLDOWN
  • KEYS_BEFORE_STARTING
ツールをダウンロード