
USB 테스트를 간편하게

AutoGadgetFS는 USB 프로토콜에 대한 깊은 지식 없이도 USB 기기와 관련 호스트/드라이버/소프트웨어를 평가할 수 있도록 하는 오픈 소스 프레임워크입니다. 이 도구는 Python3로 작성되었으며 RabbitMQ와 WiFi 접속을 활용하여 연구자가 전 세계 어디에서나 원격으로 USB 보안 평가를 수행할 수 있게 합니다. ConfigFS를 활용하여 AutoGadgetFS는 사용자가 빠르게 기기를 복제하고 에뮬레이트할 수 있도록 하여 각 구현의 세부 사항을 깊이 파고들 필요를 없앱니다. 또한 이 프레임워크는 사용자가 자신만의 퍼저를 그 위에 만들 수 있도록 합니다.
<div style="text-align:center"><img src="https://raw.githubusercontent.com/ehabhussein/AutoGadgetFS/master/screenshots/devtest.jpeg" width="450" height="187" /></div>
<a name="MMITM"/>```bash
Minimal agfs in the middle setup:

```bash Complete agfs in the middle setup with debugging support:
<div style="text-align:center"><img src="https://raw.githubusercontent.com/ehabhussein/AutoGadgetFS/master/screenshots/scenario2.jpeg"/></div>
---
<a name="Usbdev"/>
### USB Device 클래스 지원:
[✔️] USB HID 기기 완전 지원 (중간자 공격)
[⚠️] 기기 전용 테스트 .. 모든 USB 기기 (중간자 공격 없음)
[⏳] 향후 릴리스... 모든 USB 기기 (중간자 공격)
---
<a name="Caps"/>
### 기능:
1. USB 기기를 쉽게 찾고, 선택하고, 연결할 수 있습니다.
1. 모든 USB HID 기기를 에뮬레이션합니다.
1. HID 기기에 대한 중간자 스니핑 AGFS 수행 (통신을 디스크에 저장).
1. 기기 스니핑 (모든 기기).
1. 여러 퍼저를 사용하여 기기나 호스트를 퍼징할 수 있습니다.
1. 무작위 퍼저 (고정 또는 임의 길이 패킷 사용).
1. 이전 USB 통신에서 학습하는 스마트 퍼저.
1. 설명 퍼저: 퍼저에 어떤 바이트를 퍼징할지 지시하고 나머지 패킷은 동일하게 유지.
1. 가젯 퍼저.
1. 순차 퍼저.
1. 제어 전송 열거자.
1. 파일에서 패킷 재생.
1. 저장된 USBLyzer 캡처에서 패킷 재생.
1. 패킷을 시각적으로 표시하여 통신의 리버스 엔지니어링을 쉽게 수행할 수 있습니다.
1. DFU 모드의 기기나 정보 유출 시 알림.
1. USB 기기와 호스트는 인터넷상 어디에나 있을 수 있습니다.
1. 갑작스러운 인터페이스 변경 모니터링.
---
<a name="Road"/>
### 로드맵:
1. 기기에 대한 제어 전송 요청을 스니핑하고 응답합니다.
1. 중간자 공격 및 모든 유형의 기기 에뮬레이션.
1. 콘솔/QT 기반 인터페이스.
1. RPI zero W에서 더 많은 인터페이스/엔드포인트 지원.
1. greatfet과 같은 더 많은 보드 지원.
1. 맞춤형 보드로 이전.
1. 라즈베리 파이가 모든 인터페이스에서 USB 기기 에뮬레이션을 완전히 지원하도록 작업.
1. 시퀀스 번호를 통해 송수신 패킷을 상호 연관시킵니다.
---
<a name="Installation"/>
### 설치:
<a name="Linux"/>
### Linux 머신:
* 참고: USB 패스스루 문제로 인해 WSL/WSL2는 지원되지 않습니다.
* Python3, ipython3 ,git, pip 및 rabbitMQ 서버 설치
```bash
sudo apt install python3 ipython3 git python3-pip rabbitmq-server dfu-util
sudo service rabbitmq-server start
```
* 저장소 클론
```bash
git clone https://github.com/ehabhussein/AutoGadgetFS
cd AutoGadgetFS
```
* 요구 사항 설치
```bash
sudo -H pip3 install -r requirements.txt
```
* 더 나은 ipython 경험을 위해 prompt toolkit 다운그레이드:
```bash
sudo python3 -m pip install prompt-toolkit~=2.0
```
* rabbitMQ 웹 인터페이스 활성화
```bash
sudo rabbitmq-plugins enable rabbitmq_management
http://localhost:15672/ to reach the web interface
```
* *guest:guest* 자격 증명으로 웹 인터페이스에 로그인
* 참고: rabbitMQ를 `localhost`에 설치하지 않은 경우 다음 사용자를 추가하고 로그인하세요:
```bash
sudo rabbitmqctl add_user autogfs usb4ever
sudo rabbitmqctl set_user_tags autogfs administrator
```
* rabbitMQ 구성 파일 업로드
* 개요 탭에서 맨 아래로 스크롤하여 정의 가져오기
* 다음 파일 업로드: *rabbitMQbrokerconfig/rabbitmq-Config.json*
```bash
sudo service rabbitmq-server restart
```
* 설치 테스트
```python
sudo ipython3
Python 3.7.7 (default, Apr 1 2020, 13:48:52)
Type 'copyright', 'credits' or 'license' for more information
IPython 7.9.0 -- An enhanced Interactive Python. Type '?' for help.
In [1]: import libagfs
In [2]: x = libagfs.agfs()
***************************************
AutoGadgetFS: USB testing made easy
***************************************
Enter IP address of the rabbitmq server: 127.0.0.1
In [3]: exit
sudo `python3` agfsconsole.py
***************************************
AutoGadgetFS: USB testing made easy
***************************************
Enter IP address of the rabbitmq server: 127.0.0.1
Give your project a name?!:
``` ```
* Patch Pyusb langID ( Not needed unless you get pyusb errors for langID ):
* Edit the file `/usr/local/lib/python3/dist-packages/usb/util.py`
* make changes to the `def get_string` method to look like below:
```python
if 0 == len(langids):
return "Error Reading langID"
#raise ValueError("The device has no langid")
if langid is None:
langid = langids[0]
elif langid not in langids:
return "Error Reading langID"
#raise ValueError("The device does not support the specified langid")
```
* If you prefer to use `patch` apply the following patch to the file: `AutoGadgetFS/pyusb_patches/pyusb_langid.patch`
---
<a name="Rasp"/>
### Raspberry Pi Zero W:
* Obtain a copy of [Raspian Lite Edition](https://downloads.raspberrypi.org/raspios_lite_armhf_latest)
* Burn the Image to the SD card using [BalenaEtcher](https://www.balena.io/etcher/)
* Mount the SD card on your machine and make the following changes:
* In the `/path/to/sdcard/boot/config.txt` file add to the very end of the file:
```bash
enable_uart=1
dtoverlay=dwc2
```
* In the `/path/to/sdcard/boot/cmdline.txt` add right after `rootwait`
```bash
modules-load=dwc2
```
* it should look like this make sure its on the same line:
```bash
console=serial0,115200 console=tty1 root=PARTUUID=6c586e13-02 rootfstype=ext4 elevator=deadline fsck.repair=yes rootwait modules-load=dwc2
```
* Enable ssh:
* in the `/path/to/sdcard/boot` directory create an empty file name ssh:
```bash
sudo touch /path/to/sdcard/boot/ssh
```
* Enable Wifi:
* in the `/path/to/sdcard/boot` directory create an file named `wpa_supplicant.conf`:
```bash
sudo vim /path/to/sdcard/boot/wpa_supplicant.conf
```
* Add the following contents:
```bash
ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev
update_config=1
country=US
network={
ssid="<your wifi SSID>"
psk="<your wifi password>"
key_mgmt=WPA-PSK
}
```
* Unmount the SD card and place it back into the Raspberry Pi Zero and power it on.
* Copy the content of `AutogadgetFS/Pizero/` to the Pi zero: `username: pi` & `password: raspberry`
```bash
cd AutogadgetFS/Pizero/
scp gadgetfuzzer.py removegadget.sh requirements.txt router.py pi@<pi-ipaddress>:/home/pi
```
* SSH into the PI Zero and setup requirements for AutoGadgetFS: