Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
nexmon — Broadcom/Cypress WiFi 칩용 C 기반 펌웨어 패칭 프레임워크로, 모니터 모드, 프레임 인젝션 및 그 외 다양한 기능을 지원합니다. | Kitploit
도구/GitHubGitHub/seemoo-lab/nexmon
Embedded Systems SecurityPacket Sniffing & AnalysisWi-Fi AuditingReverse EngineeringInformation GatheringWireless SecurityHardware HackingHardware & IoT SecurityFirmware Analysis
GitHubseemoo-lab/nexmon

nexmon

Broadcom/Cypress WiFi 칩용 C 기반 펌웨어 패칭 프레임워크로, 모니터 모드, 프레임 인젝션 및 그 외 다양한 기능을 지원합니다.

2.9k505351개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기

NexMon logo

nexmon이란?

Nexmon은 Broadcom/Cypress WiFi 칩을 위한 C 기반 펌웨어 패칭 프레임워크로, radiotap 헤더가 포함된 모니터 모드와 프레임 주입을 활성화하는 등 자체 펌웨어 패치를 작성할 수 있게 해줍니다.

아래에서 nexmon으로 가능한 작업의 개요를 확인할 수 있습니다. 이 저장소는 주로 다양한 칩에서 모니터 모드와 프레임 주입을 활성화하는 데 초점을 맞춥니다. 추가 기능을 원한다면 다음 프로젝트들이 흥미로울 수 있습니다:

  • http://nexmon.org/jammer: 진행 중인 프레임 전송에 임의의 재밍 신호를 중첩할 수 있는 실제 Wi-Fi 재머.
    • Wi-Fi 칩을 소프트웨어 정의 라디오(SDR)로 사용하여 재밍 신호를 생성합니다
    • 2.4 GHz 대역에서 80 MHz 대역폭과 같은 비표준 채널을 사용할 수 있습니다
    • 임의의 전송 전력을 설정할 수 있습니다
    • D11 코어의 실시간 MAC 구현을 패치할 수 있습니다
  • http://nexmon.org/csi: 다양한 Wi-Fi 칩을 위한 채널 상태 정보(CSI) 추출기
    • 80 MHz 대역폭에서 최대 4x4 MIMO 전송의 CSI를 추출할 수 있습니다
  • http://nexmon.org/debugger: JTAG 접근 없이 ARM 마이크로컨트롤러 디버깅
    • 디버깅 레지스터에 대한 저수준 접근을 허용하여 중단점(Breakpoint)과 감시점(Watchpoint)을 설정하고 싱글 스텝(single stepping)을 실행할 수 있습니다
  • http://nexmon.org/covert_channel: Wi-Fi 신호에 정보를 숨기는 은닉 채널(Covert Channel)
    • 재머보다 더 고급화된 소프트웨어 정의 라디오 기능
    • 채널 상태 정보 추출의 예제 애플리케이션
  • http://nexmon.org/sdr: Wi-Fi 칩을 소프트웨어 정의 라디오로 사용
    • 현재 2.4 및 5 GHz Wi-Fi 대역에서 전송만 작동합니다

NexMon logo

경고

당사의 소프트웨어는 하드웨어를 손상시키거나 하드웨어 보증을 무효화할 수 있습니다! 도구 사용에 따른 모든 위험과 책임은 사용자에게 있습니다! 이 조건에 동의하지 않으면 nexmon을 사용하지 마세요!

지원 기기

현재 다음 기기들이 nexmon 펌웨어 패치에서 지원됩니다.

1 bcm43430a1은 과거에 bcm43438로 잘못 표기되었습니다.

2 ioctl을 통해 프레임을 주입하려면 LD_PRELOAD=libfakeioctl.so 대신 LD_PRELOAD=libnexmon.so를 사용하세요.

3 플래시 패치는 8바이트 길이여야 하며 8바이트 경계에 정렬되어야 합니다.

4 최초의 60 GHz Wi-Fi 라우터 Talon AD7200에 탑재된 802.11ad Wi-Fi 칩입니다. nexmon-arc를 사용하여 펌웨어를 패치하고, 당사의 사용자 정의 LEDE 이미지 lede-ad7200로 실행하세요.

5 nexmon 코드와 간섭하기 때문에 영역 1에서 실행 보호(Execute Never)를 비활성화했습니다(Section에 대한 Permission fault).

6 nexutil을 사용하려면 SELinux를 비활성화하거나 퍼미시브(permissive) 모드로 설정해야 합니다.

7 nexmon과 함께 Pico SDK를 사용하는 예제 애플리케이션은 pico-nexmon을 참조하세요.

8 플래시 패치는 16바이트 길이여야 하며 16바이트 경계에 정렬되어야 합니다.

9 펌웨어 설치, nexutil 및 SELinux 정책 설정에 Magisk 모듈을 사용합니다.

범례

  • M = 모니터 모드
  • RT = RadioTap 헤더가 포함된 모니터 모드
  • I = 프레임 주입
  • FP = 플래시 패칭
  • UC = Ucode 압축
  • CT = c't 기사 지원 (일관된 지원을 위해 ct-artikel 브랜치를 사용하세요)

나만의 펌웨어 패치를 만드는 단계

Linux가 실행되는 x86 컴퓨터를 사용하여 bcm4330, bcm4339 및 bcm4358용 패치 빌드 (예: Ubuntu 16.04)

  • 일부 종속성을 설치합니다: sudo apt-get install git gawk qpdf adb flex bison
  • x86_64 시스템에서만 필요합니다, i386 라이브러리를 설치하세요: ``` sudo dpkg --add-architecture i386 sudo apt-get update sudo apt-get install libc6:i386 libncurses5:i386 libstdc++6:i386
    root@kitploit:~
  • 저장소를 클론합니다: git clone https://github.com/seemoo-lab/nexmon.git
  • 저장소의 루트 디렉터리에서: cd nexmon
    • 빌드 환경을 설정합니다: source setup_env.sh
    • 일부 빌드 도구를 컴파일하고 원본 펌웨어 파일에서 ucode와 flashpatch를 추출합니다: make
  • 대상 기기의 patches 폴더로 이동합니다 (예: Nexus 5의 경우 bcm4339): cd patches/bcm4339/6_37_34_43/nexmon/
    • 패치된 펌웨어를 컴파일합니다: make
    • 원본 펌웨어 파일의 백업을 생성합니다: make backup-firmware
    • 스마트폰에 패치된 펌웨어를 설치합니다: make install-firmware (사전에 스마트폰을 컴퓨터에 연결했는지 확인하세요)

모니터 모드 패치 사용하기

  • 우리 유틸리티에서 최소한 nexutil과 libfakeioctl을 설치하세요. 가장 쉬운 방법은 이 앱을 사용하는 것입니다: https://nexmon.org/app. 하지만 utilties 폴더에서 make를 실행하여 소스에서 빌드할 수도 있습니다 (참고: 이를 위해서는 Android NDK가 올바르게 설치되어 있어야 합니다).
  • ADB 도구를 사용하여 Android 휴대폰에 연결합니다: adb shell
  • 액세스 포인트에 연결되어 있지 않은지 확인하세요
  • nexutil을 사용하여 모니터 모드를 활성화합니다: nexutil -m2
  • 이 시점에서 모니터 모드가 활성화됩니다. airmon-ng를 호출할 필요가 없습니다.
  • 중요: 대부분의 도구는 제대로 작동하려면 Radiotap 인터페이스가 필요합니다. libfakeioctl이 이러한 유형의 인터페이스를 에뮬레이션하므로, 선호하는 도구(예: tcpdump 또는 airodump-ng)를 호출할 때 LD_PRELOAD를 사용하여 이 라이브러리를 로드하세요: LD_PRELOAD=libfakeioctl.so tcpdump -i wlan0
  • 테스트되지 않은 힌트: XDA 회원 ruleh 덕분에 기본 모니터 모드를 활성화하는 bcmdhd 드라이버 패치가 있습니다. 참조: https://github.com/ruleh/misc/tree/master/monitor

Nexus 5에서 UDP를 통한 nexutil 사용

root 권한 없이 펌웨어와 통신할 수 있도록, 우리는 nexutil에서도 사용되는 libnexio를 통해 접근 가능한 UDP 인터페이스를 만들었습니다. 먼저 보안 쿠키를 설정하여 일반적으로 root 권한이 있음을 펌웨어에 증명해야 합니다. 그런 다음 UDP 기반 연결에 사용할 수 있습니다. wlan0 인터페이스에도 192.168.222.0/24 범위의 IP 주소가 필요하며, 그렇지 않으면 기본 nexutil broadcast-ip를 변경해야 합니다:

  • wlan0 인터페이스의 IP 주소를 설정합니다: ifconfig wlan0 192.168.222.1 netmask 255.255.255.0
  • root로 보안 쿠키를 설정합니다: nexutil -x<cookie (uint)>
  • 예를 들어 모니터 모드를 활성화하기 위해 UDP 연결을 시작합니다: nexutil -X<cookie> -m1

Raspbian/Raspberry Pi OS를 사용하여 RPI3/Zero W의 bcm43430a1, RPI3+/RPI4의 bcm434355c0 또는 RPI Zero 2W의 bcm43436b0용 패치 빌드 (권장)

참고: 현재 커널 버전 4.4(사용되지 않음), 4.9, 4.14, 4.19, 5.4, 5.10 및 5.15를 지원합니다. Raspbian에는 bcm43455c0용 펌웨어 버전 7.45.154이 포함되어 있습니다. 또한 Cypress의 최신 펌웨어 릴리스 7.45.189도 지원합니다. Raspberry Pi OS에는 펌웨어 버전 7.45.206이 포함되어 있습니다. 어떤 것이 가장 잘 작동하는지 직접 시도해 보십시오.

  • 다음 명령이 root로 실행되는지 확인하세요: sudo su

  • Raspbian 설치를 업그레이드합니다: apt-get update && apt-get upgrade

  • 드라이버와 일부 종속성을 빌드하기 위해 커널 헤더를 설치합니다: sudo apt install raspberrypi-kernel-headers git libgmp3-dev gawk qpdf bison flex make autoconf libtool texinfo

  • 저장소를 클론합니다: git clone https://github.com/seemoo-lab/nexmon.git

  • 저장소의 루트 디렉터리로 이동합니다: cd nexmon

  • 32bit Raspbian/Raspberry Pi OS에서

    • /usr/lib/arm-linux-gnueabihf/libisl.so.10이 존재하는지 확인하고, 존재하지 않으면 소스에서 컴파일합니다:
    • cd buildtools/isl-0.10, ./configure, make, make install,

모니터 모드 패치 사용하기

  • Mame82의 이전 작업 덕분에 다음을 실행하여 새로운 모니터 모드 인터페이스를 설정할 수 있습니다:iw phy `iw dev wlan0 info | gawk '/wiphy/ {printf "phy" $2}'` interface add mon0 type monitor
  • To activate monitor mode in the firmware, simply set the interface up: ifconfig mon0 up.
  • At this point, monitor mode is active. There is no need to call airmon-ng.
  • The interface already set the Radiotap header, therefore, tools like tcpdump or airodump-ng can be used out of the box: tcpdump -i mon0
  • Optional: To make the RPI3 load the modified driver after reboot:
    • Find the path of the default driver at reboot: modinfo brcmfmac #the first line should be the full path
    • Backup the original driver: mv "<PATH TO THE DRIVER>/brcmfmac.ko" "<PATH TO THE DRIVER>/brcmfmac.ko.orig"
    • Copy the modified driver (Kernel 4.9): cp /home/pi/nexmon/patches/bcm43430a1/7_45_41_46/nexmon/brcmfmac_kernel49/brcmfmac.ko "<PATH TO THE DRIVER>/"
    • Copy the modified driver (Kernel 4.14): cp /home/pi/nexmon/patches/bcm43430a1/7_45_41_46/nexmon/brcmfmac_4.14.y-nexmon/brcmfmac.ko "<PATH TO THE DRIVER>/"
    • Probe all modules and generate new dependency: depmod -a

How to build the utilities

To build the utilities such as nexmon or dhdutil for Android, you need to download the old NDK version 11c, extract it and export the environment variable NDK_ROOT pointing to the directory where you extracted the NDK files.

How to extract the ROM

The Wi-Fi firmware consists of a read-only part stored in the ROM of every Wi-Fi chip and another part that is loaded by the driver into the RAM. To analyze the whole firmware, one needs to extract the ROM. There are two options to do this. Either you write a firmware patch that simply copies the contents of the ROM to RAM and then you dump the RAM, or you directly dump the ROM after loading the regular firmware into the RAM. Even though, the second option is easier, it only works, if the ROM can be directly accessed by the driver, which is not always the case. Additionally, the firmware loaded into RAM can contain ROM patches that overlay the data stored in ROM. By dumping the ROM after loading the original RAM firmware, it contains flash patches. Hence, the ROM needs to be dumped again for every RAM firmware update to be consistent. As a conclusion, we prefer to dump the clean ROM after copying it to RAM.

Dumping the ROM directly

To dump the ROM directly, you need to know, where to find it and how large it is. On chips with Cortex-M3 it is usually at upper addresses such as 0x800000, while on chips with Cortex-R4 it is likely at 0x0. Run dhdutil to perform the dump:

root@kitploit:~
dhdutil membytes -r 0x0 0xA0000 > rom.bin```

## Dumping a clean ROM after copying to RAM
For the BCM4339 and BCM4358, we created `rom_extraction` projects that load a firmware patch that copies ROM to 
RAM and them dumps it using dhdutil. To dump the ROM simply execute the following in the project directory:

make dump-rom```

After ROM extraction, the rom.bin file will be copies to the corresponding firmwares subdirectory. To apply the flash patches of a specific RAM firmware version, enter its directory and execute:

root@kitploit:~
make rom.bin```



# Structure of this repository
* `buildtools`: Contains compilers and other tools to build the firmware
* `firmwares`
  * `<chip version>`
    * `<firmware version>`
      * `<firmware file>`: The original firmware that will be loaded into the RAM of the WiFi Chip
      * `definitions.mk`: Contains mainly firmware specific addresses
      * `structs.h`: Structures only valid for this firmware version
      * `Makefile`: Used to extract flashpatches and ucode
      * `flashpatches.c` (generated by Makefile): Contains flashpatches
      * `ucode.bin` (extracted by Makefile): Contains uncompressed Ucode
    * `structs.common.h`: Structures that are common between firmware versions
* `patches`
  * `<chip version>`
    * `<firmware version>`
      * `nexmon`
        * `Makefile`: Used to build the firmware
        * `patch.ld`: Linker file
        * `src`
          * `patch.c`: General patches to the firmware
          * `injection.c`: Code related to frame injection
          * `monitormode.c`: Code related to monitor mode with radiotap headers
          * `ioctl.c`: Handling of custom IOCTLs
          * ...
        * `obj` (generated by Makefile): Object files created from C files
        * `log` (generated by Makefile): Logs written during compilation
        * `gen` (generated by Makefile): Files generated during the build process
          * `nexmon.pre` (generated by gcc plugin): Extracted at-attributes and targetregion-pragmas
          * `nexmon.ld` (generated from nexmon.pre): Linker file use to place patch code at defined addresses in the firmware
          * `nexmon.mk` (generated from nexmon.pre): Make file used take code from patch.elf and place it into firmware
          * `flashpatches.ld` (generated from nexmon.pre): Linker file that places flashpatches at target locations in firmware ROM
          * `flashpatches.mk` (generated from nexmon.pre): Make file used to insert flashpatch config and data structures into firmware
          * `patch.elf` (generated from object files and linker scripts): contains the newly compiled code placed at predefined addresses
    * `common`
      * `wrapper.c`: Wrappers for functions that already exist in the firmware
      * `ucode_compression.c`: [tinflate](http://achurch.org/tinflate.c) based ucode decompression
      * `radiotap.c`: RadioTap header parser
      * `helper.c`: Helpful utility functions
    * `driver`: Patched brcmfmac driver
    * `include`: Common include files
      * `firmware_version.h`: Definitions of chip and firmware versions
      * `patcher.h`: Macros use to perform patching for existing firmware code (e.g., BPatch patches a branch instruction)
      * `capabilities.h`: Allows to indicate capabilities (such as, monitor mode and frame injection)
      * `nexioctl.h`: Defines custom IOCTL numbers

# Related projects
* [bcmon](https://bcmon.blogspot.de/): Monitor Mode and Frame Injection for the bcm4329 and bcm4330
* [monmob](https://github.com/tuter/monmob): Monitor Mode and Frame Injection for the bcm4325, bcm4329 and bcm4330
* [P4wnP1](https://github.com/mame82/P4wnP1): Highly customizable attack platform, based on Raspberry Pi Zero W and Nexmon
* [kali Nethunter OS](https://github.com/nethunteros): ROM that brings Kali Linux to smartphones with Nexmon support
* [dustcloud-nexmon](https://github.com/dgiese/dustcloud-nexmon): Nexmon for Xiaomi IoT devices (ARM based)
* [InternalBlue](https://github.com/seemoo-lab/internalblue): Bluetooth experimentation framework based on Reverse Engineering of Broadcom Bluetooth Controllers

# Interesting articles on firmware hacks
If you know more projects that use nexmon or perform similar firmware hacks, let us know and we will add a link.

* [Project Zero](https://googleprojectzero.blogspot.de/2017/09/over-air-vol-2-pt-1-exploiting-wi-fi.html): Over The Air - Vol. 2, Pt. 1: Exploiting The Wi-Fi Stack on Apple Devices
* [broadpwn](https://blog.exodusintel.com/2017/07/26/broadpwn/): Remotely Compromising Android and IOS via a Bug in Broadcom's Wi-Fi Chipsets
* [Project Zero](https://googleprojectzero.blogspot.de/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html): Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)
* [Project Zero](https://googleprojectzero.blogspot.de/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html): Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2) 

# Read my PhD thesis
* Matthias Schulz. [**Teaching Your Wireless Card New Tricks: Smartphone Performance and Security Enhancements through Wi-Fi Firmware Modifications**](http://tuprints.ulb.tu-darmstadt.de/7243/). Dr.-Ing. thesis, Technische Universität Darmstadt, Germany, February 2018. [pdf](http://tuprints.ulb.tu-darmstadt.de/7243/7/dissertation_2018_matthias_thomas_schulz.pdf)

# Read our papers
* F. Gringoli, M. Schulz, J. Link, and M. Hollick. [**Free Your CSI: A Channel State Information Extraction Platform For Modern Wi-Fi Chipsets**](https://doi.org/10.1145/3349623.3355477). Accepted to appear in *Proceedings of the 13th Workshop on Wireless Network Testbeds, Experimental evaluation & CHaracterization (WiNTECH 2019)*, October 2019. [code](https://nexmon.org/csi)
* D. Mantz, J. Classen, M. Schulz, and M. Hollick. [**InternalBlue - Bluetooth Binary Patching and Experimentation Framework**](https://dl.acm.org/citation.cfm?id=3326089). *In Proceedings of the 17th Annual International Conference on Mobile Systems, Applications, and Services (MobiSys '19)*. June 2019.
* M. Schuß, C. A. Boano, M. Weber, M. Schulz, M. Hollick, K. Römer. [**JamLab-NG: Benchmarking Low-Power Wireless Protocols under Controlable and Repeatable Wi-Fi Interference**](https://dl.acm.org/citation.cfm?id=3324331). *Proceedings of the 2019 International Conference on Embedded Wireless Systems and Networks (EWSN 2019)*, February 2019.
* M. Schulz, D. Wegemer, and M. Hollick. [**The Nexmon Firmware Analysis and Modification Framework: Empowering Researchers to Enhance Wi-Fi Devices**](https://doi.org/10.1016/j.comcom.2018.05.015). *Elsevier Computer Communications (COMCOM) Journal*. 2018.
* M. Schulz, J. Link, F. Gringoli, and M. Hollick. [**Shadow Wi-Fi: Teaching Smart- phones to Transmit Raw Signals and to Extract Channel State Information to Implement Practical Covert Channels over Wi-Fi**](https://dl.acm.org/citation.cfm?id=3210333). Accepted to appear in *Proceedings of the 16th ACM International Conference on Mobile Systems, Applications, and Services*, MobiSys 2018, June 2018.
* D. Steinmetzer, D. Wegemer, M. Schulz, J. Widmer, M. Hollick. [**Compressive Millimeter-Wave Sector Selection in Off-the-Shelf IEEE 802.11ad Devices**](https://dl.acm.org/citation.cfm?id=3143384). *Proceedings of the 13th International Conference on emerging Networking EXperiments and Technologies*, CoNEXT 2017, December 2017.
* M. Schulz, D. Wegemer, M. Hollick. [**Nexmon: Build Your Own Wi-Fi Testbeds With Low-Level MAC and PHY-Access Using Firmware Patches on Off-the-Shelf Mobile Devices**](https://dl.acm.org/citation.cfm?id=3131476). *Proceedings of the 11th ACM International Workshop on Wireless Network Testbeds, Experimental Evaluation & Characterization (WiNTECH 2017)*, October 2017. [pdf](https://www.seemoo.tu-darmstadt.de/mschulz/wintech2017) [video](https://youtu.be/m5Zrk4n4hoE)
* M. Schulz, F. Knapp, E. Deligeorgopoulos, D. Wegemer, F. Gringoli, M. Hollick. [**DEMO: Nexmon in Action: Advanced Applications Powered by the Nexmon Firmware Patching Framework**](https://dl.acm.org/citation.cfm?id=3133333), Accepted for publication in *Proceedings of the 11th ACM International Workshop on Wireless Network Testbeds, Experimental Evaluation & Characterization (WiNTECH 2017)*, October 2017. [pdf](https://www.seemoo.tu-darmstadt.de/mschulz/wintech2017demo)
* M. Schulz, F. Gringoli, D. Steinmetzer, M. Koch and M. Hollick. [**Massive Reactive Smartphone-Based Jamming using Arbitrary Waveforms and Adaptive Power Control**](https://dl.acm.org/citation.cfm?id=3098253). Proceedings of the *10th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2017)*, July 2017. [pdf](https://www.seemoo.tu-darmstadt.de/mschulz/wisec2017) [video](https://youtu.be/S2XPBK0KdiQ)
* M. Schulz, E. Deligeorgopoulos, M. Hollick and F. Gringoli. [**DEMO: Demonstrating Reactive Smartphone-Based Jamming**](https://dl.acm.org/citation.cfm?id=3106022). Proceedings of the *10th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec 2017)*, July 2017. [pdf](https://www.seemoo.tu-darmstadt.de/mschulz/wisec2017demo)
* M. Schulz. [**Nexmon - Wie man die eigene WLAN-Firmware hackt**](http://heise.de/-3538660), 
c't 26/2016, S. 168, Heise Verlag, 2016.
* M. Schulz, D. Wegemer, M. Hollick. [**DEMO: Using NexMon, the C-based WiFi 
firmware modification framework**](https://dl.acm.org/citation.cfm?id=2942419), 
Proceedings of the *9th ACM Conference on Security and Privacy in Wireless and 
Mobile Networks (WiSec 2016)*, July 2016. [pdf](https://www.seemoo.tu-darmstadt.de/mschulz/wisec2016demo1)
* M. Schulz, D. Wegemer and M. Hollick. [**NexMon: A Cookbook for Firmware 
Modifications on Smartphones to Enable Monitor Mode**](http://arxiv.org/abs/1601.07077), 
CoRR, vol. abs/1601.07077, December 2015. 
[bibtex](http://dblp.uni-trier.de/rec/bibtex/journals/corr/SchulzWH16)

[Get references as bibtex file](https://nexmon.org/bib)

# Reference our project
Any use of this project which results in an academic publication or other publication which includes a bibliography should include a citation to the Nexmon project and probably one of our papers depending on the code you use. Find all references in our [bibtex file](https://github.com/seemoo-lab/nexmon/blob/master/nexmon.bib). Here is the reference for the project only:

@electronic{nexmon:project, author = {Schulz, Matthias and Wegemer, Daniel and Hollick, Matthias}, title = {Nexmon: The C-based Firmware Patching Framework}, url = {https://nexmon.org}, year = {2017} }```

Contact

  • Matthias Schulz [email protected]
  • Daniel Wegemer [email protected]

Powered By

Secure Mobile Networking Lab (SEEMOO)

SEEMOO logo

Networked Infrastructureless Cooperation for Emergency Response (NICER)

NICER logo

Multi-Mechanisms Adaptation for the Future Internet (MAKI)

MAKI logo

Technische Universität Darmstadt

TU Darmstadt logo

도구 다운로드
WiFi 칩펌웨어 버전사용 기기운영 체제MRTIFPUCCT
bcm43305_90_100_41_staSamsung Galaxy S2Cyanogenmod 13.0XXXXO
bcm4335b06.30.171.1_staSamsung Galaxy S4LineageOS 14.1XXXXO
bcm43396_37_34_43Nexus 5Android 6 StockXXXXXO
bcm43430a117_45_41_26Raspberry Pi 3 and Zero WRaspbian 8XXXXXO
bcm43430a117_45_41_46Raspberry Pi 3 and Zero WRaspbian StretchXXXXXO
bcm43439a077_95_49 (2271bb6 CY)Raspberry Pi Pico WPico SDKXXXX
bcm43451b17_63_43_0iPhone 6iOS 10.1.1 (14B100)XX
bcm434557_45_77_0_hwHuawei P9Android 7 StockXXXXX
bcm434557_120_5_1_sta_C0Galaxy J7 2017?XX
bcm434557_45_77_0_hw(8-2017)Huawei P9Android 7 StockXXXXX
bcm4345557_46_77_11_hwHuawei P9Android 8 China StockXXXXX
bcm434557_45_59_16Sony Xperia Z5 CompactLineageOS 14.1XXXXX
bcm43455c07_45_154Raspberry Pi B3+/B4Raspbian Kernel 4.9/14/19XXXX
bcm43455c07_45_189Raspberry Pi B3+/B4Raspbian Kernel 4.14/19, 5.4XXXX
bcm43455c07_45_206Raspberry Pi B3+/B4Raspberry Pi OS Kernel 5.4XXXXX
bcm43455c07_45_234 (4ca95bb CY)Raspberry Pi B3+/B4/5Raspberry Pi OSXX
bcm43436b039_88_4_65Raspberry Pi Zero 2 WRaspberry Pi OS Kernel 5.10XXXXX
bcm43567_35_101_5_staNexus 6Android 7.1.2XXXXO
bcm43587_112_200_17_staNexus 6PAndroid 7 StockXXXXO
bcm43587_112_201_3_staNexus 6PAndroid 7.1.2 StockXXXXO
bcm435827_112_300_14_staNexus 6PAndroid 8.0.0 StockXXXXXO
bcm43596a039_75_155_45_sta_c0Samsung Galaxy S7Android 7 StockXOX
bcm43596a03,29_96_4_sta_c0Samsung Galaxy S7LineageOS 14.1XXXOX
bcm4375b13,5,618_38_18_staSamsung Galaxy S10루팅됨 + SELinux 비활성화XXXOX
bcm4375b13,5,618_41_8_9_staSamsung Galaxy S20루팅됨 + SELinux 비활성화XXXOX
bcm4389c15,8,920_82_42_sta (r994653)Samsung Galaxy S22 PlusAndroid 14, Magisk로 루팅됨XX
bcm4389c15,8,920_101_36_2 (r994653)Google Pixel 7 and 7 ProMagisk로 루팅됨XX
bcm4389c15,8,920_101_57 (r1035009)Google Pixel 7 and 7 ProMagisk로 루팅됨XX
bcm4398d05,8,924_671_6_9 (r1031525)Google Pixel 8Magisk로 루팅됨XX
bcm6715b0517_10_188_6401 (r808804)Asus RT-AX86U Pro스톡 펌웨어 3.0.0.4_388.23565/X
qca950044-1-0_55TP-Link Talon AD7200사용자 정의 LEDE 이미지
ln -s /usr/local/lib/libisl.so /usr/lib/arm-linux-gnueabihf/libisl.so.10
  • /usr/lib/arm-linux-gnueabihf/libmpfr.so.4이 존재하는지 확인하고, 존재하지 않으면 소스에서 컴파일합니다:
  • cd buildtools/mpfr-3.1.4, autoreconf -f -i, ./configure, make, make install, ln -s /usr/local/lib/libmpfr.so /usr/lib/arm-linux-gnueabihf/libmpfr.so.4
  • 64bit Raspberry Pi OS에서

    • sudo dpkg --add-architecture armhf
    • sudo apt-get update
    • sudo apt-get install libc6:armhf libisl23:armhf libmpfr6:armhf libmpc3:armhf libstdc++6:armhf
    • sudo ln -s /usr/lib/arm-linux-gnueabihf/libisl.so.23.0.0 /usr/lib/arm-linux-gnueabihf/libisl.so.10
    • sudo ln -s /usr/lib/arm-linux-gnueabihf/libmpfr.so.6.1.0 /usr/lib/arm-linux-gnueabihf/libmpfr.so.4
  • 그런 다음 펌웨어 패치 컴파일을 위한 빌드 환경을 설정할 수 있습니다

    • 빌드 환경을 설정합니다: source setup_env.sh
    • 일부 빌드 도구를 컴파일하고 원본 펌웨어 파일에서 ucode와 flashpatch를 추출합니다: make
  • bcm43430a1/bcm43455c0/bcm43436b0 칩셋용 patches 폴더로 이동합니다: cd patches/bcm43430a1/7_45_41_46/nexmon/ / patches/bcm43455c0/<7_45_154 or 7_45_189>/nexmon/ / cd patches/bcm43436b0/9_88_4_65/nexmon/

    • 패치된 펌웨어를 컴파일합니다: make
    • 원본 펌웨어 파일의 백업을 생성합니다: make backup-firmware
    • RPI3에 패치된 펌웨어를 설치합니다: make install-firmware
  • nexutil 설치: 저장소의 루트 디렉터리에서 nexutil 폴더로 전환합니다: cd utilities/nexutil/. nexutil을 컴파일하고 설치합니다: make && make install.

  • 선택 사항: WiFi 인터페이스를 더 잘 제어하려면 wpa_supplicant를 제거하세요: apt-get remove wpasupplicant
    또한 전원 절약 기능을 비활성화하는 것(iw dev wlan0 set power_save off)은 펌웨어 충돌을 방지하는 데 도움이 될 수 있습니다.

  • 참고: 일반 액세스 포인트에 연결하려면 먼저 nexutil -m0을 실행해야 합니다

  • The new driver should be loaded by default after reboot: reboot  * Note: It is possible to connect to an access point or run your own access point in parallel to the monitor mode interface on the wlan0 interface.