Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
nrf-research-firmware — 用于基于 Nordic Semiconductor nRF24LU1+ 的 USB 适配器和开发板的固件与研究工具。 | Kitploit
工具/GitHubGitHub/bastilleresearch/nrf-research-firmware
嵌入式系统安全数据包嗅探与分析侦察网络映射无线安全硬件安全
GitHubbastilleresearch/nrf-research-firmware

nrf-research-firmware

用于基于 Nordic Semiconductor nRF24LU1+ 的 USB 适配器和开发板的固件与研究工具。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
445132224年前Kitploit 审核通过

RFStorm nRF24LU1+ 研究固件

用于基于 Nordic Semiconductor nRF24LU1+ 的 USB 适配器和开发板的固件及研究工具。

依赖要求

  • SDCC(最低版本 3.1.0)
  • GNU Binutils
  • Python
  • PyUSB
  • platformio

在 Ubuntu 上安装依赖:

sudo apt-get install sdcc binutils python python-pip
sudo pip install -U pip
sudo pip install -U -I pyusb
sudo pip install -U platformio

支持的硬件

以下硬件已经过测试并确认可用。

  • CrazyRadio PA USB 适配器
  • SparkFun nRF24LU1+ 开发板
  • Logitech Unifying 适配器(型号 C-U0007,基于 Nordic Semiconductor)

构建固件

make

通过 USB 烧录

nRF24LU1+ 芯片自带出厂烧录的引导加载程序,占用闪存最顶部的 2KB。CrazyRadio 固件和 RFStorm 研究固件支持通过 USB 命令进入 Nordic 引导加载程序。

如果适配器和开发板运行以下固件之一,则可以通过 USB 进行编程:

  • Nordic Semiconductor 引导加载程序
  • CrazyRadio 固件
  • RFStorm 研究固件

通过 USB 烧录固件:

sudo make install

烧录 Logitech Unifying 适配器

最常见的 Unifying 适配器基于 nRF24LU1+,但有些使用 Texas Instruments 的芯片。 此固件仅支持型号为 C-U0007 的 nRF24LU1+ 版本。烧录 脚本会自动检测插入的适配器类型,并且只会尝试烧录 nRF24LU1+ 版本。

通过 USB 将固件烧录到 Logitech Unifying 适配器:

sudo make logitech_install

将 Logitech Unifying 适配器恢复为原始固件

下载并解压 Logitech 固件镜像,其文件名将是 RQR_012_005_00028.hex 或类似名称。然后,运行以下命令将 Logitech 固件烧录到适配器:

sudo ./prog/usb-flasher/logitech-usb-restore.py [path-to-firmware.hex]

使用 Teensy 通过 SPI 烧录

如果您的适配器或开发板变砖,您也可以使用 Teensy 通过 SPI 进行编程。

此方式仅在 Teensy 3.1/3.2 上测试过,但也很可能适用于其他 Arduino 变体。

构建并上传 Teensy 烧录器

platformio run --project-dir teensy-flasher --target upload

将 Teensy 连接到 nRF24LU1+

TeensyCrazyRadio PASparkFun nRF24LU1+ 开发板
GND9GND
83RESET
92PROG
1010P0.3
116P0.1
128P0.2
134P0.0
3.3V5VIN

烧录 nRF24LU1+

sudo make spi_install

Python 脚本

扫描器(scanner)

伪混杂模式设备发现工具,可扫描一组信道并打印解码后的增强型 Shockburst 数据包。

usage: ./nrf24-scanner.py [-h] [-c N [N ...]] [-v] [-l] [-p PREFIX] [-d DWELL]

optional arguments:
  -h, --help                          show this help message and exit
  -c N [N ...], --channels N [N ...]  RF channels
  -v, --verbose                       Enable verbose output
  -l, --lna                           Enable the LNA (for CrazyRadio PA dongles)
  -p PREFIX, --prefix PREFIX          Promiscuous mode address prefix
  -d DWELL, --dwell DWELL             Dwell time per channel, in milliseconds

扫描信道 1-5 上的设备

./nrf24-scanner.py -c {1..5}

在所有信道上扫描地址以 0xA9 开头的设备

./nrf24-scanner.py -p A9

嗅探器(sniffer)

设备跟踪嗅探器,可跟踪特定 nRF24 设备的跳频,并打印该设备解码后的增强型 Shockburst 数据包。

usage: ./nrf24-sniffer.py [-h] [-c N [N ...]] [-v] [-l] -a ADDRESS [-t TIMEOUT] [-k ACK_TIMEOUT] [-r RETRIES]

optional arguments:
  -h, --help                                 show this help message and exit
  -c N [N ...], --channels N [N ...]         RF channels
  -v, --verbose                              Enable verbose output
  -l, --lna                                  Enable the LNA (for CrazyRadio PA dongles)
  -a ADDRESS, --address ADDRESS              Address to sniff, following as it changes channels
  -t TIMEOUT, --timeout TIMEOUT              Channel timeout, in milliseconds
  -k ACK_TIMEOUT, --ack_timeout ACK_TIMEOUT  ACK timeout in microseconds, accepts [250,4000], step 250
  -r RETRIES, --retries RETRIES              Auto retry limit, accepts [0,15]

在所有信道上嗅探来自地址 61:49:66:82:03 的数据包

./nrf24-sniffer.py -a 61:49:66:82:03

网络映射器(network mapper)

星型网络映射器,通过更改指定地址的最后一个字节,并在信道列表中的每个信道上探测 256 个可能的地址,来发现星型网络中的活动地址。

usage: ./nrf24-network-mapper.py [-h] [-c N [N ...]] [-v] [-l] -a ADDRESS [-p PASSES] [-k ACK_TIMEOUT] [-r RETRIES]

optional arguments:
  -h, --help                                 show this help message and exit
  -c N [N ...], --channels N [N ...]         RF channels
  -v, --verbose                              Enable verbose output
  -l, --lna                                  Enable the LNA (for CrazyRadio PA dongles)
  -a ADDRESS, --address ADDRESS              Known address
  -p PASSES, --passes PASSES                 Number of passes (default 2)
  -k ACK_TIMEOUT, --ack_timeout ACK_TIMEOUT  ACK timeout in microseconds, accepts [250,4000], step 250
  -r RETRIES, --retries RETRIES              Auto retry limit, accepts [0,15]

映射地址 61:49:66:82:03 所属的星型网络

./nrf24-network-mapper.py -a 61:49:66:82:03

连续音调测试(continuous tone test)

nRF24LU1+ 芯片包含一种用于发射连续音调的测试机制,如果您拥有 SDR,则可以验证其频率。设备之间的频率偏移可能导致意外行为。例如,一块经过测试的 SparkFun 开发板存在约 300kHz 的频率偏移,导致它在两个相邻信道上收到数据包。

此脚本将使收发器在传入的第一个信道上发射音调。

usage: ./nrf24-continuous-tone-test.py [-h] [-c N [N ...]] [-v] [-l]

optional arguments:
  -h, --help                          show this help message and exit
  -c N [N ...], --channels N [N ...]  RF channels
  -v, --verbose                       Enable verbose output
  -l, --lna                           Enable the LNA (for CrazyRadio PA dongles)

在 2405MHz 频率上发射连续音调

./nrf24-continuous-tone-test.py -c 5
下载工具