Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Android-PIN-Bruteforce — 通过暴力破解锁屏PIN来解锁安卓手机(或设备)。将你的Kali Nethunter手机变成安卓设备的暴力PIN破解器!(无需root,无需adb) | Kitploit
工具/GitHubGitHub/urbanadventurer/android-pin-bruteforce
Android安全密码攻击硬件黑客移动安全
GitHuburbanadventurer/android-pin-bruteforce

Android-PIN-Bruteforce

通过暴力破解锁屏PIN来解锁安卓手机(或设备)。将你的Kali Nethunter手机变成安卓设备的暴力PIN破解器!(无需root,无需adb)

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
4.8k8321184年前Kitploit 审核通过

🔓📱 Android-PIN-Bruteforce

通过暴力破解锁屏PIN来解锁安卓手机(或设备)。

将您的Kali NetHunter手机变成安卓设备的PIN暴力破解工具!

📱 工作原理

它使用USB OTG线将锁定的手机连接到NetHunter设备。该设备模拟键盘,自动尝试PIN码,并在多次错误尝试后等待。

连接手机示意图

[NetHunter手机] <--> [USB线] <--> [USB OTG适配器] <--> [锁定的安卓手机]

USB HID Gadget驱动提供USB人机交互设备(HID)的模拟功能。这使得安卓NetHunter设备能够模拟键盘输入到锁定的手机上,就像直接把键盘插到锁定手机上并按键一样。

⏱ 使用三星S5尝试所有可能的4位PIN码大约需要16.6小时,但使用优化过的PIN列表,时间会大大缩短。

您需要准备

  • 一部锁定的安卓手机
  • 一台NetHunter手机(或任何已root且支持HID内核的安卓设备)
  • USB OTG(On The Go)线/适配器(USB Micro-B公头转USB A母头),以及一根标准充电线(USB Micro-B公头转A公头)
  • 仅此而已!

🌟 优点

  • 将您的NetHunter手机变成安卓PIN破解工具
  • 与其他方法不同,您无需在锁定手机上启用ADB或USB调试
  • 锁定的安卓手机无需root
  • 无需购买特殊硬件,例如Rubber Ducky、Teensy、Cellebrite、XPIN Clip等
  • 您可以轻松调整回退时间以破解其他类型的设备
  • 确实有效!

⭐ 功能

  • 破解1到10位任意长度的PIN码
  • 使用配置文件支持不同型号的手机
  • 为3、4、5、6位PIN码提供优化列表
  • 绕过手机弹窗,包括低电量警告
  • 检测手机断开或关机,每5秒重试并等待
  • 每尝试X次PIN后,可配置N秒延迟
  • 日志文件

安装

待定

执行脚本

如果您已将脚本安装到/sdcard/,可以使用以下命令执行。bash ./android-pin-bruteforce

Note that Android mounts /sdcard with the noexec flag. You can verify this with mount.

Usage

Android-PIN-Bruteforce (0.2) 用于通过暴力破解锁屏PIN来解锁Android手机(或设备)。
  更多信息请访问:https://github.com/urbanadventurer/Android-PIN-Bruteforce

命令:
  crack                开始破解PIN码
  resume               从选定的PIN码恢复
  rewind               从选定的PIN码反向破解
  diag                 显示诊断信息
  version              显示版本信息并退出

选项:
  -f, --from PIN       从此PIN码恢复
  -a, --attempts       从NUM次错误尝试开始
  -m, --mask REGEX     使用掩码表示PIN中已知的数字
  -t, --type TYPE      选择PIN或图案破解
  -l, --length NUM     破解NUM长度的PIN码
  -c, --config FILE    指定要加载的配置文件
  -p, --pinlist FILE   指定自定义PIN列表
  -d, --dry-run        用于测试的空运行。不会发送任何按键。
  -v, --verbose        输出详细日志

用法:
  android-pin-bruteforce <command> [options]```


## Supported Android Phones/Devices

This has been successfully tested with various phones including the Samsung S5, S7, Motorola G4 Plus and G5 Plus.

It can unlock Android versions 6.0.1 through to 10.0. The ability to perform a bruteforce attack doesn't depend on the Android version in use. It depends on how the device vendor developed their own lockscreen.

Check the Phone Database for more details
https://github.com/urbanadventurer/Android-PIN-Bruteforce/wiki/Phone-Database

## 🎳 PIN Lists

Optimised PIN lists are used by default unless the user selects a custom PIN list.  

### Cracking PINs of different lengths

Use the `--length` commandline option.

Use this command to crack a 3 digit PIN, 
`./android-pin-bruteforce crack --length 3`

Use this command to crack a 6 digit PIN
`./android-pin-bruteforce crack --length 6`

### Where did the optimised PIN lists come from?

The optimised PIN lists were generated by extracting numeric passwords from database leaks then sorting by frequency. All PINs that did not appear in the password leaks were appended to the list. 

The optimised PIN lists were generated from *Ga$$Pacc DB Leak* (21GB decompressed, 688M Accounts, 243 Databases, 138920 numeric passwords).

#### The 4 digit PIN list

The reason that the 4 digit PIN list is used from a different source is because it gives better results than the generated list from *Ga$$Pacc DB Leak*.

`optimised-pin-length-4.txt` is an optimised list of all possible 4 digit PINs, sorted by order of likelihood.
It can be found with the filename `pinlist.txt` at https://github.com/mandatoryprogrammer/droidbrute

This list is used with permission from Justin Engler & Paul Vines from Senior Security Engineer, iSEC Partners,
and was used in their Defcon talk, [Electromechanical PIN Cracking with Robotic Reconfigurable Button Basher (and C3BO)](https://www.defcon.org/html/defcon-21/dc-21-speakers.html#Engler)

### Cracking with Masks

Masks use regular expressions with the standard grep extended format.

`./android-pin-bruteforce crack --mask "...[45]" --dry-run`

- To try all years from 1900 to 1999, use a mask of `19..`
- To try PINs that have a 1 in the first digit, and a 1 in the last digit, use a mask of `1..1`
- To try PINs that end in 4 or 5, use `...[45]`

## 📱 Configuration for different phones

Device manufacturers create their own lock screens that are different to the default or stock Android. 
To find out what keys your phone needs, plug a keyboard into the phone and try out different combinations.

Load a different configuration file, with the `--config FILE` commandline parameter.

Example:
`./android-pin-bruteforce --config ./config.samsung.s5 crack`

You can also edit the `config` file by customising the timing and keys sent.

The following configuration variables can be used to support a different phone's lockscreen.

计时

DELAY_BETWEEN_KEYS 是每次发送按键后等待的时间(秒)

DELAY_BETWEEN_KEYS=0.25

PROGRESSIVE_COOLDOWN_ARRAY 变量作为多维数组来定制渐进式冷却

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________ 是尝试次数

PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN 是冷却前尝试的次数

PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____ 是冷却时间(秒)

PROGRESSIVE_ARRAY_ATTEMPT_COUNT__________=(1 11 41) PROGRESSIVE_ARRAY_ATTEMPTS_UNTIL_COOLDOWN=(5 1 1) PROGRESSIVE_ARRAY_COOLDOWN_IN_SECONDS____=(30 30 60)

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END 定义在冷却期结束前多少秒将发送按键

设置为0以禁用

SEND_KEYS_DISMISS_POPUPS_N_SECONDS_BEFORE_COOLDOWN_END=5

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END 配置在冷却期结束前发送以解除消息和弹出窗口的按键

SEND_KEYS_DISMISS_POPUPS_AT_COOLDOWN_END="enter enter enter"

KEYS_BEFORE_EACH_PIN 配置发送以提示锁屏出现的按键。该按键在每个密码之前发送。

默认情况下发送"escape enter",但某些手机可能会对其他按键做出响应。

示例:

KEYS_BEFORE_EACH_PIN="ctrl_escape enter"

KEYS_BEFORE_EACH_PIN="escape space"

KEYS_BEFORE_EACH_PIN="escape enter"

KEYS_STAY_AWAKE_DURING_COOLDOWN 在冷却期间发送以保持手机唤醒的按键

KEYS_STAY_AWAKE_DURING_COOLDOWN="enter"

SEND_KEYS_STAY_AWAKE_DURING_COOLDOWN_EVERY_N_SECONDS 按键发送的频率(秒)

SEND_KEYS_STAY_AWAKE_DURING_COOLDOWN_EVERY_N_SECONDS=5

DELAY_BEFORE_STARTING 是暴力破解开始前等待的时间(秒)

DELAY_BEFORE_STARTING=2

KEYS_BEFORE_STARTING 配置在暴力破解开始前发送的按键

KEYS_BEFORE_STARTING="enter"```

Popups

We send keys before the end of the cooldown period, or optionally during the cooldown period. This is to keep the lockscreen app active and to dismiss any popups about the number of incorrect PIN attempts or a low battery warning.

Test sending keys from the NetHunter phone

Test sending keys from the terminal

Use ssh from your laptop to the NetHunter phone, and use this command to test sending keys:

In this example, the enter key is sent.

echo "enter" | /system/xbin/hid-keyboard /dev/hidg0 keyboard

In this example, ctrl-escape is sent.

echo "left-ctrl escape" | /system/xbin/hid-keyboard /dev/hidg0 keyboard

Note: Sending combinations of keys in config file variables is different. Currently only ctrl_escape is supported.

In this example, keys a, b, c are sent.

echo a b c | /system/xbin/hid-keyboard /dev/hidg0 keyboard

Test sending keys from an app

This Android app is a virtual USB Keyboard that you can use to test sending keys.

https://store.nethunter.com/en/packages/remote.hid.keyboard.client/

How to send special keys

Use this list for the following variables:

  • KEYS_BEFORE_EACH_PIN
  • KEYS_STAY_AWAKE_DURING_COOLDOWN
  • KEYS_BEFORE_STARTING

To send special keys use the following labels. This list can be found in the hid_gadget_test source code.

下载工具