forked from sgxgsx/BlueToolkit
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·268 lines (207 loc) · 21.3 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·268 lines (207 loc) · 21.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
#!/bin/bash
INSTALL_DIR=/usr/share/BlueToolkit
TOOLS_DIR=/usr/share/BlueToolkit/modules/tools
DEV_MODE=false
ALREADY_INSTALLED=false
# If not root, exit
if [ "$EUID" -ne 0 ]; then
echo "Error: This script requires root privileges. Please run with sudo."
exit 1
fi
# Parse command line arguments
while [[ $# -gt 0 ]]; do
case $1 in
-dev)
DEV_MODE=true
shift
;;
*)
shift
;;
esac
done
if [ -d "$INSTALL_DIR" ]; then
if bluekit -h &> /dev/null; then
ALREADY_INSTALLED=true
fi
fi
if [ "$ALREADY_INSTALLED" = false ]; then
echo "Installing BlueToolkit..."
apt-get update
# Core Python and build essentials
apt-get install -y python3 python3-dev python3-pip build-essential python3-venv
# Bluetooth core dependencies
apt-get install -y bluez bluetooth libbluetooth-dev
# PulseAudio Bluetooth module
apt-get install -y pulseaudio-module-bluetooth
# Development, system utilities and Python dependencies
apt-get install -y zstd unzip git rfkill meson patchelf ubertooth adb python3-cairo-dev libcairo2-dev libgirepository1.0-dev libdbus-1-dev bluez-tools xterm
# System libraries
apt-get install -y libncursesw5-dev libssl-dev libsqlite3-dev tk-dev libgdbm-dev libc6-dev libbz2-dev zlib1g-dev libncurses5-dev libnss3-dev libreadline-dev libffi-dev wget
# ARM and Android tools
apt-get install -y binutils-arm-linux-gnueabi openjdk-17-jdk openjdk-17-jre android-sdk-platform-tools
# Configure Bluetooth adapter
killall pulseaudio
-u vagrant pulseaudio --start
systemctl restart bluetooth
# Creating a base directory and assigning to a current user
mkdir /usr/share/BlueToolkit
chown -R $SUDO_USER:$SUDO_USER /usr/share/BlueToolkit
# cloning bluekit
mkdir -p /usr/share/BlueToolkit/.logs
mkdir /usr/share/BlueToolkit/modules
cp -r $PWD/BlueToolkit/exploits /usr/share/BlueToolkit/
cp -r $PWD/BlueToolkit/hardware /usr/share/BlueToolkit/
mkdir $TOOLS_DIR -p
python3 -m venv /usr/share/BlueToolkit/.venv
source /usr/share/BlueToolkit/.venv/bin/activate
python3 -m pip install tabulate colorama pwntools cmd2 pure-python-adb pyelftools==0.29 scapy psutil tqdm pyyaml setuptools #--break-system-packages
# Install pybluez
python3 -m pip install git+https://github.com/pybluez/pybluez.git#egg=pybluez #--break-system-packages
if [ "$DEV_MODE" = true ]; then
# In dev mode we clone bluekit and install it in editable mode
echo "Installing bluekit in development mode..."
git clone https://github.com/sacca97/pybtool.git $PWD/BlueToolkit/pybtool
pip install -e $PWD/BlueToolkit/pybtool
pip install -e $PWD/BlueToolkit/bluekit/ --no-deps
else
# In normal mode we install bluekit from github directly
echo "Installing bluekit..."
pip install $PWD/bluekit/
fi
#### BluetoothAssistant
##### Needs access to the phone, it should be plugged in!!
git clone https://github.com/sgxgsx/BluetoothAssistant /usr/share/BlueToolkit/modules/BluetoothAssistant
chmod +x /usr/share/BlueToolkit/modules/BluetoothAssistant/install.sh
# TODO: check if I can detect the phone already
#### Bdaddr
git clone https://github.com/thxomas/bdaddr /usr/share/BlueToolkit/modules/bdaddr
make -C /usr/share/BlueToolkit/modules/bdaddr
## Installing tools in modules/tools
#### Installing BLUR
# cd $TOOLS_DIR
git clone https://github.com/francozappa/blur $TOOLS_DIR/blur
#### Installing Internalblue, blueborne, bleedingteeth, custom_exploits
git clone --single-branch --branch development https://github.com/sgxgsx/bluetoothexploits $TOOLS_DIR/blueexploits
cp -r $TOOLS_DIR/blueexploits/*/ $TOOLS_DIR/
rm -rf $TOOLS_DIR/blueexploits
gcc -o $TOOLS_DIR/bleedingtooth/poc_badchoice_cve_2020_12352 $TOOLS_DIR/bleedingtooth/poc_badchoice_cve_2020_12352.c -lbluetooth
gcc -o $TOOLS_DIR/bleedingtooth/poc_badkarma_cve_2020_12351 $TOOLS_DIR/bleedingtooth/poc_badkarma_cve_2020_12351.c -lbluetooth
gcc -o $TOOLS_DIR/bleedingtooth/poc_badvibes_cve_2020_24490 $TOOLS_DIR/bleedingtooth/poc_badvibes_cve_2020_24490.c -lbluetooth
gcc -o $TOOLS_DIR/bleedingtooth/exploit $TOOLS_DIR/bleedingtooth/exploit.c -lbluetooth
#### Internal Blue
git clone https://github.com/seemoo-lab/internalblue $TOOLS_DIR/internalblue
cp $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect.py $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_0a_00.py
cp $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect.py $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_16_0b.py
cp $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect.py $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_20_17.py
rm -f $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect.py
sed -i 's/LMP_VSC_CMD_START = 0x0f/LMP_VSC_CMD_START = 0x0a/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_0a_00.py
sed -i 's/LMP_VSC_CMD_END = 0x06/LMP_VSC_CMD_END = 0x00/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_0a_00.py
sed -i 's/LMP_VSC_CMD_START = 0x0f/LMP_VSC_CMD_START = 0x16/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_16_0b.py
sed -i 's/LMP_VSC_CMD_END = 0x06/LMP_VSC_CMD_END = 0x0b/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_16_0b.py
sed -i 's/LMP_VSC_CMD_START = 0x0f/LMP_VSC_CMD_START = 0x20/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_20_17.py
sed -i 's/LMP_VSC_CMD_END = 0x06/LMP_VSC_CMD_END = 0x17/' $TOOLS_DIR/internalblue/examples/nexus5/CVE_2018_19860_Crash_on_Connect_20_17.py
python3 -m pip install https://github.com/seemoo-lab/internalblue/archive/master.zip # --break-system-packages
#### Blueborne
# cd $TOOLS_DIR/blueborne
git clone https://github.com/sgxgsx/blueborne-CVE-2017-1000251 $TOOLS_DIR/blueborne/blueborne-CVE-2017-1000251
# cd $TOOLS_DIR/blueborne/blueborne-CVE-2017-1000251
gcc -o $TOOLS_DIR/blueborne/blueborne-CVE-2017-1000251/blueborne_cve_2017_1000251 $TOOLS_DIR/blueborne/blueborne-CVE-2017-1000251/blueborne.c -lbluetooth
export PYTHONPATH=$PYTHONPATH:$(pwd)/tools/blueborne
# Scapy PATCH (Github - I get a python error during the blueborne scan #12) TODO: check if I can fix this
PYTHON_VERSION=$(find /usr/share/BlueToolkit/.venv/lib/ -maxdepth 1 -type d -name "python3.*" -printf "%f\n" | head -n 1)
FILE_PATH="/usr/share/BlueToolkit/.venv/lib/${PYTHON_VERSION}/site-packages/scapy/layers/bluetooth.py"
## First update ConfReq
#perl -i -p0e 's/class L2CAP_ConfReq.*?fields_desc.*?\n\n/class L2CAP_ConfReq(Packet):\n name = "L2CAP Conf Req"\n fields_desc = [ LEShortField("dcid",0),\n LEShortField("flags",0),\n ByteField("type",0),\n ByteField("length",0),\n ByteField("identifier",0),\n ByteField("servicetype",0),\n LEShortField("sdusize",0),\n LEIntField("sduarrtime",0),\n LEIntField("accesslat",0),\n LEIntField("flushtime",0)]\n\n/s' "$FILE_PATH"
## Then update ConfResp with much more specific boundaries
#perl -i -p0e 's/class L2CAP_ConfResp.*?fields_desc.*?\].*?\]/class L2CAP_ConfResp(Packet):\n name = "L2CAP Conf Resp"\n fields_desc = [ LEShortField("scid",0),\n LEShortField("flags",0),\n LEShortField("result",0),\n ByteField("type0",0),\n ByteField("length0",0),\n LEShortField("option0",0),\n ByteField("type1",0),\n ByteField("length1",0),\n LEShortField("option1",0),\n ByteField("type2",0),\n ByteField("length2",0),\n LEShortField("option2",0),\n ByteField("type3",0),\n ByteField("length3",0),\n LEShortField("option3",0),\n ByteField("type4",0),\n ByteField("length4",0),\n LEShortField("option4",0),\n ByteField("type5",0),\n ByteField("length5",0),\n LEShortField("option5",0),\n ByteField("type6",0),\n ByteField("length6",0),\n LEShortField("option6",0),\n ByteField("type7",0),\n ByteField("length7",0),\n LEShortField("option7",0),\n ByteField("type8",0),\n ByteField("length8",0),\n LEShortField("option8",0),\n ByteField("type9",0),\n ByteField("length9",0),\n LEShortField("option9",0),\n ByteField("type10",0),\n ByteField("length10",0),\n LEShortField("option10",0),\n ByteField("type11",0),\n ByteField("length11",0),\n LEShortField("option11",0),\n ByteField("type12",0),\n ByteField("length12",0),\n LEShortField("option12",0),\n ByteField("type13",0),\n ByteField("length13",0),\n LEShortField("option13",0),\n ByteField("type14",0),\n ByteField("length14",0),\n LEShortField("option14",0),\n ByteField("type15",0),\n ByteField("length15",0),\n LEShortField("option15",0),\n ByteField("type16",0),\n ByteField("length16",0),\n LEShortField("option16",0),\n ByteField("type17",0),\n ByteField("length17",0),\n LEShortField("option17",0),\n ByteField("type18",0),\n ByteField("length18",0),\n LEShortField("option18",0),\n ByteField("type19",0),\n ByteField("length19",0),\n LEShortField("option19",0),\n ByteField("type20",0),\n ByteField("length20",0),\n LEShortField("option20",0),\n ByteField("type21",0),\n ByteField("length21",0),\n LEShortField("option21",0),\n ByteField("type22",0),\n ByteField("length22",0),\n LEShortField("option22",0),\n ByteField("type23",0),\n ByteField("length23",0),\n LEShortField("option23",0),\n ByteField("type24",0),\n ByteField("length24",0),\n LEShortField("option24",0),\n ByteField("type25",0),\n ByteField("length25",0),\n LEShortField("option25",0),\n ByteField("type26",0),\n ByteField("length26",0),\n LEShortField("option26",0),\n ByteField("type27",0),\n ByteField("length27",0),\n LEShortField("option27",0),\n ByteField("type28",0),\n ByteField("length28",0),\n LEShortField("option28",0),\n ByteField("type29",0),\n ByteField("length29",0),\n LEShortField("option29",0),\n ByteField("type30",0),\n ByteField("length30",0),\n LEShortField("option30",0),\n ByteField("type31",0),\n ByteField("length31",0),\n LEShortField("option31",0),\n ByteField("type32",0),\n ByteField("length32",0),\n LEShortField("option32",0),\n ByteField("type33",0),\n ByteField("length33",0),\n LEShortField("option33",0),\n ByteField("type34",0),\n ByteField("length34",0),\n LEShortField("option34",0),\n ByteField("type35",0),\n ByteField("length35",0),\n LEShortField("option35",0),\n ByteField("type36",0),\n ByteField("length36",0),\n LEShortField("option36",0),\n ByteField("type37",0),\n ByteField("length37",0),\n LEShortField("option37",0),\n ByteField("type38",0),\n ByteField("length38",0),\n LEShortField("option38",0),\n ByteField("type39",0),\n ByteField("length39",0),\n LEShortField("option39",0),\n ByteField("type40",0),\n ByteField("length40",0),\n LEShortField("option40",0),\n ByteField("type41",0),\n ByteField("length41",0),\n LEShortField("option41",0),\n ByteField("type42",0),\n ByteField("length42",0),\n LEShortField("option42",0),\n ByteField("type43",0),\n ByteField("length43",0),\n LEShortField("option43",0),\n ByteField("type44",0),\n ByteField("length44",0),\n LEShortField("option44",0),\n ByteField("type45",0),\n ByteField("length45",0),\n LEShortField("option45",0),\n ByteField("type46",0),\n ByteField("length46",0),\n LEShortField("option46",0),\n ByteField("type47",0),\n ByteField("length47",0),\n LEShortField("option47",0),\n ByteField("type48",0),\n ByteField("length48",0),\n LEShortField("option48",0),\n ByteField("type49",0),\n ByteField("length49",0),\n LEShortField("option49",0),\n ByteField("type50",0),\n ByteField("length50",0),\n LEShortField("option50",0),\n ByteField("type51",0),\n ByteField("length51",0),\n LEShortField("option51",0),\n ByteField("type52",0),\n ByteField("length52",0),\n LEShortField("option52",0),\n ByteField("type53",0),\n ByteField("length53",0),\n LEShortField("option53",0),\n ByteField("type54",0),\n ByteField("length54",0),\n LEShortField("option54",0),\n ByteField("type55",0),\n ByteField("length55",0),\n LEShortField("option55",0),\n ByteField("type56",0),\n ByteField("length56",0),\n LEShortField("option56",0),\n ByteField("type57",0),\n ByteField("length57",0),\n LEShortField("option57",0),\n ByteField("type58",0),\n ByteField("length58",0),\n LEShortField("option58",0),\n ByteField("type59",0),\n ByteField("length59",0),\n LEShortField("option59",0),\n ByteField("type60",0),\n ByteField("length60",0),\n LEShortField("option60",0),\n ByteField("type61",0),\n ByteField("length61",0),\n LEShortField("option61",0),\n ByteField("type62",0),\n ByteField("length62",0),\n LEShortField("option62",0),\n ByteField("type63",0),\n ByteField("length63",0),\n LEShortField("option63",0),\n ByteField("type64",0),\n ByteField("length64",0),\n LEShortField("option64",0),\n ByteField("type65",0),\n ByteField("length65",0),\n LEShortField("option65",0),\n ByteField("type66",0),\n ByteField("length66",0),\n LEShortField("option66",0),\n ByteField("type67",0),\n ByteField("length67",0),\n LEShortField("option67",0),\n ByteField("type68",0),\n ByteField("length68",0),\n LEShortField("option68",0),\n ByteField("type69",0),\n ByteField("length69",0),\n LEShortField("option69",0)]\n/s' "$FILE_PATH"
# create wrapper script (just copy it)
tee /usr/local/bin/bluekit > /dev/null << 'EOF'
#!/bin/bash
VENV_PATH="/usr/share/BlueToolkit/.venv"
# Check if the virtual environment exists
if [ ! -d "$VENV_PATH" ]; then
echo "Virtual environment not found at $VENV_PATH"
exit 1
fi
# Activate virtual environment
source "$VENV_PATH/bin/activate"
# Call bluekit with all passed arguments
exec bluekit "$@"
EOF
chmod +x /usr/local/bin/bluekit
else
read -p "BlueToolkit is already installed. Do you want to install additional components? (yes/no) [no]: " user_response
user_response=$(echo "$user_response" | tr '[:upper:]' '[:lower:]') # Convert to lowercase
if [ "$user_response" = "n" ] || [ "$user_response" = "no" ] || [ "$user_response" = "" ]; then
echo "Skipping additional components installation."
exit 0
fi
fi
# Optional installation of Bluetooth Assistant
while true; do
read -p "Do you want to install the Bluetooth Assistant apk? It requires a connected android phone with usb debug. (yes/no) [no]: " user_response
user_response=$(echo "$user_response" | tr '[:upper:]' '[:lower:]') # Convert to lowercase
case "$user_response" in
y|yes)
echo "Installing Bluetooth Assistant..."
# should call adb to install an apk on the Nexus 5 phone or another one
/usr/share/BlueToolkit/modules/BluetoothAssistant/install.sh
echo "Done."
break
;;
n|no|"") # Default to 'no' if user says no or presses Enter
echo "Skipping installation of Bluetooth Assistant."
break # Exit the loop
;;
*)
echo "Invalid input. Please enter 'yes', 'no', or just press Enter for 'no'."
;;
esac
done
# Optional braktooth installation
while true; do
read -p "Do you want to install Braktooth? It requires the ESP32 board to be connected. (yes/no) [no]: " user_response
user_response=$(echo "$user_response" | tr '[:upper:]' '[:lower:]') # Convert to lowercase
case "$user_response" in
y|yes)
echo "Installing Braktooth"
# Requirements
# apt-get install libpulse0 qtbase5-dev qtchooser qt5-qmake qtbase5-dev-tools libc-ares-dev
wget -O /tmp/libssl1.1_1.1.1f-1ubuntu2_amd64.deb https://archive.ubuntu.com/ubuntu/pool/main/o/openssl/libssl1.1_1.1.1f-1ubuntu2_amd64.deb
sudo dpkg -i /tmp/libssl1.1_1.1.1f-1ubuntu2_amd64.deb
rm -f /tmp/libssl1.1_1.1.1f-1ubuntu2_amd64.deb
apt-get install -y libgflags-dev libgoogle-glog-dev liblua5.2-dev
#### Installing braktooth
mkdir -p $TOOLS_DIR/braktooth
# We use release 1.0.1 for the tool since 1.2.0 does not completely work in 22.04
wget -O $TOOLS_DIR/release.zip https://github.com/Matheus-Garbelini/braktooth_esp32_bluetooth_classic_attacks/releases/download/v1.0.1/release.zip
unzip -q $TOOLS_DIR/release.zip -d $TOOLS_DIR/braktooth
rm -f $TOOLS_DIR/release.zip $TOOLS_DIR/braktooth/esp32driver.zip
# We use 1.2.0 for the ESP32 Firmware as 1.0.1 does not work in 22.04
wget -O $TOOLS_DIR/braktooth/esp32driver.zip https://github.com/Matheus-Garbelini/braktooth_esp32_bluetooth_classic_attacks/releases/download/v1.2.0/esp32driver.zip
# wget -O $TOOLS_DIR/braktooth/wdissector.tar.zst https://github.com/Matheus-Garbelini/braktooth_esp32_bluetooth_classic_attacks/releases/download/v1.2.0/wdissector_x86_64.tar.zst
unzip -q $TOOLS_DIR/braktooth/esp32driver.zip -d $TOOLS_DIR/braktooth
rm -f $TOOLS_DIR/braktooth/esp32driver.zip
#### Cannot install it as there might be no Braktooth connected to the machine
# ESP firmware
# python3 $TOOLS_DIR/braktooth/release/firmware.py flash /dev/ttyUSB1
tar -I zstd -xf $TOOLS_DIR/braktooth/wdissector.tar.zst -C $TOOLS_DIR/braktooth/
rm -f $TOOLS_DIR/braktooth/wdissector.tar.zst
sed -i 's/qt5-default//g' $TOOLS_DIR/braktooth/wdissector/requirements.sh
chmod +x $TOOLS_DIR/braktooth/wdissector/requirements.sh
$TOOLS_DIR/braktooth/wdissector/requirements.sh
echo "Done."
break
;;
n|no|"") # Default to 'no' if user says no or presses Enter
echo "Skipping installation of Braktooth."
break # Exit the loop
;;
*)
echo "Invalid input. Please enter 'yes', 'no', or just press Enter for 'no'."
;;
esac
done
# Enforce user permissions for all files
chown -R $SUDO_USER:$SUDO_USER /usr/share/BlueToolkit