radio.nix (2928B)
1 # modules/features/pentest/radio.nix — everything that is a radio but not wifi: 2 # software-defined radio, Bluetooth, and RFID/NFC. 3 # Off by default. `daemon.pentest.radio.enable = true;` 4 # 5 # Split from wireless.nix on purpose. That category is a wifi card in monitor 6 # mode; this one is a dongle on the USB bus — HackRF, RTL-SDR, Ubertooth, 7 # Proxmark3 — and it pulls in Qt GUIs and a different set of udev rules. If 8 # you have no SDR hardware, leaving this off saves a large closure. 9 # 10 # gnuradio and sdrangel are deliberately NOT here: each is a very large 11 # closure, and `gqrx` already brings a gnuradio runtime for the common case of 12 # "look at a spectrum and demodulate it". Add them to this list if you start 13 # building flowgraphs. 14 # 15 # Nearly all of it needs device access. The udev rules come from the packages 16 # themselves via services.udev.packages below, so an unprivileged user can 17 # talk to the hardware without sudo. 18 { lib, ... }: 19 (import ./_sets.nix { inherit lib; }) { 20 name = "radio"; 21 description = "SDR, Bluetooth and RFID/NFC: hackrf, rtl-sdr, ubertooth, proxmark3"; 22 default = false; 23 24 packages = pkgs: with pkgs; [ 25 # Software-defined radio 26 hackrf # hackrf_info, hackrf_sweep, hackrf_transfer 27 rtl-sdr # rtl_sdr, rtl_fm, rtl_power, rtl_test 28 rtl_433 # decode the 433/868/915 MHz device zoo 29 gqrx # spectrum + demodulation, the one you actually open 30 inspectrum # offline analysis of a capture 31 urh # Universal Radio Hacker: urh, urh_cli 32 multimon-ng # POCSAG, FLEX, DTMF and friends 33 34 # Bluetooth 35 ubertooth # ubertooth-btle, ubertooth-rx, ubertooth-specan 36 btlejack # BLE connection hijacking 37 bluez-tools # bt-adapter, bt-device, bt-network, bt-obex 38 spooftooph # clone a device's address and name 39 40 # RFID / NFC 41 proxmark3 # `pm3` — the 125 kHz / 13.56 MHz workhorse 42 libnfc # nfc-list, nfc-poll, nfc-mfclassic, … 43 mfoc # MIFARE Classic key recovery (nested attack) 44 mfcuk # the darkside attack, for when mfoc has no known key 45 ]; 46 47 expectedBins = [ 48 "hackrf_info" "hackrf_sweep" "hackrf_transfer" 49 "rtl_sdr" "rtl_fm" "rtl_power" "rtl_test" "rtl_433" 50 "gqrx" "inspectrum" "urh" "urh_cli" "multimon-ng" 51 "ubertooth-btle" "ubertooth-rx" "ubertooth-specan" "ubertooth-util" 52 "btlejack" "bt-adapter" "bt-device" "spooftooph" 53 "pm3" "proxmark3" "nfc-list" "nfc-poll" "nfc-mfclassic" "mfoc" "mfcuk" 54 ]; 55 56 extraConfig = { pkgs, lib, ... }: { 57 # Without these, every one of the above needs root to open its USB device. 58 # Each package ships the rules for its own hardware. 59 services.udev.packages = with pkgs; [ 60 hackrf 61 rtl-sdr 62 ubertooth 63 proxmark3 64 libnfc 65 ]; 66 67 # Bluetooth attacks need the stack up, and bluez's own tools (bluetoothctl, 68 # hcitool) alongside bluez-tools'. mkDefault: the host may already set this. 69 hardware.bluetooth.enable = lib.mkDefault true; 70 }; 71 }