NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

radio.nix (2928B)


      1 # modules/features/pentest/radio.nix — everything that is a radio but not wifi:
      2 # software-defined radio, Bluetooth, and RFID/NFC.
      3 # Off by default. `daemon.pentest.radio.enable = true;`
      4 #
      5 # Split from wireless.nix on purpose. That category is a wifi card in monitor
      6 # mode; this one is a dongle on the USB bus — HackRF, RTL-SDR, Ubertooth,
      7 # Proxmark3 — and it pulls in Qt GUIs and a different set of udev rules. If
      8 # you have no SDR hardware, leaving this off saves a large closure.
      9 #
     10 # gnuradio and sdrangel are deliberately NOT here: each is a very large
     11 # closure, and `gqrx` already brings a gnuradio runtime for the common case of
     12 # "look at a spectrum and demodulate it". Add them to this list if you start
     13 # building flowgraphs.
     14 #
     15 # Nearly all of it needs device access. The udev rules come from the packages
     16 # themselves via services.udev.packages below, so an unprivileged user can
     17 # talk to the hardware without sudo.
     18 { lib, ... }:
     19 (import ./_sets.nix { inherit lib; }) {
     20   name = "radio";
     21   description = "SDR, Bluetooth and RFID/NFC: hackrf, rtl-sdr, ubertooth, proxmark3";
     22   default = false;
     23 
     24   packages = pkgs: with pkgs; [
     25     # Software-defined radio
     26     hackrf # hackrf_info, hackrf_sweep, hackrf_transfer
     27     rtl-sdr # rtl_sdr, rtl_fm, rtl_power, rtl_test
     28     rtl_433 # decode the 433/868/915 MHz device zoo
     29     gqrx # spectrum + demodulation, the one you actually open
     30     inspectrum # offline analysis of a capture
     31     urh # Universal Radio Hacker: urh, urh_cli
     32     multimon-ng # POCSAG, FLEX, DTMF and friends
     33 
     34     # Bluetooth
     35     ubertooth # ubertooth-btle, ubertooth-rx, ubertooth-specan
     36     btlejack # BLE connection hijacking
     37     bluez-tools # bt-adapter, bt-device, bt-network, bt-obex
     38     spooftooph # clone a device's address and name
     39 
     40     # RFID / NFC
     41     proxmark3 # `pm3` — the 125 kHz / 13.56 MHz workhorse
     42     libnfc # nfc-list, nfc-poll, nfc-mfclassic, …
     43     mfoc # MIFARE Classic key recovery (nested attack)
     44     mfcuk # the darkside attack, for when mfoc has no known key
     45   ];
     46 
     47   expectedBins = [
     48     "hackrf_info" "hackrf_sweep" "hackrf_transfer"
     49     "rtl_sdr" "rtl_fm" "rtl_power" "rtl_test" "rtl_433"
     50     "gqrx" "inspectrum" "urh" "urh_cli" "multimon-ng"
     51     "ubertooth-btle" "ubertooth-rx" "ubertooth-specan" "ubertooth-util"
     52     "btlejack" "bt-adapter" "bt-device" "spooftooph"
     53     "pm3" "proxmark3" "nfc-list" "nfc-poll" "nfc-mfclassic" "mfoc" "mfcuk"
     54   ];
     55 
     56   extraConfig = { pkgs, lib, ... }: {
     57     # Without these, every one of the above needs root to open its USB device.
     58     # Each package ships the rules for its own hardware.
     59     services.udev.packages = with pkgs; [
     60       hackrf
     61       rtl-sdr
     62       ubertooth
     63       proxmark3
     64       libnfc
     65     ];
     66 
     67     # Bluetooth attacks need the stack up, and bluez's own tools (bluetoothctl,
     68     # hcitool) alongside bluez-tools'. mkDefault: the host may already set this.
     69     hardware.bluetooth.enable = lib.mkDefault true;
     70   };
     71 }