Skip to content
This repository has been archived by the owner on Oct 9, 2023. It is now read-only.

KOLANICH-tools/USBPcapOdinDumper.py

Repository files navigation

USBPcapOdinDumper Unlicensed work

PyPi Status Libraries.io Status Code style: antiflash

We have moved to https://codeberg.org/KOLANICH-tools/USBPcapOdinDumper, grab new versions there.

Under the disguise of "better security" Micro$oft-owned GitHub has discriminated users of 1FA passwords while having commercial interest in success of FIDO 1FA specifications and Windows Hello implementation which it promotes as a replacement for passwords. It will result in dire consequencies and is competely inacceptable, read why.

If you don't want to participate in harming yourself, it is recommended to follow the lead and migrate somewhere away of GitHub and Micro$oft. Here is the list of alternatives and rationales to do it. If they delete the discussion, there are certain well-known places where you can get a copy of it. Read why you should also leave GitHub.


It's a tool to dump ODIN3 messages into files with human-readable names for further reverse-engineering. Both usbmon (the subsystem in Linux kernel) and usbpcap (the app for Windows) captures are supported.

Requirements

  • plumbum TravisCI Build Status - for the fancy CLI.
  • RichConsole TravisCI Build Status - for colors in console. It's mandatory because this shit is used internally to generate file names, so in console the names are colorful.
  • Pipeline TravisCI Build Status - The main app's pipeline.
  • kaitaistruct TravisCI Build Status - runtime for Kaitai Striuct-generated parsers.

How to use

python3 -m USBPcapOdinDumper pcap_file_1.pcap

or

python3 -m USBPcapOdinDumper

to process all the files in the current folder.

It will generate the folders in the current folder for each pcap file.

For each isUseful (see isUseful methods) packet it will generate the file, which name usually have encoded:

  • the packet number in pcap
  • the type of USB transaction (only bulk are useful for us)
  • the direction showed with an arrow
  • some info from enums of odin messages. If enum values are incorrect, an error occurs, info about which enum and which value is incorrect will be added into a file name.

The parser of ODIN3 messages is based on Benjamin Dobell's Heimdall TravisCI Build Status flasher.

Samples of protocol:

Releases

No releases published

Packages

No packages published

Languages