{"id":71937,"date":"2020-02-29T08:54:27","date_gmt":"2020-02-29T05:54:27","guid":{"rendered":"https:\/\/prohoster.info\/blog\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera"},"modified":"2020-03-03T16:14:07","modified_gmt":"2020-03-03T13:14:07","slug":"flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera","title":{"rendered":"Flipper Zero is a cool multi-tool for penetration testers.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/84384ab16070886008e38b07affee292.png\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/flipperzero.one\">Flipper Zero<\/a><\/noindex> \u2014 a pocket multitool project based on the Raspberry Pi Zero for IoT pentesting and wireless access control systems. And it's also a Tamagotchi, home to a cyber dolphin. It will be able to:<\/p>\n<ul>\n<li><b>Work in the 433 MHz range<\/b> \u2014 to investigate remote controls, sensors, electronic locks, and relays.<\/li>\n<li><b>NFC<\/b> \u2014 read\/write and emulate ISO-14443 cards.<\/li>\n<li><b>125 kHz RFID<\/b> \u2014 read\/write and emulate low-frequency cards.<\/li>\n<li><b>iButton keys<\/b> \u2014 read\/write and emulate contact keys working on the 1-Wire protocol.<\/li>\n<li><b>Wi-Fi<\/b> \u2014 to check the security of wireless networks. The adapter supports packet injection and monitor mode.<\/li>\n<li><b>Bluetooth<\/b> \u2014 supported by the bluez package for Linux<\/li>\n<li><b>Bad USB Mode<\/b> \u2014 can connect as a USB slave and emulate a keyboard, Ethernet adapter, and other devices for code injection or network pentesting.<\/li>\n<li><b>Tamagotchi!<\/b> \u2014 a low-power microcontroller operates when the main system is turned off. <\/li>\n<\/ul>\n<p> I'm excited to introduce my most ambitious project, an idea I've been nurturing for many years. This is an attempt to combine all the often-needed tools for physical pentesting into one device, while giving it a personality to make it adorably cute. Currently, the project is in the R&amp;D phase and functionality approval stage, and I'm inviting everyone to participate in discussing features or even take part in the development. Below is a detailed description of the project.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Why is this needed?<\/h2>\n<p>I love to explore everything around me and constantly carry various tools for this. In my backpack, I have: a WiFi adapter, an NFC reader, SDR, Proxmark3, HydraNFC, Raspberry Pi Zero (this sometimes causes problems at the airport). It's not always easy to use all these devices on the go when you have a coffee cup in one hand or you're riding a bike. You need to sit down, unpack, get the computer out \u2014 it's not always convenient. I dreamed of a device that would implement typical attack scenarios, always at the ready and not just a bunch of falling apart boards taped together.<img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/eb1ffc753c79587314d09a78e3a8d7fe.png\" style=\"display:block;margin: 0 auto;\" \/> Raspberry Pi Zero W with a UPS-Lite v1.0 battery shield as a standalone fluder for sending images to Apple devices via AirDrop. Recently, after the open implementation of the AirDrop protocol was published <noindex><a rel=\"nofollow\" href=\"http:\/\/owlink.org\/\">owlink.org<\/a><\/noindex> and research from the guys at HexWay on iOS vulnerabilities <noindex><a rel=\"nofollow\" href=\"https:\/\/hexway.io\/blog\/apple-bleee\/\">Apple-Bleee<\/a><\/noindex>, I started entertaining myself in a new way: meeting people in the subway, sending them pictures via AirDrop, and collecting their phone numbers. Then I wanted to automate this process and created a standalone dick-pic machine from a Raspberry Pi Zero W and a battery. This topic deserves a separate article that I can't seem to finish. Everything was fine, but this device was extremely inconvenient to carry around; it couldn't fit in my pocket because the sharp solder drops tore the fabric of my pants. I tried printing a case on a 3D printer, but I wasn't happy with the result.  <\/p>\n<blockquote><p> A special thanks to Anna <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/users\/koteeq\/\" class=\"user_link\">koteeq<\/a><\/noindex> to the host of the Telegram channel <noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/theyforcedme\">@theyforcedme<\/a><\/noindex> who, at my request, wrote a Telegram bot <noindex><a rel=\"nofollow\" href=\"https:\/\/vee.gg\/t\/airtrollbot\">@AirTrollBot<\/a><\/noindex>, which generates images with text, Telegram usernames, and the correct aspect ratio so that they are fully displayed in the preview when sent via AirDrop. You can quickly generate a picture suitable for the situation; it looks <noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/bc\/ss\/2v\/bcss2v52pngof8z3dgex5rnz5q4.png\">about like this<\/a><\/noindex>.<\/p><\/blockquote>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/4b112ef25e471cded4ab6724952e8fcf.png\" style=\"display:block;margin: 0 auto;\" \/>Pwnagotchi assembled with an e-ink screen and a battery shield. Then I saw an amazing project <noindex><a rel=\"nofollow\" href=\"https:\/\/pwnagotchi.ai\">pwnagotchi<\/a><\/noindex>. It's like a Tamagotchi, but instead of food, it eats WPA handshakes and PMKIDs from Wi-Fi networks, which can then be brute-forced on GPU farms. I liked this project so much that I spent several days walking the streets with my pwnagotchi, watching as it delighted in its new catch. But it had all the same problems: it couldn't be properly placed in a pocket, there were no controls, so any user input was only possible from a phone or computer. And then I finally understood how I envision the perfect multitool that I lacked. I tweeted about it <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/zhovner\/status\/1185138217189826561\">on Twitter<\/a><\/noindex> and the idea resonated with my friends who are industrial designers, who create serious electronic gadgets. They suggested making a full-fledged device instead of a DIY knee project, with real factory production and precisely fitted parts. We began searching for a design concept. <noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/87\/vl\/mj\/87vlmjdqynqm6vrrhlykn6hmezu.jpeg\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/42dcafa5308eda4408915a0ebcc2883b.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/ey\/hj\/y9\/eyhjy9j1zo_y7ah9465ecc_6fkg.jpeg\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/8c17494a3df887d43b8d42cec635b1c8.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/hl\/w3\/mi\/hlw3mioanytxwil7np29zjrfko8.jpeg\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/8b64bda82c35bc5e8f211e86d121f4fb.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/5s\/ys\/5z\/5sys5zwccpoxd0pkyyul1v268oq.jpeg\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/a4030486889bf5c7b351d1e41b59c67d.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex>Clickable. The initial sketches of the Flipper Zero design. A lot of time was devoted to the case and design because I was tired of all hacker devices looking like a pile of PCBs taped together and being unusable. The task was to come up with the most convenient and compact case and device that would be easy to use autonomously without a computer or phone, and here is what came of it. The current design is described further. <b>not final <\/b>concept of the device.<\/p>\n<h2>What is Flipper Zero<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/ada4dfa7b8051ebe3b02a4c3fae43c43.png\" style=\"display:block;margin: 0 auto;\" \/>Essentially, Flipper Zero is several shields and a battery around a Raspberry Pi Zero, packaged in a case with a screen and buttons. Kali Linux is used as the operating system since it already contains all the necessary patches and natively supports rpi0. I looked at many different single-board computers: NanoPi Duo2, Banana Pi M2 Zero, Orange Pi Zero, Omega2, but they all fall short compared to rpi0, and here\u2019s why:<\/p>\n<ul>\n<li>Built-in Wi-Fi adapter supporting monitor mode and packet injection (<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/seemoo-lab\/nexmon\">nexmon<\/a><\/noindex> patches)<\/li>\n<li>Built-in Bluetooth 4.0<\/li>\n<li>Quite a good <noindex><a rel=\"nofollow\" href=\"https:\/\/magpi.raspberrypi.org\/articles\/pi-zero-w-wireless-antenna-design\">2.4 GHz antenna<\/a><\/noindex><\/li>\n<li>Officially supported by Kali Linux and has many ready-made builds like <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/mame82\/P4wnP1_aloa\">P4wnP1 A.L.O.A.<\/a><\/noindex><\/li>\n<li>Easy access to the SD card, allowing for quick transfer of large amounts of data<\/li>\n<\/ul>\n<p>Surely many will say that Raspberry Pi is not the best choice for such a device and will find numerous arguments, such as high power consumption, lack of sleep mode, closed hardware, etc. But when comparing all the drawbacks and advantages, I found nothing better than rpi0. If you have something to say about this, welcome to the developer forum <noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\">forum.flipperzero.one<\/a><\/noindex>.<img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/c3aa9d44248ea5ece2d2952286bbe328.png\" style=\"display:block;margin: 0 auto;\" \/>Flipper Zero is completely standalone and can be operated using a 5-position joystick without additional devices, such as a computer or phone. You can invoke standard attack scenarios from the menu. Naturally, not everything can be done with the joystick, so for greater control, you can connect via SSH through USB or Wi-Fi\/Bluetooth. I decided to use an old-school monochrome LCD display with a resolution of 126x64px like those on old Siemens phones. Firstly, it's just cool; the monochrome screen with orange backlighting gives me indescribable delight \u2014 a kind of retro-military-cyberpunk vibe. It's easily visible in bright sunlight, and it has very low power consumption, around 400uA with the backlight off. Therefore, it can be kept in Always-On mode, always displaying an image. The backlight will only turn on when a button is pressed.<img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/f92e0dfabdc27608d03b6dcb7d29fb29.png\" style=\"display:block;margin: 0 auto;\" \/>Examples of screens on Siemens phones. Such screens are still produced for various industrial devices and cash registers. Currently, we have chosen <noindex><a rel=\"nofollow\" href=\"https:\/\/www.buydisplay.com\/default\/1-4-inch-graphic-128x64-lcd-module-serial-spi-st7565-black-on-white\">this screen<\/a><\/noindex>. <img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/2e201b6b863382e67bd7f6505324b2fc.png\" style=\"display:block;margin: 0 auto;\" \/>Ports of Flipper Zero. The edges of Flipper Zero have standard Raspberry Pi ports, a power\/backlight button, a strap hole, and an additional service port through which you can access the UART console, charge the battery, and upload new firmware.<\/p>\n<h2>433 MHz Transmitter<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/7ed18e44c47fe332e388c9fb2765e2f3.png\" style=\"display:block;margin: 0 auto;\" \/><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/7e1486897bf01d52b57648c16a7695a6.png\" style=\"display:block;margin: 0 auto;\" \/> Flipper has a built-in antenna operating at 433 MHz and the chip <noindex><a rel=\"nofollow\" href=\"http:\/\/www.ti.com\/product\/CC1110-CC1111\">CC1111<\/a><\/noindex>, designed for operation in the &lt;1GHz range, the same as in the popular device <noindex><a rel=\"nofollow\" href=\"https:\/\/greatscottgadgets.com\/yardstickone\/\">Yard Stick One<\/a><\/noindex>. It can intercept and analyze signals from remote controls, key fobs, various smart plugs, and locks. It supports operation with the library <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/atlas0fd00m\/rfcat\">rfcat<\/a><\/noindex> and can decode, store, and reproduce popular remote codes, similar to <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/watch?v=BxfTk0PIs2Y\">remote control analyzers<\/a><\/noindex>. In cases where the Raspberry Pi cannot process the signal on time, the built-in microcontroller can control the CC1111's operation. In tamagotchi mode, Flipper can communicate with similar devices and display their names, just like pwagnotchi.<\/p>\n<h2>Bad USB<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/24a11dce36052aaf0c71afa72bad836f.png\" style=\"display:block;margin: 0 auto;\" \/>Flipper can emulate USB-slave devices and pretend to be a keyboard for payload upload, similar to <noindex><a rel=\"nofollow\" href=\"https:\/\/shop.hak5.org\/products\/usb-rubber-ducky-deluxe\">USB Rubber Ducky<\/a><\/noindex>. It can also emulate an Ethernet adapter for DNS spoofing, serial port, etc. For Raspberry Pi, there is a ready-made framework implementing various types of such attacks <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/mame82\/P4wnP1_aloa\">github.com\/mame82\/P4wnP1_aloa<\/a><\/noindex>The desired attack scenario can be selected from the menu using the joystick. While doing so, debugging information about the attack status or something harmless for camouflage may be displayed on the screen.<\/p>\n<h2>WiFi<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/744e33b9f65038c741d9653593f7a7ba.png\" style=\"display:block;margin: 0 auto;\" \/>The built-in Wi-Fi adapter in Raspberry Pi does not initially support monitor mode for packet injection, but there are <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/seemoo-lab\/nexmon\">third-party patches<\/a><\/noindex>, which add this feature. For certain types of attacks, two independent Wi-Fi adapters are needed. The challenge lies in the fact that almost all Wi-Fi chips are connected via USB, and we cannot occupy the only USB on rpi0, otherwise, the USB Slave mode will break. Therefore, it is necessary to use the SPI or SDIO interface to connect the Wi-Fi adapter. I am not aware of any chip that supports monitor mode and packet injection out of the box, while not being connected via USB. If you know of one, please let me know on the forum in the thread <noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\/t\/wi-fi-chip-with-spi-sdio-interface-that-supports-monitoring-and-packet-injection\/42\">Wi-Fi chip with SPI\/SDIO interface that supports monitoring and packet injection<\/a><\/noindex><\/p>\n<h2>NFC<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/b3705b12374e1b5d30ced4f5a56208bb.png\" style=\"display:block;margin: 0 auto;\" \/>The NFC module can read\/write all ISO-14443 cards, including Mifare, contactless bank cards like PayPass\/PayWave, ApplePay\/GooglePay, and more. It is supported by the LibNFC library. At the bottom of the Flipper is a 13.56 MHz antenna, and to work with the card, it is enough to place it on top. The issue of card emulation remains open for now. I would like a full-fledged emulator like <noindex><a rel=\"nofollow\" href=\"https:\/\/lab401.com\/products\/chameleon-mini-reve-rebooted\">Chameleon Mini <\/a><\/noindex>, but at the same time I want to be able to work with LibNFC. I don't know of any chip options besides the NXP PN532, but it cannot fully emulate cards. If you know of a better option, please write about it in the thread <noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\/t\/looking-for-better-nfc-chip-than-pn532\/43\">Looking for better NFC chip than PN532<\/a><\/noindex> <\/p>\n<h2>125kHz RFID<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/7c8eade3ac215b35b7c352d81221bc60.png\" style=\"display:block;margin: 0 auto;\" \/>Old low-frequency 125 kHz cards are still widely used in intercoms, office access cards, etc. There is a 125 kHz antenna on the side of the Flipper; it can read EM-4100 and HID Prox cards, store them in memory, and emulate previously saved cards. You can also transmit the card ID for emulation over the internet or enter it manually. This way, Flipper owners can share read cards remotely. Nice.<\/p>\n<h2>iButton<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/eb8f5d5630487f2e87e4150fb3f42681.png\" style=\"display:block;margin: 0 auto;\" \/>The iButton is an old type of contact key that remains popular in the CIS. It operates using the 1-Wire protocol and has no authentication mechanisms, making it easy to read. The Flipper can read these keys, store the ID in memory, write the ID to blanks, and emulate the key itself so it can be placed next to the reader like a key. <b>Reader mode (1-wire master)<\/b><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/31043c2c20380efadde04bfb2fb4bfaf.png\" style=\"display:block;margin: 0 auto;\" \/> In this mode, the device acts as a door reader. When the key is placed against the contacts, the Flipper reads its ID and saves it in memory. In this same mode, the saved ID can be written to a blank.<b>Key emulation mode (1-wire slave)<\/b><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/c9351346b20f2ccac741e4cb03bf9a4e.png\" style=\"display:block;margin: 0 auto;\" \/>Saved keys can be emulated in 1-wire slave mode. The Flipper acts as the key and can be placed next to the reader. The main challenge was creating a contact pad design that could function both as a reader and as a key. We found a form that works, but I believe it can be improved, and if you have suggestions, please share your ideas on the forum in the thread. <noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\/t\/ibutton-contact-pad-design\/26\">iButton contact pad design<\/a><\/noindex><\/p>\n<h2>Bluetooth<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/57a4dcda298a101e9ef9845df385e5e9.png\" style=\"display:block;margin: 0 auto;\" \/>Built-in Bluetooth adapter for Raspberry Pi. While it cannot replace devices like <noindex><a rel=\"nofollow\" href=\"https:\/\/greatscottgadgets.com\/ubertoothone\/\">ubertooth one<\/a><\/noindex>, it is fully supported by the bluez library, can be used to control the Flipper from a smartphone, or for various Bluetooth attacks such as <noindex><a rel=\"nofollow\" href=\"https:\/\/hexway.io\/blog\/apple-bleee\/\">apple-bleee<\/a><\/noindex>, which allows gathering SHA256 hashes of mobile phone numbers linked to Apple ID, as well as controlling various IoT devices.<\/p>\n<h2>Low-power microcontroller<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/b37513eed8c2605635e75f2873ce1fec.png\" style=\"display:block;margin: 0 auto;\" \/> Since the Flipper is too cool to turn off, we decided to include a separate low-power microcontroller that will operate when the Raspberry Pi is turned off. It will manage the Tamagotchi, control the Raspberry Pi's boot process until it is ready to manage the screen, and control power. It will also manage the CC1111 chip for communication with other Flippers. <\/p>\n<h2>Tamagotchi mode<\/h2>\n<p><video controls style=\"top: 0; left: 0; width: 100%; height: 100%; position: absolute;\">Your browser does not support HTML5 video.<source src=\"https:\/\/zhovner.com\/forever\/flipper_zero_tamagotchi.mp4\" type=\"video\/mp4\"><\/source><\/video>The Flipper is a cyber-dolphin hacker capable of mastering all digital elements. When the Raspberry Pi is turned off, it enters Tamagotchi mode, where you can play and find friends on a frequency of 433 MHz. In this mode, NFC functions may be partially available.<img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/bad277dac473fd69614fe8ca67e53a11.png\" style=\"display:block;margin: 0 auto;\" \/> The character is based on the dolphin from the movie <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kinopoisk.ru\/film\/3800\/\">Johnny Mnemonic<\/a><\/noindex> which helped peak into Keanu Reeves' mind and blew away the bad guys with its emission. Dolphins have a built-in frequency generator that they use to explore everything around them, as well as an innate need for entertainment and natural curiosity. We need a person who can come up with a flipper's personality, the entire game design from emotions to mini-games. All your thoughts on this matter can be written <noindex><a rel=\"nofollow\" href=\"http:\/\/forum.flipperzero.one\">forum<\/a><\/noindex> in the relevant section.<\/p>\n<h2>About me<\/h2>\n<p><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/ba40b307a99897ad3c5643045b3dedae.png\" style=\"display:block;margin: 0 auto;\" \/>My name is Pavel Zhivner, I live in Moscow. Currently, I run the Moscow <noindex><a rel=\"nofollow\" href=\"https:\/\/neuronspace.ru\">Hackspace Neuron<\/a><\/noindex>. Since childhood, I have loved to deeply explore everything around: nature, technology, people. My main specialization is networks, hardware, and security. I try never to use the word \"hacker\" because it has been completely devalued by the media. I prefer to call myself a \"geek\" because it honestly and without pretension reveals the essence. In life, I value passionate people who are deeply emotionally involved in what interests them, who can also confidently be called geeks. Flipper Zero is my attempt to create something truly cool and large-scale, yet beautiful. I believe in open source, so the project will be fully open. At the moment, I have a small team, but we lack people competent in narrow fields, especially in radio. With this post, I hope to find people who want to join the project.<\/p>\n<h2>Join the project<\/h2>\n<p>I invite everyone who liked this project to participate in the development in any available way. At this stage, we need to finalize the feature list to start implementing the first version of the device. There are many technical questions that are currently unresolved. <\/p>\n<h3>For developers<\/h3>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/ebd3f9940ad5dd003c431887fa043863.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex> We will discuss all our current R&amp;D tasks on the forum <noindex><a rel=\"nofollow\" href=\"https:\/\/forum.flipperzero.one\/\">forum.flipperzero.one<\/a><\/noindex>. If you are a hardware or software developer, or if you have any questions, advice, suggestions, or criticism \u2014 feel free to post them on the forum. This is the main place where discussions of all stages of development, crowdfunding, and production will take place. Communication on the forum is conducted <b>only in English<\/b>, don't hesitate to write awkwardly, the main thing is that the meaning is clear.<\/p>\n<h3>Vote for features<\/h3>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/forms.gle\/1odkj5PvNcWANiwz5\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/56c9771018bd02574074cbfd8a9cb36d.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex>It is very important for us to know which features should be included in the flipper. This will determine the development priorities. I may mistakenly think some features are important, or conversely, miss something. For example, I have doubts about the iButton, as it is outdated technology. Therefore, please take a short survey: <noindex><a rel=\"nofollow\" href=\"https:\/\/forms.gle\/7VWhgJRBmtS9BQtR9\">docs.google.com\/7VWhgJRBmtS9BQtR9<\/a><\/noindex><\/p>\n<h3>Send money<\/h3>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/flipperzero.one\/donate\"><img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/574baa7dcda83283f69033c4f1df3f5e.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex> When the prototype is finished and the project is ready to launch on crowdfunding platforms like Kickstarter, you can place a preorder. At the moment, you can support me personally with small donations for food through <noindex><a rel=\"nofollow\" href=\"https:\/\/patreon.com\/join\/zhovner\">Patreon<\/a><\/noindex>. Regular donations of $1 are much better than a large sum at once, as they allow for better forecasting. Donation link: <noindex><a rel=\"nofollow\" href=\"https:\/\/flipperzero.one\/donate\">flipperzero.one\/donate<\/a><\/noindex><\/p>\n<h2>Disclaimer<\/h2>\n<p>The project is at a very early stage; the site may have errors, a flawed layout, and other issues, so please don't be too harsh. Please report any mistakes and inaccuracies you find. This is the first public mention of the project, and with your help, I hope to iron out all the rough edges before publishing it to the broader English-speaking internet. <img decoding=\"async\" alt=\"Flipper Zero is a cool multi-tool for penetration testers.\" src=\"\/wp-content\/uploads\/2020\/02\/482f9c1d06bbb0c8594a5a4d9615ecfb.png\" style=\"display:block;margin: 0 auto;\" \/> I publish all project notes in my Telegram channel <noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/zhovner_hub\">@zhovner_hub<\/a><\/noindex>.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/477440\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>Flipper Zero \u2014 \u043f\u0440\u043e\u0435\u043a\u0442 \u043a\u0430\u0440\u043c\u0430\u043d\u043d\u043e\u0433\u043e \u043c\u0443\u043b\u044c\u0442\u0438\u0442\u0443\u043b\u0430 \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Raspberry Pi Zero \u0434\u043b\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u0430 IoT \u0438 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430. \u0410 \u0435\u0449\u0435 \u044d\u0442\u043e \u0442\u0430\u043c\u0430\u0433\u043e\u0447\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u0436\u0438\u0432\u0435\u0442 \u043a\u0438\u0431\u0435\u0440-\u0434\u0435\u043b\u044c\u0444\u0438\u043d.\u041e\u043d \u0431\u0443\u0434\u0435\u0442 \u0443\u043c\u0435\u0442\u044c: \u0420\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u0434\u0438\u0430\u043f\u0430\u0437\u043e\u043d\u0435 433 MHz \u2014 \u0434\u043b\u044f \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0430\u0434\u0438\u043e\u043f\u0443\u043b\u044c\u0442\u043e\u0432, \u0434\u0430\u0442\u0447\u0438\u043a\u043e\u0432, \u044d\u043b\u0435\u043a\u0442\u0440\u043e\u043d\u043d\u044b\u0445 \u0437\u0430\u043c\u043a\u043e\u0432 \u0438 \u0440\u0435\u043b\u0435. NFC \u2014 \u0447\u0438\u0442\u0430\u0442\u044c\/\u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c \u0438 \u044d\u043c\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043a\u0430\u0440\u0442\u044b ISO-14443. 125 kHz RFID \u2014 \u0447\u0438\u0442\u0430\u0442\u044c\/\u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":71938,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-71937","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Flipper Zero \u2014 \u043f\u0430\u0446\u0430\u043d\u0441\u043a\u0438\u0439 \u043c\u0443\u043b\u044c\u0442\u0438\u0442\u0443\u043b-\u0442\u0430\u043c\u0430\u0433\u043e\u0447\u0438 \u0434\u043b\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u0435\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-29T05:54:27+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:14:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Flipper Zero \u2014 a cool multi-tool-tamagotchi for pentesters | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Flipper Zero \u2014 \u043f\u0430\u0446\u0430\u043d\u0441\u043a\u0438\u0439 \u043c\u0443\u043b\u044c\u0442\u0438\u0442\u0443\u043b-\u0442\u0430\u043c\u0430\u0433\u043e\u0447\u0438 \u0434\u043b\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u0435\u0440\u0430 | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/flipper-zero-paczanskij-multitul-tamagochi-dlya-pentestera","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-29T05:54:27+00:00","article:modified_time":"2020-03-03T13:14:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"71937","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:53:47","updated":"2022-09-28 10:09:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/71937","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=71937"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/71937\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/71938"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=71937"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=71937"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=71937"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}