/flipperzero-subbrute

SubGHz key checker

Primary LanguageCMIT LicenseMIT

SubGHz BruteForcer Application for Flipper Zero

image

SubGhz BruteForcer from Unleashed Firmware

Disclaimer

This software is for experimental purposes only and is not meant for any illegal activity/purposes. We do not condone illegal activity and strongly encourage keeping transmissions to legal/valid uses allowed by law.


Installation

The application is included in the standard firmware package of Unleashed Firmware. You just need to install the latest firmware.
You can also download the release and unzip/untar it to the SD Card/apps/Sub-GHz directory.

Warning

The application has not been tested on other firmware versions other than Unleashed Firmware and OFW.


User Guide

Main Menu

image

Here you can select the protocol and frequency that will be used for bruteforce.

According to our observations, CAME 12bit 433MHz is the most common protocol, so it is selected by default.

To identify other devices and protocols you should inspect the device.

According to the protocol, when probe a key, each value is sent 3 times. For most of the devices this works but there are devices that don't work and more repetitions are needed.

The number of repetitions can be increased with the right button, the left button decreases the value.

But negative side of increasing the number of repetitions will be a longer key find time.

image


Buttons

Button Action
◀️ Decrease repeat value
🔼 Move up
▶️ Increase repeat value
🔽 Move down
⏺️ Select protocol
↩️ Close application

Supported Protocols

image

CAME

  • CAME 12bit 303MHz
  • CAME 12bit 307MHz
  • CAME 12bit 315MHz
  • CAME 12bit 330MHz
  • CAME 12bit 433MHz
  • CAME 12bit 868MHz

NICE

  • NICE 12bit 433MHz
  • NICE 12bit 868MHz

Ansonic

  • Ansonic 12bit 433.075MHz
  • Ansonic 12bit 433.920MHz
  • Ansonic 12bit 434.075MHz

Holtek

  • Holtek HT12X 12bit FM 433.920MHz (TE: 204μs)
  • Holtek HT12X 12bit AM 433.920MHz (TE: 433μs)
  • Holtek HT12X 12bit AM 315MHz (TE: 433μs)
  • Holtek HT12X 12bit AM 868MHz (TE: 433μs)
  • Holtek HT12X 12bit AM 915MHz (TE: 433μs)

Chamberlain

  • Chamberlain 9bit 300MHz
  • Chamberlain 9bit 315MHz
  • Chamberlain 9bit 318MHz
  • Chamberlain 9bit 390MHz
  • Chamberlain 9bit 433MHz
  • Chamberlain 8bit 300MHz
  • Chamberlain 8bit 315MHz
  • Chamberlain 8bit 390MHz
  • Chamberlain 7bit 300MHz
  • Chamberlain 7bit 315MHz
  • Chamberlain 7bit 390MHz

Linear

  • Linear 10bit 300MHz
  • Linear 10bit 310MHz
  • Linear Delta 3 8bit 310MHz

UNILARM

Note

Only DIP switch combinations, not full 25bit bruteforce

  • UNILARM 25bit 330MHz (TE: 209μs)
  • UNILARM 25bit 433MHz (TE: 209μs)

SMC5326

Note

Only DIP switch combinations, not full 25bit bruteforce

  • SMC5326 25bit 330MHz (TE: 320μs)
  • SMC5326 25bit 433MHz (TE: 320μs)

PT2260

Note

Only for 8 DIP switch remote, not full 24bit bruteforce

  • PT2260 24bit 315MHz (TE: 286μs)
  • PT2260 24bit 330MHz (TE: 286μs)
  • PT2260 24bit 390MHz (TE: 286μs)
  • PT2260 24bit 433MHz (TE: 286μs)

Additional

  • BF Existing dump works for most other static protocols supported by Flipper Zero