{"id":51781115,"url":"https://github.com/x3nc0n/flipper-fuzzer","last_synced_at":"2026-07-20T12:03:17.843Z","repository":{"id":370633069,"uuid":"1295811773","full_name":"x3nc0n/flipper-fuzzer","owner":"x3nc0n","description":"FluckFlock - a Flipper Zero chaff broadcaster that floods passive Wi-Fi/BLE/RF tracking with plausible, ever-rotating fake identifiers","archived":false,"fork":false,"pushed_at":"2026-07-18T23:00:42.000Z","size":367,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-07-19T00:27:03.384Z","etag":null,"topics":["anti-tracking","ble","chaff","embedded","esp32","fap","flipper-zero","flipperzero","privacy","rf","security-tools","sub-ghz","wifi"],"latest_commit_sha":null,"homepage":null,"language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/x3nc0n.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-09T21:59:54.000Z","updated_at":"2026-07-18T23:01:07.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/x3nc0n/flipper-fuzzer","commit_stats":null,"previous_names":["x3nc0n/flipper-fuzzer"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/x3nc0n/flipper-fuzzer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x3nc0n%2Fflipper-fuzzer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x3nc0n%2Fflipper-fuzzer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x3nc0n%2Fflipper-fuzzer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x3nc0n%2Fflipper-fuzzer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/x3nc0n","download_url":"https://codeload.github.com/x3nc0n/flipper-fuzzer/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/x3nc0n%2Fflipper-fuzzer/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35685359,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"ssl_error","status_checked_at":"2026-07-20T02:08:09.736Z","response_time":111,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anti-tracking","ble","chaff","embedded","esp32","fap","flipper-zero","flipperzero","privacy","rf","security-tools","sub-ghz","wifi"],"created_at":"2026-07-20T12:03:16.960Z","updated_at":"2026-07-20T12:03:17.838Z","avatar_url":"https://github.com/x3nc0n.png","language":"C","funding_links":[],"categories":[],"sub_categories":[],"readme":"# FluckFlock\n\n\u003e A Flipper Zero \"chaff\" broadcaster that floods passive wireless tracking systems with large volumes of plausible, ever-rotating fake identifiers.\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![Platform: Flipper Zero](https://img.shields.io/badge/platform-Flipper%20Zero-orange)](https://flipperzero.one)\n[![SDK: 1.4.3](https://img.shields.io/badge/SDK-1.4.3-green)](https://github.com/flipperdevices/flipperzero-firmware)\n[![Build: ufbt](https://img.shields.io/badge/build-ufbt-lightgrey)](https://github.com/flipperdevices/flipperzero-ufbt)\n![Host Tests](https://github.com/x3nc0n/flipper-fuzzer/actions/workflows/host-tests.yml/badge.svg)\n\n---\n\n## Overview\n\nFluckFlock is a Flipper Zero FAP (Flipper Application Package) that continuously emits large volumes of plausible-looking fake wireless identifiers across multiple radios simultaneously:\n\n- **BLE** — rotating advertisement packets with realistic device names and locally-administered random MACs\n- **Sub-GHz** — pseudo-random OOK/2-FSK bursts on common ISM frequencies via the CC1101\n- **Wi-Fi** — beacon frames with plausible SSIDs and vendor OUI-correct BSSIDs (optional; requires the official Flipper Wi-Fi Dev Board)\n\nThe goal is to pollute passive, dragnet-style surveillance systems — Wi-Fi MAC loggers, BLE advertisement scrapers, RF fingerprinting setups — by burying real identifiers in a high-volume stream of believable chaff. FluckFlock is a **volume play**, not a stealth play.\n\n**Single hardware target: Flipper Zero only.**\n\n---\n\n## Features\n\n- **Three-radio coverage**\n  - BLE advertising via the Flipper's native BLE stack\n  - Sub-GHz via the built-in CC1101 (315 / 433.92 / 868 / 915 MHz, region-filtered)\n  - Wi-Fi via the [official Flipper Wi-Fi Dev Board](https://shop.flipperzero.one/products/wifi-devboard) — auto-detected over UART; gracefully absent otherwise *(see [Wi-Fi Dev Board](#wi-fi-dev-board) and [Status](#status))*\n\n- **Plausible identifier generation**\n  - BLE MACs: locally-administered random-static addresses (bit 1 of first octet set, bit 0 clear) — spec-correct for BLE random addressing\n  - BSSIDs: real-world AP vendor OUIs (≥ 20 prefixes: TP-Link, Netgear, Cisco, Ubiquiti, Aruba, Ruckus, and more) with random trailing octets; unicast + globally-administered bits set to look like genuine hardware\n  - SSIDs: ≥ 30 realistic templates — ISP defaults, café/business names, home router patterns (`NETGEAR-XX`, `TP-Link_XXXX`, `ATT-WIFI-5G`, `eduroam`, etc.)\n  - BLE device names: ≥ 30 realistic names — earbuds, fitness trackers, smart speakers, phone models, Tile/AirTag-style labels\n  - Sub-GHz payloads: pseudo-random bytes; no protocol framing required — goal is RF-level noise\n\n- **Seedable PRNG** — xoshiro256\\*\\*-backed `ChaffRng` seeded from `furi_hal_random` at launch; fixed-seed mode available for deterministic testing\n\n- **Per-radio toggles** — enable or disable BLE, Sub-GHz, and Wi-Fi independently at runtime; Wi-Fi toggle is hidden when the dev board is absent\n\n- **Live counters** — per-radio identifier-emitted counts displayed in the running scene, refreshed at ≥ 1 Hz\n\n- **Configurable rotation interval** — 500 ms – 5 s per cycle, adjustable in Settings\n\n- **Disclaimer on launch** — brief About scene reminding users of legal obligations\n\n---\n\n## Status\n\n| Component | Status |\n|---|---|\n| BLE advertising | ✅ Verified on real hardware |\n| Sub-GHz (CC1101) | ✅ Verified on real hardware |\n| Wi-Fi beacon (dev board) | 🧪 Implemented + host-tested; on-device validation pending |\n| ufbt build (SDK 1.4.3) | ✅ Clean (`-Wall -Werror`) |\n| Host unit test suite | ✅ ~71 k assertions, all pass |\n\nWi-Fi: `radio_wifi_emit()` is fully implemented — the UART handshake-based dev-board detection, per-beacon `FFB` commands over the `wifi_proto` line protocol, and the ESP32-S2 companion firmware (`esp32/fluckflock_companion/`) are all in place and host-tested (236 protocol assertions). **On-device validation is still pending** — the ESP32 companion firmware has not yet been flashed due to a USB enumeration issue on the development machine. BLE and Sub-GHz have been confirmed working on a real Flipper Zero (FAP deployed over USB; emission counters climbing on-device).\n\n---\n\n## Build \u0026 Install\n\n### Prerequisites\n\n- A Flipper Zero with firmware ≥ 1.4.3\n- [**ufbt**](https://github.com/flipperdevices/flipperzero-ufbt) — the Flipper micro build tool\n\n  ```sh\n  pip install ufbt\n  ```\n\n### Build\n\n```sh\ncd flipperzero/fluckflock\nufbt\n```\n\nThe compiled application lands at `dist/fluckflock.fap`.\n\n### Deploy to a connected Flipper\n\n```sh\nufbt launch\n```\n\nThis builds (if needed) and deploys `fluckflock.fap` to a Flipper Zero connected via USB.\n\n---\n\n## Running the Host Tests\n\nThe identifier generators are pure C with no Flipper SDK dependency and are tested entirely on-host:\n\n```sh\ncd test\nmake test\n```\n\nRequires `gcc` or `clang`. Runs the full suite (~71 k assertions) covering SSID/BSSID/BLE MAC/BLE name generation, PRNG determinism, address-bit correctness, and uniqueness bounds.\n\n---\n\n## Repository Layout\n\n```\nflipper-fuzzer/\n├── spec.md                          # FluckFlock specification\n├── task-flipper.md                  # Implementation checklist\n├── flipperzero/\n│   └── fluckflock/\n│       ├── application.fam          # FAP manifest (appid, entry point, icon)\n│       ├── fluckflock.c / .h        # App entry point, App struct, ViewDispatcher / SceneManager\n│       ├── chaff_engine.c / .h      # Chaff engine — scheduler, per-radio lifecycle, stats\n│       ├── generators/\n│       │   ├── identifiers.c / .h   # Pure identifier generators (SSID, BSSID, BLE MAC/name, Sub-GHz payload)\n│       │   ├── prng.c / .h          # Seedable PRNG (xoshiro256**)\n│       │   ├── oui_table.h          # AP vendor OUI prefix table\n│       │   ├── ssid_table.h         # SSID template table\n│       │   └── ble_name_table.h     # BLE device name table\n│       ├── radio/\n│       │   ├── radio_ble.c / .h     # BLE advertising driver\n│       │   ├── radio_subghz.c / .h  # Sub-GHz (CC1101) driver\n│       │   ├── radio_wifi.c / .h    # Wi-Fi dev board driver (furi_hal_serial UART, handshake + per-beacon emit)\n│       │   └── wifi_proto.c / .h    # UART line-protocol builders (pure C, no Flipper SDK — host-testable)\n│       └── scenes/\n│           ├── scene_main_menu.c    # Main menu\n│           ├── scene_running.c      # Live-counter running scene\n│           ├── scene_settings.c     # Rotation interval settings\n│           └── scene_about.c        # About / disclaimer\n├── esp32/\n│   └── fluckflock_companion/        # ESP32-S2 companion firmware (PlatformIO, board: esp32-s2-saola-1)\n│       ├── src/main.cpp             # Parses UART protocol, injects raw 802.11 beacons via esp_wifi_80211_tx\n│       ├── platformio.ini           # PlatformIO project config\n│       └── README.md                # Flashing instructions and protocol reference\n└── test/\n    ├── test_identifiers.c           # Host tests for identifier generators\n    ├── test_prng.c                  # Host tests for PRNG determinism\n    ├── test_wifi_proto.c            # Host tests for UART protocol builders (236 assertions)\n    └── Makefile                     # Host build — no Flipper SDK required\n```\n\n---\n\n## Wi-Fi Dev Board\n\nWi-Fi beacon injection requires the [official Flipper Wi-Fi Dev Board](https://shop.flipperzero.one/products/wifi-devboard) (ESP32-S2-WROVER-I). Setup is two-part:\n\n1. **Flash the companion firmware** — the `esp32/fluckflock_companion/` directory is a PlatformIO project targeting the `esp32-s2-saola-1` board. Open it in VS Code with the PlatformIO extension (or run `pio run --target upload`) to build and flash it. See [`esp32/fluckflock_companion/README.md`](esp32/fluckflock_companion/README.md) for full flashing instructions.\n\n2. **Mount and run** — with the companion firmware flashed, plug the dev board onto the Flipper's expansion header. The FAP auto-detects it at startup via a UART handshake (`FF?` / `FF!`) and enables the Wi-Fi toggle in the UI. No manual configuration required.\n\n\u003e **⚠️ On-device validation pending.** The companion firmware has been implemented and all protocol logic is host-tested (236 assertions pass), but end-to-end beacon injection on the physical dev board has not yet been validated. A USB enumeration issue on the development machine is blocking the initial flash. This section will be updated once on-device testing is complete.\n\n---\n\n## ⚠️ Responsible Use / Legal\n\nFluckFlock is a **security research and personal anti-tracking tool**. It is intended to help individuals protect themselves from passive, dragnet-style wireless surveillance.\n\n**Radio transmission is regulated.** Sub-GHz and Wi-Fi emissions — including the specific frequencies, power levels, duty cycles, and types of transmissions permitted — are governed by national telecommunications law and vary significantly by country. Operating on unauthorized frequencies, exceeding power limits, or violating duty-cycle rules may be illegal where you are.\n\n**You are solely responsible for:**\n\n- Ensuring your use complies with all applicable local, national, and international laws and regulations\n- Confirming you are authorized to transmit on any frequency you use\n- Not interfering with licensed radio communications, emergency services, or safety-critical systems\n\n**FluckFlock must not be used to:**\n\n- Disrupt, deny, or degrade others' wireless networks or communications\n- Harass, stalk, or target individuals\n- Evade law enforcement or conduct any unlawful activity\n\nThe Flipper Zero's built-in region configuration enforces Sub-GHz frequency and duty-cycle limits; FluckFlock does not bypass these restrictions. Use responsibly.\n\n---\n\n## Contributing\n\nIssues and pull requests are welcome. Please open an issue before undertaking large changes so we can discuss approach. All contributions are subject to the MIT License.\n\n---\n\n## License\n\n[MIT](LICENSE) — see the LICENSE file for full terms.\n\n---\n\n## Credits\n\nFluckFlock was designed and built by an AI \"Squad\" team: **Keaton** (Lead / Firmware Architect), **Fenster** (Embedded Firmware Dev), **McManus** (Wireless / RF Dev), and **Hockney** (QA / Test). Project owner: [@x3nc0n](https://github.com/x3nc0n).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fx3nc0n%2Fflipper-fuzzer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fx3nc0n%2Fflipper-fuzzer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fx3nc0n%2Fflipper-fuzzer/lists"}