树莓派5用Scapy嗅探蓝牙数据包时hci0设备未检测到求助
解决Scapy蓝牙嗅探时hci0设备未找到的问题
问题根源
rfkill仅显示蓝牙设备的软/硬阻塞状态,不代表接口已完成系统层面的初始化注册。ifconfig hci0无法识别设备,说明hci0未被正确激活,而Scapy默认使用以太网socket,无法直接读取未初始化的蓝牙HCI接口信息。
解决步骤
1. 确保蓝牙服务正常运行
先启动并启用系统蓝牙服务:
sudo systemctl start bluetooth sudo systemctl enable bluetooth
2. 重新初始化hci0接口
通过hciconfig工具重置hci0状态:
sudo hciconfig hci0 down sudo hciconfig hci0 up
执行hciconfig hci0检查输出,若包含RUNNING字段,则说明接口已成功激活。
3. 修改Scapy代码适配蓝牙HCI接口
Scapy默认的sniff函数基于以太网socket,无法直接适配蓝牙HCI协议。改用Scapy提供的BluetoothHCISocket创建专用连接:
from scapy.all import * import sys import os # 蓝牙数据包处理回调 def packet_callback(packet): if packet.haslayer(Bluetooth_HCI_Hdr) and packet.haslayer(Bluetooth_HCI_Data): if packet[Bluetooth_HCI_Data].opcode == 0x04: # 探测请求对应opcode print("Probe Request captured:") packet.show() # 启动蓝牙嗅探 def start_sniffing(interface): print(f"Starting Bluetooth sniffing on {interface}...") # 创建蓝牙HCI专用socket bt_socket = BluetoothHCISocket(interface) sniff(socket=bt_socket, prn=packet_callback, store=0) if __name__ == "__main__": # 检查root权限 if os.geteuid() != 0: print("请以root权限运行脚本!") sys.exit(1) interface = "hci0" start_sniffing(interface)
4. 尝试切换到hci1接口
若hci0始终无法正常激活,可尝试将代码中的interface = "hci0"改为interface = "hci1",重复上述初始化步骤后测试。
内容的提问来源于stack exchange,提问作者Anand
相关产品推荐
相关产品推荐

