You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Wireshark中查看SteelSeries键盘RGB控制的Setup Data?

SteelSeries Apex 3 TKL RGB控制逆向分析:获取USB Setup Data问题

我正在逆向分析SteelSeries Apex 3 TKL键盘的RGB控制逻辑,最终目标是使用Python的ctrl_transfer(bmRequestType, bmRequest, wValue, wIndex, data)命令实现RGB控制。

用Wireshark捕获OpenRGB修改键盘颜色时的数据包,发现USB URB中仅显示Unused Setup Header,缺少Setup Data信息。我需要提取bmRequestType、bRequest、wValue、wIndex、wLength和Data Fragment这些参数,请问有什么方法可以查看Setup Data?

查阅资料得知,RGB控制常用bmRequestType: 0x21、bRequest: 9,但wValue和wIndex因设备而异。

捕获的数据包帧

初始帧(Frame 219)

Frame 219: 128 bytes on wire (1024 bits), 128 bytes captured (1024 bits) on interface usbmon1, id 0
    Section number: 1
    Interface id: 0 (usbmon1)
        Interface name: usbmon1
    Encapsulation type: USB packets with Linux header and padding (115)
    Arrival Time: Sep 21, 2024 12:35:27.591740000 BST
    UTC Arrival Time: Sep 21, 2024 11:35:27.591740000 UTC
    Epoch Arrival Time: 1726918527.591740000
    [Time shift for this packet: 0.000000000 seconds]
    [Time delta from previous captured frame: 0.001744000 seconds]
    [Time delta from previous displayed frame: 0.000000000 seconds]
    [Time since reference or first frame: 1.540403000 seconds]
    Frame Number: 219
    Frame Length: 128 bytes (1024 bits)
    Capture Length: 128 bytes (1024 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: usb:usbhid]
USB URB
    [Source: 1.7.2]
    [Destination: host]
    URB id: 0xffff8b7f8e353d80
    URB type: URB_COMPLETE ('C')
    URB transfer type: URB_INTERRUPT (0x01)
    Endpoint: 0x82, Direction: IN
        1... .... = Direction: IN (1)
        .... 0010 = Endpoint number: 2
    Device: 7
    URB bus id: 1
    Device setup request: not relevant ('-')
    Data: present ('\0')
    URB sec: 1726918527
    URB usec: 591740
    URB status: Success (0)
    URB length [bytes]: 64
    Data length [bytes]: 64
    [bInterfaceClass: HID (0x03)]
    Unused Setup Header
    Interval: 1
    Start frame: 0
    Copy of Transfer Flags: 0x00000204, No transfer DMA map, Dir IN
    Number of ISO descriptors: 0
HID Data: 21000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

第二帧(Frame 220)

Frame 220: 64 bytes on wire (512 bits), 64 bytes captured (512 bits) on interface usbmon1, id 0
    Section number: 1
    Interface id: 0 (usbmon1)
        Interface name: usbmon1
    Encapsulation type: USB packets with Linux header and padding (115)
    Arrival Time: Sep 21, 2024 12:35:27.591762000 BST
    UTC Arrival Time: Sep 21, 2024 11:35:27.591762000 UTC
    Epoch Arrival Time: 1726918527.591762000
    [Time shift for this packet: 0.000000000 seconds]
    [Time delta from previous captured frame: 0.000022000 seconds]
    [Time delta from previous displayed frame: 0.000022000 seconds]
    [Time since reference or first frame: 1.540425000 seconds]
    Frame Number: 220
    Frame Length: 64 bytes (512 bits)
    Capture Length: 64 bytes (512 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: usb]
USB URB
    [Source: host]
    [Destination: 1.7.2]
    URB id: 0xffff8b7f8e353d80
    URB type: URB_SUBMIT ('S')
    URB transfer type: URB_INTERRUPT (0x01)
    Endpoint: 0x82, Direction: IN
        1... .... = Direction: IN (1)
        .... 0010 = Endpoint number: 2
    Device: 7
    URB bus id: 1
    Device setup request: not relevant ('-')
    Data: not present ('<')
    URB sec: 1726918527
    URB usec: 591762
    URB status: Operation now in progress (-EINPROGRESS) (-115)
    URB length [bytes]: 64
    Data length [bytes]: 0
    [Response in: 223]
    [bInterfaceClass: HID (0x03)]
    Unused Setup Header
    Interval: 1
    Start frame: 0
    Copy of Transfer Flags: 0x00000204, No transfer DMA map, Dir IN
    Number of ISO descriptors: 0

第三帧(Frame 223)

Frame 223: 128 bytes on wire (1024 bits), 128 bytes captured (1024 bits) on interface usbmon1, id 0
    Section number: 1
    Interface id: 0 (usbmon1)
        Interface name: usbmon1
    Encapsulation type: USB packets with Linux header and padding (115)
    Arrival Time: Sep 21, 2024 12:35:27.594736000 BST
    UTC Arrival Time: Sep 21, 2024 11:35:27.594736000 UTC
    Epoch Arrival Time: 1726918527.594736000
    [Time shift for this packet: 0.000000000 seconds]
    [Time delta from previous captured frame: 0.002949000 seconds]
    [Time delta from previous displayed frame: 0.002974000 seconds]
    [Time since reference or first frame: 1.543399000 seconds]
    Frame Number: 223
    Frame Length: 128 bytes (1024 bits)
    Capture Length: 128 bytes (1024 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: usb:usbhid]
USB URB
    [Source: 1.7.2]
    [Destination: host]
    URB id: 0xffff8b7f8e353d80
    URB type: URB_COMPLETE ('C')
    URB transfer type: URB_INTERRUPT (0x01)
    Endpoint: 0x82, Direction: IN
        1... .... = Direction: IN (1)
        .... 0010 = Endpoint number: 2
    Device: 7
    URB bus id: 1
    Device setup request: not relevant ('-')
    Data: present ('\0')
    URB sec: 1726918527
    URB usec: 594736
    URB status: Success (0)
    URB length [bytes]: 64
    Data length [bytes]: 64
    [Request in: 220]
    [Time from request: 0.002974000 seconds]
    [bInterfaceClass: HID (0x03)]
    Unused Setup Header
    Interval: 1
    Start frame: 0
    Copy of Transfer Flags: 0x00000204, No transfer DMA map, Dir IN
    Number of ISO descriptors: 0
HID Data: 23000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

第四帧(Frame 224)

Frame 224: 64 bytes on wire (512 bits), 64 bytes captured (512 bits) on interface usbmon1, id 0
    Section number: 1
    Interface id: 0 (usbmon1)
        Interface name: usbmon1
    Encapsulation type: USB packets with Linux header and padding (115)
    Arrival Time: Sep 21, 2024 12:35:27.594743000 BST
    UTC Arrival Time: Sep 21, 2024 11:35:27.594743000 UTC
    Epoch Arrival Time: 1726918527.594743000
    [Time shift for this packet: 0.000000000 seconds]
    [Time delta from previous captured frame: 0.000007000 seconds]
    [Time delta from previous displayed frame: 0.000007000 seconds]
    [Time since reference or first frame: 1.543406000 seconds]
    Frame Number: 224
    Frame Length: 64 bytes (512 bits)
    Capture Length: 64 bytes (512 bits)
    [Frame is marked: False]
    [Frame is ignored: False]
    [Protocols in frame: usb]
USB URB
    [Source: host]
    [Destination: 1.7.2]
    URB id: 0xffff8b7f8e353d80
    URB type: URB_SUBMIT ('S')
    URB transfer type: URB_INTERRUPT (0x01)
    Endpoint: 0x82, Direction: IN
        1... .... = Direction: IN (1)
        .... 0010 = Endpoint number: 2
    Device: 7
    URB bus id: 1
    Device setup request: not relevant ('-')
    Data: not present ('<')
    URB sec: 1726918527
    URB usec: 594743
    URB status: Operation now in progress (-EINPROGRESS) (-115)
    URB length [bytes]: 64
    Data length [bytes]: 0
    [bInterfaceClass: HID (0x03)]
    Unused Setup Header
    Interval: 1
    Start frame: 0
    Copy of Transfer Flags: 0x00000204, No transfer DMA map, Dir IN
    Number of ISO descriptors: 0

我尝试过通过OpenRGB发送各种指令来提取Setup Data,但均未成功。

内容的提问来源于stack exchange,提问作者user27400094

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 06:12:32