#!/bin/bash
set -e
ISO_OUT="/home/workspace/nullframe-os/nullframe-os-1.0.0.iso"
WORK="/tmp/nullframe-iso"
ISOPATH="/home/workspace/nullframe-os"

# Alpine latest stable URLs
ALPINE_BASE="https://dl-cdn.alpinelinux.org/alpine/latest-stable/releases/x86_64/netboot"

rm -rf "$WORK"
mkdir -p "$WORK"/{boot/syslinux,rootfs,opt/nullframe/{wifi,ble,rf,network},boot}

echo "[+] Downloading Alpine kernel..."
curl -sL "$ALPINE_BASE/vmlinuz-lts" -o "$WORK/boot/vmlinuz" && echo "[+] Kernel OK" || exit 1

echo "[+] Downloading Alpine initramfs..."  
curl -sL "$ALPINE_BASE/initramfs-lts" -o "$WORK/boot/initramfs" && echo "[+] Initramfs OK" || exit 1

# Copy disclaimer
cp "$ISOPATH/boot/disclaimer.txt" "$WORK/boot/disclaimer.txt"

# Create attack scripts
mkdir -p "$WORK/rootfs/opt/nullframe"/{wifi,ble,rf,network}

cat > "$WORK/rootfs/opt/nullframe/wifi/monitor.sh" << 'WIFI'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   WiFi Monitor Mode Enabler      ║"
echo "╚══════════════════════════════════╝"
echo "[*] Detecting wireless interfaces..."
ip link show 2>/dev/null | grep -E 'wlan|wl' || echo "[!] No wireless interface"
echo "[*] Usage: airmon-ng start wlan0"
WIFI

cat > "$WORK/rootfs/opt/nullframe/wifi/scan.sh" << 'SCAN'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   WiFi Scanner                   ║"
echo "╚══════════════════════════════════╝"
echo "[*] Run: airodump-ng wlan0mon"
SCAN

cat > "$WORK/rootfs/opt/nullframe/wifi/deauth.sh" << 'DEAUTH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   Deauth Attack                  ║"
echo "╚══════════════════════════════════╝"
echo "[*] Usage: aireplay-ng --deauth 10 -a <BSSID> wlan0mon"
DEAUTH

cat > "$WORK/rootfs/opt/nullframe/ble/scan.sh" << 'BLE'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   BLE Scanner                     ║"
echo "╚══════════════════════════════════╝"
echo "[*] Scanning for BLE devices..."
BLE

cat > "$WORK/rootfs/opt/nullframe/ble/glitch.sh" << 'GLITCH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   Cursed BLE Glitcher             ║"
echo "╚══════════════════════════════════╝"
echo "[!] Authorized testing only"
python3 << 'PY'
import random, time
print("[*] Generating cursed spectral waveforms...")
for i in range(5):
    freq = random.randint(2400, 2480)
    print(f"[*] Pattern {i+1}: {freq}MHz burst")
    time.sleep(0.3)
print("[+] Cursed BLE glitch complete")
PY
GLITCH

cat > "$WORK/rootfs/opt/nullframe/rf/sniff.sh" << 'RF'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   RF Sniffer                      ║"
echo "╚══════════════════════════════════╝"
echo "[*] Requires RTL-SDR hardware"
RF

cat > "$WORK/rootfs/opt/nullframe/rf/glitch.sh" << 'RFGLITCH'
#!/bin/sh
echo "╔══════════════════════════════════╗"
echo "║   Cursed RF Glitcher              ║"
echo "╚══════════════════════════════════╝"
python3 << 'PY'
import random, time
for i in range(5):
    print(f"[*] Glitch {i+1}: {random.randint(300,900)}MHz")
    time.sleep(0.3)
print("[+] RF glitch complete")
PY
RFGLITCH

cat > "$WORK/rootfs/opt/nullframe/network/arpSpoof.sh" << 'NET'
#!/bin/sh
if [ -z "$1" ] || [ -z "$2" ]; then
    echo "Usage: arpSpoof.sh <target> <gateway>"
    exit 1
fi
echo "[*] ARP spoofing $1 via $2"
NET

cat > "$WORK/rootfs/opt/nullframe/network/mitm.sh" << 'MITM'
#!/bin/sh
echo "[*] MITM Attack - Use ettercap or responder"
MITM

chmod +x "$WORK/rootfs/opt/nullframe/wifi/*.sh"
chmod +x "$WORK/rootfs/opt/nullframe/ble/*.sh"
chmod +x "$WORK/rootfs/opt/nullframe/rf/*.sh"
chmod +x "$WORK/rootfs/opt/nullframe/network/*.sh"

# Copy interactive menu
cp "$ISOPATH/tools/menu.sh" "$WORK/rootfs/opt/nullframe/"

# Create motd
cat > "$WORK/rootfs/etc/motd" << 'MOTD'
╔═══════════════════════════════════════════════════════════╗
║   ██╗  ██╗██████╗  ██████╗ ██████╗ ███████╗              ║
║   ██║ ██╔╝██╔══██╗██╔═══██╗██╔══██╗██╔════╝              ║
║   █████╔╝ ██████╔╝██║   ██║██████╔╝███████╗              ║
║   ██╔═██╗ ██╔══██╗██║   ██║██╔══██╗╚════██║              ║
║   ██║  ██╗██████╔╝╚██████╔╝██████╔╝███████║              ║
║   ╚═╝  ╚═╝╚═════╝  ╚═════╝ ╚═════╝ ╚══════╝              ║
║            SECURITY TESTING LAB                         ║
║  ⚠️  AUTHORIZED USE ONLY - ALL ACTIVITY LOGGED  ⚠️       ║
╚═══════════════════════════════════════════════════════════╝

/opt/nullframe/menu.sh - Launch attack menu
WARNING: Unauthorized access is illegal
MOTD

# Setup syslinux
cat > "$WORK/boot/syslinux/syslinux.cfg << 'EOF'
DEFAULT menu
TIMEOUT 30
PROMPT 1

MENU TITLE NullFrame OS - Security Testing Lab
MENU COLOR border 30;44
MENU COLOR title 1;36;44

LABEL menu
MENU LABEL NullFrame OS (Live)
KERNEL /boot/vmlinuz
APPEND initrd=/boot/initramfs vga=791 quiet splash
TEXT HELP
Boot NullFrame Security Testing OS
ENDTEXT

LABEL safe  
MENU LABEL NullFrame OS (Safe Mode)
KERNEL /boot/vmlinuz
APPEND initrd=/boot/initramfs vga=791
TEXT HELP
Boot without attack tools
ENDTEXT
EOF

# Copy isolinux
cp /usr/share/syslinux/isolinux.bin "$WORK/boot/syslinux/" 2>/dev/null || echo "[!] isolinux.bin missing"

cat > "$WORK/boot/syslinux/boot.cat << 'EOF'
NullFrame OS
EOF

# Build ISO
echo "[+] Building ISO..."
xorriso -as mkisofs \
    -R \
    -b boot/syslinux/isolinux.bin \
    -c boot/syslinux/boot.cat \
    -no-emul-boot \
    -boot-load-size 4 \
    -boot-info-table \
    -isohybrid-mbr /usr/share/syslinux/mbr/mbr.bin \
    -o "$ISO_OUT" \
    "$WORK/" 2>&1

if [ -f "$ISO_OUT" ]; then
    echo ""
    echo "═══════════════════════════════════════════"
    echo "[+] ISO CREATED: $ISO_OUT"
    echo "═══════════════════════════════════════════"
    ls -lh "$ISO_OUT"
fi
