mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-05-12 11:18:11 -07:00
legic write/simulate [Anon]
This commit is contained in:
@@ -608,6 +608,14 @@ void UsbPacketReceived(uint8_t *packet, int len)
|
||||
break;
|
||||
#endif
|
||||
|
||||
case CMD_SIMULATE_TAG_LEGIC_RF:
|
||||
LegicRfSimulate(c->arg[0], c->arg[1], c->arg[2]);
|
||||
break;
|
||||
|
||||
case CMD_WRITER_LEGIC_RF:
|
||||
LegicRfWriter(c->arg[1], c->arg[0]);
|
||||
break;
|
||||
|
||||
case CMD_READER_LEGIC_RF:
|
||||
LegicRfReader(c->arg[0], c->arg[1]);
|
||||
break;
|
||||
|
||||
+471
-28
File diff suppressed because it is too large
Load Diff
+3
-2
@@ -11,7 +11,8 @@
|
||||
#ifndef __LEGICRF_H
|
||||
#define __LEGICRF_H
|
||||
|
||||
extern void LegicRfSimulate(void);
|
||||
extern void LegicRfReader(int bytes, int offset);
|
||||
extern void LegicRfSimulate(int phase, int frame, int reqresp);
|
||||
extern int LegicRfReader(int bytes, int offset);
|
||||
extern void LegicRfWriter(int bytes, int offset);
|
||||
|
||||
#endif /* __LEGICRF_H */
|
||||
|
||||
@@ -24,6 +24,11 @@ static command_t CommandTable[] =
|
||||
{"help", CmdHelp, 1, "This help"},
|
||||
{"decode", CmdLegicDecode, 0, "Display deobfuscated and decoded LEGIC RF tag data (use after hf legic reader)"},
|
||||
{"reader", CmdLegicRFRead, 0, "[offset [length]] -- read bytes from a LEGIC card"},
|
||||
{"save", CmdLegicSave, 0, "<filename> [<length>] -- Store samples"},
|
||||
{"load", CmdLegicLoad, 0, "<filename> -- Restore samples"},
|
||||
{"sim", CmdLegicRfSim, 0, "[phase drift [frame drift [req/resp drift]]] Start tag simulator (use after load or read)"},
|
||||
{"write", CmdLegicRfWrite,0, "<offset> <length> -- Write sample buffer (user after load or read)"},
|
||||
{"fill", CmdLegicRfFill, 0, "<offset> <length> <value> -- Fill/Write tag with constant value"},
|
||||
{NULL, NULL, 0, NULL}
|
||||
};
|
||||
|
||||
@@ -225,3 +230,136 @@ int CmdLegicRFRead(const char *Cmd)
|
||||
SendCommand(&c);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int CmdLegicLoad(const char *Cmd)
|
||||
{
|
||||
FILE *f = fopen(Cmd, "r");
|
||||
if(!f) {
|
||||
PrintAndLog("couldn't open '%s'", Cmd);
|
||||
return -1;
|
||||
}
|
||||
char line[80]; int offset = 0; unsigned int data[8];
|
||||
while(fgets(line, sizeof(line), f)) {
|
||||
int res = sscanf(line, "%x %x %x %x %x %x %x %x",
|
||||
&data[0], &data[1], &data[2], &data[3],
|
||||
&data[4], &data[5], &data[6], &data[7]);
|
||||
if(res != 8) {
|
||||
PrintAndLog("Error: could not read samples");
|
||||
fclose(f);
|
||||
return -1;
|
||||
}
|
||||
UsbCommand c={CMD_DOWNLOADED_SIM_SAMPLES_125K, {offset, 0, 0}};
|
||||
int j; for(j = 0; j < 8; j++) {
|
||||
c.d.asBytes[j] = data[j];
|
||||
}
|
||||
SendCommand(&c);
|
||||
WaitForResponse(CMD_ACK);
|
||||
offset += 8;
|
||||
}
|
||||
fclose(f);
|
||||
PrintAndLog("loaded %u samples", offset);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int CmdLegicSave(const char *Cmd)
|
||||
{
|
||||
int n;
|
||||
int requested = 1024;
|
||||
int offset = 0;
|
||||
char filename[1024];
|
||||
sscanf(Cmd, " %s %i %i", filename, &requested, &offset);
|
||||
if (offset % 4 != 0) {
|
||||
PrintAndLog("Offset must be a multiple of 4");
|
||||
return 0;
|
||||
}
|
||||
offset = offset/4;
|
||||
|
||||
int delivered = 0;
|
||||
|
||||
if (requested == 0) {
|
||||
n = 12;
|
||||
requested = 12;
|
||||
} else {
|
||||
n = requested/4;
|
||||
}
|
||||
|
||||
FILE *f = fopen(filename, "w");
|
||||
if(!f) {
|
||||
PrintAndLog("couldn't open '%s'", Cmd+1);
|
||||
return -1;
|
||||
}
|
||||
|
||||
for (int i = offset; i < n+offset; i += 12) {
|
||||
UsbCommand c = {CMD_DOWNLOAD_RAW_ADC_SAMPLES_125K, {i, 0, 0}};
|
||||
SendCommand(&c);
|
||||
WaitForResponse(CMD_DOWNLOADED_RAW_ADC_SAMPLES_125K);
|
||||
for (int j = 0; j < 48; j += 8) {
|
||||
fprintf(f, "%02x %02x %02x %02x %02x %02x %02x %02x\n",
|
||||
sample_buf[j+0],
|
||||
sample_buf[j+1],
|
||||
sample_buf[j+2],
|
||||
sample_buf[j+3],
|
||||
sample_buf[j+4],
|
||||
sample_buf[j+5],
|
||||
sample_buf[j+6],
|
||||
sample_buf[j+7]
|
||||
);
|
||||
delivered += 8;
|
||||
if (delivered >= requested)
|
||||
break;
|
||||
}
|
||||
if (delivered >= requested)
|
||||
break;
|
||||
}
|
||||
|
||||
fclose(f);
|
||||
PrintAndLog("saved %u samples", delivered);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int CmdLegicRfSim(const char *Cmd)
|
||||
{
|
||||
UsbCommand c={CMD_SIMULATE_TAG_LEGIC_RF};
|
||||
c.arg[0] = 6;
|
||||
c.arg[1] = 3;
|
||||
c.arg[2] = 0;
|
||||
sscanf(Cmd, " %i %i %i", &c.arg[0], &c.arg[1], &c.arg[2]);
|
||||
SendCommand(&c);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int CmdLegicRfWrite(const char *Cmd)
|
||||
{
|
||||
UsbCommand c={CMD_WRITER_LEGIC_RF};
|
||||
int res = sscanf(Cmd, " 0x%x 0x%x", &c.arg[0], &c.arg[1]);
|
||||
if(res != 2) {
|
||||
PrintAndLog("Please specify the offset and length as two hex strings");
|
||||
return -1;
|
||||
}
|
||||
SendCommand(&c);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int CmdLegicRfFill(const char *Cmd)
|
||||
{
|
||||
UsbCommand cmd ={CMD_WRITER_LEGIC_RF};
|
||||
int res = sscanf(Cmd, " 0x%x 0x%x 0x%x", &cmd.arg[0], &cmd.arg[1], &cmd.arg[2]);
|
||||
if(res != 3) {
|
||||
PrintAndLog("Please specify the offset, length and value as two hex strings");
|
||||
return -1;
|
||||
}
|
||||
|
||||
int i;
|
||||
UsbCommand c={CMD_DOWNLOADED_SIM_SAMPLES_125K, {0, 0, 0}};
|
||||
for(i = 0; i < 48; i++) {
|
||||
c.d.asBytes[i] = cmd.arg[2];
|
||||
}
|
||||
for(i = 0; i < 22; i++) {
|
||||
c.arg[0] = i*48;
|
||||
SendCommand(&c);
|
||||
WaitForResponse(CMD_ACK);
|
||||
}
|
||||
SendCommand(&cmd);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
@@ -15,5 +15,10 @@ int CmdHFLegic(const char *Cmd);
|
||||
|
||||
int CmdLegicRFRead(const char *Cmd);
|
||||
int CmdLegicDecode(const char *Cmd);
|
||||
int CmdLegicLoad(const char *Cmd);
|
||||
int CmdLegicSave(const char *Cmd);
|
||||
int CmdLegicRfSim(const char *Cmd);
|
||||
int CmdLegicRfWrite(const char *Cmd);
|
||||
int CmdLegicRfFill(const char *Cmd);
|
||||
|
||||
#endif
|
||||
|
||||
+9
-2
@@ -9,11 +9,13 @@
|
||||
#include "legic_prng.h"
|
||||
|
||||
struct lfsr {
|
||||
uint8_t a;
|
||||
uint8_t b;
|
||||
uint8_t a;
|
||||
uint8_t b;
|
||||
uint32_t c;
|
||||
} lfsr;
|
||||
|
||||
void legic_prng_init(uint8_t init) {
|
||||
lfsr.c = 0;
|
||||
lfsr.a = init;
|
||||
if(init == 0) /* hack to get a always 0 keystream */
|
||||
lfsr.b = 0;
|
||||
@@ -22,12 +24,17 @@ void legic_prng_init(uint8_t init) {
|
||||
}
|
||||
|
||||
void legic_prng_forward(int count) {
|
||||
lfsr.c += count;
|
||||
while(count--) {
|
||||
lfsr.a = lfsr.a >> 1 | (lfsr.a ^ lfsr.a >> 6) << 6;
|
||||
lfsr.b = lfsr.b >> 1 | (lfsr.b ^ lfsr.b >> 2 ^ lfsr.b >> 3 ^ lfsr.b >> 7) << 7;
|
||||
}
|
||||
}
|
||||
|
||||
int legic_prng_count() {
|
||||
return lfsr.c;
|
||||
}
|
||||
|
||||
uint8_t legic_prng_get_bit() {
|
||||
uint8_t idx = 7 - ( (lfsr.a & 4) | (lfsr.a >> 2 & 2) | (lfsr.a >> 4 & 1) );
|
||||
return lfsr.b >> idx & 1;
|
||||
|
||||
@@ -12,6 +12,7 @@
|
||||
#include <stdint.h>
|
||||
extern void legic_prng_init(uint8_t init);
|
||||
extern void legic_prng_forward(int count);
|
||||
extern int legic_prng_count();
|
||||
extern uint8_t legic_prng_get_bit();
|
||||
|
||||
#endif
|
||||
|
||||
@@ -84,6 +84,7 @@ typedef struct {
|
||||
#define CMD_SIMULATE_MIFARE_CARD 0x0386
|
||||
#define CMD_SIMULATE_TAG_LEGIC_RF 0x0387
|
||||
#define CMD_READER_LEGIC_RF 0x0388
|
||||
#define CMD_WRITER_LEGIC_RF 0x0399
|
||||
#define CMD_READER_MIFARE 0x0389
|
||||
|
||||
// For measurements of the antenna tuning
|
||||
|
||||
Reference in New Issue
Block a user