mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-05-12 11:18:11 -07:00
make miscchecks
This commit is contained in:
@@ -11,7 +11,7 @@
|
||||
// then from shell:
|
||||
// hexdump lf.bin -e '5/1 "%02X" /0 "\n"'
|
||||
//
|
||||
// To recall only LAST stored ID from flash use lf-last instead of lf file.
|
||||
// To recall only LAST stored ID from flash use lf-last instead of lf file.
|
||||
//
|
||||
//-----------------------------------------------------------------------------
|
||||
// Modes of operation:
|
||||
|
||||
@@ -27,7 +27,7 @@
|
||||
#include "BigBuf.h"
|
||||
#include "crc16.h"
|
||||
|
||||
#define MODULE_LONG_NAME "LF Nedap simple simulator"
|
||||
#define MODULE_LONG_NAME "LF Nedap simple simulator"
|
||||
|
||||
typedef struct _NEDAP_TAG {
|
||||
uint8_t subType;
|
||||
|
||||
+9
-9
@@ -1814,17 +1814,17 @@ int iso14443b_select_xrx_card(iso14b_card_select_t *card) {
|
||||
static const uint8_t x_wup2[] = { 0x5D, 0x37, 0x21, 0x71, 0x71 };
|
||||
uint8_t slot_mark[1];
|
||||
|
||||
uint8_t x_atqb[24] = {0x0}; // ATQB len = 18
|
||||
uint8_t x_atqb[24] = {0x0}; // ATQB len = 18
|
||||
|
||||
uint32_t start_time = 0;
|
||||
uint32_t eof_time = 0;
|
||||
|
||||
iso14b_set_timeout(24); // wait for carrier
|
||||
iso14b_set_timeout(24); // wait for carrier
|
||||
|
||||
// wup1
|
||||
CodeAndTransmit14443bAsReader(x_wup1, sizeof(x_wup1), &start_time, &eof_time, true);
|
||||
|
||||
start_time = eof_time + US_TO_SSP(9000); // 9ms before next cmd
|
||||
start_time = eof_time + US_TO_SSP(9000); // 9ms before next cmd
|
||||
|
||||
// wup2
|
||||
CodeAndTransmit14443bAsReader(x_wup2, sizeof(x_wup2), &start_time, &eof_time, true);
|
||||
@@ -1836,7 +1836,7 @@ int iso14443b_select_xrx_card(iso14b_card_select_t *card) {
|
||||
int slot;
|
||||
|
||||
for (slot = 0; slot < 4; slot++) {
|
||||
start_time = eof_time + ETU_TO_SSP(30); //(24); // next slot after 24 ETU
|
||||
start_time = eof_time + ETU_TO_SSP(30); //(24); // next slot after 24 ETU
|
||||
|
||||
retlen = Get14443bAnswerFromTag(x_atqb, sizeof(x_atqb), iso14b_timeout, &eof_time);
|
||||
|
||||
@@ -1850,14 +1850,14 @@ int iso14443b_select_xrx_card(iso14b_card_select_t *card) {
|
||||
|
||||
// tx unframed slot-marker
|
||||
|
||||
if (Demod.posCount) { // no rx, but subcarrier burst detected
|
||||
if (Demod.posCount) { // no rx, but subcarrier burst detected
|
||||
uid |= (uint64_t)slot << uid_pos;
|
||||
|
||||
slot_mark[0] = 0xB1 + (slot << 1); // ack slot
|
||||
slot_mark[0] = 0xB1 + (slot << 1); // ack slot
|
||||
CodeAndTransmit14443bAsReader(slot_mark, sizeof(slot_mark), &start_time, &eof_time, false);
|
||||
break;
|
||||
} else { // no subcarrier burst
|
||||
slot_mark[0] = 0xA1 + (slot << 1); // nak slot
|
||||
} else { // no subcarrier burst
|
||||
slot_mark[0] = 0xA1 + (slot << 1); // nak slot
|
||||
CodeAndTransmit14443bAsReader(slot_mark, sizeof(slot_mark), &start_time, &eof_time, false);
|
||||
}
|
||||
}
|
||||
@@ -1884,7 +1884,7 @@ int iso14443b_select_xrx_card(iso14b_card_select_t *card) {
|
||||
}
|
||||
|
||||
// VALIDATE CRC
|
||||
if (check_crc(CRC_14443_B, x_atqb, 18) == false) { // use fixed len because unstable EOF catch
|
||||
if (check_crc(CRC_14443_B, x_atqb, 18) == false) { // use fixed len because unstable EOF catch
|
||||
return 3;
|
||||
}
|
||||
|
||||
|
||||
@@ -62,7 +62,7 @@ function main(args)
|
||||
|
||||
local i
|
||||
local cmds = {}
|
||||
--check for params
|
||||
--check for params
|
||||
for o, a in getopt.getopt(args, 'h') do
|
||||
if o == 'h' then return help() end
|
||||
end
|
||||
|
||||
@@ -63,8 +63,8 @@ local function card_format(key_a,key_b,ab,user,s70)
|
||||
core.console(cmd)
|
||||
print(cmd)
|
||||
core.clearCommandBuffer()
|
||||
if s70 == false and k > 15 then
|
||||
return
|
||||
if s70 == false and k > 15 then
|
||||
return
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
@@ -109,8 +109,8 @@ local function main(args)
|
||||
command = 'hf 14a sim -t 1 -u ' .. uid_format
|
||||
msg('Bruteforcing Mifare Classic card numbers')
|
||||
elseif mftype == 'mfc4' then
|
||||
command = 'hf 14a sim -t 8 -u ' .. uid_format
|
||||
msg('Bruteforcing Mifare Classic 4K card numbers')
|
||||
command = 'hf 14a sim -t 8 -u ' .. uid_format
|
||||
msg('Bruteforcing Mifare Classic 4K card numbers')
|
||||
elseif mftype == 'mfu' then
|
||||
command = 'hf 14a sim -t 2 -u ' .. uid_format
|
||||
msg('Bruteforcing Mifare Ultralight card numbers')
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -228,7 +228,7 @@ static int CmdHFEPAPACESimulate(const char *Cmd) {
|
||||
CLIExecWithReturn(ctx, Cmd, argtable, false);
|
||||
|
||||
// bool use_pc = arg_get_lit(ctx, 1);
|
||||
// uint8_t pwd_type = 0;
|
||||
// uint8_t pwd_type = 0;
|
||||
|
||||
int plen = 0;
|
||||
uint8_t pwd[6] = {0};
|
||||
@@ -273,7 +273,7 @@ static command_t CommandTable[] = {
|
||||
{"help", CmdHelp, AlwaysAvailable, "This help"},
|
||||
{"cnonces", CmdHFEPACollectPACENonces, IfPm3Iso14443, "Acquire encrypted PACE nonces of specific size"},
|
||||
{"replay", CmdHFEPAPACEReplay, IfPm3Iso14443, "Perform PACE protocol by replaying given APDUs"},
|
||||
{"sim", CmdHFEPAPACESimulate, IfPm3Iso14443, "Simulate PACE protocol"},
|
||||
{"sim", CmdHFEPAPACESimulate, IfPm3Iso14443, "Simulate PACE protocol"},
|
||||
{NULL, NULL, NULL, NULL}
|
||||
};
|
||||
|
||||
|
||||
+83
-83
@@ -15,77 +15,77 @@
|
||||
#define TIMEOUT 2000
|
||||
|
||||
|
||||
#define c2l(c,l) (l = ((unsigned long)(*((c)++))), \
|
||||
l |= ((unsigned long)(*((c)++))) << 8L, \
|
||||
l |= ((unsigned long)(*((c)++))) << 16L, \
|
||||
l |= ((unsigned long)(*((c)++))) << 24L)
|
||||
#define c2l(c,l) (l = ((unsigned long)(*((c)++))), \
|
||||
l |= ((unsigned long)(*((c)++))) << 8L, \
|
||||
l |= ((unsigned long)(*((c)++))) << 16L, \
|
||||
l |= ((unsigned long)(*((c)++))) << 24L)
|
||||
|
||||
/* NOTE - c is not incremented as per c2l */
|
||||
#define c2ln(c,l1,l2,n) { \
|
||||
c += n; \
|
||||
l1 = l2 = 0; \
|
||||
switch (n) { \
|
||||
case 8: l2 = ((unsigned long)(*(--(c)))) << 24L; \
|
||||
case 7: l2 |= ((unsigned long)(*(--(c)))) << 16L; \
|
||||
case 6: l2 |= ((unsigned long)(*(--(c)))) << 8L; \
|
||||
case 5: l2 |= ((unsigned long)(*(--(c)))); \
|
||||
case 4: l1 = ((unsigned long)(*(--(c)))) << 24L; \
|
||||
case 3: l1 |= ((unsigned long)(*(--(c)))) << 16L; \
|
||||
case 2: l1 |= ((unsigned long)(*(--(c)))) << 8L; \
|
||||
case 1: l1 |= ((unsigned long)(*(--(c)))); \
|
||||
} \
|
||||
}
|
||||
#define c2ln(c,l1,l2,n) { \
|
||||
c += n; \
|
||||
l1 = l2 = 0; \
|
||||
switch (n) { \
|
||||
case 8: l2 = ((unsigned long)(*(--(c)))) << 24L; \
|
||||
case 7: l2 |= ((unsigned long)(*(--(c)))) << 16L; \
|
||||
case 6: l2 |= ((unsigned long)(*(--(c)))) << 8L; \
|
||||
case 5: l2 |= ((unsigned long)(*(--(c)))); \
|
||||
case 4: l1 = ((unsigned long)(*(--(c)))) << 24L; \
|
||||
case 3: l1 |= ((unsigned long)(*(--(c)))) << 16L; \
|
||||
case 2: l1 |= ((unsigned long)(*(--(c)))) << 8L; \
|
||||
case 1: l1 |= ((unsigned long)(*(--(c)))); \
|
||||
} \
|
||||
}
|
||||
|
||||
#define l2c(l,c) (*((c)++) = (uint8_t)(((l)) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 8L) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 16L) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 24L) & 0xff))
|
||||
#define l2c(l,c) (*((c)++) = (uint8_t)(((l)) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 8L) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 16L) & 0xff), \
|
||||
*((c)++) = (uint8_t)(((l) >> 24L) & 0xff))
|
||||
|
||||
/* NOTE - c is not incremented as per l2c */
|
||||
#define l2cn(l1,l2,c,n) { \
|
||||
c += n; \
|
||||
switch (n) { \
|
||||
case 8: *(--(c)) = (uint8_t)(((l2) >> 24L) & 0xff); \
|
||||
case 7: *(--(c)) = (uint8_t)(((l2) >> 16L) & 0xff); \
|
||||
case 6: *(--(c)) = (uint8_t)(((l2) >> 8L) & 0xff); \
|
||||
case 5: *(--(c)) = (uint8_t)(((l2)) & 0xff); \
|
||||
case 4: *(--(c)) = (uint8_t)(((l1) >> 24L) & 0xff); \
|
||||
case 3: *(--(c)) = (uint8_t)(((l1) >> 16L) & 0xff); \
|
||||
case 2: *(--(c)) = (uint8_t)(((l1) >> 8L) & 0xff); \
|
||||
case 1: *(--(c)) = (uint8_t)(((l1)) & 0xff); \
|
||||
} \
|
||||
}
|
||||
#define l2cn(l1,l2,c,n) { \
|
||||
c += n; \
|
||||
switch (n) { \
|
||||
case 8: *(--(c)) = (uint8_t)(((l2) >> 24L) & 0xff); \
|
||||
case 7: *(--(c)) = (uint8_t)(((l2) >> 16L) & 0xff); \
|
||||
case 6: *(--(c)) = (uint8_t)(((l2) >> 8L) & 0xff); \
|
||||
case 5: *(--(c)) = (uint8_t)(((l2)) & 0xff); \
|
||||
case 4: *(--(c)) = (uint8_t)(((l1) >> 24L) & 0xff); \
|
||||
case 3: *(--(c)) = (uint8_t)(((l1) >> 16L) & 0xff); \
|
||||
case 2: *(--(c)) = (uint8_t)(((l1) >> 8L) & 0xff); \
|
||||
case 1: *(--(c)) = (uint8_t)(((l1)) & 0xff); \
|
||||
} \
|
||||
}
|
||||
|
||||
/* NOTE - c is not incremented as per n2l */
|
||||
#define n2ln(c,l1,l2,n) { \
|
||||
c += n; \
|
||||
l1 = l2 = 0; \
|
||||
switch (n) { \
|
||||
case 8: l2 = ((unsigned long)(*(--(c)))); \
|
||||
case 7: l2 |= ((unsigned long)(*(--(c)))) << 8; \
|
||||
case 6: l2 |= ((unsigned long)(*(--(c)))) << 16; \
|
||||
case 5: l2 |= ((unsigned long)(*(--(c)))) << 24; \
|
||||
case 4: l1 = ((unsigned long)(*(--(c)))); \
|
||||
case 3: l1 |= ((unsigned long)(*(--(c)))) << 8; \
|
||||
case 2: l1 |= ((unsigned long)(*(--(c)))) << 16; \
|
||||
case 1: l1 |= ((unsigned long)(*(--(c)))) << 24; \
|
||||
} \
|
||||
}
|
||||
#define n2ln(c,l1,l2,n) { \
|
||||
c += n; \
|
||||
l1 = l2 = 0; \
|
||||
switch (n) { \
|
||||
case 8: l2 = ((unsigned long)(*(--(c)))); \
|
||||
case 7: l2 |= ((unsigned long)(*(--(c)))) << 8; \
|
||||
case 6: l2 |= ((unsigned long)(*(--(c)))) << 16; \
|
||||
case 5: l2 |= ((unsigned long)(*(--(c)))) << 24; \
|
||||
case 4: l1 = ((unsigned long)(*(--(c)))); \
|
||||
case 3: l1 |= ((unsigned long)(*(--(c)))) << 8; \
|
||||
case 2: l1 |= ((unsigned long)(*(--(c)))) << 16; \
|
||||
case 1: l1 |= ((unsigned long)(*(--(c)))) << 24; \
|
||||
} \
|
||||
}
|
||||
|
||||
/* NOTE - c is not incremented as per l2n */
|
||||
#define l2nn(l1,l2,c,n) { \
|
||||
c+=n; \
|
||||
switch (n) { \
|
||||
case 8: *(--(c)) = (uint8_t)(((l2)) & 0xff); \
|
||||
case 7: *(--(c)) = (uint8_t)(((l2) >> 8) & 0xff); \
|
||||
case 6: *(--(c)) = (uint8_t)(((l2) >> 16) & 0xff); \
|
||||
case 5: *(--(c)) = (uint8_t)(((l2) >> 24) & 0xff); \
|
||||
case 4: *(--(c)) = (uint8_t)(((l1)) & 0xff); \
|
||||
case 3: *(--(c)) = (uint8_t)(((l1) >> 8) & 0xff); \
|
||||
case 2: *(--(c)) = (uint8_t)(((l1) >> 16) & 0xff); \
|
||||
case 1: *(--(c)) = (uint8_t)(((l1) >> 24) & 0xff); \
|
||||
} \
|
||||
}
|
||||
#define l2nn(l1,l2,c,n) { \
|
||||
c+=n; \
|
||||
switch (n) { \
|
||||
case 8: *(--(c)) = (uint8_t)(((l2)) & 0xff); \
|
||||
case 7: *(--(c)) = (uint8_t)(((l2) >> 8) & 0xff); \
|
||||
case 6: *(--(c)) = (uint8_t)(((l2) >> 16) & 0xff); \
|
||||
case 5: *(--(c)) = (uint8_t)(((l2) >> 24) & 0xff); \
|
||||
case 4: *(--(c)) = (uint8_t)(((l1)) & 0xff); \
|
||||
case 3: *(--(c)) = (uint8_t)(((l1) >> 8) & 0xff); \
|
||||
case 2: *(--(c)) = (uint8_t)(((l1) >> 16) & 0xff); \
|
||||
case 1: *(--(c)) = (uint8_t)(((l1) >> 24) & 0xff); \
|
||||
} \
|
||||
}
|
||||
|
||||
#define n2l(c,l) (l = ((unsigned long)(*((c)++))) << 24L, \
|
||||
l |= ((unsigned long)(*((c)++))) << 16L, \
|
||||
@@ -98,17 +98,17 @@
|
||||
*((c)++) = (uint8_t)(((l)) & 0xff))
|
||||
|
||||
#define C_RC2(n) \
|
||||
t = (x0 + (x1 & ~x3) + (x2 & x3) + *(p0++)) & 0xffff; \
|
||||
x0 = (t << 1) | (t >> 15); \
|
||||
t = (x1 + (x2 & ~x0) + (x3 & x0) + *(p0++)) & 0xffff; \
|
||||
x1 = (t << 2) | (t >> 14); \
|
||||
t = (x2 + (x3 & ~x1) + (x0 & x1) + *(p0++)) & 0xffff; \
|
||||
x2 = (t << 3) | (t >> 13); \
|
||||
t = (x3 + (x0 & ~x2) + (x1 & x2) + *(p0++)) & 0xffff; \
|
||||
x3 = (t << 5) | (t >> 11);
|
||||
t = (x0 + (x1 & ~x3) + (x2 & x3) + *(p0++)) & 0xffff; \
|
||||
x0 = (t << 1) | (t >> 15); \
|
||||
t = (x1 + (x2 & ~x0) + (x3 & x0) + *(p0++)) & 0xffff; \
|
||||
x1 = (t << 2) | (t >> 14); \
|
||||
t = (x2 + (x3 & ~x1) + (x0 & x1) + *(p0++)) & 0xffff; \
|
||||
x2 = (t << 3) | (t >> 13); \
|
||||
t = (x3 + (x0 & ~x2) + (x1 & x2) + *(p0++)) & 0xffff; \
|
||||
x3 = (t << 5) | (t >> 11);
|
||||
|
||||
#define RC2_ENCRYPT 1
|
||||
#define RC2_DECRYPT 0
|
||||
#define RC2_ENCRYPT 1
|
||||
#define RC2_DECRYPT 0
|
||||
|
||||
typedef unsigned int RC2_INT;
|
||||
|
||||
@@ -533,8 +533,8 @@ static int CmdHFXeroxInfo(const char *Cmd) {
|
||||
packet->flags = (ISO14B_APPEND_CRC | ISO14B_RAW);
|
||||
packet->rawlen = 11;
|
||||
packet->raw[0] = 0x02;
|
||||
packet->raw[1] = 0x20; // set command: read mem
|
||||
memcpy(packet->raw + 2, card.uid, 8); // store uid
|
||||
packet->raw[1] = 0x20; // set command: read mem
|
||||
memcpy(packet->raw + 2, card.uid, 8); // store uid
|
||||
|
||||
for (int retry = 0; (retry < 5 && blocknum < sizeof(info_blocks)); retry++) {
|
||||
|
||||
@@ -623,7 +623,7 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
}
|
||||
|
||||
iso14b_card_select_t card;
|
||||
int status = findXerox(&card, false); // remain RF on
|
||||
int status = findXerox(&card, false); // remain RF on
|
||||
if (status != PM3_SUCCESS) {
|
||||
free(packet);
|
||||
switch_off_field();
|
||||
@@ -632,20 +632,20 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
|
||||
PrintAndLogEx(INFO, "Reading memory from tag UID " _GREEN_("%s"), sprint_hex(card.uid, card.uidlen));
|
||||
|
||||
int blocknum = 1; // block 0 all zeros
|
||||
int blocknum = 1; // block 0 all zeros
|
||||
uint8_t data[256 * 4] = {0};
|
||||
|
||||
// set up the read command
|
||||
packet->flags = (ISO14B_APPEND_CRC | ISO14B_RAW);
|
||||
packet->rawlen = 11;
|
||||
packet->raw[0] = 0x02;
|
||||
memcpy(packet->raw + 2, card.uid, 8); // store uid
|
||||
memcpy(packet->raw + 2, card.uid, 8); // store uid
|
||||
|
||||
PrintAndLogEx(INFO, "." NOLF);
|
||||
|
||||
for (int retry = 0; (retry < 5 && blocknum < 0x100); retry++) {
|
||||
|
||||
packet->raw[1] = (blocknum < 12) ? 0x30 : 0x20; // set command: read ext mem or read mem
|
||||
packet->raw[1] = (blocknum < 12) ? 0x30 : 0x20; // set command: read ext mem or read mem
|
||||
packet->raw[10] = blocknum & 0xFF;
|
||||
|
||||
PacketResponseNG resp;
|
||||
@@ -657,7 +657,7 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
resp.cmd, resp.length, resp.magic, resp.status, resp.crc, resp.oldarg[0], resp.oldarg[1], resp.oldarg[2],
|
||||
resp.data.asBytes[0], resp.data.asBytes[1], resp.data.asBytes[2], resp.ng ? 't' : 'f');
|
||||
*/
|
||||
if (/*resp.status != 0 ||*/ resp.length < 7) { // 14b raw command send data_len instead of status
|
||||
if (/*resp.status != 0 ||*/ resp.length < 7) { // 14b raw command send data_len instead of status
|
||||
PrintAndLogEx(FAILED, "retrying one more time");
|
||||
continue;
|
||||
}
|
||||
@@ -722,8 +722,8 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
memcpy(k1, k2, sizeof(k1));
|
||||
|
||||
k1[2] = k2[3] ^ data[0x22 * 4 + 0];
|
||||
k1[3] = k2[4] ^ data[0x22 * 4 + 1]; // first_key[7];
|
||||
k1[5] = k2[1] ^ 0x01; // 01 = crypto method? rfid[23][2]
|
||||
k1[3] = k2[4] ^ data[0x22 * 4 + 1]; // first_key[7];
|
||||
k1[5] = k2[1] ^ 0x01; // 01 = crypto method? rfid[23][2]
|
||||
|
||||
RC2_set_key(&exp_key, 8, k1, 64);
|
||||
|
||||
@@ -747,7 +747,7 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
uint16_t cs, csd;
|
||||
|
||||
// calc checksum
|
||||
for (b = 0, cs = 0; b < sizeof(decr) - 2; b += 2) cs += decr[b] | (decr[b + 1] << 8);
|
||||
for (b = 0, cs = 0; b < sizeof(decr) - 2; b += 2) cs += decr[b] | (decr[b + 1] << 8);
|
||||
cs = ~cs;
|
||||
csd = (decr[7] << 8) | decr[6];
|
||||
|
||||
@@ -772,7 +772,7 @@ static int CmdHFXeroxDump(const char *Cmd) {
|
||||
PrintAndLogEx(INFO, "---------+--------------+----------");
|
||||
PrintAndLogEx(NORMAL, "");
|
||||
|
||||
if (0 == filename[0]) { // generate filename from uid
|
||||
if (0 == filename[0]) { // generate filename from uid
|
||||
/*
|
||||
PrintAndLogEx(INFO, "Using UID as filename");
|
||||
|
||||
|
||||
+1
-1
@@ -11512,6 +11512,6 @@
|
||||
"metadata": {
|
||||
"commands_extracted": 727,
|
||||
"extracted_by": "PM3Help2JSON v1.00",
|
||||
"extracted_on": "2023-01-14T21:16:27"
|
||||
"extracted_on": "2023-01-14T21:23:30"
|
||||
}
|
||||
}
|
||||
+1
-1
@@ -473,7 +473,7 @@ ISO 7816-4 Basic interindustry commands. For command APDU's.
|
||||
|
||||
// 65 xx
|
||||
#define ISO7816_MEMORY_FULL 0x6501 // Memory failure
|
||||
#define ISO7816_WRITE_MEMORY_ERR 0x6581 // Write problem / Memory failure / Unknown mode
|
||||
#define ISO7816_WRITE_MEMORY_ERR 0x6581 // Write problem / Memory failure / Unknown mode
|
||||
|
||||
// 67 xx
|
||||
#define ISO7816_WRONG_LENGTH 0x6700 // Wrong length
|
||||
|
||||
Reference in New Issue
Block a user