mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-09-11 18:29:22 -07:00
foundKeys was indexed [keytype][keyno] with no AID dimension and was never reset between applications, so a key number recovered on one AID was skipped without a single auth attempt on every later AID. On a card with AES key 00 set on two apps, only the first one was ever reported. Give every application its own desfire_app_keys_t and hand that to the checker. Saving to json now uses a new 'mfdes v2' format keyed by AID, with a loader that round-trips it; v1 is kept for existing files. Also in the same path: - one auth error below 7 broke out of the key number loop, abandoning every remaining key number for the AID. Only an algo mismatch (4, 50, 51) skips the key type now; an invalid key number (3) skips just that key number, and a transmit error retries after a reselect - 3TDEA keys were stored 16 bytes wide and written out as 24 - -k with a 24 byte key was rejected by the parser, making the 24 byte branch unreachable - DesfireGetAIDList() wrote unbounded into a 78 byte app_ids buffer Co-Authored-By: Claude Opus 5 (1M context)