]> cvs.zerfleddert.de Git - proxmark3-svn/blame_incremental - include/usb_cmd.h
fix 'hf iclass sim'
[proxmark3-svn] / include / usb_cmd.h
... / ...
CommitLineData
1//-----------------------------------------------------------------------------
2// Jonathan Westhues, Mar 2006
3// Edits by Gerhard de Koning Gans, Sep 2007
4//
5// This code is licensed to you under the terms of the GNU GPL, version 2 or,
6// at your option, any later version. See the LICENSE.txt file for the text of
7// the license.
8//-----------------------------------------------------------------------------
9// Definitions for all the types of commands that may be sent over USB; our
10// own protocol.
11//-----------------------------------------------------------------------------
12
13#ifndef __USB_CMD_H
14#define __USB_CMD_H
15#ifdef _MSC_VER
16typedef DWORD uint32_t;
17typedef BYTE uint8_t;
18#define PACKED
19// stuff
20#else
21#include <stdint.h>
22#include <stdbool.h>
23#define PACKED __attribute__((packed))
24#endif
25
26#define USB_CMD_DATA_SIZE 512
27
28typedef struct {
29 uint64_t cmd;
30 uint64_t arg[3];
31 union {
32 uint8_t asBytes[USB_CMD_DATA_SIZE];
33 uint32_t asDwords[USB_CMD_DATA_SIZE/4];
34 } d;
35} PACKED UsbCommand;
36
37// A struct used to send sample-configs over USB
38typedef struct{
39 uint8_t decimation;
40 uint8_t bits_per_sample;
41 bool averaging;
42 int divisor;
43 int trigger_threshold;
44 int samples_to_skip;
45} sample_config;
46
47// For the bootloader
48#define CMD_DEVICE_INFO 0x0000
49#define CMD_SETUP_WRITE 0x0001
50#define CMD_FINISH_WRITE 0x0003
51#define CMD_HARDWARE_RESET 0x0004
52#define CMD_START_FLASH 0x0005
53#define CMD_NACK 0x00fe
54#define CMD_ACK 0x00ff
55
56// For general mucking around
57#define CMD_DEBUG_PRINT_STRING 0x0100
58#define CMD_DEBUG_PRINT_INTEGERS 0x0101
59#define CMD_DEBUG_PRINT_BYTES 0x0102
60#define CMD_LCD_RESET 0x0103
61#define CMD_LCD 0x0104
62#define CMD_BUFF_CLEAR 0x0105
63#define CMD_READ_MEM 0x0106
64#define CMD_VERSION 0x0107
65#define CMD_STATUS 0x0108
66#define CMD_PING 0x0109
67
68// controlling the ADC input multiplexer
69#define CMD_SET_ADC_MUX 0x020F
70
71// RDV40, Smart card operations
72#define CMD_SMART_RAW 0x0140
73#define CMD_SMART_UPGRADE 0x0141
74#define CMD_SMART_UPLOAD 0x0142
75#define CMD_SMART_ATR 0x0143
76// CMD_SMART_SETBAUD is unused for now
77#define CMD_SMART_SETBAUD 0x0144
78#define CMD_SMART_SETCLOCK 0x0145
79
80// For low-frequency tags
81#define CMD_READ_TI_TYPE 0x0202
82#define CMD_WRITE_TI_TYPE 0x0203
83#define CMD_DOWNLOADED_RAW_BITS_TI_TYPE 0x0204
84#define CMD_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0205
85#define CMD_MOD_THEN_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0206
86#define CMD_DOWNLOAD_RAW_ADC_SAMPLES_125K 0x0207
87#define CMD_DOWNLOADED_RAW_ADC_SAMPLES_125K 0x0208
88#define CMD_DOWNLOADED_SIM_SAMPLES_125K 0x0209
89#define CMD_SIMULATE_TAG_125K 0x020A
90#define CMD_HID_DEMOD_FSK 0x020B
91#define CMD_HID_SIM_TAG 0x020C
92#define CMD_SET_LF_DIVISOR 0x020D
93#define CMD_LF_SIMULATE_BIDIR 0x020E
94#define CMD_HID_CLONE_TAG 0x0210
95#define CMD_EM410X_WRITE_TAG 0x0211
96#define CMD_INDALA_CLONE_TAG 0x0212
97// for 224 bits UID
98#define CMD_INDALA_CLONE_TAG_L 0x0213
99#define CMD_T55XX_READ_BLOCK 0x0214
100#define CMD_T55XX_WRITE_BLOCK 0x0215
101#define CMD_T55XX_RESET_READ 0x0216
102#define CMD_PCF7931_READ 0x0217
103#define CMD_PCF7931_WRITE 0x0222
104#define CMD_PCF7931_BRUTEFORCE 0x0227
105#define CMD_EM4X_READ_WORD 0x0218
106#define CMD_EM4X_WRITE_WORD 0x0219
107#define CMD_IO_DEMOD_FSK 0x021A
108#define CMD_IO_CLONE_TAG 0x021B
109#define CMD_EM410X_DEMOD 0x021c
110// Sampling configuration for LF reader/snooper
111#define CMD_SET_LF_SAMPLING_CONFIG 0x021d
112#define CMD_FSK_SIM_TAG 0x021E
113#define CMD_ASK_SIM_TAG 0x021F
114#define CMD_PSK_SIM_TAG 0x0220
115#define CMD_AWID_DEMOD_FSK 0x0221
116#define CMD_VIKING_CLONE_TAG 0x0223
117#define CMD_T55XX_WAKEUP 0x0224
118#define CMD_COTAG 0x0225
119#define CMD_PARADOX_CLONE_TAG 0x0226
120#define CMD_EM4X_PROTECT 0x0228
121
122// For the 13.56 MHz tags
123#define CMD_ACQUIRE_RAW_ADC_SAMPLES_ISO_15693 0x0300
124#define CMD_READ_SRI512_TAG 0x0303
125#define CMD_READ_SRIX4K_TAG 0x0304
126#define CMD_ISO_14443B_COMMAND 0x0305
127#define CMD_READER_ISO_15693 0x0310
128#define CMD_SIMTAG_ISO_15693 0x0311
129#define CMD_SNOOP_ISO_15693 0x0312
130#define CMD_ISO_15693_COMMAND 0x0313
131#define CMD_ISO_15693_COMMAND_DONE 0x0314
132#define CMD_ISO_15693_FIND_AFI 0x0315
133#define CMD_ISO_15693_DEBUG 0x0316
134#define CMD_LF_SNOOP_RAW_ADC_SAMPLES 0x0317
135#define CMD_CSETUID_ISO_15693 0x0318
136
137// For Hitag2 transponders
138#define CMD_SNOOP_HITAG 0x0370
139#define CMD_SIMULATE_HITAG 0x0371
140#define CMD_READER_HITAG 0x0372
141#define CMD_SIMULATE_HITAG_S 0x0368
142#define CMD_TEST_HITAGS_TRACES 0x0367
143#define CMD_READ_HITAG_S 0x0373
144#define CMD_READ_HITAG_S_BLK 0x0374
145#define CMD_WR_HITAG_S 0x0375
146#define CMD_EMU_HITAG_S 0x0376
147
148#define CMD_SIMULATE_TAG_ISO_14443B 0x0381
149#define CMD_SNOOP_ISO_14443B 0x0382
150#define CMD_SNOOP_ISO_14443a 0x0383
151#define CMD_SIMULATE_TAG_ISO_14443a 0x0384
152#define CMD_READER_ISO_14443a 0x0385
153#define CMD_SIMULATE_TAG_LEGIC_RF 0x0387
154#define CMD_READER_LEGIC_RF 0x0388
155#define CMD_WRITER_LEGIC_RF 0x0389
156#define CMD_EPA_PACE_COLLECT_NONCE 0x038A
157#define CMD_EPA_PACE_REPLAY 0x038B
158
159#define CMD_ICLASS_READCHECK 0x038F
160#define CMD_ICLASS_CLONE 0x0390
161#define CMD_ICLASS_DUMP 0x0391
162#define CMD_SNOOP_ICLASS 0x0392
163#define CMD_SIMULATE_TAG_ICLASS 0x0393
164#define CMD_READER_ICLASS 0x0394
165#define CMD_READER_ICLASS_REPLAY 0x0395
166#define CMD_ICLASS_READBLOCK 0x0396
167#define CMD_ICLASS_WRITEBLOCK 0x0397
168#define CMD_ICLASS_EML_MEMSET 0x0398
169#define CMD_ICLASS_AUTHENTICATION 0x0399
170
171// For measurements of the antenna tuning
172#define CMD_MEASURE_ANTENNA_TUNING 0x0400
173#define CMD_MEASURE_ANTENNA_TUNING_HF 0x0401
174#define CMD_MEASURED_ANTENNA_TUNING 0x0410
175#define CMD_LISTEN_READER_FIELD 0x0420
176
177// For direct FPGA control
178#define CMD_FPGA_MAJOR_MODE_OFF 0x0500
179
180// For mifare commands
181#define CMD_MIFARE_SET_DBGMODE 0x0600
182#define CMD_MIFARE_EML_MEMCLR 0x0601
183#define CMD_MIFARE_EML_MEMSET 0x0602
184#define CMD_MIFARE_EML_MEMGET 0x0603
185#define CMD_MIFARE_EML_CARDLOAD 0x0604
186
187// magic chinese card commands
188#define CMD_MIFARE_CSETBLOCK 0x0605
189#define CMD_MIFARE_CGETBLOCK 0x0606
190#define CMD_MIFARE_CIDENT 0x0607
191#define CMD_MIFARE_CWIPE 0x0608
192
193#define CMD_SIMULATE_MIFARE_CARD 0x0610
194
195#define CMD_READER_MIFARE 0x0611
196#define CMD_MIFARE_NESTED 0x0612
197#define CMD_MIFARE_ACQUIRE_ENCRYPTED_NONCES 0x0613
198
199#define CMD_MIFARE_READBL 0x0620
200#define CMD_MIFARE_READSC 0x0621
201#define CMD_MIFARE_WRITEBL 0x0622
202#define CMD_MIFARE_CHKKEYS 0x0623
203#define CMD_MIFARE_PERSONALIZE_UID 0x0624
204#define CMD_MIFARE_SNIFFER 0x0630
205
206//ultralightC
207#define CMD_MIFAREU_READBL 0x0720
208#define CMD_MIFAREU_READCARD 0x0721
209#define CMD_MIFAREU_WRITEBL 0x0722
210#define CMD_MIFAREU_WRITEBL_COMPAT 0x0723
211#define CMD_MIFAREUC_AUTH 0x0724
212//0x0725 and 0x0726 no longer used
213#define CMD_MIFAREUC_SETPWD 0x0727
214
215
216// mifare desfire
217#define CMD_MIFARE_DESFIRE_READBL 0x0728
218#define CMD_MIFARE_DESFIRE_WRITEBL 0x0729
219#define CMD_MIFARE_DESFIRE_AUTH1 0x072a
220#define CMD_MIFARE_DESFIRE_AUTH2 0x072b
221#define CMD_MIFARE_DES_READER 0x072c
222#define CMD_MIFARE_DESFIRE_INFO 0x072d
223#define CMD_MIFARE_DESFIRE 0x072e
224
225#define CMD_HF_SNIFFER 0x0800
226#define CMD_HF_PLOT 0x0801
227
228#define CMD_UNKNOWN 0xFFFF
229
230
231// Mifare simulation flags
232#define FLAG_INTERACTIVE (1<<0)
233#define FLAG_4B_UID_IN_DATA (1<<1)
234#define FLAG_7B_UID_IN_DATA (1<<2)
235#define FLAG_NR_AR_ATTACK (1<<4)
236#define FLAG_RANDOM_NONCE (1<<5)
237
238
239// iCLASS reader flags
240#define FLAG_ICLASS_READER_ONLY_ONCE 0x01
241#define FLAG_ICLASS_READER_CC 0x02
242#define FLAG_ICLASS_READER_CSN 0x04
243#define FLAG_ICLASS_READER_CONF 0x08
244#define FLAG_ICLASS_READER_AA 0x10
245#define FLAG_ICLASS_READER_ONE_TRY 0x20
246#define FLAG_ICLASS_READER_CEDITKEY 0x40
247
248// iCLASS simulation modes
249#define ICLASS_SIM_MODE_CSN 0
250#define ICLASS_SIM_MODE_CSN_DEFAULT 1
251#define ICLASS_SIM_MODE_READER_ATTACK 2
252#define ICLASS_SIM_MODE_FULL 3
253#define ICLASS_SIM_MODE_READER_ATTACK_KEYROLL 4
254#define ICLASS_SIM_MODE_EXIT_AFTER_MAC 5 // note: device internal only
255
256
257// hw tune args
258#define FLAG_TUNE_LF 1
259#define FLAG_TUNE_HF 2
260#define FLAG_TUNE_ALL 3
261
262// Hardware capabilities
263#define HAS_EXTRA_FLASH_MEM (1 << 0)
264#define HAS_SMARTCARD_SLOT (1 << 1)
265
266
267// CMD_DEVICE_INFO response packet has flags in arg[0], flag definitions:
268/* Whether a bootloader that understands the common_area is present */
269#define DEVICE_INFO_FLAG_BOOTROM_PRESENT (1<<0)
270
271/* Whether a osimage that understands the common_area is present */
272#define DEVICE_INFO_FLAG_OSIMAGE_PRESENT (1<<1)
273
274/* Set if the bootloader is currently executing */
275#define DEVICE_INFO_FLAG_CURRENT_MODE_BOOTROM (1<<2)
276
277/* Set if the OS is currently executing */
278#define DEVICE_INFO_FLAG_CURRENT_MODE_OS (1<<3)
279
280/* Set if this device understands the extend start flash command */
281#define DEVICE_INFO_FLAG_UNDERSTANDS_START_FLASH (1<<4)
282
283/* CMD_START_FLASH may have three arguments: start of area to flash,
284 end of area to flash, optional magic.
285 The bootrom will not allow to overwrite itself unless this magic
286 is given as third parameter */
287
288#define START_FLASH_MAGIC 0x54494f44 // 'DOIT'
289
290#endif
Impressum, Datenschutz