1 //-----------------------------------------------------------------------------
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
6 //-----------------------------------------------------------------------------
7 // Low frequency Presco tag commands
8 //-----------------------------------------------------------------------------
11 #include "cmdlfpresco.h"
12 #include "proxmark3.h"
16 #include "cmdparser.h"
20 #include "protocols.h" // for T55xx config register definitions
21 #include "lfdemod.h" // parityTest
23 static int CmdHelp(const char *Cmd
);
25 int usage_lf_presco_clone(void){
26 PrintAndLog("clone a Presco tag to a T55x7 tag.");
27 PrintAndLog("Usage: lf presco clone d <Card-ID> H <hex-ID> <Q5>");
28 PrintAndLog("Options :");
29 PrintAndLog(" d <Card-ID> : 9 digit presco card ID");
30 PrintAndLog(" H <hex-ID> : 8 digit hex card number");
31 PrintAndLog(" <Q5> : specify write to Q5 (t5555 instead of t55x7)");
33 PrintAndLog("Sample : lf presco clone d 123456789");
37 int usage_lf_presco_sim(void) {
38 PrintAndLog("Enables simulation of presco card with specified card number.");
39 PrintAndLog("Simulation runs until the button is pressed or another USB command is issued.");
40 PrintAndLog("Per presco format, the card number is 9 digit number and can contain *# chars. Larger values are truncated.");
42 PrintAndLog("Usage: lf presco sim d <Card-ID> or H <hex-ID>");
43 PrintAndLog("Options :");
44 PrintAndLog(" d <Card-ID> : 9 digit presco card number");
45 PrintAndLog(" H <hex-ID> : 8 digit hex card number");
47 PrintAndLog("Sample : lf presco sim d 123456789");
51 // convert base 12 ID to sitecode & usercode & 8 bit other unknown code
52 int GetWiegandFromPresco(const char *Cmd
, uint32_t *sitecode
, uint32_t *usercode
, uint32_t *fullcode
, bool *Q5
) {
55 bool hex
= false, errors
= false;
59 while(param_getchar(Cmd
, cmdp
) != 0x00) {
60 switch(param_getchar(Cmd
, cmdp
)) {
66 *fullcode
= param_get32ex(Cmd
, cmdp
+1, 0, 10);
71 //param get string int param_getstr(const char *line, int paramnum, char * str)
72 stringlen
= param_getstr(Cmd
, cmdp
+1, id
);
73 if (stringlen
< 2) return -1;
82 PrintAndLog("Unknown parameter '%c'", param_getchar(Cmd
, cmdp
));
89 if(cmdp
== 0) errors
= 1;
95 for (int index
=0; index
< strlen(id
); ++index
) {
96 // Get value from number string.
97 if ( id
[index
] == '*' ) val
= 10;
98 if ( id
[index
] == '#') val
= 11;
99 if ( id
[index
] >= 0x30 && id
[index
] <= 0x39 )
100 val
= id
[index
] - 0x30;
104 // last digit is only added, not multipled.
105 if ( index
< strlen(id
)-1 )
110 *usercode
= *fullcode
& 0x0000FFFF; //% 65566
111 *sitecode
= (*fullcode
>> 24) & 0x000000FF; // /= 16777216;
115 // calc not certain - intended to get bitstream for programming / sim
116 int GetPrescoBits(uint32_t fullcode
, uint8_t *prescoBits
) {
117 num_to_bytebits(0x10D00000, 32, prescoBits
);
118 num_to_bytebits(0x00000000, 32, prescoBits
+32);
119 num_to_bytebits(0x00000000, 32, prescoBits
+64);
120 num_to_bytebits(fullcode
, 32, prescoBits
+96);
124 //see ASKDemod for what args are accepted
125 int CmdPrescoDemod(const char *Cmd
) {
126 if (!ASKDemod(Cmd
, false, false, 1)) {
127 if (g_debugMode
) PrintAndLog("ASKDemod failed");
130 size_t size
= DemodBufferLen
;
131 //call lfdemod.c demod for Viking
132 int ans
= PrescoDemod(DemodBuffer
, &size
);
134 if (g_debugMode
) PrintAndLog("Error Presco_Demod %d", ans
);
138 uint32_t raw1
= bytebits_to_byte(DemodBuffer
+ans
, 32);
139 uint32_t raw2
= bytebits_to_byte(DemodBuffer
+ans
+32, 32);
140 uint32_t raw3
= bytebits_to_byte(DemodBuffer
+ans
+64, 32);
141 uint32_t raw4
= bytebits_to_byte(DemodBuffer
+ans
+96, 32);
142 uint32_t cardid
= raw4
;
143 PrintAndLog("Presco Tag Found: Card ID %08X", cardid
);
144 PrintAndLog("Raw: %08X%08X%08X%08X", raw1
,raw2
,raw3
,raw4
);
145 setDemodBuf(DemodBuffer
+ans
, 128, 0);
147 uint32_t sitecode
= 0, usercode
= 0, fullcode
= 0;
150 sprintf(cmd
, "H %08X", cardid
);
151 GetWiegandFromPresco(cmd
, &sitecode
, &usercode
, &fullcode
, &Q5
);
152 PrintAndLog("SiteCode %u, UserCode %u, FullCode, %08X", sitecode
, usercode
, fullcode
);
157 //see ASKDemod for what args are accepted
158 int CmdPrescoRead(const char *Cmd
) {
159 // Presco Number: 123456789 --> Sitecode 30 | usercode 8665
163 // get samples silently
164 getSamples("30000",false);
165 // demod and output Presco ID
166 return CmdPrescoDemod(Cmd
);
169 // takes base 12 ID converts to hex
170 // Or takes 8 digit hex ID
171 int CmdPrescoClone(const char *Cmd
) {
174 uint32_t sitecode
=0, usercode
=0, fullcode
=0;
175 uint32_t blocks
[5] = {T55x7_MODULATION_MANCHESTER
| T55x7_BITRATE_RF_32
| 4<<T55x7_MAXBLOCK_SHIFT
| T55x7_ST_TERMINATOR
, 0, 0, 0, 5};
177 // get wiegand from printed number.
178 if (GetWiegandFromPresco(Cmd
, &sitecode
, &usercode
, &fullcode
, &Q5
) == -1) return usage_lf_presco_clone();
181 blocks
[0] = T5555_MODULATION_MANCHESTER
| ((32-2)>>1)<<T5555_BITRATE_SHIFT
| 4<<T5555_MAXBLOCK_SHIFT
| T5555_ST_TERMINATOR
;
183 if ((sitecode
& 0xFF) != sitecode
) {
185 PrintAndLog("Facility-Code Truncated to 8-bits (Presco): %u", sitecode
);
188 if ((usercode
& 0xFFFF) != usercode
) {
190 PrintAndLog("Card Number Truncated to 16-bits (Presco): %u", usercode
);
193 blocks
[1] = 0x10D00000; //preamble
194 blocks
[2] = 0x00000000;
195 blocks
[3] = 0x00000000;
196 blocks
[4] = fullcode
;
198 PrintAndLog("Preparing to clone Presco to T55x7 with SiteCode: %u, UserCode: %u, FullCode: %08x", sitecode
, usercode
, fullcode
);
199 PrintAndLog("Blk | Data ");
200 PrintAndLog("----+------------");
201 PrintAndLog(" 00 | 0x%08x", blocks
[0]);
202 PrintAndLog(" 01 | 0x%08x", blocks
[1]);
203 PrintAndLog(" 02 | 0x%08x", blocks
[2]);
204 PrintAndLog(" 03 | 0x%08x", blocks
[3]);
205 PrintAndLog(" 04 | 0x%08x", blocks
[4]);
208 UsbCommand c
= {CMD_T55XX_WRITE_BLOCK
, {0,0,0}};
210 for (int i
=4; i
>=0; i
--) {
211 c
.arg
[0] = blocks
[i
];
213 clearCommandBuffer();
215 if (!WaitForResponseTimeout(CMD_ACK
, &resp
, 1000)){
216 PrintAndLog("Error occurred, device did not respond during write operation.");
223 // takes base 12 ID converts to hex
224 // Or takes 8 digit hex ID
225 int CmdPrescoSim(const char *Cmd
) {
226 uint32_t sitecode
=0, usercode
=0, fullcode
=0;
228 // get wiegand from printed number.
229 if (GetWiegandFromPresco(Cmd
, &sitecode
, &usercode
, &fullcode
, &Q5
) == -1) return usage_lf_presco_sim();
231 uint8_t clk
= 32, encoding
= 1, separator
= 1, invert
= 0;
234 arg1
= clk
<< 8 | encoding
;
235 arg2
= invert
<< 8 | separator
;
237 PrintAndLog("Simulating Presco - SiteCode: %u, UserCode: %u, FullCode: %08X",sitecode
, usercode
, fullcode
);
239 UsbCommand c
= {CMD_ASK_SIM_TAG
, {arg1
, arg2
, size
}};
240 GetPrescoBits(fullcode
, c
.d
.asBytes
);
241 clearCommandBuffer();
246 static command_t CommandTable
[] = {
247 {"help", CmdHelp
, 1, "This help"},
248 {"read", CmdPrescoRead
, 0, "Attempt to read and Extract tag data"},
249 {"clone", CmdPrescoClone
, 0, "d <9 digit ID> or h <hex> [Q5] clone presco tag"},
250 {"sim", CmdPrescoSim
, 0, "d <9 digit ID> or h <hex> simulate presco tag"},
251 {NULL
, NULL
, 0, NULL
}
254 int CmdLFPresco(const char *Cmd
) {
255 clearCommandBuffer();
256 CmdsParse(CommandTable
, Cmd
);
260 int CmdHelp(const char *Cmd
) {
261 CmdsHelp(CommandTable
);