1 //-----------------------------------------------------------------------------
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
6 //-----------------------------------------------------------------------------
7 // Low frequency T55xx commands
8 //-----------------------------------------------------------------------------
13 #include "proxmark3.h"
17 #include "cmdparser.h"
20 #include "cmdlft55xx.h"
24 #include "../common/crc.h"
26 #define LF_TRACE_BUFF_SIZE 20000 // 32 x 32 x 10 (32 bit times numofblock (7), times clock skip..)
27 #define LF_BITSSTREAM_LEN 1000 // more then 1000 bits shouldn't happend.. 8block * 4 bytes * 8bits =
29 // Default configuration: ASK, not inversed.
30 t55xx_conf_block_t config
= { .modulation
= 2, .inversed
= FALSE
, .block0
= 0x00};
32 int usage_t55xx_config(){
33 PrintAndLog("Usage: lf t55xx config [d <demodulation>] [i 1]");
34 PrintAndLog("Options: ");
35 PrintAndLog(" h This help");
36 PrintAndLog(" d <FSK|ASK|PSK|NZ|BI> Set demodulation FSK / ASK / PSK / NZ / Biphase");
37 PrintAndLog(" i [1] Inverse data signal, defaults to normal");
39 PrintAndLog("Examples:");
40 PrintAndLog(" lf t55xx config d FSK - FSK demodulation");
41 PrintAndLog(" lf t55xx config d FSK i 1 - FSK demodulation, inverse data");
45 int usage_t55xx_read(){
46 PrintAndLog("Usage: lf t55xx read <block> <password>");
47 PrintAndLog(" <block>, block number to read. Between 0-7");
48 PrintAndLog(" <password>, OPTIONAL password (8 hex characters)");
50 PrintAndLog("Examples:");
51 PrintAndLog(" lf t55xx read 0 - read data from block 0");
52 PrintAndLog(" lf t55xx read 0 feedbeef - read data from block 0 password feedbeef");
56 int usage_t55xx_write(){
57 PrintAndLog("Usage: lf t55xx wr <block> <data> [password]");
58 PrintAndLog(" <block>, block number to read. Between 0-7");
59 PrintAndLog(" <data>, 4 bytes of data to write (8 hex characters)");
60 PrintAndLog(" [password], OPTIONAL password 4bytes (8 hex characters)");
62 PrintAndLog("Examples:");
63 PrintAndLog(" lf t55xx wd 3 11223344 - write 11223344 to block 3");
64 PrintAndLog(" lf t55xx wd 3 11223344 feedbeef - write 11223344 to block 3 password feedbeef");
68 int usage_t55xx_trace() {
69 PrintAndLog("Usage: lf t55xx trace [1]");
70 PrintAndLog(" [graph buffer data], if set, use Graphbuffer otherwise read data from tag.");
72 PrintAndLog("Examples:");
73 PrintAndLog(" lf t55xx trace");
74 PrintAndLog(" lf t55xx trace 1");
78 int usage_t55xx_info() {
79 PrintAndLog("Usage: lf t55xx info [1]");
80 PrintAndLog(" [graph buffer data], if set, use Graphbuffer otherwise read data from tag.");
82 PrintAndLog("Examples:");
83 PrintAndLog(" lf t55xx info");
84 PrintAndLog(" lf t55xx info 1");
88 int usage_t55xx_dump(){
89 PrintAndLog("Usage: lf t55xx dump <password>");
90 PrintAndLog(" <password>, OPTIONAL password 4bytes (8 hex symbols)");
92 PrintAndLog("Examples:");
93 PrintAndLog(" lf t55xx dump");
94 PrintAndLog(" lf t55xx dump feedbeef");
98 int usage_t55xx_detect(){
99 PrintAndLog("Usage: lf t55xx detect");
101 PrintAndLog("Examples:");
102 PrintAndLog(" lf t55xx detect");
103 PrintAndLog(" lf t55xx detect 1");
108 static int CmdHelp(const char *Cmd
);
110 int CmdT55xxSetConfig(const char *Cmd
){
113 int foundModulation
= 2;
114 bool inverse
= FALSE
;
117 char modulation
[4] = {0x00};
119 while(param_getchar(Cmd
, cmdp
) != 0x00 && !errors
)
121 switch(param_getchar(Cmd
, cmdp
))
125 return usage_t55xx_config();
127 len
= param_getstr(Cmd
, cmdp
+1, modulation
);
130 if ( strcmp(modulation
, "FSK" ) == 0)
132 else if ( strcmp(modulation
, "ASK" ) == 0)
134 else if ( strcmp(modulation
, "PSK" ) == 0)
136 else if ( strcmp(modulation
, "NZ" ) == 0)
138 else if ( strcmp(modulation
, "BI" ) == 0)
141 PrintAndLog("Unknown modulation '%s'", modulation
);
146 inverse
= param_getchar(Cmd
,cmdp
+1) == '1';
150 PrintAndLog("Unknown parameter '%c'", param_getchar(Cmd
, cmdp
));
157 printConfiguration( config
);
162 return usage_t55xx_config();
164 config
.modulation
= foundModulation
;
165 config
.inversed
= inverse
;
170 int CmdT55xxReadBlock(const char *Cmd
)
173 int password
= 0xFFFFFFFF; //default to blank Block 7
175 char cmdp
= param_getchar(Cmd
, 0);
176 if (cmdp
== 'h' || cmdp
== 'H')
177 return usage_t55xx_read();
179 int res
= sscanf(Cmd
, "%d %x", &block
, &password
);
181 if ( res
< 1 || res
> 2 )
182 return usage_t55xx_read();
185 if ((block
< 0) | (block
> 7)) {
186 PrintAndLog("Block must be between 0 and 7");
190 UsbCommand c
= {CMD_T55XX_READ_BLOCK
, {0, block
, 0}};
191 c
.d
.asBytes
[0] = 0x0;
196 c
.d
.asBytes
[0] = 0x1;
200 if ( !WaitForResponseTimeout(CMD_ACK
,NULL
,2500) ) {
201 PrintAndLog("command execution time out");
206 GetFromBigBuf(got
,sizeof(got
),0);
207 WaitForResponse(CMD_ACK
,NULL
);
208 setGraphBuf(got
, 12000);
215 void DecodeT55xxBlock(){
217 char buf
[6] = {0x00};
220 // clearing the DemodBuffer.
221 DemodBufferLen
= 0x00;
223 // use the configuration
224 switch( config
.modulation
){
226 sprintf(cmdStr
,"0 %d", config
.inversed
);
227 FSKrawDemod(cmdStr
, FALSE
);
230 sprintf(cmdStr
,"0 %d 1", config
.inversed
);
231 ASKmanDemod(cmdStr
, FALSE
, FALSE
);
234 sprintf(cmdStr
,"0 %d 1", config
.inversed
);
235 PSKDemod(cmdStr
, FALSE
);
238 sprintf(cmdStr
,"0 %d 1", config
.inversed
);
239 NRZrawDemod(cmdStr
, FALSE
);
242 //BiphaseRawDecode("0",FALSE);
249 int CmdT55xxDetect(const char *Cmd
){
250 char cmdp
= param_getchar(Cmd
, 0);
251 if (cmdp
== 'h' || cmdp
== 'H')
252 return usage_t55xx_detect();
254 // read block 0, Page 0. Configuration.
255 UsbCommand c
= {CMD_T55XX_READ_BLOCK
, {0, 0, 0}};
256 c
.d
.asBytes
[0] = 0x0;
260 // c.arg[2] = password;
261 // c.d.asBytes[0] = 0x1;
265 if ( !WaitForResponseTimeout(CMD_ACK
,NULL
,2500) ) {
266 PrintAndLog("command execution time out");
271 GetFromBigBuf(got
,sizeof(got
),0);
272 WaitForResponse(CMD_ACK
,NULL
);
273 setGraphBuf(got
, 12000);
275 if ( !tryDetectModulation() ){
276 PrintAndLog("Could not detect modulation automatically. Try setting it manually with \'lf t55xx config\'");
281 // detect configuration?
282 bool tryDetectModulation(){
285 t55xx_conf_block_t tests
[10];
287 if (GetFskClock("", FALSE
, FALSE
)){
288 if ( FSKrawDemod("0 0", FALSE
) && test()){
289 tests
[hits
].modulation
= DEMOD_FSK
;
290 tests
[hits
].inversed
= FALSE
;
293 if ( FSKrawDemod("0 1", FALSE
) && test()) {
294 tests
[hits
].modulation
= DEMOD_FSK
;
295 tests
[hits
].inversed
= TRUE
;
299 if ( ASKmanDemod("0 0 1", FALSE
, FALSE
) && test()) {
300 tests
[hits
].modulation
= DEMOD_ASK
;
301 tests
[hits
].inversed
= FALSE
;
305 if ( ASKmanDemod("0 1 1", FALSE
, FALSE
) && test()) {
306 tests
[hits
].modulation
= DEMOD_ASK
;
307 tests
[hits
].inversed
= TRUE
;
311 if ( NRZrawDemod("0 0 1", FALSE
) && test()) {
312 tests
[hits
].modulation
= DEMOD_NZR
;
313 tests
[hits
].inversed
= FALSE
;
317 if ( NRZrawDemod("0 1 1", FALSE
) && test()) {
318 tests
[hits
].modulation
= DEMOD_NZR
;
319 tests
[hits
].inversed
= TRUE
;
323 if ( PSKDemod("0 0 1", FALSE
) && test()) {
324 tests
[hits
].modulation
= DEMOD_PSK
;
325 tests
[hits
].inversed
= FALSE
;
329 if ( PSKDemod("0 1 1", FALSE
) && test()) {
330 tests
[++hits
].modulation
= DEMOD_PSK
;
331 tests
[hits
].inversed
= TRUE
;
335 // if (!BiphaseRawDecode("0",FALSE) && test()) {
336 // tests[++hits].modulation = DEMOD_BI;
337 // tests[hits].inversed = FALSE;
339 // if (!BiphaseRawDecode("1",FALSE) && test()) {
340 // tests[++hits].modulation = DEMOD_BI;
341 // tests[hits].inversed = TRUE;
345 config
.modulation
= tests
[0].modulation
;
346 config
.inversed
= tests
[0].inversed
;
347 printConfiguration( config
);
352 PrintAndLog("Found [%d] possible matches for modulation.",hits
);
353 for(int i
=0; i
<hits
; ++i
){
354 printConfiguration( tests
[i
] );
362 if ( !DemodBufferLen
)
366 uint8_t safer
= PackBits(si
, 4, DemodBuffer
); si
+= 4;
367 uint8_t resv
= PackBits(si
, 7, DemodBuffer
); si
+= 7+3;
368 uint8_t extend
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
370 //PrintAndLog("test: %X %X %X ", safer, resv, extend);
372 // 2nibble must be zeroed.
373 if ( resv
> 0x00) return FALSE
;
375 if ( safer
== 0x6 || safer
== 0x9){
379 if ( resv
== 0x00) return TRUE
;
383 void printT55xxBlock(const char *demodStr
){
385 uint32_t blockData
= 0;
386 uint8_t bits
[MAX_GRAPH_TRACE_LEN
] = {0x00};
388 if ( !DemodBufferLen
)
392 for (;i
<DemodBufferLen
;++i
)
393 bits
[i
]=DemodBuffer
[i
];
395 blockData
= PackBits(1, 32, bits
);
396 PrintAndLog("0x%08X %s [%s]", blockData
, sprint_bin(bits
+1,32), demodStr
);
399 void printConfiguration( t55xx_conf_block_t b
){
400 PrintAndLog("Modulation : %s", GetSelectedModulationStr(b
.modulation
) );
401 PrintAndLog("Inverted : %s", (b
.inversed
) ? "Yes" : "No" );
402 PrintAndLog("Block0 : %08X", b
.block0
);
406 int CmdT55xxWriteBlock(const char *Cmd
)
408 int block
= 8; //default to invalid block
409 int data
= 0xFFFFFFFF; //default to blank Block
410 int password
= 0xFFFFFFFF; //default to blank Block 7
412 char cmdp
= param_getchar(Cmd
, 0);
413 if (cmdp
== 'h' || cmdp
== 'H') {
418 int res
= sscanf(Cmd
, "%d %x %x",&block
, &data
, &password
);
420 if ( res
< 2 || res
> 3) {
426 PrintAndLog("Block must be between 0 and 7");
430 UsbCommand c
= {CMD_T55XX_WRITE_BLOCK
, {data
, block
, 0}};
431 c
.d
.asBytes
[0] = 0x0;
433 PrintAndLog("Writing to T55x7");
434 PrintAndLog("block : %d", block
);
435 PrintAndLog("data : 0x%08X", data
);
440 c
.d
.asBytes
[0] = 0x1;
441 PrintAndLog("pwd : 0x%08X", password
);
447 int CmdT55xxReadTrace(const char *Cmd
)
449 char cmdp
= param_getchar(Cmd
, 0);
451 if (strlen(Cmd
) > 1 || cmdp
== 'h' || cmdp
== 'H')
452 return usage_t55xx_trace();
454 if ( strlen(Cmd
)==0){
456 UsbCommand c
= {CMD_T55XX_READ_TRACE
, {0, 0, 0}};
458 if ( !WaitForResponseTimeout(CMD_ACK
,NULL
,2500) ) {
459 PrintAndLog("command execution time out");
464 GetFromBigBuf(got
,sizeof(got
),0);
465 WaitForResponse(CMD_ACK
,NULL
);
466 setGraphBuf(got
, 12000);
471 if ( !DemodBufferLen
)
474 RepaintGraphWindow();
477 uint32_t bl0
= PackBits(si
, 32, DemodBuffer
);
478 uint32_t bl1
= PackBits(si
+32, 32, DemodBuffer
);
480 uint32_t acl
= PackBits(si
, 8, DemodBuffer
); si
+= 8;
481 uint32_t mfc
= PackBits(si
, 8, DemodBuffer
); si
+= 8;
482 uint32_t cid
= PackBits(si
, 5, DemodBuffer
); si
+= 5;
483 uint32_t icr
= PackBits(si
, 3, DemodBuffer
); si
+= 3;
484 uint32_t year
= PackBits(si
, 4, DemodBuffer
); si
+= 4;
485 uint32_t quarter
= PackBits(si
, 2, DemodBuffer
); si
+= 2;
486 uint32_t lotid
= PackBits(si
, 12, DemodBuffer
); si
+= 12;
487 uint32_t wafer
= PackBits(si
, 5, DemodBuffer
); si
+= 5;
488 uint32_t dw
= PackBits(si
, 15, DemodBuffer
);
493 PrintAndLog("-- T55xx Trace Information ----------------------------------");
494 PrintAndLog("-------------------------------------------------------------");
495 PrintAndLog(" ACL Allocation class (ISO/IEC 15963-1) : 0x%02X (%d)", acl
, acl
);
496 PrintAndLog(" MFC Manufacturer ID (ISO/IEC 7816-6) : 0x%02X (%d)", mfc
, mfc
);
497 PrintAndLog(" CID : 0x%02X (%d)", cid
, cid
);
498 PrintAndLog(" ICR IC Revision : %d",icr
);
499 PrintAndLog(" Manufactured");
500 PrintAndLog(" Year/Quarter : %d/%d",year
, quarter
);
501 PrintAndLog(" Lot ID : %d", lotid
);
502 PrintAndLog(" Wafer number : %d", wafer
);
503 PrintAndLog(" Die Number : %d", dw
);
504 PrintAndLog("-------------------------------------------------------------");
505 PrintAndLog(" Raw Data - Page 1");
506 PrintAndLog(" Block 0 : 0x%08X %s", bl0
, sprint_bin(DemodBuffer
+5,32) );
507 PrintAndLog(" Block 1 : 0x%08X %s", bl1
, sprint_bin(DemodBuffer
+37,32) );
508 PrintAndLog("-------------------------------------------------------------");
512 1-8 ACL Allocation class (ISO/IEC 15963-1) 0xE0
513 9-16 MFC Manufacturer ID (ISO/IEC 7816-6) 0x15 Atmel Corporation
514 17-21 CID 0x1 = Atmel ATA5577M1 0x2 = Atmel ATA5577M2
515 22-24 ICR IC revision
516 25-28 YEAR (BCD encoded) 9 (= 2009)
517 29-30 QUARTER 1,2,3,4
523 18-32 DW, die number sequential
529 int CmdT55xxInfo(const char *Cmd
){
531 Page 0 Block 0 Configuration data.
535 char cmdp
= param_getchar(Cmd
, 0);
537 if (cmdp
== 'h' || cmdp
== 'H')
538 return usage_t55xx_info();
542 // read block 0, Page 0. Configuration.
543 UsbCommand c
= {CMD_T55XX_READ_BLOCK
, {0, 0, 0}};
544 c
.d
.asBytes
[0] = 0x0;
548 // c.arg[2] = password;
549 // c.d.asBytes[0] = 0x1;
553 if ( !WaitForResponseTimeout(CMD_ACK
,NULL
,2500) ) {
554 PrintAndLog("command execution time out");
559 GetFromBigBuf(got
,sizeof(got
),0);
560 WaitForResponse(CMD_ACK
,NULL
);
561 setGraphBuf(got
, 12000);
566 if ( !DemodBufferLen
)
571 uint32_t bl0
= PackBits(si
, 32, DemodBuffer
);
573 uint32_t safer
= PackBits(si
, 4, DemodBuffer
); si
+= 4;
574 uint32_t resv
= PackBits(si
, 7, DemodBuffer
); si
+= 7;
575 uint32_t dbr
= PackBits(si
, 3, DemodBuffer
); si
+= 3;
576 uint32_t extend
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
577 uint32_t datamod
= PackBits(si
, 5, DemodBuffer
); si
+= 5;
578 uint32_t pskcf
= PackBits(si
, 2, DemodBuffer
); si
+= 2;
579 uint32_t aor
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
580 uint32_t otp
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
581 uint32_t maxblk
= PackBits(si
, 3, DemodBuffer
); si
+= 3;
582 uint32_t pwd
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
583 uint32_t sst
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
584 uint32_t fw
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
585 uint32_t inv
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
586 uint32_t por
= PackBits(si
, 1, DemodBuffer
); si
+= 1;
589 PrintAndLog("-- T55xx Configuration & Tag Information --------------------");
590 PrintAndLog("-------------------------------------------------------------");
591 PrintAndLog(" Safer key : %s", GetSaferStr(safer
));
592 PrintAndLog(" reserved : %d", resv
);
593 PrintAndLog(" Data bit rate : %s", GetBitRateStr(dbr
));
594 PrintAndLog(" eXtended mode : %s", (extend
) ? "Yes - Warning":"No");
595 PrintAndLog(" Modulation : %s", GetModulationStr(datamod
));
596 PrintAndLog(" PSK clock freq : %d", pskcf
);
597 PrintAndLog(" AOR - Answer on Request : %s", (aor
) ? "Yes":"No");
598 PrintAndLog(" OTP - One Time Pad : %s", (otp
) ? "Yes - Warning":"No" );
599 PrintAndLog(" Max block : %d", maxblk
);
600 PrintAndLog(" Password mode : %s", (pwd
) ? "Yes":"No");
601 PrintAndLog(" Sequence Start Terminator : %s", (sst
) ? "Yes":"No");
602 PrintAndLog(" Fast Write : %s", (fw
) ? "Yes":"No");
603 PrintAndLog(" Inverse data : %s", (inv
) ? "Yes":"No");
604 PrintAndLog(" POR-Delay : %s", (por
) ? "Yes":"No");
605 PrintAndLog("-------------------------------------------------------------");
606 PrintAndLog(" Raw Data - Page 0");
607 PrintAndLog(" Block 0 : 0x%08X %s", bl0
, sprint_bin(DemodBuffer
+5,32) );
608 PrintAndLog("-------------------------------------------------------------");
613 int CmdT55xxDump(const char *Cmd
){
616 uint8_t pwd
[4] = {0x00};
618 char cmdp
= param_getchar(Cmd
, 0);
619 if ( cmdp
== 'h' || cmdp
== 'H') {
624 bool hasPwd
= ( strlen(Cmd
) > 0);
626 if (param_gethex(Cmd
, 0, pwd
, 8)) {
627 PrintAndLog("password must include 8 HEX symbols");
632 for ( int i
= 0; i
<8; ++i
){
633 memset(s
,0,sizeof(s
));
635 sprintf(s
,"%d %02x%02x%02x%02x", i
, pwd
[0],pwd
[1],pwd
[2],pwd
[3]);
639 CmdT55xxReadBlock(s
);
644 char * GetBitRateStr(uint32_t id
){
649 sprintf(retStr
,"%d - RF/8",id
);
652 sprintf(retStr
,"%d - RF/16",id
);
655 sprintf(retStr
,"%d - RF/32",id
);
658 sprintf(retStr
,"%d - RF/40",id
);
661 sprintf(retStr
,"%d - RF/50",id
);
664 sprintf(retStr
,"%d - RF/64",id
);
667 sprintf(retStr
,"%d - RF/100",id
);
670 sprintf(retStr
,"%d - RF/128",id
);
673 sprintf(retStr
,"%d - (Unknown)",id
);
680 char * GetSaferStr(uint32_t id
){
684 sprintf(retStr
,"%d",id
);
686 sprintf(retStr
,"%d - passwd",id
);
689 sprintf(retStr
,"%d - testmode",id
);
694 char * GetModulationStr( uint32_t id
){
700 sprintf(retStr
,"%d - DIRECT (ASK/NRZ)",id
);
703 sprintf(retStr
,"%d - PSK 1 phase change when input changes",id
);
706 sprintf(retStr
,"%d - PSK 2 phase change on bitclk if input high",id
);
709 sprintf(retStr
,"%d - PSK 3 phase change on rising edge of input",id
);
712 sprintf(retStr
,"%d - FSK 1 RF/8 RF/5",id
);
715 sprintf(retStr
,"%d - FSK 2 RF/8 RF/10",id
);
718 sprintf(retStr
,"%d - FSK 1a RF/5 RF/8",id
);
721 sprintf(retStr
,"%d - FSK 2a RF/10 RF/8",id
);
724 sprintf(retStr
,"%d - Manschester",id
);
727 sprintf(retStr
,"%d - Biphase",id
);
730 sprintf(retStr
,"%d - Reserved",id
);
733 sprintf(retStr
,"0x%02X (Unknown)",id
);
739 char * GetSelectedModulationStr( uint8_t id
){
746 sprintf(retStr
,"FSK (%d)",id
);
749 sprintf(retStr
,"ASK (%d)",id
);
752 sprintf(retStr
,"DIRECT/NRZ (%d)",id
);
755 sprintf(retStr
,"PSK (%d)",id
);
758 sprintf(retStr
,"BIPHASE (%d)",id
);
761 sprintf(retStr
,"(Unknown)");
767 uint32_t PackBits(uint8_t start
, uint8_t len
, uint8_t* bits
){
775 for (; j
>= 0; --j
, ++i
){
781 static command_t CommandTable
[] =
783 {"help", CmdHelp
, 1, "This help"},
784 {"config", CmdT55xxSetConfig
, 1, "Set T55XX config for modulation, inversed data"},
785 {"detect", CmdT55xxDetect
, 0, "Try detecting the tag modulation from reading the configuration block."},
786 {"read", CmdT55xxReadBlock
, 0, "<block> [password] -- Read T55xx block data (page 0) [optional password]"},
787 {"write", CmdT55xxWriteBlock
,0, "<block> <data> [password] -- Write T55xx block data (page 0) [optional password]"},
788 {"trace", CmdT55xxReadTrace
, 0, "[1] Show T55xx traceability data (page 1/ blk 0-1)"},
789 {"info", CmdT55xxInfo
, 0, "[1] Show T55xx configuration data (page 0/ blk 0)"},
790 {"dump", CmdT55xxDump
, 0, "[password] Dump T55xx card block 0-7. [optional password]"},
791 {NULL
, NULL
, 0, NULL
}
794 int CmdLFT55XX(const char *Cmd
)
796 CmdsParse(CommandTable
, Cmd
);
800 int CmdHelp(const char *Cmd
)
802 CmdsHelp(CommandTable
);