1 //-----------------------------------------------------------------------------
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
6 //-----------------------------------------------------------------------------
7 // Low frequency Noralsy tag commands
8 // ASK/Manchester, STT, RF/32, 96 bits long (some bits unknown)
9 //-----------------------------------------------------------------------------
10 #include "cmdlfnoralsy.h"
14 #include "proxmark3.h"
18 #include "cmdparser.h"
22 #include "protocols.h" // for T55xx config register definitions
23 #include "lfdemod.h" // parityTest
25 static int CmdHelp(const char *Cmd
);
27 int usage_lf_noralsy_clone(void){
28 PrintAndLog("clone a Noralsy tag to a T55x7 tag.");
29 PrintAndLog("Usage: lf noralsy clone [h] <card id> <year> <Q5>");
30 PrintAndLog("Options:");
31 PrintAndLog(" h : This help");
32 PrintAndLog(" <card id> : Noralsy card ID");
33 PrintAndLog(" <year> : Tag allocation year");
34 PrintAndLog(" <Q5> : specify write to Q5 (t5555 instead of t55x7)");
36 PrintAndLog("Sample: lf noralsy clone 112233");
40 int usage_lf_noralsy_sim(void) {
41 PrintAndLog("Enables simulation of Noralsy card with specified card number.");
42 PrintAndLog("Simulation runs until the button is pressed or another USB command is issued.");
44 PrintAndLog("Usage: lf noralsy sim [h] <card id> <year>");
45 PrintAndLog("Options:");
46 PrintAndLog(" h : This help");
47 PrintAndLog(" <card id> : Noralsy card ID");
48 PrintAndLog(" <year> : Tag allocation year");
50 PrintAndLog("Sample: lf noralsy sim 112233");
54 static uint8_t noralsy_chksum( uint8_t* bits
, uint8_t len
) {
56 for (uint8_t i
= 0; i
< len
; i
+= 4)
57 sum
^= bytebits_to_byte(bits
+i
, 4);
60 int getnoralsyBits(uint32_t id
, uint16_t year
, uint8_t *bits
) {
62 num_to_bytebits(0xBB0214FF, 32, bits
); // --> Have seen 0xBB0214FF / 0xBB0314FF UNKNOWN
66 uint16_t sub1
= (id
& 0xFFF0000) >> 16;
67 uint8_t sub2
= (id
& 0x000FF00) >> 8;
68 uint8_t sub3
= (id
& 0x00000FF);
70 num_to_bytebits(sub1
, 12, bits
+32);
71 num_to_bytebits(year
, 8, bits
+44);
72 num_to_bytebits(0, 4, bits
+52); // --> UNKNOWN. Flag?
74 num_to_bytebits(sub2
, 8, bits
+56);
75 num_to_bytebits(sub3
, 8, bits
+64);
78 uint8_t chksum
= noralsy_chksum(bits
+32, 40);
79 num_to_bytebits(chksum
, 4, bits
+72);
80 chksum
= noralsy_chksum(bits
, 76);
81 num_to_bytebits(chksum
, 4, bits
+76);
86 // find Noralsy preamble in already demoded data
87 int NoralsyDemod_AM(uint8_t *dest
, size_t *size
) {
88 if (*size
< 96) return -1; //make sure buffer has data
90 uint8_t preamble
[] = {1,0,1,1,1,0,1,1,0,0,0,0};
91 if (!preambleSearch(dest
, preamble
, sizeof(preamble
), size
, &startIdx
))
92 return -2; //preamble not found
93 if (*size
!= 96) return -3; //wrong demoded size
94 //return start position
100 * 2520116 | BB0214FF2529900116360000 | 10111011 00000011 00010100 11111111 00100101 00101001 10010000 00000001 00010110 00110110 00000000 00000000
101 * aaa*aaaaiiiYY*iiiicc---- **** iiiiiiii iiiiYYYY YYYY**** iiiiiiii iiiiiiii cccccccc
103 * a = fixed value BB0*14FF
104 * i = printed id, BCD-format
111 //see ASKDemod for what args are accepted
112 int CmdNoralsyDemod(const char *Cmd
) {
116 if (!ASKDemod_ext("32 0 0", false, false, 1, &st
)) {
117 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: ASK/Manchester Demod failed");
122 size_t size
= DemodBufferLen
;
123 int ans
= NoralsyDemod_AM(DemodBuffer
, &size
);
127 PrintAndLog("DEBUG: Error - Noralsy: too few bits found");
129 PrintAndLog("DEBUG: Error - Noralsy: preamble not found");
131 PrintAndLog("DEBUG: Error - Noralsy: Size not correct: %d", size
);
133 PrintAndLog("DEBUG: Error - Noralsy: ans: %d", ans
);
137 setDemodBuf(DemodBuffer
, 96, ans
);
141 uint32_t raw1
= bytebits_to_byte(DemodBuffer
, 32);
142 uint32_t raw2
= bytebits_to_byte(DemodBuffer
+32, 32);
143 uint32_t raw3
= bytebits_to_byte(DemodBuffer
+64, 32);
145 uint32_t cardid
= (bytebits_to_byte(DemodBuffer
+32, 12)<<16) | bytebits_to_byte(DemodBuffer
+32+24, 16);
147 uint16_t year
= (raw2
& 0x000ff000) >> 12;
148 year
+= ( year
> 0x60 ) ? 0x1900: 0x2000;
151 uint8_t calc1
= noralsy_chksum(DemodBuffer
+32, 40);
152 uint8_t calc2
= noralsy_chksum(DemodBuffer
, 76);
153 uint8_t chk1
= 0, chk2
= 0;
154 chk1
= bytebits_to_byte(DemodBuffer
+72, 4);
155 chk2
= bytebits_to_byte(DemodBuffer
+76, 4);
157 if ( chk1
!= calc1
) {
158 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 1 failed %x - %x\n", chk1
, calc1
);
161 if ( chk2
!= calc2
) {
162 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 2 failed %x - %x\n", chk2
, calc2
);
166 PrintAndLog("Noralsy Tag Found: Card ID %X, Year: %X Raw: %08X%08X%08X", cardid
, year
, raw1
,raw2
, raw3
);
167 if (raw1
!= 0xBB0214FF) {
168 PrintAndLog("Unknown bits set in first block! Expected 0xBB0214FF, Found: 0x%08X", raw1
);
169 PrintAndLog("Please post this output in forum to further research on this format");
174 int CmdNoralsyRead(const char *Cmd
) {
176 return CmdNoralsyDemod(Cmd
);
179 int CmdNoralsyClone(const char *Cmd
) {
183 uint32_t blocks
[4] = {T55x7_MODULATION_MANCHESTER
| T55x7_BITRATE_RF_32
| T55x7_ST_TERMINATOR
| 3 << T55x7_MAXBLOCK_SHIFT
, 0, 0};
186 memset(bs
, 0, sizeof(bits
));
188 char cmdp
= param_getchar(Cmd
, 0);
189 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_clone();
191 id
= param_get32ex(Cmd
, 0, 0, 16);
192 year
= param_get32ex(Cmd
, 1, 2000, 16);
195 if (param_getchar(Cmd
, 2) == 'Q' || param_getchar(Cmd
, 2) == 'q') {
196 //t5555 (Q5) BITRATE = (RF-2)/2 (iceman)
197 blocks
[0] = T5555_MODULATION_MANCHESTER
| ((32-2)>>1) << T5555_BITRATE_SHIFT
| T5555_ST_TERMINATOR
| 3 << T5555_MAXBLOCK_SHIFT
;
200 if ( !getnoralsyBits(id
, year
, bs
)) {
201 PrintAndLog("Error with tag bitstream generation.");
206 blocks
[1] = bytebits_to_byte(bs
,32);
207 blocks
[2] = bytebits_to_byte(bs
+32,32);
208 blocks
[3] = bytebits_to_byte(bs
+64,32);
210 PrintAndLog("Preparing to clone Noralsy to T55x7 with CardId: %x", id
);
211 PrintAndLog("Blk | Data ");
212 PrintAndLog("----+------------");
213 PrintAndLog(" 00 | 0x%08x", blocks
[0]);
214 PrintAndLog(" 01 | 0x%08x", blocks
[1]);
215 PrintAndLog(" 02 | 0x%08x", blocks
[2]);
216 PrintAndLog(" 03 | 0x%08x", blocks
[3]);
219 UsbCommand c
= {CMD_T55XX_WRITE_BLOCK
, {0,0,0}};
221 for (int i
= 3; i
>= 0; --i
) {
222 c
.arg
[0] = blocks
[i
];
224 clearCommandBuffer();
226 if (!WaitForResponseTimeout(CMD_ACK
, &resp
, T55XX_WRITE_TIMEOUT
)){
227 PrintAndLog("Error occurred, device did not respond during write operation.");
234 int CmdNoralsySim(const char *Cmd
) {
238 memset(bs
, 0, sizeof(bits
));
243 char cmdp
= param_getchar(Cmd
, 0);
244 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_sim();
246 id
= param_get32ex(Cmd
, 0, 0, 16);
247 year
= param_get32ex(Cmd
, 1, 2000, 16);
249 uint8_t clk
= 32, encoding
= 1, separator
= 1, invert
= 0;
252 arg1
= clk
<< 8 | encoding
;
253 arg2
= invert
<< 8 | separator
;
255 if ( !getnoralsyBits(id
, year
, bs
)) {
256 PrintAndLog("Error with tag bitstream generation.");
260 PrintAndLog("Simulating Noralsy - CardId: %x", id
);
262 UsbCommand c
= {CMD_ASK_SIM_TAG
, {arg1
, arg2
, size
}};
263 memcpy(c
.d
.asBytes
, bs
, size
);
264 clearCommandBuffer();
269 static command_t CommandTable
[] = {
270 {"help", CmdHelp
, 1, "This help"},
271 {"demod", CmdNoralsyDemod
,1, "Attempt to read and extract tag data from the GraphBuffer"},
272 {"read", CmdNoralsyRead
, 0, "Attempt to read and extract tag data from the antenna"},
273 {"clone", CmdNoralsyClone
,0, "clone Noralsy tag"},
274 {"sim", CmdNoralsySim
, 0, "simulate Noralsy tag"},
275 {NULL
, NULL
, 0, NULL
}
278 int CmdLFNoralsy(const char *Cmd
) {
279 clearCommandBuffer();
280 CmdsParse(CommandTable
, Cmd
);
284 int CmdHelp(const char *Cmd
) {
285 CmdsHelp(CommandTable
);