]>
cvs.zerfleddert.de Git - proxmark3-svn/blob - client/cmdhficlass.c
1 //-----------------------------------------------------------------------------
2 // Copyright (C) 2010 iZsh <izsh at fail0verflow.com>, Hagen Fritsch
3 // Copyright (C) 2011 Gerhard de Koning Gans
5 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
6 // at your option, any later version. See the LICENSE.txt file for the text of
8 //-----------------------------------------------------------------------------
9 // High frequency iClass commands
10 //-----------------------------------------------------------------------------
15 #include "iso14443crc.h" // Can also be used for iClass, using 0xE012 as CRC-type
17 //#include "proxusb.h"
18 #include "proxmark3.h"
20 #include "cmdparser.h"
21 #include "cmdhficlass.h"
25 static int CmdHelp(const char *Cmd
);
27 int CmdHFiClassList(const char *Cmd
)
30 GetFromBigBuf(got
,sizeof(got
),0);
32 PrintAndLog("recorded activity:");
33 PrintAndLog(" ETU :rssi: who bytes");
34 PrintAndLog("---------+----+----+-----------");
45 int timestamp
= *((uint32_t *)(got
+i
));
46 if (timestamp
& 0x80000000) {
47 timestamp
&= 0x7fffffff;
54 int parityBits
= *((uint32_t *)(got
+i
+4));
55 // 4 bytes of additional information...
56 // maximum of 32 additional parity bit information
59 // at each quarter bit period we can send power level (16 levels)
60 // or each half bit period in 256 levels.
68 if (i
+ len
>= 1900) {
72 uint8_t *frame
= (got
+i
+9);
74 // Break and stick with current result if buffer was not completely full
75 if (frame
[0] == 0x44 && frame
[1] == 0x44 && frame
[3] == 0x44) { break; }
79 for (j
= 0; j
< len
; j
++) {
84 oddparity
^= (((frame
[j
] & 0xFF) >> k
) & 0x01);
87 //if((parityBits >> (len - j - 1)) & 0x01) {
88 if (isResponse
&& (oddparity
!= ((parityBits
>> (len
- j
- 1)) & 0x01))) {
89 sprintf(line
+(j
*4), "%02x! ", frame
[j
]);
92 sprintf(line
+(j
*4), "%02x ", frame
[j
]);
100 for (j
= 0; j
< (len
- 1); j
++) {
101 // gives problems... search for the reason..
102 /*if(frame[j] == 0xAA) {
105 crc = "[1] Two drops close after each other";
108 crc = "[2] Potential SOC with a drop in second half of bitperiod";
111 crc = "[3] Segment Z after segment X is not possible";
114 crc = "[4] Parity bit of a fully received byte was wrong";
117 crc = "[?] Unknown error";
124 if (strlen(crc
)==0) {
125 if(!isResponse
&& len
== 4) {
126 // Rough guess that this is a command from the reader
127 // For iClass the command byte is not part of the CRC
128 ComputeCrc14443(CRC_ICLASS
, &frame
[1], len
-3, &b1
, &b2
);
131 // For other data.. CRC might not be applicable (UPDATE commands etc.)
132 ComputeCrc14443(CRC_ICLASS
, frame
, len
-2, &b1
, &b2
);
134 //printf("%1x %1x",(unsigned)b1,(unsigned)b2);
135 if (b1
!= frame
[len
-2] || b2
!= frame
[len
-1]) {
136 crc
= (isResponse
& (len
< 8)) ? "" : " !crc";
145 char metricString
[100];
147 sprintf(metricString
, "%3d", metric
);
149 strcpy(metricString
, " ");
152 PrintAndLog(" +%7d: %s: %s %s %s",
153 (prev
< 0 ? 0 : (timestamp
- prev
)),
155 (isResponse
? "TAG" : " "), line
, crc
);
163 /*void iso14a_set_timeout(uint32_t timeout) {
164 UsbCommand c = {CMD_READER_ISO_14443a, {ISO14A_SET_TIMEOUT, 0, timeout}};
168 int CmdHFiClassSnoop(const char *Cmd
)
170 UsbCommand c
= {CMD_SNOOP_ICLASS
};
175 int CmdHFiClassSim(const char *Cmd
)
178 uint8_t CSN
[8] = {0, 0, 0, 0, 0, 0, 0, 0};
181 PrintAndLog("Usage: hf iclass sim <sim type> <CSN (16 hex symbols)>");
182 PrintAndLog(" sample: hf iclass sim 0 031FEC8AF7FF12E0");
186 simType
= param_get8(Cmd
, 0);
187 if (param_gethex(Cmd
, 1, CSN
, 16)) {
188 PrintAndLog("A CSN should consist of 16 HEX symbols");
191 PrintAndLog("--simtype:%02x csn:%s", simType
, sprint_hex(CSN
, 8));
193 UsbCommand c
= {CMD_SIMULATE_TAG_ICLASS
, {simType
}};
194 memcpy(c
.d
.asBytes
, CSN
, 8);
197 /*UsbCommand * resp = WaitForResponseTimeout(CMD_ACK, 1500);
199 uint8_t isOK = resp->arg[0] & 0xff;
200 PrintAndLog("isOk:%02x", isOK);
202 PrintAndLog("Command execute timeout");
208 int CmdHFiClassReader(const char *Cmd
)
210 uint8_t readerType
= 0;
213 PrintAndLog("Usage: hf iclass reader <reader type>");
214 PrintAndLog(" sample: hf iclass reader 0");
218 readerType
= param_get8(Cmd
, 0);
219 PrintAndLog("--readertype:%02x", readerType
);
221 UsbCommand c
= {CMD_READER_ICLASS
, {readerType
}};
227 int CmdHFiClassReader_Replay(const char *Cmd
)
229 uint8_t readerType
= 0;
230 uint8_t MAC
[4]={0x00, 0x00, 0x00, 0x00};
233 PrintAndLog("Usage: hf iclass replay <MAC>");
234 PrintAndLog(" sample: hf iclass replay 00112233");
238 if (param_gethex(Cmd
, 0, MAC
, 8)) {
239 PrintAndLog("MAC must include 8 HEX symbols");
243 UsbCommand c
= {CMD_READER_ICLASS_REPLAY
, {readerType
}};
244 memcpy(c
.d
.asBytes
, MAC
, 4);
251 static command_t CommandTable
[] =
253 {"help", CmdHelp
, 1, "This help"},
254 {"list", CmdHFiClassList
, 0, "List iClass history"},
255 {"snoop", CmdHFiClassSnoop
, 0, "Eavesdrop iClass communication"},
256 {"sim", CmdHFiClassSim
, 0, "Simulate iClass tag"},
257 {"reader", CmdHFiClassReader
, 0, "Read an iClass tag"},
258 {"replay", CmdHFiClassReader_Replay
, 0, "Read an iClass tag via Reply Attack"},
259 {NULL
, NULL
, 0, NULL
}
262 int CmdHFiClass(const char *Cmd
)
264 CmdsParse(CommandTable
, Cmd
);
268 int CmdHelp(const char *Cmd
)
270 CmdsHelp(CommandTable
);