-int CmdHF14AMfUCRdCard(const char *Cmd){
- int i;
- uint8_t BlockNo = 0;
- int Pages=44;
- uint8_t *lockbytes_t=NULL;
- uint8_t lockbytes[2]={0x00};
- uint8_t *lockbytes_t2=NULL;
- uint8_t lockbytes2[2]={0x00};
- bool bit[16]={0x00};
- bool bit2[16]={0x00};
- bool dump=false;
- uint8_t datatemp[5]={0x00};
- uint8_t isOK = 0;
- uint8_t * data = NULL;
- FILE *fout = NULL;
-
- if (strchr(Cmd,'x') != 0){
- dump=true;
- if ((fout = fopen("dump_ultralightc_data.bin","wb")) == NULL) {
- PrintAndLog("Could not create file name dumpdata.bin");
- return 1;
- }
- PrintAndLog("Dumping Ultralight C Card Data...");
- }
- PrintAndLog("Attempting to Read Ultralight C... ");
- UsbCommand c = {CMD_MIFAREUC_READCARD, {BlockNo, Pages}};
- SendCommand(&c);
- UsbCommand resp;
-
- if (WaitForResponseTimeout(CMD_ACK,&resp,1500)) {
- isOK = resp.arg[0] & 0xff;
- data = resp.d.asBytes;
- //Pages=sizeof(data)/sizeof(data[0]);
- PrintAndLog("isOk:%02x", isOK);
- if (isOK)
- for (i = 0; i < Pages; i++) {
- switch(i){
- case 2:
- //process lock bytes
- lockbytes_t=data+(i*4);
- lockbytes[0]=lockbytes_t[2];
- lockbytes[1]=lockbytes_t[3];
- for(int j=0; j<16; j++){
- bit[j]=lockbytes[j/8] & ( 1 <<(7-j%8));
- }
- //might as well read bottom lockbytes too
- lockbytes_t2=data+(40*4);
- lockbytes2[0]=lockbytes_t2[2];
- lockbytes2[1]=lockbytes_t2[3];
- for(int j=0; j<16; j++){
- bit2[j]=lockbytes2[j/8] & ( 1 <<(7-j%8));
- }
- PrintAndLog("Block %02x:%s ", i,sprint_hex(data + i * 4, 4));
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 3:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[4]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 4:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[3]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 5:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[2]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 6:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[1]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 7:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[0]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 8:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[15]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 9:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[14]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 10:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[13]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 11:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[12]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 12:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[11]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 13:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[10]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 14:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[9]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 15:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit[8]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 16:
- case 17:
- case 18:
- case 19:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[6]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 20:
- case 21:
- case 22:
- case 23:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[5]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 24:
- case 25:
- case 26:
- case 27:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[4]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 28:
- case 29:
- case 30:
- case 31:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[2]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 32:
- case 33:
- case 34:
- case 35:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[1]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 36:
- case 37:
- case 38:
- case 39:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[0]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 40:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[12]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 41:
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[11]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 42:
- //auth0
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[10]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- case 43:
- //auth1
- PrintAndLog("Block %02x:%s [%d]", i,sprint_hex(data + i * 4, 4),bit2[9]);
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- default:
- PrintAndLog("Block %02x:%s ", i,sprint_hex(data + i * 4, 4));
- memcpy(datatemp,data + i * 4,4);
- if (dump) fwrite ( datatemp, 1, 4, fout );
- break;
- }
- }
-
- } else {
- PrintAndLog("Command1 execute timeout");
- }
- if (dump) fclose(fout);
- return 0;
+int CmdHF14AMfUCWrBl(const char *Cmd){
+
+ uint8_t blockNo = -1;
+ bool chinese_card = FALSE;
+ uint8_t bldata[16] = {0x00};
+ UsbCommand resp;
+
+ char cmdp = param_getchar(Cmd, 0);
+
+ if (strlen(Cmd) < 3 || cmdp == 'h' || cmdp == 'H') {
+ PrintAndLog("Usage: hf mfu cwrbl <block number> <block data (8 hex symbols)> [w]");
+ PrintAndLog(" [block number]");
+ PrintAndLog(" [block data] - (8 hex symbols)");
+ PrintAndLog(" [w] - Chinese magic ultralight tag");
+ PrintAndLog("");
+ PrintAndLog(" sample: hf mfu cwrbl 0 01020304");
+ PrintAndLog("");
+ return 0;
+ }
+
+ blockNo = param_get8(Cmd, 0);
+ if (blockNo > MAX_ULTRAC_BLOCKS ){
+ PrintAndLog("Error: Maximum number of blocks is 47 for Ultralight-C Cards!");
+ return 1;
+ }
+
+ if (param_gethex(Cmd, 1, bldata, 8)) {
+ PrintAndLog("Block data must include 8 HEX symbols");
+ return 1;
+ }
+
+ if (strchr(Cmd,'w') != 0 || strchr(Cmd,'W') != 0 ) {
+ chinese_card = TRUE;
+ }
+
+ if ( blockNo <= 3 ) {
+ if (!chinese_card){
+ PrintAndLog("Access Denied");
+ } else {
+ PrintAndLog("--Special block no: 0x%02x", blockNo);
+ PrintAndLog("--Data: %s", sprint_hex(bldata, 4));
+ UsbCommand d = {CMD_MIFAREU_WRITEBL, {blockNo}};
+ memcpy(d.d.asBytes,bldata, 4);
+ SendCommand(&d);
+ if (WaitForResponseTimeout(CMD_ACK,&resp,1500)) {
+ uint8_t isOK = resp.arg[0] & 0xff;
+ PrintAndLog("isOk:%02x", isOK);
+ } else {
+ PrintAndLog("Command execute timeout");
+ }
+ }
+ } else {
+ PrintAndLog("--Block no : 0x%02x", blockNo);
+ PrintAndLog("--Data: %s", sprint_hex(bldata, 4));
+ UsbCommand e = {CMD_MIFAREU_WRITEBL, {blockNo}};
+ memcpy(e.d.asBytes,bldata, 4);
+ SendCommand(&e);
+ if (WaitForResponseTimeout(CMD_ACK,&resp,1500)) {
+ uint8_t isOK = resp.arg[0] & 0xff;
+ PrintAndLog("isOk : %02x", isOK);
+ } else {
+ PrintAndLog("Command execute timeout");
+ }
+ }
+ return 0;