X-Git-Url: http://cvs.zerfleddert.de/cgi-bin/gitweb.cgi/proxmark3-svn/blobdiff_plain/a3abb028978d98bf28676d3b4a98083db3b2912a..547595784facfc9565ca08af18d9bead6bfac31b:/client/scripts/tnp3sim.lua?ds=sidebyside

diff --git a/client/scripts/tnp3sim.lua b/client/scripts/tnp3sim.lua
index af3d2d4c..ca729f38 100644
--- a/client/scripts/tnp3sim.lua
+++ b/client/scripts/tnp3sim.lua
@@ -5,7 +5,8 @@ local lib14a = require('read14a')
 local utils = require('utils')
 local md5 = require('md5')
 local toys = require('default_toys')
-
+local pre = require('precalc')
+		
 example =[[
 	1. script run tnp3sim
 	2. script run tnp3sim -m
@@ -23,11 +24,12 @@ Arguments:
 	-h             : this help
 	-m             : Maxed out items (experimental)
 	-i             : filename for the datadump to read (bin)
-]]
+
+	]]
 
 local TIMEOUT = 2000 -- Shouldn't take longer than 2 seconds
 local DEBUG = true -- the debug flag
-
+local RANDOM = '20436F707972696768742028432920323031302041637469766973696F6E2E20416C6C205269676874732052657365727665642E20'
 
 local band = bit32.band
 local bor = bit32.bor
@@ -41,9 +43,7 @@ local format = string.format
 --- 
 -- A debug printout-function
 function dbg(args)
-	if not DEBUG then
-		return
-	end
+	if not DEBUG then return end
 	
     if type(args) == "table" then
 		local i = 1
@@ -59,6 +59,7 @@ end
 -- This is only meant to be used when errors occur
 function oops(err)
 	print("ERROR: ",err)
+	return nil,err
 end
 --- 
 -- Usage help
@@ -105,6 +106,14 @@ local function GetCheckSum(blocks, dataarea, chksumtype)
 	return utils.SwapEndianness(crc,16)
 end
 
+local function SetAllCheckSum(blocks)
+	print('Updating all checksums')
+	SetCheckSum(blocks, 3)
+	SetCheckSum(blocks, 2)
+	SetCheckSum(blocks, 1)
+	SetCheckSum(blocks, 0)
+end
+
 local function SetCheckSum(blocks, chksumtype)
 
 	if blocks == nil then return nil, 'Argument \"blocks\" nil' end
@@ -152,7 +161,8 @@ function CalcCheckSum(blocks, dataarea, chksumtype)
 end
 
 local function ValidateCheckSums(blocks)
-
+	print(' Validating checksums')
+	
 	local isOk, crc, calc
 	-- Checksum Type 0
 	crc = GetCheckSum(blocks,1,0)
@@ -195,35 +205,42 @@ local function ValidateCheckSums(blocks)
 	calc = CalcCheckSum(blocks,2,3)
 	if crc == calc then isOk='Ok' else isOk = 'Error' end	
 	io.write( ('TYPE 3 area 2: %04x = %04x -- %s\n'):format(crc,calc,isOk))
+
+end
+
+local function AddKey(keys, blockNo, data)
+	local pos = (math.floor( blockNo / 4 ) * 12)+1
+	local key = keys:sub(pos, pos + 11 )
+	return key..data:sub(13)
 end
 
-local function LoadEmulator(blocks)
-	local HASHCONSTANT = '20436F707972696768742028432920323031302041637469766973696F6E2E20416C6C205269676874732052657365727665642E20'
-	local cmd
-	local blockdata
+local function LoadEmulator(uid, blocks)
+	print('Sending dumpdata to emulator memory')
+	local keys = pre.GetAll(uid)
+	local cmd, blockdata
 	for _,b in pairs(blocks) do 
 		
 		blockdata = b
 		
 		if  _%4 ~= 3 then
 			if (_ >= 8 and _<=21)  or  (_ >= 36 and _<=49) then
-				local base = ('%s%s%02x%s'):format(blocks[0], blocks[1], _ , HASHCONSTANT)	
+				local base = ('%s%s%02x%s'):format(blocks[0], blocks[1], _ , RANDOM)	
 				local baseStr = utils.ConvertHexToAscii(base)
 				local key = md5.sumhexa(baseStr)
-				local enc = core.aes(key, blockdata)
-				local hex = utils.ConvertAsciiToBytes(enc)
-				hex = utils.ConvertBytesToHex(hex)
-			
-				blockdata = hex
+				local enc = core.aes128_encrypt(key, blockdata)
+				blockdata = utils.ConvertAsciiToHex(enc)
 				io.write( _..',')
 			end
+		else		
+			-- add keys if not existing..
+			if ( blockdata:sub(1,12) == '000000000000' ) then
+				blockdata = AddKey(keys, _, blockdata)
+			end
 		end
-
-		cmd = Command:new{cmd = cmds.CMD_MIFARE_EML_MEMSET, arg1 = _ ,arg2 = 1,arg3 = 0, data = blockdata}
+		core.clearCommandBuffer()
+		cmd = Command:new{cmd = cmds.CMD_MIFARE_EML_MEMSET, arg1 = _ ,arg2 = 1,arg3 = 16, data = blockdata}
 		local err = core.SendCommand(cmd:getBytes())
-		if err then 
-			return err
-		end
+		if err then return err end
 	end
 	io.write('\n')
 end
@@ -346,21 +363,6 @@ local function main(args)
 	local cmdSetDbgOff = "hf mf dbg 0"
 	core.console( cmdSetDbgOff) 
 	
-	-- if not loadFromDump then
-		-- -- Look for tag present on reader,
-		-- result, err = lib14a.read1443a(false)
-		-- if not result then return oops(err)	end
-
-		-- core.clearCommandBuffer()
-	
-		-- if 0x01 ~= result.sak then -- NXP MIFARE TNP3xxx
-			-- return oops('This is not a TNP3xxx tag. aborting.')
-		-- end	
-
-		-- -- Show tag info
-		-- print((' Found tag : %s'):format(result.name))
-	-- end
-	
 	-- Load dump.bin file
 	print( (' Load data from %s'):format(inputTemplate))
 	hex, err = utils.ReadDumpFile(inputTemplate)
@@ -373,10 +375,7 @@ local function main(args)
 		blockindex = blockindex + 1
 	end
 
-	if DEBUG then
-		print('Validating checksums in the loaded datadump')
-		ValidateCheckSums(blocks)
-	end
+	if DEBUG then ValidateCheckSums(blocks)	end
 	
 	--
 	print( string.rep('--',20) )	
@@ -393,7 +392,7 @@ local function main(args)
 	local item = toys.Find( toytype, subtype)
 	if item then
 		local itemStr = ('%s - %s (%s)'):format(item[6],item[5], item[4])
-		print(' ITEM TYPE :'..itemStr )
+		print(' ITEM TYPE : '..itemStr )
 	else
 		print( (' ITEM TYPE : 0x%s 0x%s'):format(toytype, subtype) )
 	end	
@@ -407,12 +406,19 @@ local function main(args)
 	print( string.rep('--',20) )
 
 
-	-- lets do something.
-	-- 
+	-- Experience should be:  	
 	local experience = blocks[8]:sub(1,6)
-	print(('Experience  : %d'):format(utils.SwapEndianness(experience,24)))
+	print(('Experience  : %d'):format(utils.SwapEndianness(experience,16)))
+	
 	local money = blocks[8]:sub(7,10)
 	print(('Money       : %d'):format(utils.SwapEndianness(money,16)))
+
+	-- 
+	
+	-- Sequence number
+	local seqnum = blocks[8]:sub(18,19)
+	print(('Sequence number : %d'):format( tonumber(seqnum,16)))
+	
 	local fairy = blocks[9]:sub(1,8)
 	--FD0F = Left, FF0F = Right
 	local path = 'not choosen'
@@ -425,6 +431,12 @@ local function main(args)
 	
 	local hat = blocks[9]:sub(8,11)
 	print(('Hat         : %d'):format(utils.SwapEndianness(hat,16)))
+
+	local level = blocks[13]:sub(27,28)
+	print(('LEVEL : %d'):format( tonumber(level,16)))
+
+	--local health = blocks[]:sub();
+	--print(('Health : %d'):format( tonumber(health,16))
 	
 	--0x0D    0x29    0x0A    0x02    16-bit hero points value. Maximum 100.
 	local heropoints = blocks[13]:sub(20,23)
@@ -434,6 +446,11 @@ local function main(args)
 	local challenges = blocks[16]:sub(25,32)
 	print(('Finished hero challenges : %d'):format(utils.SwapEndianness(challenges,32)))
 	
+	-- Character Name
+	local name1 = blocks[10]:sub(1,32)
+	local name2 = blocks[12]:sub(1,32)
+	print('Custom name : '..utils.ConvertHexToAscii(name1..name2))
+	
 	if maxed then
 		print('Lets try to max out some values')
 		-- max out money, experience
@@ -455,20 +472,15 @@ local function main(args)
 		--print (blocks[13])
 	
 		-- Update Checksums
-		print('Updating all checksums')
-		SetCheckSum(blocks, 3)
-		SetCheckSum(blocks, 2)
-		SetCheckSum(blocks, 1)
-		SetCheckSum(blocks, 0)
-	
-		print('Validating all checksums')	
+		SetAllCheckSum(blocks)
+
+		-- Validate Checksums
 		ValidateCheckSums(blocks)
 	end
-	
+
 	--Load dumpdata to emulator memory
 	if DEBUG then
-		print('Sending dumpdata to emulator memory')
-		err = LoadEmulator(blocks)
+		err = LoadEmulator(uid, blocks)
 		if err then return oops(err) end	
 		core.clearCommandBuffer()
 		print('The simulation is now prepared.\n --> run \"hf mf sim u '..uid..'\" <--')