X-Git-Url: http://cvs.zerfleddert.de/cgi-bin/gitweb.cgi/proxmark3-svn/blobdiff_plain/ff3e07447893b004c6de5c7202c9b50f2c81ab04..13629a71d3f77223281a2dcec5375e038419a808:/client/cmdhf14b.c diff --git a/client/cmdhf14b.c b/client/cmdhf14b.c index fbe4d2e6..f6692bac 100644 --- a/client/cmdhf14b.c +++ b/client/cmdhf14b.c @@ -12,175 +12,153 @@ #include <stdlib.h> #include <stdbool.h> #include <stdint.h> -#include "iso14443crc.h" -#include "proxmark3.h" -#include "data.h" -#include "graph.h" -#include "util.h" -#include "ui.h" -#include "cmdparser.h" #include "cmdhf14b.h" -#include "cmdmain.h" -#include "cmdhf14a.h" -#include "tea.h" -#include "cmdhf.h" -#include "prng.h" -#include "sha1.h" +#define TIMEOUT 2000 static int CmdHelp(const char *Cmd); -int CmdHF14BList(const char *Cmd) { - CmdHFList("14b"); +int usage_hf_14b_info(void){ + PrintAndLog("Usage: hf 14b info [-h] [-s]"); + PrintAndLog(" -h this help"); + PrintAndLog(" -s silently"); return 0; } - -int CmdHF14BSim(const char *Cmd) -{ - UsbCommand c = {CMD_SIMULATE_TAG_ISO_14443B}; - clearCommandBuffer(); - SendCommand(&c); +int usage_hf_14b_reader(void){ + PrintAndLog("Usage: hf 14b reader [-h] [-s]"); + PrintAndLog(" -h this help"); + PrintAndLog(" -s silently"); return 0; } - -int CmdHF14BSnoop(const char *Cmd) -{ - UsbCommand c = {CMD_SNOOP_ISO_14443B}; - clearCommandBuffer(); - SendCommand(&c); +int usage_hf_14b_raw(void){ + PrintAndLog("Usage: hf 14b raw [-h] [-r] [-c] [-p] [-s || -ss] <0A 0B 0C ... hex>"); + PrintAndLog(" -h this help"); + PrintAndLog(" -r do not read response"); + PrintAndLog(" -c calculate and append CRC"); + PrintAndLog(" -p leave the field on after receive"); + PrintAndLog(" -s active signal field ON with select"); + PrintAndLog(" -ss active signal field ON with select for SRx ST Microelectronics tags"); + return 0; +} +int usage_hf_14b_snoop(void){ + PrintAndLog("It get data from the field and saves it into command buffer."); + PrintAndLog("Buffer accessible from command 'hf list 14b'"); + PrintAndLog("Usage: hf 14b snoop [-h]"); + PrintAndLog(" -h this help"); + PrintAndLog("sample: hf 14b snoop"); + return 0; +} +int usage_hf_14b_sim(void){ + PrintAndLog("Emulating ISO/IEC 14443 type B tag with 4 UID"); + PrintAndLog("Usage: hf 14b sim [-h]"); + PrintAndLog(" -h this help"); + PrintAndLog("sample: hf 14b sim"); + return 0; +} +int usage_hf_14b_read_srx(void){ + PrintAndLog("Usage: hf 14b read [h] <1|2>"); + PrintAndLog("Options:"); + PrintAndLog(" h this help"); + PrintAndLog(" <1|2> 1 = SRIX4K , 2 = SRI512"); + PrintAndLog("sample: hf 14b read 1"); + PrintAndLog(" : hf 14b read 2"); return 0; } - -/* New command to read the contents of a SRI512 tag - * SRI512 tags are ISO14443-B modulated memory tags, - * this command just dumps the contents of the memory - */ -int CmdSri512Read(const char *Cmd) -{ - UsbCommand c = {CMD_READ_SRI512_TAG, {strtol(Cmd, NULL, 0), 0, 0}}; - clearCommandBuffer(); - SendCommand(&c); +int usage_hf_14b_write_srx(void){ + PrintAndLog("Usage: hf 14b write <1|2> <BLOCK> <DATA>"); + PrintAndLog("Options:"); + PrintAndLog(" h this help"); + PrintAndLog(" <1|2> 1 = SRIX4K , 2 = SRI512"); + PrintAndLog(" <block> BLOCK number depends on tag, special block == FF"); + PrintAndLog(" <data> hex bytes of data to be written"); + PrintAndLog("sample : hf 14b write 1 7F 11223344"); + PrintAndLog(" : hf 14b write 1 FF 11223344"); + PrintAndLog(" : hf 14b write 2 15 11223344"); + PrintAndLog(" : hf 14b write 2 FF 11223344"); return 0; } -/* New command to read the contents of a SRIX4K tag - * SRIX4K tags are ISO14443-B modulated memory tags, - * this command just dumps the contents of the memory/ - */ -int CmdSrix4kRead(const char *Cmd) { - UsbCommand c = {CMD_READ_SRIX4K_TAG, {strtol(Cmd, NULL, 0), 0, 0}}; +static int rawClose(){ + UsbCommand c = {CMD_ISO_14443B_COMMAND, {ISO14B_DISCONNECT, 0, 0}}; clearCommandBuffer(); SendCommand(&c); - return 0; + return 1; } -int rawClose(void){ - UsbCommand resp; - UsbCommand c = {CMD_ISO_14443B_COMMAND, {0, 0, 0}}; - clearCommandBuffer(); - SendCommand(&c); - if (!WaitForResponseTimeout(CMD_ACK,&resp,1000)) { - PrintAndLog("Command time-out"); - return 1; - } +int CmdHF14BList(const char *Cmd) { + CmdHFList("14b"); return 0; } -int HF14BCmdRaw(bool reply, bool *crc, bool power, uint8_t *data, uint8_t *datalen, bool verbose){ - - if(*crc) { - ComputeCrc14443(CRC_14443_B, data, *datalen, data+*datalen, data+*datalen+1); - *datalen += 2; - } - - UsbCommand c = {CMD_ISO_14443B_COMMAND, {0, 0, 0}}; // len,recv,power - c.arg[0] = *datalen; - c.arg[1] = reply; - c.arg[2] = power; - memcpy(c.d.asBytes, data, *datalen); +int CmdHF14BSim(const char *Cmd) { + char cmdp = param_getchar(Cmd, 0); + if (cmdp == 'h' || cmdp == 'H') return usage_hf_14b_sim(); + + UsbCommand c = {CMD_SIMULATE_TAG_ISO_14443B, {0, 0, 0}}; clearCommandBuffer(); SendCommand(&c); + return 0; +} - if (!reply) return 1; - - UsbCommand resp; - if (!WaitForResponseTimeout(CMD_ACK, &resp, 2000)) { - if (verbose) PrintAndLog("timeout while waiting for reply."); - return 0; - } - - *datalen = resp.arg[0]; - if (verbose) PrintAndLog("received %u octets", *datalen); - if(*datalen<3) return 0; - - memcpy(data, resp.d.asBytes, *datalen); +int CmdHF14BSnoop(const char *Cmd) { - uint8_t first = 0, second = 0; - ComputeCrc14443(CRC_14443_B, data, *datalen-2, &first, &second); - *crc = ( data[*datalen-2] == first && data[*datalen-1] == second); - - if (verbose) - PrintAndLog("[LEN %u] %s[%02X %02X] %s", - *datalen, - sprint_hex(data, *datalen-2), - data[*datalen-2], - data[*datalen-1], - (*crc)?"OK":"FAIL" - ); + char cmdp = param_getchar(Cmd, 0); + if (cmdp == 'h' || cmdp == 'H') return usage_hf_14b_snoop(); - return 1; + UsbCommand c = {CMD_SNOOP_ISO_14443B, {0, 0, 0}}; + clearCommandBuffer(); + SendCommand(&c); + return 0; } int CmdHF14BCmdRaw (const char *Cmd) { - bool reply = true; - bool crc = false; - bool power = false; - bool select = false; - bool SRx = false; - char buf[5]=""; - uint8_t data[USB_CMD_DATA_SIZE] = {0x00}; - uint8_t datalen = 0; - unsigned int temp; - int i = 0; - if (strlen(Cmd)<3) { - PrintAndLog("Usage: hf 14b raw [-r] [-c] [-p] [-s || -ss] <0A 0B 0C ... hex>"); - PrintAndLog(" -r do not read response"); - PrintAndLog(" -c calculate and append CRC"); - PrintAndLog(" -p leave the field on after receive"); - PrintAndLog(" -s active signal field ON with select"); - PrintAndLog(" -ss active signal field ON with select for SRx ST Microelectronics tags"); - return 0; - } + bool reply = TRUE; + bool power = FALSE; + bool select = FALSE; + char buf[5]=""; + + int i = 0; + uint8_t data[USB_CMD_DATA_SIZE] = {0x00}; + uint16_t datalen = 0; + uint32_t flags = 0; + uint32_t temp = 0; + + if (strlen(Cmd)<3) return usage_hf_14b_raw(); // strip - while (*Cmd==' ' || *Cmd=='\t') Cmd++; + while (*Cmd==' ' || *Cmd=='\t') ++Cmd; while (Cmd[i]!='\0') { - if (Cmd[i]==' ' || Cmd[i]=='\t') { i++; continue; } + if (Cmd[i]==' ' || Cmd[i]=='\t') { ++i; continue; } if (Cmd[i]=='-') { switch (Cmd[i+1]) { + case 'H': + case 'h': + return usage_hf_14b_raw(); case 'r': case 'R': - reply = false; + reply = FALSE; break; case 'c': case 'C': - crc = true; + flags |= ISO14B_APPEND_CRC; break; case 'p': case 'P': - power = true; + power = TRUE; break; case 's': case 'S': - select = true; + flags |= ISO14B_CONNECT; + select = TRUE; if (Cmd[i+2]=='s' || Cmd[i+2]=='S') { - SRx = true; - i++; + flags |= ISO14B_SELECT_SR; + ++i; + } else { + flags |= ISO14B_SELECT_STD; } break; default: - PrintAndLog("Invalid option"); - return 0; + return usage_hf_14b_raw(); } i+=2; continue; @@ -194,7 +172,7 @@ int CmdHF14BCmdRaw (const char *Cmd) { if (strlen(buf)>=2) { sscanf(buf,"%x",&temp); - data[datalen++]=(uint8_t)(temp & 0xff); + data[datalen++] = (uint8_t)(temp & 0xff); *buf=0; memset(buf, 0x00, sizeof(buf)); } @@ -203,84 +181,55 @@ int CmdHF14BCmdRaw (const char *Cmd) { PrintAndLog("Invalid char on input"); return 0; } - if (datalen == 0) - { - PrintAndLog("Missing data input"); - return 0; - } - - if (select){ //auto select 14b tag - uint8_t cmd2[16]; - bool crc2 = true; - uint8_t cmdLen; - - if (SRx) { - // REQ SRx - cmdLen = 2; - cmd2[0] = 0x06; - cmd2[1] = 0x00; - } else { - // REQB - cmdLen = 3; - cmd2[0] = 0x05; - cmd2[1] = 0x00; - cmd2[2] = 0x08; - } - - // REQB - if (HF14BCmdRaw(true, &crc2, true, cmd2, &cmdLen, false)==0) return rawClose(); - - PrintAndLog("REQB : %s", sprint_hex(cmd2, cmdLen)); - - if ( SRx && (cmdLen != 3 || !crc2) ) return rawClose(); - else if (cmd2[0] != 0x50 || cmdLen != 14 || !crc2) return rawClose(); - - uint8_t chipID = 0; - if (SRx) { - // select - chipID = cmd2[0]; - cmd2[0] = 0x0E; - cmd2[1] = chipID; - cmdLen = 2; - } else { - // attrib - cmd2[0] = 0x1D; - // UID from cmd2[1 - 4] - cmd2[5] = 0x00; - cmd2[6] = 0x08; - cmd2[7] = 0x01; - cmd2[8] = 0x00; - cmdLen = 9; - } - // wait - - // attrib - if (HF14BCmdRaw(true, &crc2, true, cmd2, &cmdLen, false)==0) return rawClose(); - PrintAndLog("ATTRIB : %s", sprint_hex(cmd2, cmdLen)); - - if (cmdLen != 3 || !crc2) return rawClose(); - if (SRx && cmd2[0] != chipID) return rawClose(); - } - return HF14BCmdRaw(reply, &crc, power, data, &datalen, true); + if(!power) + flags |= ISO14B_DISCONNECT; + + if(datalen>0) + flags |= ISO14B_RAW; + + // Max buffer is USB_CMD_DATA_SIZE + datalen = (datalen > USB_CMD_DATA_SIZE) ? USB_CMD_DATA_SIZE : datalen; + + UsbCommand c = {CMD_ISO_14443B_COMMAND, {flags, datalen, 0}}; + memcpy(c.d.asBytes, data, datalen); + clearCommandBuffer(); + SendCommand(&c); + + if (!reply) return 1; + + bool success = TRUE; + // get back iso14b_card_select_t, don't print it. + if(select) + success = waitCmd(FALSE); + + // get back response from the raw bytes you sent. + if(success && datalen>0) waitCmd(TRUE); + + return 1; } // print full atqb info -static void print_atqb_resp(uint8_t *data){ - //PrintAndLog (" UID: %s", sprint_hex(data+1,4)); - PrintAndLog (" App Data: %s", sprint_hex(data+5,4)); - PrintAndLog (" Protocol: %s", sprint_hex(data+9,3)); - uint8_t BitRate = data[9]; - if (!BitRate) PrintAndLog (" Bit Rate: 106 kbit/s only PICC <-> PCD"); - if (BitRate & 0x10) PrintAndLog (" Bit Rate: 212 kbit/s PICC -> PCD supported"); - if (BitRate & 0x20) PrintAndLog (" Bit Rate: 424 kbit/s PICC -> PCD supported"); - if (BitRate & 0x40) PrintAndLog (" Bit Rate: 847 kbit/s PICC -> PCD supported"); - if (BitRate & 0x01) PrintAndLog (" Bit Rate: 212 kbit/s PICC <- PCD supported"); - if (BitRate & 0x02) PrintAndLog (" Bit Rate: 424 kbit/s PICC <- PCD supported"); - if (BitRate & 0x04) PrintAndLog (" Bit Rate: 847 kbit/s PICC <- PCD supported"); - if (BitRate & 0x80) PrintAndLog (" Same bit rate <-> required"); - - uint16_t maxFrame = data[10]>>4; +// bytes +// 0,1,2,3 = application data +// 4 = bit rate capacity +// 5 = max frame size / -4 info +// 6 = FWI / Coding options +static void print_atqb_resp(uint8_t *data, uint8_t cid){ + //PrintAndLog(" UID: %s", sprint_hex(data+1,4)); + PrintAndLog(" App Data: %s", sprint_hex(data,4)); + PrintAndLog(" Protocol: %s", sprint_hex(data+4,3)); + uint8_t BitRate = data[4]; + if (!BitRate) PrintAndLog(" Bit Rate: 106 kbit/s only PICC <-> PCD"); + if (BitRate & 0x10) PrintAndLog(" Bit Rate: 212 kbit/s PICC -> PCD supported"); + if (BitRate & 0x20) PrintAndLog(" Bit Rate: 424 kbit/s PICC -> PCD supported"); + if (BitRate & 0x40) PrintAndLog(" Bit Rate: 847 kbit/s PICC -> PCD supported"); + if (BitRate & 0x01) PrintAndLog(" Bit Rate: 212 kbit/s PICC <- PCD supported"); + if (BitRate & 0x02) PrintAndLog(" Bit Rate: 424 kbit/s PICC <- PCD supported"); + if (BitRate & 0x04) PrintAndLog(" Bit Rate: 847 kbit/s PICC <- PCD supported"); + if (BitRate & 0x80) PrintAndLog(" Same bit rate <-> required"); + + uint16_t maxFrame = data[5]>>4; if (maxFrame < 5) maxFrame = 8 * maxFrame + 16; else if (maxFrame == 5) maxFrame = 64; else if (maxFrame == 6) maxFrame = 96; @@ -288,16 +237,28 @@ static void print_atqb_resp(uint8_t *data){ else if (maxFrame == 8) maxFrame = 256; else maxFrame = 257; - PrintAndLog ("Max Frame Size: %u%s",maxFrame, (maxFrame == 257) ? "+ RFU" : ""); - uint8_t protocolT = data[10] & 0xF; - PrintAndLog (" Protocol Type: Protocol is %scompliant with ISO/IEC 14443-4",(protocolT) ? "" : "not " ); - PrintAndLog ("Frame Wait Int: %u", data[11]>>4); - PrintAndLog (" App Data Code: Application is %s",(data[11]&4) ? "Standard" : "Proprietary"); - PrintAndLog (" Frame Options: NAD is %ssupported",(data[11]&2) ? "" : "not "); - PrintAndLog (" Frame Options: CID is %ssupported",(data[11]&1) ? "" : "not "); - PrintAndLog ("Max Buf Length: %u (MBLI) %s",data[14]>>4, (data[14] & 0xF0) ? "" : "not supported"); + + PrintAndLog("Max Frame Size: %u%s bytes",maxFrame, (maxFrame == 257) ? "+ RFU" : ""); + uint8_t protocolT = data[5] & 0xF; + PrintAndLog(" Protocol Type: Protocol is %scompliant with ISO/IEC 14443-4",(protocolT) ? "" : "not " ); + + uint8_t fwt = data[6]>>4; + if ( fwt < 16 ){ + uint32_t etus = (32 << fwt); + uint32_t fwt_time = (302 << fwt); + PrintAndLog("Frame Wait Integer: %u - %u ETUs | %u µS", fwt, etus, fwt_time); + } else { + PrintAndLog("Frame Wait Integer: %u - RFU", fwt); + } + + PrintAndLog(" App Data Code: Application is %s",(data[6]&4) ? "Standard" : "Proprietary"); + PrintAndLog(" Frame Options: NAD is %ssupported",(data[6]&2) ? "" : "not "); + PrintAndLog(" Frame Options: CID is %ssupported",(data[6]&1) ? "" : "not "); + PrintAndLog("Tag :"); + PrintAndLog(" Max Buf Length: %u (MBLI) %s", cid>>4, (cid & 0xF0) ? "" : "chained frames not supported"); + PrintAndLog(" CDI : %u", cid & 0x0f); return; } @@ -320,301 +281,347 @@ char *get_ST_Chip_Model(uint8_t data){ return retStr; } +// REMAKE: int print_ST_Lock_info(uint8_t model){ - //assume connection open and tag selected... - uint8_t data[16] = {0x00}; - uint8_t datalen = 2; - bool crc = true; - uint8_t resplen; - uint8_t blk1; - data[0] = 0x08; - - if (model == 0x2) { //SR176 has special command: - data[1] = 0xf; - resplen = 4; - } else { - data[1] = 0xff; - resplen = 6; - } - //std read cmd - if (HF14BCmdRaw(true, &crc, true, data, &datalen, false)==0) return rawClose(); - - if (datalen != resplen || !crc) return rawClose(); - - PrintAndLog("Chip Write Protection Bits:"); - // now interpret the data - switch (model){ - case 0x0: //fall through (SRIX4K special) - case 0x3: //fall through (SRIx4K) - case 0x7: // (SRI4K) - //only need data[3] - blk1 = 9; - PrintAndLog(" raw: %s", sprint_bin(data+3, 1)); - PrintAndLog(" 07/08:%slocked", (data[3] & 1) ? " not " : " " ); - for (uint8_t i = 1; i<8; i++){ - PrintAndLog(" %02u:%slocked", blk1, (data[3] & (1 << i)) ? " not " : " " ); - blk1++; - } - break; - case 0x4: //fall through (SRIX512) - case 0x6: //fall through (SRI512) - case 0xC: // (SRT512) - //need data[2] and data[3] - blk1 = 0; - PrintAndLog(" raw: %s", sprint_bin(data+2, 2)); - for (uint8_t b=2; b<4; b++){ - for (uint8_t i=0; i<8; i++){ - PrintAndLog(" %02u:%slocked", blk1, (data[b] & (1 << i)) ? " not " : " " ); - blk1++; - } - } - break; - case 0x2: // (SR176) - //need data[2] - blk1 = 0; - PrintAndLog(" raw: %s", sprint_bin(data+2, 1)); - for (uint8_t i = 0; i<8; i++){ - PrintAndLog(" %02u/%02u:%slocked", blk1, blk1+1, (data[2] & (1 << i)) ? " " : " not " ); - blk1+=2; - } - break; - default: - return rawClose(); - } + // PrintAndLog("Chip Write Protection Bits:"); + // // now interpret the data + // switch (model){ + // case 0x0: //fall through (SRIX4K special) + // case 0x3: //fall through (SRIx4K) + // case 0x7: // (SRI4K) + // //only need data[3] + // blk1 = 9; + // PrintAndLog(" raw: %s", sprint_bin(data+3, 1)); + // PrintAndLog(" 07/08:%slocked", (data[3] & 1) ? " not " : " " ); + // for (uint8_t i = 1; i<8; i++){ + // PrintAndLog(" %02u:%slocked", blk1, (data[3] & (1 << i)) ? " not " : " " ); + // blk1++; + // } + // break; + // case 0x4: //fall through (SRIX512) + // case 0x6: //fall through (SRI512) + // case 0xC: // (SRT512) + // //need data[2] and data[3] + // blk1 = 0; + // PrintAndLog(" raw: %s", sprint_bin(data+2, 2)); + // for (uint8_t b=2; b<4; b++){ + // for (uint8_t i=0; i<8; i++){ + // PrintAndLog(" %02u:%slocked", blk1, (data[b] & (1 << i)) ? " not " : " " ); + // blk1++; + // } + // } + // break; + // case 0x2: // (SR176) + // //need data[2] + // blk1 = 0; + // PrintAndLog(" raw: %s", sprint_bin(data+2, 1)); + // for (uint8_t i = 0; i<8; i++){ + // PrintAndLog(" %02u/%02u:%slocked", blk1, blk1+1, (data[2] & (1 << i)) ? " " : " not " ); + // blk1+=2; + // } + // break; + // default: + // return rawClose(); + // } return 1; } // print UID info from SRx chips (ST Microelectronics) -static void print_st_general_info(uint8_t *data){ +static void print_st_general_info(uint8_t *data, uint8_t len){ //uid = first 8 bytes in data - PrintAndLog(" UID: %s", sprint_hex(SwapEndian64(data,8,8),8)); + PrintAndLog(" UID: %s", sprint_hex(SwapEndian64(data,8,8), len)); PrintAndLog(" MFG: %02X, %s", data[6], getTagInfo(data[6])); PrintAndLog("Chip: %02X, %s", data[5]>>2, get_ST_Chip_Model(data[5]>>2)); return; } -// 14b get and print UID only (general info) -int HF14BStdReader(uint8_t *data, uint8_t *datalen){ - //05 00 00 = find one tag in field - //1d xx xx xx xx 00 08 01 00 = attrib xx=UID (resp 10 [f9 e0]) - //a3 = ? (resp 03 [e2 c2]) - //02 = ? (resp 02 [6a d3]) - // 022b (resp 02 67 00 [29 5b]) - // 0200a40400 (resp 02 67 00 [29 5b]) - // 0200a4040c07a0000002480300 (resp 02 67 00 [29 5b]) - // 0200a4040c07a0000002480200 (resp 02 67 00 [29 5b]) - // 0200a4040006a0000000010100 (resp 02 6a 82 [4b 4c]) - // 0200a4040c09d27600002545500200 (resp 02 67 00 [29 5b]) - // 0200a404000cd2760001354b414e4d30310000 (resp 02 6a 82 [4b 4c]) - // 0200a404000ca000000063504b43532d313500 (resp 02 6a 82 [4b 4c]) - // 0200a4040010a000000018300301000000000000000000 (resp 02 6a 82 [4b 4c]) - //03 = ? (resp 03 [e3 c2]) - //c2 = ? (resp c2 [66 15]) - //b2 = ? (resp a3 [e9 67]) - //a2 = ? (resp 02 [6a d3]) - bool crc = true; - *datalen = 3; - //std read cmd - data[0] = 0x05; - data[1] = 0x00; - data[2] = 0x08; - - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)==0) return rawClose(); - - if (data[0] != 0x50 || *datalen != 14 || !crc) return rawClose(); - - PrintAndLog ("\n14443-3b tag found:"); - PrintAndLog (" UID: %s", sprint_hex(data+1,4)); - - uint8_t cmd2[16]; - uint8_t cmdLen = 3; - bool crc2 = true; - - cmd2[0] = 0x1D; - // UID from data[1 - 4] - cmd2[1] = data[1]; - cmd2[2] = data[2]; - cmd2[3] = data[3]; - cmd2[4] = data[4]; - cmd2[5] = 0x00; - cmd2[6] = 0x08; - cmd2[7] = 0x01; - cmd2[8] = 0x00; - cmdLen = 9; - - // attrib - if (HF14BCmdRaw(true, &crc2, true, cmd2, &cmdLen, false)==0) return rawClose(); - - if (cmdLen != 3 || !crc2) return rawClose(); - // add attrib responce to data - data[14] = cmd2[0]; - rawClose(); - return 1; -} +//05 00 00 = find one tag in field +//1d xx xx xx xx 00 08 01 00 = attrib xx=UID (resp 10 [f9 e0]) +//a3 = ? (resp 03 [e2 c2]) +//02 = ? (resp 02 [6a d3]) +// 022b (resp 02 67 00 [29 5b]) +// 0200a40400 (resp 02 67 00 [29 5b]) +// 0200a4040c07a0000002480300 (resp 02 67 00 [29 5b]) +// 0200a4040c07a0000002480200 (resp 02 67 00 [29 5b]) +// 0200a4040006a0000000010100 (resp 02 6a 82 [4b 4c]) +// 0200a4040c09d27600002545500200 (resp 02 67 00 [29 5b]) +// 0200a404000cd2760001354b414e4d30310000 (resp 02 6a 82 [4b 4c]) +// 0200a404000ca000000063504b43532d313500 (resp 02 6a 82 [4b 4c]) +// 0200a4040010a000000018300301000000000000000000 (resp 02 6a 82 [4b 4c]) +//03 = ? (resp 03 [e3 c2]) +//c2 = ? (resp c2 [66 15]) +//b2 = ? (resp a3 [e9 67]) +//a2 = ? (resp 02 [6a d3]) // 14b get and print Full Info (as much as we know) -int HF14BStdInfo(uint8_t *data, uint8_t *datalen){ - if (!HF14BStdReader(data,datalen)) return 0; - +bool HF14B_Std_Info(bool verbose){ //add more info here - print_atqb_resp(data); - return 1; + return FALSE; } -// SRx get and print general info about SRx chip from UID -int HF14B_ST_Reader(uint8_t *data, uint8_t *datalen, bool closeCon){ - bool crc = true; - *datalen = 2; - //wake cmd - data[0] = 0x06; - data[1] = 0x00; - - //leave power on - // verbose on for now for testing - turn off when functional - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)==0) return rawClose(); +// SRx get and print full info (needs more info...) +bool HF14B_ST_Info(bool verbose){ + + UsbCommand c = {CMD_ISO_14443B_COMMAND, {ISO14B_CONNECT | ISO14B_SELECT_SR | ISO14B_DISCONNECT, 0, 0}}; + clearCommandBuffer(); + SendCommand(&c); + UsbCommand resp; - if (*datalen != 3 || !crc) return rawClose(); + if (!WaitForResponseTimeout(CMD_ACK, &resp, TIMEOUT)) { + if (verbose) PrintAndLog("timeout while waiting for reply."); + return FALSE; + } - uint8_t chipID = data[0]; - // select - data[0] = 0x0E; - data[1] = chipID; - *datalen = 2; + iso14b_card_select_t card; + memcpy(&card, (iso14b_card_select_t *)resp.d.asBytes, sizeof(iso14b_card_select_t)); + + uint64_t status = resp.arg[0]; + if ( status > 0 ) { + rawClose(); + return FALSE; + } - //leave power on - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)==0) return rawClose(); + //add locking bit information here. uint8_t data[16] = {0x00}; + // uint8_t datalen = 2; + // uint8_t resplen; + // uint8_t blk1; + // data[0] = 0x08; + + // + // if (model == 0x2) { //SR176 has special command: + // data[1] = 0xf; + // resplen = 4; + // } else { + // data[1] = 0xff; + // resplen = 6; + // } + + // //std read cmd + // if (HF14BCmdRaw(true, true, data, &datalen, false)==0) + // return rawClose(); + + // if (datalen != resplen || !crc) return rawClose(); + //print_ST_Lock_info(data[5]>>2); + rawClose(); + return TRUE; +} - if (*datalen != 3 || !crc || data[0] != chipID) return rawClose(); +// get and print all info known about any known 14b tag +bool HF14BInfo(bool verbose){ - // get uid - data[0] = 0x0B; - *datalen = 1; + // try std 14b (atqb) + if (HF14B_Std_Info(verbose)) return TRUE; - //leave power on - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)==0) return rawClose(); + // try st 14b + if (HF14B_ST_Info(verbose)) return TRUE; - if (*datalen != 10 || !crc) return rawClose(); + // try unknown 14b read commands (to be identified later) + // could be read of calypso, CEPAS, moneo, or pico pass. - //power off ? - if (closeCon) rawClose(); + if (verbose) PrintAndLog("no 14443B tag found"); + return FALSE; +} - PrintAndLog("\n14443-3b ST tag found:"); - print_st_general_info(data); - return 1; +// menu command to get and print all info known about any known 14b tag +int CmdHF14Binfo(const char *Cmd){ + char cmdp = param_getchar(Cmd, 0); + if (cmdp == 'h' || cmdp == 'H') return usage_hf_14b_info(); + + bool verbose = !((cmdp == 's') || (cmdp == 'S')); + return HF14BInfo(verbose); } -// SRx get and print full info (needs more info...) -int HF14B_ST_Info(uint8_t *data, uint8_t *datalen){ - if (!HF14B_ST_Reader(data, datalen, false)) return 0; +bool HF14B_ST_Reader(bool verbose){ + + bool isSuccess = FALSE; + + // SRx get and print general info about SRx chip from UID + UsbCommand c = {CMD_ISO_14443B_COMMAND, {ISO14B_CONNECT | ISO14B_SELECT_SR | ISO14B_DISCONNECT, 0, 0}}; + clearCommandBuffer(); + SendCommand(&c); + UsbCommand resp; - //add locking bit information here. - if (print_ST_Lock_info(data[5]>>2)) - rawClose(); + if (!WaitForResponseTimeout(CMD_ACK, &resp, TIMEOUT)) { + if (verbose) PrintAndLog("timeout while waiting for reply."); + return FALSE; + } - return 1; -} + + iso14b_card_select_t card; + memcpy(&card, (iso14b_card_select_t *)resp.d.asBytes, sizeof(iso14b_card_select_t)); -// test for other 14b type tags (mimic another reader - don't have tags to identify) -int HF14B_Other_Reader(uint8_t *data, uint8_t *datalen){ - bool crc = true; - *datalen = 4; - //std read cmd - data[0] = 0x00; - data[1] = 0x0b; - data[2] = 0x3f; - data[3] = 0x80; - - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)!=0) { - if (*datalen > 2 || !crc) { - PrintAndLog ("\n14443-3b tag found:"); - PrintAndLog ("Unknown tag type answered to a 0x000b3f80 command ans:"); - PrintAndLog ("%s",sprint_hex(data,*datalen)); - rawClose(); - return 1; - } - } + uint64_t status = resp.arg[0]; - crc = false; - *datalen = 1; - data[0] = 0x0a; - - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)!=0) { - if (*datalen > 0) { - PrintAndLog ("\n14443-3b tag found:"); - PrintAndLog ("Unknown tag type answered to a 0x0A command ans:"); - PrintAndLog ("%s",sprint_hex(data,*datalen)); - rawClose(); - return 1; - } + switch( status ){ + case 0: + print_st_general_info(card.uid, card.uidlen); + isSuccess = TRUE; + break; + case 1: + if (verbose) PrintAndLog("iso14443-3 random chip id fail"); + break; + case 2: + if (verbose) PrintAndLog("iso14443-3 ATTRIB fail"); + break; + case 3: + if (verbose) PrintAndLog("iso14443-3 CRC fail"); + break; + default: + if (verbose) PrintAndLog("iso14443b card select SRx failed"); + break; } - crc = false; - *datalen = 1; - data[0] = 0x0c; - - if (HF14BCmdRaw(true, &crc, true, data, datalen, false)!=0) { - if (*datalen > 0) { - PrintAndLog ("\n14443-3b tag found:"); - PrintAndLog ("Unknown tag type answered to a 0x0C command ans:"); - PrintAndLog ("%s",sprint_hex(data,*datalen)); - rawClose(); - return 1; - } - } rawClose(); - return 0; + return isSuccess; } -// get and print all info known about any known 14b tag -int HF14BInfo(bool verbose){ - uint8_t data[USB_CMD_DATA_SIZE]; - uint8_t datalen = 5; +bool HF14B_Std_Reader(bool verbose){ - // try std 14b (atqb) - if (HF14BStdInfo(data, &datalen)) return 1; + bool isSuccess = FALSE; - // try st 14b - if (HF14B_ST_Info(data, &datalen)) return 1; + // 14b get and print UID only (general info) + UsbCommand c = {CMD_ISO_14443B_COMMAND, {ISO14B_CONNECT | ISO14B_SELECT_STD | ISO14B_DISCONNECT, 0, 0}}; + clearCommandBuffer(); + SendCommand(&c); + UsbCommand resp; + + if (!WaitForResponseTimeout(CMD_ACK, &resp, TIMEOUT)) { + if (verbose) PrintAndLog("timeout while waiting for reply."); + return FALSE; + } + + iso14b_card_select_t card; + memcpy(&card, (iso14b_card_select_t *)resp.d.asBytes, sizeof(iso14b_card_select_t)); + + uint64_t status = resp.arg[0]; + + switch( status ){ + case 0: + PrintAndLog(" UID : %s", sprint_hex(card.uid, card.uidlen)); + PrintAndLog(" ATQB : %s", sprint_hex(card.atqb, sizeof(card.atqb))); + PrintAndLog(" CHIPID : %02X", card.chipid); + print_atqb_resp(card.atqb, card.cid); + isSuccess = TRUE; + break; + case 2: + if (verbose) PrintAndLog("iso14443-3 ATTRIB fail"); + break; + case 3: + if (verbose) PrintAndLog("iso14443-3 CRC fail"); + break; + default: + if (verbose) PrintAndLog("iso14443b card select failed"); + break; + } + + rawClose(); + return isSuccess; +} - // try unknown 14b read commands (to be identified later) - // could be read of calypso, CEPAS, moneo, or pico pass. - if (HF14B_Other_Reader(data, &datalen)) return 1; +// test for other 14b type tags (mimic another reader - don't have tags to identify) +bool HF14B_Other_Reader(){ - if (verbose) PrintAndLog("no 14443B tag found"); - return 0; -} + // uint8_t data[] = {0x00, 0x0b, 0x3f, 0x80}; + // uint8_t datalen = 4; -// menu command to get and print all info known about any known 14b tag -int CmdHF14Binfo(const char *Cmd){ - return HF14BInfo(true); + // // 14b get and print UID only (general info) + // uint32_t flags = ISO14B_CONNECT | ISO14B_SELECT_STD | ISO14B_RAW | ISO14B_APPEND_CRC; + + // UsbCommand c = {CMD_ISO_14443B_COMMAND, {flags, datalen, 0}}; + // memcpy(c.d.asBytes, data, datalen); + + // clearCommandBuffer(); + // SendCommand(&c); + // UsbCommand resp; + // WaitForResponse(CMD_ACK,&resp); + + // if (datalen > 2 ) { + // printandlog ("\n14443-3b tag found:"); + // printandlog ("unknown tag type answered to a 0x000b3f80 command ans:"); + // //printandlog ("%s", sprint_hex(data, datalen)); + // rawclose(); + // return true; + // } + + // c.arg1 = 1; + // c.d.asBytes[0] = ISO14443B_AUTHENTICATE; + // clearCommandBuffer(); + // SendCommand(&c); + // UsbCommand resp; + // WaitForResponse(CMD_ACK, &resp); + + // if (datalen > 0) { + // PrintAndLog ("\n14443-3b tag found:"); + // PrintAndLog ("Unknown tag type answered to a 0x0A command ans:"); + // // PrintAndLog ("%s", sprint_hex(data, datalen)); + // rawClose(); + // return TRUE; + // } + + // c.arg1 = 1; + // c.d.asBytes[0] = ISO14443B_RESET; + // clearCommandBuffer(); + // SendCommand(&c); + // UsbCommand resp; + // WaitForResponse(CMD_ACK, &resp); + + // if (datalen > 0) { + // PrintAndLog ("\n14443-3b tag found:"); + // PrintAndLog ("Unknown tag type answered to a 0x0C command ans:"); + // PrintAndLog ("%s", sprint_hex(data, datalen)); + // rawClose(); + // return TRUE; + // } + + // rawClose(); + return FALSE; } // get and print general info about all known 14b chips -int HF14BReader(bool verbose){ - uint8_t data[USB_CMD_DATA_SIZE]; - uint8_t datalen = 5; +bool HF14BReader(bool verbose){ // try std 14b (atqb) - if (HF14BStdReader(data, &datalen)) return 1; + if (HF14B_Std_Reader(verbose)) return TRUE; - // try st 14b - if (HF14B_ST_Reader(data, &datalen, true)) return 1; + // try ST Microelectronics 14b + if (HF14B_ST_Reader(verbose)) return TRUE; // try unknown 14b read commands (to be identified later) // could be read of calypso, CEPAS, moneo, or pico pass. - if (HF14B_Other_Reader(data, &datalen)) return 1; + if (HF14B_Other_Reader()) return TRUE; if (verbose) PrintAndLog("no 14443B tag found"); - return 0; + return FALSE; } // menu command to get and print general info about all known 14b chips int CmdHF14BReader(const char *Cmd){ - return HF14BReader(true); + char cmdp = param_getchar(Cmd, 0); + if (cmdp == 'h' || cmdp == 'H') return usage_hf_14b_reader(); + + bool verbose = !((cmdp == 's') || (cmdp == 'S')); + return HF14BReader(verbose); } -int CmdSriWrite( const char *Cmd){ +/* New command to read the contents of a SRI512|SRIX4K tag + * SRI* tags are ISO14443-B modulated memory tags, + * this command just dumps the contents of the memory/ + */ +int CmdHF14BReadSri(const char *Cmd){ + char cmdp = param_getchar(Cmd, 0); + if (strlen(Cmd) < 1 || cmdp == 'h' || cmdp == 'H') return usage_hf_14b_read_srx(); + + uint8_t tagtype = param_get8(Cmd, 0); + uint8_t blocks = (tagtype == 1) ? 0x7F : 0x0F; + + UsbCommand c = {CMD_READ_SRI_TAG, {blocks, 0, 0}}; + clearCommandBuffer(); + SendCommand(&c); + return 0; +} +// New command to write a SRI512/SRIX4K tag. +int CmdHF14BWriteSri(const char *Cmd){ /* * For SRIX4K blocks 00 - 7F * hf 14b raw -c -p 09 $srix4kwblock $srix4kwdata @@ -629,26 +636,17 @@ int CmdSriWrite( const char *Cmd){ uint8_t blockno = -1; uint8_t data[4] = {0x00}; bool isSrix4k = true; - char str[20]; - - if (strlen(Cmd) < 1 || cmdp == 'h' || cmdp == 'H') { - PrintAndLog("Usage: hf 14b write <1|2> <BLOCK> <DATA>"); - PrintAndLog(" [1 = SRIX4K]"); - PrintAndLog(" [2 = SRI512]"); - PrintAndLog(" [BLOCK number depends on tag, special block == FF]"); - PrintAndLog(" sample: hf 14b write 1 7F 11223344"); - PrintAndLog(" : hf 14b write 1 FF 11223344"); - PrintAndLog(" : hf 14b write 2 15 11223344"); - PrintAndLog(" : hf 14b write 2 FF 11223344"); - return 0; - } + char str[30]; + memset(str, 0x00, sizeof(str)); + + if (strlen(Cmd) < 1 || cmdp == 'h' || cmdp == 'H') return usage_hf_14b_write_srx(); if ( cmdp == '2' ) isSrix4k = false; //blockno = param_get8(Cmd, 1); - if ( param_gethex(Cmd,1, &blockno, 2) ) { + if ( param_gethex(Cmd, 1, &blockno, 2) ) { PrintAndLog("Block number must include 2 HEX symbols"); return 0; } @@ -670,13 +668,21 @@ int CmdSriWrite( const char *Cmd){ return 0; } - if ( blockno == 0xff) - PrintAndLog("[%s] Write special block %02X [ %s ]", (isSrix4k)?"SRIX4K":"SRI512" , blockno, sprint_hex(data,4) ); - else - PrintAndLog("[%s] Write block %02X [ %s ]", (isSrix4k)?"SRIX4K":"SRI512", blockno, sprint_hex(data,4) ); - - sprintf(str, "-c 09 %02x %02x%02x%02x%02x", blockno, data[0], data[1], data[2], data[3]); - + if ( blockno == 0xff) { + PrintAndLog("[%s] Write special block %02X [ %s ]", + (isSrix4k) ? "SRIX4K":"SRI512", + blockno, + sprint_hex(data,4) + ); + } else { + PrintAndLog("[%s] Write block %02X [ %s ]", + (isSrix4k) ? "SRIX4K":"SRI512", + blockno, + sprint_hex(data,4) + ); + } + + sprintf(str, "-ss -c %02x %02x %02x%02x%02x%02x", ISO14443B_WRITE_BLK, blockno, data[0], data[1], data[2], data[3]); CmdHF14BCmdRaw(str); return 0; } @@ -816,19 +822,55 @@ int CmdteaSelfTest(const char *Cmd){ return 0; } +bool waitCmd(bool verbose) { + + bool crc = FALSE; + uint8_t b1 = 0, b2 = 0; + uint8_t data[USB_CMD_DATA_SIZE] = {0x00}; + uint8_t status = 0; + uint16_t len = 0; + UsbCommand resp; + + if (WaitForResponseTimeout(CMD_ACK, &resp, TIMEOUT)) { + + status = (resp.arg[0] & 0xFFFF); + if ( status > 0 ) return FALSE; + + len = (resp.arg[1] & 0xFFFF); + memcpy(data, resp.d.asBytes, len); + + if (verbose) { + + ComputeCrc14443(CRC_14443_B, data, len-2, &b1, &b2); + crc = ( data[len-2] == b1 && data[len-1] == b2); + + PrintAndLog("[LEN %u] %s[%02X %02X] %s", + len, + sprint_hex(data, len-2), + data[len-2], + data[len-1], + (crc) ? "OK" : "FAIL" + ); + } + return TRUE; + } else { + PrintAndLog("timeout while waiting for reply."); + return FALSE; + } +} + static command_t CommandTable[] = { {"help", CmdHelp, 1, "This help"}, {"info", CmdHF14Binfo, 0, "Find and print details about a 14443B tag"}, {"list", CmdHF14BList, 0, "[Deprecated] List ISO 14443B history"}, + {"raw", CmdHF14BCmdRaw, 0, "Send raw hex data to tag"}, {"reader", CmdHF14BReader, 0, "Act as a 14443B reader to identify a tag"}, {"sim", CmdHF14BSim, 0, "Fake ISO 14443B tag"}, {"snoop", CmdHF14BSnoop, 0, "Eavesdrop ISO 14443B"}, - {"sri512read", CmdSri512Read, 0, "Read contents of a SRI512 tag"}, - {"srix4kread", CmdSrix4kRead, 0, "Read contents of a SRIX4K tag"}, - {"sriwrite", CmdSriWrite, 0, "Write data to a SRI512 | SRIX4K tag"}, - {"raw", CmdHF14BCmdRaw, 0, "Send raw hex data to tag"}, + {"sriread", CmdHF14BReadSri, 0, "Read contents of a SRI512 | SRIX4K tag"}, + {"sriwrite", CmdHF14BWriteSri, 0, "Write data to a SRI512 | SRIX4K tag"}, //{"valid", srix4kValid, 1, "srix4k checksum test"}, - {"valid", CmdteaSelfTest, 1, "tea test"}, + //{"valid", CmdteaSelfTest, 1, "tea test"}, {NULL, NULL, 0, NULL} };