int usage_hf_14a_sim(void) {
// PrintAndLog("\n Emulating ISO/IEC 14443 type A tag with 4,7 or 10 byte UID\n");
PrintAndLog("\n Emulating ISO/IEC 14443 type A tag with 4,7 byte UID\n");
- PrintAndLog("Usage: hf 14a sim t <type> u <uid> x");
- PrintAndLog(" Options : ");
- PrintAndLog(" h : this help");
+ PrintAndLog("usage: hf 14a sim [h] t <type> u <uid> [x] [e] [v]");
+ PrintAndLog("options: ");
+ PrintAndLog(" h : This help");
PrintAndLog(" t : 1 = MIFARE Classic");
PrintAndLog(" 2 = MIFARE Ultralight");
PrintAndLog(" 3 = MIFARE Desfire");
PrintAndLog(" 7 = AMIIBO (NTAG 215), pack 0x8080");
// PrintAndLog(" u : 4, 7 or 10 byte UID");
PrintAndLog(" u : 4, 7 byte UID");
- PrintAndLog(" x : (Optional) performs the 'reader attack', nr/ar attack against a legitimate reader");
- PrintAndLog(" v : (Optional) show maths used for cracking reader. Useful for debugging.");
- PrintAndLog("\n sample : hf 14a sim t 1 u 11223344 x");
- PrintAndLog(" : hf 14a sim t 1 u 11223344");
- PrintAndLog(" : hf 14a sim t 1 u 11223344556677");
-// PrintAndLog(" : hf 14a sim t 1 u 11223445566778899AA\n");
+ PrintAndLog(" x : (Optional) Performs the 'reader attack', nr/ar attack against a reader");
+ PrintAndLog(" e : (Optional) Fill simulator keys from found keys");
+ PrintAndLog(" v : (Optional) Verbose");
+ PrintAndLog("samples:");
+ PrintAndLog(" hf 14a sim t 1 u 11223344 x");
+ PrintAndLog(" hf 14a sim t 1 u 11223344");
+ PrintAndLog(" hf 14a sim t 1 u 11223344556677");
+// PrintAndLog(" hf 14a sim t 1 u 11223445566778899AA\n");
return 0;
}
int usage_hf_14a_sniff(void){
uint8_t uid[10] = {0,0,0,0,0,0,0,0,0,0};
int uidlen = 0;
bool useUIDfromEML = TRUE;
- bool verbose = false;
+ bool setEmulatorMem = FALSE;
+ bool verbose = FALSE;
while(param_getchar(Cmd, cmdp) != 0x00) {
switch(param_getchar(Cmd, cmdp)) {
// Retrieve the tag type
tagtype = param_get8ex(Cmd, cmdp+1, 0, 10);
if (tagtype == 0)
- errors = true;
+ errors = TRUE;
cmdp += 2;
break;
case 'u':
flags |= FLAG_NR_AR_ATTACK;
cmdp++;
break;
+ case 'e':
+ case 'E':
+ setEmulatorMem = TRUE;
+ cmdp++;
+ break;
default:
PrintAndLog("Unknown parameter '%c'", param_getchar(Cmd, cmdp));
errors = true;
if ( useUIDfromEML )
flags |= FLAG_UID_IN_EMUL;
- PrintAndLog("Press pm3-button to abort simulation");
-
UsbCommand c = {CMD_SIMULATE_TAG_ISO_14443a,{ tagtype, flags, 0 }};
memcpy(c.d.asBytes, uid, uidlen>>1);
clearCommandBuffer();
nonces_t data[ATTACK_KEY_COUNT*2];
UsbCommand resp;
-
+
+ PrintAndLog("Press pm3-button to abort simulation");
while( !ukbhit() ){
if (!WaitForResponseTimeout(CMD_ACK, &resp, 1500) ) continue;
-
if ( !(flags & FLAG_NR_AR_ATTACK) ) break;
if ( (resp.arg[0] & 0xffff) != CMD_SIMULATE_MIFARE_CARD ) break;
memcpy( data, resp.d.asBytes, sizeof(data) );
- readerAttack(data, TRUE, verbose);
+ readerAttack(data, setEmulatorMem, verbose);
}
return 0;
}
return 0;\r
}\r
int usage_hf14_mf1ksim(void){\r
- PrintAndLog("Usage: hf mf sim [h] u <uid (8,14,20 hex symbols)> n <numreads> i x");\r
+ PrintAndLog("Usage: hf mf sim [h] u <uid> n <numreads> [i] [x] [e] [v]");\r
PrintAndLog("options:");\r
PrintAndLog(" h this help");\r
PrintAndLog(" u (Optional) UID 4,7 or 10bytes. If not specified, the UID 4b from emulator memory will be used");\r
PrintAndLog(" n (Optional) Automatically exit simulation after <numreads> blocks have been read by reader. 0 = infinite");\r
PrintAndLog(" i (Optional) Interactive, means that console will not be returned until simulation finishes or is aborted");\r
- PrintAndLog(" x (Optional) Crack, performs the 'reader attack', nr/ar attack against a legitimate reader, fishes out the key(s)");\r
- PrintAndLog(" e (Optional) Fill simulator keys from what we crack");\r
- PrintAndLog(" v (Optional) Show maths used for cracking reader. Useful for debugging.");\r
+ PrintAndLog(" x (Optional) Crack, performs the 'reader attack', nr/ar attack against a reader");\r
+ PrintAndLog(" e (Optional) Fill simulator keys from found keys");\r
+ PrintAndLog(" v (Optional) Verbose");\r
PrintAndLog("samples:");\r
PrintAndLog(" hf mf sim u 0a0a0a0a");\r
PrintAndLog(" hf mf sim u 11223344556677");\r
PrintAndLog(" hf mf sim u 112233445566778899AA"); \r
+ PrintAndLog(" hf mf sim u 11223344 i x"); \r
return 0;\r
}\r
int usage_hf14_dbg(void){\r
k_sector[i].foundKey[1] = FALSE;\r
}\r
\r
- printf("enter reader attack\n");\r
+ if (verbose) printf("enter Moebius attack (mfkey32v2) \n");\r
+ \r
for (uint8_t i = 0; i < ATTACK_KEY_COUNT; ++i) {\r
\r
// if no-collected data \r
uint8_t sectorNum = data[i+ATTACK_KEY_COUNT].sector;\r
uint8_t keyType = data[i+ATTACK_KEY_COUNT].keytype;\r
\r
- PrintAndLog("Found Key%s for sector %02d: [%012"llx"]"\r
+ PrintAndLog("Reader is trying authenticate with: Key %s, sector %02d: [%012"llx"]"\r
, keyType ? "B" : "A"\r
, sectorNum\r
, key\r
\r
while( !ukbhit() ){\r
if (!WaitForResponseTimeout(CMD_ACK, &resp, 1500) ) continue;\r
-\r
if ( !(flags & FLAG_NR_AR_ATTACK) ) break;\r
if ( (resp.arg[0] & 0xffff) != CMD_SIMULATE_MIFARE_CARD ) break;\r
\r
}\r
\r
if (k_sector != NULL) {\r
- printKeyTable(k_sectorsCount, k_sector );\r
+ printKeyTable(k_sectorsCount, k_sector);\r
free(k_sector);\r
k_sector = NULL;\r
}\r