iceman1001 [Tue, 12 Jan 2016 21:33:54 +0000 (22:33 +0100)]
FIX: Coverity, unintended sign extention, CID #121363, (numbits << 16) becomes int, then uint64_t. But the signness might set all upper bits to 1 in the process.
iceman1001 [Tue, 12 Jan 2016 21:30:22 +0000 (22:30 +0100)]
FIX: Coverity, unchecked return value, CID #121292,..
basicallty the flush queue commmand is replaced with clearCommandBuffer();.
iceman1001 [Tue, 12 Jan 2016 21:15:49 +0000 (22:15 +0100)]
FIX: Coverity, out-of-bounds write, CID# 121336, s_index should take factor in consideration when looping. Not sure about this one.
FIX: another thing struck me, the g_index wasn't increased, meaning the "un-decimation" always worked on the same first byte of GraphBuffer.
iceman [Tue, 12 Jan 2016 09:39:23 +0000 (10:39 +0100)]
ADD: created some build scripts for the CoverityScans
iceman1001 [Sat, 9 Jan 2016 16:20:58 +0000 (17:20 +0100)]
Merge branch 'master' of https://github.com/iceman1001/proxmark3
iceman1001 [Sat, 9 Jan 2016 16:20:06 +0000 (17:20 +0100)]
FIX: minor fixes to the HID wiegand generation command. Still not complete
iceman1001 [Sat, 9 Jan 2016 16:19:09 +0000 (17:19 +0100)]
CHG: syntax suger
iceman1001 [Sat, 9 Jan 2016 16:17:36 +0000 (17:17 +0100)]
ADD: a new pwdgen algo Nicknamed C, (Huge props to @Bettse for everything) also added to the "hf mfu info" command. However, that will not work given the system's lockbits.. :( Maybe I'll add a function to test all imp pwdgens given a UID without making a authentication call to tag.
ADD: BSWAP_32 macro, for changing endianness.
iceman1001 [Sat, 9 Jan 2016 16:13:54 +0000 (17:13 +0100)]
ADD: Travis now builds automatically.
Iceman [Fri, 8 Jan 2016 21:40:02 +0000 (22:40 +0100)]
Update README.txt
iceman1001 [Fri, 8 Jan 2016 21:30:36 +0000 (22:30 +0100)]
fix: gcc-arm-none-eabi still not working...
iceman1001 [Fri, 8 Jan 2016 21:27:09 +0000 (22:27 +0100)]
ADD: added gcc-arm-none-eabi compiler to travie script
iceman1001 [Fri, 8 Jan 2016 21:18:15 +0000 (22:18 +0100)]
CHG: added the make command
iceman1001 [Fri, 8 Jan 2016 21:14:22 +0000 (22:14 +0100)]
ADD: added integration with Travis CI,
iceman1001 [Fri, 8 Jan 2016 14:29:06 +0000 (15:29 +0100)]
FIX: @marshmellow42 's cleanup of includes.
iceman1001 [Fri, 8 Jan 2016 14:28:24 +0000 (15:28 +0100)]
FIX: coverty scan defects.
- bigbuf.c is comparision correct (iLen versus numofparity)
- cmdhfepa.c resourceleak, add a call to free
- cipherutils.c resourceleak, added calls to free
iceman1001 [Fri, 8 Jan 2016 13:31:27 +0000 (14:31 +0100)]
REM: code cleanup.
iceman1001 [Fri, 8 Jan 2016 13:30:56 +0000 (14:30 +0100)]
FIX: coverty scan, resourceleak in "hf mf sniff", added call to 'free' befor return.
FIX: coverty scan, overflow in "hf 14a raw", added an extra len check against USB_CMD_DATA_SIZE
iceman1001 [Fri, 8 Jan 2016 13:28:13 +0000 (14:28 +0100)]
ADD: @go_tus 's code to generate wiegand codes from FacilityCode/SiteCode and Cardnumber. Almost there, formatlength supported is 26,34,35,37,38,40,44,75,84, when its finised.
iceman1001 [Fri, 8 Jan 2016 13:26:35 +0000 (14:26 +0100)]
Syntax suger, making the code easier to read (for me at least)
iceman1001 [Fri, 8 Jan 2016 13:25:10 +0000 (14:25 +0100)]
FIX: coverty scan reveals some resourceleaks and overruns, which is supposed to be fixed now.
/armsrc/des.c overflow 7 instead of 6
/client/cmdlfhitag.c overflows traclen
/client/util.c sprint_bin_break overflows.
/client/cmdhficlass.c need to free memory after malloc.
ADD: RotateRight macro in util.h
Iceman [Fri, 8 Jan 2016 12:29:59 +0000 (13:29 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:29:01 +0000 (13:29 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:24:56 +0000 (13:24 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:22:05 +0000 (13:22 +0100)]
Update README.txt
Iceman [Wed, 6 Jan 2016 17:38:12 +0000 (18:38 +0100)]
Update README.txt
Iceman [Wed, 6 Jan 2016 17:34:43 +0000 (18:34 +0100)]
added coverty build scan badge
iceman1001 [Mon, 4 Jan 2016 09:13:38 +0000 (10:13 +0100)]
ADD: added a Q5 parameter for "lf t55xx wipe",
the default config blocks is:
t55x7 :
000880E0
t5555 (Q5) :
6001F004
iceman1001 [Mon, 4 Jan 2016 09:11:20 +0000 (10:11 +0100)]
ADD: added @pwpiwi 's corrections to "hf mf hardnested"
iceman1001 [Sun, 3 Jan 2016 16:17:44 +0000 (17:17 +0100)]
code clean up, added some comments to hitag
iceman1001 [Sun, 3 Jan 2016 16:16:50 +0000 (17:16 +0100)]
added @pwpiwi 's latest changes to "hf mf hardnested"
iceman1001 [Sun, 3 Jan 2016 16:16:06 +0000 (17:16 +0100)]
added @broken_bad's imp of showing T555/Q5 trace data. (with my modifications ;) )
iceman1001 [Wed, 23 Dec 2015 22:26:03 +0000 (23:26 +0100)]
REM: removed an offensive #include on archlinux. Compiles on mingw without.
iceman1001 [Wed, 23 Dec 2015 10:59:34 +0000 (11:59 +0100)]
FIX: removed printBits reference.
iceman1001 [Tue, 22 Dec 2015 15:14:03 +0000 (16:14 +0100)]
FIX: the usb_poll_validate_length() check should be inversed, thanks @marshmellow42
iceman1001 [Mon, 21 Dec 2015 18:48:33 +0000 (19:48 +0100)]
ADD: @marshmellow42 's changes to "hf mfu dump"
iceman1001 [Mon, 21 Dec 2015 18:48:00 +0000 (19:48 +0100)]
CHG: some textual change to README.txt
ADD: a prng.c to collect some different PRNG's i've ran into
ADD: some changes the tea implementation
ADD: a enhanced version - SwapEndian64ex
iceman1001 [Mon, 21 Dec 2015 18:44:47 +0000 (19:44 +0100)]
add: added @AdamLaurie 's iclass raw keys changes
iceman1001 [Wed, 16 Dec 2015 10:01:46 +0000 (11:01 +0100)]
ADD: @marshmellow42 's fixes for Q5, t55xx, fskclock,
ADD: got tired of always writing wrong "hf 14a list", so I hooked it back up to call the "hf list" with argument. Things becomes smoother that way.
iceman1001 [Tue, 15 Dec 2015 08:34:55 +0000 (09:34 +0100)]
ADD: @marshmellow42 's changes to "hf mfu *" ,
ADD: @marshmellow42 's changes to "hf mf sim",
ADD: @pwpiwi 's parity files was missing.
iceman1001 [Tue, 15 Dec 2015 07:51:29 +0000 (08:51 +0100)]
ADD: @pwpiwi 's latest code from his 'hardnested' branch.
iceman1001 [Mon, 14 Dec 2015 21:52:04 +0000 (22:52 +0100)]
FIX: minor fixes in hf mfu, from @marshmello42 's branch.
iceman1001 [Mon, 14 Dec 2015 21:50:54 +0000 (22:50 +0100)]
REM: removed an unused doublett function "printBits" in util.c
ADD: added a new string helper function "sprint_hex_ascii" in util.c
ADD: added "LF AWID BRUTE", a very simple bruteforce command for the awid commands.
it takes a facility-code, and iterates all possible 0xFFFF cardnum by sending sim command. It also uses the usb_poll function to stop the bruteforce on keypress and not leaving the pm3 device running the simulation.
the command implements the help parameter.
iceman1001 [Thu, 10 Dec 2015 09:30:13 +0000 (10:30 +0100)]
ADD: @marshmellow42 's fixes to cmdlft55xx.c (save_restoreGB)
ADD: started with a skeleton method for printing hex and ascill.
iceman1001 [Wed, 9 Dec 2015 14:29:18 +0000 (15:29 +0100)]
Two fixes for warnings when compiling on Ubuntu14.04.
FIX: a wrongly set parameter call to memset in CmdT55xxWipe .
FIX: an ignored fread call in cmdhficlass.c,
iceman1001 [Wed, 9 Dec 2015 13:58:16 +0000 (14:58 +0100)]
ADD: @marshmello42 's fixes for low frequency demodulation lengths greater the 512bits.
iceman1001 [Wed, 9 Dec 2015 13:57:16 +0000 (14:57 +0100)]
ADD: a TEA crypto algorithm implemention.
iceman1001 [Sat, 5 Dec 2015 21:18:42 +0000 (22:18 +0100)]
added some keys
iceman1001 [Wed, 2 Dec 2015 22:06:03 +0000 (23:06 +0100)]
ADD: hooked up the new pwdgen functions inside the "hf mfu info", to be tested if the authlimit is not set.
iceman1001 [Wed, 2 Dec 2015 21:46:11 +0000 (22:46 +0100)]
CHG: updated helptext for lf t55xx bruteforce
ADD: a ROL function in util.c
ADD: two pwdgen functions in cmdhfmfu.c, call them with a 7byte UID and get a 4byte number back. Will see if it can be connected with the "hf mfu info" command, make data extraction easier later on.
ADD: added some more easy pwd in the dictionary file default_pwd.dic
iceman1001 [Wed, 2 Dec 2015 15:48:25 +0000 (16:48 +0100)]
add: missing two hard_nested files..
iceman1001 [Tue, 1 Dec 2015 21:47:03 +0000 (22:47 +0100)]
ADD: Added the possibility to exit the bruteforce mode (either rangesearch or file) with the keyboard.
FIX: if not found, the range search printed wrong number.
iceman1001 [Tue, 1 Dec 2015 21:38:37 +0000 (22:38 +0100)]
FIX: the lfsampling.c for t55xx had a tendecy to enter a neverending loop. Moved exit branch into the while statement, which seems to solve it.
FIX: Strange int -> uint8_t casting behavior (0x05 gets the 25bit set and becomes 0x10005 instead) in fskdemod, removed int and sscanf.
iceman1001 [Tue, 1 Dec 2015 19:44:12 +0000 (20:44 +0100)]
FIX: added a break if the device starts acting strange when aquirering data from tag.
iceman1001 [Tue, 1 Dec 2015 15:44:53 +0000 (16:44 +0100)]
FIXES: the custom keys testloop now increases the read pwd :)
iceman1001 [Tue, 1 Dec 2015 12:07:01 +0000 (13:07 +0100)]
ADD: added the possibility to load a default pwd file to be used with the "lf t55xx bruteforce" command.
new option:
lf t55xx brutefore i default_pwd.dic - will load default pwds from file and test against tag.
iceman1001 [Fri, 27 Nov 2015 16:00:48 +0000 (17:00 +0100)]
textual fix.
iceman1001 [Fri, 27 Nov 2015 15:59:35 +0000 (16:59 +0100)]
FIX: the t55xx bruteforce method got some fixes, in commandname, uint32_t instead of int, and output texts.
iceman1001 [Fri, 27 Nov 2015 15:24:00 +0000 (16:24 +0100)]
ADD: @go_tus simple bruteforce for t55xx, refactored a bit.
ADD: @pwpiwi 's implementation of Hardnested
iceman1001 [Mon, 23 Nov 2015 09:49:16 +0000 (10:49 +0100)]
CHG: Missing some headers
FIX: some message/warning in pm3_binlib.c @gm4tr1x
iceman1001 [Sun, 22 Nov 2015 20:48:15 +0000 (21:48 +0100)]
FIX: the read counter in "hf 14a sim" (for ntag/ev) should work better now. Instead of always returning zero, it increases aswell.
--Started to add the TI demod into the 'LF SEARCH"
iceman1001 [Sun, 22 Nov 2015 17:13:26 +0000 (18:13 +0100)]
ADD: 'hf mfu info' now prints following settings:
NFC_COUNTER_EN - If set, every read,fast_read increases a counter.
NFC_COUNTER_PROT_PWD - If set, reading nfc_counter needs a successfull pwd authentication before
These new settings is only valid for NTAG213/215/216,
iceman1001 [Sun, 22 Nov 2015 16:33:41 +0000 (17:33 +0100)]
ADD: @marshmellow's fixes to awid, viking and T55x7
ADD: 'lf t55xx detect' now can be called with a password.
ADD: trying to add the read counter and increase counter commands for ntag sim.
iceman1001 [Sat, 21 Nov 2015 17:48:58 +0000 (18:48 +0100)]
ADD: lf indalademod output, The binary string is now printed with linebreaks every 16bits
ADD: lf awid code is modified, some minor changes in outputs
ADD: lf t55xx write now prints the password on the same row, looks better when using the new "lf t55xx wipe" command.
ADD: the ioprox T55X7_IOPROX_CONFIG_BLOCK block.
iceman1001 [Fri, 20 Nov 2015 15:56:43 +0000 (16:56 +0100)]
@marshmellows last LF changes.
- wipe a t55x7 tag
- stable demods
-
iceman1001 [Tue, 10 Nov 2015 17:56:43 +0000 (18:56 +0100)]
FIX: some fixes to indalademod and viking from @marshmellow42
iceman1001 [Tue, 10 Nov 2015 10:45:45 +0000 (11:45 +0100)]
FIX: an error that I introduced to the csetblock command with wrong length of crc calcs.
CHG: variable name in csetblock change. just trying to be consistant.
ADD: code clean up in hf 14a, added some help text methods.
iceman1001 [Tue, 10 Nov 2015 10:42:59 +0000 (11:42 +0100)]
added @marshmellows new viking demod.
adjusted it to fit with the clone/demod that is under "lf viking" commands.
did some code clean up, 3spaces into tab.
iceman1001 [Mon, 9 Nov 2015 21:06:48 +0000 (22:06 +0100)]
fix: forgot to remove this when merging piwi's fixes.
iceman1001 [Mon, 9 Nov 2015 20:51:34 +0000 (21:51 +0100)]
CHG: minor code clean up, removed commented old code.
ADD: usb_poll_validate_length to some deviceside loops.
ADD: @marshmellow42 's fixes to LF
iceman1001 [Mon, 9 Nov 2015 20:49:02 +0000 (21:49 +0100)]
ADD: @marshmellow fix for em41x clock.
CHG: swap the int to a uint8_t to skip a compiler error
iceman1001 [Mon, 9 Nov 2015 20:48:09 +0000 (21:48 +0100)]
ADD: @piwi's fixes to "hf snoop" where it empties the bigbuffer before snooping.
iceman1001 [Mon, 9 Nov 2015 20:47:26 +0000 (21:47 +0100)]
ADD: @piwi's changes to .gitignore.
iceman1001 [Mon, 9 Nov 2015 20:46:57 +0000 (21:46 +0100)]
ADD: @piwi's fixes to .history
iceman1001 [Mon, 9 Nov 2015 20:46:15 +0000 (21:46 +0100)]
CHG: a major remake of the "hf mf c*" commands. Ie chinese magic tags. Tried to make them consistent in parameter calls and simplified. And fixed the annoying gen1 tags that answers with a ACK/NACK on HALT commands..
iceman1001 [Mon, 2 Nov 2015 19:47:15 +0000 (20:47 +0100)]
ADD: @bm2gii some kind of andriod fix for the lua.
iceman1001 [Mon, 2 Nov 2015 19:46:17 +0000 (20:46 +0100)]
ADD: @marshmellow42 's fixex and resetread t55x7
iceman1001 [Mon, 2 Nov 2015 10:41:25 +0000 (11:41 +0100)]
CHG: @ematrix / @piwi fixes for 'hf snoop'
iceman1001 [Sun, 1 Nov 2015 21:16:16 +0000 (22:16 +0100)]
CHG: some magic generation1 tags is not following protocol and answers to the "halt" command. This gives an error and makes the users think something went wrong. This also affected the magic identification in "Hf 14a reader" command, where it in those moments stated "NO" even if the tag is indeed a generation1.
iceman1001 [Sun, 1 Nov 2015 18:49:08 +0000 (19:49 +0100)]
ADD: help text for 'hf snoop' / 'hf search' / 'hf list'
CHG: minor code changes.
CHG: makefile , moved hi_sniffer.v from LF into HF row. @piwi suggestion for PR https://github.com/Proxmark/proxmark3/pull/141
iceman1001 [Fri, 30 Oct 2015 08:10:09 +0000 (09:10 +0100)]
CHG: the updated fpga image for the "hf snoop"
iceman1001 [Fri, 30 Oct 2015 08:09:35 +0000 (09:09 +0100)]
CHG: some desfire changes from @bforbort fork. *untested*
iceman1001 [Fri, 30 Oct 2015 08:07:04 +0000 (09:07 +0100)]
ADD: a minor xor script
iceman1001 [Fri, 30 Oct 2015 08:05:22 +0000 (09:05 +0100)]
ADD: @gm4tr1x found some new known mifare keys.
iceman1001 [Tue, 27 Oct 2015 20:47:21 +0000 (21:47 +0100)]
ADD: added the "hf snoop" patch original from @Enio, rearranged by @Etmatrix.
ADD: added the "t55x7" refactoring by @marshmellow42
iceman1001 [Wed, 21 Oct 2015 07:12:33 +0000 (09:12 +0200)]
ADD: 'LF T55X7 WAKEUP' command. For tags with AOR bit set, send this command with password to wake tag up and be able to do a "LF SEARCH" etc on it.
CHG: Minor code changes on T55X7 code. Default password is back to 'FF FF FF FF',
REM: removed @marshmellow42 's wakeup option in "lf t55x7 read",
--- BASICALLY:
if a T55X7 tag has following bits set:
AOR - send wakeup command with pwd, to enable LF interacting with it.
PWD - send read/write/trace/info command with pwd. No need to send wakeup.
iceman1001 [Wed, 21 Oct 2015 07:07:36 +0000 (09:07 +0200)]
CHG: move some methods, its easier to read now. Cosmetic change.
iceman1001 [Tue, 20 Oct 2015 17:02:03 +0000 (19:02 +0200)]
CHG: some cleanup of pcf7931.c
iceman1001 [Tue, 20 Oct 2015 17:00:02 +0000 (19:00 +0200)]
ADD: @marshmellows42 's fixes for "lf cmdread" and CHANGELOG.md
ADD: Added the "lf t55x7 wakeup" command. It will send a pwd, and leave the antenna on.
Process like:
1. lf t55x7 wakeup p
11223344
2. lf search
---
It is still not finished, will work together with the "lf t55x7 commands" in next step when I figure out the process from the datasheets.
iceman1001 [Mon, 19 Oct 2015 20:41:53 +0000 (22:41 +0200)]
ADD: some more keys found on a pastebin
iceman1001 [Mon, 19 Oct 2015 20:39:08 +0000 (22:39 +0200)]
FIX: tnp3sim, now can insert keys if the dumpfile is blank. Like the ,,,lander dumps...
iceman1001 [Sat, 17 Oct 2015 12:35:04 +0000 (14:35 +0200)]
FIX: "abort trap 6" error when runing the tnp3sim.lua script was because the CMD_MIFARE_EML_MEMSET needs to sent the bytewitdh now with recent changes in code to deal with different sizes in emulatormemory. the third argument should be 16 instead of 0.
iceman1001 [Sat, 17 Oct 2015 12:16:42 +0000 (14:16 +0200)]
FIX: @tony pointed out that there was a method name lost... its been reinstated :)
iceman1001 [Fri, 16 Oct 2015 21:16:46 +0000 (23:16 +0200)]
FIX: thanks @tony, for pointing out a "end" statement inside tnp3sim.lua
ADD: @marshmello42 fixs for t55x7
iceman1001 [Thu, 15 Oct 2015 17:30:11 +0000 (19:30 +0200)]
test
iceman1001 [Thu, 15 Oct 2015 17:17:20 +0000 (19:17 +0200)]
FIX: a suggested fix for #136 where the "lf t55x7 read" command when called with a password. The call will now try loading the config block, decode it and see if PWD is set.
If PWD Bit is set, the call will be allowed to execute.
If PWD Bit is NOT set, the call will print a message and excute the call but without sending the password.
If config block is not being able to read or decode, the call with print a warning message and exit the call.
iceman1001 [Thu, 15 Oct 2015 09:30:37 +0000 (11:30 +0200)]
CHG: code clean up. Have some questions regarding the CopyVikingTo method. The configblock looks wrong..
iceman1001 [Thu, 15 Oct 2015 09:00:07 +0000 (11:00 +0200)]
CHG: minor updates in the T55x7 methods. added the LED_A_ON / LED_A_OFF to indicate when a T55x7 command is running.
CHG: added some more comments to T55x7, next person who looks at this will have it easier.
iceman1001 [Thu, 15 Oct 2015 08:23:15 +0000 (10:23 +0200)]
ADD: @marshmellows fixes for t55x7 reading signal.
ADD: @marshmellows "diphase" definition for T55x7.
MOV: extracted the aquisition from the t55x7 methods and put them inside lfsampling.c
FIX: pcf7931 write, there is 16bytes in a block.. not 4 as I thought before.
FIX: t55x7 lowered the WRITE_0 to 16. Even bigger gap.
iceman1001 [Wed, 14 Oct 2015 09:39:51 +0000 (11:39 +0200)]
FIX: The T55x7ReadBlock method, should not have the startgap since it indicats that it might be a write command. See if this fixes the bug.
ADD: Extracted the whole pcf7931 functionality into seperat files. The lfops.c is starting to become too large.