Commit Graph
280 Commits
Author SHA1 Message Date
GameTec-live 39a597b5ea Merge branch 'main' into ulc 2026-10-04 10:37:12 +02:00
GameTec-live ccf60753f9 Merge pull request #426 from azuwis/fix-autopwn-hardnested
Deploy wiki to GitHub Pages with Jekyll / build (push) Canceled after 0s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Canceled after 0s
Firmware build / Build fw-builder Docker image (push) Canceled after 0s
Firmware build / Build firmware (lite) (push) Canceled after 0s
Firmware build / Build firmware (ultra) (push) Canceled after 0s
Push handler / Build Firmware (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-linux.zip" .) , linux, ubuntu-latest, true ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-macos.zip" .) , macos, macos-latest, true ) (push) Canceled after 0s
Client build / Build client (Compress-Archive -Path software\dist\* -DestinationPath client-windows.zip , windows, windows-latest, ? . ) (push) Canceled after 0s
Push handler / Create dev pre-release with artifacts (push) Canceled after 0s
Push handler / Create tagged release with artifacts (push) Canceled after 0s
Push handler / Start the next PR review cycle (push) Canceled after 0s
fix: fall back to hardnested in autopwn when nested fails
2026-09-10 08:46:37 +02:00
GameTec-live 66a36881cf Merge pull request #425 from azuwis/fix-hf-mf-dump
fix: fill both key A and key B in sector trailer when dumping
2026-09-10 08:45:46 +02:00
Didier A cf4595e953 Merge branch 'RfidResearchGroup:main' into parity-check 2026-09-07 14:10:12 +02:00
GameTec-live aa881ee596 Merge pull request #424 from azuwis/fix-hf-mf-fchk
Deploy wiki to GitHub Pages with Jekyll / build (push) Canceled after 0s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Canceled after 0s
Firmware build / Build firmware (ultra) (push) Canceled after 0s
Firmware build / Build firmware (lite) (push) Canceled after 0s
Firmware build / Build fw-builder Docker image (push) Canceled after 0s
Client build / Build client (Compress-Archive -Path software\dist\* -DestinationPath client-windows.zip , windows, windows-latest, ? . ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-macos.zip" .) , macos, macos-latest, true ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-linux.zip" .) , linux, ubuntu-latest, true ) (push) Canceled after 0s
Push handler / Create dev pre-release with artifacts (push) Canceled after 0s
Push handler / Create tagged release with artifacts (push) Canceled after 0s
Push handler / Start the next PR review cycle (push) Canceled after 0s
Push handler / Build Firmware (push) Canceled after 0s
fix: load_key_file and load_dic_file for hf mf fchk
2026-09-07 13:59:54 +02:00
DidierA 52ff1d0fb6 add space for correct alignment 2026-09-07 11:26:16 +02:00
DidierA 38a745fdf4 hf 14a sniff: add parity checks 2026-09-07 11:26:05 +02:00
Aaron Tulino (Aaronjamt) 1f99ddd4db SEOS emulation support 2026-07-28 11:18:18 -07:00
GameTec-live dd5b11642d Merge pull request #317 from bob-zebedy/fix/pyinstaller-bin-path
fix: resolve binary tools detection after PyInstaller packaging
2026-07-04 13:15:14 +02:00
Foxushka d8e85d53dc feat: add change key command 2026-06-13 13:01:15 +03:00
Foxushka 2999d9dd5f feat: MIFARE Ultralight C authentication and emulation 2026-06-13 11:38:40 +03:00
Milan DavídekandClaude Opus 4.7 52f37bff8d Merge upstream/main into Jablotron PR #404
Resolved conflicts from upstream feature additions (IDTECK PR #407,
LF_T55XX_WRITE PR #413, ISO14443-4 T=CL emulation, HF14A scan-keep,
etc.) by keeping both sides where independent.

Command ID note for reviewer:
- Maintainer's IDTECK shift commit (1e78976) stated "Jablotron retains
  the original slots 3016 and 3017", but upstream had already taken
  3016 for DATA_CMD_LF_T55XX_WRITE. Only 3017 was actually free.
- Resolution: JABLOTRON_WRITE_TO_T55XX kept at 3017 (honors intent).
  JABLOTRON_SCAN moved 3016 -> 3019 (next free slot).
- 5xxx range: JABLOTRON_SET/GET_EMU_ID = 5010/5011 unchanged
  (IDTECK shifted to 5012/5013 as planned).

Python files parse cleanly. No duplicate command IDs in data_cmd.h
(3xxx and 5xxx ranges checked).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:51:54 +02:00
matteoscrugli 729a7e56ea feat(cli): add lf idteck subgroup and extend lf clone with idteck type
Adds host-side CLI support for IDTECK:
- lf idteck econfig -s <slot> [--id <hex>]   set or read the emulated frame
- lf idteck write --id <hex>                 clone to a T55xx tag in reader mode
- lf clone -t idteck --id <hex>              same via the unified clone command
- hw slot list                                now renders Frame and Card ID
                                              for IDTECK slots

Input accepts 16 hex characters for the full 64-bit frame, or 8 hex
for the 32-bit payload (the fixed preamble 4944544B is auto-prepended).
A non-blocking informational note is emitted when the payload checksum
does not match the value computed from the card number, since some
readers validate this field and some do not.

Private helpers in chameleon_cli_unit.py (_idteck_compute_checksum,
_idteck_compose_frame, _idteck_frame_info) parse and compose IDTECK
frames and expose card-number-driven composition for a future
`lf idteck compose` command.
2026-05-15 10:09:51 +02:00
Zhong Jianxin f39de047be fix: fall back to hardnested in autopwn when nested fails
When nt_level is 1 (PRNG_WEAK), nested recovery can fail because
recover_a_key re-detects the PRNG and returns None if it's actually
HardNested (nt_level == 2). Also, the PRNG detection can misclassify
a HardNested tag as PRNG_WEAK from a single NT sample.

Now autopwn tries hardnested as a fallback when nested returns None.
2026-05-13 20:56:54 +08:00
Zhong Jianxin d13001bab8 fix: load_key_file and load_dic_file for hf mf fchk
load_key_file (--key): read raw 6-byte binary keys instead of
trying UTF-8 decode, which failed on binary key files.

load_dic_file (--dic): implement stub that was just returning
keys unchanged; now reads 12-char hex keys line by line.
2026-05-13 20:14:54 +08:00
Zhong Jianxin 7b1faccc52 fix: fill both key A and key B in sector trailer when dumping
MIFARE Classic blanks the authenticated key bytes when reading a
sector trailer. Find both key A and key B for each sector, then
fill both into the trailer from known keys instead of relying on
the read response.
2026-05-13 19:23:04 +08:00
Niel Nielsen cba4b84c4a FIX MFDEs version detection
Fixes version detection of MFDes info
2026-05-13 12:31:24 +02:00
Niel Nielsen b973385f8f Add full DESFire key check command with 3K3DES support
Adds hf des chk and hf des info commands for MIFARE DESFire EV1/EV2/EV3 key checking and card info enumeration.

Tested against: DESFire EV1 (SAK 0x20, 2KB storage) via Chameleon Ultra v2.1 USB
2026-05-12 11:21:24 +02:00
Niel Nielsen cef8b42c26 make_style as that is best practise 2026-05-11 12:36:51 +02:00
Niel Nielsen 8351a3e206 Add files via upload 2026-05-11 11:26:13 +02:00
Niel Nielsen 4e8227d331 Add files via upload 2026-05-11 11:09:24 +02:00
GameTec-live f06efdf815 Merge pull request #413 from nieldk/t55write
Deploy wiki to GitHub Pages with Jekyll / build (push) Failing after 35s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Has been skipped
Push handler / Build Firmware (push) Failing after 34s
Push handler / Create dev pre-release with artifacts (push) Has been skipped
Push handler / Create tagged release with artifacts (push) Has been skipped
T55write
2026-05-08 17:26:51 +02:00
Niel Nielsen 36daf7038c Add files via upload 2026-05-07 20:07:23 +02:00
Niel Nielsen f8b0ae6085 FEAT: hf 14a auth-trace 2026-05-07 17:46:53 +02:00
Zhong Jianxin 874bb49485 fix: hf mf eview param error due to chunk exceeding 32-block limit
The firmware limits mf1_read_emu_block_data to at most 32 blocks per
request, but eview's chunk_count only honored data_max_length (256).
Added the same 32-block cap already used by esave.
2026-05-06 18:21:47 +08:00
naaraxi 0460d9b95e Support for changing the wake time in the client 2026-05-01 14:36:52 +03:00
GameTec-live 193ca010f0 Merge branch 'main' into fix/pyinstaller-bin-path 2026-04-25 08:44:55 +02:00
Niel Nielsen de1d9f6c28 T55xx PAC clone
Add lf clone PAC command
2026-04-24 13:21:48 +02:00
Niel Nielsen c3fd94ca8c hf 14a sniff, even more descriptive answers 2026-04-23 09:08:23 +02:00
Niel Nielsen 20d6136ee0 hf 14a sniff, more descriptive answers 2026-04-23 08:45:34 +02:00
Niel Nielsen 1e8c36f38c hf 14a sniff improvements for nonce collection and crack, fence to catch missing or blocked mfkey binaries 2026-04-23 07:58:57 +02:00
Niel Nielsen 4406788aef BUG: reverted bug that was reintroduced 2026-04-15 14:45:41 +02:00
Milan DavídekandClaude Sonnet 4.6 fcb6eb4718 Add Jablotron LF tag support (read, emulate, write to T55xx)
Jablotron uses differential biphase (inverted) at RF/64, 64-bit frames:
  bits  0-15: 0xFFFF preamble
  bits 16-55: 40-bit data (5 bytes), bit 16 must be 0
  bits 56-63: 8-bit checksum = (sum of data bytes) XOR 0x3A

Firmware:
  - rfid/nfctag/lf/protocols/jablotron.c  - encoder/decoder codec
  - rfid/nfctag/lf/utils/diphase.c        - inverted-biphase state machine
    (shared util, reusable by other diphase protocols)
  - rfid/reader/lf/lf_jablotron_data.c    - GPIO-interval reader path
  - app_cmd.c: JABLOTRON_SCAN, JABLOTRON_WRITE_TO_T55XX,
                JABLOTRON_SET_EMU_ID, JABLOTRON_GET_EMU_ID
  - tag_base_type.h: TAG_TYPE_JABLOTRON enum
  - t55xx.h: T5577_JABLOTRON_CONFIG (DIPHASE modulation, RF/64)
  - lf_tag_em.c: load callback, factory-default data, save callback

Python CLI (software/script/):
  - lf jablotron read               - scan a real tag
  - lf jablotron write --id         - clone onto T55xx
  - lf jablotron econfig -s N --id  - set emulator ID on a slot
  - hw slot list shows Jablotron ID and decimal card number

Python test (software/script/tests/test_jablotron_modulator.py):
  Pure-Python round-trip validator that reimplements the modulator and
  diphase decoder, expands PWM entries to an edge stream, and confirms
  the decoded data matches the input.  Regression guard for both the
  firmware's double-frame encoding and the single-frame variant.

Notable PWM design choices:
  - Constant-level diphase encoding uses the same PAC pattern:
    CC=0 for LOW, CC=counter_top+1 for HIGH.  counter_top=31 gives
    exactly 32 carrier cycles per half-bit at NRF_PWM_CLK_125kHz.
  - The 64-bit frame is encoded twice in the 256-entry PWM buffer with
    the internal level variable persisting between the two passes.
    This is required for clean PWM looping: a single 64-bit diphase
    frame with an odd number of zero bits ends at a level opposite the
    starting level, leaving no transition at the loop boundary where
    the reader expects one.  Encoding twice guarantees a continuous
    diphase stream regardless of the data's zero-count parity.

Reference: Proxmark3 cmdlfjablotron.c

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-15 14:15:55 +02:00
Niel Nielsen 76c961ed59 Added Ultra/Lite guard 2026-04-14 09:45:02 +02:00
Niel Nielsen d70a0dd63f fix hf14a sniff 2026-04-14 09:32:35 +02:00
Niel Nielsen 0ce680b5c7 Refactor LF clone command and update usage examples 2026-04-13 06:39:03 +02:00
Niel Nielsen 63a465ce9b Fix argument parsing for 'fc' in ioprox 2026-04-12 20:10:36 +02:00
Niel Nielsen 1a09fbaf0e Merge branch 'RfidResearchGroup:main' into t55write 2026-04-08 13:11:02 +02:00
Niel Nielsen 12284d5f71 Fix: emv scan truncation 2026-04-08 12:36:12 +02:00
Niel Nielsen e16505e6a7 FEAT! Add T55 write commands 2026-04-07 10:36:06 +02:00
Niel Nielsen efa2ea2c7b protocol ISO 14443-4 and emv scan, loading json file from PM3rdv4 2026-04-07 10:23:58 +02:00
Fauzan Mirza dc950c4f60 fix: correct nfcimport class placement after merge 2026-04-07 00:52:07 +02:00
Fauzan Mirza 7931150412 Merge remote-tracking branch 'origin/main' into pr/nfcimport-v2 2026-04-07 00:49:42 +02:00
GameTec-live 93c1e150ab Merge pull request #361 from azuwis/esave
Deploy wiki to GitHub Pages with Jekyll / build (push) Failing after 56s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Has been skipped
Push handler / Build Firmware (push) Failing after 47s
Push handler / Create dev pre-release with artifacts (push) Has been skipped
Push handler / Create tagged release with artifacts (push) Has been skipped
Fix `param error` of `hf mf esave`
2026-04-06 18:30:30 +02:00
Kevin Yuan eddbb31c05 Merge branch 'main' into pac-emulation 2026-04-06 16:43:41 +01:00
GameTec-live b77af1e779 Merge pull request #389 from Crazycurly/main
Deploy wiki to GitHub Pages with Jekyll / build (push) Failing after 1m7s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Has been skipped
Push handler / Build Firmware (push) Failing after 1m2s
Push handler / Create dev pre-release with artifacts (push) Has been skipped
Push handler / Create tagged release with artifacts (push) Has been skipped
feat(cli): integrate HardNested attack into autopwn
2026-04-04 20:12:31 +02:00
Kevin Yuan 3924ad134b Merge branch 'main' into pac-emulation 2026-04-02 14:17:42 +01:00
Niel Nielsen ce932d2e8a feat(data): add LF capture analysis commands 2026-04-02 07:43:16 +02:00
Sam 6f4722a964 feat(cli): integrate hardnested attack into autopwn for HardNested vulnerable cards
When autopwn detects a HardNested vulnerable card (nt_level=2) with some known keys,
it now automatically attempts to recover remaining keys using the hardnested attack,
instead of only printing an advisory message. The implementation:

- Iterates over each missing key slot, picking a known key before each attempt
  (allows newly recovered keys to be reused for subsequent targets)
- Invokes hardnested.recover_key() with standard parameters (200 max runs, 3 max attempts)
- After each found key, checks if it is reusable for other sectors
- Falls back to senested attack if hardnested does not recover all keys

This matches the existing behavior for nested and static-encrypted-nested attacks.
2026-03-25 16:30:48 +08:00
Kevin Yuan f5d721bbfd PAC/Stanley CLI: replace --id with --cn/--raw (PM3 parity)
Split the single --id argument into --cn (8 ASCII chars) and --raw
(32 hex char T55XX bitstream, directly compatible with PM3 raw output).
Add Python-side PAC bitstream encoder/decoder for raw format support.
Output now shows CN and Raw labels matching PM3's format.

Add NRF_LOG module registration to pac.c for debug logging,
consistent with other protocol implementations.

Reassign PAC command IDs (3014/3015) to avoid collision with ioProx
(3010/3011) after rebase onto upstream/main.
2026-03-24 15:04:41 +00:00