362 Commits
Author SHA1 Message Date
GameTec-live 14c42544ad Merge branch 'main' into main 2026-10-04 21:26:32 +02:00
GameTec-live 39a597b5ea Merge branch 'main' into ulc 2026-10-04 10:37:12 +02:00
GameTec-live ccf60753f9 Merge pull request #426 from azuwis/fix-autopwn-hardnested
Deploy wiki to GitHub Pages with Jekyll / build (push) Canceled after 0s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Canceled after 0s
Firmware build / Build fw-builder Docker image (push) Canceled after 0s
Firmware build / Build firmware (lite) (push) Canceled after 0s
Firmware build / Build firmware (ultra) (push) Canceled after 0s
Push handler / Build Firmware (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-linux.zip" .) , linux, ubuntu-latest, true ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-macos.zip" .) , macos, macos-latest, true ) (push) Canceled after 0s
Client build / Build client (Compress-Archive -Path software\dist\* -DestinationPath client-windows.zip , windows, windows-latest, ? . ) (push) Canceled after 0s
Push handler / Create dev pre-release with artifacts (push) Canceled after 0s
Push handler / Create tagged release with artifacts (push) Canceled after 0s
Push handler / Start the next PR review cycle (push) Canceled after 0s
fix: fall back to hardnested in autopwn when nested fails
2026-09-10 08:46:37 +02:00
GameTec-live 66a36881cf Merge pull request #425 from azuwis/fix-hf-mf-dump
fix: fill both key A and key B in sector trailer when dumping
2026-09-10 08:45:46 +02:00
Didier A cf4595e953 Merge branch 'RfidResearchGroup:main' into parity-check 2026-09-07 14:10:12 +02:00
GameTec-live aa881ee596 Merge pull request #424 from azuwis/fix-hf-mf-fchk
Deploy wiki to GitHub Pages with Jekyll / build (push) Canceled after 0s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Canceled after 0s
Firmware build / Build firmware (ultra) (push) Canceled after 0s
Firmware build / Build firmware (lite) (push) Canceled after 0s
Firmware build / Build fw-builder Docker image (push) Canceled after 0s
Client build / Build client (Compress-Archive -Path software\dist\* -DestinationPath client-windows.zip , windows, windows-latest, ? . ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-macos.zip" .) , macos, macos-latest, true ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-linux.zip" .) , linux, ubuntu-latest, true ) (push) Canceled after 0s
Push handler / Create dev pre-release with artifacts (push) Canceled after 0s
Push handler / Create tagged release with artifacts (push) Canceled after 0s
Push handler / Start the next PR review cycle (push) Canceled after 0s
Push handler / Build Firmware (push) Canceled after 0s
fix: load_key_file and load_dic_file for hf mf fchk
2026-09-07 13:59:54 +02:00
DidierA 52ff1d0fb6 add space for correct alignment 2026-09-07 11:26:16 +02:00
DidierA 38a745fdf4 hf 14a sniff: add parity checks 2026-09-07 11:26:05 +02:00
Curious, aren't we? 549e4457f0 Merge branch 'main' into main 2026-08-07 23:17:24 +02:00
Aaron Tulino (Aaronjamt) 1f99ddd4db SEOS emulation support 2026-07-28 11:18:18 -07:00
GameTec-live dd5b11642d Merge pull request #317 from bob-zebedy/fix/pyinstaller-bin-path
fix: resolve binary tools detection after PyInstaller packaging
2026-07-04 13:15:14 +02:00
Foxushka d8e85d53dc feat: add change key command 2026-06-13 13:01:15 +03:00
Foxushka 2999d9dd5f feat: MIFARE Ultralight C authentication and emulation 2026-06-13 11:38:40 +03:00
Curious, aren't we? f0566dd720 Add long button press threshold as a user setting 2026-05-26 17:19:31 +02:00
Milan DavídekandClaude Opus 4.7 38689a82ba Move JABLOTRON_WRITE_TO_T55XX from 3017 to 3020
Keep SCAN(3019)/WRITE(3020) adjacent, matching the SCAN+WRITE
adjacency convention used by every other LF protocol
(EM410X 3000/3001, HIDPROX 3002/3003, VIKING 3004/3005,
IOPROX 3010/3011, PAC 3014/3015). Slot 3017 is now free for
future use.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 14:01:58 +02:00
Milan DavídekandClaude Opus 4.7 52f37bff8d Merge upstream/main into Jablotron PR #404
Resolved conflicts from upstream feature additions (IDTECK PR #407,
LF_T55XX_WRITE PR #413, ISO14443-4 T=CL emulation, HF14A scan-keep,
etc.) by keeping both sides where independent.

Command ID note for reviewer:
- Maintainer's IDTECK shift commit (1e78976) stated "Jablotron retains
  the original slots 3016 and 3017", but upstream had already taken
  3016 for DATA_CMD_LF_T55XX_WRITE. Only 3017 was actually free.
- Resolution: JABLOTRON_WRITE_TO_T55XX kept at 3017 (honors intent).
  JABLOTRON_SCAN moved 3016 -> 3019 (next free slot).
- 5xxx range: JABLOTRON_SET/GET_EMU_ID = 5010/5011 unchanged
  (IDTECK shifted to 5012/5013 as planned).

Python files parse cleanly. No duplicate command IDs in data_cmd.h
(3xxx and 5xxx ranges checked).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:51:54 +02:00
matteoscrugli 1e78976bd9 feat(lf): shift IDTECK command IDs to avoid collision with Jablotron PR #404
LupusE requested in the PR #407 review (2026-05-13) to move IDTECK
command IDs since PR #404 (Jablotron) also uses 3017 / 5010 / 5011.
Both PRs are open with the feature-freeze label; Jablotron retains
the original slots and IDTECK shifts up:

  DATA_CMD_IDTECK_WRITE_TO_T55XX: 3017 -> 3018
  DATA_CMD_IDTECK_SET_EMU_ID:     5010 -> 5012
  DATA_CMD_IDTECK_GET_EMU_ID:     5011 -> 5013

Files changed:
- firmware/application/src/data_cmd.h
- software/script/chameleon_enum.py

app_cmd.c references the constants by name only, no edit needed there.
2026-05-15 10:09:51 +02:00
matteoscrugli 729a7e56ea feat(cli): add lf idteck subgroup and extend lf clone with idteck type
Adds host-side CLI support for IDTECK:
- lf idteck econfig -s <slot> [--id <hex>]   set or read the emulated frame
- lf idteck write --id <hex>                 clone to a T55xx tag in reader mode
- lf clone -t idteck --id <hex>              same via the unified clone command
- hw slot list                                now renders Frame and Card ID
                                              for IDTECK slots

Input accepts 16 hex characters for the full 64-bit frame, or 8 hex
for the 32-bit payload (the fixed preamble 4944544B is auto-prepended).
A non-blocking informational note is emitted when the payload checksum
does not match the value computed from the card number, since some
readers validate this field and some do not.

Private helpers in chameleon_cli_unit.py (_idteck_compute_checksum,
_idteck_compose_frame, _idteck_frame_info) parse and compose IDTECK
frames and expose card-number-driven composition for a future
`lf idteck compose` command.
2026-05-15 10:09:51 +02:00
Zhong Jianxin f39de047be fix: fall back to hardnested in autopwn when nested fails
When nt_level is 1 (PRNG_WEAK), nested recovery can fail because
recover_a_key re-detects the PRNG and returns None if it's actually
HardNested (nt_level == 2). Also, the PRNG detection can misclassify
a HardNested tag as PRNG_WEAK from a single NT sample.

Now autopwn tries hardnested as a fallback when nested returns None.
2026-05-13 20:56:54 +08:00
Zhong Jianxin d13001bab8 fix: load_key_file and load_dic_file for hf mf fchk
load_key_file (--key): read raw 6-byte binary keys instead of
trying UTF-8 decode, which failed on binary key files.

load_dic_file (--dic): implement stub that was just returning
keys unchanged; now reads 12-char hex keys line by line.
2026-05-13 20:14:54 +08:00
Zhong Jianxin 7b1faccc52 fix: fill both key A and key B in sector trailer when dumping
MIFARE Classic blanks the authenticated key bytes when reading a
sector trailer. Find both key A and key B for each sector, then
fill both into the trailer from known keys instead of relying on
the read response.
2026-05-13 19:23:04 +08:00
Niel Nielsen cba4b84c4a FIX MFDEs version detection
Fixes version detection of MFDes info
2026-05-13 12:31:24 +02:00
Niel Nielsen b973385f8f Add full DESFire key check command with 3K3DES support
Adds hf des chk and hf des info commands for MIFARE DESFire EV1/EV2/EV3 key checking and card info enumeration.

Tested against: DESFire EV1 (SAK 0x20, 2KB storage) via Chameleon Ultra v2.1 USB
2026-05-12 11:21:24 +02:00
Niel Nielsen cef8b42c26 make_style as that is best practise 2026-05-11 12:36:51 +02:00
Niel Nielsen 8351a3e206 Add files via upload 2026-05-11 11:26:13 +02:00
Niel Nielsen 4e8227d331 Add files via upload 2026-05-11 11:09:24 +02:00
GameTec-live f06efdf815 Merge pull request #413 from nieldk/t55write
Deploy wiki to GitHub Pages with Jekyll / build (push) Failing after 35s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Has been skipped
Push handler / Build Firmware (push) Failing after 34s
Push handler / Create dev pre-release with artifacts (push) Has been skipped
Push handler / Create tagged release with artifacts (push) Has been skipped
T55write
2026-05-08 17:26:51 +02:00
GameTec-live 1a769a0c4a Merge pull request #417 from azuwis/fix-hf-mf-eview
Push handler / Build Firmware (push) Failing after 30s
Deploy wiki to GitHub Pages with Jekyll / build (push) Failing after 13m2s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Has been skipped
Push handler / Create dev pre-release with artifacts (push) Has been skipped
Push handler / Create tagged release with artifacts (push) Has been skipped
fix: hf mf eview param error due to chunk exceeding 32-block limit
2026-05-07 21:20:58 +02:00
Niel Nielsen 36daf7038c Add files via upload 2026-05-07 20:07:23 +02:00
Niel Nielsen f8b0ae6085 FEAT: hf 14a auth-trace 2026-05-07 17:46:53 +02:00
Zhong Jianxin d2c1f43a0e fix: hf14a_raw should return data bytes, not Response object
Callers treat the return value as bytes (len(), slicing), but hf14a_raw
was returning the Response object itself, causing TypeError.
2026-05-06 21:05:44 +08:00
Zhong Jianxin 874bb49485 fix: hf mf eview param error due to chunk exceeding 32-block limit
The firmware limits mf1_read_emu_block_data to at most 32 blocks per
request, but eview's chunk_count only honored data_max_length (256).
Added the same 32-block cap already used by esave.
2026-05-06 18:21:47 +08:00
naaraxi 0460d9b95e Support for changing the wake time in the client 2026-05-01 14:36:52 +03:00
Niel Nielsen 285d81b31e fix: restore executable permission to chameleon_cli_main.py 2026-04-28 20:36:26 +00:00
GameTec-live 193ca010f0 Merge branch 'main' into fix/pyinstaller-bin-path 2026-04-25 08:44:55 +02:00
Niel Nielsen de1d9f6c28 T55xx PAC clone
Add lf clone PAC command
2026-04-24 13:21:48 +02:00
Niel Nielsen c3fd94ca8c hf 14a sniff, even more descriptive answers 2026-04-23 09:08:23 +02:00
Niel Nielsen 20d6136ee0 hf 14a sniff, more descriptive answers 2026-04-23 08:45:34 +02:00
Niel Nielsen 1e8c36f38c hf 14a sniff improvements for nonce collection and crack, fence to catch missing or blocked mfkey binaries 2026-04-23 07:58:57 +02:00
Milan Davídek 5efa6b4ab0 Remove Jablotron placeholder comment from chameleon_enum 2026-04-15 15:54:19 +02:00
Niel Nielsen 4406788aef BUG: reverted bug that was reintroduced 2026-04-15 14:45:41 +02:00
Milan DavídekandClaude Sonnet 4.6 fcb6eb4718 Add Jablotron LF tag support (read, emulate, write to T55xx)
Jablotron uses differential biphase (inverted) at RF/64, 64-bit frames:
  bits  0-15: 0xFFFF preamble
  bits 16-55: 40-bit data (5 bytes), bit 16 must be 0
  bits 56-63: 8-bit checksum = (sum of data bytes) XOR 0x3A

Firmware:
  - rfid/nfctag/lf/protocols/jablotron.c  - encoder/decoder codec
  - rfid/nfctag/lf/utils/diphase.c        - inverted-biphase state machine
    (shared util, reusable by other diphase protocols)
  - rfid/reader/lf/lf_jablotron_data.c    - GPIO-interval reader path
  - app_cmd.c: JABLOTRON_SCAN, JABLOTRON_WRITE_TO_T55XX,
                JABLOTRON_SET_EMU_ID, JABLOTRON_GET_EMU_ID
  - tag_base_type.h: TAG_TYPE_JABLOTRON enum
  - t55xx.h: T5577_JABLOTRON_CONFIG (DIPHASE modulation, RF/64)
  - lf_tag_em.c: load callback, factory-default data, save callback

Python CLI (software/script/):
  - lf jablotron read               - scan a real tag
  - lf jablotron write --id         - clone onto T55xx
  - lf jablotron econfig -s N --id  - set emulator ID on a slot
  - hw slot list shows Jablotron ID and decimal card number

Python test (software/script/tests/test_jablotron_modulator.py):
  Pure-Python round-trip validator that reimplements the modulator and
  diphase decoder, expands PWM entries to an edge stream, and confirms
  the decoded data matches the input.  Regression guard for both the
  firmware's double-frame encoding and the single-frame variant.

Notable PWM design choices:
  - Constant-level diphase encoding uses the same PAC pattern:
    CC=0 for LOW, CC=counter_top+1 for HIGH.  counter_top=31 gives
    exactly 32 carrier cycles per half-bit at NRF_PWM_CLK_125kHz.
  - The 64-bit frame is encoded twice in the 256-entry PWM buffer with
    the internal level variable persisting between the two passes.
    This is required for clean PWM looping: a single 64-bit diphase
    frame with an odd number of zero bits ends at a level opposite the
    starting level, leaving no transition at the loop boundary where
    the reader expects one.  Encoding twice guarantees a continuous
    diphase stream regardless of the data's zero-count parity.

Reference: Proxmark3 cmdlfjablotron.c

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-15 14:15:55 +02:00
Niel Nielsen 76c961ed59 Added Ultra/Lite guard 2026-04-14 09:45:02 +02:00
Niel Nielsen d70a0dd63f fix hf14a sniff 2026-04-14 09:32:35 +02:00
Niel Nielsen 0ce680b5c7 Refactor LF clone command and update usage examples 2026-04-13 06:39:03 +02:00
Niel Nielsen 63a465ce9b Fix argument parsing for 'fc' in ioprox 2026-04-12 20:10:36 +02:00
Niel Nielsen 1a09fbaf0e Merge branch 'RfidResearchGroup:main' into t55write 2026-04-08 13:11:02 +02:00
Niel Nielsen 12284d5f71 Fix: emv scan truncation 2026-04-08 12:36:12 +02:00
Niel Nielsen 350a774d7c align with RRG 2026-04-07 10:47:41 +02:00
Niel Nielsen 67c1c36212 Clarify exit method behavior with comments
Added comments to clarify behavior of exit method.
2026-04-07 10:36:15 +02:00