hf mfu chk: one dictionary check that detects UL-C or UL-AES

hf mfu cchk and hf mfu aeschk were the same command twice. Ninety lines of
dictionary loading and chunked device calls were duplicated, and the only
real difference was which key slot they targeted: aeschk took --idx, cchk
hardcoded the Ultralight C slot. Both are replaced by hf mfu chk, which
reads the tag type off the card with GetHF14AMfU_Type() and picks the slot
itself. Ultralight AES still honours --idx, 0 DataProtKey, 1 UIDRetrKey,
2 OriginalityKey. Ultralight C holds a single key, so --idx is rejected
there rather than silently ignored. Any other tag is refused with a pointer
to hf mfu info.

Without -f the dictionary is mfulc_default_keys.dic for both tag types. A
segment check keeps needing an explicit -f, because the segment dictionaries
hold four byte keys and the default one does not. aeschk used to advertise
mfulaes_default_keys.dic in its help, which has never been shipped.

Collapsing the two bodies also fixes --retries. firstChunk and lastChunk
were declared outside the retry loop and never reset, so only the first pass
was correct. From the second pass on, every chunk went out with firstchunk
clear and lastchunk set, which on the device side means no select and a
field teardown after each chunk, against a field the previous pass had
already dropped. They are now scoped to the pass.

client/pyscripts/mfulaes_mask_recovery.py called aeschk and now calls chk.
doc/commands.md and doc/commands.json are regenerated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
iceman1001
2026-09-16 12:40:47 +02:00
co-authored by Claude Opus 5
parent 60eca59fee
commit 00aabd7443
5 changed files with 132 additions and 221 deletions
+1 -1
View File
@@ -80,7 +80,7 @@ def bruteforce_key(p, key_segment, idx, segment, retries=5, bitflips=2):
sys.stdout.flush()
key = construct_key(key_segment, segment)
console_debug(p,
f'hf mfu aeschk -i {idx} '
f'hf mfu chk -i {idx} '
f'-f mfulaes_segment_hw{bitflips}.dic '
f'--segment {segment} '
f'--key {key} '