Commit Graph
541 Commits
Author SHA1 Message Date
iceman1001andClaude Opus 5 e648438306 hf 14b view: decode MyKey / COGES keys on SRIX4K
The SRIX4K block scrambler in cmdhf14b.c was a three entry lookup table with
its callers commented out, so `hf 14b valid` printed hard coded values and
nothing ever decoded. The scrambler is a 4x4 transpose of the block read as
sixteen crumbs. A transpose is its own inverse and it reproduces all three
entries of the old table, so the stub is replaced by a working parser.

client/src/parsers/parsemykey.c reads the application off a dump: key id,
production date, operations counter, vendor code, lock id, current and
previous credit, and the eight slot transaction ring. Every block carries a
checksum in its top byte and the parser reports how many hold up, which
catches a wrong UID or a torn write. The credit blocks are XORed with a
session key derived from the UID, the vendor code and the count down counter
in block 6, so the file name has to carry the UID.

`hf 14b valid` is removed. Checking that the maths holds is now
`hf 14b view --selftest`, following `hf mf view --selftest`, and it runs
against traces/hf-14b-D0021F673CB26556-dump.json, a dump of a real reset key.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 10:58:57 +02:00
iceman1001 c0a109dbc6 text 2026-09-16 02:39:42 +02:00
iceman1001andClaude Opus 5 (1M context) ee2d55fafb hf mfdes: put a DESFire card image in emulator memory
Adds the on-device card image a DESFire simulation will read, the client
side that packs a dump into it, and eload / esave / eview.

The layout is in include/desfire_em.h. Tables grow up from the header,
file data grows down from the end, and an allocation only has to leave
the two frontiers apart -- so a three-file card spends a few hundred
bytes rather than a worst case, and the space between them is what the
card has left. The PICC is application 000000 and uses the same struct
as any other application, so key settings and keys are always stated
against an AID. Delete sets a tombstone rather than compacting, which is
not a shortcut: a real card does not reclaim on delete either, measured
as 2080 bytes free with zero applications before an experiment and 2560
after FormatPICC.

Two size limits, and a reader only ever sees the first. cardsize is what
the emulated card claims to hold, so GetFreeMem answers from that and
CreateFile will refuse with OUT_OF_EEPROM when it runs out. Without it a
card impersonating a 2K part would report 7434 bytes free, which no 2K
part does. The image size is what emulator memory physically holds, is
the harder limit, and is never visible.

cardsize is anchored to the free memory the real card reported when the
dump was taken -- observed free plus what we reserve for the same content
-- so the emulation answers what its original answered. That is also a
check on the reservation rule rather than only a convenience: for the
bench card it computed 576 bytes spent, and 1984 + 576 is 2560, exactly
what that card reports when formatted.

Reservation follows what CommitTransaction covers. Backup data, value and
record files each get a shadow region because writes to them are staged
until commit; a standard data file writes through and does not. Sizes
round to a 32 byte granule, which is the granule a real card allocates in.
It deliberately does not reproduce NXP's allocator -- that is
undocumented and does not fit a simple model, a declared 1024 byte record
file costs 1088 on silicon -- so what matters is that the figure is
self-consistent and shrinks as the reader writes.

No new device command. Emulator memory is one shared region, so
CMD_HF_MIFARE_EML_MEMSET and BIG_BUF_EML already reach it, and both
inherit the bounds checking those paths gained earlier.

Verified with the client only, no simulation yet: packing a dump taken
from a DESFire EV2 and walking it back reproduces every field including
file contents byte for byte, the same round trip through the device via
eload and esave is identical, and an image too large is refused by name
rather than truncated -- 'Out of emulator memory laying out AID 112233
file 00: needs 4066 more bytes'.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 19:48:45 +02:00
iceman1001 b82f603622 urmet parsing 2026-09-14 12:11:42 +02:00
Niel Nielsen 52fac7ca1b Add parsehexact.c to Makefile build list
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:44:42 +02:00
Niel Nielsen ea585bacd6 Fix include directive for dependency files in Makefile
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:18:57 +02:00
iceman1001 7142ddc9bd added hexact parser 2026-09-13 12:55:43 +02:00
iceman1001andClaude Opus 5 (1M context) a9105c5089 hf mf: split HID and VIGIK decoding into client/src/parsers/
The shared viewer had the VIGIK sector assembly inlined, and the HID PACS
decode sat in hf mf mad's file branch where hf mf view and hf mf dump --ns
could not reach it. Neither scheme had a home of its own.

Give each one a parser next to parsehrt.c, same shape as that one - an
is_valid_x_card() detector and an x_parser_parse() that prints:

  parsers/parsehid.c    MAD aid 0x484d, PACS sector, Wiegand decode
  parsers/parsevigik.c  MAD aid 0x4910/0x4916, sector assembly

parsevigik.c also takes vigik_get_service(), vigik_verify() and
vigik_annotate() out of mifare/mifarehost.c, 306 lines that were VIGIK only
with a single caller.

mf_view_dump() is now two detector calls, so hf mf view -f and hf mf dump --ns
both decode a HID credential off a live card for the first time, and adding a
scheme is a new file plus two lines. hf mf mad -f keeps its HID decode through
the same parser.

The sector copy in the VIGIK path gains a bounds check; a MAD entry pointing
past the end of a short dump used to read past the buffer.

All three source lists get the new files: client/Makefile,
client/CMakeLists.txt and client/experimental_lib/CMakeLists.txt. The library
one matters because vigik_annotate() moved; without it anything linking
libpm3rrg_rdv4 loses the symbol.

hf mf mad against a card still cannot decode PACS. It authenticates with the
MAD key alone and never reads the application sector, so it has no credential
bytes to work with - unchanged here.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-13 08:37:17 +02:00
Niel Nielsen bd24a6197d Fix Makefile to include dependency files correctly
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-12 16:47:03 +02:00
MsprgandClaude Fable 5 d852118de5 client: build the tab completion vocabulary at runtime from the command tree
Tab completion used a generated table (pm3line_vocabulary.h, refreshed by
hand via `make commands`) that drifted from the real command tables: new
commands were missing (e.g. `hw bwm*`), removed ones lingered, and the
"offline" flag depended on the platform of whoever regenerated it
(IfPm5() returns true offline on PM5 builds).

Build the vocabulary at startup instead:

- cmdparser: add walkCommandsRecursive(), a tree walk using a fourth
  internal sentinel (XX_internal_command_walk_XX) next to the dump ones.
  It hands each leaf to a visitor as its command_t chain (ancestors +
  leaf). A dispatch counter detects entries shown like a category but
  with their own parser (reveng) and reports them as leaves.
- pm3line_vocabulary: dynamic vocabulary holding the IsAvailable()
  predicates of every command and its ancestor categories, so completion
  applies exactly the rule CmdsHelp() uses, live, for both offline and
  connected devices. Script entries ("script run <relpath>") come from
  the same directories `script list` scans, sorted, including
  subdirectories with the path `script run` needs.
- pm3line: readline and linenoise completers consume the live vocabulary.
  The walk runs with output disabled so category handlers stay silent.
- Drop pm3_help2list.py and the header regeneration from `make commands`.

Behaviour change: entries whose category is hidden by `help` (e.g. `mem`,
`usart` offline) are no longer offered, matching `help`; when connected,
commands the device does not support are no longer offered either.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-28 14:29:04 +02:00
Niel Nielsen 6e741fa9e9 Add files via upload
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-26 16:07:37 +02:00
Iceman 48458b6ba7 Merge pull request #3527 from kormax/felica-info-auth-idi-pmi
Determine IDi and PMi in `hf felica info` for cards with known keys
2026-08-26 18:15:00 +07:00
kormax f3bca6c291 Determine IDi and PMi in 'hf felica info' for cards with known keys 2026-08-26 11:34:57 +03:00
Niel Nielsen 3b3ba27a86 Add conditional includes for PM5 platform
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-25 12:20:26 +02:00
Philippe Teuwen 644ebba3d7 Try to fix MSYS2 compilation with openjpeg 2026-08-22 00:54:36 +02:00
iceman1001 f6e0119f5f added PACE (--can) support to emrtd commands. 2026-08-21 22:32:06 +02:00
iceman1001 0f3092ceb8 added support to view JPEG2000 images commonly used with epassports. The lib use a BSD-2 license compatible with our GPL3+ 2026-08-21 20:10:30 +02:00
dxl 83114823ec Added cmdfpga for client. 2026-08-19 12:04:32 +02:00
iceman1001 19cc98c532 hooked up the new DSP code. Should improve the t55xx commands 2026-07-30 16:43:09 +02:00
iceman1001 c6d01e6e72 update helptexts 2026-06-29 23:51:37 +02:00
Sanduuz 4ff1a50288 Moved HRT parser logic under client/src/parsers + Restructured parser calling code to its own file that is hooked from hf mfdes info command 2026-06-20 23:55:55 +03:00
Sanduuz f71071eb94 Initial commit for HRT parser 2026-06-17 19:24:06 +03:00
achazal d6ed3c18c2 mad: Add unified MAD read/write/verify with ops struct abstraction 2026-06-09 18:48:25 +02:00
klks e1152fc98a Add native fmcos support to pm3 2026-05-24 19:12:12 +08:00
Connor Milligan cc7b235a5b Native client support for FM11RF08S SEN recovery 2026-05-21 01:19:15 +02:00
Philippe Teuwen fe82cae1df Add vec in cliuent deps 2026-05-19 00:37:37 +02:00
Philippe Teuwen d8c7f84598 Add Makefile PLATFORM_FILE variable to specify another Makefile.platform file 2026-05-19 00:10:17 +02:00
Philippe Teuwen 620e8b4744 Client Makefile: add FORCE* options to mirror the SKIP* options, mostly for maintainers 2026-05-11 21:43:57 +02:00
kormax fa414f3b65 Implement 'hf mfd verifycert' command 2026-05-04 22:07:33 +03:00
kormax d06106b538 Add 'hf calypso info' command 2026-05-01 22:41:42 +03:00
kormax 4a2e161954 Move common functions related to Mifare GetVersion to a dedicated Mifare Prime module 2026-04-16 18:55:34 +03:00
Antiklesys 8d6e474a75 hf iclass legbrute speed improvements #1
Imported updates from legbrute hashcat modules to speed up hf iclass legbrute

1. Bitslicing — biggest win (~32×)
Kernel stores each cipher register (l, r, b, t) as 32 parallel 1-bit lanes in u32s (m64000_a3-pure.cl:147-201, bs_iclass_tick) and computes 32 MACs per tick. The CPU doMAC_brute does 1 at a time. A 64-bit bitslice port would give ~64× per core; AVX2 gets 256×. This is the single largest speedup lever.

2. Early-reject after 8 output ticks
In m64000_sxx (m64000_a3-pure.cl:534-535) the kernel breaks out as soon as the first MAC byte can't match. doMAC_brute always produces the full 32 output bits before memcmp. Comparing byte-by-byte as bits are produced saves ~3× on the output phase since 255/256 keys fail after byte 0.

3. Pre-expanded y_ccnr bit array
Kernel expands the 96 input bits into a flat array once (m64000_a3-pure.cl:239-247) and reuses it for every candidate. suc_bytes in cipher.c:181 re-does b >>= 1 shifts for every key. Pre-expanding lets the inner loop be branch-free and vectorizable.

4. Widen lanes to 256/512 via AVX2/AVX-512. The bitslice code is written against a single uint64_t lane type — swapping for __m256i/__m512i (or an abstracted bs_word_t) gives 4×/8× throughput on hosts that support it, with scalar u64 fallback on ARM/older x86. NEON gives 2× for ARM.
2026-04-15 01:09:19 +08:00
Philippe Teuwen 961e59b5d1 Revert "Release v4.21611 - BREAKMEIFYOUCAN!"
This reverts commit aaacc75e9f.
2026-04-14 10:19:30 +02:00
Philippe Teuwen aaacc75e9f Release v4.21611 - BREAKMEIFYOUCAN! 2026-04-14 10:19:30 +02:00
iceman1001 36a5c881d0 proper fix for ip, socket handling for win32 , proxspace env 2026-04-11 08:01:48 +07:00
Antiklesys 128e4006bf SE Conf Card Sim Base
Added `hf secc` to build a base for simulating basic function of iclass SE config cards
2026-03-30 22:58:52 +08:00
kormax c8a4314353 Add hf gst commands 2026-03-14 17:34:58 +02:00
pingu2211 c07d688597 Implement Gallagher MIFARE Classic card writing and update MAD sector functionality 2026-03-10 15:13:42 +11:00
Philippe Teuwen 0304977eba tabs 2026-03-01 15:27:31 +01:00
Philippe Teuwen 5175c32c35 Fix makefile warning when there is no qt6 available 2026-03-01 15:27:18 +01:00
Philippe Teuwen 55df8edbba Add support for Qt 6.2.4 (Ubuntu 22.04) 2026-03-01 13:23:07 +01:00
Philippe Teuwen fcb337f086 makefile: limit qt6 fix 2026-02-28 23:45:58 +01:00
Philippe Teuwen 20d194e5bd Makefile: serialize targets to avoid interleaved compilations. -j still supported. 2026-02-28 19:53:41 +01:00
Philippe Teuwen 55e58466aa Fix C++ flags handling (fix relocation error on Fedora 41) 2026-02-28 18:15:44 +01:00
Philippe Teuwen f9cfda9a72 Add hardening flags (NOHARDENING=1 to disable them) and fix Windows stringop-overflow 2026-02-28 16:22:44 +01:00
kormax de94afa4f6 Add 'hf aliro info' command 2026-02-27 20:26:50 +02:00
Philippe Teuwen 93791a0d9b Add SKIPQT6 if one wants to force Qt5 2026-02-27 13:15:12 +01:00
Philippe Teuwen b2df498e3e fix the fix of the fix 2026-02-27 00:41:22 +01:00
Philippe Teuwen d5d8a7192a Qt6: makefile fixes 2026-02-27 00:38:05 +01:00
Philippe Teuwen b2d34ddc15 Fix for Ubuntu 24.04 Qt6 2026-02-27 00:20:54 +01:00