Commit Graph
104 Commits
Author SHA1 Message Date
iceman1001andClaude Opus 5 e648438306 hf 14b view: decode MyKey / COGES keys on SRIX4K
The SRIX4K block scrambler in cmdhf14b.c was a three entry lookup table with
its callers commented out, so `hf 14b valid` printed hard coded values and
nothing ever decoded. The scrambler is a 4x4 transpose of the block read as
sixteen crumbs. A transpose is its own inverse and it reproduces all three
entries of the old table, so the stub is replaced by a working parser.

client/src/parsers/parsemykey.c reads the application off a dump: key id,
production date, operations counter, vendor code, lock id, current and
previous credit, and the eight slot transaction ring. Every block carries a
checksum in its top byte and the parser reports how many hold up, which
catches a wrong UID or a torn write. The credit blocks are XORed with a
session key derived from the UID, the vendor code and the count down counter
in block 6, so the file name has to carry the UID.

`hf 14b valid` is removed. Checking that the maths holds is now
`hf 14b view --selftest`, following `hf mf view --selftest`, and it runs
against traces/hf-14b-D0021F673CB26556-dump.json, a dump of a real reset key.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 10:58:57 +02:00
iceman1001andClaude Opus 5 4dc412e403 hf mfdes sim: authentication, secure messaging, reads, writes and transactions
The DESFire simulation now plays the EV1 protocol rather than just the
activation and a handful of unauthenticated queries. A reader authenticates,
enumerates, reads and writes files, and commits or aborts transactions against
the card image `hf mfdes eload` put in emulator memory.

Authentication covers 0x0A, 0x1A and 0xAA with DES, 2TDEA, 3K3DES and AES keys
taken from the image. A key the image only holds a version for still refuses to
authenticate rather than authenticating with zeros.

Secure messaging follows the file's communication mode, with the rule that the
mode only applies when a key right matching the authenticated key granted the
operation -- access granted by the free-access right runs plain whatever the
file settings say. Responses are MACed or enciphered accordingly, and the
session CMAC is taken over every command and response in order so the two sides'
IVs stay together even where neither puts a MAC on the wire.

Reads cover ReadData, ReadRecords, GetValue and GetCardUID. Writes cover
WriteData, WriteRecord, UpdateRecord, Credit, Debit and LimitedCredit, plus
CommitTransaction, AbortTransaction and ClearRecordFile. Backup data, value and
record files write into their shadow region and only move across on commit, so
an abort really does discard.

Three fixes were needed to interoperate with the client, and all three share a
shape worth naming: the authentication handshake still succeeded, because it
runs on the original key, and only the traffic afterwards was wrong.

1. A DES or 2TDEA key is stored as 16 bytes and the key itself decides which
   cipher the PICC uses -- if the second half equals the first it is a single
   DES key, and that governs session key generation too (M134034 8.1). The
   all-zero default key is the common case. Deriving a 2K3DES session key from
   it left the card MACing under a key the reader did not have. Confirmed by
   decrypting a captured GetCardUID response offline: under the session key the
   reader derives it yields the UID and a valid CRC32, under the other it does
   not.

2. Session keys are built here rather than through Desfire_session_key_new(),
   whose 3K3DES branch clears the low bit of the first eight bytes. Those bits
   are key version, which a session key does not have, and the reader keeps them.

3. The reader's 0xAF continuation is not a command, it continues one. Giving it
   its own CMAC restarted the running calculation halfway through a chained
   answer, so every chained response longer than one frame carried a wrong MAC
   while single-frame answers verified fine.

The sample card in traces/mifare is rekeyed from all zeros to the sequence
01 02 .. 10, extended to .. 18 for 3TDEA. An all-zero key has matching halves,
so it exercises only the degenerate path of fix 1 above and hides the bug;
distinct halves surface a wrong derivation on the first MACed frame.

tools/desfire_sim_test.sh loads an image, simulates it, drives the second
Proxmark3 at it and reports. It stops the simulation the way the client does, a
newline on its stdin, through a fifo held open for the run rather than a fixed
timer -- a run that outlives its timer leaves the device simulating. A command
counts as passing only if it prints something that says it worked: card errors,
client side argument rejections and MAC or CRC complaints all fail, because
several of those print a plausible result line as well and matching on the
result alone reports passes that never happened.

Tested on two RDV4s, one simulating and one reading: activation, info,
application and file enumeration, all three key types, enciphered GetCardUID,
plain and MACed reads up to 256 bytes over chained frames, and writes verified
by reading the image back out with `hf mfdes esave`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-15 20:40:32 +02:00
iceman1001 6755b96323 added a couple of desfire test files for easy simmulation 2026-09-15 14:49:32 +02:00
iceman1001 c91993acc8 text 2026-09-12 21:48:46 +02:00
iceman1001 1a34aac8df texts 2026-09-04 13:32:54 +02:00
iceman1001 50c1c72136 added some sample dump files and trace file for hitag2 2026-09-03 19:35:58 +02:00
iceman1001 6b7678edeb added some tests of etc annotations 2026-08-26 20:47:55 +02:00
towelbyte 0ef1d35891 Added a few COTAG trace dumps. 2026-06-12 22:49:06 +02:00
CinderSocket b05a4f9bcf Support non-06 iCLASS SE AIA SIO blocks 2026-06-08 04:37:26 -07:00
iceman1001 32a4e622d2 added two trace files for UL-AES in order for people to more easily understand secure messaging and authentication 2025-10-17 18:08:15 +02:00
nvx 96a1f21764 fix pacs data in example trace filename 2024-12-02 16:16:59 +10:00
Henry Gabryjelski 1d4e5e8d90 Fix .PM3 traces that exceed single-byte range
This was done programmatically using python.

The `lf_Keri.pm3` was in range `[-508 .. 491]` (1000 value range).
Each value was divided by four, cast to integer, and then adjusted by +1 (to center the values).
The data plot in the pm3 client now shows discernible changes in amplitude.
The resulting samples are all within range [-128,127].

This final fix allows ALL sample `.pm3` traces to be converted to one-byte-per-sample binary format.
2024-09-16 23:35:03 -07:00
Henry Gabryjelski 1a7267ca53 Fix .PM3 traces that exceed single-byte range
This was done programmatically using python.
Files with a range that fell outside of [-128,127], but which would fit into that range, were offset by the noted amount to ensure the file woul now fit within range [-128,127].  This allows the trace files to be converted to one-byte-per-sample binary format, for example.

offset | filename
-----|-----
`-14` | `lf_Q5_mod-manchester.pm3`
`-14` | `lf_Q5_mod-nrz.pm3`
`-10` | `lf_Q5_mod-fsk1.pm3`
`-15` | `lf_Q5_mod-biphase.pm3`
`-9` | `lf_Q5_mod-fsk2.pm3`
2024-09-16 23:05:15 -07:00
iceman1001 641b8f3f57 added a trace file for looking at a genuine Hitag2 read out when card is configured in Crypto mode 2024-04-25 07:37:26 +02:00
Xavier Zhang 21065321ae update encoder config for new iclass syntax 2024-02-17 21:44:25 -05:00
iceman1001 bfa912952e added a trace of xerox info execution 2024-01-26 21:25:45 +01:00
iceman1001 50a1c63470 improved the SEOS annotation, also added a trace file to look at 2024-01-04 19:49:59 +01:00
kitsunehunter ab9753629b Add omnikey auto downgrade config file
Signed-off-by: kitsunehunter <90627943+kitsunehunter@users.noreply.github.com>
2023-12-12 12:14:09 -05:00
iceman1001 da98ad8854 adapted the notes on downgrade attacks to follow the repo style 2023-12-12 17:05:10 +01:00
Alex 6947a61d98 Whitespace 2023-08-09 14:30:07 +02:00
iceman1001 8793f1c9c5 color 2023-07-26 23:33:05 +02:00
iceman1001 538ac4b191 added a bunch of empty dump files and key files in order to easily simulate a empty tag. Just eload it and sim. 2023-07-26 17:51:35 +02:00
iceman1001 bc27847bc8 added a new trace sample file 2023-07-21 16:45:12 +02:00
iceman1001 c97f003b2f added a pm3 simulating trace of MIFARE HID SIO 1K card 2022-07-04 17:21:36 +02:00
iceman1001 a79b23edc4 and the files... 2022-01-30 21:27:13 +01:00
iceman1001 54ddd8176f added iclass sniff 2022-01-30 21:25:02 +01:00
iceman1001 7dcaf59cdd added a sniffed desfire trace 2022-01-30 21:23:17 +01:00
Philippe Teuwen 8a85702662 hitags: don't record SOF in trace and demodulate AC frame 2021-12-30 01:11:12 +01:00
Philippe Teuwen 323f70ff7a Add partial byte annotation in Hitag traces
Example:
[usb] pm3 --> trace load -f traces/lf_HitagS256_dump.trace
[+] loaded 287 bytes from binary file traces/lf_HitagS256_dump.trace
[+] Recorded Activity (TraceLen = 287 bytes)
[?] try `trace list -1 -t ...` to view trace.  Remember the `-1` param
[usb] pm3 --> trace list -1 -t hitags -c
[+] Recorded activity (trace len = 287 bytes)
[=] start = start of start frame end = end of frame. src = source of transfer
[=] Hitag1 / Hitag2 / HitagS - Timings in ETU (8us)

      Start |        End | Src | Data (! denotes parity error)
------------+------------+-----+-----------------------------------------
          0 |          0 | Rdr |18(5)
        117 |        117 | Tag |0f(4) 2c  ab  cc  b3  cf  32  bf [2f]
          0 |          0 | Rdr |00(5) 21  a5  b4  73 [8c]
        117 |        117 | Tag |0f(4) c9  00  00  aa [75]
          0 |          0 | Rdr |0c(4) 00 [ab]
        117 |        117 | Tag |0f(4) 21  a5  b4  73 [53]
          0 |          0 | Rdr |0c(4) 01 [b6]
        117 |        117 | Tag |0f(4) c9  00  00  aa [75]
          0 |          0 | Rdr |0c(4) 02 [91]
        117 |        117 | Tag |0f(4) 48  54  4f  4e [2c]
          0 |          0 | Rdr |0c(4) 03 [8c]
        117 |        117 | Tag |0f(4) 4d  49  4b  52 [1e]
          0 |          0 | Rdr |0c(4) 04 [df]
        117 |        117 | Tag |0f(4) 00  00  00  00 [a6]
          0 |          0 | Rdr |0c(4) 05 [c2]
        117 |        117 | Tag |0f(4) 00  00  00  00 [a6]
          0 |          0 | Rdr |0c(4) 06 [e5]
        117 |        117 | Tag |0f(4) 00  00  00  00 [a6]
          0 |          0 | Rdr |0c(4) 07 [f8]
        117 |        117 | Tag |0f(4) 57  5f  4f  4b [88]
          0 |          0 | Rdr |0c(4) 08 [43]
2021-12-29 23:48:16 +01:00
Philippe Teuwen e5c20fc850 Add HitagS trace
Acquired with:
[usb] pm3 --> lf hitag reader --01
[#] Authenticating using nr,ar pair:
[#] 00 00 00 00 00 00 00 00
[#] Page[ 0]: 73 B4 A5 21
[#] Page[ 1]: AA 00 00 C9
[#] Page[ 2]: 4E 4F 54 48
[#] Page[ 3]: 52 4B 49 4D
[#] Page[ 4]: 00 00 00 00
[#] Page[ 5]: 00 00 00 00
[#] Page[ 6]: 00 00 00 00
[#] Page[ 7]: 4B 4F 5F 57
2021-12-29 17:13:13 +01:00
iceman1001 0330234aea Added sniffed traces of Visa Apple ECP transactions. Thanks to @a66at for them! 2021-10-14 19:49:57 +02:00
Philippe Teuwen ca741cdfea Add MFULC auth trace with default key 2021-10-14 19:23:45 +02:00
iceman1001 fe75de7440 added a trace of reading a MIFARE UL-C with 3DES authentication, thanks @rad1game! 2021-10-13 19:10:17 +02:00
iceman1001 710c612a2c text 2021-09-03 19:14:04 +02:00
iceman1001 24d55e8c35 Mifare Plus MAD/ read sector 0 traces 2021-09-03 19:10:27 +02:00
Matthew Saunier 26227e1d7b Added trace 2021-06-08 12:20:46 -06:00
Matthew Saunier d8d29bc5cd Added HID Indala 4041X trace 2021-06-07 14:22:55 -06:00
STRSHR 1280912589 Add an IDTECK sample 2021-04-25 09:45:29 +03:00
iceman1001 89d2e4fe8f text 2021-03-05 10:49:00 +01:00
iceman1001 59a1f15f5d cryptoRF sniff of anticollision / select 2021-03-05 10:46:44 +01:00
Philippe Teuwen 34a56fae9a blue cloner trace 2020-10-17 00:46:10 +02:00
Philippe Teuwen b823e8648a Destron: missing trace 2020-10-12 14:22:55 +02:00
Philippe Teuwen 76701af8a7 Make clear current FDX in Pm3 is FDX-B only 2020-10-11 22:38:52 +02:00
iceman1001 eb05cadb1c hid 2020-10-07 01:29:00 +02:00
tcprst bc34aba175 update scripts with new keri syntax 2020-10-04 14:08:07 -04:00
tcprst 51c0d07eb9 lf hid clone, sim, brute, watch - now use cliparser 2020-10-03 15:40:03 -04:00
Philippe Teuwen fc6492288c add trace 2020-10-02 02:20:45 +02:00
Philippe Teuwen b3a3828c3f add 14b* traces 2020-10-02 01:18:49 +02:00
Philippe Teuwen d1bb16f862 text 2020-09-29 18:19:23 +02:00
Philippe Teuwen 1abdbf3369 text 2020-09-29 18:09:29 +02:00