Commit Graph
23099 Commits
Author SHA1 Message Date
Matthew CarrollandClaude Opus 5 0586b8a1c3 lf t55xx detect: settle the block 0 rotation with the broadcast period
A block read repeats one 32 bit word, so every offset yields a rotation and more
than one can pass the structural checks. A T5577 in direct/nrz carried both
00080040, the word on the tag, and 00080001, its ror19 - both master key 0,
reserved 0, RF/32, direct. test() answers with the first hit from a fixed floor,
so which one detect reported was scan order rather than evidence.

No structural check separates them: every bit of block 0 is a real field, and
the three the scan skips are otp, fast write and inverse data, all settable. The
tag can, though - maxblock has to account for what regular read mode cycles
through. So measure the broadcast period and keep the rotation that agrees,
reusing the constraint printConfiguration already applies to the psk2/psk3
pre-images. Costs one acquisition, and only when the reading is ambiguous.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 14:57:15 -07:00
Matthew CarrollandClaude Opus 5 907f21b8cb lf psk demod: do not accept a phase shift from the lead-in
The emitted bit is the running phase, so a shift accepted before the tag answers
toggles curPhase once too often and the rest of the word comes back complemented.

pskFindFirstPhaseShift judged its first measured length, but waveStart starts as
wherever the caller began looking - that length is part of a wave, not a wave,
and any gap beating fc was taken as a shift. Baseline on the first peak instead.
pskRawDemod_ext separately trusted a shift under one bit period in; the clock is
known by then, so look again from a bit period in.

Both are needed - dropping either leaves one of the tags measured inverting on
most reads.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 14:57:15 -07:00
Matthew CarrollandClaude Opus 5 e206d748a2 lf fsk demod: do not fabricate a bit from a leading run
aggregate_bits sized each run of like waves in bits and then forced a zero to
one. That is right mid-stream, where a run rounding to nothing would drop a bit
the tag did send. On the leading run it is wrong: a single subcarrier wave is
about fchigh samples against a bit period of clk, so it rounds to no bits and
was made into one anyway - a bit the tag never sent, shifting every bit after it
and dragging startIdx back by most of a bit period.

Skip a leading run that rounds to nothing and let the next transition be first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 14:57:14 -07:00
Matthew CarrollandClaude Opus 5 1ebcf225f1 lf nrz demod: start the bitstream at the first edge
The samples before the first level change were counted as bits, and where no
edge arrives inside ten clocks the long-run flush fired first and invented ten
of them out of the quiet lead-in. The count sat on a rounding boundary, so one
sample of jitter in that edge added or dropped a leading bit and rotated the
rest of the word - while startIdx, derived from the same count, held i % clk and
could name no sample.

A level change can only fall on a bit boundary, so start there and report it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 14:57:11 -07:00
Iceman 0884083530 Merge pull request #3610 from innocentbystanderproxmark/pm5-documentation-update
Add verbiage to make flashing the BWM clearer
2026-09-10 15:34:53 +07:00
iceman1001 82c726dd9b fix t55xx_config.lua script with scoring of psk2/3 to write a proper text 2026-09-10 10:05:10 +02:00
Innocent Bystander 1457a5d827 Add verbage to make flashing the BWM clearer 2026-09-10 01:17:06 -04:00
iceman1001 78b4d4ef00 fix psk1 detection. now scores 24/24 tests 2026-09-10 05:45:13 +02:00
iceman1001 e121e3f0a8 fixing FSK / t5577 2026-09-10 05:28:06 +02:00
iceman1001 d54ae662ce fix lua scripts grabbing return text. mimics the python binding way now 2026-09-10 04:31:47 +02:00
Iceman 7342737139 Merge pull request #3609 from innocentbystanderproxmark/pm5-bmw-flashing-instructions
Adding BWM Flashing instructions to PM5 Documentation
2026-09-10 09:10:48 +07:00
iceman1001 bef7f3752a another entry 2026-09-10 04:03:57 +02:00
iceman1001andClaude Opus 5 (1M context) ea2909702f lf t55xx: anchor the block read offset in samples, not demod bits
GetT55xxBlockData extracted every block at config.offset, a bit index into a
demod buffer cached by the last detect - a different capture. Demodulators do
not all start on the same bit, so a later read could return a rotation of the
block with nothing marking it as wrong: psk1 by four or five bits, fsk2a and
nrz by one, manchester and biphase never.

Record the boundary where it is stable instead. Every demodulator reports the
graph sample its first bit sits on, and turn_read_lf_on(137 * 8) makes the
firmware open each read acquisition at the same point, so the word boundary
lands on the same sample every time. Convert back per demodulation.

Block 0 re-anchors from its known value, and a write is now verified by the
value being anywhere in the repeating stream rather than at one cached offset -
which also fixes correct writes reporting as validation failures. A block 0
verify re-detects on a mismatch, not only on a decode failure: the pre-write
config can decode the post-write signal into garbage rather than failing.

Also fixes a -1 password sentinel truncated to 32 bits by a ternary, which made
that detect report a password that was never supplied.

Measured on a T5577 across psk1, fsk2a and direct/nrz: three consecutive dumps
agree field for field, against a baseline where psk1 corrupted 22 of 24.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-10 03:58:14 +02:00
Innocent Bystander b3123d153f Adding BWM Flashing instructions to PM5 Documentation 2026-09-09 21:14:26 -04:00
iceman1001 253e0d148a hf emrtd info - did not identify and mapped OID for algorithms in PACE. Now we keep a list and pretty print it 2026-09-10 02:55:16 +02:00
Iceman 9ec11eda2a Merge pull request #3605 from Actu4l-Human/testy-earwig
fix(pm5): terminate packet-aligned AT32 USB CDC writes with ZLP
2026-09-10 02:16:40 +07:00
Young, Nathen C 186c72eefd fix(usb): terminate packet-aligned CDC transfers with ZLP
Send a synchronous zero-length packet after CDC responses whose length is
an exact multiple of the endpoint packet size, preventing oversized host
reads from remaining pending.
2026-09-09 08:57:09 -07:00
Iceman a38ab20b53 Merge pull request #3604 from ry4000/master
R&Y: Updated `MEGACASH` AID in `aid_desfire.json`
2026-09-09 14:51:41 +07:00
ry4000 ef23d014eb R&Y: Updated MEGACASH AID in aid_desfire.json
# Updates
1. Updated `MEGACASH` vendor name from `Bank Mega` to `PT Bank Mega Tbk` *which is the vendor's full name*.

-r&y.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-09 16:15:03 +10:00
Iceman 23d6f67dc8 Merge pull request #3603 from kormax/new-aid-desfire-entries
Add new ISO7816 & DESFire AID values
2026-09-08 22:57:50 +07:00
Iceman a9ac330040 Merge pull request #3602 from nieldk/esp32-c2
Esp32 app descriptor check
2026-09-08 22:57:17 +07:00
kormax 6c8cf5bdcf Add new ISO7816 AID values 2026-09-08 18:24:09 +03:00
kormax a4b1dd0ee7 Add new DESFire AID entries 2026-09-08 18:23:15 +03:00
Niel Nielsen 6e84d4ca8b Refactor chip ID and app signature checks
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 13:35:48 +02:00
Niel Nielsen b0aa484eba Fix comment for app descriptor in cmdhw.c
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 12:17:34 +02:00
Niel Nielsen c9fe1dd891 Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-08 12:11:52 +02:00
Niel Nielsen 14ab313ca7 Implement firmware image validation for ESP32-C2
Add checks for firmware image validity before flashing.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 12:11:32 +02:00
Iceman 4031fb8cf1 Merge pull request #3601 from sophiel-meow/master
Fix `hf mf sen` abort with wrong frame size
2026-09-08 16:36:48 +07:00
Sophiel Zhou 7cfc6fdea2 fix hf mf sen wrong payload frame size 2026-09-08 16:47:07 +08:00
Iceman aef0a76409 Merge pull request #3600 from Antiklesys/master
Faster i2c comms
2026-09-08 15:29:25 +07:00
Iceman 5fc30b1a6e Merge pull request #3597 from kormax/iso1443_3a_timeslot_support
Add ISO14443-3 Type A timeslot support to 'hf 14a info' and 'hf 14a reader'
2026-09-08 15:28:30 +07:00
Antiklesys 4633805268 Update i2c.h 2026-09-08 16:07:15 +08:00
Antiklesys b412b9c167 Merge branch 'master' of https://github.com/Antiklesys/proxmark3 2026-09-08 16:04:48 +08:00
Antiklesys 9785461f17 Faster i2c comms 2026-09-08 16:04:45 +08:00
iceman1001 764783cbfc annotation for topaz had an issue where it used 9 bytes for reader frames when it could be up to 16 bytes. 2026-09-08 08:04:09 +02:00
Iceman bb20da60a4 Merge pull request #3598 from ry4000/master
R&Y: Updated `Fermax` AID in `aid_desfire.json`
2026-09-08 12:58:30 +07:00
ry4000 26bacfa258 R&Y: Updated Fermax AID in aid_desfire.json
# Updates
1. Updated `Fermax` AID to reflect the parent company's name/country and DESFire PACS product.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-08 10:21:54 +10:00
kormaxandmxcdoam 1ecbcb74be Add ISO14443-3 Type A timeslot support to 'hf 14a info' and 'hf 14a reader'
Co-authored-by: mxcdoam <72457810+mxcdoam@users.noreply.github.com>
2026-09-07 22:55:24 +03:00
Iceman 9f641c3ced Merge pull request #3427 from Sanduuz/feature/st25ta_ndef_sim
Added support for emulating ST25TA tag (IKEA Rothult) with custom NDEF response
2026-09-07 15:38:46 +07:00
Iceman e807ef0df7 Merge pull request #3497 from 0x6r1an0y/20260823-uscuiddoc
Update USCUID section in magic_cards_notes
2026-09-07 15:31:12 +07:00
Iceman 07209fc358 Merge pull request #3493 from 0x6r1an0y/20260819-gdmfix
Improve `hf mf gdm*` commands
2026-09-07 15:28:56 +07:00
ry4000 6b1305cbc9 R&Y: Nomeclature updates to felica_system_code_list.json
# Updates
1. Changed `type` from `e-amusement` to `arcade` for:
    - Bandai Namco Passport
    - Konami e-amusement pass
    - Sega Aime
    - Taito NESiCA
2. Updated `description` to include the full name and `(AIC)` annotation to note that this information only applies to the Amusement IC Card variants as opposed to MFC/ICODE SLI/MFC/MFU, respectively.

-r&y.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-07 10:09:18 +02:00
Iceman 428a573b55 Merge pull request #3593 from xilni/docs/bwm-command-references
docs(bwm): fix stale hw bwm command references
2026-09-07 11:55:21 +07:00
xilni 342cc37cca docs(bwm): fix stale hw bwm command references 2026-09-07 00:07:07 -04:00
Iceman c42ead12dd Merge pull request #3591 from Antiklesys/master
TA1=96 support for SIM module
2026-09-06 21:25:42 +07:00
Iceman 2da575ab36 Merge branch 'master' into master
Signed-off-by: Iceman <iceman@iuse.se>
2026-09-06 21:25:31 +07:00
Iceman 23f8bfbc46 Merge pull request #3473 from YoungJules/feature/add_kgh_tools
Feature/add kgh tools
2026-09-06 21:01:40 +07:00
Iceman 8423286160 Merge pull request #3549 from 0x6r1an0y/20260823-mfuformat
Complete `hf mfu format` command
2026-09-06 21:00:20 +07:00
Iceman 45c1d79282 Merge branch 'master' into 20260823-mfuformat
Signed-off-by: Iceman <iceman@iuse.se>
2026-09-06 21:00:13 +07:00
Antiklesys b2ae468bf9 Update i2c.h 2026-09-06 13:53:46 +08:00