Commit Graph
14210 Commits
Author SHA1 Message Date
Matthew CarrollandClaude Opus 5 0586b8a1c3 lf t55xx detect: settle the block 0 rotation with the broadcast period
A block read repeats one 32 bit word, so every offset yields a rotation and more
than one can pass the structural checks. A T5577 in direct/nrz carried both
00080040, the word on the tag, and 00080001, its ror19 - both master key 0,
reserved 0, RF/32, direct. test() answers with the first hit from a fixed floor,
so which one detect reported was scan order rather than evidence.

No structural check separates them: every bit of block 0 is a real field, and
the three the scan skips are otp, fast write and inverse data, all settable. The
tag can, though - maxblock has to account for what regular read mode cycles
through. So measure the broadcast period and keep the rotation that agrees,
reusing the constraint printConfiguration already applies to the psk2/psk3
pre-images. Costs one acquisition, and only when the reading is ambiguous.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-10 14:57:15 -07:00
iceman1001 82c726dd9b fix t55xx_config.lua script with scoring of psk2/3 to write a proper text 2026-09-10 10:05:10 +02:00
iceman1001 78b4d4ef00 fix psk1 detection. now scores 24/24 tests 2026-09-10 05:45:13 +02:00
iceman1001 e121e3f0a8 fixing FSK / t5577 2026-09-10 05:28:06 +02:00
iceman1001 d54ae662ce fix lua scripts grabbing return text. mimics the python binding way now 2026-09-10 04:31:47 +02:00
iceman1001 bef7f3752a another entry 2026-09-10 04:03:57 +02:00
iceman1001andClaude Opus 5 (1M context) ea2909702f lf t55xx: anchor the block read offset in samples, not demod bits
GetT55xxBlockData extracted every block at config.offset, a bit index into a
demod buffer cached by the last detect - a different capture. Demodulators do
not all start on the same bit, so a later read could return a rotation of the
block with nothing marking it as wrong: psk1 by four or five bits, fsk2a and
nrz by one, manchester and biphase never.

Record the boundary where it is stable instead. Every demodulator reports the
graph sample its first bit sits on, and turn_read_lf_on(137 * 8) makes the
firmware open each read acquisition at the same point, so the word boundary
lands on the same sample every time. Convert back per demodulation.

Block 0 re-anchors from its known value, and a write is now verified by the
value being anywhere in the repeating stream rather than at one cached offset -
which also fixes correct writes reporting as validation failures. A block 0
verify re-detects on a mismatch, not only on a decode failure: the pre-write
config can decode the post-write signal into garbage rather than failing.

Also fixes a -1 password sentinel truncated to 32 bits by a ternary, which made
that detect report a password that was never supplied.

Measured on a T5577 across psk1, fsk2a and direct/nrz: three consecutive dumps
agree field for field, against a baseline where psk1 corrupted 22 of 24.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-10 03:58:14 +02:00
iceman1001 253e0d148a hf emrtd info - did not identify and mapped OID for algorithms in PACE. Now we keep a list and pretty print it 2026-09-10 02:55:16 +02:00
ry4000 ef23d014eb R&Y: Updated MEGACASH AID in aid_desfire.json
# Updates
1. Updated `MEGACASH` vendor name from `Bank Mega` to `PT Bank Mega Tbk` *which is the vendor's full name*.

-r&y.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-09 16:15:03 +10:00
Iceman 23d6f67dc8 Merge pull request #3603 from kormax/new-aid-desfire-entries
Add new ISO7816 & DESFire AID values
2026-09-08 22:57:50 +07:00
kormax 6c8cf5bdcf Add new ISO7816 AID values 2026-09-08 18:24:09 +03:00
kormax a4b1dd0ee7 Add new DESFire AID entries 2026-09-08 18:23:15 +03:00
Niel Nielsen 6e84d4ca8b Refactor chip ID and app signature checks
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 13:35:48 +02:00
Niel Nielsen b0aa484eba Fix comment for app descriptor in cmdhw.c
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 12:17:34 +02:00
Niel Nielsen c9fe1dd891 Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-08 12:11:52 +02:00
Niel Nielsen 14ab313ca7 Implement firmware image validation for ESP32-C2
Add checks for firmware image validity before flashing.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-08 12:11:32 +02:00
Sophiel Zhou 7cfc6fdea2 fix hf mf sen wrong payload frame size 2026-09-08 16:47:07 +08:00
Iceman 5fc30b1a6e Merge pull request #3597 from kormax/iso1443_3a_timeslot_support
Add ISO14443-3 Type A timeslot support to 'hf 14a info' and 'hf 14a reader'
2026-09-08 15:28:30 +07:00
iceman1001 764783cbfc annotation for topaz had an issue where it used 9 bytes for reader frames when it could be up to 16 bytes. 2026-09-08 08:04:09 +02:00
ry4000 26bacfa258 R&Y: Updated Fermax AID in aid_desfire.json
# Updates
1. Updated `Fermax` AID to reflect the parent company's name/country and DESFire PACS product.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-08 10:21:54 +10:00
kormaxandmxcdoam 1ecbcb74be Add ISO14443-3 Type A timeslot support to 'hf 14a info' and 'hf 14a reader'
Co-authored-by: mxcdoam <72457810+mxcdoam@users.noreply.github.com>
2026-09-07 22:55:24 +03:00
Iceman 9f641c3ced Merge pull request #3427 from Sanduuz/feature/st25ta_ndef_sim
Added support for emulating ST25TA tag (IKEA Rothult) with custom NDEF response
2026-09-07 15:38:46 +07:00
Iceman 07209fc358 Merge pull request #3493 from 0x6r1an0y/20260819-gdmfix
Improve `hf mf gdm*` commands
2026-09-07 15:28:56 +07:00
ry4000 6b1305cbc9 R&Y: Nomeclature updates to felica_system_code_list.json
# Updates
1. Changed `type` from `e-amusement` to `arcade` for:
    - Bandai Namco Passport
    - Konami e-amusement pass
    - Sega Aime
    - Taito NESiCA
2. Updated `description` to include the full name and `(AIC)` annotation to note that this information only applies to the Amusement IC Card variants as opposed to MFC/ICODE SLI/MFC/MFU, respectively.

-r&y.

Signed-off-by: ry4000 <154689120+ry4000@users.noreply.github.com>
2026-09-07 10:09:18 +02:00
xilni 342cc37cca docs(bwm): fix stale hw bwm command references 2026-09-07 00:07:07 -04:00
Iceman 2da575ab36 Merge branch 'master' into master
Signed-off-by: Iceman <iceman@iuse.se>
2026-09-06 21:25:31 +07:00
Iceman 23f8bfbc46 Merge pull request #3473 from YoungJules/feature/add_kgh_tools
Feature/add kgh tools
2026-09-06 21:01:40 +07:00
Iceman 45c1d79282 Merge branch 'master' into 20260823-mfuformat
Signed-off-by: Iceman <iceman@iuse.se>
2026-09-06 21:00:13 +07:00
dxl fc355df050 Added IO test capabilities to the factory QC for PM5. 2026-09-05 18:09:46 +02:00
dxl ea5485b4b8 Rename CMD_PM5_QC_TEST to CMD_PM5_QC_TEST_HW
and delete repeated def: CMD_PM5_BWM_SET_CAP
2026-09-05 18:09:46 +02:00
Antiklesys 999f64ddf9 Merge branch 'RfidResearchGroup:master' into master 2026-09-05 17:17:25 +08:00
Antiklesys 264d9bf284 TA1=96 support for SIM module 2026-09-05 17:16:38 +08:00
Niel Nielsen ea4d90ebe4 Refactor BWM command handling for clarity and structure
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-05 10:09:23 +02:00
歐歪 6960a6e788 fix: oops 2026-09-05 05:40:45 +08:00
歐歪 7e2ecc0ba6 rename: hf mfu format to ndefformat 2026-09-05 05:18:36 +08:00
Julian Isaac 71ca59a8ad Moved the new tool to tools/kgh and renamed it legic_kgh_tool. Added some validation so we don't return random bytes from non-kgh cards. Applied some styling to the new code. Added GPL header to new source file. Cleaned up the static build. 2026-09-04 23:14:22 +02:00
Julian Isaac 1d5d09b073 Merge branch 'master' into feature/add_kgh_tools 2026-09-04 22:23:13 +02:00
Niel Nielsen 93ea5600f8 Merge branch 'RfidResearchGroup:master' into BWM-work 2026-09-04 17:10:15 +02:00
iceman1001 0aef94c667 fix 'lf hitag reader -@' mode with sending a break afterwards. 2026-09-04 15:18:16 +02:00
Niel Nielsen 7b37171986 Merge pull request #1 from nieldk/bwm-ota-begin-timeout
Give BWM OTA begin enough time to erase, and stop retuning UART for t…
2026-09-04 14:55:00 +02:00
Niel Nielsen cf3730e1b4 Merge branch 'RfidResearchGroup:master' into BWM-work 2026-09-04 14:29:26 +02:00
WillandCursor 22969ec79a Give BWM OTA begin enough time to erase, and stop retuning UART for the transfer
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-04 08:24:16 -04:00
iceman1001 ace5d63ff9 hitag2: fix simulation against genuine readers, add restore, fix info
Simulation now completes the full exchange with a genuine Paxton reader in
password mode, and crypto mode read/write passes Proxmark-to-Proxmark.

Firmware:
- SOF was one bit period short. The lead-in that compensated for the lost
  head half bit was removed and nothing replaced it, so readers rejected
  every answer with a second START_AUTH. Default is now 6.
- The edge-detect threshold was latched before being measured, so the value
  chosen depended on whether the Proxmark was in a field when sim started.
  It is now measured on field entry and re-armed when the reader leaves.
- The percentile walk latched on run-scoped variables, so one attempt made
  outside a field poisoned every later one.
- Field loss was detected from TIMESTAMP, which is free-running MCU time and
  never stalls. Detect it from receive silence instead.
- Frames of a length the protocol does not have no longer reach the state
  machine; our own modulation tail was resetting the session and breaking
  every write.
- A dropped edge merges two or three reader bit periods into one gap. Those
  bits were discarded; they are now recovered by decomposition, which is what
  made crypto mode work (AUTH decode 15% -> 100%).
- Threshold selection is limited to 20 and 32 and settles in under 25 ms.

Client:
- lf hitag info printed a hardcoded 0x06 and reported 'Password mode' for
  every tag. It now reads page 3, takes -k (4 bytes password, 6 bytes
  crypto), and says so when the config cannot be read.
- lf hitag restore: writes a dump back in dependency order - user pages,
  then key material, then config last - validates the config byte, and
  prints the credential the tag will require afterwards.
- lf hitag crack2 now reports why it failed instead of a bare 'fail'.
- trace list: bit count moved to its own column, relative mode shows a
  Frame Delay Time row rather than renaming Start/End, --frame and -r
  rejected together.
2026-09-04 13:20:29 +02:00
Niel Nielsen a019756bfa Merge branch 'RfidResearchGroup:master' into BWM-work 2026-09-04 12:58:10 +02:00
Niel Nielsen d4e375f50b Move all bmw commands to subgroups
hw bwmautooff	hw bwm autooff
hw bwmcharge	hw bwm charge
hw bwmsetcap	hw bwm setcap
hw bwmupgrade	hw bwm upgrade
hw bwmvchg	hw bwm vchg
hw bwmwifi	hw bwm wifi

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-04 11:57:28 +02:00
iceman1001 d85550c6de text 2026-09-04 10:18:08 +02:00
iceman1001 ff387762b4 text 2026-09-04 10:16:34 +02:00
Niel Nielsen edd5ada64a Increase response timeout and update comments in cmdhw.c
Increase timeout for response when querying BWM version and adjust comments for clarity.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-04 09:47:35 +02:00
Niel Nielsen 81a3c61058 Add progress bar and write delay to OTA function
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-04 09:31:47 +02:00
Niel Nielsen afcfa2168b Update print statement from 'Hello' to 'Goodbye'
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-04 09:28:36 +02:00