Commit Graph
23232 Commits
Author SHA1 Message Date
iceman1001 1dbb77e238 lesson learned 2026-09-14 16:57:59 +02:00
iceman1001 e3096510c5 text 2026-09-14 16:54:28 +02:00
iceman1001 1f450c9bf8 add missing HF_LEGIC_RDV4 2026-09-14 16:53:50 +02:00
iceman1001andClaude Opus 5 (1M context) 3e98b2dfe4 hf legic: stop eload losing everything after its first packet
'hf legic eload' writes emulator memory as a burst of back-to-back
packets. CMD_HF_LEGIC_ESET called FpgaDownloadAndGo(FPGA_BITSTREAM_HF)
on every one of them, and when that actually had a bitstream to download
the device stopped servicing USB for long enough that the packets already
in flight behind it were dropped.

Reproducible, and it only shows after a command that left a different
bitstream loaded, which is why it has gone unnoticed:

    hf iclass eload ...      # loads FPGA_BITSTREAM_HF_15
    hf legic eload -f x.bin  # first packet downloads FPGA_BITSTREAM_HF
    hf legic esave --1024    # 404 bytes of 1024 come back as zeros

The boundary is always 619, which is max_cmd_data_size minus
sizeof(legic_packet_t) -- exactly one packet. Back to back a second time
it works, because the bitstream is then already loaded. The 'fast push
mode' in legic_seteml() is not involved: block_after_ACK only applies to
OLD frames and these are NG.

So the handler does no FPGA work at all now. The comment it used to carry
-- 'if it is called later, it might destroy the Emulator Memory' -- was
aiming at a real problem but solving it at the wrong end. init_tag() in
legicrfsim.c is where the bitstream is genuinely needed, and it was using
the plain variant twelve lines above 'legic_mem = BigBuf_get_EM_addr()',
so 'hf legic sim' was wiping the image it was about to serve. That one
becomes _keep_EM.

Five sibling handlers carry the same copy-pasted comment and the same
wipe-before-use pattern and are switched to _keep_EM as well:
CMD_LF_EM4X50_SIM (em4x50_sim reads its tag out of emulator memory),
CMD_LF_EM4X50_ESET, CMD_HF_ISO15693_EML_SETMEM, EML_GETMEM and
CMD_HF_MIFARE_EML_MEMCLR. Only the LEGIC path has a reproducer; the rest
is the same fix applied where the same mistake is visible.

Verified on an RDV4: the reproducer above now loses 0 bytes over three
runs, 'hf legic sim' reports the MCD/MSN of the uploaded image, and
eload/esave still round-trips byte-identical for MIFARE Classic 4K,
iso15693 and iCLASS.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 15:05:31 +02:00
iceman1001 d2dd2d9f32 text 2026-09-14 14:58:54 +02:00
iceman1001andClaude Opus 5 (1M context) 616ec198f0 BigBuf: raise emulator memory to 8192 bytes
A MIFARE Classic 4K fills 4096 of emulator memory exactly, so at that
size it was fully committed and nothing larger could be simulated at
all.

The 4096 comes out of BigBuf, which is 33272 bytes on AT91, so it is
4096 that traces and LF samples do not get. The largest allocation any
tag simulation makes alongside emulator memory is 10459 bytes, which
leaves 18.7 kB of trace at the new size. LF acquisition is unaffected
either way: lfops.c calls BigBuf_free(), which drops emulator memory
entirely, so the two never coexist.

The device already reports this size to the client in capabilities_t, so
no client change is needed and both the client and device side download
clamps pick up the new value on their own.

This increased reserved space for emulator memory is intended pave the way for MIFARE DESfire simulation better.

Verified on an RDV4: eload/esave round trips byte-identical for MIFARE
Classic 4K, Ultralight, iso15693, iCLASS and LEGIC MIM1024; ST25TA
simulation starts and runs; lf read still gets 33271 samples; both
clamps now truncate at 8192.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 14:50:23 +02:00
iceman1001andClaude Opus 5 (1M context) 5b909402b5 BigBuf: stop narrowing sizes, and size the 14a modulation buffer to fit
Three things that all cost memory or correctness once BigBuf is larger
than 64KB, which it already is on PM5.

BigBuf_max_traceLen() returned a uint16_t while s_bigbuf_hi is a
uint32_t. At 33272 on AT91 that is harmless; on AT32, where BigBuf runs
to several hundred kbyte, it truncates and LF sampling asks for a
fraction of the buffer that is there. Widened, along with the four
callers that assigned it straight back into a uint16_t.

BigBuf_malloc() and BigBuf_calloc() took a uint16_t chunksize, so a
request of exactly 65536 arrived as 0 and anything above wrapped. It
returned NULL for the 65536 case by accident, not by design. Both take a
uint32_t now and the guard tests the upper bound explicitly, so an
oversized request fails like any other allocation that does not fit.

The 14a tag simulation allocated its dynamic modulation buffer as a flat
512, or 4096 for ST25TA. prepare_tag_modulation() memcpy's the encoded
answer out of the ToSend buffer and tosend_stuffbit() hard caps that at
TOSEND_BUFFER_SIZE, so 1788 of ST25TA's 4096 could never be reached --
it was the largest single allocation of any tag simulation for nothing.
Meanwhile 512 is 68 bytes short of what a full 64 byte response encodes
to, at 9 bytes per byte plus 4, so those answers were refused at
modulation time.

Both are now derived from the response size and capped at what ToSend
can hold: 580 for the default tag types, 2308 for ST25TA. That also
fixes the reason the 4096 never helped -- all six call sites passed the
512 macro as max_buffer_size rather than the size actually allocated, so
ST25TA allocated 4096 and then bounds checked against 512.

Worst case for a simulation that also holds emulator memory drops from
12247 bytes of BigBuf to 10459.

Built for client, RDV4 and PM3GENERIC. Not yet run on hardware.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 13:06:14 +02:00
iceman1001 8393783548 one more entry in the mad 2026-09-14 12:40:51 +02:00
iceman1001 8f5fd048d3 improve emulator downloads with out of bounds checks 2026-09-14 12:27:06 +02:00
iceman1001 465deeda39 text 2026-09-14 12:24:31 +02:00
iceman1001 aae70014e0 - VIGIK service badge fields now show which ones the RSA signature actually covers 2026-09-14 12:21:47 +02:00
iceman1001 9caa6d6117 minor change we device now reports back EMULATOR memory size to the client. Had to bump capability version number to 11. 2026-09-14 12:16:51 +02:00
iceman1001andClaude Opus 5 (1M context) 6f4643a637 hf mf: add the MAD helpers parseproac needs, and register AID 0x4982
b82f60362 landed parseproac.c without them, so a clean checkout does not
build.

 - mad.c / mad.h: mad_find_aid() and mad_count_aid(); DetectHID() delegates
   to the first, it was already generic
 - mad.json: 0x4982 PROAC, sorted in after NORALSY's 0x4980

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 12:13:35 +02:00
iceman1001 b82f603622 urmet parsing 2026-09-14 12:11:42 +02:00
iceman1001 cac7378e95 text 2026-09-14 09:19:29 +02:00
iceman1001 9b60b1b218 missing define 2026-09-14 09:19:17 +02:00
iceman1001andClaude Opus 5 (1M context) 82783eae26 hf mf: decode the Hexact payload
Sectors 9 and 11 were printed raw and marked 'not decoded'.

 - remove the XOR keystream and print the ten eight byte records
 - check the eighteen record bytes that are XOR combinations of sector 0,
   sector 15 and the UID, plus three record to record ties
 - 'hf mf view --selftest' now covers the decoder, using a synthetic card
 - sector 15 marker compare ignores case, factory blanks were not matched
 - an all FF or all 00 payload is named, not decrypted
 - sector 15 block 2 is text on a blank, so only read a serial there when
   the first four bytes are not printable

Research. The remaining 58 payload bytes are issuer data and are printed
without interpretation.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 09:19:05 +02:00
iceman1001andClaude Opus 5 (1M context) 8fd9bcbebc hf mfdes: dump a whole card to json, and view it back
'hf mfdes dump' walked one application and printed it. It now walks
every application on the PICC, keeps what it reads, and saves a
'hf-mfdes-<UID>-dump.json' card image. '--aid' / '--isoid' / '--dfname'
still narrow it to one application, '--ns' skips the save.

The format is 'mfdes v1', written and read in fileutils.c and documented
in doc/mfdes_dump_format.md. Two decisions worth stating:

 - The PICC level is application 000000, so every key in the file says
   which AID it opens. Key version and key value are separate: a version
   with no key is the normal shape for a key that was found but never
   recovered, and a missing key never means the key is zero.

 - Every file carries a 'Read' flag. A file whose contents could not be
   fetched is recorded as unread with no data at all, rather than as a
   run of zeros. A simulator built on this must not confuse '8 bytes of
   00' with 'we could not read 8 bytes'.

'hf mfdes view -f <fn>' prints such a file with no device attached.

With no '--keys', the dump looks for 'hf-mfdes-<UID>-keys.json' by
itself, so a 'hf mfdes chk -j' run is picked up on the next dump without
naming the file again.

Two fixes fell out of testing against a DESFire EV2:

 - DesfireSetKey() calls DesfireClearContext(), which wipes command set,
   comm mode, KDF and UID, not just the key. Swapping in a per-application
   key that way left the context at 'Communication mode: n/a' and
   DesfireFillFileList() then returned junk file ids. Use
   DesfireSetKeyNoClear().

 - GetVersion and the originality signature are answered unauthenticated.
   Asking for them from inside the authenticated session produced a
   'Wrong communication mode' warning and a run of MAC mismatches.

hex_to_buffer() treats hex_max_len as a byte count while every sprint_hex*
caller passes sizeof(buf) - 1, a character count, so it writes two or
three times the buffer size. Measured, sprint_hex_inrow overflowed at
4098 input bytes. Doubling UTIL_BUFFER_SIZE_SPRINT to 16384 moves that to
8192; the mixed semantics still need auditing across ~30 call sites.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-14 09:11:38 +02:00
iceman1001 66dbf6ac5c update 2026-09-14 09:03:57 +02:00
iceman1001 48d779261a the new dump format for desfire cards 2026-09-14 08:37:00 +02:00
Iceman 7751be208c Merge pull request #3624 from nieldk/esp32-c2
PM5 add option to connect by BLE name
2026-09-14 01:22:25 +07:00
Niel Nielsen 96634fb2bf Increase PM3_FPC_MAX_DATA from 2048 to 4096
Fixes the the disconnects when on BLE connection

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 20:18:32 +02:00
Niel Nielsen 23d851610b Fix CMakeLists.txt to properly end foreach loop
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 18:26:44 +02:00
Niel Nielsen d8d0ecc724 Fix CMakeLists.txt by correcting foreach loop syntax
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 18:24:07 +02:00
Niel Nielsen 1b9eb458ec Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-13 18:22:48 +02:00
iceman1001 64b5db4ddd text 2026-09-13 18:22:27 +02:00
Niel Nielsen 720ea518f7 Fix CMakeLists.txt by adding missing newline
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 18:20:51 +02:00
Niel Nielsen afeab5f6dc Fix CMakeLists.txt by adding missing newline
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 18:20:43 +02:00
Niel Nielsen 2486e74aa0 Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-13 17:59:03 +02:00
Niel Nielsen 284e4b385c Refactor BLE error handling and time functions
Refactor BLE error handling to return standard error codes instead of PM3_* constants. Update time-related functions to use a consistent method for obtaining the current time.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 17:58:45 +02:00
Niel Nielsen c264251935 Fix CMakeLists.txt to properly close foreach loop
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 17:57:59 +02:00
Niel Nielsen 583f05198a Add parsehexact.c to CMakeLists.txt
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 17:57:07 +02:00
iceman1001andClaude Opus 5 (1M context) a812e6728f tools: run the vigik_recover_pk selftests in CI
Beside the recover_pk ones, in the common target.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-13 17:50:45 +02:00
Niel Nielsen 0a90b714cc Add files via upload
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 17:31:12 +02:00
Niel Nielsen bf703c24ff Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-13 17:03:14 +02:00
Niel Nielsen 50e07859e8 Refactor error handling in select function
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 16:25:09 +02:00
iceman1001andClaude Opus 5 (1M context) e19c6755fe hf mf: stop a refused nested auth from hanging autopwn and eating the keys
MifareNested collected nonces in 'while (target_nt[i] == 0)' with no
attempt counter. When the tag NAKs the nested authentication the loop
re-sent the identical frame forever, so the client's 2s wait expired and
autopwn returned PM3_ETIMEOUT — throwing away every key recovered up to
that point. Reported on a card whose sector 16 refuses the standard MFC
EV1 keys: 32 keys cracked, nothing saved.

A NAK is a refusal, not a glitch, so the device now gives up on it and
reports PM3_EWRONGANSWER. autopwn names the sector it skipped and carries
on, and a timeout falls through to the key table and the dump whenever
anything was recovered.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-13 15:56:41 +02:00
iceman1001 c615ef8930 adapting parser 2026-09-13 15:52:39 +02:00
Niel Nielsen 510767f51e Update return values in ble_posix.h documentation
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 14:54:45 +02:00
Niel Nielsen cdc4d7ad26 Refactor BLE connection error handling and logging
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 14:54:07 +02:00
Niel Nielsen e004cc213a Update Makefile
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 14:52:41 +02:00
Niel Nielsen 52fac7ca1b Add parsehexact.c to Makefile build list
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:44:42 +02:00
Niel Nielsen ea585bacd6 Fix include directive for dependency files in Makefile
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:18:57 +02:00
Niel Nielsen 28daf3e2c4 Enhance BLE capabilities hint and connection logic
Add hints for granting BLE scanning privileges and improve error handling in connection functions.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:15:40 +02:00
Niel Nielsen 84dd953cf4 Merge branch 'RfidResearchGroup:master' into esp32-c2 2026-09-13 13:12:32 +02:00
Niel Nielsen ca29260b0d Correct preprocessor directive formatting
Fix formatting of preprocessor directive ending.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 13:09:46 +02:00
iceman1001andClaude Opus 5 (1M context) 66f9a6b51f hf mfdes: report a select/auth failure once, not twice
DesfireSelectAndAuthenticate*() and its callers both printed the same
error at different severities, so every failure came out as two lines.
The core helper now owns the message and names the AID and the step;
the 23 restatements in cmdhfmfdes.c are gone. Same duplicate pair fixed
in cmdhfgallagher.c.

Also: DesfireAuthErrorToStr() falls back to DesfireGetErrorString() for
the PM3_E* codes the select paths pass through, which used to print an
empty reason, and auth error 7 no longer reuses the text of error 1.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-13 12:58:46 +02:00
iceman1001 7142ddc9bd added hexact parser 2026-09-13 12:55:43 +02:00
Niel Nielsen 7efc83ca1d Implement BD address validation and update BLE logic
Added a function to check if a string is a valid Bluetooth address and updated the BLE connection logic to handle both addresses and names.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 12:44:15 +02:00
Niel Nielsen dcde9dd16e Add ble_resolve_name function for device name resolution
Added a function to resolve advertised device names to their LE addresses.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-13 12:43:40 +02:00