Commit Graph
159 Commits
Author SHA1 Message Date
Philippe Teuwen 634edd11fd make style 2026-09-16 19:00:50 +02:00
iceman1001andClaude Opus 5 (1M context) 344c2d6185 trace: stop trace save writing a stale client side buffer
`trace save` saved the client side trace buffer whenever it was non-empty
and only downloaded from device when it was empty. After `trace load` or
`trace list -1` a following sniff -> `trace save` silently wrote the old
trace, byte identical to the previous save, with no way to reset it.
See #3592, and #1252 / #1512 for earlier reports of the same thing.

- `trace save` now downloads from device by default and takes `-1` to save
  the client side buffer, mirroring `trace list`. Offline it falls back to
  the buffer so `trace load` -> `trace save` still works.
- split download_trace() into download_trace_ex(), which hands the caller
  its own buffer. `trace save` uses it and no longer mutates gs_trace, so
  `-1` means the client buffer regardless of what ran before.
- download_trace() freed gs_trace before it knew the download had worked,
  so a timeout threw away a loaded trace. It now swaps on success only.
- added `trace clear` to discard the client side buffer, and a shared
  ClearTraceBuffer() to replace the free/NULL/zero pattern that was
  open coded in ImportTraceBuffer() and CmdTraceLoad().

Help text for both new commands names the device vs client distinction.

Co-Authored-By: Claude Opus 5 (1M context)
2026-09-12 21:39:35 +02:00
iceman1001 10dafd8048 fix a hitagu overflow in cmdtrace.c 2026-09-12 11:56:10 +02:00
iceman1001 764783cbfc annotation for topaz had an issue where it used 9 bytes for reader frames when it could be up to 16 bytes. 2026-09-08 08:04:09 +02:00
iceman1001 ace5d63ff9 hitag2: fix simulation against genuine readers, add restore, fix info
Simulation now completes the full exchange with a genuine Paxton reader in
password mode, and crypto mode read/write passes Proxmark-to-Proxmark.

Firmware:
- SOF was one bit period short. The lead-in that compensated for the lost
  head half bit was removed and nothing replaced it, so readers rejected
  every answer with a second START_AUTH. Default is now 6.
- The edge-detect threshold was latched before being measured, so the value
  chosen depended on whether the Proxmark was in a field when sim started.
  It is now measured on field entry and re-armed when the reader leaves.
- The percentile walk latched on run-scoped variables, so one attempt made
  outside a field poisoned every later one.
- Field loss was detected from TIMESTAMP, which is free-running MCU time and
  never stalls. Detect it from receive silence instead.
- Frames of a length the protocol does not have no longer reach the state
  machine; our own modulation tail was resetting the session and breaking
  every write.
- A dropped edge merges two or three reader bit periods into one gap. Those
  bits were discarded; they are now recovered by decomposition, which is what
  made crypto mode work (AUTH decode 15% -> 100%).
- Threshold selection is limited to 20 and 32 and settles in under 25 ms.

Client:
- lf hitag info printed a hardcoded 0x06 and reported 'Password mode' for
  every tag. It now reads page 3, takes -k (4 bytes password, 6 bytes
  crypto), and says so when the config cannot be read.
- lf hitag restore: writes a dump back in dependency order - user pages,
  then key material, then config last - validates the config byte, and
  prints the credential the tag will require afterwards.
- lf hitag crack2 now reports why it failed instead of a bare 'fail'.
- trace list: bit count moved to its own column, relative mode shows a
  Frame Delay Time row rather than renaming Start/End, --frame and -r
  rejected together.
2026-09-04 13:20:29 +02:00
iceman1001 b0c1e42720 textual changes and layout changes to 'lf hitag list'. Now it is more uniform with the rest of the annotation formats 2026-09-03 18:15:44 +02:00
Philippe Teuwen 0cde2124c8 Replace pm3_max_cmd_data_size() by g_conn.max_cmd_data_size 2026-09-01 17:58:14 +02:00
Niel Nielsen 9e1b63edce make style
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-01 17:57:31 +02:00
Niel Nielsen 9df1c62ec5 Add files via upload
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-09-01 17:57:31 +02:00
iceman1001 87b5ee37c9 stablize download trace more 2026-08-29 17:02:15 +02:00
iceman1001 76181dfb8e sim module firmware is now v4.60, (sim020.bin) it adds a better drain when T=0 exits abnormal (abort). Better waiting time floor, with faster ETU which doesnt shrink with WWT.\n Changes to i2c with SDA timings, also modified the fixed msleep(100) with an idle time waiting which leads to 107 ms off from every iteration.\n Added a ATR cache to remember which TA1 was autonegotiated. This impact i2c comms speed with sim module for same card. 'smart pps' is better documented.\n The sam_common.c now also logs 61xx and GET_RESPONSE :) and generic long-form ASN-1 lengths. trace list -t 7816 now also shows rdr frames in us. \n All in all, this should lead for 'emv reader -w' to go from 5.87sec to 2.78sec. 'hf seos sam' is down to 1.92sec. 'hw ping' is down to 0.57sec. A USB round trip is down from 20.8ms to 1.3ms. It should give a snappier end user experience 2026-08-27 22:37:32 +02:00
iceman1001 5f05cbf576 the annotations for 7816 handles contact vs contactless situations better now. Thanks Claude 2026-08-26 20:44:34 +02:00
kormax cec963b9ba Annotate FeliCa SEAC request and response traces 2026-08-01 12:42:06 +03:00
iceman1001 2c6e607110 style 2026-07-15 16:39:15 +02:00
kormax 15ab857ea8 Add trace anntation support for basic Innovatron commands 2026-06-26 23:31:24 +03:00
Philippe Teuwen d078e8a62b make style 2026-05-21 20:54:44 +02:00
iceman1001 cbb572afad style 2026-05-11 14:36:17 +02:00
kormax 3da7e52c1a Implement 'hf calypso list' command 2026-05-10 21:18:04 +03:00
kormax 9399dfc16e Fix ISO7816 trace CRC status handling 2026-05-10 21:18:04 +03:00
iceman1001 69f40df005 unified some minor hint text messages. added a ndef detection to hf mfu dump, hf mfu view, hf mfu eview in order to suggest that there is actually a ndefmessage 2026-04-19 08:52:16 +07:00
iceman1001 ad82c50158 enforce NULL checks after all malloc, calloc, realloc 2026-03-29 10:20:30 +07:00
Philippe Teuwen c00e4801b7 make style 2026-02-06 13:43:41 +01:00
Philippe Teuwen fd88967443 make style 2025-10-14 09:50:59 +02:00
Oleg Moiseenko 944a80d217 make style 2025-09-21 16:41:30 +03:00
iceman1001 5de4dd68e5 text 2025-06-22 20:34:54 +02:00
iceman1001 ad292e8810 unify test - step 2 2025-03-25 10:17:42 +01:00
iceman1001 4d603a4530 unify hint text 2025-03-20 22:55:26 +01:00
iceman1001 ccef511dec updated trace list -t seos to also annotate ISO7816 2025-03-20 20:01:04 +01:00
iceman1001 17a8f0f9c2 text 2025-03-20 12:17:37 +01:00
iceman1001 440d283a53 in the philosofy to have short and direct params , the trace list -t hitag types has been shortend from hitag1 - ht1 2025-03-19 15:24:39 +01:00
douniwan5788 4bde83b89d Added lf hitag htu support for Hitag µ/8265 2025-03-19 18:56:23 +08:00
douniwan5788 64a4f6cd81 Enhance Hitag S annotation and debugging 2025-03-19 18:12:53 +08:00
douniwan5788 3d0c8cab5c Refactor Hitag low-level functions into hitag_common 2025-03-19 17:05:39 +08:00
iceman1001 2137284a93 style\n Some improvements to trace list -t seos annotations. 2025-03-12 16:41:06 +01:00
iceman1001 2f56bdcf10 text and style 2025-02-18 18:44:24 +01:00
Philippe Teuwen 917be92afc typos 2025-01-05 14:27:14 +01:00
klks df3916c7b6 Add annotations for FMCOS2.0 CPU Card
Adding annotations for the FMCOS 2.0 CPU Card that is used/sold in China.
2024-12-20 22:50:20 +08:00
nvx bac1bf05af log a message when aborting trace list display 2024-11-13 21:53:31 +10:00
Philippe Teuwen 5848b31ee1 trace list: don't mix 02x and 02X 2024-10-18 19:44:38 +02:00
douniwan5788 ac1f490aab fix: trace list when there are exactly 8 bits of data. 2024-10-15 13:36:34 +08:00
douniwan5788 375eb612e8 style: Hitag names 2024-09-13 17:15:37 +08:00
iceman1001 384a7212d0 text 2024-08-25 17:09:31 +02:00
iceman1001 6a95f16102 style and text 2024-08-25 15:17:02 +02:00
iceman1001 369db7c9d7 style 2024-05-27 20:29:02 +02:00
iceman1001 4bbfc944f3 fix const params, logic, casting 2024-05-14 14:13:13 +02:00
iceman1001 2e2fa850bb const params, vars, scope, bad if statements 2024-05-14 12:25:00 +02:00
iceman1001 3f6ea0f0fc style 2024-04-22 16:35:22 +02:00
iceman1001 c8849af5e0 This is the major changes made to the HITAG2 commands. Its heavly based on RFIDLers implementation and its been converted to work with Proxmark3. Special thanks to @kevsecurity for his amazing implementations of the Gone in 360 Seconds paper by Roel, Flavio & Balasch. Thanks to @adamlaurie for his RFIDler project. It wouldnt been doable without it. 2024-04-22 16:20:24 +02:00
iceman1001 4e540053e9 style 2024-04-07 11:38:51 +02:00
iceman1001 700d558432 move hitag2 crypto parts to the common folder in order to be able to use it on the client side. Some textual and minor adaptations across the bord 2024-03-27 09:32:00 +01:00