mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-03 16:58:37 +00:00
hf mfu cchk and hf mfu aeschk were the same command twice. Ninety lines of dictionary loading and chunked device calls were duplicated, and the only real difference was which key slot they targeted: aeschk took --idx, cchk hardcoded the Ultralight C slot. Both are replaced by hf mfu chk, which reads the tag type off the card with GetHF14AMfU_Type() and picks the slot itself. Ultralight AES still honours --idx, 0 DataProtKey, 1 UIDRetrKey, 2 OriginalityKey. Ultralight C holds a single key, so --idx is rejected there rather than silently ignored. Any other tag is refused with a pointer to hf mfu info. Without -f the dictionary is mfulc_default_keys.dic for both tag types. A segment check keeps needing an explicit -f, because the segment dictionaries hold four byte keys and the default one does not. aeschk used to advertise mfulaes_default_keys.dic in its help, which has never been shipped. Collapsing the two bodies also fixes --retries. firstChunk and lastChunk were declared outside the retry loop and never reset, so only the first pass was correct. From the second pass on, every chunk went out with firstchunk clear and lastchunk set, which on the device side means no select and a field teardown after each chunk, against a field the previous pass had already dropped. They are now scoped to the pass. client/pyscripts/mfulaes_mask_recovery.py called aeschk and now calls chk. doc/commands.md and doc/commands.json are regenerated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>