mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-03 10:28:09 +00:00
'hf mfdes dump' walked one application and printed it. It now walks every application on the PICC, keeps what it reads, and saves a 'hf-mfdes-<UID>-dump.json' card image. '--aid' / '--isoid' / '--dfname' still narrow it to one application, '--ns' skips the save. The format is 'mfdes v1', written and read in fileutils.c and documented in doc/mfdes_dump_format.md. Two decisions worth stating: - The PICC level is application 000000, so every key in the file says which AID it opens. Key version and key value are separate: a version with no key is the normal shape for a key that was found but never recovered, and a missing key never means the key is zero. - Every file carries a 'Read' flag. A file whose contents could not be fetched is recorded as unread with no data at all, rather than as a run of zeros. A simulator built on this must not confuse '8 bytes of 00' with 'we could not read 8 bytes'. 'hf mfdes view -f <fn>' prints such a file with no device attached. With no '--keys', the dump looks for 'hf-mfdes-<UID>-keys.json' by itself, so a 'hf mfdes chk -j' run is picked up on the next dump without naming the file again. Two fixes fell out of testing against a DESFire EV2: - DesfireSetKey() calls DesfireClearContext(), which wipes command set, comm mode, KDF and UID, not just the key. Swapping in a per-application key that way left the context at 'Communication mode: n/a' and DesfireFillFileList() then returned junk file ids. Use DesfireSetKeyNoClear(). - GetVersion and the originality signature are answered unauthenticated. Asking for them from inside the authenticated session produced a 'Wrong communication mode' warning and a run of MAC mismatches. hex_to_buffer() treats hex_max_len as a byte count while every sprint_hex* caller passes sizeof(buf) - 1, a character count, so it writes two or three times the buffer size. Measured, sprint_hex_inrow overflowed at 4098 input bytes. Doubling UTIL_BUFFER_SIZE_SPRINT to 16384 moves that to 8192; the mixed semantics still need auditing across ~30 call sites. Co-Authored-By: Claude Opus 5 (1M context)