mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-09-17 05:54:42 +00:00
foundKeys was indexed [keytype][keyno] with no AID dimension and was never reset between applications, so a key number recovered on one AID was skipped without a single auth attempt on every later AID. On a card with AES key 00 set on two apps, only the first one was ever reported. Give every application its own desfire_app_keys_t and hand that to the checker. Saving to json now uses a new 'mfdes v2' format keyed by AID, with a loader that round-trips it; v1 is kept for existing files. Also in the same path: - one auth error below 7 broke out of the key number loop, abandoning every remaining key number for the AID. Only an algo mismatch (4, 50, 51) skips the key type now; an invalid key number (3) skips just that key number, and a transmit error retries after a reselect - 3TDEA keys were stored 16 bytes wide and written out as 24 - -k with a 24 byte key was rejected by the parser, making the 24 byte branch unreachable - DesfireGetAIDList() wrote unbounded into a 78 byte app_ids buffer Co-Authored-By: Claude Opus 5 (1M context)
46 lines
1.6 KiB
C
46 lines
1.6 KiB
C
//-----------------------------------------------------------------------------
|
|
// Copyright (C) Proxmark3 contributors. See AUTHORS.md for details.
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License for more details.
|
|
//
|
|
// See LICENSE.txt for the text of the license.
|
|
//-----------------------------------------------------------------------------
|
|
#ifndef __DESFIRE_H
|
|
#define __DESFIRE_H
|
|
|
|
#include "common.h"
|
|
|
|
#define DESFIRE_MAX_CRYPTO_BLOCK_SIZE 16
|
|
#define DESFIRE_MAX_KEY_SIZE 24
|
|
#define DESFIRE_MAC_LENGTH 4
|
|
#define DESFIRE_CMAC_LENGTH 8
|
|
|
|
typedef enum {
|
|
T_DES = 0x00,
|
|
T_3DES = 0x01, //aka 2K3DES
|
|
T_3K3DES = 0x02,
|
|
T_AES = 0x03
|
|
} DesfireCryptoAlgorithm;
|
|
|
|
#define DESFIRE_MAX_ALGO_COUNT 4 // T_DES ... T_AES
|
|
#define DESFIRE_MAX_KEY_COUNT 0x0E // key numbers 0x00 ... 0x0D
|
|
#define DESFIRE_MAX_APP_COUNT 64 // applications we keep track of per PICC
|
|
|
|
// Keys recovered for one application.
|
|
// keys[algo][keyno][0] is the found flag, keys[algo][keyno][1..] the key itself.
|
|
// `algo` is a DesfireCryptoAlgorithm, `keyno` the DESFire key number.
|
|
typedef struct {
|
|
uint32_t aid;
|
|
uint8_t keys[DESFIRE_MAX_ALGO_COUNT][DESFIRE_MAX_KEY_COUNT][DESFIRE_MAX_KEY_SIZE + 1];
|
|
} desfire_app_keys_t;
|
|
|
|
#endif
|