mirror of
https://github.com/DarkFlippers/unleashed-firmware.git
synced 2026-08-29 09:58:38 +00:00
* NFC: do not probe the default password when AUTHLIM is unreadable try_default_pass reads access.authlim straight out of the in-memory card image and probes the default password when it is zero. On a card with PROT=1 and AUTH0 low enough to cover the ACCESS page, that page is never returned by the card, so it is still the zero fill from malloc - and zero decodes as "no authentication limit". The result is a PWD_AUTH with the default password on every plain read of exactly the cards that count failed attempts. Per the MF0ULX1 data sheet each negative verification is counted, and once the counter reaches AUTHLIM the next one permanently locks the protected memory, at which point every PWD_AUTH fails regardless of the password. Gate the probe on the ACCESS page having actually been read. AUTHLIM unknown now means "assume protected" instead of "assume unlimited". Cards with PROT=0 keep default-password detection, since their config pages stay readable; the ones that lose it are the ones where probing was unsafe. Write mode is exempt. The app deliberately skips the read-phase auth when writing to a target, so for password-protected types this probe is the only thing that can set auth_success - gating it there would turn a working write into "Card locked" for any target still carrying the factory password. That path is user-initiated, unlike a plain read. Also take the return of mf_ultralight_get_config_page() instead of dropping it - it only fails for types with no config page, which the feature check above already excludes, but the next line dereferences the pointer it would have left NULL. Fixes #1087 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * changelog: default password not tried when AUTHLIM is unreadable Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>