Files
Mykhailo ShevchukandClaude Opus 5 c02616a351 [NFC]: don't probe the default password when AUTHLIM cannot be read (#1089)
* NFC: do not probe the default password when AUTHLIM is unreadable

try_default_pass reads access.authlim straight out of the in-memory card
image and probes the default password when it is zero. On a card with
PROT=1 and AUTH0 low enough to cover the ACCESS page, that page is never
returned by the card, so it is still the zero fill from malloc - and
zero decodes as "no authentication limit".

The result is a PWD_AUTH with the default password on every plain read
of exactly the cards that count failed attempts. Per the MF0ULX1 data
sheet each negative verification is counted, and once the counter
reaches AUTHLIM the next one permanently locks the protected memory, at
which point every PWD_AUTH fails regardless of the password.

Gate the probe on the ACCESS page having actually been read. AUTHLIM
unknown now means "assume protected" instead of "assume unlimited".
Cards with PROT=0 keep default-password detection, since their config
pages stay readable; the ones that lose it are the ones where probing
was unsafe.

Write mode is exempt. The app deliberately skips the read-phase auth
when writing to a target, so for password-protected types this probe is
the only thing that can set auth_success - gating it there would turn a
working write into "Card locked" for any target still carrying the
factory password. That path is user-initiated, unlike a plain read.

Also take the return of mf_ultralight_get_config_page() instead of
dropping it - it only fails for types with no config page, which the
feature check above already excludes, but the next line dereferences the
pointer it would have left NULL.

Fixes #1087

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* changelog: default password not tried when AUTHLIM is unreadable

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-21 00:12:27 +03:00
..
2026-01-05 22:26:28 +03:00
2025-09-24 21:00:39 +04:00
2024-07-15 20:02:45 +03:00
2026-08-11 02:42:32 +03:00
2026-01-11 09:30:28 +03:00
2026-01-11 09:30:28 +03:00

Structure

  • app-scened-template - C++ app library
  • bit_lib - library for working with bits/bytes directly
  • ble_profile - BLE Profiles source code
  • cmsis_core - CMSIS Core package, contain cortex-m core headers
  • cxxheaderparser - C++ headers parser, used by SDK bundler
  • datetime - DateTime library
  • digital_signal - Digital signal library: used by NFC for software implemented protocols
  • drivers - Various flipper drivers
  • fatfs - FatFS file system driver
  • flipper_application - Flipper application library, used for FAPs
  • flipper_format - Flipper File Format library
  • FreeRTOS-glue - Extra glue to hold together FreeRTOS kernel and flipper firmware
  • FreeRTOS-Kernel - FreeRTOS kernel source code
  • heatshrink - Heatshrink compression library
  • ibutton - ibutton library, used by iButton application
  • infrared - Infrared library, used by Infrared application
  • lfrfid - LF-RFID library, used by LF RFID application
  • libusb_stm32 - LibUSB for STM32 series MCU
  • mbedtls - MbedTLS cryptography library
  • microtar - MicroTAR library
  • mjs - MJs, javascript engine library
  • mlib - M-Lib C containers library
  • music_worker - MusicWorker library for playing midi and RTTTL files
  • nanopb - NanoPB library, protobuf implementation for MCU
  • nfc - NFC library, used by NFC application
  • one_wire - OneWire library, used by iButton application
  • print - Tiny printf implementation
  • digital_signal - Digital Signal library used by NFC for software implemented protocols
  • pulse_reader - Pulse Reader library used by NFC for software implemented protocols
  • stm32wb_cmsis - STM32WB series CMSIS headers, extends CMSIS Core
  • stm32wb_copro - STM32WB Copro library: contains WPAN and radio co-processor firmware
  • stm32wb_hal - STM32WB HAL library, extends STM32WB CMSIS and provides HAL
  • subghz - Subghz library, used by SubGhz application
  • toolbox - Toolbox library, contains various things that is used by Flipper firmware
  • u8g2 - u8g2 graphics library, used by GUI subsystem
  • update_util - update utilities library, used by updater