]> git.zerfleddert.de Git - proxmark3-svn/blame - include/usb_cmd.h
modify USB communications
[proxmark3-svn] / include / usb_cmd.h
CommitLineData
e30c654b 1//-----------------------------------------------------------------------------
e30c654b 2// Jonathan Westhues, Mar 2006
3// Edits by Gerhard de Koning Gans, Sep 2007
bd20f8f4 4//
5// This code is licensed to you under the terms of the GNU GPL, version 2 or,
6// at your option, any later version. See the LICENSE.txt file for the text of
7// the license.
8//-----------------------------------------------------------------------------
9// Definitions for all the types of commands that may be sent over USB; our
10// own protocol.
e30c654b 11//-----------------------------------------------------------------------------
12
72622d64 13#ifndef USB_CMD_H__
14#define USB_CMD_H__
15
e30c654b 16#ifdef _MSC_VER
17typedef DWORD uint32_t;
18typedef BYTE uint8_t;
19#define PACKED
e30c654b 20#else
21#include <stdint.h>
22#include <stdbool.h>
23#define PACKED __attribute__((packed))
24#endif
25
902cb3c0 26#define USB_CMD_DATA_SIZE 512
27
b8ed9975 28// the packets sent from client to PM3
902cb3c0 29typedef struct {
72622d64 30 uint64_t cmd;
31 uint64_t arg[3];
32 union {
33 uint8_t asBytes[USB_CMD_DATA_SIZE];
34 uint32_t asDwords[USB_CMD_DATA_SIZE/4];
35 } d;
e30c654b 36} PACKED UsbCommand;
a9104f7e 37
b8ed9975 38// the packets sent from PM3 to client (a smaller version of UsbCommand)
39typedef struct {
40 uint16_t cmd;
41 uint16_t datalen;
42 uint32_t arg[3];
43 union {
44 uint8_t asBytes[USB_CMD_DATA_SIZE];
45 uint32_t asDwords[USB_CMD_DATA_SIZE/4];
46 } d;
47} PACKED UsbResponse;
72622d64 48
31abe49f 49// A struct used to send sample-configs over USB
72622d64 50typedef struct {
31abe49f
MHS
51 uint8_t decimation;
52 uint8_t bits_per_sample;
53 bool averaging;
54 int divisor;
55 int trigger_threshold;
2de26056 56 int samples_to_skip;
31abe49f 57} sample_config;
e30c654b 58
72622d64 59
e30c654b 60// For the bootloader
3ebf4b3d 61#define CMD_DEVICE_INFO 0x0000
62#define CMD_SETUP_WRITE 0x0001
63#define CMD_FINISH_WRITE 0x0003
64#define CMD_HARDWARE_RESET 0x0004
65#define CMD_START_FLASH 0x0005
66#define CMD_NACK 0x00fe
67#define CMD_ACK 0x00ff
e30c654b 68
69// For general mucking around
3ebf4b3d 70#define CMD_DEBUG_PRINT_STRING 0x0100
71#define CMD_DEBUG_PRINT_INTEGERS 0x0101
72#define CMD_DEBUG_PRINT_BYTES 0x0102
73#define CMD_LCD_RESET 0x0103
74#define CMD_LCD 0x0104
75#define CMD_BUFF_CLEAR 0x0105
76#define CMD_READ_MEM 0x0106
77#define CMD_VERSION 0x0107
43591e64 78#define CMD_STATUS 0x0108
79#define CMD_PING 0x0109
80
a9104f7e 81// controlling the ADC input multiplexer
82#define CMD_SET_ADC_MUX 0x020F
83
43591e64 84// RDV40, Smart card operations
85#define CMD_SMART_RAW 0x0140
86#define CMD_SMART_UPGRADE 0x0141
87#define CMD_SMART_UPLOAD 0x0142
88#define CMD_SMART_ATR 0x0143
89// CMD_SMART_SETBAUD is unused for now
90#define CMD_SMART_SETBAUD 0x0144
91#define CMD_SMART_SETCLOCK 0x0145
e30c654b 92
93// For low-frequency tags
3ebf4b3d 94#define CMD_READ_TI_TYPE 0x0202
95#define CMD_WRITE_TI_TYPE 0x0203
96#define CMD_DOWNLOADED_RAW_BITS_TI_TYPE 0x0204
97#define CMD_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0205
98#define CMD_MOD_THEN_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0206
99#define CMD_DOWNLOAD_RAW_ADC_SAMPLES_125K 0x0207
100#define CMD_DOWNLOADED_RAW_ADC_SAMPLES_125K 0x0208
101#define CMD_DOWNLOADED_SIM_SAMPLES_125K 0x0209
102#define CMD_SIMULATE_TAG_125K 0x020A
103#define CMD_HID_DEMOD_FSK 0x020B
104#define CMD_HID_SIM_TAG 0x020C
105#define CMD_SET_LF_DIVISOR 0x020D
106#define CMD_LF_SIMULATE_BIDIR 0x020E
3ebf4b3d 107#define CMD_HID_CLONE_TAG 0x0210
108#define CMD_EM410X_WRITE_TAG 0x0211
109#define CMD_INDALA_CLONE_TAG 0x0212
110// for 224 bits UID
111#define CMD_INDALA_CLONE_TAG_L 0x0213
54a942b0 112#define CMD_T55XX_READ_BLOCK 0x0214
113#define CMD_T55XX_WRITE_BLOCK 0x0215
66837a03 114#define CMD_T55XX_RESET_READ 0x0216
54a942b0 115#define CMD_PCF7931_READ 0x0217
dc4300ba 116#define CMD_PCF7931_WRITE 0x0222
786ad91c 117#define CMD_PCF7931_BRUTEFORCE 0x0227
54a942b0 118#define CMD_EM4X_READ_WORD 0x0218
119#define CMD_EM4X_WRITE_WORD 0x0219
a1f3bb12 120#define CMD_IO_DEMOD_FSK 0x021A
121#define CMD_IO_CLONE_TAG 0x021B
abd6112f 122#define CMD_EM410X_DEMOD 0x021c
31abe49f
MHS
123// Sampling configuration for LF reader/snooper
124#define CMD_SET_LF_SAMPLING_CONFIG 0x021d
abd6112f 125#define CMD_FSK_SIM_TAG 0x021E
126#define CMD_ASK_SIM_TAG 0x021F
872e3d4d 127#define CMD_PSK_SIM_TAG 0x0220
dbf6e824 128#define CMD_AWID_DEMOD_FSK 0x0221
709665b5 129#define CMD_VIKING_CLONE_TAG 0x0223
be2d41b7 130#define CMD_T55XX_WAKEUP 0x0224
e04475c4 131#define CMD_COTAG 0x0225
5f84531b 132#define CMD_PARADOX_CLONE_TAG 0x0226
2de26056 133#define CMD_EM4X_PROTECT 0x0228
66707a3b 134
e30c654b 135// For the 13.56 MHz tags
3ebf4b3d 136#define CMD_ACQUIRE_RAW_ADC_SAMPLES_ISO_15693 0x0300
3ebf4b3d 137#define CMD_READ_SRI512_TAG 0x0303
138#define CMD_READ_SRIX4K_TAG 0x0304
7cf3ef20 139#define CMD_ISO_14443B_COMMAND 0x0305
3ebf4b3d 140#define CMD_READER_ISO_15693 0x0310
141#define CMD_SIMTAG_ISO_15693 0x0311
d9de20fa 142#define CMD_SNOOP_ISO_15693 0x0312
3ebf4b3d 143#define CMD_ISO_15693_COMMAND 0x0313
144#define CMD_ISO_15693_COMMAND_DONE 0x0314
145#define CMD_ISO_15693_FIND_AFI 0x0315
146#define CMD_ISO_15693_DEBUG 0x0316
b014c96d 147#define CMD_LF_SNOOP_RAW_ADC_SAMPLES 0x0317
096dee17 148#define CMD_CSETUID_ISO_15693 0x0318
d19929cb 149
150// For Hitag2 transponders
151#define CMD_SNOOP_HITAG 0x0370
152#define CMD_SIMULATE_HITAG 0x0371
153#define CMD_READER_HITAG 0x0372
4e12287d 154#define CMD_SIMULATE_HITAG_S 0x0368
43591e64 155#define CMD_TEST_HITAGS_TRACES 0x0367
156#define CMD_READ_HITAG_S 0x0373
7b6e3205 157#define CMD_READ_HITAG_S_BLK 0x0374
43591e64 158#define CMD_WR_HITAG_S 0x0375
159#define CMD_EMU_HITAG_S 0x0376
4e12287d 160
132a0217 161#define CMD_SIMULATE_TAG_ISO_14443B 0x0381
162#define CMD_SNOOP_ISO_14443B 0x0382
3ebf4b3d 163#define CMD_SNOOP_ISO_14443a 0x0383
164#define CMD_SIMULATE_TAG_ISO_14443a 0x0384
165#define CMD_READER_ISO_14443a 0x0385
166#define CMD_SIMULATE_TAG_LEGIC_RF 0x0387
167#define CMD_READER_LEGIC_RF 0x0388
168#define CMD_WRITER_LEGIC_RF 0x0389
5acd09bd 169#define CMD_EPA_PACE_COLLECT_NONCE 0x038A
3bb07d96 170#define CMD_EPA_PACE_REPLAY 0x038B
3ebf4b3d 171
aa53efc3 172#define CMD_ICLASS_CLONE 0x0390
173#define CMD_ICLASS_DUMP 0x0391
3ebf4b3d 174#define CMD_SNOOP_ICLASS 0x0392
175#define CMD_SIMULATE_TAG_ICLASS 0x0393
176#define CMD_READER_ICLASS 0x0394
aa53efc3 177#define CMD_ICLASS_READBLOCK 0x0396
178#define CMD_ICLASS_WRITEBLOCK 0x0397
7781a656 179#define CMD_ICLASS_EML_MEMSET 0x0398
ece38ef3 180#define CMD_ICLASS_CHECK 0x0399
72622d64 181#define CMD_ICLASS_READCHECK 0x039A
e30c654b 182
183// For measurements of the antenna tuning
3ebf4b3d 184#define CMD_MEASURE_ANTENNA_TUNING 0x0400
185#define CMD_MEASURE_ANTENNA_TUNING_HF 0x0401
186#define CMD_MEASURED_ANTENNA_TUNING 0x0410
187#define CMD_LISTEN_READER_FIELD 0x0420
e30c654b 188
189// For direct FPGA control
3ebf4b3d 190#define CMD_FPGA_MAJOR_MODE_OFF 0x0500
9ca155ba
M
191
192// For mifare commands
3ebf4b3d 193#define CMD_MIFARE_SET_DBGMODE 0x0600
194#define CMD_MIFARE_EML_MEMCLR 0x0601
195#define CMD_MIFARE_EML_MEMSET 0x0602
196#define CMD_MIFARE_EML_MEMGET 0x0603
197#define CMD_MIFARE_EML_CARDLOAD 0x0604
3fe4ff4f 198
199// magic chinese card commands
200#define CMD_MIFARE_CSETBLOCK 0x0605
201#define CMD_MIFARE_CGETBLOCK 0x0606
202#define CMD_MIFARE_CIDENT 0x0607
3a05a1e7 203#define CMD_MIFARE_CWIPE 0x0608
9ca155ba 204
3ebf4b3d 205#define CMD_SIMULATE_MIFARE_CARD 0x0610
9ca155ba 206
3ebf4b3d 207#define CMD_READER_MIFARE 0x0611
208#define CMD_MIFARE_NESTED 0x0612
c48c4d78 209#define CMD_MIFARE_ACQUIRE_ENCRYPTED_NONCES 0x0613
9ca155ba 210
3ebf4b3d 211#define CMD_MIFARE_READBL 0x0620
212#define CMD_MIFARE_READSC 0x0621
213#define CMD_MIFARE_WRITEBL 0x0622
214#define CMD_MIFARE_CHKKEYS 0x0623
0b4efbde 215#define CMD_MIFARE_PERSONALIZE_UID 0x0624
3ebf4b3d 216#define CMD_MIFARE_SNIFFER 0x0630
0b4efbde 217
3fe4ff4f 218//ultralightC
0b4efbde 219#define CMD_MIFAREU_READBL 0x0720
220#define CMD_MIFAREU_READCARD 0x0721
221#define CMD_MIFAREU_WRITEBL 0x0722
222#define CMD_MIFAREU_WRITEBL_COMPAT 0x0723
9d87eb66 223#define CMD_MIFAREUC_AUTH 0x0724
72622d64 224//0x0725 and 0x0726 no longer used
f168b263 225#define CMD_MIFAREUC_SETPWD 0x0727
226
3fe4ff4f 227
228// mifare desfire
229#define CMD_MIFARE_DESFIRE_READBL 0x0728
230#define CMD_MIFARE_DESFIRE_WRITEBL 0x0729
231#define CMD_MIFARE_DESFIRE_AUTH1 0x072a
232#define CMD_MIFARE_DESFIRE_AUTH2 0x072b
233#define CMD_MIFARE_DES_READER 0x072c
234#define CMD_MIFARE_DESFIRE_INFO 0x072d
235#define CMD_MIFARE_DESFIRE 0x072e
b62a5a84 236
0472d76d 237#define CMD_HF_SNIFFER 0x0800
fc52fbd4 238#define CMD_HF_PLOT 0x0801
0472d76d 239
b8ed9975 240#define CMD_VARIABLE_SIZE_FLAG 0x8000
3ebf4b3d 241#define CMD_UNKNOWN 0xFFFF
3851172d 242
d2f487af 243
0ab9002f 244// Mifare simulation flags
72622d64 245#define FLAG_INTERACTIVE (1<<0)
246#define FLAG_4B_UID_IN_DATA (1<<1)
247#define FLAG_7B_UID_IN_DATA (1<<2)
248#define FLAG_NR_AR_ATTACK (1<<4)
249#define FLAG_RANDOM_NONCE (1<<5)
d2f487af 250
251
0ab9002f 252// iCLASS reader flags
496bb4be 253#define FLAG_ICLASS_READER_INIT (1<<0)
254#define FLAG_ICLASS_READER_CC (1<<1)
255#define FLAG_ICLASS_READER_CSN (1<<2)
256#define FLAG_ICLASS_READER_CONF (1<<3)
257#define FLAG_ICLASS_READER_AA (1<<4)
258#define FLAG_ICLASS_READER_CREDITKEY (1<<5)
259#define FLAG_ICLASS_READER_CLEARTRACE (1<<6)
260
caaf9618 261
0ab9002f 262// iCLASS simulation modes
263#define ICLASS_SIM_MODE_CSN 0
264#define ICLASS_SIM_MODE_CSN_DEFAULT 1
265#define ICLASS_SIM_MODE_READER_ATTACK 2
266#define ICLASS_SIM_MODE_FULL 3
267#define ICLASS_SIM_MODE_READER_ATTACK_KEYROLL 4
268#define ICLASS_SIM_MODE_EXIT_AFTER_MAC 5 // note: device internal only
d2f487af 269
0ab9002f 270
271// hw tune args
fdcfbdcc
RAB
272#define FLAG_TUNE_LF 1
273#define FLAG_TUNE_HF 2
274#define FLAG_TUNE_ALL 3
275
a9104f7e 276// Hardware capabilities
277#define HAS_EXTRA_FLASH_MEM (1 << 0)
278#define HAS_SMARTCARD_SLOT (1 << 1)
279
31abe49f 280
e30c654b 281// CMD_DEVICE_INFO response packet has flags in arg[0], flag definitions:
282/* Whether a bootloader that understands the common_area is present */
72622d64 283#define DEVICE_INFO_FLAG_BOOTROM_PRESENT (1<<0)
e30c654b 284
285/* Whether a osimage that understands the common_area is present */
72622d64 286#define DEVICE_INFO_FLAG_OSIMAGE_PRESENT (1<<1)
e30c654b 287
288/* Set if the bootloader is currently executing */
72622d64 289#define DEVICE_INFO_FLAG_CURRENT_MODE_BOOTROM (1<<2)
e30c654b 290
291/* Set if the OS is currently executing */
72622d64 292#define DEVICE_INFO_FLAG_CURRENT_MODE_OS (1<<3)
e30c654b 293
294/* Set if this device understands the extend start flash command */
72622d64 295#define DEVICE_INFO_FLAG_UNDERSTANDS_START_FLASH (1<<4)
e30c654b 296
297/* CMD_START_FLASH may have three arguments: start of area to flash,
298 end of area to flash, optional magic.
299 The bootrom will not allow to overwrite itself unless this magic
300 is given as third parameter */
301
302#define START_FLASH_MAGIC 0x54494f44 // 'DOIT'
303
304#endif
Impressum, Datenschutz