]> git.zerfleddert.de Git - proxmark3-svn/blobdiff - winsrc/command.cpp
Add checks in em4x50read to avoid segfaults in case loops go over the GraphTraceLen.
[proxmark3-svn] / winsrc / command.cpp
index 4ac807d969e17f5baa5a2d6a3aa76c36c3e51f0d..454fbab2417b1ddff306eb647fee98ce602ce862 100644 (file)
@@ -301,17 +301,19 @@ static void CmdEM4x50read(char *str)
        while(i < GraphTraceLen)\r
                {\r
                // measure from low to low\r
-               while(GraphBuffer[i] > low)\r
+               while((GraphBuffer[i] > low) && (i<GraphTraceLen))\r
                        ++i;\r
                start= i;\r
-               while(GraphBuffer[i] < high)\r
+               while((GraphBuffer[i] < high) && (i<GraphTraceLen))\r
                        ++i;\r
-               while(GraphBuffer[i] > low)\r
+               while((GraphBuffer[i] > low) && (i<GraphTraceLen))\r
                        ++i;\r
+               if (j>(MAX_GRAPH_TRACE_LEN/64)) {\r
+                       break;\r
+               }\r
                tmpbuff[j++]= i - start;\r
                }\r
 \r
-\r
        /* look for data start - should be 2 pairs of LW (pulses of 192,128) */\r
        start= -1;\r
        skip= 0;\r
@@ -331,7 +333,7 @@ static void CmdEM4x50read(char *str)
 \r
        /* skip over the remainder of the LW */\r
        skip += tmpbuff[i+1]+tmpbuff[i+2];\r
-       while(GraphBuffer[skip] > low)\r
+       while(skip < MAX_GRAPH_TRACE_LEN && GraphBuffer[skip] > low)\r
                ++skip;\r
        skip += 8;\r
 \r
@@ -1395,14 +1397,14 @@ static void CmdHi15demod(char *str)
        PrintToScrollback("CRC=%04x", Iso15693Crc(outBuf, k-2));\r
 }\r
 \r
-static void CmdTiread(char *str)\r
+static void CmdTIReadRaw(char *str)\r
 {\r
        UsbCommand c;\r
        c.cmd = CMD_ACQUIRE_RAW_BITS_TI_TYPE;\r
        SendCommand(&c, FALSE);\r
 }\r
 \r
-static void CmdTibits(char *str)\r
+static void CmdTIBits(char *str)\r
 {\r
        int cnt = 0;\r
        int i;\r
@@ -1554,7 +1556,30 @@ static void CmdFSKdemod(char *cmdline)
        PrintToScrollback("hex: %08x %08x", hi, lo);\r
 }\r
 \r
-static void CmdTidemod(char *cmdline)\r
+// read a TI tag and return its ID\r
+static void CmdTIRead(char *str)\r
+{\r
+       UsbCommand c;\r
+       c.cmd = CMD_READ_TI_TYPE;\r
+       SendCommand(&c, FALSE);\r
+}\r
+\r
+// write new data to a r/w TI tag\r
+static void CmdTIWrite(char *str)\r
+{\r
+       UsbCommand c;\r
+       int res=0;\r
+\r
+       c.cmd = CMD_WRITE_TI_TYPE;\r
+       res = sscanf(str, "0x%x 0x%x 0x%x ", &c.ext1, &c.ext2, &c.ext3);\r
+       if (res == 2) c.ext3=0;\r
+       if (res<2)\r
+               PrintToScrollback("Please specify 2 or three hex strings, eg 0x1234 0x5678");\r
+       else\r
+               SendCommand(&c, FALSE);\r
+}\r
+\r
+static void CmdTIDemod(char *cmdline)\r
 {\r
        /* MATLAB as follows:\r
 f_s = 2000000;  % sampling frequency\r
@@ -1754,9 +1779,13 @@ h = sign(sin(cumsum(h)));
                // align 16 bit "end bits" or "ident" into lower half of shift3\r
          shift3 >>= 16;\r
 \r
-               if ( (shift3^shift0)&0xffff ) {\r
+               // only 15 bits compare, last bit of ident is not valid\r
+               if ( (shift3^shift0)&0x7fff ) {\r
                        PrintToScrollback("Error: Ident mismatch!");\r
                }\r
+               // WARNING the order of the bytes in which we calc crc below needs checking\r
+               // i'm 99% sure the crc algorithm is correct, but it may need to eat the\r
+               // bytes in reverse or something\r
                // calculate CRC\r
                crc=0;\r
                crc = update_crc16(crc, (shift0)&0xff);\r
@@ -2841,9 +2870,11 @@ static struct {
        {"scale",                                       CmdScale,                                               1, "<int> -- Set cursor display scale"},\r
        {"setlfdivisor",        CmdSetDivisor,                  0, "<19 - 255> -- Drive LF antenna at 12Mhz/(divisor+1)"},\r
        {"sri512read",          CmdSri512read,                  0, "<int> -- Read contents of a SRI512 tag"},\r
-       {"tibits",                              CmdTibits,                                      0, "Get raw bits for TI-type LF tag"},\r
-       {"tidemod",                             CmdTidemod,                                     1, "Demodulate raw bits for TI-type LF tag"},\r
-       {"tiread",                              CmdTiread,                                      0, "Read a TI-type 134 kHz tag"},\r
+       {"tibits",                              CmdTIBits,                                      0, "Get raw bits for TI-type LF tag"},\r
+       {"tidemod",                             CmdTIDemod,                                     1, "Demodulate raw bits for TI-type LF tag"},\r
+       {"tireadraw",                   CmdTIReadRaw,                           0, "Read a TI-type 134 kHz tag in raw mode"},\r
+       {"tiread",                              CmdTIRead,                                      0, "Read and decode a TI 134 kHz tag"},\r
+       {"tiwrite",                             CmdTIWrite,                                     0, "Write new data to a r/w TI 134 kHz tag"},\r
        {"threshold",                   CmdThreshold,                           1, "Maximize/minimize every value in the graph window depending on threshold"},\r
        {"tune",                                        CmdTune,                                                0, "Measure antenna tuning"},\r
        {"vchdemod",                    CmdVchdemod,                            0, "['clone'] -- Demodulate samples for VeriChip"},\r
Impressum, Datenschutz