]> git.zerfleddert.de Git - proxmark3-svn/blobdiff - client/mifarehost.c
another "magic card" backdoor - command "read block". Added several commands to manip...
[proxmark3-svn] / client / mifarehost.c
index c6f2fe3fa248a7ebded551448addb14d975b2d74..ef70fe9770ddba86a69ea87659e298179ba37328 100644 (file)
@@ -10,6 +10,7 @@
 \r
 #include <stdio.h>\r
 #include <stdlib.h> \r
+#include <string.h>\r
 #include "mifarehost.h"\r
 \r
 \r
@@ -195,3 +196,70 @@ int mfCheckKeys (uint8_t blockNo, uint8_t keyType, uint8_t keycnt, uint8_t * key
        *key = bytes_to_num(resp->d.asBytes, 6);\r
        return 0;\r
 }\r
+\r
+int mfEmlGetMem(uint8_t *data, int blockNum, int blocksCount) {\r
+       UsbCommand c = {CMD_MIFARE_EML_MEMGET, {blockNum, blocksCount, 0}};\r
\r
+       SendCommand(&c);\r
+\r
+       UsbCommand * resp = WaitForResponseTimeout(CMD_ACK, 1500);\r
+\r
+       if (resp == NULL) return 1;\r
+       memcpy(data, resp->d.asBytes, blocksCount * 16); \r
+       return 0;\r
+}\r
+\r
+int mfEmlSetMem(uint8_t *data, int blockNum, int blocksCount) {\r
+       UsbCommand c = {CMD_MIFARE_EML_MEMSET, {blockNum, blocksCount, 0}};\r
+       memcpy(c.d.asBytes, data, blocksCount * 16); \r
+       SendCommand(&c);\r
+       return 0;\r
+}\r
+\r
+int mfCSetUID(uint8_t *uid, uint8_t *oldUID, int wantWipe) {\r
+       uint8_t block0[16];\r
+       memset(block0, 0, 16);\r
+       memcpy(block0, uid, 4); \r
+       block0[4] = block0[0]^block0[1]^block0[2]^block0[3]; // Mifare UID BCC\r
+       \r
+       return mfCSetBlock(0, block0, oldUID, wantWipe, CSETBLOCK_SINGLE_OPER);\r
+}\r
+\r
+int mfCSetBlock(uint8_t blockNo, uint8_t *data, uint8_t *uid, int wantWipe, uint8_t params) {\r
+       uint8_t isOK = 0;\r
+\r
+       UsbCommand c = {CMD_MIFARE_EML_CSETBLOCK, {wantWipe, params & (0xFE | (uid == NULL ? 0:1)), blockNo}};\r
+       memcpy(c.d.asBytes, data, 16); \r
+       SendCommand(&c);\r
+\r
+       UsbCommand * resp = WaitForResponseTimeout(CMD_ACK, 1500);\r
+\r
+       if (resp != NULL) {\r
+               isOK  = resp->arg[0] & 0xff;\r
+               if (uid != NULL) memcpy(uid, resp->d.asBytes, 4); \r
+               if (!isOK) return 2;\r
+       } else {\r
+               PrintAndLog("Command execute timeout");\r
+               return 1;\r
+       }\r
+       return 0;\r
+}\r
+\r
+int mfCGetBlock(uint8_t blockNo, uint8_t *data, uint8_t params) {\r
+       uint8_t isOK = 0;\r
+\r
+       UsbCommand c = {CMD_MIFARE_EML_CGETBLOCK, {params, 0, blockNo}};\r
+       SendCommand(&c);\r
+\r
+       UsbCommand * resp = WaitForResponseTimeout(CMD_ACK, 1500);\r
+\r
+       if (resp != NULL) {\r
+               isOK  = resp->arg[0] & 0xff;\r
+               memcpy(data, resp->d.asBytes, 16); \r
+               if (!isOK) return 2;\r
+       } else {\r
+               PrintAndLog("Command execute timeout");\r
+               return 1;\r
+       }\r
+       return 0;\r
+}\r
Impressum, Datenschutz