]> git.zerfleddert.de Git - proxmark3-svn/blob - client/cmdlfnoralsy.c
added EMV tag #9F6E (#676)
[proxmark3-svn] / client / cmdlfnoralsy.c
1 //-----------------------------------------------------------------------------
2 //
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
5 // the license.
6 //-----------------------------------------------------------------------------
7 // Low frequency Noralsy tag commands
8 // ASK/Manchester, STT, RF/32, 96 bits long (some bits unknown)
9 //-----------------------------------------------------------------------------
10
11 #include "cmdlfnoralsy.h"
12
13 #include <string.h>
14 #include <inttypes.h>
15 #include <math.h>
16 #include "comms.h"
17 #include "ui.h"
18 #include "util.h"
19 #include "graph.h"
20 #include "cmdparser.h"
21 #include "cmddata.h"
22 #include "cmdmain.h"
23 #include "cmdlf.h"
24 #include "protocols.h" // for T55xx config register definitions
25 #include "lfdemod.h" // parityTest
26
27 static int CmdHelp(const char *Cmd);
28
29 int usage_lf_noralsy_clone(void){
30 PrintAndLog("clone a Noralsy tag to a T55x7 tag.");
31 PrintAndLog("Usage: lf noralsy clone [h] <card id> <year> <Q5>");
32 PrintAndLog("Options:");
33 PrintAndLog(" h : This help");
34 PrintAndLog(" <card id> : Noralsy card ID");
35 PrintAndLog(" <year> : Tag allocation year");
36 PrintAndLog(" <Q5> : specify write to Q5 (t5555 instead of t55x7)");
37 PrintAndLog("");
38 PrintAndLog("Sample: lf noralsy clone 112233");
39 return 0;
40 }
41
42 int usage_lf_noralsy_sim(void) {
43 PrintAndLog("Enables simulation of Noralsy card with specified card number.");
44 PrintAndLog("Simulation runs until the button is pressed or another USB command is issued.");
45 PrintAndLog("");
46 PrintAndLog("Usage: lf noralsy sim [h] <card id> <year>");
47 PrintAndLog("Options:");
48 PrintAndLog(" h : This help");
49 PrintAndLog(" <card id> : Noralsy card ID");
50 PrintAndLog(" <year> : Tag allocation year");
51 PrintAndLog("");
52 PrintAndLog("Sample: lf noralsy sim 112233");
53 return 0;
54 }
55
56 static uint8_t noralsy_chksum( uint8_t* bits, uint8_t len) {
57 uint8_t sum = 0;
58 for (uint8_t i = 0; i < len; i += 4)
59 sum ^= bytebits_to_byte(bits+i, 4);
60 return sum & 0x0F ;
61 }
62 int getnoralsyBits(uint32_t id, uint16_t year, uint8_t *bits) {
63 //preamp
64 num_to_bytebits(0xBB0214FF, 32, bits); // --> Have seen 0xBB0214FF / 0xBB0314FF UNKNOWN
65
66 year &= 0xFF;
67
68 uint16_t sub1 = (id & 0xFFF0000) >> 16;
69 uint8_t sub2 = (id & 0x000FF00) >> 8;
70 uint8_t sub3 = (id & 0x00000FF);
71
72 num_to_bytebits(sub1, 12, bits+32);
73 num_to_bytebits(year, 8, bits+44);
74 num_to_bytebits(0, 4, bits+52); // --> UNKNOWN. Flag?
75
76 num_to_bytebits(sub2, 8, bits+56);
77 num_to_bytebits(sub3, 8, bits+64);
78
79 //chksum byte
80 uint8_t chksum = noralsy_chksum(bits+32, 40);
81 num_to_bytebits(chksum, 4, bits+72);
82 chksum = noralsy_chksum(bits, 76);
83 num_to_bytebits(chksum, 4, bits+76);
84 return 1;
85 }
86
87 // by iceman
88 // find Noralsy preamble in already demoded data
89 int NoralsyDemod_AM(uint8_t *dest, size_t *size) {
90 if (*size < 96) return -1; //make sure buffer has data
91 size_t startIdx = 0;
92 uint8_t preamble[] = {1,0,1,1,1,0,1,1,0,0,0,0};
93 if (!preambleSearch(dest, preamble, sizeof(preamble), size, &startIdx))
94 return -2; //preamble not found
95 if (*size != 96) return -3; //wrong demoded size
96 //return start position
97 return (int)startIdx;
98 }
99
100 /*
101 *
102 * 2520116 | BB0214FF2529900116360000 | 10111011 00000011 00010100 11111111 00100101 00101001 10010000 00000001 00010110 00110110 00000000 00000000
103 * aaa*aaaaiiiYY*iiiicc---- **** iiiiiiii iiiiYYYY YYYY**** iiiiiiii iiiiiiii cccccccc
104 *
105 * a = fixed value BB0*14FF
106 * i = printed id, BCD-format
107 * Y = year
108 * c = checksum
109 * * = unknown
110 *
111 **/
112
113 //see ASKDemod for what args are accepted
114 int CmdNoralsyDemod(const char *Cmd) {
115
116 //ASK / Manchester
117 bool st = true;
118 if (!ASKDemod_ext("32 0 0", false, false, 1, &st)) {
119 if (g_debugMode) PrintAndLog("DEBUG: Error - Noralsy: ASK/Manchester Demod failed");
120 return 0;
121 }
122 if (!st) return 0;
123
124 size_t size = DemodBufferLen;
125 int ans = NoralsyDemod_AM(DemodBuffer, &size);
126 if (ans < 0){
127 if (g_debugMode){
128 if (ans == -1)
129 PrintAndLog("DEBUG: Error - Noralsy: too few bits found");
130 else if (ans == -2)
131 PrintAndLog("DEBUG: Error - Noralsy: preamble not found");
132 else if (ans == -3)
133 PrintAndLog("DEBUG: Error - Noralsy: Size not correct: %d", size);
134 else
135 PrintAndLog("DEBUG: Error - Noralsy: ans: %d", ans);
136 }
137 return 0;
138 }
139 setDemodBuf(DemodBuffer, 96, ans);
140 setClockGrid(g_DemodClock, g_DemodStartIdx + (ans*g_DemodClock));
141 //setGrid_Clock(32);
142
143 //got a good demod
144 uint32_t raw1 = bytebits_to_byte(DemodBuffer, 32);
145 uint32_t raw2 = bytebits_to_byte(DemodBuffer+32, 32);
146 uint32_t raw3 = bytebits_to_byte(DemodBuffer+64, 32);
147
148 uint32_t cardid = (bytebits_to_byte(DemodBuffer+32, 12)<<16) | bytebits_to_byte(DemodBuffer+32+24, 16);
149
150 uint16_t year = (raw2 & 0x000ff000) >> 12;
151 year += ( year > 0x60 ) ? 0x1900: 0x2000;
152
153 // calc checksums
154 uint8_t calc1 = noralsy_chksum(DemodBuffer+32, 40);
155 uint8_t calc2 = noralsy_chksum(DemodBuffer, 76);
156 uint8_t chk1 = 0, chk2 = 0;
157 chk1 = bytebits_to_byte(DemodBuffer+72, 4);
158 chk2 = bytebits_to_byte(DemodBuffer+76, 4);
159 // test checksums
160 if ( chk1 != calc1 ) {
161 if (g_debugMode) PrintAndLog("DEBUG: Error - Noralsy: checksum 1 failed %x - %x\n", chk1, calc1);
162 return 0;
163 }
164 if ( chk2 != calc2 ) {
165 if (g_debugMode) PrintAndLog("DEBUG: Error - Noralsy: checksum 2 failed %x - %x\n", chk2, calc2);
166 return 0;
167 }
168
169 PrintAndLog("Noralsy Tag Found: Card ID %X, Year: %X Raw: %08X%08X%08X", cardid, year, raw1 ,raw2, raw3);
170 if (raw1 != 0xBB0214FF) {
171 PrintAndLog("Unknown bits set in first block! Expected 0xBB0214FF, Found: 0x%08X", raw1);
172 PrintAndLog("Please post this output in forum to further research on this format");
173 }
174 return 1;
175 }
176
177 int CmdNoralsyRead(const char *Cmd) {
178 lf_read(true, 8000);
179 return CmdNoralsyDemod(Cmd);
180 }
181
182 int CmdNoralsyClone(const char *Cmd) {
183
184 uint16_t year = 0;
185 uint32_t id = 0;
186 uint32_t blocks[4] = {T55x7_MODULATION_MANCHESTER | T55x7_BITRATE_RF_32 | T55x7_ST_TERMINATOR | 3 << T55x7_MAXBLOCK_SHIFT, 0, 0};
187 uint8_t bits[96];
188 uint8_t *bs = bits;
189 memset(bs, 0, sizeof(bits));
190
191 char cmdp = param_getchar(Cmd, 0);
192 if (strlen(Cmd) == 0 || cmdp == 'h' || cmdp == 'H') return usage_lf_noralsy_clone();
193
194 id = param_get32ex(Cmd, 0, 0, 16);
195 year = param_get32ex(Cmd, 1, 2000, 16);
196
197 //Q5
198 if (param_getchar(Cmd, 2) == 'Q' || param_getchar(Cmd, 2) == 'q') {
199 //t5555 (Q5) BITRATE = (RF-2)/2 (iceman)
200 blocks[0] = T5555_MODULATION_MANCHESTER | ((32-2)>>1) << T5555_BITRATE_SHIFT | T5555_ST_TERMINATOR | 3 << T5555_MAXBLOCK_SHIFT;
201 }
202
203 if ( !getnoralsyBits(id, year, bs)) {
204 PrintAndLog("Error with tag bitstream generation.");
205 return 1;
206 }
207
208 //
209 blocks[1] = bytebits_to_byte(bs,32);
210 blocks[2] = bytebits_to_byte(bs+32,32);
211 blocks[3] = bytebits_to_byte(bs+64,32);
212
213 PrintAndLog("Preparing to clone Noralsy to T55x7 with CardId: %x", id);
214 PrintAndLog("Blk | Data ");
215 PrintAndLog("----+------------");
216 PrintAndLog(" 00 | 0x%08x", blocks[0]);
217 PrintAndLog(" 01 | 0x%08x", blocks[1]);
218 PrintAndLog(" 02 | 0x%08x", blocks[2]);
219 PrintAndLog(" 03 | 0x%08x", blocks[3]);
220
221 UsbCommand resp;
222 UsbCommand c = {CMD_T55XX_WRITE_BLOCK, {0,0,0}};
223
224 for (int i = 3; i >= 0; --i) {
225 c.arg[0] = blocks[i];
226 c.arg[1] = i;
227 clearCommandBuffer();
228 SendCommand(&c);
229 if (!WaitForResponseTimeout(CMD_ACK, &resp, T55XX_WRITE_TIMEOUT)){
230 PrintAndLog("Error occurred, device did not respond during write operation.");
231 return -1;
232 }
233 }
234 return 0;
235 }
236
237 int CmdNoralsySim(const char *Cmd) {
238
239 uint8_t bits[96];
240 uint8_t *bs = bits;
241 memset(bs, 0, sizeof(bits));
242
243 uint16_t year = 0;
244 uint32_t id = 0;
245
246 char cmdp = param_getchar(Cmd, 0);
247 if (strlen(Cmd) == 0 || cmdp == 'h' || cmdp == 'H') return usage_lf_noralsy_sim();
248
249 id = param_get32ex(Cmd, 0, 0, 16);
250 year = param_get32ex(Cmd, 1, 2000, 16);
251
252 uint8_t clk = 32, encoding = 1, separator = 1, invert = 0;
253 uint16_t arg1, arg2;
254 size_t size = 96;
255 arg1 = clk << 8 | encoding;
256 arg2 = invert << 8 | separator;
257
258 if ( !getnoralsyBits(id, year, bs)) {
259 PrintAndLog("Error with tag bitstream generation.");
260 return 1;
261 }
262
263 PrintAndLog("Simulating Noralsy - CardId: %x", id);
264
265 UsbCommand c = {CMD_ASK_SIM_TAG, {arg1, arg2, size}};
266 memcpy(c.d.asBytes, bs, size);
267 clearCommandBuffer();
268 SendCommand(&c);
269 return 0;
270 }
271
272 static command_t CommandTable[] = {
273 {"help", CmdHelp, 1, "This help"},
274 {"demod", CmdNoralsyDemod,1, "Attempt to read and extract tag data from the GraphBuffer"},
275 {"read", CmdNoralsyRead, 0, "Attempt to read and extract tag data from the antenna"},
276 {"clone", CmdNoralsyClone,0, "clone Noralsy tag"},
277 {"sim", CmdNoralsySim, 0, "simulate Noralsy tag"},
278 {NULL, NULL, 0, NULL}
279 };
280
281 int CmdLFNoralsy(const char *Cmd) {
282 clearCommandBuffer();
283 CmdsParse(CommandTable, Cmd);
284 return 0;
285 }
286
287 int CmdHelp(const char *Cmd) {
288 CmdsHelp(CommandTable);
289 return 0;
290 }
Impressum, Datenschutz