1 //-----------------------------------------------------------------------------
3 // This code is licensed to you under the terms of the GNU GPL, version 2 or,
4 // at your option, any later version. See the LICENSE.txt file for the text of
6 //-----------------------------------------------------------------------------
7 // Low frequency Noralsy tag commands
8 // ASK/Manchester, STT, RF/32, 96 bits long
9 //-----------------------------------------------------------------------------
10 #include "cmdlfnoralsy.h"
14 #include "proxmark3.h"
18 #include "cmdparser.h"
22 #include "protocols.h" // for T55xx config register definitions
23 #include "lfdemod.h" // parityTest
25 static int CmdHelp(const char *Cmd
);
27 int usage_lf_noralsy_clone(void){
28 PrintAndLog("clone a Noralsy tag to a T55x7 tag.");
29 PrintAndLog("Usage: lf noralsy clone [h] <card id> <year> <Q5>");
30 PrintAndLog("Options:");
31 PrintAndLog(" h : This help");
32 PrintAndLog(" <card id> : Noralsy card ID");
33 PrintAndLog(" <year> : Tag allocation year");
34 PrintAndLog(" <Q5> : specify write to Q5 (t5555 instead of t55x7)");
36 PrintAndLog("Sample: lf noralsy clone 112233");
40 int usage_lf_noralsy_sim(void) {
41 PrintAndLog("Enables simulation of Noralsy card with specified card number.");
42 PrintAndLog("Simulation runs until the button is pressed or another USB command is issued.");
44 PrintAndLog("Usage: lf noralsy sim [h] <card id> <year>");
45 PrintAndLog("Options:");
46 PrintAndLog(" h : This help");
47 PrintAndLog(" <card id> : Noralsy card ID");
48 PrintAndLog(" <year> : Tag allocation year");
50 PrintAndLog("Sample: lf noralsy sim 112233");
54 static uint8_t noralsy_chksum( uint8_t* bits
, uint8_t len
) {
56 for (uint8_t i
= 0; i
< len
; i
+= 4)
57 sum
^= bytebits_to_byte(bits
+i
, 4);
60 int getnoralsyBits(uint32_t id
, uint16_t year
, uint8_t *bits
) {
62 num_to_bytebits(0xBB0214FF, 32, bits
); // --> Have seen 0xBB0214FF / 0xBB0314FF UNKNOWN
66 uint16_t sub1
= (id
& 0xFFF0000) >> 16;
67 uint8_t sub2
= (id
& 0x000FF00) >> 8;
68 uint8_t sub3
= (id
& 0x00000FF);
70 num_to_bytebits(sub1
, 12, bits
+32);
71 num_to_bytebits(year
, 8, bits
+44);
72 num_to_bytebits(0, 4, bits
+52); // --> UNKNOWN. Flag?
74 num_to_bytebits(sub2
, 8, bits
+56);
75 num_to_bytebits(sub3
, 8, bits
+64);
78 uint8_t chksum
= noralsy_chksum(bits
+32, 40);
79 num_to_bytebits(chksum
, 4, bits
+72);
80 chksum
= noralsy_chksum(bits
, 76);
81 num_to_bytebits(chksum
, 4, bits
+76);
86 // find Noralsy preamble in already demoded data
87 int NoralsyDemod_AM(uint8_t *dest
, size_t *size
) {
88 if (*size
< 96) return -1; //make sure buffer has data
90 uint8_t preamble
[] = {1,0,1,1,1,0,1,1,0,0,0,0};
91 if (!preambleSearch(dest
, preamble
, sizeof(preamble
), size
, &startIdx
))
92 return -2; //preamble not found
93 if (*size
!= 96) return -3; //wrong demoded size
94 //return start position
100 * 2520116 | BB0214FF2529900116360000 | 10111011 00000011 00010100 11111111 00100101 00101001 10010000 00000001 00010110 00110110 00000000 00000000
101 * aaaaaaaaiii***iiiicc---- iiiiiiii iiiiYYYY YYYY**** iiiiiiii iiiiiiii cccccccc
103 * a = fixed value BB0314FF
104 * i = printed id, BCD-format
110 //see ASKDemod for what args are accepted
111 int CmdNoralsyDemod(const char *Cmd
) {
114 DemodBufferLen
= getFromGraphBuf(DemodBuffer
);
115 if (DemodBufferLen
< 255) return 0;
117 size_t ststart
= 0, stend
= 0;
118 bool st
= DetectST_ext(DemodBuffer
, &DemodBufferLen
, &foundclk
, &ststart
, &stend
);
121 if (!ASKDemod_ext("32 0 0", FALSE
, FALSE
, 1, &st
)) {
122 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: ASK/Manchester Demod failed");
125 size_t size
= DemodBufferLen
;
126 int ans
= NoralsyDemod_AM(DemodBuffer
, &size
);
130 PrintAndLog("DEBUG: Error - Noralsy: too few bits found");
132 PrintAndLog("DEBUG: Error - Noralsy: preamble not found");
134 PrintAndLog("DEBUG: Error - Noralsy: Size not correct: %d", size
);
136 PrintAndLog("DEBUG: Error - Noralsy: ans: %d", ans
);
140 setDemodBuf(DemodBuffer
, 96, ans
);
144 uint32_t raw1
= bytebits_to_byte(DemodBuffer
, 32);
145 uint32_t raw2
= bytebits_to_byte(DemodBuffer
+32, 32);
146 uint32_t raw3
= bytebits_to_byte(DemodBuffer
+64, 32);
148 uint32_t cardid
= (bytebits_to_byte(DemodBuffer
+32, 12)<<16) | bytebits_to_byte(DemodBuffer
+32+24, 16);
150 uint16_t year
= (raw2
& 0x000ff000) >> 12;
151 year
+= ( year
> 0x60 ) ? 0x1900: 0x2000;
154 uint8_t calc1
= noralsy_chksum(DemodBuffer
+32, 40);
155 uint8_t calc2
= noralsy_chksum(DemodBuffer
, 76);
156 uint8_t chk1
= 0, chk2
= 0;
157 chk1
= bytebits_to_byte(DemodBuffer
+72, 4);
158 chk2
= bytebits_to_byte(DemodBuffer
+76, 4);
160 if ( chk1
!= calc1
) {
161 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 1 failed %x - %x\n", chk1
, calc1
);
164 if ( chk2
!= calc2
) {
165 if (g_debugMode
) PrintAndLog("DEBUG: Error - Noralsy: checksum 2 failed %x - %x\n", chk2
, calc2
);
169 PrintAndLog("Noralsy Tag Found: Card ID %X, Year: %X Raw: %08X%08X%08X", cardid
, year
, raw1
,raw2
, raw3
);
170 if (raw1
!= 0xBB0214FF) {
171 PrintAndLog("Unknown bits set in first block! Expected 0xBB0214FF, Found: 0x%08X", raw1
);
172 PrintAndLog("Please post this output in forum to further research on this format");
177 int CmdNoralsyRead(const char *Cmd
) {
179 getSamples("8000",TRUE
);
180 return CmdNoralsyDemod(Cmd
);
183 int CmdNoralsyClone(const char *Cmd
) {
187 uint32_t blocks
[4] = {T55x7_MODULATION_MANCHESTER
| T55x7_BITRATE_RF_32
| T55x7_ST_TERMINATOR
| 3 << T55x7_MAXBLOCK_SHIFT
, 0, 0};
190 memset(bs
, 0, sizeof(bits
));
192 char cmdp
= param_getchar(Cmd
, 0);
193 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_clone();
195 id
= param_get32ex(Cmd
, 0, 0, 16);
196 year
= param_get32ex(Cmd
, 1, 2000, 16);
199 if (param_getchar(Cmd
, 2) == 'Q' || param_getchar(Cmd
, 2) == 'q') {
200 //t5555 (Q5) BITRATE = (RF-2)/2 (iceman)
201 blocks
[0] = T5555_MODULATION_MANCHESTER
| ((32-2)>>1) << T5555_BITRATE_SHIFT
| T5555_ST_TERMINATOR
| 3 << T5555_MAXBLOCK_SHIFT
;
204 if ( !getnoralsyBits(id
, year
, bs
)) {
205 PrintAndLog("Error with tag bitstream generation.");
210 blocks
[1] = bytebits_to_byte(bs
,32);
211 blocks
[2] = bytebits_to_byte(bs
+32,32);
212 blocks
[3] = bytebits_to_byte(bs
+64,32);
214 PrintAndLog("Preparing to clone Noralsy to T55x7 with CardId: %x", id
);
215 PrintAndLog("Blk | Data ");
216 PrintAndLog("----+------------");
217 PrintAndLog(" 00 | 0x%08x", blocks
[0]);
218 PrintAndLog(" 01 | 0x%08x", blocks
[1]);
219 PrintAndLog(" 02 | 0x%08x", blocks
[2]);
220 PrintAndLog(" 03 | 0x%08x", blocks
[3]);
223 UsbCommand c
= {CMD_T55XX_WRITE_BLOCK
, {0,0,0}};
225 for (int i
= 3; i
>= 0; --i
) {
226 c
.arg
[0] = blocks
[i
];
228 clearCommandBuffer();
230 if (!WaitForResponseTimeout(CMD_ACK
, &resp
, T55XX_WRITE_TIMEOUT
)){
231 PrintAndLog("Error occurred, device did not respond during write operation.");
238 int CmdNoralsySim(const char *Cmd
) {
242 memset(bs
, 0, sizeof(bits
));
247 char cmdp
= param_getchar(Cmd
, 0);
248 if (strlen(Cmd
) == 0 || cmdp
== 'h' || cmdp
== 'H') return usage_lf_noralsy_sim();
250 id
= param_get32ex(Cmd
, 0, 0, 16);
251 year
= param_get32ex(Cmd
, 1, 2000, 16);
253 uint8_t clk
= 32, encoding
= 1, separator
= 1, invert
= 0;
256 arg1
= clk
<< 8 | encoding
;
257 arg2
= invert
<< 8 | separator
;
259 if ( !getnoralsyBits(id
, year
, bs
)) {
260 PrintAndLog("Error with tag bitstream generation.");
264 PrintAndLog("Simulating Noralsy - CardId: %x", id
);
266 UsbCommand c
= {CMD_ASK_SIM_TAG
, {arg1
, arg2
, size
}};
267 memcpy(c
.d
.asBytes
, bs
, size
);
268 clearCommandBuffer();
273 static command_t CommandTable
[] = {
274 {"help", CmdHelp
, 1, "This help"},
275 {"demod", CmdNoralsyDemod
,1, "Attempt to read and extract tag data from the GraphBuffer"},
276 {"read", CmdNoralsyRead
, 0, "Attempt to read and extract tag data from the antenna"},
277 {"clone", CmdNoralsyClone
,0, "clone Noralsy tag"},
278 {"sim", CmdNoralsySim
, 0, "simulate Noralsy tag"},
279 {NULL
, NULL
, 0, NULL
}
282 int CmdLFNoralsy(const char *Cmd
) {
283 clearCommandBuffer();
284 CmdsParse(CommandTable
, Cmd
);
288 int CmdHelp(const char *Cmd
) {
289 CmdsHelp(CommandTable
);