#include "proxmark3.h"\r
#include "cmdmain.h"\r
#include "cmdhfmfhard.h"\r
+#include "parity.h"\r
#include "util.h"\r
#include "util_posix.h"\r
#include "usb_cmd.h"\r
//var\r
int res = 0;\r
int len = 0;\r
+ int parlen = 0;\r
int blockLen = 0;\r
int pckNum = 0;\r
int num = 0;\r
uint8_t *buf = NULL;\r
uint16_t bufsize = 0;\r
uint8_t *bufPtr = NULL;\r
+ uint8_t parity[16];\r
\r
char ctmp = param_getchar(Cmd, 0);\r
if ( ctmp == 'h' || ctmp == 'H' ) {\r
} else {\r
isTag = false;\r
}\r
+ parlen = (len - 1) / 8 + 1;\r
bufPtr += 2;\r
if ((len == 14) && (bufPtr[0] == 0xff) && (bufPtr[1] == 0xff) && (bufPtr[12] == 0xff) && (bufPtr[13] == 0xff)) {\r
memcpy(uid, bufPtr + 2, 7);\r
if (wantDecrypt)\r
mfTraceInit(uid, atqa, sak, wantSaveToEmlFile);\r
} else {\r
- PrintAndLog("%s(%d):%s", isTag ? "TAG":"RDR", num, sprint_hex(bufPtr, len));\r
+ oddparitybuf(bufPtr, len, parity);\r
+ PrintAndLog("%s(%d):%s [%s] c[%s]%c", \r
+ isTag ? "TAG":"RDR", \r
+ num, \r
+ sprint_hex(bufPtr, len), \r
+ printBitsPar(bufPtr + len, len), \r
+ printBitsPar(parity, len),\r
+ memcmp(bufPtr + len, parity, len / 8 + 1) ? '!' : ' ');\r
if (wantLogToFile)\r
AddLogHex(logHexFileName, isTag ? "TAG: ":"RDR: ", bufPtr, len);\r
if (wantDecrypt)\r
- mfTraceDecode(bufPtr, len, wantSaveToEmlFile);\r
+ mfTraceDecode(bufPtr, len, bufPtr[len], wantSaveToEmlFile);\r
num++;\r
}\r
bufPtr += len;\r
- bufPtr += ((len-1)/8+1); // ignore parity\r
+ bufPtr += parlen; // ignore parity\r
}\r
pckNum = 0;\r
}\r
#include "usb_cmd.h"\r
#include "cmdmain.h"\r
#include "ui.h"\r
+#include "parity.h"\r
#include "util.h"\r
#include "iso14443crc.h"\r
\r
\r
struct Crypto1State *revstate;\r
uint64_t lfsr;\r
+uint64_t ui64Key;\r
uint32_t ks2;\r
uint32_t ks3;\r
\r
-uint32_t uid; // serial number\r
-uint32_t nt; // tag challenge\r
-uint32_t nr_enc; // encrypted reader challenge\r
-uint32_t ar_enc; // encrypted reader response\r
-uint32_t at_enc; // encrypted tag response\r
+uint32_t uid; // serial number\r
+uint32_t nt; // tag challenge\r
+uint32_t nt_enc; // encrypted tag challenge\r
+uint8_t nt_enc_par; // encrypted tag challenge parity\r
+uint32_t nr_enc; // encrypted reader challenge\r
+uint32_t ar_enc; // encrypted reader response\r
+uint8_t ar_enc_par; // encrypted reader response parity\r
+uint32_t at_enc; // encrypted tag response\r
+uint8_t at_enc_par; // encrypted tag response parity\r
\r
int isTraceCardEmpty(void) {\r
return ((traceCard[0] == 0) && (traceCard[1] == 0) && (traceCard[2] == 0) && (traceCard[3] == 0));\r
return;\r
}\r
\r
+bool NTParityCheck(uint32_t ntx) {\r
+ if (\r
+ (oddparity8(ntx >> 8 & 0xff) ^ (ntx & 0x01) ^ ((nt_enc_par >> 5) & 0x01) ^ (nt_enc & 0x01)) ||\r
+ (oddparity8(ntx >> 16 & 0xff) ^ (ntx >> 8 & 0x01) ^ ((nt_enc_par >> 6) & 0x01) ^ (nt_enc >> 8 & 0x01)) ||\r
+ (oddparity8(ntx >> 24 & 0xff) ^ (ntx >> 16 & 0x01) ^ ((nt_enc_par >> 7) & 0x01) ^ (nt_enc >> 16 & 0x01))\r
+ )\r
+ return false;\r
+ \r
+ uint32_t ar = prng_successor(ntx, 64);\r
+ if (\r
+ (oddparity8(ar >> 8 & 0xff) ^ (ar & 0x01) ^ ((ar_enc_par >> 5) & 0x01) ^ (ar_enc & 0x01)) ||\r
+ (oddparity8(ar >> 16 & 0xff) ^ (ar >> 8 & 0x01) ^ ((ar_enc_par >> 6) & 0x01) ^ (ar_enc >> 8 & 0x01)) ||\r
+ (oddparity8(ar >> 24 & 0xff) ^ (ar >> 16 & 0x01) ^ ((ar_enc_par >> 7) & 0x01) ^ (ar_enc >> 16 & 0x01))\r
+ )\r
+ return false;\r
+\r
+ uint32_t at = prng_successor(ntx, 96);\r
+ if (\r
+ (oddparity8(ar & 0xff) ^ (at >> 24 & 0x01) ^ ((ar_enc_par >> 4) & 0x01) ^ (at_enc >> 24 & 0x01)) ||\r
+ (oddparity8(at >> 8 & 0xff) ^ (at & 0x01) ^ ((at_enc_par >> 5) & 0x01) ^ (at_enc & 0x01)) ||\r
+ (oddparity8(at >> 16 & 0xff) ^ (at >> 8 & 0x01) ^ ((at_enc_par >> 6) & 0x01) ^ (at_enc >> 8 & 0x01)) ||\r
+ (oddparity8(at >> 24 & 0xff) ^ (at >> 16 & 0x01) ^ ((at_enc_par >> 7) & 0x01) ^ (at_enc >> 16 & 0x01))\r
+ )\r
+ return false;\r
+ \r
+ return true;\r
+}\r
\r
-int mfTraceDecode(uint8_t *data_src, int len, bool wantSaveToEmlFile) {\r
+\r
+int mfTraceDecode(uint8_t *data_src, int len, uint8_t parity, bool wantSaveToEmlFile) {\r
uint8_t data[64];\r
\r
if (traceState == TRACE_ERROR) return 1;\r
memcpy(data, data_src, len);\r
if ((traceCrypto1) && ((traceState == TRACE_IDLE) || (traceState > TRACE_AUTH_OK))) {\r
mf_crypto1_decrypt(traceCrypto1, data, len, 0);\r
- PrintAndLog("dec> %s", sprint_hex(data, len));\r
+ uint8_t parity[16];\r
+ oddparitybuf(data, len, parity);\r
+ PrintAndLog("dec> %s [%s]", sprint_hex(data, len), printBitsPar(parity, len));\r
AddLogHex(logHexFileName, "dec> ", data, len);\r
}\r
\r
case TRACE_AUTH1:\r
if (len == 4) {\r
traceState = TRACE_AUTH2;\r
- nt = bytes_to_num(data, 4);\r
+ if (!traceCrypto1) {\r
+ nt = bytes_to_num(data, 4);\r
+ } else {\r
+ nt_enc = bytes_to_num(data, 4);\r
+ nt_enc_par = parity;\r
+ }\r
return 0;\r
} else {\r
traceState = TRACE_ERROR;\r
\r
nr_enc = bytes_to_num(data, 4);\r
ar_enc = bytes_to_num(data + 4, 4);\r
+ ar_enc_par = parity << 4;\r
return 0;\r
} else {\r
traceState = TRACE_ERROR;\r
if (len ==4) {\r
traceState = TRACE_IDLE;\r
\r
+ at_enc = bytes_to_num(data, 4);\r
+ at_enc_par = parity;\r
if (!traceCrypto1) {\r
- at_enc = bytes_to_num(data, 4);\r
\r
// decode key here)\r
ks2 = ar_enc ^ prng_successor(nt, 64);\r
lfsr_rollback_word(revstate, uid ^ nt, 0);\r
\r
crypto1_get_lfsr(revstate, &lfsr);\r
- printf("key> %x%x\n", (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF));\r
+ crypto1_destroy(revstate);\r
+ ui64Key = lfsr;\r
+ printf("key> probable key:%x%x Prng:%s ks2:%08x ks3:%08x\n", \r
+ (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF), \r
+ validate_prng_nonce(nt) ? "WEAK": "HARDEND",\r
+ ks2,\r
+ ks3);\r
AddLogUint64(logHexFileName, "key> ", lfsr);\r
} else {\r
- printf("key> nested not implemented!\n");\r
- at_enc = bytes_to_num(data, 4);\r
+ if (validate_prng_nonce(nt)) {\r
+ struct Crypto1State *pcs;\r
+ pcs = crypto1_create(ui64Key);\r
+ uint32_t nt1 = crypto1_word(pcs, nt_enc ^ uid, 1) ^ nt_enc;\r
+ uint32_t ar = prng_successor(nt1, 64);\r
+ uint32_t at = prng_successor(nt1, 96);\r
+ printf("key> nested auth uid: %08x nt: %08x nt_parity: %s ar: %08x at: %08x\n", uid, nt1, printBitsPar(&nt_enc_par, 4), ar, at);\r
+ uint32_t nr1 = crypto1_word(pcs, nr_enc, 1) ^ nr_enc;\r
+ uint32_t ar1 = crypto1_word(pcs, 0, 0) ^ ar_enc;\r
+ uint32_t at1 = crypto1_word(pcs, 0, 0) ^ at_enc;\r
+ printf("key> the same key test. nr1: %08x ar1: %08x at1: %08x \n", nr1, ar1, at1);\r
+\r
+ if (NTParityCheck(nt1))\r
+ printf("key> the same key test OK. key=%x%x\n", (unsigned int)((ui64Key & 0xFFFFFFFF00000000) >> 32), (unsigned int)(ui64Key & 0xFFFFFFFF));\r
+ else\r
+ printf("key> the same key test. check nt parity error.\n");\r
+ \r
+ uint32_t ntc = prng_successor(nt, 90);\r
+ uint32_t ntx = 0;\r
+ int ntcnt = 0;\r
+ for (int i = 0; i < 16383; i++) {\r
+ ntc = prng_successor(ntc, 1);\r
+ if (NTParityCheck(ntc)){\r
+ if (!ntcnt)\r
+ ntx = ntc;\r
+ ntcnt++;\r
+ } \r
+ }\r
+ if (ntcnt)\r
+ printf("key> nt candidate=%08x nonce distance=%d candidates count=%d\n", ntx, nonce_distance(nt, ntx), ntcnt);\r
+ else\r
+ printf("key> don't have any nt candidate( \n");\r
+\r
+ nt = ntx;\r
+ ks2 = ar_enc ^ prng_successor(ntx, 64);\r
+ ks3 = at_enc ^ prng_successor(ntx, 96);\r
+\r
+ // decode key\r
+ revstate = lfsr_recovery64(ks2, ks3);\r
+ lfsr_rollback_word(revstate, 0, 0);\r
+ lfsr_rollback_word(revstate, 0, 0);\r
+ lfsr_rollback_word(revstate, nr_enc, 1);\r
+ lfsr_rollback_word(revstate, uid ^ nt, 0);\r
+\r
+ crypto1_get_lfsr(revstate, &lfsr);\r
+ crypto1_destroy(revstate);\r
+ ui64Key = lfsr;\r
+ printf("key> probable key:%x%x ks2:%08x ks3:%08x\n", \r
+ (unsigned int)((lfsr & 0xFFFFFFFF00000000) >> 32), (unsigned int)(lfsr & 0xFFFFFFFF),\r
+ ks2,\r
+ ks3);\r
+ AddLogUint64(logHexFileName, "key> ", lfsr);\r
+ } else { \r
+ printf("key> hardnested not implemented!\n");\r
\r
- crypto1_destroy(traceCrypto1);\r
+ crypto1_destroy(traceCrypto1);\r
\r
- // not implemented\r
- traceState = TRACE_ERROR;\r
+ // not implemented\r
+ traceState = TRACE_ERROR;\r
+ }\r
}\r
\r
int blockShift = ((traceCurBlock & 0xFC) + 3) * 16;\r