iceman1001 [Wed, 13 Jan 2016 11:58:10 +0000 (12:58 +0100)]
FIX: Coverity, strlen(Cmd) can never be lesser than zero.. *douh*
iceman1001 [Wed, 13 Jan 2016 11:50:18 +0000 (12:50 +0100)]
FIX: Coverity, resource leaks 'nd more.. in "lf t55xx bruteforce" nasty piece of code...
iceman1001 [Wed, 13 Jan 2016 11:49:21 +0000 (12:49 +0100)]
FIX: forgot to change a modified call from @pwpivi 's last update.
iceman1001 [Wed, 13 Jan 2016 08:31:13 +0000 (09:31 +0100)]
ADD: @pwpiwi 's latest changes to 'hf mf hardnested'
iceman1001 [Tue, 12 Jan 2016 23:24:37 +0000 (00:24 +0100)]
REM: Removed lot of obselete code from before.
iceman1001 [Tue, 12 Jan 2016 23:16:11 +0000 (00:16 +0100)]
ADD: "lf hid bruteforce" for a simple bruteforce attact against a HID reader. *work in progress*
iceman1001 [Tue, 12 Jan 2016 23:14:08 +0000 (00:14 +0100)]
FIX: tcgetattr for Linux in Ukbhit(), should return -1 if fail.
iceman1001 [Tue, 12 Jan 2016 23:08:23 +0000 (00:08 +0100)]
FIX: Coverity, Unchecked return value, CID #121288, lets do the same check that is everywhere is this call is used.
iceman1001 [Tue, 12 Jan 2016 23:07:14 +0000 (00:07 +0100)]
FIX: Coverity, CID# 121351, #121371, #121372, old code that is not used any more, I should remove this.
iceman1001 [Tue, 12 Jan 2016 23:05:55 +0000 (00:05 +0100)]
FIX: textual changes
iceman1001 [Tue, 12 Jan 2016 22:56:15 +0000 (23:56 +0100)]
FIX: Coverity, resource leak, CID #121357, Mat needs to be free
iceman1001 [Tue, 12 Jan 2016 22:42:42 +0000 (23:42 +0100)]
FIX: Coverity, logical vs bitwise operator, remove the extra '&' for it to become bitwise.
iceman1001 [Tue, 12 Jan 2016 22:40:57 +0000 (23:40 +0100)]
FIX: Coverity, Unintended sign extension, data[7] would have become int, then uint64_t. Should work better now with adding typecasting.
iceman1001 [Tue, 12 Jan 2016 22:38:47 +0000 (23:38 +0100)]
FIX: Coverity, Resource leak, CID #121361, filehandle f needs to be free
iceman1001 [Tue, 12 Jan 2016 22:37:33 +0000 (23:37 +0100)]
FIX: Coverity, Resource leak, CID# 121360, keyBlock needs to be free
iceman1001 [Tue, 12 Jan 2016 22:35:06 +0000 (23:35 +0100)]
FIX: Coverity, out-of-bounds write, CID#121340, CID#121341, CID#121342, CID#121343, wrong size in check, sprintf always adds a null terminator, so if filepath would have been 996 chars long, this might had happend... but no more.
iceman1001 [Tue, 12 Jan 2016 22:29:05 +0000 (23:29 +0100)]
CHG: Syntax suger
iceman1001 [Tue, 12 Jan 2016 22:27:42 +0000 (23:27 +0100)]
FIX: Coverity, CID#121314, Explicit null dereferenced, in really odd occasions buf would be NULL, and sending NULL to memcpy dereferences it. Not sure about this fix.
iceman1001 [Tue, 12 Jan 2016 22:16:20 +0000 (23:16 +0100)]
FIX: Coverity, CID# 121337, Out-of-bounds. In the loop, variable i, can be as much as 1051, overflowing the databuf with size 1024.
iceman1001 [Tue, 12 Jan 2016 22:10:38 +0000 (23:10 +0100)]
FIX: Coverity, uninitialized scalar variable, filename array could be NULL..
iceman1001 [Tue, 12 Jan 2016 22:06:53 +0000 (23:06 +0100)]
FIX: Coverity, CID #121346, resouce leak, close filehandle.
iceman1001 [Tue, 12 Jan 2016 22:05:10 +0000 (23:05 +0100)]
FIX: Coverity, out-of-bounds, CID#121330, CID#121331, CID#121332, CID#121333,
keyNbr has to be smaller then ICLASS_KEYS_MAX (since the Iclass_Key_Table array is initialised with it).
iceman1001 [Tue, 12 Jan 2016 21:57:23 +0000 (22:57 +0100)]
FIX: Coverity, Dereference null return, CID #212329, filehandle could be NULL
iceman1001 [Tue, 12 Jan 2016 21:53:13 +0000 (22:53 +0100)]
FIX, Coverity, Unsigned compared against 0. CID #212326, keyNBr will never be negative.
iceman1001 [Tue, 12 Jan 2016 21:49:29 +0000 (22:49 +0100)]
FIX, Coverity, Argument can't be negative, CID #212324, ftell(f) can be negative, not allowed in malloc.
iceman1001 [Tue, 12 Jan 2016 21:47:48 +0000 (22:47 +0100)]
FIX: Coverity , Argument can't be negative, CID #121323, ftell(f) can be negative, not allowed in malloc.
FIX: forgot to close the filehandle :(
iceman1001 [Tue, 12 Jan 2016 21:43:28 +0000 (22:43 +0100)]
FIX, Coverity, Argument can't be negative. CID# 212322, ftell(f) can be negative. Not allowed in malloc...
iceman1001 [Tue, 12 Jan 2016 21:42:31 +0000 (22:42 +0100)]
CHG: syntax suger
iceman1001 [Tue, 12 Jan 2016 21:37:35 +0000 (22:37 +0100)]
FIX: Coverity, Identical code for different branches, CID #121315, added a message and different return value.
iceman1001 [Tue, 12 Jan 2016 21:33:54 +0000 (22:33 +0100)]
FIX: Coverity, unintended sign extention, CID #121363, (numbits << 16) becomes int, then uint64_t. But the signness might set all upper bits to 1 in the process.
iceman1001 [Tue, 12 Jan 2016 21:30:22 +0000 (22:30 +0100)]
FIX: Coverity, unchecked return value, CID #121292,..
basicallty the flush queue commmand is replaced with clearCommandBuffer();.
iceman1001 [Tue, 12 Jan 2016 21:15:49 +0000 (22:15 +0100)]
FIX: Coverity, out-of-bounds write, CID# 121336, s_index should take factor in consideration when looping. Not sure about this one.
FIX: another thing struck me, the g_index wasn't increased, meaning the "un-decimation" always worked on the same first byte of GraphBuffer.
iceman1001 [Sat, 9 Jan 2016 16:20:58 +0000 (17:20 +0100)]
Merge branch 'master' of https://github.com/iceman1001/proxmark3
iceman1001 [Sat, 9 Jan 2016 16:20:06 +0000 (17:20 +0100)]
FIX: minor fixes to the HID wiegand generation command. Still not complete
iceman1001 [Sat, 9 Jan 2016 16:19:09 +0000 (17:19 +0100)]
CHG: syntax suger
iceman1001 [Sat, 9 Jan 2016 16:17:36 +0000 (17:17 +0100)]
ADD: a new pwdgen algo Nicknamed C, (Huge props to @Bettse for everything) also added to the "hf mfu info" command. However, that will not work given the system's lockbits.. :( Maybe I'll add a function to test all imp pwdgens given a UID without making a authentication call to tag.
ADD: BSWAP_32 macro, for changing endianness.
iceman1001 [Sat, 9 Jan 2016 16:13:54 +0000 (17:13 +0100)]
ADD: Travis now builds automatically.
Iceman [Fri, 8 Jan 2016 21:40:02 +0000 (22:40 +0100)]
Update README.txt
iceman1001 [Fri, 8 Jan 2016 21:30:36 +0000 (22:30 +0100)]
fix: gcc-arm-none-eabi still not working...
iceman1001 [Fri, 8 Jan 2016 21:27:09 +0000 (22:27 +0100)]
ADD: added gcc-arm-none-eabi compiler to travie script
iceman1001 [Fri, 8 Jan 2016 21:18:15 +0000 (22:18 +0100)]
CHG: added the make command
iceman1001 [Fri, 8 Jan 2016 21:14:22 +0000 (22:14 +0100)]
ADD: added integration with Travis CI,
iceman1001 [Fri, 8 Jan 2016 14:29:06 +0000 (15:29 +0100)]
FIX: @marshmellow42 's cleanup of includes.
iceman1001 [Fri, 8 Jan 2016 14:28:24 +0000 (15:28 +0100)]
FIX: coverty scan defects.
- bigbuf.c is comparision correct (iLen versus numofparity)
- cmdhfepa.c resourceleak, add a call to free
- cipherutils.c resourceleak, added calls to free
iceman1001 [Fri, 8 Jan 2016 13:31:27 +0000 (14:31 +0100)]
REM: code cleanup.
iceman1001 [Fri, 8 Jan 2016 13:30:56 +0000 (14:30 +0100)]
FIX: coverty scan, resourceleak in "hf mf sniff", added call to 'free' befor return.
FIX: coverty scan, overflow in "hf 14a raw", added an extra len check against USB_CMD_DATA_SIZE
iceman1001 [Fri, 8 Jan 2016 13:28:13 +0000 (14:28 +0100)]
ADD: @go_tus 's code to generate wiegand codes from FacilityCode/SiteCode and Cardnumber. Almost there, formatlength supported is 26,34,35,37,38,40,44,75,84, when its finised.
iceman1001 [Fri, 8 Jan 2016 13:26:35 +0000 (14:26 +0100)]
Syntax suger, making the code easier to read (for me at least)
iceman1001 [Fri, 8 Jan 2016 13:25:10 +0000 (14:25 +0100)]
FIX: coverty scan reveals some resourceleaks and overruns, which is supposed to be fixed now.
/armsrc/des.c overflow 7 instead of 6
/client/cmdlfhitag.c overflows traclen
/client/util.c sprint_bin_break overflows.
/client/cmdhficlass.c need to free memory after malloc.
ADD: RotateRight macro in util.h
Iceman [Fri, 8 Jan 2016 12:29:59 +0000 (13:29 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:29:01 +0000 (13:29 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:24:56 +0000 (13:24 +0100)]
Update README.txt
Iceman [Fri, 8 Jan 2016 12:22:05 +0000 (13:22 +0100)]
Update README.txt
Iceman [Wed, 6 Jan 2016 17:38:12 +0000 (18:38 +0100)]
Update README.txt
Iceman [Wed, 6 Jan 2016 17:34:43 +0000 (18:34 +0100)]
added coverty build scan badge
iceman1001 [Mon, 4 Jan 2016 09:13:38 +0000 (10:13 +0100)]
ADD: added a Q5 parameter for "lf t55xx wipe",
the default config blocks is:
t55x7 :
000880E0
t5555 (Q5) :
6001F004
iceman1001 [Mon, 4 Jan 2016 09:11:20 +0000 (10:11 +0100)]
ADD: added @pwpiwi 's corrections to "hf mf hardnested"
iceman1001 [Sun, 3 Jan 2016 16:17:44 +0000 (17:17 +0100)]
code clean up, added some comments to hitag
iceman1001 [Sun, 3 Jan 2016 16:16:50 +0000 (17:16 +0100)]
added @pwpiwi 's latest changes to "hf mf hardnested"
iceman1001 [Sun, 3 Jan 2016 16:16:06 +0000 (17:16 +0100)]
added @broken_bad's imp of showing T555/Q5 trace data. (with my modifications ;) )
iceman1001 [Wed, 23 Dec 2015 22:26:03 +0000 (23:26 +0100)]
REM: removed an offensive #include on archlinux. Compiles on mingw without.
iceman1001 [Wed, 23 Dec 2015 10:59:34 +0000 (11:59 +0100)]
FIX: removed printBits reference.
iceman1001 [Tue, 22 Dec 2015 15:14:03 +0000 (16:14 +0100)]
FIX: the usb_poll_validate_length() check should be inversed, thanks @marshmellow42
iceman1001 [Mon, 21 Dec 2015 18:48:33 +0000 (19:48 +0100)]
ADD: @marshmellow42 's changes to "hf mfu dump"
iceman1001 [Mon, 21 Dec 2015 18:48:00 +0000 (19:48 +0100)]
CHG: some textual change to README.txt
ADD: a prng.c to collect some different PRNG's i've ran into
ADD: some changes the tea implementation
ADD: a enhanced version - SwapEndian64ex
iceman1001 [Mon, 21 Dec 2015 18:44:47 +0000 (19:44 +0100)]
add: added @AdamLaurie 's iclass raw keys changes
iceman1001 [Wed, 16 Dec 2015 10:01:46 +0000 (11:01 +0100)]
ADD: @marshmellow42 's fixes for Q5, t55xx, fskclock,
ADD: got tired of always writing wrong "hf 14a list", so I hooked it back up to call the "hf list" with argument. Things becomes smoother that way.
iceman1001 [Tue, 15 Dec 2015 08:34:55 +0000 (09:34 +0100)]
ADD: @marshmellow42 's changes to "hf mfu *" ,
ADD: @marshmellow42 's changes to "hf mf sim",
ADD: @pwpiwi 's parity files was missing.
iceman1001 [Tue, 15 Dec 2015 07:51:29 +0000 (08:51 +0100)]
ADD: @pwpiwi 's latest code from his 'hardnested' branch.
iceman1001 [Mon, 14 Dec 2015 21:52:04 +0000 (22:52 +0100)]
FIX: minor fixes in hf mfu, from @marshmello42 's branch.
iceman1001 [Mon, 14 Dec 2015 21:50:54 +0000 (22:50 +0100)]
REM: removed an unused doublett function "printBits" in util.c
ADD: added a new string helper function "sprint_hex_ascii" in util.c
ADD: added "LF AWID BRUTE", a very simple bruteforce command for the awid commands.
it takes a facility-code, and iterates all possible 0xFFFF cardnum by sending sim command. It also uses the usb_poll function to stop the bruteforce on keypress and not leaving the pm3 device running the simulation.
the command implements the help parameter.
iceman1001 [Thu, 10 Dec 2015 09:30:13 +0000 (10:30 +0100)]
ADD: @marshmellow42 's fixes to cmdlft55xx.c (save_restoreGB)
ADD: started with a skeleton method for printing hex and ascill.
iceman1001 [Wed, 9 Dec 2015 14:29:18 +0000 (15:29 +0100)]
Two fixes for warnings when compiling on Ubuntu14.04.
FIX: a wrongly set parameter call to memset in CmdT55xxWipe .
FIX: an ignored fread call in cmdhficlass.c,
iceman1001 [Wed, 9 Dec 2015 13:58:16 +0000 (14:58 +0100)]
ADD: @marshmello42 's fixes for low frequency demodulation lengths greater the 512bits.
iceman1001 [Wed, 9 Dec 2015 13:57:16 +0000 (14:57 +0100)]
ADD: a TEA crypto algorithm implemention.
iceman1001 [Sat, 5 Dec 2015 21:18:42 +0000 (22:18 +0100)]
added some keys
iceman1001 [Wed, 2 Dec 2015 22:06:03 +0000 (23:06 +0100)]
ADD: hooked up the new pwdgen functions inside the "hf mfu info", to be tested if the authlimit is not set.
iceman1001 [Wed, 2 Dec 2015 21:46:11 +0000 (22:46 +0100)]
CHG: updated helptext for lf t55xx bruteforce
ADD: a ROL function in util.c
ADD: two pwdgen functions in cmdhfmfu.c, call them with a 7byte UID and get a 4byte number back. Will see if it can be connected with the "hf mfu info" command, make data extraction easier later on.
ADD: added some more easy pwd in the dictionary file default_pwd.dic
iceman1001 [Wed, 2 Dec 2015 15:48:25 +0000 (16:48 +0100)]
add: missing two hard_nested files..
iceman1001 [Tue, 1 Dec 2015 21:47:03 +0000 (22:47 +0100)]
ADD: Added the possibility to exit the bruteforce mode (either rangesearch or file) with the keyboard.
FIX: if not found, the range search printed wrong number.
iceman1001 [Tue, 1 Dec 2015 21:38:37 +0000 (22:38 +0100)]
FIX: the lfsampling.c for t55xx had a tendecy to enter a neverending loop. Moved exit branch into the while statement, which seems to solve it.
FIX: Strange int -> uint8_t casting behavior (0x05 gets the 25bit set and becomes 0x10005 instead) in fskdemod, removed int and sscanf.
iceman1001 [Tue, 1 Dec 2015 19:44:12 +0000 (20:44 +0100)]
FIX: added a break if the device starts acting strange when aquirering data from tag.
iceman1001 [Tue, 1 Dec 2015 15:44:53 +0000 (16:44 +0100)]
FIXES: the custom keys testloop now increases the read pwd :)
iceman1001 [Tue, 1 Dec 2015 12:07:01 +0000 (13:07 +0100)]
ADD: added the possibility to load a default pwd file to be used with the "lf t55xx bruteforce" command.
new option:
lf t55xx brutefore i default_pwd.dic - will load default pwds from file and test against tag.
iceman1001 [Fri, 27 Nov 2015 16:00:48 +0000 (17:00 +0100)]
textual fix.
iceman1001 [Fri, 27 Nov 2015 15:59:35 +0000 (16:59 +0100)]
FIX: the t55xx bruteforce method got some fixes, in commandname, uint32_t instead of int, and output texts.
iceman1001 [Fri, 27 Nov 2015 15:24:00 +0000 (16:24 +0100)]
ADD: @go_tus simple bruteforce for t55xx, refactored a bit.
ADD: @pwpiwi 's implementation of Hardnested
iceman1001 [Mon, 23 Nov 2015 09:49:16 +0000 (10:49 +0100)]
CHG: Missing some headers
FIX: some message/warning in pm3_binlib.c @gm4tr1x
iceman1001 [Sun, 22 Nov 2015 20:48:15 +0000 (21:48 +0100)]
FIX: the read counter in "hf 14a sim" (for ntag/ev) should work better now. Instead of always returning zero, it increases aswell.
--Started to add the TI demod into the 'LF SEARCH"
iceman1001 [Sun, 22 Nov 2015 17:13:26 +0000 (18:13 +0100)]
ADD: 'hf mfu info' now prints following settings:
NFC_COUNTER_EN - If set, every read,fast_read increases a counter.
NFC_COUNTER_PROT_PWD - If set, reading nfc_counter needs a successfull pwd authentication before
These new settings is only valid for NTAG213/215/216,
iceman1001 [Sun, 22 Nov 2015 16:33:41 +0000 (17:33 +0100)]
ADD: @marshmellow's fixes to awid, viking and T55x7
ADD: 'lf t55xx detect' now can be called with a password.
ADD: trying to add the read counter and increase counter commands for ntag sim.
iceman1001 [Sat, 21 Nov 2015 17:48:58 +0000 (18:48 +0100)]
ADD: lf indalademod output, The binary string is now printed with linebreaks every 16bits
ADD: lf awid code is modified, some minor changes in outputs
ADD: lf t55xx write now prints the password on the same row, looks better when using the new "lf t55xx wipe" command.
ADD: the ioprox T55X7_IOPROX_CONFIG_BLOCK block.
iceman1001 [Fri, 20 Nov 2015 15:56:43 +0000 (16:56 +0100)]
@marshmellows last LF changes.
- wipe a t55x7 tag
- stable demods
-
iceman1001 [Tue, 10 Nov 2015 17:56:43 +0000 (18:56 +0100)]
FIX: some fixes to indalademod and viking from @marshmellow42
iceman1001 [Tue, 10 Nov 2015 10:45:45 +0000 (11:45 +0100)]
FIX: an error that I introduced to the csetblock command with wrong length of crc calcs.
CHG: variable name in csetblock change. just trying to be consistant.
ADD: code clean up in hf 14a, added some help text methods.
iceman1001 [Tue, 10 Nov 2015 10:42:59 +0000 (11:42 +0100)]
added @marshmellows new viking demod.
adjusted it to fit with the clone/demod that is under "lf viking" commands.
did some code clean up, 3spaces into tab.
iceman1001 [Mon, 9 Nov 2015 21:06:48 +0000 (22:06 +0100)]
fix: forgot to remove this when merging piwi's fixes.
iceman1001 [Mon, 9 Nov 2015 20:51:34 +0000 (21:51 +0100)]
CHG: minor code clean up, removed commented old code.
ADD: usb_poll_validate_length to some deviceside loops.
ADD: @marshmellow42 's fixes to LF
iceman1001 [Mon, 9 Nov 2015 20:49:02 +0000 (21:49 +0100)]
ADD: @marshmellow fix for em41x clock.
CHG: swap the int to a uint8_t to skip a compiler error
iceman1001 [Mon, 9 Nov 2015 20:48:09 +0000 (21:48 +0100)]
ADD: @piwi's fixes to "hf snoop" where it empties the bigbuffer before snooping.