38 #endif // HAVE_CONFIG_H
56 static mifare_param mp;
57 static mifare_classic_tag mtKeys;
58 static mifare_classic_tag mtDump;
60 static bool bUseKeyFile;
61 static uint8_t uiBlocks;
62 static byte_t keys[] = {
63 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
64 0xd3, 0xf7, 0xd3, 0xf7, 0xd3, 0xf7,
65 0xa0, 0xa1, 0xa2, 0xa3, 0xa4, 0xa5,
66 0xb0, 0xb1, 0xb2, 0xb3, 0xb4, 0xb5,
67 0x4d, 0x3a, 0x99, 0xc3, 0x51, 0xdd,
68 0x1a, 0x98, 0x2c, 0x7e, 0x45, 0x9a,
69 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff,
70 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
71 0xab, 0xcd, 0xef, 0x12, 0x34, 0x56
79 static size_t num_keys =
sizeof (keys) / 6;
82 print_success_or_failure (
bool bFailure, uint32_t * uiBlockCounter)
84 printf (
"%c", (bFailure) ?
'x' :
'.');
85 if (uiBlockCounter && !bFailure)
86 *uiBlockCounter += (*uiBlockCounter < 128) ? 4 : 16;
90 is_first_block (uint32_t uiBlock)
94 return ((uiBlock) % 4 == 0);
96 return ((uiBlock) % 16 == 0);
100 is_trailer_block (uint32_t uiBlock)
104 return ((uiBlock + 1) % 4 == 0);
106 return ((uiBlock + 1) % 16 == 0);
110 get_trailer_block (uint32_t uiFirstBlock)
113 uint32_t trailer_block = 0;
114 if (uiFirstBlock < 128) {
115 trailer_block = uiFirstBlock + (3 - (uiFirstBlock % 4));
117 trailer_block = uiFirstBlock + (15 - (uiFirstBlock % 16));
119 return trailer_block;
123 authenticate (uint32_t uiBlock)
126 uint32_t uiTrailerBlock;
132 memcpy (mp.mpa.abtUid, nt.nti.nai.abtUid, 4);
135 uiTrailerBlock = get_trailer_block (uiBlock);
140 memcpy (mp.mpa.abtKey, mtKeys.amb[uiTrailerBlock].mbt.abtKeyA, 6);
143 memcpy (mp.mpa.abtKey, mtKeys.amb[uiTrailerBlock].mbt.abtKeyB, 6);
147 if (nfc_initiator_mifare_cmd (pnd, mc, uiBlock, &mp))
153 mc = (bUseKeyA) ? MC_AUTH_A : MC_AUTH_B;
156 memcpy (mp.mpa.abtUid, nt.nti.nai.abtUid, 4);
158 for (key_index = 0; key_index < num_keys; key_index++) {
159 memcpy (mp.mpa.abtKey, keys + (key_index * 6), 6);
160 if (nfc_initiator_mifare_cmd (pnd, mc, uiBlock, &mp)) {
162 memcpy (mtKeys.amb[uiBlock].mbt.abtKeyA, &mp.mpa.abtKey, 6);
164 memcpy (mtKeys.amb[uiBlock].mbt.abtKeyB, &mp.mpa.abtKey, 6);
180 bool bFailure =
false;
181 uint32_t uiReadBlocks = 0;
183 printf (
"Reading out %d blocks |", uiBlocks + 1);
186 for (iBlock = uiBlocks; iBlock >= 0; iBlock--) {
188 if (is_trailer_block (iBlock)) {
190 if (iBlock != uiBlocks)
191 print_success_or_failure (bFailure, &uiReadBlocks);
197 printf (
"!\nError: tag was removed\n");
206 if (!authenticate (iBlock)) {
207 printf (
"!\nError: authentication failed for block 0x%02x\n", iBlock);
211 if (nfc_initiator_mifare_cmd (pnd, MC_READ, iBlock, &mp)) {
213 memcpy (mtDump.amb[iBlock].mbt.abtKeyA, mtKeys.amb[iBlock].mbt.abtKeyA, 6);
214 memcpy (mtDump.amb[iBlock].mbt.abtAccessBits, mp.mpd.abtData + 6, 4);
215 memcpy (mtDump.amb[iBlock].mbt.abtKeyB, mtKeys.amb[iBlock].mbt.abtKeyB, 6);
217 printf (
"!\nError: unable to read trailer block 0x%02x\n", iBlock);
223 if (nfc_initiator_mifare_cmd (pnd, MC_READ, iBlock, &mp)) {
224 memcpy (mtDump.amb[iBlock].mbd.abtData, mp.mpd.abtData, 16);
227 printf (
"!\nError: unable to read block 0x%02x\n", iBlock);
233 print_success_or_failure (bFailure, &uiReadBlocks);
235 printf (
"Done, %d of %d blocks read.\n", uiReadBlocks, uiBlocks + 1);
245 bool bFailure =
false;
246 uint32_t uiWriteBlocks = 0;
248 printf (
"Writing %d blocks |", uiBlocks + 1);
251 for (uiBlock = 0; uiBlock <= uiBlocks; uiBlock++) {
253 if (is_first_block (uiBlock)) {
256 print_success_or_failure (bFailure, &uiWriteBlocks);
262 printf (
"!\nError: tag was removed\n");
271 if (!authenticate (uiBlock)) {
272 printf (
"!\nError: authentication failed for block %02x\n", uiBlock);
277 if (is_trailer_block (uiBlock)) {
279 memcpy (mp.mpd.abtData, mtDump.amb[uiBlock].mbt.abtKeyA, 6);
280 memcpy (mp.mpd.abtData + 6, mtDump.amb[uiBlock].mbt.abtAccessBits, 4);
281 memcpy (mp.mpd.abtData + 10, mtDump.amb[uiBlock].mbt.abtKeyB, 6);
284 if (nfc_initiator_mifare_cmd (pnd, MC_WRITE, uiBlock, &mp) ==
false) {
285 printf (
"failed to write trailer block %d \n", uiBlock);
296 memcpy (mp.mpd.abtData, mtDump.amb[uiBlock].mbd.abtData, 16);
297 if (!nfc_initiator_mifare_cmd (pnd, MC_WRITE, uiBlock, &mp))
302 print_success_or_failure (bFailure, &uiWriteBlocks);
304 printf (
"Done, %d of %d blocks written.\n", uiWriteBlocks, uiBlocks + 1);
311 mifare_classic_extract_payload (
const char *abDump,
char *pbPayload)
313 uint8_t uiSectorIndex;
314 uint8_t uiBlockIndex;
316 size_t szPayloadIndex = 0;
318 for (uiSectorIndex = 1; uiSectorIndex < 16; uiSectorIndex++) {
319 for (uiBlockIndex = 0; uiBlockIndex < 3; uiBlockIndex++) {
320 szDumpOffset = uiSectorIndex * 16 * 4 + uiBlockIndex * 16;
322 memcpy (pbPayload + szPayloadIndex, abDump + szDumpOffset, 16);
323 szPayloadIndex += 16;
336 print_usage (
const char *pcProgramName)
339 printf (
"%s r|w a|b <dump.mfd> [<keys.mfd>]\n", pcProgramName);
340 printf (
" r|w - Perform read from (r) or write to (w) card\n");
341 printf (
" a|b - Use A or B keys for action\n");
342 printf (
" <dump.mfd> - MiFare Dump (MFD) used to write (card to MFD) or (MFD to card)\n");
343 printf (
" <keys.mfd> - MiFare Dump (MFD) that contain the keys (optional)\n");
345 printf (
"%s x <dump.mfd> <payload.bin>\n", pcProgramName);
346 printf (
" x - Extract payload (data blocks) from MFD\n");
347 printf (
" <dump.mfd> - MiFare Dump (MFD) that contains wanted payload\n");
348 printf (
" <payload.bin> - Binary file where payload will be extracted\n");
352 main (
int argc,
const char *argv[])
355 action_t atAction = ACTION_USAGE;
359 const char *command = argv[1];
362 print_usage (argv[0]);
366 if (strcmp (command,
"r") == 0) {
367 atAction = ACTION_READ;
368 bUseKeyA = tolower ((
int) ((
unsigned char) *(argv[2]))) ==
'a';
369 bUseKeyFile = (argc > 4);
370 }
else if (strcmp (command,
"w") == 0) {
371 atAction = ACTION_WRITE;
372 bUseKeyA = tolower ((
int) ((
unsigned char) *(argv[2]))) ==
'a';
373 bUseKeyFile = (argc > 4);
374 }
else if (strcmp (command,
"x") == 0) {
375 atAction = ACTION_EXTRACT;
380 print_usage (argv[0]);
386 print_usage (argv[0]);
391 pfKeys = fopen (argv[4],
"rb");
392 if (pfKeys == NULL) {
393 printf (
"Could not open keys file: %s\n", argv[4]);
396 if (fread (&mtKeys, 1,
sizeof (mtKeys), pfKeys) !=
sizeof (mtKeys)) {
397 printf (
"Could not read keys file: %s\n", argv[4]);
404 if (atAction == ACTION_READ) {
405 memset (&mtDump, 0x00,
sizeof (mtDump));
407 pfDump = fopen (argv[3],
"rb");
409 if (pfDump == NULL) {
410 printf (
"Could not open dump file: %s\n", argv[3]);
414 if (fread (&mtDump, 1,
sizeof (mtDump), pfDump) !=
sizeof (mtDump)) {
415 printf (
"Could not read dump file: %s\n", argv[3]);
426 printf (
"Error connecting NFC reader\n");
458 printf (
"Connected to NFC reader: %s\n", pnd->
acName);
462 printf (
"Error: no tag was found\n");
467 if ((nt.nti.nai.btSak & 0x08) == 0) {
468 printf (
"Error: tag is not a MIFARE Classic card\n");
475 b4K = (mtKeys.amb[0].mbm.abtATQA[1] == 0x02);
476 pbtUID = mtKeys.amb[0].mbm.abtUID;
479 if (memcmp (nt.nti.nai.abtUid, pbtUID, 4) != 0) {
480 printf (
"Expected MIFARE Classic %ck card with UID: %02x%02x%02x%02x\n", b4K ?
'4' :
'1', pbtUID[3], pbtUID[2],
481 pbtUID[1], pbtUID[0]);
485 pbtUID = nt.nti.nai.abtUid;
486 b4K = (nt.nti.nai.abtAtqa[1] == 0x02);
487 printf (
"Found MIFARE Classic %ck card with UID: %02x%02x%02x%02x\n", b4K ?
'4' :
'1', pbtUID[3], pbtUID[2],
488 pbtUID[1], pbtUID[0]);
490 uiBlocks = (b4K) ? 0xff : 0x3f;
492 if (atAction == ACTION_READ) {
494 printf (
"Writing data to file: %s ...", argv[3]);
496 pfDump = fopen (argv[3],
"wb");
497 if (pfDump == NULL) {
498 printf (
"Could not open dump file: %s\n", argv[3]);
501 if (fwrite (&mtDump, 1,
sizeof (mtDump), pfDump) !=
sizeof (mtDump)) {
502 printf (
"\nCould not write to file: %s\n", argv[3]);
515 case ACTION_EXTRACT:{
516 const char *pcDump = argv[2];
517 const char *pcPayload = argv[3];
520 FILE *pfPayload = NULL;
523 char abPayload[4096];
525 pfDump = fopen (pcDump,
"rb");
527 if (pfDump == NULL) {
528 printf (
"Could not open dump file: %s\n", pcDump);
532 if (fread (abDump, 1,
sizeof (abDump), pfDump) !=
sizeof (abDump)) {
533 printf (
"Could not read dump file: %s\n", pcDump);
539 mifare_classic_extract_payload (abDump, abPayload);
541 printf (
"Writing data to file: %s\n", pcPayload);
542 pfPayload = fopen (pcPayload,
"wb");
543 if (pfPayload == NULL) {
544 printf (
"Could not open file %s for writting.\n", pcPayload);
547 if (fwrite (abPayload, 1,
sizeof (abPayload), pfPayload) !=
sizeof (abPayload)) {
548 printf (
"Could not write to file: %s\n", pcPayload);
552 printf (
"Done, all bytes have been extracted!\n");