nfc_magic_scene_mf_classic_dict_attack.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311
  1. #include "../nfc_magic_app_i.h"
  2. #include <dolphin/dolphin.h>
  3. #include <lib/nfc/protocols/mf_classic/mf_classic_poller.h>
  4. #include "views/dict_attack.h"
  5. #define TAG "NfcMagicMfClassicDictAttack"
  6. typedef enum {
  7. DictAttackStateUserDictInProgress,
  8. DictAttackStateSystemDictInProgress,
  9. } DictAttackState;
  10. NfcCommand nfc_dict_attack_worker_callback(NfcGenericEvent event, void* context) {
  11. furi_assert(context);
  12. furi_assert(event.event_data);
  13. furi_assert(event.instance);
  14. furi_assert(event.protocol == NfcProtocolMfClassic);
  15. NfcCommand command = NfcCommandContinue;
  16. MfClassicPollerEvent* mfc_event = event.event_data;
  17. NfcMagicApp* instance = context;
  18. if(mfc_event->type == MfClassicPollerEventTypeCardDetected) {
  19. instance->nfc_dict_context.is_card_present = true;
  20. view_dispatcher_send_custom_event(
  21. instance->view_dispatcher, NfcMagicAppCustomEventCardDetected);
  22. } else if(mfc_event->type == MfClassicPollerEventTypeCardLost) {
  23. instance->nfc_dict_context.is_card_present = false;
  24. view_dispatcher_send_custom_event(
  25. instance->view_dispatcher, NfcMagicAppCustomEventCardLost);
  26. } else if(mfc_event->type == MfClassicPollerEventTypeRequestMode) {
  27. const MfClassicData* mfc_data = nfc_poller_get_data(instance->poller);
  28. nfc_device_set_data(instance->target_dev, NfcProtocolMfClassic, mfc_data);
  29. FURI_LOG_D(TAG, "MFC type: %d", mfc_data->type);
  30. mfc_event->data->poller_mode.mode = MfClassicPollerModeDictAttack;
  31. mfc_event->data->poller_mode.data = mfc_data;
  32. instance->nfc_dict_context.sectors_total =
  33. mf_classic_get_total_sectors_num(mfc_data->type);
  34. FURI_LOG_D(TAG, "Total sectors: %d", mf_classic_get_total_sectors_num(mfc_data->type));
  35. mf_classic_get_read_sectors_and_keys(
  36. mfc_data,
  37. &instance->nfc_dict_context.sectors_read,
  38. &instance->nfc_dict_context.keys_found);
  39. view_dispatcher_send_custom_event(
  40. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  41. } else if(mfc_event->type == MfClassicPollerEventTypeRequestKey) {
  42. MfClassicKey key = {};
  43. if(keys_dict_get_next_key(
  44. instance->nfc_dict_context.dict, key.data, sizeof(MfClassicKey))) {
  45. mfc_event->data->key_request_data.key = key;
  46. mfc_event->data->key_request_data.key_provided = true;
  47. instance->nfc_dict_context.dict_keys_current++;
  48. if(instance->nfc_dict_context.dict_keys_current % 10 == 0) {
  49. view_dispatcher_send_custom_event(
  50. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  51. }
  52. } else {
  53. mfc_event->data->key_request_data.key_provided = false;
  54. }
  55. } else if(mfc_event->type == MfClassicPollerEventTypeDataUpdate) {
  56. MfClassicPollerEventDataUpdate* data_update = &mfc_event->data->data_update;
  57. instance->nfc_dict_context.sectors_read = data_update->sectors_read;
  58. instance->nfc_dict_context.keys_found = data_update->keys_found;
  59. instance->nfc_dict_context.current_sector = data_update->current_sector;
  60. view_dispatcher_send_custom_event(
  61. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  62. } else if(mfc_event->type == MfClassicPollerEventTypeNextSector) {
  63. keys_dict_rewind(instance->nfc_dict_context.dict);
  64. instance->nfc_dict_context.dict_keys_current = 0;
  65. instance->nfc_dict_context.current_sector =
  66. mfc_event->data->next_sector_data.current_sector;
  67. view_dispatcher_send_custom_event(
  68. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  69. } else if(mfc_event->type == MfClassicPollerEventTypeFoundKeyA) {
  70. view_dispatcher_send_custom_event(
  71. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  72. } else if(mfc_event->type == MfClassicPollerEventTypeFoundKeyB) {
  73. view_dispatcher_send_custom_event(
  74. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  75. } else if(mfc_event->type == MfClassicPollerEventTypeKeyAttackStart) {
  76. instance->nfc_dict_context.key_attack_current_sector =
  77. mfc_event->data->key_attack_data.current_sector;
  78. instance->nfc_dict_context.is_key_attack = true;
  79. view_dispatcher_send_custom_event(
  80. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  81. } else if(mfc_event->type == MfClassicPollerEventTypeKeyAttackStop) {
  82. keys_dict_rewind(instance->nfc_dict_context.dict);
  83. instance->nfc_dict_context.is_key_attack = false;
  84. instance->nfc_dict_context.dict_keys_current = 0;
  85. view_dispatcher_send_custom_event(
  86. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackDataUpdate);
  87. } else if(mfc_event->type == MfClassicPollerEventTypeSuccess) {
  88. const MfClassicData* mfc_data = nfc_poller_get_data(instance->poller);
  89. nfc_device_set_data(instance->target_dev, NfcProtocolMfClassic, mfc_data);
  90. view_dispatcher_send_custom_event(
  91. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackComplete);
  92. command = NfcCommandStop;
  93. }
  94. return command;
  95. }
  96. void nfc_dict_attack_dict_attack_result_callback(DictAttackEvent event, void* context) {
  97. furi_assert(context);
  98. NfcMagicApp* instance = context;
  99. if(event == DictAttackEventSkipPressed) {
  100. view_dispatcher_send_custom_event(
  101. instance->view_dispatcher, NfcMagicAppCustomEventDictAttackSkip);
  102. }
  103. }
  104. static void nfc_magic_scene_mf_classic_dict_attack_update_view(NfcMagicApp* instance) {
  105. NfcMagicAppMfClassicDictAttackContext* mfc_dict = &instance->nfc_dict_context;
  106. if(mfc_dict->is_key_attack) {
  107. dict_attack_set_key_attack(instance->dict_attack, mfc_dict->key_attack_current_sector);
  108. } else {
  109. dict_attack_reset_key_attack(instance->dict_attack);
  110. dict_attack_set_sectors_total(instance->dict_attack, mfc_dict->sectors_total);
  111. dict_attack_set_sectors_read(instance->dict_attack, mfc_dict->sectors_read);
  112. dict_attack_set_keys_found(instance->dict_attack, mfc_dict->keys_found);
  113. dict_attack_set_current_dict_key(instance->dict_attack, mfc_dict->dict_keys_current);
  114. dict_attack_set_current_sector(instance->dict_attack, mfc_dict->current_sector);
  115. }
  116. }
  117. static void nfc_magic_scene_mf_classic_dict_attack_prepare_view(NfcMagicApp* instance) {
  118. uint32_t state =
  119. scene_manager_get_scene_state(instance->scene_manager, NfcMagicSceneMfClassicDictAttack);
  120. if(state == DictAttackStateUserDictInProgress) {
  121. do {
  122. if(!keys_dict_check_presence(NFC_APP_MF_CLASSIC_DICT_USER_PATH)) {
  123. state = DictAttackStateSystemDictInProgress;
  124. break;
  125. }
  126. instance->nfc_dict_context.dict = keys_dict_alloc(
  127. NFC_APP_MF_CLASSIC_DICT_USER_PATH, KeysDictModeOpenAlways, sizeof(MfClassicKey));
  128. if(keys_dict_get_total_keys(instance->nfc_dict_context.dict) == 0) {
  129. keys_dict_free(instance->nfc_dict_context.dict);
  130. state = DictAttackStateSystemDictInProgress;
  131. break;
  132. }
  133. dict_attack_set_header(instance->dict_attack, "MF Classic User Dictionary");
  134. } while(false);
  135. }
  136. if(state == DictAttackStateSystemDictInProgress) {
  137. instance->nfc_dict_context.dict = keys_dict_alloc(
  138. NFC_APP_MF_CLASSIC_DICT_SYSTEM_PATH, KeysDictModeOpenExisting, sizeof(MfClassicKey));
  139. dict_attack_set_header(instance->dict_attack, "MF Classic System Dictionary");
  140. }
  141. instance->nfc_dict_context.dict_keys_total =
  142. keys_dict_get_total_keys(instance->nfc_dict_context.dict);
  143. dict_attack_set_total_dict_keys(
  144. instance->dict_attack, instance->nfc_dict_context.dict_keys_total);
  145. instance->nfc_dict_context.dict_keys_current = 0;
  146. dict_attack_set_callback(
  147. instance->dict_attack, nfc_dict_attack_dict_attack_result_callback, instance);
  148. nfc_magic_scene_mf_classic_dict_attack_update_view(instance);
  149. scene_manager_set_scene_state(
  150. instance->scene_manager, NfcMagicSceneMfClassicDictAttack, state);
  151. }
  152. void nfc_magic_scene_mf_classic_dict_attack_on_enter(void* context) {
  153. NfcMagicApp* instance = context;
  154. scene_manager_set_scene_state(
  155. instance->scene_manager,
  156. NfcMagicSceneMfClassicDictAttack,
  157. DictAttackStateUserDictInProgress);
  158. nfc_magic_scene_mf_classic_dict_attack_prepare_view(instance);
  159. dict_attack_set_card_state(instance->dict_attack, true);
  160. view_dispatcher_switch_to_view(instance->view_dispatcher, NfcMagicAppViewDictAttack);
  161. nfc_magic_app_blink_start(instance);
  162. notification_message(instance->notifications, &sequence_display_backlight_enforce_on);
  163. instance->poller = nfc_poller_alloc(instance->nfc, NfcProtocolMfClassic);
  164. nfc_poller_start(instance->poller, nfc_dict_attack_worker_callback, instance);
  165. }
  166. static void nfc_magic_scene_mf_classic_dict_attack_notify_read(NfcMagicApp* instance) {
  167. const MfClassicData* mfc_data = nfc_poller_get_data(instance->poller);
  168. bool is_card_fully_read = mf_classic_is_card_read(mfc_data);
  169. if(is_card_fully_read) {
  170. notification_message(instance->notifications, &sequence_success);
  171. } else {
  172. notification_message(instance->notifications, &sequence_semi_success);
  173. }
  174. }
  175. bool nfc_magic_scene_mf_classic_dict_attack_on_event(void* context, SceneManagerEvent event) {
  176. NfcMagicApp* instance = context;
  177. bool consumed = false;
  178. uint32_t state =
  179. scene_manager_get_scene_state(instance->scene_manager, NfcMagicSceneMfClassicDictAttack);
  180. if(event.type == SceneManagerEventTypeCustom) {
  181. if(event.event == NfcMagicAppCustomEventDictAttackComplete) {
  182. if(state == DictAttackStateUserDictInProgress) {
  183. nfc_poller_stop(instance->poller);
  184. nfc_poller_free(instance->poller);
  185. keys_dict_free(instance->nfc_dict_context.dict);
  186. scene_manager_set_scene_state(
  187. instance->scene_manager,
  188. NfcMagicSceneMfClassicDictAttack,
  189. DictAttackStateSystemDictInProgress);
  190. nfc_magic_scene_mf_classic_dict_attack_prepare_view(instance);
  191. instance->poller = nfc_poller_alloc(instance->nfc, NfcProtocolMfClassic);
  192. nfc_poller_start(instance->poller, nfc_dict_attack_worker_callback, instance);
  193. consumed = true;
  194. } else {
  195. nfc_magic_scene_mf_classic_dict_attack_notify_read(instance);
  196. if(instance->protocol == NfcMagicProtocolGen2) {
  197. scene_manager_next_scene(instance->scene_manager, NfcMagicSceneGen2WriteCheck);
  198. } else {
  199. scene_manager_next_scene(
  200. instance->scene_manager, NfcMagicSceneMfClassicWriteCheck);
  201. }
  202. dolphin_deed(DolphinDeedNfcReadSuccess);
  203. consumed = true;
  204. }
  205. } else if(event.event == NfcMagicAppCustomEventCardDetected) {
  206. dict_attack_set_card_state(instance->dict_attack, true);
  207. consumed = true;
  208. } else if(event.event == NfcMagicAppCustomEventCardLost) {
  209. dict_attack_set_card_state(instance->dict_attack, false);
  210. consumed = true;
  211. } else if(event.event == NfcMagicAppCustomEventDictAttackDataUpdate) {
  212. nfc_magic_scene_mf_classic_dict_attack_update_view(instance);
  213. } else if(event.event == NfcMagicAppCustomEventDictAttackSkip) {
  214. const MfClassicData* mfc_data = nfc_poller_get_data(instance->poller);
  215. nfc_device_set_data(instance->target_dev, NfcProtocolMfClassic, mfc_data);
  216. if(state == DictAttackStateUserDictInProgress) {
  217. if(instance->nfc_dict_context.is_card_present) {
  218. nfc_poller_stop(instance->poller);
  219. nfc_poller_free(instance->poller);
  220. keys_dict_free(instance->nfc_dict_context.dict);
  221. scene_manager_set_scene_state(
  222. instance->scene_manager,
  223. NfcMagicSceneMfClassicDictAttack,
  224. DictAttackStateSystemDictInProgress);
  225. nfc_magic_scene_mf_classic_dict_attack_prepare_view(instance);
  226. instance->poller = nfc_poller_alloc(instance->nfc, NfcProtocolMfClassic);
  227. nfc_poller_start(instance->poller, nfc_dict_attack_worker_callback, instance);
  228. } else {
  229. nfc_magic_scene_mf_classic_dict_attack_notify_read(instance);
  230. if(instance->protocol == NfcMagicProtocolGen2) {
  231. scene_manager_next_scene(
  232. instance->scene_manager, NfcMagicSceneGen2WriteCheck);
  233. } else {
  234. scene_manager_next_scene(
  235. instance->scene_manager, NfcMagicSceneMfClassicWriteCheck);
  236. }
  237. dolphin_deed(DolphinDeedNfcReadSuccess);
  238. }
  239. consumed = true;
  240. } else if(state == DictAttackStateSystemDictInProgress) {
  241. nfc_magic_scene_mf_classic_dict_attack_notify_read(instance);
  242. if(instance->protocol == NfcMagicProtocolGen2) {
  243. scene_manager_next_scene(instance->scene_manager, NfcMagicSceneGen2WriteCheck);
  244. } else {
  245. scene_manager_next_scene(
  246. instance->scene_manager, NfcMagicSceneMfClassicWriteCheck);
  247. }
  248. dolphin_deed(DolphinDeedNfcReadSuccess);
  249. consumed = true;
  250. }
  251. }
  252. } else if(event.type == SceneManagerEventTypeBack) {
  253. scene_manager_previous_scene(instance->scene_manager);
  254. consumed = true;
  255. }
  256. return consumed;
  257. }
  258. void nfc_magic_scene_mf_classic_dict_attack_on_exit(void* context) {
  259. NfcMagicApp* instance = context;
  260. const MfClassicData* mfc_data = nfc_poller_get_data(instance->poller);
  261. nfc_device_set_data(instance->target_dev, NfcProtocolMfClassic, mfc_data);
  262. nfc_poller_stop(instance->poller);
  263. nfc_poller_free(instance->poller);
  264. dict_attack_reset(instance->dict_attack);
  265. scene_manager_set_scene_state(
  266. instance->scene_manager,
  267. NfcMagicSceneMfClassicDictAttack,
  268. DictAttackStateUserDictInProgress);
  269. keys_dict_free(instance->nfc_dict_context.dict);
  270. instance->nfc_dict_context.current_sector = 0;
  271. instance->nfc_dict_context.sectors_total = 0;
  272. instance->nfc_dict_context.sectors_read = 0;
  273. instance->nfc_dict_context.keys_found = 0;
  274. instance->nfc_dict_context.dict_keys_total = 0;
  275. instance->nfc_dict_context.dict_keys_current = 0;
  276. instance->nfc_dict_context.is_key_attack = false;
  277. instance->nfc_dict_context.key_attack_current_sector = 0;
  278. instance->nfc_dict_context.is_card_present = false;
  279. nfc_magic_app_blink_stop(instance);
  280. notification_message(instance->notifications, &sequence_display_backlight_enforce_auto);
  281. }