nfc_worker.c 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <platform.h>
  4. #include "parsers/nfc_supported_card.h"
  5. #define TAG "NfcWorker"
  6. /***************************** NFC Worker API *******************************/
  7. NfcWorker* nfc_worker_alloc() {
  8. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  9. // Worker thread attributes
  10. nfc_worker->thread = furi_thread_alloc();
  11. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  12. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  13. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  14. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  15. nfc_worker->callback = NULL;
  16. nfc_worker->context = NULL;
  17. nfc_worker->storage = furi_record_open(RECORD_STORAGE);
  18. // Initialize rfal
  19. while(furi_hal_nfc_is_busy()) {
  20. furi_delay_ms(10);
  21. }
  22. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  23. nfc_worker->reader_analyzer = reader_analyzer_alloc(nfc_worker->storage);
  24. return nfc_worker;
  25. }
  26. void nfc_worker_free(NfcWorker* nfc_worker) {
  27. furi_assert(nfc_worker);
  28. furi_thread_free(nfc_worker->thread);
  29. furi_record_close(RECORD_STORAGE);
  30. reader_analyzer_free(nfc_worker->reader_analyzer);
  31. free(nfc_worker);
  32. }
  33. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  34. return nfc_worker->state;
  35. }
  36. void nfc_worker_start(
  37. NfcWorker* nfc_worker,
  38. NfcWorkerState state,
  39. NfcDeviceData* dev_data,
  40. NfcWorkerCallback callback,
  41. void* context) {
  42. furi_assert(nfc_worker);
  43. furi_assert(dev_data);
  44. while(furi_hal_nfc_is_busy()) {
  45. furi_delay_ms(10);
  46. }
  47. nfc_worker->callback = callback;
  48. nfc_worker->context = context;
  49. nfc_worker->dev_data = dev_data;
  50. nfc_worker_change_state(nfc_worker, state);
  51. furi_thread_start(nfc_worker->thread);
  52. }
  53. void nfc_worker_stop(NfcWorker* nfc_worker) {
  54. furi_assert(nfc_worker);
  55. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  56. return;
  57. }
  58. furi_hal_nfc_stop();
  59. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  60. furi_thread_join(nfc_worker->thread);
  61. }
  62. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  63. nfc_worker->state = state;
  64. }
  65. /***************************** NFC Worker Thread *******************************/
  66. int32_t nfc_worker_task(void* context) {
  67. NfcWorker* nfc_worker = context;
  68. furi_hal_nfc_exit_sleep();
  69. if(nfc_worker->state == NfcWorkerStateRead) {
  70. nfc_worker_read(nfc_worker);
  71. } else if(nfc_worker->state == NfcWorkerStateUidEmulate) {
  72. nfc_worker_emulate_uid(nfc_worker);
  73. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  74. nfc_worker_emulate_apdu(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateMfUltralightEmulate) {
  76. nfc_worker_emulate_mf_ultralight(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateMfClassicEmulate) {
  78. nfc_worker_emulate_mf_classic(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateReadMfUltralightReadAuth) {
  80. nfc_worker_mf_ultralight_read_auth(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateMfClassicDictAttack) {
  82. nfc_worker_mf_classic_dict_attack(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateAnalyzeReader) {
  84. nfc_worker_analyze_reader(nfc_worker);
  85. }
  86. furi_hal_nfc_sleep();
  87. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  88. return 0;
  89. }
  90. static bool nfc_worker_read_mf_ultralight(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  91. bool read_success = false;
  92. MfUltralightReader reader = {};
  93. MfUltralightData data = {};
  94. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  95. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, tx_rx, false);
  96. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  97. }
  98. do {
  99. // Try to read supported card
  100. FURI_LOG_I(TAG, "Trying to read a supported card ...");
  101. for(size_t i = 0; i < NfcSupportedCardTypeEnd; i++) {
  102. if(nfc_supported_card[i].protocol == NfcDeviceProtocolMifareUl) {
  103. if(nfc_supported_card[i].verify(nfc_worker, tx_rx)) {
  104. if(nfc_supported_card[i].read(nfc_worker, tx_rx)) {
  105. read_success = true;
  106. nfc_supported_card[i].parse(nfc_worker->dev_data);
  107. break;
  108. }
  109. } else {
  110. furi_hal_nfc_sleep();
  111. }
  112. }
  113. }
  114. if(read_success) break;
  115. furi_hal_nfc_sleep();
  116. // Otherwise, try to read as usual
  117. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 200)) break;
  118. if(!mf_ul_read_card(tx_rx, &reader, &data)) break;
  119. // Copy data
  120. nfc_worker->dev_data->mf_ul_data = data;
  121. read_success = true;
  122. } while(false);
  123. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  124. reader_analyzer_stop(nfc_worker->reader_analyzer);
  125. }
  126. return read_success;
  127. }
  128. static bool nfc_worker_read_mf_classic(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  129. furi_assert(nfc_worker->callback);
  130. bool read_success = false;
  131. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  132. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, tx_rx, false);
  133. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  134. }
  135. do {
  136. // Try to read supported card
  137. FURI_LOG_I(TAG, "Trying to read a supported card ...");
  138. for(size_t i = 0; i < NfcSupportedCardTypeEnd; i++) {
  139. if(nfc_supported_card[i].protocol == NfcDeviceProtocolMifareClassic) {
  140. if(nfc_supported_card[i].verify(nfc_worker, tx_rx)) {
  141. if(nfc_supported_card[i].read(nfc_worker, tx_rx)) {
  142. read_success = true;
  143. nfc_supported_card[i].parse(nfc_worker->dev_data);
  144. break;
  145. }
  146. } else {
  147. furi_hal_nfc_sleep();
  148. }
  149. }
  150. }
  151. if(read_success) break;
  152. // Try to read card with key cache
  153. FURI_LOG_I(TAG, "Search for key cache ...");
  154. if(nfc_worker->callback(NfcWorkerEventReadMfClassicLoadKeyCache, nfc_worker->context)) {
  155. FURI_LOG_I(TAG, "Load keys cache success. Start reading");
  156. uint8_t sectors_read =
  157. mf_classic_update_card(tx_rx, &nfc_worker->dev_data->mf_classic_data);
  158. uint8_t sectors_total =
  159. mf_classic_get_total_sectors_num(nfc_worker->dev_data->mf_classic_data.type);
  160. FURI_LOG_I(TAG, "Read %d sectors out of %d total", sectors_read, sectors_total);
  161. read_success = mf_classic_is_card_read(&nfc_worker->dev_data->mf_classic_data);
  162. }
  163. } while(false);
  164. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  165. reader_analyzer_stop(nfc_worker->reader_analyzer);
  166. }
  167. return read_success;
  168. }
  169. static bool nfc_worker_read_mf_desfire(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  170. bool read_success = false;
  171. MifareDesfireData* data = &nfc_worker->dev_data->mf_df_data;
  172. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  173. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, tx_rx, false);
  174. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  175. }
  176. do {
  177. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 300)) break;
  178. if(!mf_df_read_card(tx_rx, data)) break;
  179. read_success = true;
  180. } while(false);
  181. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  182. reader_analyzer_stop(nfc_worker->reader_analyzer);
  183. }
  184. return read_success;
  185. }
  186. static bool nfc_worker_read_bank_card(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  187. bool read_success = false;
  188. EmvApplication emv_app = {};
  189. EmvData* result = &nfc_worker->dev_data->emv_data;
  190. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  191. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, tx_rx, false);
  192. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  193. }
  194. // Bank cards require strong field to start application. If we find AID, try at least several
  195. // times to start EMV application
  196. uint8_t start_application_attempts = 0;
  197. while(start_application_attempts < 3) {
  198. if(nfc_worker->state != NfcWorkerStateRead) break;
  199. start_application_attempts++;
  200. if(!furi_hal_nfc_detect(&nfc_worker->dev_data->nfc_data, 300)) break;
  201. if(emv_read_bank_card(tx_rx, &emv_app)) {
  202. FURI_LOG_D(TAG, "Bank card number read from %d attempt", start_application_attempts);
  203. break;
  204. } else if(emv_app.aid_len && !emv_app.app_started) {
  205. FURI_LOG_D(
  206. TAG,
  207. "AID found but failed to start EMV app from %d attempt",
  208. start_application_attempts);
  209. furi_hal_nfc_sleep();
  210. continue;
  211. } else {
  212. FURI_LOG_D(TAG, "Failed to find AID");
  213. break;
  214. }
  215. }
  216. // Copy data
  217. if(emv_app.aid_len) {
  218. result->aid_len = emv_app.aid_len;
  219. memcpy(result->aid, emv_app.aid, result->aid_len);
  220. read_success = true;
  221. }
  222. if(emv_app.card_number_len) {
  223. result->number_len = emv_app.card_number_len;
  224. memcpy(result->number, emv_app.card_number, result->number_len);
  225. }
  226. if(emv_app.name_found) {
  227. memcpy(result->name, emv_app.name, sizeof(emv_app.name));
  228. }
  229. if(emv_app.exp_month) {
  230. result->exp_mon = emv_app.exp_month;
  231. result->exp_year = emv_app.exp_year;
  232. }
  233. if(emv_app.country_code) {
  234. result->country_code = emv_app.country_code;
  235. }
  236. if(emv_app.currency_code) {
  237. result->currency_code = emv_app.currency_code;
  238. }
  239. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  240. reader_analyzer_stop(nfc_worker->reader_analyzer);
  241. }
  242. return read_success;
  243. }
  244. static bool nfc_worker_read_nfca(NfcWorker* nfc_worker, FuriHalNfcTxRxContext* tx_rx) {
  245. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  246. bool card_read = false;
  247. furi_hal_nfc_sleep();
  248. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  249. FURI_LOG_I(TAG, "Mifare Ultralight / NTAG detected");
  250. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareUl;
  251. card_read = nfc_worker_read_mf_ultralight(nfc_worker, tx_rx);
  252. } else if(mf_classic_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  253. FURI_LOG_I(TAG, "Mifare Classic detected");
  254. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  255. nfc_worker->dev_data->mf_classic_data.type =
  256. mf_classic_get_classic_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak);
  257. card_read = nfc_worker_read_mf_classic(nfc_worker, tx_rx);
  258. } else if(mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  259. FURI_LOG_I(TAG, "Mifare DESFire detected");
  260. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  261. if(!nfc_worker_read_mf_desfire(nfc_worker, tx_rx)) {
  262. FURI_LOG_I(TAG, "Unknown card. Save UID");
  263. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  264. }
  265. card_read = true;
  266. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  267. FURI_LOG_I(TAG, "ISO14443-4 card detected");
  268. nfc_worker->dev_data->protocol = NfcDeviceProtocolEMV;
  269. if(!nfc_worker_read_bank_card(nfc_worker, tx_rx)) {
  270. FURI_LOG_I(TAG, "Unknown card. Save UID");
  271. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  272. }
  273. card_read = true;
  274. } else {
  275. nfc_worker->dev_data->protocol = NfcDeviceProtocolUnknown;
  276. card_read = true;
  277. }
  278. return card_read;
  279. }
  280. void nfc_worker_read(NfcWorker* nfc_worker) {
  281. furi_assert(nfc_worker);
  282. furi_assert(nfc_worker->callback);
  283. nfc_device_data_clear(nfc_worker->dev_data);
  284. NfcDeviceData* dev_data = nfc_worker->dev_data;
  285. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  286. FuriHalNfcTxRxContext tx_rx = {};
  287. NfcWorkerEvent event = 0;
  288. bool card_not_detected_notified = false;
  289. while(nfc_worker->state == NfcWorkerStateRead) {
  290. if(furi_hal_nfc_detect(nfc_data, 300)) {
  291. // Process first found device
  292. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  293. card_not_detected_notified = false;
  294. if(nfc_data->type == FuriHalNfcTypeA) {
  295. if(nfc_worker_read_nfca(nfc_worker, &tx_rx)) {
  296. if(dev_data->protocol == NfcDeviceProtocolMifareUl) {
  297. event = NfcWorkerEventReadMfUltralight;
  298. break;
  299. } else if(dev_data->protocol == NfcDeviceProtocolMifareClassic) {
  300. event = NfcWorkerEventReadMfClassicDone;
  301. break;
  302. } else if(dev_data->protocol == NfcDeviceProtocolMifareDesfire) {
  303. event = NfcWorkerEventReadMfDesfire;
  304. break;
  305. } else if(dev_data->protocol == NfcDeviceProtocolEMV) {
  306. event = NfcWorkerEventReadBankCard;
  307. break;
  308. } else if(dev_data->protocol == NfcDeviceProtocolUnknown) {
  309. event = NfcWorkerEventReadUidNfcA;
  310. break;
  311. }
  312. } else {
  313. if(dev_data->protocol == NfcDeviceProtocolMifareClassic) {
  314. event = NfcWorkerEventReadMfClassicDictAttackRequired;
  315. break;
  316. }
  317. }
  318. } else if(nfc_data->type == FuriHalNfcTypeB) {
  319. event = NfcWorkerEventReadUidNfcB;
  320. break;
  321. } else if(nfc_data->type == FuriHalNfcTypeF) {
  322. event = NfcWorkerEventReadUidNfcF;
  323. break;
  324. } else if(nfc_data->type == FuriHalNfcTypeV) {
  325. event = NfcWorkerEventReadUidNfcV;
  326. break;
  327. }
  328. } else {
  329. if(!card_not_detected_notified) {
  330. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  331. card_not_detected_notified = true;
  332. }
  333. }
  334. furi_hal_nfc_sleep();
  335. furi_delay_ms(100);
  336. }
  337. // Notify caller and exit
  338. if(event > NfcWorkerEventReserved) {
  339. nfc_worker->callback(event, nfc_worker->context);
  340. }
  341. }
  342. void nfc_worker_emulate_uid(NfcWorker* nfc_worker) {
  343. FuriHalNfcTxRxContext tx_rx = {};
  344. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  345. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  346. // TODO add support for RATS
  347. // Need to save ATS to support ISO-14443A-4 emulation
  348. while(nfc_worker->state == NfcWorkerStateUidEmulate) {
  349. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, false, 100)) {
  350. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  351. reader_data->size = tx_rx.rx_bits / 8;
  352. if(reader_data->size > 0) {
  353. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  354. if(nfc_worker->callback) {
  355. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  356. }
  357. }
  358. } else {
  359. FURI_LOG_E(TAG, "Failed to get reader commands");
  360. }
  361. }
  362. }
  363. }
  364. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  365. FuriHalNfcTxRxContext tx_rx = {};
  366. FuriHalNfcDevData params = {
  367. .uid = {0xCF, 0x72, 0xd4, 0x40},
  368. .uid_len = 4,
  369. .atqa = {0x00, 0x04},
  370. .sak = 0x20,
  371. .type = FuriHalNfcTypeA,
  372. };
  373. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  374. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, &tx_rx, true);
  375. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  376. }
  377. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  378. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  379. FURI_LOG_D(TAG, "POS terminal detected");
  380. if(emv_card_emulation(&tx_rx)) {
  381. FURI_LOG_D(TAG, "EMV card emulated");
  382. }
  383. } else {
  384. FURI_LOG_D(TAG, "Can't find reader");
  385. }
  386. furi_hal_nfc_sleep();
  387. furi_delay_ms(20);
  388. }
  389. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  390. reader_analyzer_stop(nfc_worker->reader_analyzer);
  391. }
  392. }
  393. void nfc_worker_emulate_mf_ultralight(NfcWorker* nfc_worker) {
  394. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  395. MfUltralightEmulator emulator = {};
  396. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  397. while(nfc_worker->state == NfcWorkerStateMfUltralightEmulate) {
  398. mf_ul_reset_emulation(&emulator, true);
  399. furi_hal_nfc_emulate_nfca(
  400. nfc_data->uid,
  401. nfc_data->uid_len,
  402. nfc_data->atqa,
  403. nfc_data->sak,
  404. mf_ul_prepare_emulation_response,
  405. &emulator,
  406. 5000);
  407. // Check if data was modified
  408. if(emulator.data_changed) {
  409. nfc_worker->dev_data->mf_ul_data = emulator.data;
  410. if(nfc_worker->callback) {
  411. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  412. }
  413. emulator.data_changed = false;
  414. }
  415. }
  416. }
  417. static void nfc_worker_mf_classic_key_attack(
  418. NfcWorker* nfc_worker,
  419. uint64_t key,
  420. FuriHalNfcTxRxContext* tx_rx,
  421. uint16_t start_sector) {
  422. furi_assert(nfc_worker);
  423. bool card_found_notified = true;
  424. bool card_removed_notified = false;
  425. MfClassicData* data = &nfc_worker->dev_data->mf_classic_data;
  426. uint32_t total_sectors = mf_classic_get_total_sectors_num(data->type);
  427. furi_assert(start_sector < total_sectors);
  428. // Check every sector's A and B keys with the given key
  429. for(size_t i = start_sector; i < total_sectors; i++) {
  430. furi_hal_nfc_sleep();
  431. if(furi_hal_nfc_activate_nfca(200, NULL)) {
  432. furi_hal_nfc_sleep();
  433. if(!card_found_notified) {
  434. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  435. card_found_notified = true;
  436. card_removed_notified = false;
  437. }
  438. uint8_t block_num = mf_classic_get_sector_trailer_block_num_by_sector(i);
  439. if(mf_classic_is_sector_read(data, i)) continue;
  440. if(!mf_classic_is_key_found(data, i, MfClassicKeyA)) {
  441. FURI_LOG_D(
  442. TAG,
  443. "Trying A key for sector %d, key: %04lx%08lx",
  444. i,
  445. (uint32_t)(key >> 32),
  446. (uint32_t)key);
  447. if(mf_classic_authenticate(tx_rx, block_num, key, MfClassicKeyA)) {
  448. mf_classic_set_key_found(data, i, MfClassicKeyA, key);
  449. FURI_LOG_D(TAG, "Key found");
  450. nfc_worker->callback(NfcWorkerEventFoundKeyA, nfc_worker->context);
  451. }
  452. }
  453. if(!mf_classic_is_key_found(data, i, MfClassicKeyB)) {
  454. FURI_LOG_D(
  455. TAG,
  456. "Trying B key for sector %d, key: %04lx%08lx",
  457. i,
  458. (uint32_t)(key >> 32),
  459. (uint32_t)key);
  460. if(mf_classic_authenticate(tx_rx, block_num, key, MfClassicKeyB)) {
  461. mf_classic_set_key_found(data, i, MfClassicKeyB, key);
  462. FURI_LOG_D(TAG, "Key found");
  463. nfc_worker->callback(NfcWorkerEventFoundKeyB, nfc_worker->context);
  464. }
  465. }
  466. if(mf_classic_is_sector_read(data, i)) continue;
  467. mf_classic_read_sector(tx_rx, data, i);
  468. } else {
  469. if(!card_removed_notified) {
  470. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  471. card_removed_notified = true;
  472. card_found_notified = false;
  473. }
  474. }
  475. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  476. }
  477. }
  478. void nfc_worker_mf_classic_dict_attack(NfcWorker* nfc_worker) {
  479. furi_assert(nfc_worker);
  480. furi_assert(nfc_worker->callback);
  481. MfClassicData* data = &nfc_worker->dev_data->mf_classic_data;
  482. NfcMfClassicDictAttackData* dict_attack_data =
  483. &nfc_worker->dev_data->mf_classic_dict_attack_data;
  484. uint32_t total_sectors = mf_classic_get_total_sectors_num(data->type);
  485. uint64_t key = 0;
  486. uint64_t prev_key = 0;
  487. FuriHalNfcTxRxContext tx_rx = {};
  488. bool card_found_notified = true;
  489. bool card_removed_notified = false;
  490. // Load dictionary
  491. MfClassicDict* dict = dict_attack_data->dict;
  492. if(!dict) {
  493. FURI_LOG_E(TAG, "Dictionary not found");
  494. nfc_worker->callback(NfcWorkerEventNoDictFound, nfc_worker->context);
  495. return;
  496. }
  497. FURI_LOG_D(
  498. TAG, "Start Dictionary attack, Key Count %ld", mf_classic_dict_get_total_keys(dict));
  499. for(size_t i = 0; i < total_sectors; i++) {
  500. FURI_LOG_I(TAG, "Sector %d", i);
  501. nfc_worker->callback(NfcWorkerEventNewSector, nfc_worker->context);
  502. uint8_t block_num = mf_classic_get_sector_trailer_block_num_by_sector(i);
  503. if(mf_classic_is_sector_read(data, i)) continue;
  504. bool is_key_a_found = mf_classic_is_key_found(data, i, MfClassicKeyA);
  505. bool is_key_b_found = mf_classic_is_key_found(data, i, MfClassicKeyB);
  506. uint16_t key_index = 0;
  507. while(mf_classic_dict_get_next_key(dict, &key)) {
  508. FURI_LOG_T(TAG, "Key %d", key_index);
  509. if(++key_index % NFC_DICT_KEY_BATCH_SIZE == 0) {
  510. nfc_worker->callback(NfcWorkerEventNewDictKeyBatch, nfc_worker->context);
  511. }
  512. furi_hal_nfc_sleep();
  513. if(furi_hal_nfc_activate_nfca(200, NULL)) {
  514. furi_hal_nfc_sleep();
  515. if(!card_found_notified) {
  516. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  517. card_found_notified = true;
  518. card_removed_notified = false;
  519. nfc_worker_mf_classic_key_attack(nfc_worker, prev_key, &tx_rx, i);
  520. }
  521. FURI_LOG_D(
  522. TAG,
  523. "Try to auth to sector %d with key %04lx%08lx",
  524. i,
  525. (uint32_t)(key >> 32),
  526. (uint32_t)key);
  527. if(!is_key_a_found) {
  528. is_key_a_found = mf_classic_is_key_found(data, i, MfClassicKeyA);
  529. if(mf_classic_authenticate(&tx_rx, block_num, key, MfClassicKeyA)) {
  530. mf_classic_set_key_found(data, i, MfClassicKeyA, key);
  531. FURI_LOG_D(TAG, "Key found");
  532. nfc_worker->callback(NfcWorkerEventFoundKeyA, nfc_worker->context);
  533. nfc_worker_mf_classic_key_attack(nfc_worker, key, &tx_rx, i + 1);
  534. }
  535. furi_hal_nfc_sleep();
  536. }
  537. if(!is_key_b_found) {
  538. is_key_b_found = mf_classic_is_key_found(data, i, MfClassicKeyB);
  539. if(mf_classic_authenticate(&tx_rx, block_num, key, MfClassicKeyB)) {
  540. FURI_LOG_D(TAG, "Key found");
  541. mf_classic_set_key_found(data, i, MfClassicKeyB, key);
  542. nfc_worker->callback(NfcWorkerEventFoundKeyB, nfc_worker->context);
  543. nfc_worker_mf_classic_key_attack(nfc_worker, key, &tx_rx, i + 1);
  544. }
  545. }
  546. if(is_key_a_found && is_key_b_found) break;
  547. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  548. } else {
  549. if(!card_removed_notified) {
  550. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  551. card_removed_notified = true;
  552. card_found_notified = false;
  553. }
  554. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  555. }
  556. memcpy(&prev_key, &key, sizeof(key));
  557. }
  558. if(nfc_worker->state != NfcWorkerStateMfClassicDictAttack) break;
  559. mf_classic_read_sector(&tx_rx, data, i);
  560. mf_classic_dict_rewind(dict);
  561. }
  562. if(nfc_worker->state == NfcWorkerStateMfClassicDictAttack) {
  563. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  564. } else {
  565. nfc_worker->callback(NfcWorkerEventAborted, nfc_worker->context);
  566. }
  567. }
  568. void nfc_worker_emulate_mf_classic(NfcWorker* nfc_worker) {
  569. FuriHalNfcTxRxContext tx_rx = {};
  570. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  571. MfClassicEmulator emulator = {
  572. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  573. .data = nfc_worker->dev_data->mf_classic_data,
  574. .data_changed = false,
  575. };
  576. NfcaSignal* nfca_signal = nfca_signal_alloc();
  577. tx_rx.nfca_signal = nfca_signal;
  578. rfal_platform_spi_acquire();
  579. furi_hal_nfc_listen_start(nfc_data);
  580. while(nfc_worker->state == NfcWorkerStateMfClassicEmulate) {
  581. if(furi_hal_nfc_listen_rx(&tx_rx, 300)) {
  582. mf_classic_emulator(&emulator, &tx_rx);
  583. }
  584. }
  585. if(emulator.data_changed) {
  586. nfc_worker->dev_data->mf_classic_data = emulator.data;
  587. if(nfc_worker->callback) {
  588. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  589. }
  590. emulator.data_changed = false;
  591. }
  592. nfca_signal_free(nfca_signal);
  593. rfal_platform_spi_release();
  594. }
  595. void nfc_worker_mf_ultralight_read_auth(NfcWorker* nfc_worker) {
  596. furi_assert(nfc_worker);
  597. furi_assert(nfc_worker->callback);
  598. MfUltralightData* data = &nfc_worker->dev_data->mf_ul_data;
  599. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  600. FuriHalNfcTxRxContext tx_rx = {};
  601. MfUltralightReader reader = {};
  602. mf_ul_reset(data);
  603. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  604. reader_analyzer_prepare_tx_rx(nfc_worker->reader_analyzer, &tx_rx, true);
  605. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeDebugLog);
  606. }
  607. uint32_t key = 0;
  608. uint16_t pack = 0;
  609. while(nfc_worker->state == NfcWorkerStateReadMfUltralightReadAuth) {
  610. furi_hal_nfc_sleep();
  611. if(furi_hal_nfc_detect(nfc_data, 300) && nfc_data->type == FuriHalNfcTypeA) {
  612. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  613. nfc_worker->callback(NfcWorkerEventCardDetected, nfc_worker->context);
  614. if(data->auth_method == MfUltralightAuthMethodManual) {
  615. nfc_worker->callback(NfcWorkerEventMfUltralightPassKey, nfc_worker->context);
  616. key = nfc_util_bytes2num(data->auth_key, 4);
  617. } else if(data->auth_method == MfUltralightAuthMethodAmeebo) {
  618. key = mf_ul_pwdgen_amiibo(nfc_data);
  619. } else if(data->auth_method == MfUltralightAuthMethodXiaomi) {
  620. key = mf_ul_pwdgen_xiaomi(nfc_data);
  621. } else {
  622. FURI_LOG_E(TAG, "Incorrect auth method");
  623. break;
  624. }
  625. data->auth_success = mf_ultralight_authenticate(&tx_rx, key, &pack);
  626. if(!data->auth_success) {
  627. // Reset card
  628. furi_hal_nfc_sleep();
  629. if(!furi_hal_nfc_activate_nfca(300, NULL)) {
  630. nfc_worker->callback(NfcWorkerEventFail, nfc_worker->context);
  631. break;
  632. }
  633. }
  634. mf_ul_read_card(&tx_rx, &reader, data);
  635. if(data->auth_success) {
  636. MfUltralightConfigPages* config_pages = mf_ultralight_get_config_pages(data);
  637. if(config_pages != NULL) {
  638. config_pages->auth_data.pwd.value = REVERSE_BYTES_U32(key);
  639. config_pages->auth_data.pack.value = pack;
  640. }
  641. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  642. break;
  643. } else {
  644. nfc_worker->callback(NfcWorkerEventFail, nfc_worker->context);
  645. break;
  646. }
  647. } else {
  648. nfc_worker->callback(NfcWorkerEventWrongCardDetected, nfc_worker->context);
  649. furi_delay_ms(10);
  650. }
  651. } else {
  652. nfc_worker->callback(NfcWorkerEventNoCardDetected, nfc_worker->context);
  653. furi_delay_ms(10);
  654. }
  655. }
  656. if(furi_hal_rtc_is_flag_set(FuriHalRtcFlagDebug)) {
  657. reader_analyzer_stop(nfc_worker->reader_analyzer);
  658. }
  659. }
  660. static void nfc_worker_reader_analyzer_callback(ReaderAnalyzerEvent event, void* context) {
  661. furi_assert(context);
  662. NfcWorker* nfc_worker = context;
  663. if((nfc_worker->state == NfcWorkerStateAnalyzeReader) &&
  664. (event == ReaderAnalyzerEventMfkeyCollected)) {
  665. if(nfc_worker->callback) {
  666. nfc_worker->callback(NfcWorkerEventDetectReaderMfkeyCollected, nfc_worker->context);
  667. }
  668. }
  669. }
  670. void nfc_worker_analyze_reader(NfcWorker* nfc_worker) {
  671. furi_assert(nfc_worker);
  672. furi_assert(nfc_worker->callback);
  673. FuriHalNfcTxRxContext tx_rx = {};
  674. ReaderAnalyzer* reader_analyzer = nfc_worker->reader_analyzer;
  675. FuriHalNfcDevData* nfc_data = reader_analyzer_get_nfc_data(reader_analyzer);
  676. MfClassicEmulator emulator = {
  677. .cuid = nfc_util_bytes2num(&nfc_data->uid[nfc_data->uid_len - 4], 4),
  678. .data = nfc_worker->dev_data->mf_classic_data,
  679. .data_changed = false,
  680. };
  681. NfcaSignal* nfca_signal = nfca_signal_alloc();
  682. tx_rx.nfca_signal = nfca_signal;
  683. reader_analyzer_prepare_tx_rx(reader_analyzer, &tx_rx, true);
  684. reader_analyzer_start(nfc_worker->reader_analyzer, ReaderAnalyzerModeMfkey);
  685. reader_analyzer_set_callback(reader_analyzer, nfc_worker_reader_analyzer_callback, nfc_worker);
  686. rfal_platform_spi_acquire();
  687. FURI_LOG_D(TAG, "Start reader analyzer");
  688. uint8_t reader_no_data_received_cnt = 0;
  689. bool reader_no_data_notified = true;
  690. while(nfc_worker->state == NfcWorkerStateAnalyzeReader) {
  691. furi_hal_nfc_stop_cmd();
  692. furi_delay_ms(5);
  693. furi_hal_nfc_listen_start(nfc_data);
  694. if(furi_hal_nfc_listen_rx(&tx_rx, 300)) {
  695. if(reader_no_data_notified) {
  696. nfc_worker->callback(NfcWorkerEventDetectReaderDetected, nfc_worker->context);
  697. }
  698. reader_no_data_received_cnt = 0;
  699. reader_no_data_notified = false;
  700. NfcProtocol protocol =
  701. reader_analyzer_guess_protocol(reader_analyzer, tx_rx.rx_data, tx_rx.rx_bits / 8);
  702. if(protocol == NfcDeviceProtocolMifareClassic) {
  703. mf_classic_emulator(&emulator, &tx_rx);
  704. }
  705. } else {
  706. reader_no_data_received_cnt++;
  707. if(!reader_no_data_notified && (reader_no_data_received_cnt > 5)) {
  708. nfc_worker->callback(NfcWorkerEventDetectReaderLost, nfc_worker->context);
  709. reader_no_data_received_cnt = 0;
  710. reader_no_data_notified = true;
  711. }
  712. FURI_LOG_D(TAG, "No data from reader");
  713. continue;
  714. }
  715. }
  716. rfal_platform_spi_release();
  717. reader_analyzer_stop(nfc_worker->reader_analyzer);
  718. nfca_signal_free(nfca_signal);
  719. }