picopass_scene_elite_dict_attack.c 10.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238
  1. #include "../picopass_i.h"
  2. #include <dolphin/dolphin.h>
  3. #include "../picopass_keys.h"
  4. #define PICOPASS_SCENE_DICT_ATTACK_KEYS_BATCH_UPDATE (10)
  5. enum {
  6. PicopassSceneEliteDictAttackDictEliteUser,
  7. PicopassSceneEliteDictAttackDictStandard,
  8. PicopassSceneEliteDictAttackDictElite,
  9. };
  10. const char* picopass_dict_name[] = {
  11. [PicopassSceneEliteDictAttackDictEliteUser] = "Elite User Dictionary",
  12. [PicopassSceneEliteDictAttackDictStandard] = "Standard System Dictionary",
  13. [PicopassSceneEliteDictAttackDictElite] = "Elite System Dictionary",
  14. };
  15. static bool picopass_elite_dict_attack_change_dict(Picopass* picopass) {
  16. bool success = false;
  17. do {
  18. uint32_t scene_state =
  19. scene_manager_get_scene_state(picopass->scene_manager, PicopassSceneEliteDictAttack);
  20. nfc_dict_free(picopass->dict);
  21. picopass->dict = NULL;
  22. if(scene_state == PicopassSceneEliteDictAttackDictElite) break;
  23. if(scene_state == PicopassSceneEliteDictAttackDictEliteUser) {
  24. if(!nfc_dict_check_presence(PICOPASS_ICLASS_STANDARD_DICT_FLIPPER_NAME)) break;
  25. picopass->dict = nfc_dict_alloc(
  26. PICOPASS_ICLASS_STANDARD_DICT_FLIPPER_NAME,
  27. NfcDictModeOpenExisting,
  28. PICOPASS_KEY_LEN);
  29. scene_state = PicopassSceneEliteDictAttackDictStandard;
  30. } else if(scene_state == PicopassSceneEliteDictAttackDictStandard) {
  31. if(!nfc_dict_check_presence(PICOPASS_ICLASS_ELITE_DICT_FLIPPER_NAME)) break;
  32. picopass->dict = nfc_dict_alloc(
  33. PICOPASS_ICLASS_ELITE_DICT_FLIPPER_NAME,
  34. NfcDictModeOpenExisting,
  35. PICOPASS_KEY_LEN);
  36. scene_state = PicopassSceneEliteDictAttackDictElite;
  37. }
  38. picopass->dict_attack_ctx.card_detected = true;
  39. picopass->dict_attack_ctx.total_keys = nfc_dict_get_total_keys(picopass->dict);
  40. picopass->dict_attack_ctx.current_key = 0;
  41. picopass->dict_attack_ctx.name = picopass_dict_name[scene_state];
  42. scene_manager_set_scene_state(
  43. picopass->scene_manager, PicopassSceneEliteDictAttack, scene_state);
  44. success = true;
  45. } while(false);
  46. return success;
  47. }
  48. NfcCommand picopass_elite_dict_attack_worker_callback(PicopassPollerEvent event, void* context) {
  49. furi_assert(context);
  50. NfcCommand command = NfcCommandContinue;
  51. Picopass* picopass = context;
  52. if(event.type == PicopassPollerEventTypeRequestMode) {
  53. event.data->req_mode.mode = PicopassPollerModeRead;
  54. } else if(event.type == PicopassPollerEventTypeRequestKey) {
  55. uint8_t key[PICOPASS_KEY_LEN] = {};
  56. bool is_key_provided = true;
  57. if(!nfc_dict_get_next_key(picopass->dict, key, PICOPASS_KEY_LEN)) {
  58. if(picopass_elite_dict_attack_change_dict(picopass)) {
  59. is_key_provided = nfc_dict_get_next_key(picopass->dict, key, PICOPASS_KEY_LEN);
  60. view_dispatcher_send_custom_event(
  61. picopass->view_dispatcher, PicopassCustomEventDictAttackUpdateView);
  62. } else {
  63. is_key_provided = false;
  64. }
  65. }
  66. uint32_t scene_state =
  67. scene_manager_get_scene_state(picopass->scene_manager, PicopassSceneEliteDictAttack);
  68. memcpy(event.data->req_key.key, key, PICOPASS_KEY_LEN);
  69. event.data->req_key.is_elite_key =
  70. (scene_state != PicopassSceneEliteDictAttackDictStandard);
  71. event.data->req_key.is_key_provided = is_key_provided;
  72. if(is_key_provided) {
  73. picopass->dict_attack_ctx.current_key++;
  74. if(picopass->dict_attack_ctx.current_key %
  75. PICOPASS_SCENE_DICT_ATTACK_KEYS_BATCH_UPDATE ==
  76. 0) {
  77. view_dispatcher_send_custom_event(
  78. picopass->view_dispatcher, PicopassCustomEventDictAttackUpdateView);
  79. }
  80. }
  81. } else if(event.type == PicopassPollerEventTypeSuccess) {
  82. const PicopassDeviceData* data = picopass_poller_get_data(picopass->poller);
  83. memcpy(&picopass->dev->dev_data, data, sizeof(PicopassDeviceData));
  84. view_dispatcher_send_custom_event(
  85. picopass->view_dispatcher, PicopassCustomEventPollerSuccess);
  86. } else if(event.type == PicopassPollerEventTypeFail) {
  87. const PicopassDeviceData* data = picopass_poller_get_data(picopass->poller);
  88. memcpy(&picopass->dev->dev_data, data, sizeof(PicopassDeviceData));
  89. view_dispatcher_send_custom_event(
  90. picopass->view_dispatcher, PicopassCustomEventPollerSuccess);
  91. } else if(event.type == PicopassPollerEventTypeCardLost) {
  92. picopass->dict_attack_ctx.card_detected = false;
  93. view_dispatcher_send_custom_event(
  94. picopass->view_dispatcher, PicopassCustomEventDictAttackUpdateView);
  95. } else if(event.type == PicopassPollerEventTypeCardDetected) {
  96. picopass->dict_attack_ctx.card_detected = true;
  97. view_dispatcher_send_custom_event(
  98. picopass->view_dispatcher, PicopassCustomEventDictAttackUpdateView);
  99. }
  100. return command;
  101. }
  102. static void picopass_scene_elite_dict_attack_update_view(Picopass* instance) {
  103. if(instance->dict_attack_ctx.card_detected) {
  104. dict_attack_set_card_detected(instance->dict_attack);
  105. dict_attack_set_header(instance->dict_attack, instance->dict_attack_ctx.name);
  106. dict_attack_set_total_dict_keys(
  107. instance->dict_attack, instance->dict_attack_ctx.total_keys);
  108. dict_attack_set_current_dict_key(
  109. instance->dict_attack, instance->dict_attack_ctx.current_key);
  110. } else {
  111. dict_attack_set_card_removed(instance->dict_attack);
  112. }
  113. }
  114. static void picopass_scene_elite_dict_attack_callback(void* context) {
  115. Picopass* instance = context;
  116. view_dispatcher_send_custom_event(
  117. instance->view_dispatcher, PicopassCustomEventDictAttackSkip);
  118. }
  119. void picopass_scene_elite_dict_attack_on_enter(void* context) {
  120. Picopass* picopass = context;
  121. dolphin_deed(DolphinDeedNfcRead);
  122. // Setup dict attack context
  123. uint32_t state = PicopassSceneEliteDictAttackDictEliteUser;
  124. bool use_user_dict = nfc_dict_check_presence(PICOPASS_ICLASS_ELITE_DICT_USER_NAME);
  125. if(use_user_dict) {
  126. picopass->dict = nfc_dict_alloc(
  127. PICOPASS_ICLASS_ELITE_DICT_USER_NAME, NfcDictModeOpenExisting, PICOPASS_KEY_LEN);
  128. if(nfc_dict_get_total_keys(picopass->dict) == 0) {
  129. nfc_dict_free(picopass->dict);
  130. use_user_dict = false;
  131. }
  132. }
  133. if(use_user_dict) {
  134. state = PicopassSceneEliteDictAttackDictEliteUser;
  135. } else {
  136. picopass->dict = nfc_dict_alloc(
  137. PICOPASS_ICLASS_STANDARD_DICT_FLIPPER_NAME, NfcDictModeOpenExisting, PICOPASS_KEY_LEN);
  138. state = PicopassSceneEliteDictAttackDictStandard;
  139. }
  140. picopass->dict_attack_ctx.card_detected = true;
  141. picopass->dict_attack_ctx.total_keys = nfc_dict_get_total_keys(picopass->dict);
  142. picopass->dict_attack_ctx.current_key = 0;
  143. picopass->dict_attack_ctx.name = picopass_dict_name[state];
  144. scene_manager_set_scene_state(picopass->scene_manager, PicopassSceneEliteDictAttack, state);
  145. // Setup view
  146. picopass_scene_elite_dict_attack_update_view(picopass);
  147. dict_attack_set_callback(
  148. picopass->dict_attack, picopass_scene_elite_dict_attack_callback, picopass);
  149. // Start worker
  150. picopass->poller = picopass_poller_alloc(picopass->nfc);
  151. picopass_poller_start(picopass->poller, picopass_elite_dict_attack_worker_callback, picopass);
  152. view_dispatcher_switch_to_view(picopass->view_dispatcher, PicopassViewDictAttack);
  153. picopass_blink_start(picopass);
  154. }
  155. bool picopass_scene_elite_dict_attack_on_event(void* context, SceneManagerEvent event) {
  156. Picopass* picopass = context;
  157. bool consumed = false;
  158. if(event.type == SceneManagerEventTypeCustom) {
  159. if(event.event == PicopassCustomEventPollerSuccess) {
  160. if(memcmp(
  161. picopass->dev->dev_data.pacs.key,
  162. picopass_factory_debit_key,
  163. PICOPASS_BLOCK_LEN) == 0) {
  164. scene_manager_next_scene(picopass->scene_manager, PicopassSceneReadFactorySuccess);
  165. } else {
  166. scene_manager_next_scene(picopass->scene_manager, PicopassSceneReadCardSuccess);
  167. }
  168. consumed = true;
  169. } else if(event.event == PicopassCustomEventDictAttackUpdateView) {
  170. picopass_scene_elite_dict_attack_update_view(picopass);
  171. consumed = true;
  172. } else if(event.event == PicopassCustomEventDictAttackSkip) {
  173. uint32_t scene_state = scene_manager_get_scene_state(
  174. picopass->scene_manager, PicopassSceneEliteDictAttack);
  175. if(scene_state != PicopassSceneEliteDictAttackDictElite) {
  176. picopass_elite_dict_attack_change_dict(picopass);
  177. picopass_scene_elite_dict_attack_update_view(picopass);
  178. } else {
  179. if(memcmp(
  180. picopass->dev->dev_data.pacs.key,
  181. picopass_factory_debit_key,
  182. PICOPASS_BLOCK_LEN) == 0) {
  183. scene_manager_next_scene(
  184. picopass->scene_manager, PicopassSceneReadFactorySuccess);
  185. } else {
  186. scene_manager_next_scene(
  187. picopass->scene_manager, PicopassSceneReadCardSuccess);
  188. }
  189. }
  190. consumed = true;
  191. }
  192. }
  193. return consumed;
  194. }
  195. void picopass_scene_elite_dict_attack_on_exit(void* context) {
  196. Picopass* picopass = context;
  197. if(picopass->dict) {
  198. nfc_dict_free(picopass->dict);
  199. picopass->dict = NULL;
  200. }
  201. picopass->dict_attack_ctx.current_key = 0;
  202. picopass->dict_attack_ctx.total_keys = 0;
  203. picopass_poller_stop(picopass->poller);
  204. picopass_poller_free(picopass->poller);
  205. // Clear view
  206. popup_reset(picopass->popup);
  207. scene_manager_set_scene_state(
  208. picopass->scene_manager,
  209. PicopassSceneEliteDictAttack,
  210. PicopassSceneEliteDictAttackDictEliteUser);
  211. picopass_blink_stop(picopass);
  212. }