weebo_scene_write.c 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240
  1. #include "../weebo_i.h"
  2. #include <nfc/protocols/mf_ultralight/mf_ultralight_poller.h>
  3. #define TAG "SceneWrite"
  4. static uint8_t SLB[] = {0x00, 0x00, 0x0F, 0xE0};
  5. static uint8_t CC[] = {0xf1, 0x10, 0xff, 0xee};
  6. static uint8_t DLB[] = {0x01, 0x00, 0x0f, 0xbd};
  7. static uint8_t CFG0[] = {0x00, 0x00, 0x00, 0x04};
  8. static uint8_t CFG1[] = {0x5f, 0x00, 0x00, 0x00};
  9. static uint8_t PACKRFUI[] = {0x80, 0x80, 0x00, 0x00};
  10. enum NTAG215Pages {
  11. staticLockBits = 2,
  12. capabilityContainer = 3,
  13. userMemoryFirst = 4,
  14. userMemoryLast = 129,
  15. dynamicLockBits = 130,
  16. cfg0 = 131,
  17. cfg1 = 132,
  18. pwd = 133,
  19. pack = 134,
  20. total = 135
  21. };
  22. void weebo_scene_write_calculate_pwd(uint8_t* uid, uint8_t* pwd) {
  23. pwd[0] = uid[1] ^ uid[3] ^ 0xAA;
  24. pwd[1] = uid[2] ^ uid[4] ^ 0x55;
  25. pwd[2] = uid[3] ^ uid[5] ^ 0xAA;
  26. pwd[3] = uid[4] ^ uid[6] ^ 0x55;
  27. }
  28. NfcCommand weebo_scene_write_poller_callback(NfcGenericEvent event, void* context) {
  29. furi_assert(event.protocol == NfcProtocolMfUltralight);
  30. Weebo* weebo = context;
  31. NfcCommand ret = NfcCommandContinue;
  32. const MfUltralightPollerEvent* mf_ultralight_event = event.event_data;
  33. MfUltralightPoller* poller = event.instance;
  34. if(mf_ultralight_event->type == MfUltralightPollerEventTypeRequestMode) {
  35. // no-op
  36. } else if(mf_ultralight_event->type == MfUltralightPollerEventTypeAuthRequest) {
  37. mf_ultralight_event->data->auth_context.skip_auth = true;
  38. } else if(mf_ultralight_event->type == MfUltralightPollerEventTypeReadSuccess) {
  39. nfc_device_set_data(
  40. weebo->nfc_device, NfcProtocolMfUltralight, nfc_poller_get_data(weebo->poller));
  41. const MfUltralightData* data =
  42. nfc_device_get_data(weebo->nfc_device, NfcProtocolMfUltralight);
  43. if(!mf_ultralight_is_all_data_read(data)) {
  44. view_dispatcher_send_custom_event(weebo->view_dispatcher, WeeboCustomEventWrongCard);
  45. ret = NfcCommandStop;
  46. return ret;
  47. }
  48. if(data->type != MfUltralightTypeNTAG215) {
  49. view_dispatcher_send_custom_event(weebo->view_dispatcher, WeeboCustomEventWrongCard);
  50. ret = NfcCommandStop;
  51. return ret;
  52. }
  53. view_dispatcher_send_custom_event(weebo->view_dispatcher, WeeboCustomEventCardDetected);
  54. FURI_LOG_D(
  55. TAG,
  56. "UID: %02X%02X%02X%02X%02X%02X",
  57. data->iso14443_3a_data->uid[0],
  58. data->iso14443_3a_data->uid[1],
  59. data->iso14443_3a_data->uid[2],
  60. data->iso14443_3a_data->uid[3],
  61. data->iso14443_3a_data->uid[4],
  62. data->iso14443_3a_data->uid[5]);
  63. uint8_t PWD[4];
  64. weebo_scene_write_calculate_pwd(data->iso14443_3a_data->uid, PWD);
  65. FURI_LOG_D(TAG, "PWD: %02X%02X%02X%02X", PWD[0], PWD[1], PWD[2], PWD[3]);
  66. for(size_t p = 0; p < 2; p++) {
  67. for(size_t i = 0; i < MF_ULTRALIGHT_PAGE_SIZE; i++) {
  68. weebo->figure[NFC3D_UID_OFFSET + p * MF_ULTRALIGHT_PAGE_SIZE + i] =
  69. data->page[p].data[i];
  70. }
  71. }
  72. uint8_t modified[NTAG215_SIZE];
  73. nfc3d_amiibo_pack(&weebo->amiiboKeys, weebo->figure, modified);
  74. MfUltralightError error;
  75. MfUltralightPage page;
  76. // You might think it odd that I'm doing this writing "by hand" and not using the flipper SDK, but this is for two reasons:
  77. // 1. The flipper SDK doesn't write beyond user memory
  78. // 2. I order the writes from least destructive to most destructive, so that if something goes wrong, recovery _might_ be possible
  79. do {
  80. // user data
  81. view_dispatcher_send_custom_event(
  82. weebo->view_dispatcher, WeeboCustomEventWritingUserData);
  83. for(size_t i = userMemoryFirst; i <= userMemoryLast; i++) {
  84. memcpy(
  85. page.data, modified + (i * MF_ULTRALIGHT_PAGE_SIZE), MF_ULTRALIGHT_PAGE_SIZE);
  86. FURI_LOG_D(TAG, "Writing page %zu", i);
  87. error = mf_ultralight_poller_write_page(poller, i, &page);
  88. if(error != MfUltralightErrorNone) {
  89. FURI_LOG_E(TAG, "Error writing page %zu: %d", i, error);
  90. ret = NfcCommandStop;
  91. break;
  92. }
  93. }
  94. if(error != MfUltralightErrorNone) {
  95. ret = NfcCommandStop;
  96. break;
  97. }
  98. view_dispatcher_send_custom_event(
  99. weebo->view_dispatcher, WeeboCustomEventWritingConfigData);
  100. // pwd
  101. memcpy(page.data, PWD, sizeof(PWD));
  102. error = mf_ultralight_poller_write_page(poller, pwd, &page);
  103. if(error != MfUltralightErrorNone) {
  104. FURI_LOG_E(TAG, "Error writing PWD: %d", error);
  105. ret = NfcCommandStop;
  106. break;
  107. }
  108. // pack
  109. memcpy(page.data, PACKRFUI, sizeof(PACKRFUI));
  110. error = mf_ultralight_poller_write_page(poller, pack, &page);
  111. if(error != MfUltralightErrorNone) {
  112. FURI_LOG_E(TAG, "Error writing PACKRFUI: %d", error);
  113. ret = NfcCommandStop;
  114. break;
  115. }
  116. // capability container
  117. memcpy(page.data, CC, sizeof(CC));
  118. error = mf_ultralight_poller_write_page(poller, capabilityContainer, &page);
  119. if(error != MfUltralightErrorNone) {
  120. FURI_LOG_E(TAG, "Error writing CC: %d", error);
  121. ret = NfcCommandStop;
  122. break;
  123. }
  124. // cfg0
  125. memcpy(page.data, CFG0, sizeof(CFG0));
  126. error = mf_ultralight_poller_write_page(poller, cfg0, &page);
  127. if(error != MfUltralightErrorNone) {
  128. FURI_LOG_E(TAG, "Error writing CFG0: %d", error);
  129. ret = NfcCommandStop;
  130. break;
  131. }
  132. // cfg1
  133. memcpy(page.data, CFG1, sizeof(CFG1));
  134. error = mf_ultralight_poller_write_page(poller, cfg1, &page);
  135. if(error != MfUltralightErrorNone) {
  136. FURI_LOG_E(TAG, "Error writing CFG1: %d", error);
  137. ret = NfcCommandStop;
  138. break;
  139. }
  140. // dynamic lock bits
  141. memcpy(page.data, DLB, sizeof(DLB));
  142. error = mf_ultralight_poller_write_page(poller, dynamicLockBits, &page);
  143. if(error != MfUltralightErrorNone) {
  144. FURI_LOG_E(TAG, "Error writing DLB: %d", error);
  145. ret = NfcCommandStop;
  146. break;
  147. }
  148. // static lock bits
  149. memcpy(page.data, SLB, sizeof(SLB));
  150. error = mf_ultralight_poller_write_page(poller, staticLockBits, &page);
  151. if(error != MfUltralightErrorNone) {
  152. FURI_LOG_E(TAG, "Error writing SLB: %d", error);
  153. ret = NfcCommandStop;
  154. break;
  155. }
  156. } while(false);
  157. ret = NfcCommandStop;
  158. view_dispatcher_send_custom_event(weebo->view_dispatcher, WeeboCustomEventWriteSuccess);
  159. } else {
  160. FURI_LOG_D(TAG, "Unhandled event type: %d", mf_ultralight_event->type);
  161. }
  162. return ret;
  163. }
  164. void weebo_scene_write_on_enter(void* context) {
  165. Weebo* weebo = context;
  166. Popup* popup = weebo->popup;
  167. popup_set_header(popup, "Present NTAG215", 58, 28, AlignCenter, AlignCenter);
  168. weebo->poller = nfc_poller_alloc(weebo->nfc, NfcProtocolMfUltralight);
  169. nfc_poller_start(weebo->poller, weebo_scene_write_poller_callback, weebo);
  170. weebo_blink_start(weebo);
  171. view_dispatcher_switch_to_view(weebo->view_dispatcher, WeeboViewPopup);
  172. }
  173. bool weebo_scene_write_on_event(void* context, SceneManagerEvent event) {
  174. Weebo* weebo = context;
  175. bool consumed = false;
  176. if(event.type == SceneManagerEventTypeCustom) {
  177. scene_manager_set_scene_state(weebo->scene_manager, WeeboSceneWrite, event.event);
  178. if(event.event == WeeboCustomEventCardDetected) {
  179. popup_set_text(weebo->popup, "Card detected", 64, 36, AlignCenter, AlignTop);
  180. consumed = true;
  181. } else if(event.event == WeeboCustomEventWritingUserData) {
  182. popup_set_text(weebo->popup, "Writing user data", 64, 36, AlignCenter, AlignTop);
  183. consumed = true;
  184. } else if(event.event == WeeboCustomEventWritingConfigData) {
  185. popup_set_text(weebo->popup, "Writing config data", 64, 36, AlignCenter, AlignTop);
  186. consumed = true;
  187. } else if(event.event == WeeboCustomEventWriteSuccess) {
  188. popup_set_text(weebo->popup, "Write success", 64, 36, AlignCenter, AlignTop);
  189. consumed = true;
  190. scene_manager_next_scene(weebo->scene_manager, WeeboSceneWriteCardSuccess);
  191. } else if(event.event == WeeboCustomEventWrongCard) {
  192. popup_set_text(weebo->popup, "Wrong card", 64, 36, AlignCenter, AlignTop);
  193. consumed = true;
  194. }
  195. }
  196. return consumed;
  197. }
  198. void weebo_scene_write_on_exit(void* context) {
  199. Weebo* weebo = context;
  200. if(weebo->poller) {
  201. nfc_poller_stop(weebo->poller);
  202. nfc_poller_free(weebo->poller);
  203. weebo->poller = NULL;
  204. }
  205. popup_reset(weebo->popup);
  206. weebo_blink_stop(weebo);
  207. }