nfc_worker.c 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674
  1. #include "nfc_worker_i.h"
  2. #include <furi_hal.h>
  3. #include <lib/nfc_protocols/nfc_util.h>
  4. #include <lib/nfc_protocols/emv.h>
  5. #include <lib/nfc_protocols/mifare_common.h>
  6. #include <lib/nfc_protocols/mifare_ultralight.h>
  7. #include <lib/nfc_protocols/mifare_classic.h>
  8. #include <lib/nfc_protocols/mifare_desfire.h>
  9. #include "helpers/nfc_mf_classic_dict.h"
  10. #define TAG "NfcWorker"
  11. /***************************** NFC Worker API *******************************/
  12. NfcWorker* nfc_worker_alloc() {
  13. NfcWorker* nfc_worker = malloc(sizeof(NfcWorker));
  14. // Worker thread attributes
  15. nfc_worker->thread = furi_thread_alloc();
  16. furi_thread_set_name(nfc_worker->thread, "NfcWorker");
  17. furi_thread_set_stack_size(nfc_worker->thread, 8192);
  18. furi_thread_set_callback(nfc_worker->thread, nfc_worker_task);
  19. furi_thread_set_context(nfc_worker->thread, nfc_worker);
  20. nfc_worker->callback = NULL;
  21. nfc_worker->context = NULL;
  22. nfc_worker->storage = furi_record_open("storage");
  23. // Initialize rfal
  24. while(furi_hal_nfc_is_busy()) {
  25. osDelay(10);
  26. }
  27. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  28. return nfc_worker;
  29. }
  30. void nfc_worker_free(NfcWorker* nfc_worker) {
  31. furi_assert(nfc_worker);
  32. furi_thread_free(nfc_worker->thread);
  33. furi_record_close("storage");
  34. free(nfc_worker);
  35. }
  36. NfcWorkerState nfc_worker_get_state(NfcWorker* nfc_worker) {
  37. return nfc_worker->state;
  38. }
  39. void nfc_worker_start(
  40. NfcWorker* nfc_worker,
  41. NfcWorkerState state,
  42. NfcDeviceData* dev_data,
  43. NfcWorkerCallback callback,
  44. void* context) {
  45. furi_assert(nfc_worker);
  46. furi_assert(dev_data);
  47. while(furi_hal_nfc_is_busy()) {
  48. osDelay(10);
  49. }
  50. nfc_worker->callback = callback;
  51. nfc_worker->context = context;
  52. nfc_worker->dev_data = dev_data;
  53. nfc_worker_change_state(nfc_worker, state);
  54. furi_thread_start(nfc_worker->thread);
  55. }
  56. void nfc_worker_stop(NfcWorker* nfc_worker) {
  57. furi_assert(nfc_worker);
  58. if(nfc_worker->state == NfcWorkerStateBroken || nfc_worker->state == NfcWorkerStateReady) {
  59. return;
  60. }
  61. furi_hal_nfc_stop();
  62. nfc_worker_change_state(nfc_worker, NfcWorkerStateStop);
  63. furi_thread_join(nfc_worker->thread);
  64. }
  65. void nfc_worker_change_state(NfcWorker* nfc_worker, NfcWorkerState state) {
  66. nfc_worker->state = state;
  67. }
  68. /***************************** NFC Worker Thread *******************************/
  69. int32_t nfc_worker_task(void* context) {
  70. NfcWorker* nfc_worker = context;
  71. furi_hal_power_insomnia_enter();
  72. furi_hal_nfc_exit_sleep();
  73. if(nfc_worker->state == NfcWorkerStateDetect) {
  74. nfc_worker_detect(nfc_worker);
  75. } else if(nfc_worker->state == NfcWorkerStateEmulate) {
  76. nfc_worker_emulate(nfc_worker);
  77. } else if(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  78. nfc_worker_read_emv_app(nfc_worker);
  79. } else if(nfc_worker->state == NfcWorkerStateReadEMVData) {
  80. nfc_worker_read_emv(nfc_worker);
  81. } else if(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  82. nfc_worker_emulate_apdu(nfc_worker);
  83. } else if(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  84. nfc_worker_read_mifare_ultralight(nfc_worker);
  85. } else if(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  86. nfc_worker_emulate_mifare_ul(nfc_worker);
  87. } else if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  88. nfc_worker_mifare_classic_dict_attack(nfc_worker);
  89. } else if(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  90. nfc_worker_read_mifare_desfire(nfc_worker);
  91. }
  92. furi_hal_nfc_sleep();
  93. nfc_worker_change_state(nfc_worker, NfcWorkerStateReady);
  94. furi_hal_power_insomnia_exit();
  95. return 0;
  96. }
  97. void nfc_worker_detect(NfcWorker* nfc_worker) {
  98. nfc_device_data_clear(nfc_worker->dev_data);
  99. NfcDeviceData* dev_data = nfc_worker->dev_data;
  100. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  101. while(nfc_worker->state == NfcWorkerStateDetect) {
  102. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  103. // Process first found device
  104. if(nfc_data->type == FuriHalNfcTypeA) {
  105. if(mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  106. dev_data->protocol = NfcDeviceProtocolMifareUl;
  107. } else if(mf_classic_check_card_type(
  108. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  109. dev_data->protocol = NfcDeviceProtocolMifareClassic;
  110. } else if(mf_df_check_card_type(
  111. nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  112. dev_data->protocol = NfcDeviceProtocolMifareDesfire;
  113. } else if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  114. dev_data->protocol = NfcDeviceProtocolEMV;
  115. } else {
  116. dev_data->protocol = NfcDeviceProtocolUnknown;
  117. }
  118. }
  119. // Notify caller and exit
  120. if(nfc_worker->callback) {
  121. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  122. }
  123. break;
  124. }
  125. furi_hal_nfc_sleep();
  126. osDelay(100);
  127. }
  128. }
  129. void nfc_worker_emulate(NfcWorker* nfc_worker) {
  130. FuriHalNfcTxRxContext tx_rx = {};
  131. FuriHalNfcDevData* data = &nfc_worker->dev_data->nfc_data;
  132. NfcReaderRequestData* reader_data = &nfc_worker->dev_data->reader_data;
  133. while(nfc_worker->state == NfcWorkerStateEmulate) {
  134. if(furi_hal_nfc_listen(data->uid, data->uid_len, data->atqa, data->sak, true, 100)) {
  135. if(furi_hal_nfc_tx_rx(&tx_rx, 100)) {
  136. reader_data->size = tx_rx.rx_bits / 8;
  137. if(reader_data->size > 0) {
  138. memcpy(reader_data->data, tx_rx.rx_data, reader_data->size);
  139. if(nfc_worker->callback) {
  140. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  141. }
  142. }
  143. } else {
  144. FURI_LOG_E(TAG, "Failed to get reader commands");
  145. }
  146. }
  147. }
  148. }
  149. void nfc_worker_read_emv_app(NfcWorker* nfc_worker) {
  150. FuriHalNfcTxRxContext tx_rx = {};
  151. EmvApplication emv_app = {};
  152. NfcDeviceData* result = nfc_worker->dev_data;
  153. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  154. nfc_device_data_clear(result);
  155. while(nfc_worker->state == NfcWorkerStateReadEMVApp) {
  156. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  157. // Card was found. Check that it supports EMV
  158. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  159. result->protocol = NfcDeviceProtocolEMV;
  160. if(emv_search_application(&tx_rx, &emv_app)) {
  161. // Notify caller and exit
  162. result->emv_data.aid_len = emv_app.aid_len;
  163. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  164. if(nfc_worker->callback) {
  165. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  166. }
  167. }
  168. } else {
  169. FURI_LOG_W(TAG, "Card doesn't support EMV");
  170. }
  171. } else {
  172. FURI_LOG_D(TAG, "Can't find any cards");
  173. }
  174. furi_hal_nfc_sleep();
  175. osDelay(20);
  176. }
  177. }
  178. void nfc_worker_read_emv(NfcWorker* nfc_worker) {
  179. FuriHalNfcTxRxContext tx_rx = {};
  180. EmvApplication emv_app = {};
  181. NfcDeviceData* result = nfc_worker->dev_data;
  182. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  183. nfc_device_data_clear(result);
  184. while(nfc_worker->state == NfcWorkerStateReadEMVData) {
  185. if(furi_hal_nfc_detect(nfc_data, 1000)) {
  186. // Card was found. Check that it supports EMV
  187. if(nfc_data->interface == FuriHalNfcInterfaceIsoDep) {
  188. result->protocol = NfcDeviceProtocolEMV;
  189. if(emv_read_bank_card(&tx_rx, &emv_app)) {
  190. result->emv_data.number_len = emv_app.card_number_len;
  191. memcpy(
  192. result->emv_data.number, emv_app.card_number, result->emv_data.number_len);
  193. result->emv_data.aid_len = emv_app.aid_len;
  194. memcpy(result->emv_data.aid, emv_app.aid, emv_app.aid_len);
  195. if(emv_app.name_found) {
  196. memcpy(result->emv_data.name, emv_app.name, sizeof(emv_app.name));
  197. }
  198. if(emv_app.exp_month) {
  199. result->emv_data.exp_mon = emv_app.exp_month;
  200. result->emv_data.exp_year = emv_app.exp_year;
  201. }
  202. if(emv_app.country_code) {
  203. result->emv_data.country_code = emv_app.country_code;
  204. }
  205. if(emv_app.currency_code) {
  206. result->emv_data.currency_code = emv_app.currency_code;
  207. }
  208. // Notify caller and exit
  209. if(nfc_worker->callback) {
  210. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  211. }
  212. break;
  213. }
  214. } else {
  215. FURI_LOG_W(TAG, "Card doesn't support EMV");
  216. }
  217. } else {
  218. FURI_LOG_D(TAG, "Can't find any cards");
  219. }
  220. furi_hal_nfc_sleep();
  221. osDelay(20);
  222. }
  223. }
  224. void nfc_worker_emulate_apdu(NfcWorker* nfc_worker) {
  225. FuriHalNfcTxRxContext tx_rx = {};
  226. FuriHalNfcDevData params = {
  227. .uid = {0xCF, 0x72, 0xd4, 0x40},
  228. .uid_len = 4,
  229. .atqa = {0x00, 0x04},
  230. .sak = 0x20,
  231. .type = FuriHalNfcTypeA,
  232. };
  233. while(nfc_worker->state == NfcWorkerStateEmulateApdu) {
  234. if(furi_hal_nfc_listen(params.uid, params.uid_len, params.atqa, params.sak, false, 300)) {
  235. FURI_LOG_D(TAG, "POS terminal detected");
  236. if(emv_card_emulation(&tx_rx)) {
  237. FURI_LOG_D(TAG, "EMV card emulated");
  238. }
  239. } else {
  240. FURI_LOG_D(TAG, "Can't find reader");
  241. }
  242. furi_hal_nfc_sleep();
  243. osDelay(20);
  244. }
  245. }
  246. void nfc_worker_read_mifare_ultralight(NfcWorker* nfc_worker) {
  247. FuriHalNfcTxRxContext tx_rx = {};
  248. MfUltralightReader reader = {};
  249. MfUltralightData data = {};
  250. NfcDeviceData* result = nfc_worker->dev_data;
  251. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  252. while(nfc_worker->state == NfcWorkerStateReadMifareUltralight) {
  253. if(furi_hal_nfc_detect(nfc_data, 300)) {
  254. if(nfc_data->type == FuriHalNfcTypeA &&
  255. mf_ul_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  256. FURI_LOG_D(TAG, "Found Mifare Ultralight tag. Start reading");
  257. if(mf_ul_read_card(&tx_rx, &reader, &data)) {
  258. result->protocol = NfcDeviceProtocolMifareUl;
  259. result->mf_ul_data = data;
  260. // Notify caller and exit
  261. if(nfc_worker->callback) {
  262. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  263. }
  264. break;
  265. } else {
  266. FURI_LOG_D(TAG, "Failed reading Mifare Ultralight");
  267. }
  268. } else {
  269. FURI_LOG_W(TAG, "Tag is not Mifare Ultralight");
  270. }
  271. } else {
  272. FURI_LOG_D(TAG, "Can't find any tags");
  273. }
  274. furi_hal_nfc_sleep();
  275. osDelay(100);
  276. }
  277. }
  278. void nfc_worker_emulate_mifare_ul(NfcWorker* nfc_worker) {
  279. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  280. MfUltralightEmulator emulator = {};
  281. mf_ul_prepare_emulation(&emulator, &nfc_worker->dev_data->mf_ul_data);
  282. while(nfc_worker->state == NfcWorkerStateEmulateMifareUltralight) {
  283. furi_hal_nfc_emulate_nfca(
  284. nfc_data->uid,
  285. nfc_data->uid_len,
  286. nfc_data->atqa,
  287. nfc_data->sak,
  288. mf_ul_prepare_emulation_response,
  289. &emulator,
  290. 5000);
  291. // Check if data was modified
  292. if(emulator.data_changed) {
  293. nfc_worker->dev_data->mf_ul_data = emulator.data;
  294. if(nfc_worker->callback) {
  295. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  296. }
  297. emulator.data_changed = false;
  298. }
  299. }
  300. }
  301. void nfc_worker_mifare_classic_dict_attack(NfcWorker* nfc_worker) {
  302. furi_assert(nfc_worker->callback);
  303. FuriHalNfcTxRxContext tx_rx_ctx = {};
  304. MfClassicAuthContext auth_ctx = {};
  305. MfClassicReader reader = {};
  306. uint64_t curr_key = 0;
  307. uint16_t curr_sector = 0;
  308. uint8_t total_sectors = 0;
  309. NfcWorkerEvent event;
  310. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  311. // Open dictionary
  312. nfc_worker->dict_stream = file_stream_alloc(nfc_worker->storage);
  313. if(!nfc_mf_classic_dict_open_file(nfc_worker->dict_stream)) {
  314. event = NfcWorkerEventNoDictFound;
  315. nfc_worker->callback(event, nfc_worker->context);
  316. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  317. stream_free(nfc_worker->dict_stream);
  318. return;
  319. }
  320. // Detect Mifare Classic card
  321. while(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  322. if(furi_hal_nfc_detect(nfc_data, 300)) {
  323. if(mf_classic_get_type(
  324. nfc_data->uid,
  325. nfc_data->uid_len,
  326. nfc_data->atqa[0],
  327. nfc_data->atqa[1],
  328. nfc_data->sak,
  329. &reader)) {
  330. total_sectors = mf_classic_get_total_sectors_num(&reader);
  331. if(reader.type == MfClassicType1k) {
  332. event = NfcWorkerEventDetectedClassic1k;
  333. } else {
  334. event = NfcWorkerEventDetectedClassic4k;
  335. }
  336. nfc_worker->callback(event, nfc_worker->context);
  337. break;
  338. }
  339. } else {
  340. event = NfcWorkerEventNoCardDetected;
  341. nfc_worker->callback(event, nfc_worker->context);
  342. }
  343. }
  344. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  345. bool card_removed_notified = false;
  346. bool card_found_notified = false;
  347. // Seek for mifare classic keys
  348. for(curr_sector = 0; curr_sector < total_sectors; curr_sector++) {
  349. FURI_LOG_I(TAG, "Sector: %d ...", curr_sector);
  350. event = NfcWorkerEventNewSector;
  351. nfc_worker->callback(event, nfc_worker->context);
  352. mf_classic_auth_init_context(&auth_ctx, reader.cuid, curr_sector);
  353. bool sector_key_found = false;
  354. while(nfc_mf_classic_dict_get_next_key(nfc_worker->dict_stream, &curr_key)) {
  355. furi_hal_nfc_sleep();
  356. if(furi_hal_nfc_activate_nfca(300, &reader.cuid)) {
  357. if(!card_found_notified) {
  358. if(reader.type == MfClassicType1k) {
  359. event = NfcWorkerEventDetectedClassic1k;
  360. } else {
  361. event = NfcWorkerEventDetectedClassic4k;
  362. }
  363. nfc_worker->callback(event, nfc_worker->context);
  364. card_found_notified = true;
  365. card_removed_notified = false;
  366. }
  367. FURI_LOG_D(
  368. TAG,
  369. "Try to auth to sector %d with key %04lx%08lx",
  370. curr_sector,
  371. (uint32_t)(curr_key >> 32),
  372. (uint32_t)curr_key);
  373. if(mf_classic_auth_attempt(&tx_rx_ctx, &auth_ctx, curr_key)) {
  374. sector_key_found = true;
  375. if((auth_ctx.key_a != MF_CLASSIC_NO_KEY) &&
  376. (auth_ctx.key_b != MF_CLASSIC_NO_KEY))
  377. break;
  378. }
  379. } else {
  380. // Notify that no tag is availalble
  381. FURI_LOG_D(TAG, "Can't find tags");
  382. if(!card_removed_notified) {
  383. event = NfcWorkerEventNoCardDetected;
  384. nfc_worker->callback(event, nfc_worker->context);
  385. card_removed_notified = true;
  386. card_found_notified = false;
  387. }
  388. }
  389. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  390. osDelay(1);
  391. }
  392. if(nfc_worker->state != NfcWorkerStateReadMifareClassic) break;
  393. if(sector_key_found) {
  394. // Notify that keys were found
  395. if(auth_ctx.key_a != MF_CLASSIC_NO_KEY) {
  396. FURI_LOG_I(
  397. TAG,
  398. "Sector %d key A: %04lx%08lx",
  399. curr_sector,
  400. (uint32_t)(auth_ctx.key_a >> 32),
  401. (uint32_t)auth_ctx.key_a);
  402. event = NfcWorkerEventFoundKeyA;
  403. nfc_worker->callback(event, nfc_worker->context);
  404. }
  405. if(auth_ctx.key_b != MF_CLASSIC_NO_KEY) {
  406. FURI_LOG_I(
  407. TAG,
  408. "Sector %d key B: %04lx%08lx",
  409. curr_sector,
  410. (uint32_t)(auth_ctx.key_b >> 32),
  411. (uint32_t)auth_ctx.key_b);
  412. event = NfcWorkerEventFoundKeyB;
  413. nfc_worker->callback(event, nfc_worker->context);
  414. }
  415. // Add sectors to read sequence
  416. mf_classic_reader_add_sector(&reader, curr_sector, auth_ctx.key_a, auth_ctx.key_b);
  417. }
  418. nfc_mf_classic_dict_reset(nfc_worker->dict_stream);
  419. }
  420. }
  421. if(nfc_worker->state == NfcWorkerStateReadMifareClassic) {
  422. FURI_LOG_I(TAG, "Found keys to %d sectors. Start reading sectors", reader.sectors_to_read);
  423. uint8_t sectors_read =
  424. mf_classic_read_card(&tx_rx_ctx, &reader, &nfc_worker->dev_data->mf_classic_data);
  425. if(sectors_read) {
  426. event = NfcWorkerEventSuccess;
  427. nfc_worker->dev_data->protocol = NfcDeviceProtocolMifareClassic;
  428. FURI_LOG_I(TAG, "Successfully read %d sectors", sectors_read);
  429. } else {
  430. event = NfcWorkerEventFail;
  431. FURI_LOG_W(TAG, "Failed to read any sector");
  432. }
  433. nfc_worker->callback(event, nfc_worker->context);
  434. }
  435. nfc_mf_classic_dict_close_file(nfc_worker->dict_stream);
  436. stream_free(nfc_worker->dict_stream);
  437. }
  438. void nfc_worker_read_mifare_desfire(NfcWorker* nfc_worker) {
  439. ReturnCode err;
  440. uint8_t tx_buff[64] = {};
  441. uint16_t tx_len = 0;
  442. uint8_t rx_buff[512] = {};
  443. uint16_t rx_len;
  444. NfcDeviceData* result = nfc_worker->dev_data;
  445. nfc_device_data_clear(result);
  446. MifareDesfireData* data = &result->mf_df_data;
  447. FuriHalNfcDevData* nfc_data = &nfc_worker->dev_data->nfc_data;
  448. while(nfc_worker->state == NfcWorkerStateReadMifareDesfire) {
  449. furi_hal_nfc_sleep();
  450. if(!furi_hal_nfc_detect(nfc_data, 300)) {
  451. osDelay(100);
  452. continue;
  453. }
  454. memset(data, 0, sizeof(MifareDesfireData));
  455. if(nfc_data->type != FuriHalNfcTypeA ||
  456. !mf_df_check_card_type(nfc_data->atqa[0], nfc_data->atqa[1], nfc_data->sak)) {
  457. FURI_LOG_D(TAG, "Tag is not DESFire");
  458. osDelay(100);
  459. continue;
  460. }
  461. FURI_LOG_D(TAG, "Found DESFire tag");
  462. result->protocol = NfcDeviceProtocolMifareDesfire;
  463. // Get DESFire version
  464. tx_len = mf_df_prepare_get_version(tx_buff);
  465. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  466. if(err != ERR_NONE) {
  467. FURI_LOG_W(TAG, "Bad exchange getting version, err: %d", err);
  468. continue;
  469. }
  470. if(!mf_df_parse_get_version_response(rx_buff, rx_len, &data->version)) {
  471. FURI_LOG_W(TAG, "Bad DESFire GET_VERSION response");
  472. continue;
  473. }
  474. tx_len = mf_df_prepare_get_free_memory(tx_buff);
  475. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  476. if(err == ERR_NONE) {
  477. data->free_memory = malloc(sizeof(MifareDesfireFreeMemory));
  478. memset(data->free_memory, 0, sizeof(MifareDesfireFreeMemory));
  479. if(!mf_df_parse_get_free_memory_response(rx_buff, rx_len, data->free_memory)) {
  480. FURI_LOG_D(TAG, "Bad DESFire GET_FREE_MEMORY response (normal for pre-EV1 cards)");
  481. free(data->free_memory);
  482. data->free_memory = NULL;
  483. }
  484. }
  485. tx_len = mf_df_prepare_get_key_settings(tx_buff);
  486. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  487. if(err != ERR_NONE) {
  488. FURI_LOG_D(TAG, "Bad exchange getting key settings, err: %d", err);
  489. } else {
  490. data->master_key_settings = malloc(sizeof(MifareDesfireKeySettings));
  491. memset(data->master_key_settings, 0, sizeof(MifareDesfireKeySettings));
  492. if(!mf_df_parse_get_key_settings_response(rx_buff, rx_len, data->master_key_settings)) {
  493. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  494. free(data->master_key_settings);
  495. data->master_key_settings = NULL;
  496. }
  497. MifareDesfireKeyVersion** key_version_head =
  498. &data->master_key_settings->key_version_head;
  499. for(uint8_t key_id = 0; key_id < data->master_key_settings->max_keys; key_id++) {
  500. tx_len = mf_df_prepare_get_key_version(tx_buff, key_id);
  501. err =
  502. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  503. if(err != ERR_NONE) {
  504. FURI_LOG_W(TAG, "Bad exchange getting key version, err: %d", err);
  505. continue;
  506. }
  507. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  508. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  509. key_version->id = key_id;
  510. if(!mf_df_parse_get_key_version_response(rx_buff, rx_len, key_version)) {
  511. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  512. free(key_version);
  513. continue;
  514. }
  515. *key_version_head = key_version;
  516. key_version_head = &key_version->next;
  517. }
  518. }
  519. tx_len = mf_df_prepare_get_application_ids(tx_buff);
  520. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  521. if(err != ERR_NONE) {
  522. FURI_LOG_W(TAG, "Bad exchange getting application IDs, err: %d", err);
  523. } else {
  524. if(!mf_df_parse_get_application_ids_response(rx_buff, rx_len, &data->app_head)) {
  525. FURI_LOG_W(TAG, "Bad DESFire GET_APPLICATION_IDS response");
  526. }
  527. }
  528. for(MifareDesfireApplication* app = data->app_head; app; app = app->next) {
  529. tx_len = mf_df_prepare_select_application(tx_buff, app->id);
  530. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  531. if(!mf_df_parse_select_application_response(rx_buff, rx_len)) {
  532. FURI_LOG_W(TAG, "Bad exchange selecting application, err: %d", err);
  533. continue;
  534. }
  535. tx_len = mf_df_prepare_get_key_settings(tx_buff);
  536. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  537. if(err != ERR_NONE) {
  538. FURI_LOG_W(TAG, "Bad exchange getting key settings, err: %d", err);
  539. } else {
  540. app->key_settings = malloc(sizeof(MifareDesfireKeySettings));
  541. memset(app->key_settings, 0, sizeof(MifareDesfireKeySettings));
  542. if(!mf_df_parse_get_key_settings_response(rx_buff, rx_len, app->key_settings)) {
  543. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_SETTINGS response");
  544. free(app->key_settings);
  545. app->key_settings = NULL;
  546. }
  547. MifareDesfireKeyVersion** key_version_head = &app->key_settings->key_version_head;
  548. for(uint8_t key_id = 0; key_id < app->key_settings->max_keys; key_id++) {
  549. tx_len = mf_df_prepare_get_key_version(tx_buff, key_id);
  550. err = furi_hal_nfc_exchange_full(
  551. tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  552. if(err != ERR_NONE) {
  553. FURI_LOG_W(TAG, "Bad exchange getting key version, err: %d", err);
  554. continue;
  555. }
  556. MifareDesfireKeyVersion* key_version = malloc(sizeof(MifareDesfireKeyVersion));
  557. memset(key_version, 0, sizeof(MifareDesfireKeyVersion));
  558. key_version->id = key_id;
  559. if(!mf_df_parse_get_key_version_response(rx_buff, rx_len, key_version)) {
  560. FURI_LOG_W(TAG, "Bad DESFire GET_KEY_VERSION response");
  561. free(key_version);
  562. continue;
  563. }
  564. *key_version_head = key_version;
  565. key_version_head = &key_version->next;
  566. }
  567. }
  568. tx_len = mf_df_prepare_get_file_ids(tx_buff);
  569. err = furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  570. if(err != ERR_NONE) {
  571. FURI_LOG_W(TAG, "Bad exchange getting file IDs, err: %d", err);
  572. } else {
  573. if(!mf_df_parse_get_file_ids_response(rx_buff, rx_len, &app->file_head)) {
  574. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_IDS response");
  575. }
  576. }
  577. for(MifareDesfireFile* file = app->file_head; file; file = file->next) {
  578. tx_len = mf_df_prepare_get_file_settings(tx_buff, file->id);
  579. err =
  580. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  581. if(err != ERR_NONE) {
  582. FURI_LOG_W(TAG, "Bad exchange getting file settings, err: %d", err);
  583. continue;
  584. }
  585. if(!mf_df_parse_get_file_settings_response(rx_buff, rx_len, file)) {
  586. FURI_LOG_W(TAG, "Bad DESFire GET_FILE_SETTINGS response");
  587. continue;
  588. }
  589. switch(file->type) {
  590. case MifareDesfireFileTypeStandard:
  591. case MifareDesfireFileTypeBackup:
  592. tx_len = mf_df_prepare_read_data(tx_buff, file->id, 0, 0);
  593. break;
  594. case MifareDesfireFileTypeValue:
  595. tx_len = mf_df_prepare_get_value(tx_buff, file->id);
  596. break;
  597. case MifareDesfireFileTypeLinearRecord:
  598. case MifareDesfireFileTypeCyclicRecord:
  599. tx_len = mf_df_prepare_read_records(tx_buff, file->id, 0, 0);
  600. break;
  601. }
  602. err =
  603. furi_hal_nfc_exchange_full(tx_buff, tx_len, rx_buff, sizeof(rx_buff), &rx_len);
  604. if(err != ERR_NONE) {
  605. FURI_LOG_W(TAG, "Bad exchange reading file %d, err: %d", file->id, err);
  606. continue;
  607. }
  608. if(!mf_df_parse_read_data_response(rx_buff, rx_len, file)) {
  609. FURI_LOG_W(TAG, "Bad response reading file %d", file->id);
  610. continue;
  611. }
  612. }
  613. }
  614. // Notify caller and exit
  615. if(nfc_worker->callback) {
  616. nfc_worker->callback(NfcWorkerEventSuccess, nfc_worker->context);
  617. }
  618. break;
  619. }
  620. }