mirror of
https://github.com/Proxmark/proxmark3.git
synced 2025-08-20 13:23:25 -07:00
couple q5 fixes + continue with em4x05 em4x69..
.. readword demods (not tested) still a work in progress
This commit is contained in:
parent
7666f4608e
commit
6f1a597855
4 changed files with 135 additions and 7 deletions
|
@ -22,6 +22,7 @@ command_t * CmdDataCommands();
|
|||
int CmdData(const char *Cmd);
|
||||
void printDemodBuff(void);
|
||||
void setDemodBuf(uint8_t *buff, size_t size, size_t startIdx);
|
||||
int CmdPrintDemodBuff(const char *Cmd);
|
||||
int CmdAskEM410xDemod(const char *Cmd);
|
||||
int CmdVikingDemod(const char *Cmd);
|
||||
int CmdG_Prox_II_Demod(const char *Cmd);
|
||||
|
|
|
@ -140,7 +140,7 @@ int CmdAWIDClone(const char *Cmd) {
|
|||
if (sscanf(Cmd, "%u %u", &fc, &cn ) != 2) return usage_lf_awid_clone();
|
||||
|
||||
if (param_getchar(Cmd, 3) == 'Q' || param_getchar(Cmd, 3) == 'q')
|
||||
blocks[0] = T5555_MODULATION_FSK2 | T5555_INVERT_OUTPUT | 50<<T5555_BITRATE_SHIFT | 3<<T5555_MAXBLOCK_SHIFT;
|
||||
blocks[0] = T5555_MODULATION_FSK2 | T5555_INVERT_OUTPUT | ((50-2)>>1)<<T5555_BITRATE_SHIFT | 3<<T5555_MAXBLOCK_SHIFT;
|
||||
|
||||
if ((fc & 0xFF) != fc) {
|
||||
fc &= 0xFF;
|
||||
|
|
|
@ -512,6 +512,125 @@ int usage_lf_em_read(void) {
|
|||
PrintAndLog(" lf em readword 1 11223344");
|
||||
return 0;
|
||||
}
|
||||
|
||||
//search for given preamble in given BitStream and return success=1 or fail=0 and startIndex
|
||||
uint8_t EMpreambleSearch(uint8_t *BitStream, uint8_t *preamble, size_t pLen, size_t size, size_t *startIdx)
|
||||
{
|
||||
// Sanity check. If preamble length is bigger than bitstream length.
|
||||
if ( size <= pLen ) return 0;
|
||||
// em only sends preamble once, so look for it once in the first x bits
|
||||
uint8_t foundCnt = 0;
|
||||
for (int idx = 0; idx < size - pLen; idx++){
|
||||
if (memcmp(BitStream+idx, preamble, pLen) == 0){
|
||||
//first index found
|
||||
foundCnt++;
|
||||
if (foundCnt == 1) {
|
||||
*startIdx = idx;
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
int demodEM4x05resp(uint8_t bitsNeeded) {
|
||||
int ans = 0;
|
||||
bool demodFound = false;
|
||||
DemodBufferLen = 0x00;
|
||||
// skip first two 0 bits as they might have been missed in the demod
|
||||
uint8_t preamble[6] = {0,0,1,0,1,0};
|
||||
|
||||
// test for FSK wave (easiest to 99% ID)
|
||||
if (GetFskClock("", FALSE, FALSE)) {
|
||||
//valid fsk clocks found
|
||||
ans = FSKrawDemod("0 0", false);
|
||||
if (!ans) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305: FSK Demod failed");
|
||||
//return -1;
|
||||
} else {
|
||||
// set size to 10 to only test first 4 positions for the preamble
|
||||
size_t size = (10 > DemodBufferLen) ? DemodBufferLen : 10;
|
||||
size_t startIdx = 0;
|
||||
|
||||
if (g_debugMode) PrintAndLog("ANS: %d | %u | %u", ans, startIdx, size);
|
||||
|
||||
uint8_t errChk = !EMpreambleSearch(DemodBuffer, preamble, sizeof(preamble), size, &startIdx);
|
||||
if ( errChk == 0) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305 preamble not found :: %d", startIdx);
|
||||
//return -1;
|
||||
} else {
|
||||
//can't test size because the preamble doesn't repeat :(
|
||||
//meaning chances of false positives are high.
|
||||
demodFound = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
ans = GetPskClock("", FALSE, FALSE);
|
||||
if (ans>0) {
|
||||
PrintAndLog("PSK response possibly found, run `data rawd p1` to attempt to demod");
|
||||
}
|
||||
|
||||
if (!demodFound) {
|
||||
DemodBufferLen = 0x00;
|
||||
//try biphase
|
||||
ans = ASKbiphaseDemod("0 0 1", FALSE);
|
||||
if (!ans) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305: ASK/biphase Demod failed");
|
||||
//return -1;
|
||||
} else {
|
||||
// set size to 10 to only test first 4 positions for the preamble
|
||||
size_t size = (10 > DemodBufferLen) ? DemodBufferLen : 10;
|
||||
size_t startIdx = 0;
|
||||
|
||||
if (g_debugMode) PrintAndLog("ANS: %d | %u | %u", ans, startIdx, size);
|
||||
|
||||
uint8_t errChk = !EMpreambleSearch(DemodBuffer, preamble, sizeof(preamble), size, &startIdx);
|
||||
if ( errChk == 0) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305 preamble not found :: %d", startIdx);
|
||||
//return -1;
|
||||
} else {
|
||||
//can't test size because the preamble doesn't repeat :(
|
||||
//meaning chances of false positives are high.
|
||||
demodFound = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (!demodFound) {
|
||||
DemodBufferLen = 0x00;
|
||||
// try manchester - NOTE: ST only applies to T55x7 tags.
|
||||
ans = ASKDemod_ext("0,0,1", false, false, 1, false);
|
||||
if (!ans) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305: ASK/Manchester Demod failed");
|
||||
//return -1;
|
||||
} else {
|
||||
// set size to 10 to only test first 4 positions for the preamble
|
||||
size_t size = (10 > DemodBufferLen) ? DemodBufferLen : 10;
|
||||
size_t startIdx = 0;
|
||||
|
||||
if (g_debugMode) PrintAndLog("ANS: %d | %u | %u", ans, startIdx, size);
|
||||
|
||||
uint8_t errChk = !EMpreambleSearch(DemodBuffer, preamble, sizeof(preamble), size, &startIdx);
|
||||
if ( errChk == 0) {
|
||||
if (g_debugMode) PrintAndLog("DEBUG: Error - EM4305 preamble not found :: %d", startIdx);
|
||||
//return -1;
|
||||
} else {
|
||||
//can't test size because the preamble doesn't repeat :(
|
||||
//meaning chances of false positives are high.
|
||||
demodFound = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (demodFound && bitsNeeded < DemodBufferLen) {
|
||||
setDemodBuf(DemodBuffer + ans + sizeof(preamble), bitsNeeded, 0);
|
||||
CmdPrintDemodBuff("x");
|
||||
return 1;
|
||||
}
|
||||
return -1;
|
||||
}
|
||||
|
||||
int CmdReadWord(const char *Cmd) {
|
||||
int addr, pwd;
|
||||
bool usePwd = false;
|
||||
|
@ -541,14 +660,22 @@ int CmdReadWord(const char *Cmd) {
|
|||
return -1;
|
||||
}
|
||||
|
||||
uint8_t got[6000]; // 8 bit preamble + 32 bit word response (max clock (128) * 40bits = 5120 samples)
|
||||
uint8_t got[6000];
|
||||
GetFromBigBuf(got, sizeof(got), 0);
|
||||
if ( !WaitForResponseTimeout(CMD_ACK, NULL, 8000) ) {
|
||||
if ( !WaitForResponseTimeout(CMD_ACK, NULL, 2500) ) {
|
||||
PrintAndLog("command execution time out");
|
||||
return 0;
|
||||
return -1;
|
||||
}
|
||||
setGraphBuf(got, sizeof(got));
|
||||
//todo: demodulate read data
|
||||
int testLen = (GraphTraceLen < 1000) ? GraphTraceLen : 1000;
|
||||
if (graphJustNoise(GraphBuffer, testLen)) {
|
||||
PrintAndLog("no tag not found");
|
||||
return -1;
|
||||
}
|
||||
|
||||
//need 32 bits for read word
|
||||
demodEM4x05resp(32);
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
|
|
|
@ -178,7 +178,7 @@ int CmdPrescoClone(const char *Cmd) {
|
|||
if (GetWiegandFromPresco(Cmd, &sitecode, &usercode, &fullcode, &Q5) == -1) return usage_lf_presco_clone();
|
||||
|
||||
if (Q5)
|
||||
blocks[0] = T5555_MODULATION_MANCHESTER | 32<<T5555_BITRATE_SHIFT | 4<<T5555_MAXBLOCK_SHIFT | T5555_ST_TERMINATOR;
|
||||
blocks[0] = T5555_MODULATION_MANCHESTER | ((32-2)>>1)<<T5555_BITRATE_SHIFT | 4<<T5555_MAXBLOCK_SHIFT | T5555_ST_TERMINATOR;
|
||||
|
||||
if ((sitecode & 0xFF) != sitecode) {
|
||||
sitecode &= 0xFF;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue