mirror of
https://github.com/Proxmark/proxmark3.git
synced 2025-07-30 19:40:09 -07:00
@iceman1001 updated scripts
This commit is contained in:
parent
d730878d8c
commit
ab7fdfcbed
4 changed files with 59 additions and 39 deletions
|
@ -13,6 +13,7 @@ local band = bit32.band
|
||||||
example =[[
|
example =[[
|
||||||
script run tnp3clone
|
script run tnp3clone
|
||||||
script run tnp3clone -h
|
script run tnp3clone -h
|
||||||
|
script run tnp3clone -l
|
||||||
script run tnp3clone -t aa00 -s 0030
|
script run tnp3clone -t aa00 -s 0030
|
||||||
|
|
||||||
]]
|
]]
|
||||||
|
@ -23,7 +24,8 @@ This script will try making a barebone clone of a tnp3 tag on to a magic generat
|
||||||
|
|
||||||
Arguments:
|
Arguments:
|
||||||
-h : this help
|
-h : this help
|
||||||
-t <data> : toytype id, 4hex symbols.
|
-l : list all known toy tokens
|
||||||
|
-t <data> : toytype id, 4hex symbols
|
||||||
-s <data> : subtype id, 4hex symbols
|
-s <data> : subtype id, 4hex symbols
|
||||||
|
|
||||||
For fun, try the following subtype id:
|
For fun, try the following subtype id:
|
||||||
|
@ -32,7 +34,7 @@ Arguments:
|
||||||
0138 - Series 2
|
0138 - Series 2
|
||||||
0234 - Special
|
0234 - Special
|
||||||
023c - Special
|
023c - Special
|
||||||
|
0020 - Swapforce
|
||||||
]]
|
]]
|
||||||
|
|
||||||
|
|
||||||
|
@ -98,10 +100,11 @@ local function main(args)
|
||||||
local DEBUG = true
|
local DEBUG = true
|
||||||
|
|
||||||
-- Arguments for the script
|
-- Arguments for the script
|
||||||
for o, a in getopt.getopt(args, 'ht:s:') do
|
for o, a in getopt.getopt(args, 'ht:s:l') do
|
||||||
if o == "h" then return help() end
|
if o == "h" then return help() end
|
||||||
if o == "t" then toytype = a end
|
if o == "t" then toytype = a end
|
||||||
if o == "s" then subtype = a end
|
if o == "s" then subtype = a end
|
||||||
|
if o == "l" then return toys.List() end
|
||||||
end
|
end
|
||||||
|
|
||||||
if #toytype ~= 4 then return oops('Wrong size - toytype. (4hex symbols)') end
|
if #toytype ~= 4 then return oops('Wrong size - toytype. (4hex symbols)') end
|
||||||
|
@ -140,7 +143,8 @@ local function main(args)
|
||||||
local cmd = (csetuid..'%s 0004 08 w'):format(result.uid)
|
local cmd = (csetuid..'%s 0004 08 w'):format(result.uid)
|
||||||
core.console(cmd)
|
core.console(cmd)
|
||||||
|
|
||||||
local b1 = toytype..'00000000000000000000'..subtype
|
local b1 = toytype..string.rep('00',10)..subtype
|
||||||
|
|
||||||
local calc = utils.Crc16(b0..b1)
|
local calc = utils.Crc16(b0..b1)
|
||||||
local calcEndian = bor(rsh(calc,8), lsh(band(calc, 0xff), 8))
|
local calcEndian = bor(rsh(calc,8), lsh(band(calc, 0xff), 8))
|
||||||
|
|
||||||
|
|
|
@ -217,6 +217,7 @@ local function main(args)
|
||||||
local hex = utils.ConvertAsciiToBytes(aestest)
|
local hex = utils.ConvertAsciiToBytes(aestest)
|
||||||
hex = utils.ConvertBytesToHex(hex)
|
hex = utils.ConvertBytesToHex(hex)
|
||||||
blocks[blockNo+1] = ('%02d :: %s'):format(blockNo,hex)
|
blocks[blockNo+1] = ('%02d :: %s'):format(blockNo,hex)
|
||||||
|
io.write(blockNo..',')
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
else
|
else
|
||||||
|
@ -273,5 +274,7 @@ local function main(args)
|
||||||
print( (' UID : 0x%s'):format(uid) )
|
print( (' UID : 0x%s'):format(uid) )
|
||||||
print( (' CARDID : 0x%s'):format(cardid ) )
|
print( (' CARDID : 0x%s'):format(cardid ) )
|
||||||
print( string.rep('--',20) )
|
print( string.rep('--',20) )
|
||||||
|
|
||||||
|
core.clearCommandBuffer()
|
||||||
end
|
end
|
||||||
main(args)
|
main(args)
|
|
@ -23,10 +23,22 @@ Arguments:
|
||||||
-h : this help
|
-h : this help
|
||||||
-m : Maxed out items (experimental)
|
-m : Maxed out items (experimental)
|
||||||
-i : filename for the datadump to read (bin)
|
-i : filename for the datadump to read (bin)
|
||||||
|
|
||||||
]]
|
]]
|
||||||
|
|
||||||
local TIMEOUT = 2000 -- Shouldn't take longer than 2 seconds
|
local TIMEOUT = 2000 -- Shouldn't take longer than 2 seconds
|
||||||
local DEBUG = true -- the debug flag
|
local DEBUG = false -- the debug flag
|
||||||
|
local RANDOM = '20436F707972696768742028432920323031302041637469766973696F6E2E20416C6C205269676874732052657365727665642E20'
|
||||||
|
|
||||||
|
local band = bit32.band
|
||||||
|
local bor = bit32.bor
|
||||||
|
local lshift = bit32.lshift
|
||||||
|
local rshift = bit32.rshift
|
||||||
|
local byte = string.byte
|
||||||
|
local char = string.char
|
||||||
|
local sub = string.sub
|
||||||
|
local format = string.format
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
local band = bit32.band
|
local band = bit32.band
|
||||||
|
@ -197,8 +209,6 @@ local function ValidateCheckSums(blocks)
|
||||||
io.write( ('TYPE 3 area 2: %04x = %04x -- %s\n'):format(crc,calc,isOk))
|
io.write( ('TYPE 3 area 2: %04x = %04x -- %s\n'):format(crc,calc,isOk))
|
||||||
end
|
end
|
||||||
|
|
||||||
local function LoadEmulator(blocks)
|
|
||||||
local HASHCONSTANT = '20436F707972696768742028432920323031302041637469766973696F6E2E20416C6C205269676874732052657365727665642E20'
|
|
||||||
local cmd
|
local cmd
|
||||||
local blockdata
|
local blockdata
|
||||||
for _,b in pairs(blocks) do
|
for _,b in pairs(blocks) do
|
||||||
|
@ -207,10 +217,10 @@ local function LoadEmulator(blocks)
|
||||||
|
|
||||||
if _%4 ~= 3 then
|
if _%4 ~= 3 then
|
||||||
if (_ >= 8 and _<=21) or (_ >= 36 and _<=49) then
|
if (_ >= 8 and _<=21) or (_ >= 36 and _<=49) then
|
||||||
local base = ('%s%s%02x%s'):format(blocks[0], blocks[1], _ , HASHCONSTANT)
|
local base = ('%s%s%02x%s'):format(blocks[0], blocks[1], _ , RANDOM)
|
||||||
local baseStr = utils.ConvertHexToAscii(base)
|
local baseStr = utils.ConvertHexToAscii(base)
|
||||||
local key = md5.sumhexa(baseStr)
|
local key = md5.sumhexa(baseStr)
|
||||||
local enc = core.aes(key, blockdata)
|
local enc = core.aes128_encrypt(key, blockdata)
|
||||||
local hex = utils.ConvertAsciiToBytes(enc)
|
local hex = utils.ConvertAsciiToBytes(enc)
|
||||||
hex = utils.ConvertBytesToHex(hex)
|
hex = utils.ConvertBytesToHex(hex)
|
||||||
|
|
||||||
|
@ -346,21 +356,6 @@ local function main(args)
|
||||||
local cmdSetDbgOff = "hf mf dbg 0"
|
local cmdSetDbgOff = "hf mf dbg 0"
|
||||||
core.console( cmdSetDbgOff)
|
core.console( cmdSetDbgOff)
|
||||||
|
|
||||||
-- if not loadFromDump then
|
|
||||||
-- -- Look for tag present on reader,
|
|
||||||
-- result, err = lib14a.read1443a(false)
|
|
||||||
-- if not result then return oops(err) end
|
|
||||||
|
|
||||||
-- core.clearCommandBuffer()
|
|
||||||
|
|
||||||
-- if 0x01 ~= result.sak then -- NXP MIFARE TNP3xxx
|
|
||||||
-- return oops('This is not a TNP3xxx tag. aborting.')
|
|
||||||
-- end
|
|
||||||
|
|
||||||
-- -- Show tag info
|
|
||||||
-- print((' Found tag : %s'):format(result.name))
|
|
||||||
-- end
|
|
||||||
|
|
||||||
-- Load dump.bin file
|
-- Load dump.bin file
|
||||||
print( (' Load data from %s'):format(inputTemplate))
|
print( (' Load data from %s'):format(inputTemplate))
|
||||||
hex, err = utils.ReadDumpFile(inputTemplate)
|
hex, err = utils.ReadDumpFile(inputTemplate)
|
||||||
|
@ -374,7 +369,7 @@ local function main(args)
|
||||||
end
|
end
|
||||||
|
|
||||||
if DEBUG then
|
if DEBUG then
|
||||||
print('Validating checksums in the loaded datadump')
|
print(' Validating checksums')
|
||||||
ValidateCheckSums(blocks)
|
ValidateCheckSums(blocks)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
@ -407,12 +402,19 @@ local function main(args)
|
||||||
print( string.rep('--',20) )
|
print( string.rep('--',20) )
|
||||||
|
|
||||||
|
|
||||||
-- lets do something.
|
-- Experience should be:
|
||||||
--
|
|
||||||
local experience = blocks[8]:sub(1,6)
|
local experience = blocks[8]:sub(1,6)
|
||||||
print(('Experience : %d'):format(utils.SwapEndianness(experience,24)))
|
print(('Experience : %d'):format(utils.SwapEndianness(experience,16)))
|
||||||
|
|
||||||
local money = blocks[8]:sub(7,10)
|
local money = blocks[8]:sub(7,10)
|
||||||
print(('Money : %d'):format(utils.SwapEndianness(money,16)))
|
print(('Money : %d'):format(utils.SwapEndianness(money,16)))
|
||||||
|
|
||||||
|
--
|
||||||
|
|
||||||
|
-- Sequence number
|
||||||
|
local seqnum = blocks[8]:sub(18,19)
|
||||||
|
print(('Sequence number : %d'):format( tonumber(seqnum,16)))
|
||||||
|
|
||||||
local fairy = blocks[9]:sub(1,8)
|
local fairy = blocks[9]:sub(1,8)
|
||||||
--FD0F = Left, FF0F = Right
|
--FD0F = Left, FF0F = Right
|
||||||
local path = 'not choosen'
|
local path = 'not choosen'
|
||||||
|
@ -426,6 +428,12 @@ local function main(args)
|
||||||
local hat = blocks[9]:sub(8,11)
|
local hat = blocks[9]:sub(8,11)
|
||||||
print(('Hat : %d'):format(utils.SwapEndianness(hat,16)))
|
print(('Hat : %d'):format(utils.SwapEndianness(hat,16)))
|
||||||
|
|
||||||
|
local level = blocks[13]:sub(27,28)
|
||||||
|
print(('LEVEL : %d'):format( tonumber(level,16)))
|
||||||
|
--hälsa: 667 029b
|
||||||
|
--local health = blocks[]:sub();
|
||||||
|
--print(('Health : %d'):format( tonumber(health,16))
|
||||||
|
|
||||||
--0x0D 0x29 0x0A 0x02 16-bit hero points value. Maximum 100.
|
--0x0D 0x29 0x0A 0x02 16-bit hero points value. Maximum 100.
|
||||||
local heropoints = blocks[13]:sub(20,23)
|
local heropoints = blocks[13]:sub(20,23)
|
||||||
print(('Hero points : %d'):format(utils.SwapEndianness(heropoints,16)))
|
print(('Hero points : %d'):format(utils.SwapEndianness(heropoints,16)))
|
||||||
|
@ -434,6 +442,11 @@ local function main(args)
|
||||||
local challenges = blocks[16]:sub(25,32)
|
local challenges = blocks[16]:sub(25,32)
|
||||||
print(('Finished hero challenges : %d'):format(utils.SwapEndianness(challenges,32)))
|
print(('Finished hero challenges : %d'):format(utils.SwapEndianness(challenges,32)))
|
||||||
|
|
||||||
|
-- Character Name
|
||||||
|
local name1 = blocks[10]:sub(1,32)
|
||||||
|
local name2 = blocks[12]:sub(1,32)
|
||||||
|
print('Custom name : '..utils.ConvertHexToAscii(name1..name2))
|
||||||
|
|
||||||
if maxed then
|
if maxed then
|
||||||
print('Lets try to max out some values')
|
print('Lets try to max out some values')
|
||||||
-- max out money, experience
|
-- max out money, experience
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue