1 //-----------------------------------------------------------------------------
2 // Copyright (C) Proxmark3 contributors. See AUTHORS.md for details.
4 // This program is free software: you can redistribute it and/or modify
5 // it under the terms of the GNU General Public License as published by
6 // the Free Software Foundation, either version 3 of the License, or
7 // (at your option) any later version.
9 // This program is distributed in the hope that it will be useful,
10 // but WITHOUT ANY WARRANTY; without even the implied warranty of
11 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 // GNU General Public License for more details.
14 // See LICENSE.txt for the text of the license.
15 //-----------------------------------------------------------------------------
16 // Low frequency T55xx commands
17 //-----------------------------------------------------------------------------
19 #ifndef CMDLFT55XX_H__
20 #define CMDLFT55XX_H__
24 #define T55x7_CONFIGURATION_BLOCK 0x00
25 #define T55x7_PWD_BLOCK 0x07
26 #define T55x7_TRACE_BLOCK1 0x01
27 #define T55x7_TRACE_BLOCK2 0x02
28 #define T55x7_PAGE0 0x00
29 #define T55x7_PAGE1 0x01
30 #define T55x7_PWD 0x00000010
31 #define REGULAR_READ_MODE_BLOCK 0xFF
32 #define T55x7_BLOCK_COUNT 12
35 #define T55X7_DEFAULT_CONFIG_BLOCK 0x000880E8 // ASK, compat mode, data rate 32, manchester, STT, 7 data blocks
36 #define T55X7_RAW_CONFIG_BLOCK 0x000880E0 // ASK, compat mode, data rate 32, manchester, 7 data blocks
37 #define T55X7_EM_UNIQUE_CONFIG_BLOCK 0x00148040 // ASK, EM4x02/unique - compat mode, manchester, data rate 64, 2 data blocks
38 #define T55X7_EM_PAXTON_CONFIG_BLOCK 0x00148040 // ASK, EM4x02/paxton - compat mode, manchester, data rate 64, 2 data blocks
39 #define T55X7_VISA2000_CONFIG_BLOCK 0x00148068 // ASK, data rate 64, 3 data blocks, STT
40 #define T55X7_VIKING_CONFIG_BLOCK 0x00088040 // ASK, compat mode, data rate 32, Manchester, 2 data blocks
41 #define T55X7_NORALSY_CONFIG_BLOCK 0x00088C6A // ASK, compat mode, (NORALSY - KCP3000), data rate 32, 3 data blocks
42 #define T55X7_PRESCO_CONFIG_BLOCK 0x00088088 // ASK, data rate 32, Manchester, 4 data blocks, STT
43 #define T55X7_SECURAKEY_CONFIG_BLOCK 0x000C8060 // ASK, Manchester, data rate 40, 3 data blocks
44 #define T55X7_UNK_CONFIG_BLOCK 0x000880FA // ASK, Manchester, data rate 32, 7 data blocks STT, Inverse ...
45 #define T55X7_PYRONIX_CONFIG_BLOCK 0x00088C40 // ASK, Manchester, data rate 32, 2 data blocks
47 // FDXB requires data inversion and BiPhase 57 is simply BiPhase 50 inverted, so we can either do it using the modulation scheme or the inversion flag
48 // we've done both below to prove that it works either way, and the modulation value for BiPhase 50 in the Atmel data sheet of binary "10001" (17) is a typo,
49 // and it should actually be "10000" (16)
50 // #define T55X7_FDXB_CONFIG_BLOCK 0x903F8080 // BiPhase, fdx-b - xtended mode, BiPhase ('57), data rate 32, 4 data blocks
51 #define T55X7_FDXB_CONFIG_BLOCK 0x903F0082 // BiPhase, fdx-b - xtended mode, BiPhase ('50), invert data, data rate 32, 4 data blocks
52 #define T55X7_FDXB_2_CONFIG_BLOCK 0x00098080 //
54 #define T55X7_HID_26_CONFIG_BLOCK 0x00107060 // FSK2a, hid 26 bit - compat mode, data rate 50, 3 data blocks
55 #define T55X7_PARADOX_CONFIG_BLOCK 0x00107060 // FSK2a, hid 26 bit - compat mode, data rate 50, 3 data blocks
56 #define T55X7_AWID_CONFIG_BLOCK 0x00107060 // FSK2a, hid 26 bit - compat mode, data rate 50, 3 data blocks
57 #define T55X7_PYRAMID_CONFIG_BLOCK 0x00107080 // FSK2a, Pyramid 26 bit - compat mode, data rate 50, 4 data blocks
58 #define T55X7_IOPROX_CONFIG_BLOCK 0x00147040 // FSK2a, data rate 64, 2 data blocks
60 #define T55X7_INDALA_64_CONFIG_BLOCK 0x00081040 // PSK1, indala 64 bit - compat mode, psk carrier FC * 2, data rate 32, maxblock 2
61 #define T55X7_INDALA_224_CONFIG_BLOCK 0x000810E0 // PSK1, indala 224 bit - compat mode, psk carrier FC * 2, data rate 32, maxblock 7
62 #define T55X7_MOTOROLA_CONFIG_BLOCK 0x00081040 // PSK1, data rate 32, 2 data blocks
63 #define T55X7_NEXWATCH_CONFIG_BLOCK 0x00081060 // PSK1 data rate 16, psk carrier FC * 2, 3 data blocks
64 #define T55X7_KERI_CONFIG_BLOCK 0x603E1040 // PSK1, 2 data blocks
65 #define T55X7_IDTECK_CONFIG_BLOCK 0x00081040 // PSK1, data rate 32, 2 data blocks
67 #define T55X7_JABLOTRON_CONFIG_BLOCK 0x00158040 // Biphase, data rate 64, 2 data blocks
68 #define T55X7_GUARDPROXII_CONFIG_BLOCK 0x00150060 // Biphase, data rate 64, Direct modulation, 3 data blocks
69 #define T55X7_NEDAP_64_CONFIG_BLOCK 0x907f0042 // BiPhase, data rate 64, 2 data blocks
70 #define T55X7_NEDAP_128_CONFIG_BLOCK 0x907f0082 // BiPhase, data rate 64, 4 data blocks
72 #define T55X7_PAC_CONFIG_BLOCK 0x00080080 // NRZ, data rate 32, 4 data blocks
73 #define T55X7_VERICHIP_CONFIG_BLOCK 0x000C0080 // NRZ, data rate 40, 4 data blocks
75 #define T55X7_bin 0b0010
77 // Q5 / Termic / T5555
78 #define T5555_DEFAULT_CONFIG_BLOCK 0x6001F004 // ASK, data rate 64, manchester, 2 data blocks?
130 DEMOD_FSK
= 0xF0, //generic FSK (auto detect FCs)
137 t55xx_modulation modulation
;
163 refLongLeading
= 0x01,
167 } t55xx_conf_block_t
;
172 } t55xx_memory_item_t
;
174 t55xx_conf_block_t
Get_t55xx_Config(void);
175 void Set_t55xx_Config(t55xx_conf_block_t conf
);
177 int CmdLFT55XX(const char *Cmd
);
179 void SetConfigWithBlock0(uint32_t block0
);
180 void SetConfigWithBlock0Ex(uint32_t block0
, uint8_t offset
, bool Q5
);
182 char *GetPskCfStr(uint32_t id
, bool q5
);
183 char *GetBitRateStr(uint32_t id
, bool xmode
);
184 char *GetSaferStr(uint32_t id
);
185 char *GetQ5ModulationStr(uint32_t id
);
186 char *GetModulationStr(uint32_t id
, bool xmode
);
187 char *GetModelStrFromCID(uint32_t cid
);
188 char *GetConfigBlock0Source(uint8_t id
);
189 char *GetSelectedModulationStr(uint8_t id
);
190 char *GetDownlinkModeStr(uint8_t downlink_mode
);
191 void printT5xxHeader(uint8_t page
);
192 void printT55xxBlock(uint8_t blockNum
, bool page1
);
193 int printConfiguration(t55xx_conf_block_t b
);
195 bool t55xxAcquireAndCompareBlock0(bool usepwd
, uint32_t password
, uint32_t known_block0
, bool verbose
);
196 bool t55xxAcquireAndDetect(bool usepwd
, uint32_t password
, uint32_t known_block0
, bool verbose
);
197 bool t55xxVerifyWrite(uint8_t block
, bool page1
, bool usepwd
, uint8_t override
, uint32_t password
, uint8_t downlink_mode
, uint32_t data
);
198 int T55xxReadBlock(uint8_t block
, bool page1
, bool usepwd
, uint8_t override
, uint32_t password
, uint8_t downlink_mode
);
199 int T55xxReadBlockEx(uint8_t block
, bool page1
, bool usepwd
, uint8_t override
, uint32_t password
, uint8_t downlink_mode
, bool verbose
);
201 int t55xxWrite(uint8_t block
, bool page1
, bool usepwd
, bool testMode
, uint32_t password
, uint8_t downlink_mode
, uint32_t data
);
203 bool GetT55xxBlockData(uint32_t *blockdata
);
204 bool DecodeT55xxBlock(void);
205 bool t55xxTryDetectModulation(uint8_t downlink_mode
, bool print_config
);
206 //bool t55xxTryDetectModulationEx(uint8_t downlink_mode, bool print_config, uint32_t wanted_conf);
207 bool t55xxTryDetectModulationEx(uint8_t downlink_mode
, bool print_config
, uint32_t wanted_conf
, uint64_t pwd
);
208 bool testKnownConfigBlock(uint32_t block0
);
210 bool tryDetectP1(bool getData
);
211 bool test(uint8_t mode
, uint8_t *offset
, int *fndBitRate
, uint8_t clk
, bool *Q5
);
212 int CmdT55xxSpecial(const char *Cmd
);
213 bool AcquireData(uint8_t page
, uint8_t block
, bool pwdmode
, uint32_t password
, uint8_t downlink_mode
);
214 uint8_t t55xx_try_one_password(uint32_t password
, uint8_t downlink_mode
, bool try_all_dl_modes
);
216 void printT55x7Trace(t55x7_tracedata_t data
, uint8_t repeat
);
217 void printT5555Trace(t5555_tracedata_t data
, uint8_t repeat
);
219 int clone_t55xx_tag(uint32_t *blockdata
, uint8_t numblocks
);