2010-01-15 11:18:11 +01:00
|
|
|
/*-
|
2010-11-17 15:27:11 +01:00
|
|
|
* Public platform independent Near Field Communication (NFC) library examples
|
2012-05-29 02:33:22 +02:00
|
|
|
*
|
2012-10-21 16:09:16 +02:00
|
|
|
* Copyright (C) 2009 Roel Verdult
|
|
|
|
* Copyright (C) 2010 Romuald Conty
|
2012-05-29 02:33:22 +02:00
|
|
|
*
|
2010-11-17 15:27:11 +01:00
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions are met:
|
|
|
|
* 1) Redistributions of source code must retain the above copyright notice,
|
2012-05-29 02:33:22 +02:00
|
|
|
* this list of conditions and the following disclaimer.
|
2010-11-17 15:27:11 +01:00
|
|
|
* 2 )Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
|
|
|
* AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
|
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
|
|
|
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
|
|
|
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
|
|
|
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
|
|
|
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
|
|
|
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
|
|
|
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
|
|
|
* POSSIBILITY OF SUCH DAMAGE.
|
2012-05-29 02:33:22 +02:00
|
|
|
*
|
2010-11-17 15:27:11 +01:00
|
|
|
* Note that this license only applies on the examples, NFC library itself is under LGPL
|
2009-10-12 16:52:26 +02:00
|
|
|
*
|
2010-01-15 11:18:11 +01:00
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
2010-10-08 16:05:10 +02:00
|
|
|
* @file nfc-emulate-uid.c
|
2010-10-14 13:53:27 +02:00
|
|
|
* @brief Emulates a tag which which have a "really" custom UID
|
2012-05-29 02:33:22 +02:00
|
|
|
*
|
2010-10-08 21:24:54 +02:00
|
|
|
* NFC devices are able to emulate passive tags but manufacturers restrict the
|
|
|
|
* customization of UID. With PN53x, UID is only 4-byte long and the first
|
|
|
|
* byte of emulated UID is hard-wired to 0x08 which is the standard way to say
|
|
|
|
* this is a random UID. This example shows how to emulate a fully customized
|
|
|
|
* UID by "manually" replying to anti-collision process sent by the initiator.
|
2009-10-12 16:52:26 +02:00
|
|
|
*/
|
2009-05-01 17:47:44 +02:00
|
|
|
|
2010-01-15 11:18:11 +01:00
|
|
|
#ifdef HAVE_CONFIG_H
|
2010-09-07 19:51:03 +02:00
|
|
|
# include "config.h"
|
2010-01-15 11:18:11 +01:00
|
|
|
#endif // HAVE_CONFIG_H
|
|
|
|
|
2009-05-01 17:47:44 +02:00
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
2009-05-27 14:18:21 +02:00
|
|
|
#include <stddef.h>
|
2009-05-27 12:13:19 +02:00
|
|
|
#include <stdint.h>
|
2009-05-01 17:47:44 +02:00
|
|
|
#include <string.h>
|
2010-10-12 17:51:57 +02:00
|
|
|
#include <signal.h>
|
2009-05-27 12:13:19 +02:00
|
|
|
|
2009-12-01 15:23:00 +01:00
|
|
|
#include <nfc/nfc.h>
|
2009-11-02 12:34:58 +01:00
|
|
|
|
2011-09-30 13:33:31 +02:00
|
|
|
#include "utils/nfc-utils.h"
|
2009-05-01 17:47:44 +02:00
|
|
|
|
2009-11-10 10:47:59 +01:00
|
|
|
#define MAX_FRAME_LEN 264
|
|
|
|
|
2011-11-24 11:54:42 +01:00
|
|
|
static uint8_t abtRecv[MAX_FRAME_LEN];
|
2012-01-09 12:26:57 +01:00
|
|
|
static int szRecvBits;
|
2011-11-23 16:55:40 +01:00
|
|
|
static nfc_device *pnd;
|
2009-05-01 17:47:44 +02:00
|
|
|
|
|
|
|
// ISO14443A Anti-Collision response
|
2011-11-24 11:54:42 +01:00
|
|
|
uint8_t abtAtqa[2] = { 0x04, 0x00 };
|
2013-01-22 00:45:42 +01:00
|
|
|
uint8_t abtUidBcc[5] = { 0xDE, 0xAD, 0xBE, 0xEF, 0x22 };
|
2011-11-24 11:54:42 +01:00
|
|
|
uint8_t abtSak[9] = { 0x08, 0xb6, 0xdd };
|
2009-05-01 17:47:44 +02:00
|
|
|
|
2012-05-13 14:48:28 +02:00
|
|
|
static void
|
2012-05-29 17:54:36 +02:00
|
|
|
intr_hdlr(int sig)
|
2010-10-12 17:51:57 +02:00
|
|
|
{
|
2012-05-14 15:47:31 +02:00
|
|
|
(void) sig;
|
2010-10-12 17:51:57 +02:00
|
|
|
if (pnd != NULL) {
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("\nAborting current command...\n");
|
|
|
|
nfc_abort_command(pnd);
|
2010-10-12 17:51:57 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2012-05-13 14:48:28 +02:00
|
|
|
static void
|
2012-05-29 17:54:36 +02:00
|
|
|
print_usage(char *argv[])
|
2009-09-07 12:15:34 +02:00
|
|
|
{
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("Usage: %s [OPTIONS] [UID]\n", argv[0]);
|
|
|
|
printf("Options:\n");
|
|
|
|
printf("\t-h\tHelp. Print this message.\n");
|
|
|
|
printf("\t-q\tQuiet mode. Silent output: received and sent frames will not be shown (improves timing).\n");
|
|
|
|
printf("\n");
|
|
|
|
printf("\t[UID]\tUID to emulate, specified as 8 HEX digits (default is DEADBEEF).\n");
|
2009-09-07 12:15:34 +02:00
|
|
|
}
|
|
|
|
|
2010-09-07 19:51:03 +02:00
|
|
|
int
|
2012-05-29 17:54:36 +02:00
|
|
|
main(int argc, char *argv[])
|
2009-09-07 12:15:34 +02:00
|
|
|
{
|
2011-11-24 11:54:42 +01:00
|
|
|
uint8_t *pbtTx = NULL;
|
2010-09-07 19:51:03 +02:00
|
|
|
size_t szTxBits;
|
|
|
|
bool quiet_output = false;
|
2009-08-23 11:50:46 +02:00
|
|
|
|
2010-09-07 19:51:03 +02:00
|
|
|
int arg,
|
|
|
|
i;
|
2009-09-07 12:15:34 +02:00
|
|
|
|
2009-08-23 11:50:46 +02:00
|
|
|
// Get commandline options
|
2010-09-07 19:51:03 +02:00
|
|
|
for (arg = 1; arg < argc; arg++) {
|
2012-05-29 17:54:36 +02:00
|
|
|
if (0 == strcmp(argv[arg], "-h")) {
|
|
|
|
print_usage(argv);
|
2010-10-08 16:05:10 +02:00
|
|
|
exit(EXIT_SUCCESS);
|
2012-05-29 17:54:36 +02:00
|
|
|
} else if (0 == strcmp(argv[arg], "-q")) {
|
|
|
|
printf("Quiet mode.\n");
|
2009-08-26 12:57:38 +02:00
|
|
|
quiet_output = true;
|
2012-05-29 17:54:36 +02:00
|
|
|
} else if ((arg == argc - 1) && (strlen(argv[arg]) == 8)) { // See if UID was specified as HEX string
|
2011-11-24 11:54:42 +01:00
|
|
|
uint8_t abtTmp[3] = { 0x00, 0x00, 0x00 };
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("[+] Using UID: %s\n", argv[arg]);
|
2010-09-07 19:51:03 +02:00
|
|
|
abtUidBcc[4] = 0x00;
|
|
|
|
for (i = 0; i < 4; ++i) {
|
2012-05-29 17:54:36 +02:00
|
|
|
memcpy(abtTmp, argv[arg] + i * 2, 2);
|
|
|
|
abtUidBcc[i] = (uint8_t) strtol((char *) abtTmp, NULL, 16);
|
2009-09-07 12:15:34 +02:00
|
|
|
abtUidBcc[4] ^= abtUidBcc[i];
|
|
|
|
}
|
|
|
|
} else {
|
2012-05-29 17:54:36 +02:00
|
|
|
ERR("%s is not supported option.", argv[arg]);
|
|
|
|
print_usage(argv);
|
2010-10-08 16:05:10 +02:00
|
|
|
exit(EXIT_FAILURE);
|
2009-08-23 11:50:46 +02:00
|
|
|
}
|
2009-08-21 15:34:53 +02:00
|
|
|
}
|
|
|
|
|
2010-10-12 17:51:57 +02:00
|
|
|
#ifdef WIN32
|
2012-05-29 17:54:36 +02:00
|
|
|
signal(SIGINT, (void (__cdecl *)(int)) intr_hdlr);
|
2010-10-12 17:51:57 +02:00
|
|
|
#else
|
2012-05-29 17:54:36 +02:00
|
|
|
signal(SIGINT, intr_hdlr);
|
2010-10-12 17:51:57 +02:00
|
|
|
#endif
|
|
|
|
|
2012-12-04 19:29:57 +01:00
|
|
|
nfc_context *context;
|
|
|
|
nfc_init(&context);
|
2012-05-29 02:33:22 +02:00
|
|
|
|
2010-10-08 16:05:10 +02:00
|
|
|
// Try to open the NFC device
|
2012-12-04 19:29:57 +01:00
|
|
|
pnd = nfc_open(context, NULL);
|
2009-09-07 12:15:34 +02:00
|
|
|
|
2010-09-07 19:51:03 +02:00
|
|
|
if (pnd == NULL) {
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("Unable to open NFC device\n");
|
2010-10-08 16:05:10 +02:00
|
|
|
exit(EXIT_FAILURE);
|
2009-05-01 17:47:44 +02:00
|
|
|
}
|
|
|
|
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("\n");
|
|
|
|
printf("NFC device: %s opened\n", nfc_device_get_name(pnd));
|
|
|
|
printf("[+] Try to break out the auto-emulation, this requires a second NFC device!\n");
|
|
|
|
printf("[+] To do this, please send any command after the anti-collision\n");
|
|
|
|
printf("[+] For example, send a RATS command or use the \"nfc-anticol\" or \"nfc-list\" tool.\n");
|
2010-10-04 14:46:03 +02:00
|
|
|
|
2011-11-23 16:55:40 +01:00
|
|
|
// Note: We have to build a "fake" nfc_target in order to do exactly the same that was done before the new nfc_target_init() was introduced.
|
|
|
|
nfc_target nt = {
|
2011-02-28 10:47:31 +01:00
|
|
|
.nm = {
|
|
|
|
.nmt = NMT_ISO14443A,
|
|
|
|
.nbr = NBR_UNDEFINED,
|
|
|
|
},
|
|
|
|
.nti = {
|
|
|
|
.nai = {
|
|
|
|
.abtAtqa = { 0x04, 0x00 },
|
|
|
|
.abtUid = { 0x08, 0xad, 0xbe, 0xef },
|
|
|
|
.btSak = 0x20,
|
|
|
|
.szUidLen = 4,
|
|
|
|
.szAtsLen = 0,
|
|
|
|
},
|
|
|
|
},
|
2010-10-04 14:46:03 +02:00
|
|
|
};
|
2012-05-29 17:54:36 +02:00
|
|
|
if ((szRecvBits = nfc_target_init(pnd, &nt, abtRecv, sizeof(abtRecv), 0)) < 0) {
|
|
|
|
nfc_perror(pnd, "nfc_target_init");
|
|
|
|
ERR("Could not come out of auto-emulation, no command was received");
|
2011-05-05 16:24:27 +02:00
|
|
|
goto error;
|
2009-05-01 17:47:44 +02:00
|
|
|
}
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("[+] Received initiator command: ");
|
|
|
|
print_hex_bits(abtRecv, (size_t) szRecvBits);
|
|
|
|
printf("[+] Configuring communication\n");
|
|
|
|
if ((nfc_device_set_property_bool(pnd, NP_HANDLE_CRC, false) < 0) || (nfc_device_set_property_bool(pnd, NP_HANDLE_PARITY, true) < 0)) {
|
|
|
|
nfc_perror(pnd, "nfc_device_set_property_bool");
|
|
|
|
exit(EXIT_FAILURE);
|
2010-08-18 19:22:13 +02:00
|
|
|
}
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("[+] Done, the emulated tag is initialized with UID: %02X%02X%02X%02X\n\n", abtUidBcc[0], abtUidBcc[1],
|
|
|
|
abtUidBcc[2], abtUidBcc[3]);
|
2009-05-01 17:47:44 +02:00
|
|
|
|
2010-09-07 19:51:03 +02:00
|
|
|
while (true) {
|
2009-05-01 17:47:44 +02:00
|
|
|
// Test if we received a frame
|
2012-05-29 17:54:36 +02:00
|
|
|
if ((szRecvBits = nfc_target_receive_bits(pnd, abtRecv, sizeof(abtRecv), 0)) > 0) {
|
2009-05-01 17:47:44 +02:00
|
|
|
// Prepare the command to send back for the anti-collision request
|
2010-09-07 19:51:03 +02:00
|
|
|
switch (szRecvBits) {
|
2012-05-29 17:52:51 +02:00
|
|
|
case 7: // Request or Wakeup
|
|
|
|
pbtTx = abtAtqa;
|
|
|
|
szTxBits = 16;
|
|
|
|
// New anti-collsion session started
|
|
|
|
if (!quiet_output)
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("\n");
|
2012-05-29 17:52:51 +02:00
|
|
|
break;
|
|
|
|
|
|
|
|
case 16: // Select All
|
|
|
|
pbtTx = abtUidBcc;
|
|
|
|
szTxBits = 40;
|
|
|
|
break;
|
|
|
|
|
|
|
|
case 72: // Select Tag
|
|
|
|
pbtTx = abtSak;
|
|
|
|
szTxBits = 24;
|
|
|
|
break;
|
|
|
|
|
|
|
|
default: // unknown length?
|
|
|
|
szTxBits = 0;
|
|
|
|
break;
|
2009-05-01 17:47:44 +02:00
|
|
|
}
|
|
|
|
|
2010-09-07 19:51:03 +02:00
|
|
|
if (!quiet_output) {
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("R: ");
|
|
|
|
print_hex_bits(abtRecv, (size_t) szRecvBits);
|
2009-08-23 11:50:46 +02:00
|
|
|
}
|
2009-05-01 17:47:44 +02:00
|
|
|
// Test if we know how to respond
|
2010-09-07 19:51:03 +02:00
|
|
|
if (szTxBits) {
|
2009-05-01 17:47:44 +02:00
|
|
|
// Send and print the command to the screen
|
2012-05-29 17:54:36 +02:00
|
|
|
if (nfc_target_send_bits(pnd, pbtTx, szTxBits, NULL) < 0) {
|
|
|
|
nfc_perror(pnd, "nfc_target_send_bits");
|
2011-05-05 16:24:27 +02:00
|
|
|
goto error;
|
2010-08-18 19:22:13 +02:00
|
|
|
}
|
2010-09-07 19:51:03 +02:00
|
|
|
if (!quiet_output) {
|
2012-05-29 17:54:36 +02:00
|
|
|
printf("T: ");
|
|
|
|
print_hex_bits(pbtTx, szTxBits);
|
2009-08-23 11:50:46 +02:00
|
|
|
}
|
2009-05-01 17:47:44 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2012-05-29 17:54:36 +02:00
|
|
|
nfc_close(pnd);
|
2012-12-04 19:29:57 +01:00
|
|
|
nfc_exit(context);
|
2012-05-29 17:54:36 +02:00
|
|
|
exit(EXIT_SUCCESS);
|
2011-05-05 16:24:27 +02:00
|
|
|
|
|
|
|
error:
|
2012-05-29 17:54:36 +02:00
|
|
|
nfc_close(pnd);
|
2012-12-04 19:29:57 +01:00
|
|
|
nfc_exit(context);
|
2012-05-29 17:54:36 +02:00
|
|
|
exit(EXIT_FAILURE);
|
2009-05-01 17:47:44 +02:00
|
|
|
}
|