Closed BreakSecurity closed 4 years ago
@bogiton , maybe something for you?
PR #462 should fix it. Added a new lua script that uses SPIFFS instead (read_pwd_mem_spiffs.lua) that reads the hf_bog.log file where the passwords are saved now. Could be adapted for other files too.
yeah, @BreakSecurity test it, I merged @bogiton 's PR
script run read_pwd_mem_spiffs.lua -f hf_bog.log
Give the output:
---------------------------------------- Read passwords stored in memory (SPIFFS) ---------------------------------------- [01] 00000000 [02] 00000000 [03] 00000000 [04] 00000000 [05] 00000000 [06] 00000000 [07] 00000000 [08] 00000000 [09] 00000000 [10] 00000000 [11] 00000000 [12] 00000000 ---------------------------------------- [+] found 12 passwords [+] Finished read_pwd_mem_spiffs.lua
It should only give the ffffffff psw
The lua script stops when it finds a 0xFFFFFFFF value, just like the previous one. The logic behind this is that you normally won't have to sniff that default pwd but most importantly, at least in the previous version of the flash mem, the initial values (after wipe) is full of FFs. That is why it was chosen as the stop value. Of course, since we now use SPIFFS we could omit this restriction. @iceman1001 what do you think?
if we download a file from spiffs, we really don't need a stop value :) the number of bytes read from spiffs should be the limit. But why does it add 0x00 00 00 00 serveral times? aha, you append regardsless of previous findings.
Should be fixed with latest fixes from @bogiton
Describe the bug
script run read_pwd_mem -k 6
print tons of empty passwordsTo Reproduce Steps to reproduce the behavior: Set prox RDV4 in Bogito Standalone mode With a second proxmark try:
hf mfu dump k FFFFFFFF
Then exit standalone mode (on rdv4) and try:script run read_pwd_mem -k 6
Desktop (please complete the following information):
hw status
data tune
[=] You can cancel this operation by pressing the pm3 button ..
[+] LF antenna: 65.86 V - 125.00 kHz [+] LF antenna: 41.92 V - 134.00 kHz [+] LF optimal: 65.86 V - 125.00 kHz [+] LF antenna is OK
[+] HF antenna: 35.38 V - 13.56 MHz [+] HF antenna is OK
[+] Displaying LF tuning graph. Divisor 89 is 134kHz, 95 is 125kHz.