proxmark3/pm3

549 lines
17 KiB
Text
Raw Normal View History

#!/usr/bin/env bash
2019-09-09 18:58:11 +08:00
# Usage: run option -h to get help
2020-04-29 21:15:25 +08:00
# BT auto detection
# Shall we look for white HC-06-USB dongle ?
FINDBTDONGLE=true
# Shall we look for rfcomm interface ?
2020-04-29 21:15:25 +08:00
FINDBTRFCOMM=true
# Shall we look for registered BT device ? (Linux only)
FINDBTDIRECT=true
2019-07-15 00:20:41 +08:00
PM3PATH=$(dirname "$0")
2020-11-14 07:44:18 +08:00
EVALENV=""
2019-09-10 01:55:27 +08:00
FULLIMAGE="fullimage.elf"
BOOTIMAGE="bootrom.elf"
2020-12-29 23:38:02 +08:00
#Skip check if --list is used
if [ ! "$1" == "--list" ]; then
2021-06-05 04:08:32 +08:00
# try pm3 dirs in current repo workdir
if [ -d "$PM3PATH/client/" ]; then
if [ -x "$PM3PATH/client/proxmark3" ]; then
CLIENT="$PM3PATH/client/proxmark3"
elif [ -x "$PM3PATH/client/build/proxmark3" ]; then
CLIENT="$PM3PATH/client/build/proxmark3"
else
echo >&2 "[!!] In devel workdir but no executable found, did you compile it?"
exit 1
fi
# Devel mode: point to workdir pm3.py module
EVALENV+=" PYTHONPATH=$PM3PATH/client/src"
# try install dir
elif [ -x "$PM3PATH/proxmark3" ]; then
CLIENT="$PM3PATH/proxmark3"
EVALENV+=" PYTHONPATH=$PM3PATH/../share/proxmark3/pyscripts/"
# or /usr/[local/]lib/python3/dist-packages/pm3.py ?
else
# hope it's installed somehow, still not sure where fw images and pm3.py are...
CLIENT="proxmark3"
fi
fi
2020-12-29 23:38:02 +08:00
# LeakSanitizer suppressions
if [ -e .lsan_suppressions ]; then
2020-11-14 07:44:18 +08:00
EVALENV+=" LSAN_OPTIONS=suppressions=.lsan_suppressions"
fi
if [ "$EVALENV" != "" ]; then
EVALENV="export $EVALENV"
fi
PM3LIST=()
SHOWLIST=false
function get_pm3_list_Linux {
2020-04-21 23:11:18 +08:00
N=$1
PM3LIST=()
if [ ! -c "/dev/tty0" ]; then
echo >&2 "[!!] Script cannot access /dev/ttyXXX files, insufficient privileges"
exit 1
fi
for DEV in $(find /dev/ttyACM* 2>/dev/null); do
2021-09-05 06:34:26 +08:00
if command -v udevadm >/dev/null; then
# WSL1 detection
if udevadm info -q property -n "$DEV" | grep -q "ID_VENDOR=proxmark.org"; then
PM3LIST+=("$DEV")
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
fi
fi
# WSL2 with usbipd detection - doesn't report same things as WSL1
if grep -q "proxmark.org" "/sys/class/tty/${DEV#/dev/}/../../../manufacturer" 2>/dev/null; then
PM3LIST+=("$DEV")
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
2020-04-21 23:11:18 +08:00
fi
2019-07-15 00:20:41 +08:00
fi
2019-03-09 18:10:22 +08:00
done
if $FINDBTDONGLE; then
# check if the HC-06-USB white dongle is present (still, that doesn't tell us if it's paired with a Proxmark3...)
for DEV in $(find /dev/ttyUSB* 2>/dev/null); do
2021-09-05 06:34:26 +08:00
if command -v udevadm >/dev/null; then
if udevadm info -q property -n "$DEV" | grep -q "ID_MODEL=CP2104_USB_to_UART_Bridge_Controller"; then
PM3LIST+=("$DEV")
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
fi
else
if grep -q "DRIVER=cp210x" "/sys/class/tty/${DEV#/dev/}/../../uevent" 2>/dev/null; then
PM3LIST+=("$DEV")
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
2020-04-21 23:11:18 +08:00
fi
fi
done
fi
2020-04-29 21:15:25 +08:00
if $FINDBTRFCOMM; then
# check if the MAC of a Proxmark3 was bound to a local rfcomm interface
2020-04-29 21:15:25 +08:00
# (on OSes without deprecated rfcomm and hcitool, the loop will be simply skipped)
for DEVMAC in $(rfcomm -a 2>/dev/null | grep " 20:19:0[45]" | sed 's/^\(.*\): \([0-9:]*\) .*/\1@\2/'); do
DEV=${DEVMAC/@*/}
MAC=${DEVMAC/*@/}
2020-04-29 21:15:25 +08:00
# check which are Proxmark3 and, side-effect, if they're actually present
if hcitool name "$MAC" | grep -q "PM3"; then
PM3LIST+=("/dev/$DEV")
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
2020-04-21 23:11:18 +08:00
return
fi
fi
done
fi
2020-04-29 21:15:25 +08:00
if $FINDBTDIRECT; then
# check if the MAC of a Proxmark3 was registered in the known devices
2020-04-29 21:29:34 +08:00
for MAC in $(dbus-send --system --print-reply --type=method_call --dest='org.bluez' '/' org.freedesktop.DBus.ObjectManager.GetManagedObjects 2>/dev/null|\
2020-04-29 21:15:25 +08:00
awk '/"Address"/{getline;gsub(/"/,"",$3);a=$3}/Name/{getline;if (/PM3_RDV4/) print a}'); do
PM3LIST+=("bt:$MAC")
done
# we don't probe the device so there is no guarantee the device is actually present
fi
}
function get_pm3_list_macOS {
2020-04-21 23:11:18 +08:00
N=$1
PM3LIST=()
for DEV in $(ioreg -r -c "IOUSBHostDevice" -l | awk -F '"' '
$2=="USB Vendor Name"{b=($4=="proxmark.org")}
b==1 && $2=="IODialinDevice"{print $4}'); do
PM3LIST+=("$DEV")
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
2020-04-21 23:11:18 +08:00
return
fi
2019-03-09 18:10:22 +08:00
done
}
function get_pm3_list_Windows {
2020-04-21 23:11:18 +08:00
N=$1
PM3LIST=()
2021-10-17 05:44:46 +08:00
2021-12-13 07:42:02 +08:00
# Normal SERIAL PORTS (COM)
2021-02-10 17:59:49 +08:00
for DEV in $(wmic /locale:ms_409 path Win32_SerialPort Where "PNPDeviceID LIKE '%VID_9AC4&PID_4B8F%' Or PNPDeviceID LIKE '%VID_2D2D&PID_504D%'" Get DeviceID 2>/dev/null | awk -b '/^COM/{print $1}'); do
2021-02-10 16:31:08 +08:00
DEV=${DEV/ */}
2021-06-05 04:08:32 +08:00
#prevent soft bricking when using pm3-flash-all on an outdated bootloader
if [ $(basename -- "$0") = "pm3-flash-all" ]; then
if [ ! $(wmic /locale:ms_409 path Win32_SerialPort Where "DeviceID='$DEV'" Get PNPDeviceID 2>/dev/null | awk -b '/^USB/{print $1}') = "USB\VID_9AC4&PID_4B8F\ICEMAN" ]; then
echo -e "\033[0;31m[!] Using pm3-flash-all on an oudated bootloader, use pm3-flash-bootrom first!"
exit 1
fi
fi
2021-09-19 07:31:17 +08:00
PM3LIST+=("$DEV")
2021-02-10 16:31:08 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
done
2021-10-17 05:44:46 +08:00
2021-09-19 07:31:17 +08:00
#BT direct SERIAL PORTS (COM)
if $FINDBTRFCOMM; then
for DEV in $(wmic /locale:ms_409 path Win32_PnPEntity Where "Caption LIKE '%Bluetooth%(COM%'" Get Name 2> /dev/null | awk -b 'match($0,/(COM[0-9]+)/,m){print m[1]}'); do
DEV=${DEV/ */}
PM3LIST+=("$DEV")
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
done
fi
#white BT dongle SERIAL PORTS (COM)
if $FINDBTDONGLE; then
2020-11-29 08:58:16 +08:00
for DEV in $(wmic /locale:ms_409 path Win32_SerialPort Where "PNPDeviceID LIKE '%VID_10C4&PID_EA60%'" Get DeviceID 2>/dev/null | awk -b '/^COM/{print $1}'); do
DEV=${DEV/ */}
PM3LIST+=("$DEV")
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
done
fi
}
function get_pm3_list_WSL {
N=$1
PM3LIST=()
2021-10-17 05:44:46 +08:00
2021-12-13 07:42:02 +08:00
# Normal SERIAL PORTS (COM)
2021-03-23 03:46:39 +08:00
for DEV in $($PSHEXE -command "Get-CimInstance -ClassName Win32_serialport | Where-Object {\$_.PNPDeviceID -like '*VID_9AC4&PID_4B8F*' -or \$_.PNPDeviceID -like '*VID_2D2D&PID_504D*'} | Select -expandproperty DeviceID" 2>/dev/null | tr -dc '[:print:]'); do
2021-06-05 04:08:32 +08:00
_comport=$DEV
DEV=$(echo $DEV | sed -nr 's#^COM([0-9]+)\b#/dev/ttyS\1#p')
2021-02-10 16:31:08 +08:00
# ttyS counterpart takes some more time to appear
if [ -e "$DEV" ]; then
2021-06-05 04:08:32 +08:00
#prevent soft bricking when using pm3-flash-all on an outdated bootloader
if [ $(basename -- "$0") = "pm3-flash-all" ]; then
if [ ! $($PSHEXE -command "Get-CimInstance -ClassName Win32_serialport | Where-Object {\$_.DeviceID -eq '$_comport'} | Select -expandproperty PNPDeviceID" 2>/dev/null | tr -dc '[:print:]') = "USB\VID_9AC4&PID_4B8F\ICEMAN" ]; then
echo -e "\033[0;31m[!] Using pm3-flash-all on an oudated bootloader, use pm3-flash-bootrom first!"
exit 1
fi
fi
2021-09-19 07:31:17 +08:00
PM3LIST+=("$DEV")
2021-02-10 16:31:08 +08:00
if [ ! -w "$DEV" ]; then
echo "[!] Let's give users read/write access to $DEV"
sudo chmod 666 "$DEV"
fi
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
fi
done
2021-09-19 07:31:17 +08:00
#BT direct SERIAL PORTS (COM)
if $FINDBTRFCOMM; then
for DEV in $($PSHEXE -command "Get-CimInstance -ClassName Win32_PnPEntity | Where-Object Caption -like 'Standard Serial over Bluetooth link (COM*' | Select Name" 2> /dev/null | sed -nr 's#.*\bCOM([0-9]+)\b.*#/dev/ttyS\1#p'); do
# ttyS counterpart takes some more time to appear
if [ -e "$DEV" ]; then
PM3LIST+=("$DEV")
if [ ! -w "$DEV" ]; then
echo "[!] Let's give users read/write access to $DEV"
sudo chmod 666 "$DEV"
fi
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
fi
done
fi
#white BT dongle SERIAL PORTS (COM)
if $FINDBTDONGLE; then
for DEV in $($PSHEXE -command "Get-CimInstance -ClassName Win32_serialport | Where-Object PNPDeviceID -like '*VID_10C4&PID_EA60*' | Select DeviceID" 2>/dev/null | sed -nr 's#^COM([0-9]+)\b#/dev/ttyS\1#p'); do
# ttyS counterpart takes some more time to appear
if [ -e "$DEV" ]; then
PM3LIST+=("$DEV")
if [ ! -w "$DEV" ]; then
2020-05-17 18:12:13 +08:00
echo "[!] Let's give users read/write access to $DEV"
sudo chmod 666 "$DEV"
fi
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
return
fi
fi
done
fi
2019-07-13 06:06:19 +08:00
}
SCRIPT=$(basename -- "$0")
if [ "$SCRIPT" = "pm3" ]; then
CMD() { eval "$EVALENV"; $CLIENT "$@"; }
2019-09-09 18:58:11 +08:00
HELP() {
cat << EOF
2020-06-05 17:43:27 +08:00
Quick helper script for proxmark3 client when working with a Proxmark3 device
2019-09-09 18:58:11 +08:00
Description:
The usage is the same as for the proxmark3 client, with the following differences:
* the correct port name will be automatically guessed;
* the script will wait for a Proxmark to be connected (same as option -w of the client).
2020-06-05 17:43:27 +08:00
You can also specify a first option -n N to access the Nth Proxmark3 connected.
2020-04-21 18:05:47 +08:00
To see a list of available ports, use --list.
2019-09-09 18:58:11 +08:00
Usage:
$SCRIPT [-n <N>] [<any other proxmark3 client option>]
$SCRIPT [--list] [-h|--help] [-hh|--helpclient]
$SCRIPT [-o|--offline]
2020-06-05 17:43:27 +08:00
Arguments:
-h/--help this help
-hh/--helpclient proxmark3 client help (the script will forward these options)
2020-06-05 17:43:27 +08:00
--list list all detected com ports
-n <N> connect device referred to the N:th number on the --list output
-o/--offline shortcut to use directly the proxmark3 client without guessing ports
2020-06-05 17:43:27 +08:00
Samples:
./$SCRIPT -- Auto detect/ select com port in the following order BT, USB/CDC, BT DONGLE
./$SCRIPT -p /dev/ttyACM0 -- connect to port /dev/ttyACM0
./$SCRIPT -n 2 -- use second item from the --list output
./$SCRIPT -c 'lf search' -i -- run command and stay in client once completed
2019-09-09 18:58:11 +08:00
EOF
}
2019-09-09 07:07:46 +08:00
elif [ "$SCRIPT" = "pm3-flash" ]; then
FINDBTDONGLE=false
2020-04-29 21:15:25 +08:00
FINDBTRFCOMM=false
FINDBTDIRECT=false
2019-09-09 07:07:46 +08:00
CMD() {
ARGS=("--port" "$1" "--flash")
2019-09-09 07:07:46 +08:00
shift;
while [ "$1" != "" ]; do
if [ "$1" == "-b" ]; then
ARGS+=("--unlock-bootloader")
elif [ "$1" == "--force" ]; then
ARGS+=("--force")
2019-09-09 07:07:46 +08:00
else
ARGS+=("--image" "$1")
fi
shift;
done
2020-05-17 18:23:03 +08:00
$CLIENT "${ARGS[@]}";
2019-09-09 07:07:46 +08:00
}
2019-09-09 18:58:11 +08:00
HELP() {
cat << EOF
Quick helper script for flashing a Proxmark device via USB
Description:
The usage is similar to the old proxmark3-flasher binary, except that the correct port name will be automatically guessed.
You can also specify a first option -n N to access the Nth Proxmark3 connected on USB.
2019-09-09 18:58:11 +08:00
If this doesn't work, you'll have to use manually the proxmark3 client, see "$CLIENT -h".
2020-04-21 18:05:47 +08:00
To see a list of available ports, use --list.
2019-09-09 18:58:11 +08:00
Usage:
$SCRIPT [-n <N>] [-b] image.elf [image.elf...]
2020-04-21 18:05:47 +08:00
$SCRIPT --list
2019-09-09 18:58:11 +08:00
Options:
-b Enable flashing of bootloader area (DANGEROUS)
Example:
2019-09-09 19:24:45 +08:00
$SCRIPT -b bootrom.elf fullimage.elf
2019-09-09 18:58:11 +08:00
EOF
}
elif [ "$SCRIPT" = "pm3-flash-all" ]; then
FINDBTDONGLE=false
2020-04-29 21:15:25 +08:00
FINDBTRFCOMM=false
FINDBTDIRECT=false
CMD() {
ARGS=("--port" "$1" "--flash" "--unlock-bootloader" "--image" "$BOOTIMAGE" "--image" "$FULLIMAGE")
shift;
while [ "$1" != "" ]; do
if [ "$1" == "--force" ]; then
ARGS+=("--force")
fi
shift;
done
$CLIENT "${ARGS[@]}";
}
2019-09-09 18:58:11 +08:00
HELP() {
cat << EOF
Quick helper script for flashing a Proxmark device via USB
Description:
The correct port name will be automatically guessed and the stock bootloader and firmware image will be flashed.
You can also specify a first option -n N to access the Nth Proxmark3 connected on USB.
2019-09-09 18:58:11 +08:00
If this doesn't work, you'll have to use manually the proxmark3 client, see "$CLIENT -h".
2020-04-21 18:05:47 +08:00
To see a list of available ports, use --list.
2019-09-09 18:58:11 +08:00
Usage:
$SCRIPT [-n <N>]
2020-04-21 18:05:47 +08:00
$SCRIPT --list
2019-09-09 18:58:11 +08:00
EOF
}
elif [ "$SCRIPT" = "pm3-flash-fullimage" ]; then
FINDBTDONGLE=false
2020-04-29 21:15:25 +08:00
FINDBTRFCOMM=false
FINDBTDIRECT=false
CMD() {
ARGS=("--port" "$1" "--flash" "--image" "$FULLIMAGE")
shift;
while [ "$1" != "" ]; do
if [ "$1" == "--force" ]; then
ARGS+=("--force")
fi
shift;
done
$CLIENT "${ARGS[@]}";
}
2019-09-09 18:58:11 +08:00
HELP() {
cat << EOF
Quick helper script for flashing a Proxmark device via USB
Description:
The correct port name will be automatically guessed and the stock firmware image will be flashed.
You can also specify a first option -n N to access the Nth Proxmark3 connected on USB.
2019-09-09 18:58:11 +08:00
If this doesn't work, you'll have to use manually the proxmark3 client, see "$CLIENT -h".
2020-04-21 18:05:47 +08:00
To see a list of available ports, use --list.
2019-09-09 18:58:11 +08:00
Usage:
$SCRIPT [-n <N>]
2020-04-21 18:05:47 +08:00
$SCRIPT --list
2019-09-09 18:58:11 +08:00
EOF
}
elif [ "$SCRIPT" = "pm3-flash-bootrom" ]; then
FINDBTDONGLE=false
2020-04-29 21:15:25 +08:00
FINDBTRFCOMM=false
FINDBTDIRECT=false
CMD() {
ARGS=("--port" "$1" "--flash" "--unlock-bootloader" "--image" "$BOOTIMAGE")
shift;
while [ "$1" != "" ]; do
if [ "$1" == "--force" ]; then
ARGS+=("--force")
fi
shift;
done
$CLIENT "${ARGS[@]}";
}
2019-09-09 18:58:11 +08:00
HELP() {
cat << EOF
Quick helper script for flashing a Proxmark device via USB
Description:
The correct port name will be automatically guessed and the stock bootloader will be flashed.
You can also specify a first option -n N to access the Nth Proxmark3 connected on USB.
2019-09-09 18:58:11 +08:00
If this doesn't work, you'll have to use manually the proxmark3 client, see "$CLIENT -h".
2020-04-21 18:05:47 +08:00
To see a list of available ports, use --list.
2019-09-09 18:58:11 +08:00
Usage:
$SCRIPT [-n <N>]
2020-04-21 18:05:47 +08:00
$SCRIPT --list
2019-09-09 18:58:11 +08:00
EOF
}
else
2020-05-17 18:12:13 +08:00
echo >&2 "[!!] Script ran under unknown name, abort: $SCRIPT"
exit 1
fi
# priority to the help options
for ARG; do
if [ "$ARG" == "-h" ] || [ "$ARG" == "--help" ]; then
HELP
exit 0
fi
if [ "$ARG" == "-hh" ] || [ "$ARG" == "--helpclient" ]; then
CMD "-h"
exit 0
fi
done
# if offline, bypass the script and forward all other args
for ARG; do
shift
if [ "$ARG" == "-o" ] || [ "$ARG" == "--offline" ]; then
CMD "$@"
exit $?
fi
set -- "$@" "$ARG"
done
# if a port is already provided, let's just run the command as such
for ARG; do
2023-02-03 21:41:23 +08:00
shift
if [ "$ARG" == "-p" ]; then
CMD "$@"
exit $?
fi
set -- "$@" "$ARG"
done
if [ "$1" == "--list" ]; then
shift
if [ "$1" != "" ]; then
2020-05-17 18:12:13 +08:00
echo >&2 "[!!] Option --list must be used alone"
exit 1
fi
SHOWLIST=true
fi
# Number of the proxmark3 we're interested in
N=1
if [ "$1" == "-n" ]; then
shift
if [ "$1" -ge 1 ] && [ "$1" -lt 10 ]; then
N=$1
shift
else
2020-05-17 18:12:13 +08:00
echo >&2 "[!!] Option -n requires a number between 1 and 9, got \"$1\""
exit 1
fi
fi
HOSTOS=$(uname | awk '{print toupper($0)}')
if [ "$HOSTOS" = "LINUX" ]; then
2019-07-13 06:06:19 +08:00
if uname -a|grep -q Microsoft; then
# First try finding it using the PATH environment variable
2021-09-05 06:34:26 +08:00
PSHEXE=$(command -v powershell.exe 2>/dev/null)
# If it fails (such as if WSLENV is not set), try using the default installation path
if [ -z "$PSHEXE" ]; then
PSHEXE=/mnt/c/Windows/System32/WindowsPowerShell/v1.0/powershell.exe
fi
# Finally test if PowerShell is working
if ! "$PSHEXE" exit >/dev/null 2>&1; then
echo >&2 "[!!] Cannot run powershell.exe, are you sure your WSL is authorized to run Windows processes? (cf WSL interop flag)"
exit 1
fi
GETPM3LIST=get_pm3_list_WSL
2019-07-13 06:06:19 +08:00
else
GETPM3LIST=get_pm3_list_Linux
2019-07-13 06:06:19 +08:00
fi
elif [ "$HOSTOS" = "DARWIN" ]; then
GETPM3LIST=get_pm3_list_macOS
elif [[ "$HOSTOS" =~ MINGW(32|64)_NT* ]]; then
GETPM3LIST=get_pm3_list_Windows
else
2020-05-17 18:12:13 +08:00
echo >&2 "[!!] Host OS not recognized, abort: $HOSTOS"
exit 1
fi
if $SHOWLIST; then
2020-04-21 23:11:18 +08:00
# Probe for up to 9 devs
$GETPM3LIST 9
if [ ${#PM3LIST} -lt 1 ]; then
2020-05-17 18:12:13 +08:00
echo >&2 "[!!] No port found"
exit 1
fi
n=1
2020-05-17 18:23:03 +08:00
for DEV in "${PM3LIST[@]}"
do
echo "$n: $DEV"
n=$((n+1))
done
exit 0
fi
# Wait till we get at least N proxmark3 devices
2020-05-17 18:23:03 +08:00
$GETPM3LIST "$N"
if [ ${#PM3LIST} -lt "$N" ]; then
echo >&2 "[=] Waiting for Proxmark3 to appear..."
fi
while true; do
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST[*]} -ge "$N" ]; then
break
fi
sleep .1
2020-05-17 18:23:03 +08:00
$GETPM3LIST "$N"
done
2020-05-17 18:23:03 +08:00
if [ ${#PM3LIST} -lt "$N" ]; then
2020-06-05 17:43:27 +08:00
HELP() {
cat << EOF
[!!] No port found, abort
[?] Hint: try '$SCRIPT --list' to see list of available ports, and use the -n command like below
[?] $SCRIPT [-n <N>]
2021-06-05 03:57:41 +08:00
2020-06-05 17:43:27 +08:00
EOF
}
HELP
exit 1
fi
CMD "${PM3LIST[$((N-1))]}" "$@"
exit $?