Proxmark developers community

Research, development and trades concerning the powerful Proxmark3 device!

You are not logged in.

#1 Re: Various Tools and Utilities » HackRF One - A platform for RF analysis - Windows Guide » Today 08:24:01


Having a working GNURADIO system under Windows can really be hard, at least in my experience, so this is what you need to install BEFORE installing GNURADIO (this is my actual "configuration"):

1 - python-2.7.3.msi (Python interpreter - link)
2 - numpy-1.6.2-win32-superpack-python2.7.exe (link
3 - PyQt-Py2.7-x86-gpl-4.9.6-1.exe (link)
4 - setuptools-0.6c11.win32-py2.7.exe (used to install other Python dependencies - link)
5 - pygtk-all-in-one-2.24.2.win32-py2.7.msi (link)
6 - wxPython2.8-win32-unicode- (link)
7 - PyQt4.Qwt5-5.2.1.win32-py27.exe
8 - lxml-3.0.2.win32-py2.7.exe (link)
9 - Python OpenGL (link)
10 - Visual C++ 2010 Runtime

(info taken here)

After that install:
- uhd_003.005.003-release_Win32.exe (USRP drivers - link)
- gnuradio_3.6.4.1_Win32.exe (link)

After that start GNURADIO Companion usually located here: C:\Program Files (x86)\gnuradio\bin\ (it can take some couple of seconds before it starts)

If, for some strange reason, the software will not start anymore over time try to reinstall the fist 3 packets of the environment and it should start again... weired but it did the work in my case.

Now a tutorial on how to use gnuradio is really welcome !

#2 Re: Various Tools and Utilities » HackRF One - A platform for RF analysis - Windows Guide » Yesterday 18:48:25


Download and install the following packages:
- MinGW Setup (mine was already installed to compile Proxmark3)
- CMake (I am using v3.0.2-win32-x86 and I installed it in C:\CMake, this path is important in the commands we must send in the MinGW shell)

Download and extract the following packages respectively in the path C:\MinGW\msys\1.0\local\include\libusb-1.0.18\libusb and C:\libusbx-1.0.18-win:
- libusb-1.0 (I am using v1.0.18)
- libusb-win32 (I am using v1.0.18)

Download and extract the following package in the root of your C:\ drive and rename the folder to C:\hackrf:
- Latest HackRF package

Now launch C:\MinGW\msys\1.0\msys.bat to open MinGW shell and type the following:

cd /c
cd hackrf
cd host
mkdir build
cd build
cmake ../ -G "MSYS Makefiles" -DLIBUSB_INCLUDE_DIR=/usr/local/include/libusb-1.0/
cmake ../ -G "MSYS Makefiles" -DLIBUSB_LIBRARIES=/c/libusbx-1.0.18-win/MinGW32/dll/libusb-1.0.dll
make install

You have now compiled HackRF !

Compiled .exe tools can be found here: C:\hackrf\host\build\hackrf-tools\src
libhackrf.dll here C:\hackrf\host\build\libhackrf\src
Firmware can be found here: C:\hackrf\firmware-bin (this is already present in the hackrf downlodable package)

To see if everything is working fine connect HackRF One to USB port and then launch hackrf_info.exe, it should show HackRF specifications just like this:
Those .dlls are needed:

#3 Re: Questions and Requests » HackRF - Dedicated Section ? » Yesterday 11:50:14

Here it is (1st part).

Next part will be about compiling under Windows.

The last part will be Installing and configuring GNURADIO under Windows (this is the best I can reach until now): if someone is able to write a tutorial on how to use GNURADIO with HackRF One ot will be wonderful (this is what probably vivat is asking for) !!!! I am really really new to this software and SDR in general...

#4 Various Tools and Utilities » HackRF One - A platform for RF analysis - Windows Guide » Yesterday 11:31:14

Replies: 2

Dealing with a hardware+software platform born under linux can be a real pain for people not used to it so I will try to make things easier for them explaining what I did to make that great HackRF One hardware working under Windows. I am still not too good in those kind of subjects so I will try to explain things the same way I understood them; if you find incongruences please feel free to correct me and I will update this post giving credits to contributors.

It is a platform with open hardware and software created by by Michael Ossmann specific for radio frequencies analysis; this is at the moment the only hardware able to scan the widest range of RF signas starting from 30MHz to 6GHz !! (another hardware that is going to be released this year is Airspy but its range will be from 24MHz to 1.7GHz - there are other very cheap usb dvb dongles able to do that kind of analysis but they are not natively built for that kind of stuff and are really limited compared to HackRF One).
Using an hardware device called Ham-It-Up RF converter (picture below) the HackRF One can also explore the LF and MF frequencies range so the full range is extended from 300kHz to 6GHz !!!
This device is the succesor of the Jawbreaker hardware and its manufacturing was possible thanks to a specific kickstarter campaign.


Frequency Range: 10MHz - 6GHz (kickstarter campaign says "from 30MHz" while acutal official site says "from 10MHz") [from 300kHz to 6GHz if you add an Ham It Up RF Converter hardware]  - the range practically starts from the upper part of LF (Low Frequency) band to the lower part of SHF (Super High Frequency) band.

- Bandwidth: the maximum bandwidth of HackRF is 20 MHz (about 10 times the bandwidth of TV tuner dongles); that means that HackRF could be used for high speed digital radio applications such as LTE or 802.11g. Bandwidht is the maximum range of frequencies "explorable" at the same time: this means that you can "see" or better "listen" to a range of frequencies 20MHz-wide; here is a practical example: if you set HackRF One to 20 MHz bandwidth and you center the frequency to 97MHz your bandwidht will be approximatively from 87 to 107MHz (that is almost the full radio FM spectrum from 87.5 to 108.0 MHz (with some exceptions such as Japan FM broadcast range that is form 76 to 90MHz) !):
the peaks above represent radio broadcasting stations.
So everything in the range of the bandwidth you are listening to is recordable -> so it can save up to 20 million samples per second !

- Included Antenna Specs: it is called ANT500, it is telescopic, and it is designed for operations from 75 MHz to 1 GHz (this means that that if you want to reach the non-supported frequencies you need to buy/build your own antenna):

- half-duplex transceiver: it means that it can transmit or receive but can't do both at the same time. However, full-duplex operation is possible if you use two HackRF devices.

- SMA female antenna connector

- SMA female clock input and output for synchronization

- compatible with GNU Radio, SDR# (also called SDRSharp), and more: picture above is taken with SDR#

- software-configurable RX and TX gain and baseband filter

- software-controlled antenna port power (50 mA at 3.3 V)

- convenient buttons for programming

- internal pin headers for expansion

- Hi-Speed USB 2.0: (Male Type A <---> Male Micro B cable-connectors)

- Same cable USB-powered: one cable-only to connect and to powering-up

- open source hardware

- opens ource software

- 8-bit quadrature samples (8-bit I and 8-bit Q): I don't know what it is, if someone can explain it I will be grateful !


(taken directly from the kickstarter campaing page):

SDR is the application of Digital Signal Processing to radio waveforms. It is similar to the software-based digital audio techniques that became popular a couple of decades ago. Just as a sound card in a computer digitizes audio waveforms, a software radio peripheral digitizes radio waveforms. It's like a very fast sound card with the speaker and microphone replaced by an antenna. A single software radio platform can be used to implement virtually any wireless technology (Bluetooth, ZigBee, cellular technologies, FM radio, etc.).


- Download the following file: from SDR# page (it needs an internet connection to download necessay files)

- Once downloaded unzip it, launch "install.bat" and wait for the program to download the necessay files

- now connect HackRF One to an USB port and execute zadig.exe to install Windows Drivers; if the new USB devices is not shown go to "Options" and select "List All Devices" (see picture below);

- now choose "WinUSB (v6.x.xxxx.xxxxx)" and press "Install WCID Driver" button:
Usually under Windows HackRF will work with ONE USB PORT AND THIS ONE ONLY !!! So try all USB ports before saying "hardware not found by SDRSharp!"

- now you can execute SDRSharp.exe (it is in the same zadig.exe folder) and SDRSharp will open up:

Here are the basics:
- 1st of all click on the "gear" icon and set the device as "Jawbraker" (A)
- then set the sampling rate: the more it is the wider the band will be with zoom set to 0 (B)
- then set the LNA gain according to your receiving signal (see further) (C)

- now set the kind of radio you want to listen to (WFM is the "normal radio" band)

- now set the "step size": this represents the "accuracy" of the vertical red line while you move it through the frequencies; it is the same thing that happens when you press the "forward" button of yoru radio-car-system if the automatic station scan is disabled, it goes "a step further" and the width of this step is represented by this "step size" value: the smaller it is the more precise it will be (smaller values should be used when you are inspecting a narrow band range)

- now set the resolution: this is the resolution of the peaks you can see in the upper part of the Spectrum Analyzer: the higher it is the more the processor will work: setting it above 65535 can cause system performance slow down.

NOW YOU CAN PRESS THE "PLAY BUTTON" to make the software analyzing HackRF One sniffed traffic:
Double-click on any peak to tune to that frequency and listen to it !

The Spectrum Analyzer represents a graphic peak-view of the band of the frequencies you are exploring; higher peaks means that something is broadcasting over that frequency. [X = Frequency ; Y = Amplitude]
(peaks can be automatically marked setting the option "Mark Peaks" you can see in the lower-right corner of the previous picture)

The Waterfall represents a graphic "cascade" representation of the signals across the frequency range you are investigating, usually "coded" with a specific color which indicates signal amplitude or strength displayed over time (more recent are at the top of the waterfall, older ones are at the bottom).
If your waterfall doesn't seems to have any broadcast signal try to increment the LNA gain in the settings.

ZOOM: with this slider you can narrow or make wider the graphic band your are seeing

CONTRAST: it changes the color of the waterfall "silent" background and of the waterfall "hot lines" (I prefere the "silent" background to be blue and the "broadcasting frequencies" to be orange/red as you can see in the watefall picture above).

RANGE: it narrows or widen the "Y coordinate" (amplitude) in the "Spectrum Analyzer" graphic

OFFSET: it moves up and down the "Y coordinate" (amplitude) in the "Spectrum Analyzer" graphic

Here is a sum-up of the various available frequencies:
Please note that most of them have many sub-ranges !

Here are some GREAT SDR with HackRF tutorials by Michael Ossmann, the author of HackRF !

Next part will be installing the HackRF environment and compiling it under Windows !

#5 Re: 125 kHz - ISO 11784 / 11785 » Cloning a em410x tag fails » Yesterday 09:20:27

vivat wrote:
alucardx wrote:

is this the unit : h*t*t*p://

seem like too good to be true, but when the unit arrive, i tested with HID Prox II card, see if it can be done or not


They must be kidding...

I agree...

#6 Re: Questions and Requests » HackRF - Dedicated Section ? » Yesterday 09:19:26

I am glad ot see that someone (and BIG ones) are interested !

I will create a thread in "Various Tools and Utilities" covering the stuff I was able to do right now (really few considering the hardware potentials but I am still a noob wink )

#7 Re: MIFARE Classic » Reset a UID Changable Magic Card » Yesterday 06:08:52

Update the firmware to the software release. R0.0.5(firmware+software) is suggested.

#8 Questions and Requests » HackRF - Dedicated Section ? » 2014-09-29 16:21:18

Replies: 6

Hi guys,

I recently had some time to use the HackRF device and I think it is a great product:
I was able to use it under Win7 (64 bit) but I found some difficulties in setting it up with the SDRSharp (SDR#) software and compiling the sources; after some days I was finally able to correctly use it (together with the sources) so I would like to know if someone is interested in opening a specific form thread maybe in the "Various Tools and Utilities" or in "Hardware Remarks and Questions" section.

If you agree I can make some step-by-step guides on how to use it under Windows to make linux-unfriendly-people-approach easier.

#9 Re: Calypso » Calyso card » 2014-09-24 18:25:06

A friend tried to sniff a calipso card but something went wrong in receiving data back. It should be ISO14443B' and not ISO14443B so something should be different inside the protocol (older one). There is a specific post somewhere in this forum.

#11 Re: Questions and Requests » Cant quite get driver installed » 2014-09-23 11:21:14

You are right n3rd, I need to update the .PDF with the new renamed file names; you can flas FPGA and after flashing it flash OS image using the appropriate .bat file and always keeping the button pressed. Otherwise you can flash fullimage only. OS image is the one that is updated more frequently so usually you don't need to flash fpga but if someone is updating from a very old version (like you) it is suggested to flash fullimage OR fpga+OS. Once your firmware is correctly updated (bootrom+fpga+os form the same build) your pm3 will be recognized without holding the button.

Flash FPGA first and then OS image (this is not mandatory, it should work in reverse also).

#12 Re: Questions and Requests » Cant quite get driver installed » 2014-09-22 14:37:26

Bus pirate is the "last chance", you probably missed that sentence:

Do the same procedure you used to flash the bootloader (holding the pm3 button) and flash fullimage or FPGA and OS images and you should be fine

so try to use the othe .bat files to flash fpga and os before buying a bus pirate.

#13 Re: Questions and Requests » Cant quite get driver installed » 2014-09-22 07:19:15

Thanks!  I will try that now.  However, why does the pm3-bin-0.0.5 come with the older driver if it doesn't work with the GUI?  Is it required to flash the firmware in stages (old one first, then the new one)?

Because the windows package comes with everything you can need to see if your just-received pm3 is working and if its firmware is libusb or cdc-serial; the GUI is an accessory-only to make things easier; to use the old libusb driver/firmware you need to use an old proxmark3.exe but old libusb executables are no more supported so I will not add them to avoid further confusions such as the ones you had with the drivers.
It is not needed to flash the pm3 in stages; already-bulit pm3 comes with an older firmware that usually is NOT the latest version available; it is advised to flash the latest firmware to avoid nasty bugs.

The flasher.exe (or more accurately, the PDF that comes with the gui) says the FLASH files need to go in the /win32 folder.  This box is a 64 bit Win 7 machine, there is no /win32 folder.  Does this imply that I need a different flasher?  Or should I just create c:/win32/ ?

The package comes with all files/folders you need if you mantain the provided folder structure; you are correct about the \win32 folder name, it is misleading and I will change it to \Windows Binaries in future releases, thanks for pointing that out.

...I renamed that file from "FLASH - NEW Bootrom (uses old flasher exe with -b option).bat" to 'doit.bat' because it's very tedious to type otherwise

Well you just need to double click on the .bat file to execute it without needing to type inside a Dos shell; renaming the file in "doit.bat" will cause more problems than the ones you had because people will not know what that file is used for.

OK I found that DLL elsewhere and stuck it in /win32 and the flasher runs.

The needed .dlls are inside the windows folder, they are not hiding "elsewhere":

When plugged into USB, the PM3 now lights up the red and yellow LED, and every 30 seconds, the relay clicks and the green LED lights up.

As midnitesnake correctly pointed out, you now need to flash the fullimage or FPGA+OS image because you only flashed the bootloader right now.
Do the same procedure you used to flash the bootloader (holding the pm3 button) and flash fullimage or FPGA and OS images and you should be fine. If the pm3 will not flash you will need to buy a a bus pirate and follow this procedure.

#14 Re: Questions and Requests » Going to try again » 2014-09-21 23:01:43

The incorrect driver won't install so you can try without fear. If you have old libusb you should consider to update to the new cdc-serial firmware because libusb is no more supported.

#15 Re: Questions and Requests » Cant quite get driver installed » 2014-09-21 22:56:38

You have the old libusb firmware inside your pm3, to use the cdc-serial driver you need to update pm3 to the correspondant cdc-serial firmware (above r655, suggested r0.0.5).

#16 Re: iClass » iClass is coming... » 2014-09-20 13:01:04

It compiles fine under my win environement; added pm3-bin-0.0.5 to the specific thread's 1st post. Thank you holiman !

#18 Re: MIFARE Classic » MCT - An Android NFC-App for reading/writing/analysing/etc. MF Classic » 2014-09-20 12:38:54

You asked, I answered but I was not clear and I am sorry for that.
Raw commands can be sent but NOT ALL raw commands (this topic it is already covered in this thread, at page4's bottom):
Mifare tags (and other tags) are not full ISO14443A comaptible, sometimes they use proprietary 7bits commands that ARE IMPOSSIBLE to send using mobile phone firmware nfc chips (they are full ISO14443A/B compliants but they do not support single specific special commands even if they are mifare compatible); the only way will be to modify internal nfc chip firmware that is not possible at this time.

#19 Re: 125 kHz - ISO 11784 / 11785 » Broken: LF T55xx commands. » 2014-09-17 05:40:09

I am not able to find the fork (github is not my best friend tongue), can you write down the link?

#20 Re: MIFARE Classic » MCT - An Android NFC-App for reading/writing/analysing/etc. MF Classic » 2014-09-16 21:44:15

No it is not possible to send raw commands using mobile phones.

#21 Re: Questions and Requests » Going to try again » 2014-09-14 07:00:31

A good place to start using pm3 under windows wink

#22 Re: Windows Client » Compiled Windows Client - Download » 2014-09-13 12:33:01

Updated r0.0.04 link in the 1st post and above.

#23 Re: Windows Client » Compiled Windows Client - Download » 2014-09-12 14:09:45

Added r0.0.4 (whatsnew)

Changed also a few things in the GUI interface and in the batch files according to the recent fixes.

#24 Re: Windows Client » hf mf dump for 4k cards broken? » 2014-09-12 07:31:44

A question about hf mf chk:

How many blocks are there in a mifare 4k ? In the datsheet it says 32 sectors of 4 blocks and 8 sectors of 16 blocks... so when I use the hf mf chk with the "block number" option my possibility range is from 0 to 128+128 [255] ?

#25 Re: Windows Client » Compiled Windows Client - Download » 2014-09-11 17:37:41

Added new compiled windows release (named 0.0.3) in the 1st post with piwi's latest patches.

Unfortunately the main trunk seems not to be updated with the relatively new iclass stuff.

If you are updating from ver. 0.0.2 remember to update both bootloader and fullimage !! Otherwise your pm3 will not be recognized by windows !!!

Board footer

Powered by FluxBB