Proxmark developers community

Research, development and trades concerning the powerful Proxmark3 device!

You are not logged in.

#1 Re: Questions and Requests » New user - Driver problems » 2015-10-04 18:09:55

You have a libusb bootloader and you are trying to flash over it with the CDC-serial flasher; you need to use the old flasher.

#3 Re: MIFARE Classic » cracking mifare keys » 2015-10-02 13:17:58

Need to test a different mizip; i suspect keys will be the same and not uid-dependant.

#4 Re: MIFARE Ultralight » a popular toy AmiiBo » 2015-09-30 12:47:30

To get the amiibo password without sniffing you can use this online tool.

#5 Re: Trade Parts » Where can I buy a PM3? » 2015-09-28 18:05:07

The kit seems to be missing the HF antenna... is this true ?

#6 Re: MIFARE Classic » MCT - An Android NFC-App for reading/writing/analysing/etc. MF Classic » 2015-09-27 08:58:45

Good test tontol1 but even solving that problem there is another one to make it "full raw compatible": the ability to send 7bits commands insted of 8bits. 26 (or 52) is a 7bits command that is part of the mifare standard command set managed by the NXP chip. If you want, for example, "talk" with a magic 1st gen mifare card you must send another 7bits command [it is 40] that is not coded inside NXP chip so even with your method it will be not possible to achieve a full raw.

It is something like SRIX4K support: they are not supported by Android because they are not full ISO14443B and have specific commands not supported by the chipset (at least this is what came out by tests) but maybe with your method this one can be solved because those specific commands (SRIX) are 8bits [the command is exactly 0600 = INITIATE]. Let us know if you find a way (also for ISO14443B commnds) !

#7 Re: Questions and Requests » 13.56Mhz Sielox tags... » 2015-09-27 08:49:01

In theory the tag should start answering with something like an UID while just entering the magnetic field (if it does not want any specific wake-up command).
The answer must be in ISO14443 format to be shown in pm3; if it is ISO14443A, as iceman said, you need to test all the 256 bytes possibilities using the following commands:

hf 14a raw -p 00
hf 14a raw -p 01
hf 14a raw -p 02
hf 14a raw -p 03
hf 14a raw -p 04
hf 14a raw -p 05
hf 14a raw -p 06
hf 14a raw -p 07
hf 14a raw -p 08
hf 14a raw -p 09
hf 14a raw -p 0A
hf 14a raw -p 0B
hf 14a raw -p 0C
hf 14a raw -p 0D
hf 14a raw -p 0E
hf 14a raw -p 0F
hf 14a raw -p 10
hf 14a raw -p 11
hf 14a raw -p 12
hf 14a raw -p 13
hf 14a raw -p 14
and so on until FF value (=256).

#8 Re: Questions and Requests » 212$ usd proxmark3 elechouse dev kit version 2.0 » 2015-09-23 11:04:13

It is supposed to be a modified pm3 hardware with support for offical pm3 firmware (the site is linking to my compiled firmware releases). Version 2.0.0 does not support pcf write but the site it calims it is supported but it is not if you do not update firmare to the latest revision available (that is NOT 2.0.0) so I don't trust sites that says something that is not real (to show better compatibility only) even if the stuff they sell seems to be good.

#9 Re: Questions and Requests » 212$ usd proxmark3 elechouse dev kit version 2.0 » 2015-09-23 00:44:24

Pcfwrite in v2.0.0 is totally fake... maybe the product is good but the info are not... i will not buy from them only for this reason but this is my opinion.

#10 Re: Questions and Requests » 13.56Mhz Sielox tags... » 2015-09-22 09:31:40

Possible candidates: EM4006 (as you suggested), EM4022 (not much probable), EM4033. Datasheets.

#11 Re: Questions and Requests » 13.56Mhz Sielox tags... » 2015-09-21 21:34:19

Surely marshmellow but there is a chance it is a know documented tag, just a bit "rare" in the wild. Another way is decapping the chip.

#12 Re: Questions and Requests » 13.56Mhz Sielox tags... » 2015-09-21 21:22:40

Topaz is not read only while this one is stated to be. Look at the tag specs summary list I  built in that page and look for similarities. I remember some EM and ST tags like those. EM4006? It can be. I am not on my pc now to look for datasheets in a "comfortable" way wink.

#13 Re: Questions and Requests » 13.56Mhz Sielox tags... » 2015-09-21 17:46:46

Here are the tech specs (AC-15T-E Mirage Proximity Tag).

It seems to be a Read Only 64bit 13.56MHz chip, have a look if you can find something here.

#14 Re: Windows Client » Compiled Android Client - Download » 2015-09-16 19:46:44

bobylive wrote:

@asper I'm looking for the proxdroid SVN834.Can you sent this software to me?Thx

I don't have it anymore, sorry.

#15 Re: Questions and Requests » Need help to identify tag » 2015-09-12 13:32:02

There seems to be communcation errors; try to use different antenna positioning/distances while sniffing communication between tag and circuit. When you will obtain a more constant data flow (for example always same bytes) this will be a good positioning.

#16 Re: Questions and Requests » Need help to identify tag » 2015-09-11 09:03:27

It seems to get some iso15693 but those 01 01... do not correspond to any iso15693 commands; my suggestion: start to snoop without the tag and VERY QUICKLY put it over the circuit. Try to do that again with 14a and 14b.

#17 Re: Questions and Requests » Need help to identify tag » 2015-09-10 18:41:16

Your antenna is great.
Try to snoop again when you approach the tag to the circuit.

#18 Re: MIFARE Ultralight » a popular toy AmiiBo » 2015-09-04 17:44:33

Thanks to some great help Amiibo can be considered almost understood.
The auth password can be found looking at "Inkling Boy" and "Squid" data posted in the previous page (a little hint: xor !).
About encryption it was really really hard and long to find the needed data (those data, as stated in the previously linked thread on reddit, are Nintendo properties so cannot be shared).

#19 Re: 125 kHz - ISO 11784 / 11785 » PCF7931 » 2015-08-24 10:26:18

We hope to see your code ! Thank you for your contribution.

#20 Re: Windows Client » Compiled Windows Client - Download » 2015-08-16 20:53:12

Added the new rev 2.2.0 to the 1st post !

Note that OS Image will be not be present anymore from now on ! Use fullimage to flash the firmware !

#21 Re: 125 kHz - ISO 11784 / 11785 » Megamos Crypto Paper Finally Released » 2015-08-16 20:47:25

VERY VERY interesting !
Thanks for sharing the link !!

He says "we have developed an open source library for custom and proprietary RFID communication schemes that operate at an frequency of 125kHz": is it possible to see this open source library ? Any link ? Or is he referring to this forum ?

#22 Re: Questions and Requests » Bulk Programming » 2015-08-12 18:06:58

Don't ask "US" ? This is your 1st post and your nick is too similar to mine... I don't think you are part of "US" (nobody can be considered as "US"); if you are a member of this community with a different username please use your real nick to make this kind of charges taking your responsabilities... or better... do not post here, this is a tech forum and people here are free to help others if they like to without any constraints. If you personally (or "digitally") know mnelson please solve your differences outside.

#23 Re: MIFARE Ultralight » a popular toy AmiiBo » 2015-08-10 22:40:39

They are probably unlocked in a virgin tag (i don't have a 215 but i have similars which are unlocked). Need to spoof to see if the locking bits are required for the tag to be read.

#24 Re: MIFARE Ultralight » a popular toy AmiiBo » 2015-08-08 16:14:22

Which pages are locked? I can check with a blank ntag.

#25 Re: Device Components and Interfaces » Choosing the right JTAG (advice needed) » 2015-08-04 13:21:34

rbubba1911 wrote:

Hi asper,

I read your feedback experience, I'm not afraid about IDA/Odbg/SoftICE  wink

I trust you blindly, we seem to share same taste for hacking device !

I'll take this one, thanks a lot for your advice .

best regards

You seem to be smart my friend !
Do you have an account where we can get in contact (mail, msn, skype, fb, etc) ?

Board footer

Powered by FluxBB