Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
What is the problem? Who is to blame? Antenna or a special protection?
> tune
# LF antenna @ 0 mA / 134 mV [1273 ohms] 125Khz
# LF antenna @ 0 mA / 134 mV [1187 ohms] 134Khz
# HF antenna @ 50 mA / 11762 mV [235 ohms] 13.56Mhz
That has always been:
recorded activity:
ETU :rssi: who bytes
---------+----+----+-----------
+ 0: : 26
+ 322054: : 26
+ 321200: : 26
+ 64: 0: TAG 04 00
+ 7656: : 93 20
+ 64: 0: TAG 8b 80 4e 6b 2e
+ 10647: : 93 70 8b 80 4e 6b 2e a7 66
+ 64: 0: TAG 08 b6 dd
+ 43569: : 60 00 f5 7b
+ 112: 0: TAG c3 c9 c5 2c
+ 10344: : 2f 73 7b 5b 84 19 62 9b !crc
+ 64: 0: TAG af c5 8d 60!
+ 12390: : ee e0 0a 53 !crc
+ 64: 0: TAG 02
+ 3704: : 1c a2 73 35 e9 a9 f0 19 4a 88 d9 a7 bc 1d 25 00 5b f5 !crc
+ 2630: 0: TAG 0c!
+ 19175: : 7f 88 fd cf !crc
+ 112: 0: TAG 9d! ff! 31 5d
+ 10799: : c5 18 ae 88 0c 23 ba 05 !crc
+ 64: 0: TAG 11!
+ 128: 0: TAG 52! 08 01
+ 11614: : 26 0b 8d f6 !crc
+ 64: 0: TAG 04
+ 3752: : 5d 63 6b 60 8d b1 bb 27 cc f3 f3 8c 04 fa c6 70 8f 19 !crc
+ 2631: 0: TAG 08
+ 18989: : 25 03 ee 0e !crc
......................................
+ 2631: 0: TAG 0c!
+ 19046: : 23 02 2e 4f !crc
+ 112: 0: TAG 59! 41 58 43!
+ 10295: : 29 3d 0c a7 3d 97 66 a4 !crc
+ 63: 0: TAG be!
+ 12342: : 24 28 43 24 !crc
+ 64: 0: TAG 07
And like this elsewhere(He made three attempts hi14asnoop):
First attempt:
>> Started prox, built Jul 13 2009 01:21:29
>> Connected to device
> hi14asnoop
#db# blew circular buffer!
#db# 00000191, 00000003, 00000004
#db# 00000020, 00000473, 00000093
> hi14alist
recorded activity:
ETU :rssi: who bytes
---------+----+----+-----------
+ 0: : 26
+ 3440: : 26
+ 3431: : 26
+ 2536: : 26
+ 2296: : 26
..............
+ 488: : 26
+ 1263: : 26
+ 720: : 93 20
+ 1504: : 93 70 71 19 7f ba ad 07 8e
+ 864: : 26
+ 1216: : 26
+ 1304: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 26
+ 1303: : 26
+ 1384: : 93 70 71 19 7f ba ad 07 8e
+ 728: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 60 08 bd f7
+ 1168: : 20 d6 72 d9 08 41 41 ed !crc
+ 926: : 7e 7d e7 1e !crc
+ 2088: : 61 ce 14 df !crc
+ 2024: : 26
+ 1232: : 26
Second attempt:
> hi14asnoop
#db# blew circular buffer!
#db# 00000191, 00000002, 00000002
#db# 00000020, 00000347, 00000093
> hi14alist
recorded activity:
ETU :rssi: who bytes
---------+----+----+-----------
+ 0: : 26
+ 3424: : 26
+ 2296: : 26
+ 1144: : 26
..........................
+ 1136: : 26
+ 1152: : 26
+ 122: 0: TAG 03!
+ 42: 0: TAG 01
+ 396: : 26
+ 1152: : 26
+ 122: 0: TAG 07
+ 50: 0: TAG 01
+ 380: : 26
+ 1286: : 26
+ 504: : 26
+ 1152: : 26
+ 131: 0: TAG ff!
+ 277: : 26
+ 1152: : 26
+ 440: : 26
+ 1136: : 26
+ 456: : 26
+ 1144: : 26
+ 672: : 93 20
+ 130: 0: TAG 04
+ 80: 0: TAG 80
+ 1262: : 93 70 71 19 7f ba ad 07 8e
+ 864: : 26
+ 1216: : 26
+ 1288: : 93 70 71 19 7f ba ad 07 8e
+ 132: 0: TAG 01
+ 40: 0: TAG 03!
+ 916: : 26
+ 1280: : 26
+ 1391: : 93 70 71 19 7f ba ad 07 8e
+ 744: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 60 08 bd f7
+ 1176: : 89 e8 e3 01 5d 29 fe 87 !crc
+ 928: : f8 17 02 10 !crc
+ 188: 0: TAG 01
+ 1899: : 8b e6 e6 dd !crc
+ 2024: : 26
+ 1224: : 26
Third attempt
> hi14asnoop
#db# blew circular buffer!
#db# 00000191, 00000000, 00000000
#db# 00000020, 0000019e, 00000055
> hi14alist
recorded activity:
ETU :rssi: who bytes
---------+----+----+-----------
+ 0: 0: TAG 02
+ 5200: 0: TAG 00!
+ 92: 0: TAG 00!
+ 17854: 0: TAG 00!
+ 44: 0: TAG 00!
+ 11452: 0: TAG 04
+ 1760: 0: TAG 04 00
+ 680: 0: TAG 71 19 7f ba ad
+ 1480: 0: TAG 88 be 59
+ 2080: 0: TAG 04 00
+ 1304: 0: TAG 88 be 59
+ 2424: 0: TAG 04 00
+ 1392: 0: TAG 88 be 59
+ 1880: 0: TAG 04 00
+ 1200: 0: TAG 88 be 59
+ 1168: 0: TAG 04 af 5d 9c
+ 1136: 0: TAG f7 f6! 96! 4d
+ 936: 0: TAG b9! f8! 2b! 32 05! fc! 51 b8 db! 16! 37 22 b5! bb! aa eb 9b! a1! !crc
+ 2087: 0: TAG 66! 6d! 65 57! 36! 78! 95 0f 6d a2 d6! 3b! eb 1b! b2! f6 99! 94! !crc
+ 3248: 0: TAG 04 00
+ 1304: 0: TAG 88 be 59
+ 2416: 0: TAG 04 00
+ 1400: 0: TAG 88 be 59
+ 1879: 0: TAG 04 00
+ 1208: 0: TAG 88 be 59
+ 1160: 0: TAG eb f1 23 6c
+ 1128: 0: TAG fb ff 1c 01
+ 936: 0: TAG 4c! ad 74! d0 00
+ 480: 0: TAG f3! 0c be f3! 50 a3 c0 bf ae! 20! d7! 03! !crc
+ 1600: 0: TAG 2a! ef! fd! a9 ab f8! 19! 1d! e0! 1f! f5 75 8c! f3! a4! 65 1b 26! !crc
+ 3248: 0: TAG 04 00
Offline
What is the firmware version?
Offline
It seems you're not getting a good read of the card, try different orientation of the card relative to the antenna.
Offline
It seems you're not getting a good read of the card, try different orientation of the card relative to the antenna.
I need to remake a new antenna?
What is the firmware version?
pm3-20090713-r52
Offline
I know that either samy or edo512, if I recall correctly has made some improvements to the buffler handling routines in newer firmware revisions specifically to handle this 14443A blew circular buffer problems so you might have to upgrade to a new firmware ...
Last edited by rleroy (2009-09-26 20:57:38)
Offline
I know that either samy or edo512, if I recall correctly has made some improvements to the buffler handling routines in newer firmware revisions specifically to handle this 14443A blew circular buffer problems so you might have to upgrade to a new firmware ...
Where it is possible to download this insertion? Now I test the version - pm3-20090905-r216
> version
#db# Prox/RFID mark3 RFID instrument
#db# bootrom: svn 215 2009-09-05 14:10:58
#db# os: svn 215 2009-09-05 14:10:59
#db# FPGA image built on 2009/ 8/28 at 23:49:10
# LF antenna: 0.00 V @ 125.00 kHz
# LF antenna: 0.13 V @ 134.00 kHz
# LF optimal: 0.00 V @ 12000.00 kHz
# HF antenna: 11.99 V @ 13.56 MHz
# Your LF antenna is unusable.
Offline
There are two posts in the FAQ about this, check it out here and here.
blew circular buffer means that the microprocessor (ARM) could not catch up with the FPGA for parsing the incoming bits. On a clean trace (with a good antenna), this would most likely never occur, but when the antenna is receiving to much noise it could happen
Offline
There are two posts in the FAQ about this, check it out here and here.
blew circular buffer means that the microprocessor (ARM) could not catch up with the FPGA for parsing the incoming bits. On a clean trace (with a good antenna), this would most likely never occur, but when the antenna is receiving to much noise it could happen
In what ways it is possible to protect antenna from superfluous noise? What ways are?
Last edited by tarantul (2009-09-28 12:09:53)
Offline
When the antenna receives a partial transmission it could recognize SOF/EOF (start/end of frame) bits that are not correct. It means that the microprocessor code takes to long to process the incoming bits. If you add a delay to the parsing routine, or you start feed the arm random bit sequences, I guess you can simulate this behavior.
Offline
Today has made the test in the same place with an insertion pm3-20090905-r216. Errors blew circular buffer! This time was not. It seems to me it has not turned out to grasp the sufficient information for crapto1. Or I am mistaken. Please help me to understand.
#db# COMMAND FINISHED
#db# 0000004d, 00000000, 00000001
#db# 00000020, 00000bc2, 00000026
#db# 0000004d, 00000000, 00000001
#db# 00000020, 00000bc2, 00000026
> hi14alist
recorded activity:
ETU :rssi: who bytes
---------+----+----+-----------
+ 0: : 26
+ 1144: : 26
+ 416: : 26
+ 1144: : 26
+ 456: : 26
+ 1144: : 26
+ 600: : 26
+ 1136: : 26
+ 576: : 26
+ 1144: : 26
+ 672: : 93 20
+ 1472: : 93 70 71 19 7f ba ad 07 8e
+ 863: : 26
+ 1216: : 26
+ 1288: : 93 70 71 19 7f ba ad 07 8e
+ 1088: : 26
+ 1272: : 26
+ 1392: : 93 70 71 19 7f ba ad 07 8e
+ 744: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 60 08 bd f7
+ 2102: : be 01 f0 cb !crc
+ 2088: : 96 bf 75 8e !crc
+ 2024: : 26
+ 1224: : 26
+ 1304: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 26
+ 1304: : 26
+ 1392: : 93 70 71 19 7f ba ad 07 8e
+ 736: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 60 09 34 e6
+ 156: 0: TAG 01
+ 56: 0: TAG 01
+ 972: : ff 3e 00 4e ee 9e af f3 !crc
+ 116: 0: TAG 07
+ 160: 0: TAG 0f!
+ 660: : 5a 90 67 17 !crc
+ 196: 0: TAG 01
+ 76: 0: TAG 01
+ 256: 0: TAG 00!
+ 268: 0: TAG 01
+ 168: 0: TAG 01
+ 292: 0: TAG 03!
+ 832: : 8a 49 51 98 !crc
+ 456: 0: TAG 00!
+ 294: 0: TAG 00! 7b 77! 02
+ 262: 0: TAG 03!
+ 216: 0: TAG 03!
+ 796: : 26
+ 2551: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 26
+ 1288: : 26
+ 1400: : 93 70 71 19 7f ba ad 07 8e
+ 736: : 26
+ 1144: : 26
+ 1208: : 93 70 71 19 7f ba ad 07 8e
+ 1112: : 60 0a af d4
+ 1176: : 32 77 9f 8c 29 5f 56 ad !crc
+ 3007: : 40 17 4e ef !crc
+ 2032: : 26
+ 1232: : 26
+ 1296: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 26
+ 1312: : 26
+ 1400: : 93 70 71 19 7f ba ad 07 8e
+ 728: : 26
+ 1150: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1112: : 60 0c 99 b1
+ 1168: : fd 5b 56 fc 50 a7 c0 51 !crc
+ 944: : 78 7f 1c bc !crc
+ 2080: : 4e b4 8d 9b !crc
+ 2032: : 26
+ 1208: : 26
+ 1296: : 93 70 71 19 7f ba ad 07 8e
+ 114: 0: TAG 01
+ 974: : 26
+ 1288: : 26
+ 1400: : 93 70 71 19 7f ba ad 07 8e
+ 744: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 60 0d 10 a0
+ 1176: : 2d 78 1c be 79 57 c5 23 !crc
+ 936: : cc 9f 3a 4c !crc
+ 2087: : 48 44 b5 2a !crc
+ 2032: : 26
+ 1216: : 26
+ 1304: : 93 70 71 19 7f ba ad 07 8e
+ 1088: : 26
+ 1280: : 26
+ 1392: : 93 70 71 19 7f ba ad 07 8e
+ 752: : 26
+ 1144: : 26
+ 2319: : 60 0e 8b 92
+ 1176: : 02 11 08 33 21 3f 56 8b !crc
+ 928: : 53 b4 14 fa !crc
+ 2088: : 9f b4 b4 45 !crc
+ 2024: : 26
+ 1232: : 26
+ 1320: : 93 70 71 19 7f ba ad 07 8e
+ 1120: : 26
+ 1278: : 26
+ 1392: : 93 70 71 19 7f ba ad 07 8e
+ 736: : 26
+ 1144: : 26
+ 1208: : 93 70 71 19 7f ba ad 07 8e
+ 1208: : 60 08 bd f7
+ 154: 0: TAG 46
+ 1030: : 57 bd 3e ba 5a 24 1d 88 !crc
+ 5576: : 26
+ 1240: : 93 70 71 19 7f ba ad 07 8e
+ 172: 0: TAG 03!
+ 732: : 26
+ 1152: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 688: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 172: 0: TAG 03!
+ 748: : 26
+ 1144: : 26
+ 1887: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 904: : 26
+ 1152: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 696: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 920: : 26
+ 1144: : 26
+ 1895: : 26
+ 1152: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 904: : 26
+ 1152: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 704: : 26
+ 1144: : 26
+ 1208: : 93 70 71 19 7f ba ad 07 8e
+ 912: : 26
+ 3038: : 26
+ 1152: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 912: : 26
+ 1144: : 26
+ 1200: : 93 70 71 19 7f ba ad 07 8e
+ 696: : 26
+ 1144: : 26
Offline
I have the HF antenna bought on http://www.proxmark3.com/
My snoop is out of order, It worked previously, but not now and i don't know why.
When I run the snoop, immediatly after it display "blew circular buffer! " even if the antenna is in the air. (not between the card and the reader)
I tryed many version of osimage/fpgaimage/bootromimage available on the svn (218, 338, 442, and the last) but the problem is the same.
See below 2 examples where my antenna is in the air (not between the card and the reader)
proxmark3> hw tune
#db# Measuring antenna characteristics, please wait.
proxmark3>
# LF antenna: 0.00 V @ 125.00 kHz
# LF antenna: 0.00 V @ 134.00 kHz
# LF optimal: 0.00 V @ 12000.00 kHz
# HF antenna: 5.80 V @ 13.56 MHz
# Your LF antenna is unusable.
proxmark3> hf 14a snoop
#db# blew circular buffer!
#db# 191 0 0
#db# 20 0 0
with the other position of the switch of the antenna
proxmark3> hw tune
#db# Measuring antenna characteristics, please wait.
proxmark3>
# LF antenna: 0.00 V @ 125.00 kHz
# LF antenna: 0.00 V @ 134.00 kHz
# LF optimal: 0.00 V @ 12000.00 kHz
# HF antenna: 9.05 V @ 13.56 MHz
# Your LF antenna is unusable.
proxmark3> hf 14a snoop
#db# blew circular buffer!
#db# 191 0 0
#db# 20 0 0
proxmark3>
It's append the same with the antenna between the reader and the card, but sometimes if i'm lucky i can "hf 14a list" 2 ou 3 commands of the reader. The rest of the time, there is any communications recorded.
Does anyone have an idea ?
Last edited by MisterB (2010-06-17 14:15:31)
Offline
The switch should be left in the position yielding 9V. This is the expected voltage for a 47pF HF circuit.
Offline
Thanks but it doesn't fix my problem.
Offline