Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2015-08-08 20:53:27

silentperplexion
Member
Registered: 2015-08-06
Posts: 4

Nested key recovery causes Proxmark to become unresponsive

Hi all.

I recently purchased a Proxmark3 for a university project, and I'm having issues running the MIFARE nested key recovery. All of the other functions I've used within the hf tree seem to work fine (reading, writing, sniffing, emulating, etc.) However, if I attempt to launch the nested attack, the Proxmark freezes, turns three solid red lights on, and refuses to respond to commands from the PC. The command window prints, "Waiting for a response from the proxmark... Don't forget to cancel its operation first by pressing on the button" over and over. If I try to cancel the operation by pressing the button, nothing happens. Interestingly enough, if I move the Proxmark away from the tag, I get a "#db# Nested: Can't select card" error, which seems to indicate the Proxmark is trying to do something. The only way to regain control of the device is to disconnect it from the PC and reconnect it. I let the command run overnight just to make sure I wasn't being impatient, but it did the same thing for 8 hours straight.

This issue originally occurred on 2.1.0, but I later downgraded to 2.0.0 to see if it had any effect - it didn't. I'm completely at a loss at what is going wrong, and I'd appreciate any help or ideas anyone can offer. Hopefully I'm overlooking something obvious.

Thanks!

[== Undefined ==]
#db# Prox/RFID mark3 RFID instrument
#db# bootrom: /-suspect 2015-05-24 09:54:53
#db# os: /-suspect 2015-05-24 09:56:23
#db# HF FPGA image built on 2015/03/09 at 08:41:42
uC: AT91SAM7S512 Rev A
Embedded Processor: ARM7TDMI
Nonvolatile Program Memory Size: 512K bytes
Second Nonvolatile Program Memory Size: None
Internal SRAM Size: 64K bytes
Architecture Identifier: AT91SAM7Sxx Series
Nonvolatile Program Memory Type: Embedded Flash Memory
proxmark3> hf mf dbg 2
#db# Debug level: 2
proxmark3> hf mf nested 4 0 A a0a1a2a3a4a5 t (I'm sure this key is valid.)
Testing known keys. Sector count=40
nested...
-----------------------------------------------
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
(...)
#db# Nested: Can't select card
#db# Nested: Can't select card
#db# Nested: Can't select card
#db# Nested: Can't select card
#db# Nested: Can't select card
#db# Nested: Can't select card
#db# Nested: Can't select card
(...)
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
Waiting for a response from the proxmark...
Don't forget to cancel its operation first by pressing on the button
(...)

Offline

#2 2015-08-08 21:04:58

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: Nested key recovery causes Proxmark to become unresponsive

Try the latest release (2.2.0) or download the github source and compile/flash,   If you can report back both tracelog and output from nested.  (hf list 14a / hf mf nested)

Offline

#3 2015-08-09 05:35:48

silentperplexion
Member
Registered: 2015-08-06
Posts: 4

Re: Nested key recovery causes Proxmark to become unresponsive

iceman wrote:

Try the latest release (2.2.0) or download the github source and compile/flash,   If you can report back both tracelog and output from nested.  (hf list 14a / hf mf nested)

When I compile from the github source or from (2.2.0), I get a fullimage.stage1.elf and a fullimage.elf file. The latter is only ~150kb which is substantially lower than the fullimage.elf files I have from 2.0.0 and 2.1.0. Does that sound correct? Also, what do I do with the *.stage1.elf file? I just want to make sure I compiled everything properly before I go flash this and end up with a colorful brick with shiny lights.

Offline

#4 2015-08-09 07:20:37

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: Nested key recovery causes Proxmark to become unresponsive

sounds about right,  but with this you must flash the bootrom first.  The reason for them being smaller is the compression being added to them by piwi's latest changes.

Do nothing with the *stage* files.

Offline

#5 2015-08-12 03:23:14

silentperplexion
Member
Registered: 2015-08-06
Posts: 4

Re: Nested key recovery causes Proxmark to become unresponsive

Alright - got everything compiled and running from the current github source, however the nested attack still doesn't seem to work. Interestingly enough, it now says the card isn't vulnerable to attack. I tried a Gen1 1k Chinese Magic Card and that also failed. Output is below. (Thanks for all your help thus far, iceman)

[== Undefined ==]
Prox/RFID mark3 RFID instrument          
bootrom: master/v2.2.0-52-g5d01f50-suspect 2015-08-11 04:04:11
os: master/v2.2.0-52-g5d01f50-suspect 2015-08-11 04:04:12
LF FPGA image built for 2s30vq100 on 2015/03/06 at 07:38:04
HF FPGA image built for 2s30vq100 on 2015/06/22 at 21:47:54
          
uC: AT91SAM7S512 Rev A          
Embedded Processor: ARM7TDMI          
Nonvolatile Program Memory Size: 512K bytes. Used: 166364 bytes (32%). Free: 357924 bytes (68%).          
Second Nonvolatile Program Memory Size: None          
Internal SRAM Size: 64K bytes          
Architecture Identifier: AT91SAM7Sxx Series          
Nonvolatile Program Memory Type: Embedded Flash Memory          
proxmark3> hf mf nested 4 0 A a0a1a2a3a4a5 t
Testing known keys. Sector count=40          
nested...          
-----------------------------------------------          
Tag isn't vulnerable to Nested Attack (random numbers are not predictable).
[== Undefined ==]
proxmark3> hf list 14a
Recorded Activity (TraceLen = 3434 bytes)          
          
Start = Start of Start Bit, End = End of last modulation. Src = Source of Transfer          
iso14443a - All times are in carrier periods (1/13.56Mhz)          
iClass    - Timings are not as accurate          
          
     Start |       End | Src | Data (! denotes parity error)                                   | CRC | Annotation         |          
-----------|-----------|-----|-----------------------------------------------------------------|-----|--------------------|          
         0 |      4768 | Rdr | 50  00  57  cd                                                  |     | HALT          
    140160 |    141152 | Rdr | 52                                                              |     | WUPA          
    142388 |    144756 | Tag | 02  00                                                          |     |           
    147200 |    149664 | Rdr | 93  20                                                          |     | ANTICOLL          
    150836 |    156660 | Tag | 24  99  4d  cc  3c                                              |     |           
    158848 |    169312 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
    170548 |    174132 | Tag | 18  37  cd                                                      |     |           
    175616 |    180320 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
    184628 |    189300 | Tag | 4e  e4  df  bd                                                  |     |           
    198144 |    207456 | Rdr | 93  7f! 8f! b1! 9d! 9a  56  f3                                  | !crc| ANTICOLL          
    208692 |    213428 | Tag | 59! 00  8c  1c                                                  |     |           
    218880 |    223648 | Rdr | 19! ea! bb! c4                                                  | !crc| ?          
    227892 |    232628 | Tag | 99  ae! a6  c1                                                  |     |           
    241536 |    250912 | Rdr | 89! 43  32! 67! 05  4c  69! 44!                                 | !crc| ?          
    252084 |    256820 | Tag | f8! 97  3e  bb!                                                 |     |           
    290816 |    295520 | Rdr | 65  fa! 9a! 21                                                  | !crc| ?          
    430976 |    431968 | Rdr | 52                                                              |     | WUPA          
    433204 |    435572 | Tag | 02  00                                                          |     |           
    438016 |    440480 | Rdr | 93  20                                                          |     | ANTICOLL          
    441652 |    447476 | Tag | 24  99  4d  cc  3c                                              |     |           
    449664 |    460128 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
    461364 |    464948 | Tag | 18  37  cd                                                      |     |           
    466432 |    471136 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
    475444 |    480180 | Tag | 0a  35  0b  ba                                                  |     |           
    488960 |    498336 | Rdr | 0c! 58! d5  72  77! f9! 7d  7e!                                 | !crc| ?          
    499508 |    504180 | Tag | c9  4f! ff! 85!                                                 |     |           
    509696 |    514464 | Rdr | 3f! 0b  76! fd                                                  | !crc| ?          
    518708 |    523380 | Tag | f7! 5e  bf! 72                                                  |     |           
    532224 |    541600 | Rdr | 38  aa  b7  47  47  2f  c2  51                                  | !crc| ?          
    542772 |    547444 | Tag | 7d  85! a6  0a                                                  |     |           
    581504 |    586208 | Rdr | 8f  4b  63  92!                                                 | !crc| ?          
    721664 |    722656 | Rdr | 52                                                              |     | WUPA          
    723892 |    726260 | Tag | 02  00                                                          |     |           
    728704 |    731168 | Rdr | 93  20                                                          |     | ANTICOLL          
    732340 |    738164 | Tag | 24  99  4d  cc  3c                                              |     |           
    740352 |    750816 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
    752052 |    755636 | Tag | 18  37  cd                                                      |     |           
    757120 |    761824 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
    766132 |    770804 | Tag | 61  13  56  3f                                                  |     |           
    779648 |    788960 | Rdr | 51  28  4b! a4! b8  22  21! c5                                  | !crc| ?          
    790196 |    794932 | Tag | 96  ed  49  e2!                                                 |     |           
    800384 |    805088 | Rdr | 6f  8a! 91! 01!                                                 | !crc| ?          
    809396 |    814068 | Tag | c4  6d  92  54!                                                 |     |           
    822912 |    832288 | Rdr | 4c  dc  a2! 0f  73  14! 68  fe                                  | !crc| ?          
    833460 |    838132 | Tag | 3c! c6! e3  47                                                  |     |           
    872192 |    876896 | Rdr | 97! a4  6a  28                                                  | !crc| ?          
   1012352 |   1013344 | Rdr | 52                                                              |     | WUPA          
   1014580 |   1016948 | Tag | 02  00                                                          |     |           
   1019392 |   1021856 | Rdr | 93  20                                                          |     | ANTICOLL          
   1023028 |   1028852 | Tag | 24  99  4d  cc  3c                                              |     |           
   1031040 |   1041504 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   1042740 |   1046324 | Tag | 18  37  cd                                                      |     |           
   1047808 |   1052512 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   1056820 |   1061556 | Tag | 22  28  25  20                                                  |     |           
   1070336 |   1079712 | Rdr | a5  c3  99! 1a! c1  ae  26  ac!                                 | !crc| ?          
   1080884 |   1085556 | Tag | 9a  8b  f1! c6                                                  |     |           
   1091072 |   1095776 | Rdr | 33  48! e4! 78                                                  | !crc| ?          
   1100084 |   1104820 | Tag | 11  25! 53  4a                                                  |     |           
   1113600 |   1122912 | Rdr | 2c  a0  29! a9  05! 32! c4! 9a                                  | !crc| ?          
   1124148 |   1128884 | Tag | 8d  39! 1a! 12!                                                 |     |           
   1162880 |   1167648 | Rdr | be  e2  5f! db!                                                 | !crc| ?          
   1303040 |   1304032 | Rdr | 52                                                              |     | WUPA          
   1305268 |   1307636 | Tag | 02  00                                                          |     |           
   1310080 |   1312544 | Rdr | 93  20                                                          |     | ANTICOLL          
   1313716 |   1319540 | Tag | 24  99  4d  cc  3c                                              |     |           
   1321728 |   1332192 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   1333428 |   1337012 | Tag | 18  37  cd                                                      |     |           
   1338496 |   1343200 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   1347508 |   1352180 | Tag | 63  a8  82  b1                                                  |     |           
   1361024 |   1370400 | Rdr | 92! 3f! 88! 36! b5! 1b  ec  75                                  | !crc| ?          
   1371572 |   1376244 | Tag | 03  01! 3c! 3b!                                                 |     |           
   1381760 |   1386528 | Rdr | e3! 0c  fd  cc!                                                 | !crc| ?          
   1390772 |   1395444 | Tag | ee! fa  d6! ee                                                  |     |           
   1404288 |   1413664 | Rdr | 22  83  56! 4c! d7! e9  3e! d4!                                 | !crc| ?          
   1414836 |   1419572 | Tag | 47! 8f  0d  88!                                                 |     |           
   1453568 |   1458336 | Rdr | e0! 8c! cb! 82!                                                 | !crc| RATS          
   1593728 |   1594720 | Rdr | 52!                                                             |     | WUPA          
   1595956 |   1598324 | Tag | 02  00                                                          |     |           
   1600768 |   1603232 | Rdr | 93  20                                                          |     | ANTICOLL          
   1604404 |   1610228 | Tag | 24  99  4d  cc  3c                                              |     |           
   1612416 |   1622880 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   1624116 |   1627700 | Tag | 18  37  cd                                                      |     |           
   1629184 |   1633888 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   1638196 |   1642868 | Tag | 83  6a  77  a9                                                  |     |           
   1651712 |   1661024 | Rdr | 2d! 10  44  83! 5f! fe! 27  9c                                  | !crc| ?          
   1662260 |   1666996 | Tag | 81! 4f! 5c! 4a                                                  |     |           
   1672448 |   1677216 | Rdr | d5! c4  da  fc!                                                 | !crc| ?          
   1681460 |   1686196 | Tag | 00! d2  97! 8f                                                  |     |           
   1694976 |   1704288 | Rdr | 6b! ab  4c  06! 4a! 49! 3d  74                                  | !crc| ?          
   1705524 |   1710260 | Tag | a5  ff  77! 6b                                                  |     |           
   1744256 |   1749024 | Rdr | f6  8a  ee  e0                                                  | !crc| ?          
   1884416 |   1885408 | Rdr | 52                                                              |     | WUPA          
   1886644 |   1889012 | Tag | 02  00                                                          |     |           
   1891456 |   1893920 | Rdr | 93  20                                                          |     | ANTICOLL          
   1895092 |   1900916 | Tag | 24  99  4d  cc  3c                                              |     |           
   1903104 |   1913568 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   1914804 |   1918388 | Tag | 18  37  cd                                                      |     |           
   1919872 |   1924576 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   1928884 |   1933556 | Tag | 19  55  22  c6                                                  |     |           
   1942400 |   1951712 | Rdr | 3c! 86! 49! 9f! 8d! bb  17  6c                                  | !crc| READ_SIG          
   1952948 |   1957684 | Tag | 30  65! 76! f8                                                  |     |           
   1963136 |   1967840 | Rdr | e0  77  93  f9                                                  | !crc| RATS          
   1972148 |   1976820 | Tag | b9! ab! 92! 58!                                                 |     |           
   1985664 |   1994976 | Rdr | 4f! bd! 1a  f6! 16! ff! bb  58!                                 | !crc| ?          
   1996212 |   2000948 | Tag | 96! b9! cc! da                                                  |     |           
   2034944 |   2039648 | Rdr | dd  96! d8! 87                                                  | !crc| ?          
   2175104 |   2176096 | Rdr | 52!                                                             |     | WUPA          
   2177332 |   2179700 | Tag | 02  00                                                          |     |           
   2182144 |   2184608 | Rdr | 93  20                                                          |     | ANTICOLL          
   2185780 |   2191604 | Tag | 24  99  4d  cc  3c                                              |     |           
   2193792 |   2204256 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   2205492 |   2209076 | Tag | 18  37  cd                                                      |     |           
   2210560 |   2215264 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   2219572 |   2224244 | Tag | c8  b6  6e  c5                                                  |     |           
   2233088 |   2242400 | Rdr | 46  8c  dc  18! 2e! 63  06! ee                                  | !crc| ?          
   2243636 |   2248372 | Tag | 9f! 1c! 87  40                                                  |     |           
   2253824 |   2258528 | Rdr | 47  26! 73  7e                                                  | !crc| ?          
   2262836 |   2267508 | Tag | 1f! 00! 72  d0!                                                 |     |           
   2276352 |   2285664 | Rdr | ac! 54  ce  ac  bb  6a  87! ba!                                 | !crc| ?          
   2286900 |   2291636 | Tag | b9  66! 8c  5e                                                  |     |           
   2325632 |   2330336 | Rdr | 5a! 2d! 94! 52!                                                 | !crc| ?          
   2465792 |   2466784 | Rdr | 52                                                              |     | WUPA          
   2468020 |   2470388 | Tag | 02  00                                                          |     |           
   2472832 |   2475296 | Rdr | 93  20                                                          |     | ANTICOLL          
   2476468 |   2482292 | Tag | 24  99  4d  cc  3c                                              |     |           
   2484480 |   2494944 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   2496180 |   2499764 | Tag | 18  37  cd                                                      |     |           
   2501248 |   2505952 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   2510260 |   2514932 | Tag | 1d  b0  ab  c6                                                  |     |           
   2523776 |   2533088 | Rdr | 6c  6f! 5e! 53! 96  f4! de  a1!                                 | !crc| ?          
   2534324 |   2538996 | Tag | 7b  ba  ef! dd                                                  |     |           
   2544512 |   2549216 | Rdr | b1! f1! 13  90                                                  | !crc| ?          
   2553524 |   2558260 | Tag | 8d  1d! 56! ca!                                                 |     |           
   2567168 |   2576480 | Rdr | f2  80  04  0e  31  4b  89  ca                                  | !crc| ?          
   2577716 |   2582452 | Tag | ee  d3  1e! cf!                                                 |     |           
   2616448 |   2621216 | Rdr | 90! d9  4c  c5!                                                 | !crc| ?          
   2756608 |   2757600 | Rdr | 52                                                              |     | WUPA          
   2758836 |   2761204 | Tag | 02  00                                                          |     |           
   2763648 |   2766112 | Rdr | 93  20                                                          |     | ANTICOLL          
   2767284 |   2773108 | Tag | 24  99  4d  cc  3c                                              |     |           
   2775296 |   2785760 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   2786996 |   2790580 | Tag | 18  37  cd                                                      |     |           
   2792064 |   2796768 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   2801076 |   2805812 | Tag | 7c  0f  89  57                                                  |     |           
   2814592 |   2823904 | Rdr | e0! 8f  6e! b7  af  c9! 5c! d8                                  | !crc| RATS          
   2825140 |   2829812 | Tag | eb  91! c5  d6!                                                 |     |           
   2835328 |   2840096 | Rdr | bf  71! 10! bd!                                                 | !crc| ?          
   2844340 |   2849012 | Tag | 58! ce! 7d! 8b                                                  |     |           
   2857856 |   2867232 | Rdr | 22! ec! ef  36  d5! 4f! d4! fa!                                 | !crc| ?          
   2868404 |   2873076 | Tag | 9e  74! b2! b2                                                  |     |           
   2907136 |   2911904 | Rdr | 93  cc  cb! 4e!                                                 | !crc| ANTICOLL          
   3047296 |   3048288 | Rdr | 52!                                                             |     | WUPA          
   3049524 |   3051892 | Tag | 02  00                                                          |     |           
   3054336 |   3056800 | Rdr | 93  20                                                          |     | ANTICOLL          
   3057972 |   3063796 | Tag | 24  99  4d  cc  3c                                              |     |           
   3065984 |   3076448 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   3077684 |   3081268 | Tag | 18  37  cd                                                      |     |           
   3082752 |   3087456 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   3091764 |   3096436 | Tag | e5  1d  94  0a                                                  |     |           
   3105280 |   3114592 | Rdr | 28! c0! f0  2b! be  08! fc! db                                  | !crc| ?          
   3115828 |   3120500 | Tag | ac  29  af  83!                                                 |     |           
   3126016 |   3130720 | Rdr | c3  d2  e1! de                                                  | !crc| ?          
   3135028 |   3139764 | Tag | ce! cb  4a! b6                                                  |     |           
   3148544 |   3157856 | Rdr | f5  5b! c1! f9! fd! d9  76! 13!                                 | !crc| ?          
   3159092 |   3163828 | Tag | 19  b0! a6! c5!                                                 |     |           
   3197824 |   3202592 | Rdr | 99! ad! 1f! b2!                                                 | !crc| ?          
   3337984 |   3338976 | Rdr | 52!                                                             |     | WUPA          
   3340212 |   3342580 | Tag | 02  00                                                          |     |           
   3345024 |   3347488 | Rdr | 93  20                                                          |     | ANTICOLL          
   3348660 |   3354484 | Tag | 24  99  4d  cc  3c                                              |     |           
   3356672 |   3367136 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   3368372 |   3371956 | Tag | 18  37  cd                                                      |     |           
   3373440 |   3378144 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   3382452 |   3387124 | Tag | 6e  cb  64  30                                                  |     |           
   3395968 |   3405344 | Rdr | c3! 1c  2c  5c! 62! 60  42! d5                                  | !crc| ?          
   3406516 |   3411188 | Tag | be! 5b! e5  c9                                                  |     |           
   3416704 |   3421408 | Rdr | bc! 96  a9! 86!                                                 | !crc| ?          
   3425716 |   3430452 | Tag | 3b! ec  25  4a                                                  |     |           
   3439232 |   3448544 | Rdr | b7! b0! cb  4e! 1a! 1a  d1  14                                  | !crc| ?          
   3449780 |   3454516 | Tag | db! 30! 64  b4!                                                 |     |           
   3488512 |   3493216 | Rdr | fc  94  fe! 1a!                                                 | !crc| ?          
   3628672 |   3629664 | Rdr | 52                                                              |     | WUPA          
   3630900 |   3633268 | Tag | 02  00                                                          |     |           
   3635712 |   3638176 | Rdr | 93  20                                                          |     | ANTICOLL          
   3639348 |   3645172 | Tag | 24  99  4d  cc  3c                                              |     |           
   3647360 |   3657824 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   3659060 |   3662644 | Tag | 18  37  cd                                                      |     |           
   3664128 |   3668832 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   3673140 |   3677812 | Tag | 42  ef  c4  35                                                  |     |           
   3686656 |   3696032 | Rdr | 2d! 08  5e! ed  ff  8d! 8d! 2b!                                 | !crc| ?          
   3697204 |   3701940 | Tag | 18  c3! 79! 81!                                                 |     |           
   3707392 |   3712160 | Rdr | e7! 49! f1! e1!                                                 | !crc| ?          
   3716404 |   3721076 | Tag | 23  d9! 46! a9                                                  |     |           
   3729920 |   3739296 | Rdr | 28! ac! 8e  d7  f8  f8  6e! 22!                                 | !crc| ?          
   3740468 |   3745204 | Tag | 19! 5c  e5  4a                                                  |     |           
   3779200 |   3783968 | Rdr | 14  ee  f9  64                                                  | !crc| ?          
   3919360 |   3920352 | Rdr | 52!                                                             |     | WUPA          
   3921588 |   3923956 | Tag | 02  00                                                          |     |           
   3926400 |   3928864 | Rdr | 93  20                                                          |     | ANTICOLL          
   3930036 |   3935860 | Tag | 24  99  4d  cc  3c                                              |     |           
   3938048 |   3948512 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   3949748 |   3953332 | Tag | 18  37  cd                                                      |     |           
   3954816 |   3959520 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   3963828 |   3968564 | Tag | d0  34  8e  37                                                  |     |           
   3977344 |   3986656 | Rdr | e4  4d! 08  fc  f6  5a  42  49!                                 | !crc| ?          
   3987892 |   3992564 | Tag | 0e  ff  89  99                                                  |     |           
   3998080 |   4002848 | Rdr | b9  c7  ec  e4!                                                 | !crc| ?          
   4007092 |   4011828 | Tag | f1  51! 14  96!                                                 |     |           
   4020608 |   4029984 | Rdr | 80  b4! ae  26! a9  0c! fd! 95!                                 | !crc| ?          
   4031156 |   4035828 | Tag | ac! 87! 58  2e                                                  |     |           
   4069888 |   4074656 | Rdr | 8a  ed! 98! 00!                                                 | !crc| ?          
   4210048 |   4211040 | Rdr | 52                                                              |     | WUPA          
   4212276 |   4214644 | Tag | 02  00                                                          |     |           
   4217088 |   4219552 | Rdr | 93  20                                                          |     | ANTICOLL          
   4220724 |   4226548 | Tag | 24  99  4d  cc  3c                                              |     |           
   4228736 |   4239200 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   4240436 |   4244020 | Tag | 18  37  cd                                                      |     |           
   4245504 |   4250208 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   4254516 |   4259252 | Tag | fd  02  32  f4                                                  |     |           
   4268032 |   4277344 | Rdr | c4  3e  8c! d9! 4b! fc! 56  17                                  | !crc| ?          
   4278580 |   4283316 | Tag | 38! c6! e7! 79                                                  |     |           
   4288768 |   4293472 | Rdr | e7! c1  fa  0b!                                                 | !crc| ?          
   4297780 |   4302516 | Tag | 18! 42! 94  af!                                                 |     |           
   4311424 |   4320800 | Rdr | 22! 4e! ce  b6  00  e9! 92  84!                                 | !crc| ?          
   4321972 |   4326708 | Tag | 20  4a! 98! fb                                                  |     |           
   4360704 |   4365408 | Rdr | d7  d2  bd  5c                                                  | !crc| ?          
   4500864 |   4501856 | Rdr | 52                                                              |     | WUPA          
   4503092 |   4505460 | Tag | 02  00                                                          |     |           
   4507904 |   4510368 | Rdr | 93  20                                                          |     | ANTICOLL          
   4511540 |   4517364 | Tag | 24  99  4d  cc  3c                                              |     |           
   4519552 |   4530016 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   4531252 |   4534836 | Tag | 18  37  cd                                                      |     |           
   4536320 |   4541024 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   4545332 |   4550068 | Tag | fa  f6  a1  e9                                                  |     |           
   4558848 |   4568160 | Rdr | 03! 32  70! cd! b0  79! 0e  c9                                  | !crc| ?          
   4569396 |   4574068 | Tag | 30  cd! a4! 7d                                                  |     |           
   4579584 |   4584352 | Rdr | 4a  ad  9a! 46                                                  | !crc| ?          
   4588596 |   4593332 | Tag | 2b  23  03! 3c!                                                 |     |           
   4602112 |   4611424 | Rdr | 73! ad! 6b! f3! 92  5b  2f! 94!                                 | !crc| ?          
   4612660 |   4617332 | Tag | b5! 0d! af! 6c                                                  |     |           
   4651392 |   4656160 | Rdr | fd  ff  63! 3d                                                  | !crc| ?          
   4791552 |   4792544 | Rdr | 52!                                                             |     | WUPA          
   4793780 |   4796148 | Tag | 02  00                                                          |     |           
   4798592 |   4801056 | Rdr | 93  20                                                          |     | ANTICOLL          
   4802228 |   4808052 | Tag | 24  99  4d  cc  3c                                              |     |           
   4810240 |   4820704 | Rdr | 93  70  24  99  4d  cc  3c  5d  e2                              |     | SELECT_UID          
   4821940 |   4825524 | Tag | 18  37  cd                                                      |     |           
   4827008 |   4831712 | Rdr | 60  00  f5  7b                                                  |     | AUTH-A(0)          
   4836020 |   4840756 | Tag | 80  b0  30  e5                                                  |     |           
   4849536 |   4858848 | Rdr | 2f! 73! 8b! 78! 4c! eb! 0b! 90                                  | !crc| ?          
   4860084 |   4864756 | Tag | 29  14  ef  55                                                  |     |           
   4870272 |   4874976 | Rdr | 8f  53! c0! 8c!                                                 | !crc| ?          
   4879284 |   4883956 | Tag | 53! 34! 0b  27                                                  |     |           
   4892800 |   4902112 | Rdr | ef! cf! 40  8c  26! ff  2d  b4                                  | !crc| ?          
   4903348 |   4908020 | Tag | 80  6a! ac  ef!                                                 |     |           
proxmark3> 

Offline

#6 2015-08-12 08:07:37

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: Nested key recovery causes Proxmark to become unresponsive

two tries,  one failed because its of a newer version of the 1k which it now says.  (a patch from @piwi )

and the chinese gen1 try, I'm not sure, you just pasted the tracelog.  Not the "hf mf nested" output for it.
If you can do that, it would help.

Offline

#7 2015-08-15 23:53:57

silentperplexion
Member
Registered: 2015-08-06
Posts: 4

Re: Nested key recovery causes Proxmark to become unresponsive

iceman wrote:

two tries,  one failed because its of a newer version of the 1k which it now says.  (a patch from @piwi )

The card I'm trying to read is a MIFARE Classic 4K, so unless that's what you mean by "newer version of the 1k," there's something amiss. Below is the hf 14a read output for the aforementioned card. Does the nested attack not work on 4K cards?

 UID : 24 99 4d cc 
ATQA : 00 02
 SAK : 18 [2]
TYPE : NXP MIFARE Classic 4k | Plus 4k SL1
proprietary non iso14443-4 card found, RATS not supported
Answers to chinese magic backdoor commands: NO
iceman wrote:

and the chinese gen1 try, I'm not sure, you just pasted the tracelog.  Not the "hf mf nested" output for it.
If you can do that, it would help.

When I run the nested attack on the Chinese Gen1 card, the same thing as before I updated the firmware happens - "Waiting for a response from the proxmark... Don't forget to cancel its operation first by pressing on the button" if dbg level is >=2. Otherwise, it just prints "---------------------------------------" forever.

The hf mf nested output for the Chinese Gen1 card is as follows:

proxmark3> hf mf nested 1 0 A a0a1a2a3a4a5 t 
Testing known keys. Sector count=16
nested...
-----------------------------------------------
-----------------------------------------------
-----------------------------------------------
(...)

Offline

#8 2015-08-16 10:42:08

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: Nested key recovery causes Proxmark to become unresponsive

Yes,  newer version of mifare tags which uses the crypto-1,   which could be 1k or 4k.   I just assumed it was a 1K, didn't look at yr parameter for the command.  Yr 4k tag is not vulnable to the nested attack.  You can still sniff the trafic between tag and a reader to get keys,  or you can try the known default keys. (hf mf chk)

Yr magic gen1 tag seem not like the nested command either. However you can always write yr own keys on that tag with the "hf mf c*" commands.  What is the output from "hf 14a reader" on it?

Offline

Board footer

Powered by FluxBB