Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2016-01-22 02:14:11

M&S
Contributor
Registered: 2015-12-15
Posts: 44

an other keri fob ....

I come across a strange Keri FOB.

printed code K21xx_28xxx34
"Lf search" failed to recognise this fob

"lf read"
https://www.dropbox.com/s/d50imlhtikann2u/keri_2131_2890234?dl=0

"lf investigate"
https://www.dropbox.com/s/ecy0fmxny9mssaj/investigated_keri_2131_2890234_.txt?dl=0

data plot
https://www.dropbox.com/s/sweowucux3jkwi4/keri.png?dl=0


only "data rawdemod" P1 or P2 delivered some results

re-occurrent code "FDB50DA55C7FFFFF" with "data rawdemod P1" and
re-occurrent code "36F8B77F24000000" with "data rawdemod P2" ....

That is all I can get ... But I don't see in the re-occurrent codes anything related to the printed code K21xx_28xxx34!

Does this make any sense to you?

Offline

#2 2016-01-22 09:19:44

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: an other keri fob ....

Your signal in your traces is really bad.  What's the voltage on your LF antenna? 

Maybe you can get at better demod if your captured signal is stronger

Offline

#3 2016-01-22 15:29:14

M&S
Contributor
Registered: 2015-12-15
Posts: 44

Re: an other keri fob ....

thanks for looking into this signal Iceman.

I was aware of that signal amplitude. But my pm3 only reads on this KERI's fob consistent that low. In between Keri reading I did check with HW tune on antenna signal, it is ok,

here is the SW I used
Prox/RFID mark3 RFID instrument         
bootrom: /-suspect 2015-12-07 18:21:10
os: /-suspect 2015-12-07 18:21:30
LF FPGA image built for 2s30vq100 on 2015/03/06 at 07:38:04
HF FPGA image built for 2s30vq100 on 2015/11/ 2 at  9: 8: 8
uC: AT91SAM7S512 Rev B         
Embedded Processor: ARM7TDMI         
Nonvolatile Program Memory Size: 512K bytes. Used: 168743 bytes (32%). Free: 355545 bytes (68%).         
Second Nonvolatile Program Memory Size: None         
Internal SRAM Size: 64K bytes         
Architecture Identifier: AT91SAM7Sxx Series         
Nonvolatile Program Memory Type: Embedded Flash Memory

and the power
.         
# LF antenna: 11.69 V @   125.00 kHz         
# LF antenna: 24.06 V @   134.00 kHz         
# LF optimal: 25.85 V @   134.83 kHz         
# HF antenna:  0.78 V @    13.56 MHz         

and I also did attempt EM41xx read between the Keri reading. It recognised the EM41xx fob ID without problem, but when going back to the keri it shown that much signal only and situation is consistent. no where decoding but only on P1 and P2.

I dont have the fob anymore, it belongs to my friend when I see him again in a month or two, I would like to have a strategy to collect much as possible datas to see why it is so with this fob

What steps should I do?

HW tune
lf search
lf search u

Offline

#4 2016-01-25 18:12:41

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: an other keri fob ....

the signal looks ok for PSK.
the repeating psk1 data appears correct, though I'd invert the bits for this particular format.  (and there is still a lot we don't know about this format.)

there is a thread that talks a little about it i believe here:http://www.proxmark.org/forum/viewtopic … 390#p13390

basically it is a scrambled bit pattern.

Offline

#5 2016-01-25 19:13:55

iceman
Administrator
Registered: 2013-04-25
Posts: 9,538
Website

Re: an other keri fob ....

If you get access to the fob again,  try getting a better read (somehow)... 

if you have access to several fobs of this kind,  map  printed number and psk-reads...   

Then look at the link @marshmellow posted and you take it from there.

Offline

#6 2016-01-26 22:35:24

M&S
Contributor
Registered: 2015-12-15
Posts: 44

Re: an other keri fob ....

Thank you.

I have looked in the link you provided. It looks like very much more datas we need to make this type of fob.

apropos the ful print cde is K2131_2890234.

When I have the fob again I will try to have more data. Regarding better reading, I am not sure if I can provide better. Before I contact the forum I must have done at least 30 readings, different angle, distance, all are consistent very low read signal I don't understand why read quality is so bad.

Also by trying all command in LF sector, I saw something strange with snoop. Is the command "lf snoop" a real command? It seems not to do anything

Offline

#7 2016-01-27 03:49:19

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: an other keri fob ....

Thanks for sharing.  It gets us closer.  The weak signal is not surprising for a small keyfob.  It is plenty strong enough to demod without errors.  psk tends to "look" weak anyway.  (since there are no long on or off periods to build up power)

Offline

#8 2016-01-27 03:50:48

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: an other keri fob ....

Also the lf snoop works if it is used as intended.  There is some information on that command on the forum that should guide you if you'd like to capture the communication from a reader to a tag.

Offline

#9 2016-01-27 04:02:53

M&S
Contributor
Registered: 2015-12-15
Posts: 44

Re: an other keri fob ....

Thank you for your info regarding the fob reading, Marshmellow.

I read somewhere You wish to have a Q5 fob for experiment/testing your SW fork. Do you still need one? I would gladly share some to you.

Offline

#10 2016-01-27 05:08:36

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: an other keri fob ....

I believe I fixed the main issues we had with the q5 in my fork...  though I have yet to finish up a few items to get it committed to the master.  Thanks for the offer though.  Out of curiosity, is the Q5 cheaper than the t55x7 chips in your area?

Offline

#11 2016-01-27 06:02:04

M&S
Contributor
Registered: 2015-12-15
Posts: 44

Re: an other keri fob ....

No, in general Q5 Sokymat is always at least double expensive than T5577 fob/disk/tag. How much more it depends which type you want.

http://www.rfidplaza.com/collections/keyfobs

I got lucky once and been offered a handful of Sokymat Bobsleigh Keyfobs Q5 with very good throw-away price.

Offline

#12 2016-01-27 06:23:44

marshmellow
Contributor
From: US
Registered: 2013-06-10
Posts: 2,302

Re: an other keri fob ....

That is what I thought, but I've been told by some it was cheaper and more readily available....  Maybe in china?   Not here.

Offline

Board footer

Powered by FluxBB