Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
Pages: 1
My sniffer get only reader comand. I have uid,nr,ar and know key. How recover nt ?
On 1k not patched nt generation how nt = count << 16 | prng_successor(count, 16);
and i found nt quickly.
But if i try with card 1k with patched nt, i not found nt.
How rule get nt on fixed card ?
For example prox read 7 byte fixed card
36352 | 41056 | Rdr | 60 00 f5 7b | ok | AUTH-A(0)
43060 | 47732 | Tag | f5 9c b1 44
nt = f59cb144 not found by nt = count << 16 | prng_successor(count, 16);
Offline
currently you don't. For hardend prng, you have to use the hardnested attack (see helptext: hf mf hard h )
Offline
iceman, I do not break the card, I know the key. I wanted to find out what formula in patched cards is generated Nt ?
Or nt is completely random and not described by a formula like in non-patched cards?
Offline
So do we all. The fixed prng formula is unknown.
Offline
Pages: 1