Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
did a unmagic block0 write on a gen1 magic tag resulting that the tag don't responds anymore.
As a final idea, what is the "hf 14a raw" commands needed to talk to a magic tag?
hf 14a raw -p -a 52 // wupA
hf 14a raw -p -b 7 40 // wupC1
hf 14a raw -p 43 // wupC2
hf 14a raw -p 41 // wipe
Offline
Where did you get 41 and 43?
I remember an old thread with a sniffed trace between magic and "official" reader but i cannot find it...
Offline
Got it. thanks!
Offline
Maybe 43 and/or 41 are sent by the reader to look for a special card, maybe not all cards got the backdoor enabled with the same commands so the reader send more than 1.
Offline
A) 0x40 7 bits ( wake up Magic step1)
B) 0x43 8bits ( wake up Magic step 2) -- magic card is now in "backdoor mode"
C) 0x41 8bits ( special wipe the card command) resests the card to zeros..
This is the commands that is implemented inside the ARMSRC for magic cards.
A & B in sequence is needed to "enter" the backdoor mode.
after that there is only to send normal read / write commands and the tag will give it back without password.
or you can send the extra command C, which wipes the card.
Offline
Oh ok I was not aware of this, thank you.
Offline