Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
Pages: 1
Hello,
I am not sure this topic may relate to pm3. At lease pm3 can read this kind of tag in ISO15693 or hf 15
I am testing tag Infineon My-d vicinity SRF55V02S and SRF55V10P. Regarding the datasheet, Tag has 2 operation mode 1) Plain Mode 2) Secure mode
I have both kind of tags.
1) Plain mode can read data from any block while
2) Secure mode I can get only UID, when I tried to read block data it read failed.
I am wondering I can't/no permission to read block data so how the specific reader gets data from tag in secure mode? Is there a secret keys sending between specific reader and tag? Is it possible to sniff data using pm3?
Thank you.
Last edited by trazodone (2018-05-11 16:33:32)
Offline
This is from hf 15 dumpmemory (SRF55V10P) plain mode
===================================
roxmark3> hf 15 dumpmemory
Reading memory from tag UID=E0050000012F7544
Tag Info: Infineon; SRF55V10P [IC id = 00] plain mode 10KBit
Block 00 00 00 00 00 ....
Block 01 12 34 56 78 .4Vx
Block 02 62 54 02 65 bT.e
Block 03 6E 32 46 39 n2F9
Block 04 34 78 6D 52 4xmR
Block 05 6A 4C 49 65 jLIe
Block 06 6D 6D 75 4F mmuO
Block 07 6A 39 65 36 j9e6
Block 08 44 54 79 38 DTy8
Block 09 00 00 00 00 ....
Block 0a 49 39 48 38 I9H8
Block 0b 48 54 39 49 HT9I
Block 0c 45 44 52 39 EDR9
Block 0d 74 41 6B 6E tAkn
Block 0e 74 39 32 43 t92C
Block 0f 4F 57 61 49 OWaI
Block 10 43 75 73 76 Cusv
Block 11 36 7A 56 46 6zVF
Block 12 4E 39 43 57 N9CW
Block 13 62 64 35 61 bd5a
Block 14 64 4A 59 72 dJYr
Block 15 36 33 4F 76 63Ov
Block 16 56 30 41 73 V0As
Block 17 52 38 39 4E R89N
proxmark3>
===================================
This is from hf 15 dumpmemory (SRF55V02S) secure mode
===================================
proxmark3> hf 15 dumpmemory
Reading memory from tag UID=E00550000AC2AA32
Tag Info: Infineon; SRF55V02S [IC id = 80] secure mode 2kBit
Tag returned Error 16: The specified block is not available (doesn’t exist).
proxmark3>
Thanks
Last edited by trazodone (2018-05-11 16:33:45)
Offline
Hi,
I just have a secured one, tried to get some datasheets to get all commands for these tags, but unfortunately they are available with NDA - and the public ones you get do not reveal much about the secure mode...
In secure mode it looks like there is some negotiation, reader always starts this challenge/response with a0 0520030005
The token sends everytime different bytes back, and the next command from reader is also everytime different , but constant command start: a0 05f9fafafa <then random bytes>.
I sniffed with chameleon mini.
Cheers
Offline
I Have Infineon magic card
Offline
Pages: 1