Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2020-08-03 14:30:19

hamperfait
Contributor
Registered: 2020-05-29
Posts: 2

Standalone HF_14ASNIFF MiFare Classic Sniff & decrypt keys

I have used a couple times the hf mf sniff command to later on decrypt the keys with mfkey64, but for that I need the proxmark3 connected to the computer through cable or the bluetooth module, which I don't have.
I saw the HF_14ASNIFF standalone mode, which sniffs 14a traffic and saves it to flashmem, so I can plug the proxmark3 into a battery, sniff the data using the standalone mode and afterwards plug it into the computer to retrieve the data.
Here are the commands I use after having sniffed the data

mem spiffs dump o hf_14asniff.trc f trace.trc
trace load trace.trc
trace list mf 1

But instead of getting the usual long chunk of communication reader/card, it only spills out 2 blocks, one for the tag and one for the reader.

      Start |        End | Src | Data (! denotes parity error)                                           | CRC | Annotation
------------+------------+-----+-------------------------------------------------------------------------+-----+--------------------
  300228560 |  300228563 | Tag |ff  20  00! 02! b4  71  46  49  08  49! 00! 09! 5c! 49! 00  8e! 44! 02!  |     | 
            |            |     |bc! 70  47! c0  46! 03! 00  51! e1  00! 00! e0! 33  01! 00! a0! 83  1e!  |     | 
            |            |     |ff! 2f  11  02! 00  50! e1! 00  00  e0  33  01! 00! a0  83  00  00  a0   |     | 
            |            |     |03! 1e  ff! 2f! e1! 80  22! 06! 4b! 52  04! 5a! 61  80  22! 05  4b  1b!  |     | 
            |            |     |68! d9! 69  52  01  11  42  00  d0  1a  62  70  47! c0! 46! 00  f4! ff!  |     | 
            |            |     |ff! 24  0d! 20! 00! 80! 23! 1c  4a  d1! 68  5b! 05  0b  43! 70! b5! d3   |     | 
            |            |     |60! 80! 22  19! 4b! 19! 68! 0a! 43  1a  60  80! 22! 00  25  12! 01  1a!  |     | 
            |            |     |61! 16  4b! 9d  60! 5d! 60! 80  23  15  4c  5b  04! 23  60! 23  61! 63!  |     | 
            |            |     |63! ff! f7  d3  ff  01  22  12  4b! 5a  60! 0a! 23  12! 4a  13  60  12!  |     | 
            |            |     |4b! 55  60  93! 60  11  49  d3  68  5b  18! 1b! 04  10  48! 11! 4d! 1b!  |     | 
            |            |     |0c! d1  68  09! 04! 09! 0c! 99  42! 01  d0! 05  60! f8  e7! 80  23! 5b   |     | 
            |            |     |04  23  63  23  61! 70  bc! 01  bc! 00  47! c0! 46  20! fc! ff! ff! 00!  |     | 
            |            |     |fc! ff! ff! 00! 00! fb  ff! 00! f4! ff! ff! 00  c0  fc! ff  00  c2  fc!  |     | 
            |            |     |ff! ff  ff  00! 00! 50! 12! 00! 00! 40  fd  ff  ff! 01  00  00! a5! f0   |     | 
            |            |     |b5! 01  24  2d! 4b  1b! 68  87  b0! 15  00  08! 2a  00  d9  08! 25! 4e!  |     | 
            |            |     |19  b1! 42! 25  d1! 06  6b! 26  42  26  d1! 4f  27! 1e! 6b  03! 96! 03!  |     | 
            |            |     |9e  3e  43  03! 96! 03! 9e! b4  46! 10  26  67! 46! 3e  43! 03  96! 03   |     | 
            |            |     |9e  1e  63  02  26! 07  6b  01! 97  01  9f! 37  42! 21! d0  1a  6b  04   | !crc| 
 2967844336 | 2967844418 | Rdr |03  90  24  a8  22  f0  ea  f8  22  f0  b7  f9  05  00  22  f0  70  fa   |     | 
            |            |     |67  4b  01  90  98  42  00  dd  01  93  22  f0  d7  f9  01  21  5f  20   |     | 
            |            |     |ff  f7  59  fd  01  21  00  20  ff  f7  1d  fe  6a  78  2b  78  9a  42   |     | 
            |            |     |26  d8  02  23  69  1e  01  9a  93  42  24  db  01  22  0a  e0  ea  5c   |     | 
            |            |     |c8  5c  90  42  01  d3  c0  2a  03  d8  01  33  01  9a  93  42  f5  db   |     | 
            |            |     |00  22  00  21  0e  00  08  00  02  91  00  91  94  46  5a  1c  01  99   |     | 
            |            |     |8a  42  15  db  02  9b  04  a9  1a  01  03  98  22  f0  8f  f8  02  98   |     | 
            |            |     |65  b0  f0  bc  02  bc  08  47  02  23  69  1e  e3  e7  ea  5c  c8  5c   |     | 
            |            |     |90  42  01  d8  3f  2a  d4  d9  01  33  cf  e7  a9  18  01  39  09  78   |     | 
            |            |     |0c  00  a9  5c  8c  42  04  d9  67  46  01  2f  57  d1  c0  29  06  d8   |     | 
            |            |     |8c  42  53  d2  67  46  00  2f  50  d1  3f  29  4e  d8  d1  1a  0f  29   |     | 
            |            |     |09  dd  17  29  0b  dd  1f  29  3a  dd  27  29  5b  dc  b3  42  4c  d1   |     | 
            |            |     |50  32  06  e0  10  27  7f  1a  07  2f  30  dc  b3  42  61  d1  60  32   |     | 
            |            |     |ff  32  80  28  23  d1  00  20  02  9b  1e  01  04  ab  24  a9  f6  18   |     | 
            |            |     |cb  79  8f  79  5b  00  db  19  4f  79  5b  00  db  19  0f  79  5b  00   |     | 
            |            |     |db  19  cf  78  5b  00  db  19  8f  78  5b  00  db  19  4f  78  5b  00   |     | 
            |            |     |db  19  0f  78  5b  00  db  19  33  54  01  30  08  31  10  28  e4  d1   |     | 
            |            |     |02  9b  01  33  02  93  01  9b  9a  42  31  da  00  26  00  96  30  00   |     | 

Any help in how to decrypt the password with something like this?
Thanks a lot in advance

Last edited by hamperfait (2020-08-03 14:31:08)

Offline

Board footer

Powered by FluxBB