Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

  • Logged in as ikarus
  • Last visit: Today 11:22:42

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2021-05-27 22:18:29

bretzd
Contributor
Registered: 2021-03-28
Posts: 10

Recovering Mifare keys

Hi everyone,

I have here a card where the standard keys don't work and wanted to try to recover they keys. To do that I used the proxmark3 to sniff (hf mf sniff) the communication between the card and the reader. The whole communication was written in the console, and initally I wasn't able to save it since I thought it would be possible to save it with the hf list command (but there was no communication listed).

I found and saved the whole communication in the proxmark3 log file, but I'm not sure how to recover the keys from there. Can someone give me some tips?

thank you

Offline

#2 2021-05-28 18:18:20

Onisan
Contributor
From: London
Registered: 2016-07-18
Posts: 88

Re: Recovering Mifare keys

Why don't you just use the nested/hardnested code to get the keys?

Offline

#3 2021-05-29 19:23:51

bretzd
Contributor
Registered: 2021-03-28
Posts: 10

Re: Recovering Mifare keys

Hi Onsian,

my understanding was that for hardnested there is one key needed to get the other keys. With the command:

hf mf hardnested r

I'm prompted with "Could not open nonces.bin". Additionally to that I tried the hardnested attack on another mifare card where I got some keys (chk), my computer would shut down after some time, so I thought that reading the communication between the card and reader would make it easier to recover the keys.

thanks

Offline

#4 2021-06-19 17:24:40

iceman
Administrator
Registered: 2013-04-25
Posts: 9,468
Website

Re: Recovering Mifare keys

I suggest you give RRG/Iceman repo a try,  and use

 hf mf autopwn 

Offline

Quick reply

Write your message and submit

Board footer

Powered by FluxBB