> For the complete documentation index, see [llms.txt](https://fonty-s.gitbook.io/hacking-guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://fonty-s.gitbook.io/hacking-guide/devices-1/locker-rfid.md).

# Locker RFID

This post is about a device that uses different types of RFID tags for opening and closing a personal locker.

{% hint style="info" %}
[More information about RFID on the dedicated "Technology" page.](/hacking-guide/technology-1/researched-technologies/untitled.md)
{% endhint %}

### Attack scenario's  <a href="#docs-internal-guid-3ff257f3-7fff-da25-d793-8eaf5bb546b7" id="docs-internal-guid-3ff257f3-7fff-da25-d793-8eaf5bb546b7"></a>

* Bruteforce RFID UID&#x20;
* Card cloning
* Card read and simulation&#x20;
* Card write sector 0 (dos)

### Real life scenario's  <a href="#docs-internal-guid-6a79a191-7fff-0996-04ca-bf7b26f938f4" id="docs-internal-guid-6a79a191-7fff-0996-04ca-bf7b26f938f4"></a>

Card skimming by placing a reader next or on top of the existing reader. To execute a **card cloning or card simulation attack.**

A **Bruteforce attack** by trying multiple UID'S on a specific locker. This is not ideal because you will have to press a button each time before you can unlock it, this is not very realistic.&#x20;

A **Dos attack** by rewriting sector 0 on users RFID cards. Only possible with writeable cards.

### Steps

Steps for a card cloning/simulation attack.

1. Use card 1 to lock the locker.
2. Scan card 1 with a rfid reader to get the UID.
3. Write UID of card 1 to card 2.
4. Use card 2 to open the locker or simulate the UID of card 1 to open the locker by using the proxmark3.

#### Proxmark easy Steps

Steps for  a card cloning/Simulate attack using a proxmark.

1. Use card 1 to lock the locker.
2. Scan card 1 with proxmark  using the command **hf search** to get the UID and type of card.

   ![](https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5r6p-8T3dZELD5--q%2F-Lv5sELXuYlMi_lHAGRe%2Fafbeelding.png?alt=media\&token=0eb9e6dc-9948-4c58-8ed4-d085eb8c5fa1)
3. Check default keys of Mifare classic card using the command **hf mf chk \*1 ?** (Go to step 9 for Simulate UID).                     &#x20;

   &#x20;<img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5r6p-8T3dZELD5--q%2F-Lv5tFZkX5DSJ7Wj7S5W%2Fafbeelding.png?alt=media&amp;token=58cc3575-4363-4eb3-82c7-f8838cfed926" alt="" data-size="original">                      &#x20;
4. Dumping keys for each sector to dumpkeys.bin using command **hf mf nested 1 0 A ffffffffffff d** <img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5uGz_5QjXToaZiVZb%2F-Lv5ugg5TUwLj7dcjIDi%2Fafbeelding.png?alt=media&amp;token=2fdcb45e-c1e0-4f70-8bed-131df755419f" alt="" data-size="original">
5. Create dump file with the command **hf mf dump**&#x20;

   &#x20;<img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5uGz_5QjXToaZiVZb%2F-Lv5vqBmEiONO3gK-to8%2Fafbeelding.png?alt=media&amp;token=36668527-280d-44d2-9a6e-267e7acfea20" alt="" data-size="original">
6. Get card 2 change UID with the command **hf mf csetuid 795f17ad**<img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5uGz_5QjXToaZiVZb%2F-Lv5wMQyV0f7sbL1mrF6%2Fafbeelding.png?alt=media&amp;token=1d51aa18-5241-45e8-be10-73d81d14f5c4" alt="" data-size="original">
7. Use card 2 to open locker.

   <img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5uGz_5QjXToaZiVZb%2F-Lv5w_sLcs485bertY9k%2Fafbeelding.png?alt=media&amp;token=85df7bc8-28af-46e1-9fce-df77de54ab59" alt="" data-size="original">
8. Simulate card 1 using the command **hf 14a sim t 1 u 795f17ad** <img src="https://1131606193-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LsusNz5ftEuA4vj2ZtX%2F-Lv5uGz_5QjXToaZiVZb%2F-Lv5wv9KHk6_NTKBng4E%2Fafbeelding.png?alt=media&amp;token=84ca695c-23ee-4139-93d2-0c7c10f19821" alt="" data-size="original">
9. Use the proxmark to open locker

### DEMO

{% embed url="<https://drive.google.com/file/d/1ARkWg0eN_rc2suxeIY9FSc--V38q1PVN/view>" %}

#### Tools used

* Proxmark is handy for reading/writing data and to simulate RFID tags
  * Software and firmware used from the [ proxmark3 GitHub](https://github.com/Proxmark/proxmark3)
* RFID card 1 M1 S50 13,56 MHZ
* RFID card 2 UID 13,56 MHZ (clone card)
