Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Time changes and with it the technology
Proxmark3 @ discord
Users of this forum, please be aware that information stored on this site is not private.
Pages: 1
Hi all,
As far as I can see, at the moment the proxmark would not be able to snoop on 125kHz communications between tags & readers: am I missing something there? I'd like to be able to do this to better understand some weird 125kHz tags I have... Do you think it would be possible to implement this type of feature without touching the FPGA code ?
Ed
Offline
i'm just starting here so everything i'm gonna say can be far away from the truth :
the point of snooping is to get all the part of a communication between a tag and a reader.
i'm not sure that 125Khz are having any kind of 'communication'.
the tag is only seending his id when he gets powered up by a reader.
so there would be nothing to snoop.
Offline
Hmm, not necessarily quite true: just getting raw samples of the communication between the tag & reader can be useful to determine what type of modulation the tag & reader use. I agree, though, most 125kHz tags just send their ID, but a lot of LF tags can still be programmed using proprietary commands.
Offline
It can be more than only the ID, take for example the hitag2 product. It communicates over LF, but still uses an encrypted communication. The cipher is very similar to the MIFARE Classic. More info about this can be found here.
Offline
i'm just starting here so everything i'm gonna say can be far away from the truth :
the point of snooping is to get all the part of a communication between a tag and a reader.
i'm not sure that 125Khz are having any kind of 'communication'.
the tag is only seending his id when he gets powered up by a reader.so there would be nothing to snoop.
actually, things like 125khz hotel keys have stored data blocks, so snooping the reader commands that are used to access those blocks when the key is presented would be very useful...
Offline
Has anyone made any progress on snooping 125khz? I know this would be very handy for things like Henryk and Karsten do.
Thanks,
CSM
Offline
Pages: 1