@florianvandillen... Maybe is Crapto 1 but, I'm not sure, because in the video show the name card Mifare in the program, if u know, you let me know plz
Great video - thanks for posting it. Whilst we can appreciate that the technology has moved on since this was filmed, it nonetheless demonstrates how RFID 'contactless' systems are less than 100% secure, and also the modus operandi for gaining unauthorised access. It's crazy to think that for a tiny sum of money we can RFID protect Mr.Garcia's card - and in doing so , the potential to intercept data is removed, therefore there's no more problem. Whaddya think?
How do you gather data from an RFID reader? RFID is passive, so a serial attack is out of the question, because there's no "authenticated" signal to detect.
This comment has received too many negative votesshow
Hahaha!!!! Wow I can't believe some people believe this is real. Just look at the "data collector device" the ring on the end is made of duct tape. Lol, I don't believe duct tape can hack computer data.
iemand buiten de uni die die proxmark3 al in bezit heeft? Ik ben al een tijdje bezig om dit zelf eens te proberen.. maarja 350 euro voor een proxmark3 is toch een aardig bedrag :(
the signnature created is never the same on two transaction with the use of CDA, it uses unique number, amount etc. on the signure. the use of a static signature is rare, and can only be done so often by a card.
I work with contacless cards, and the only weak link here is the program implemented in the card, not the card itself. The use of CDA protocol makes this impossible to replicate, unless you discover the private key, but good luck with that (this with an asymetric key protocol).
It is useful to notice that an exact duplicate of a signature created by for example a 4096 bit key is still a valid signature.
The protocol could be as strong as you could make it, but if the data stored on the medium could be copied from a distance, there is no sense of security.
How did you get started in RFID hacking? And where/how did you get the sniffer? It looked pretty DIY. Very interesting! I see our little green sea is pretty far in this technology, and hacking it. lol. A friend of mine has a system in his school that's pretty similar. I wanna try to clone his card. Any tips where I can start?
jsommerlad: I agree with you, but what many people who view this video fail to realize is that RFID itself is not to blame here. The "implementation" is flawed. As you point out, the system SHOULD only let one person through but it's obviously not doing that.
This shit is so fucking easy to hack it's not funny. It's the dim witted dumb fucks that think they need to stop thinking once they get out of school that don't get it. I have got into almost every computer lab on many different campuses and planted so much shit by doing this very thing (well something very much like it). It was funny when everyone got Fs in Chemistry right before Spring Break... hehe
as a user of oyster PrePay in London I (and family members) have had problems too - not from hacking, but from the system not always reading cards properly and then charging the default 'maximum fare'. On complaining to the Oyster helpline (by telephone) I was told that sometimes there are problems with card readers at the ticket gates, but these are always corrected 'quickly'.
There is also someone being taken to court for failing to pay a bus fare - his card had enough money on it and he says that he did swipe it - so its not his fault if the system did not work correctly.
The first part is stupid ! The attacker can't connect data unless there's a card in the field. Reader gets data (from card) only after a succesful request+anticollision+select loop.
@noeglups The first part is ok, it can be used to get crypto key, but it is not so easy to read the card just "meeting" the person on the street. You have to be really near the card (few centimeters) and it takes time to read all sectors and blocks, at least 2-3 seconds. Possible but not so easy like it looks in this video.
That depends on who is going to do what with it. Russian mafia copying millions of Oyster cards in London and selling them at busstops would make it worth it...
My point is not whether or not it's worth it (of course it is). The point is that RFID is NOT the culprit, it's poor IMPLEMENTATIONS that give the technology a bad rap.
Getting unauthorized access in a office building is one thing, BUT the really frightening thing is RFID is now being used for credit /Debit cards, and other financial accounts accessing as well.
A lot of key cards still require a personal number to be punched in. It's impossible to find that number unless you can hack the main security server.
This comment has received too many negative votesshow
Smartass! Unbelievably impossible! Why do yo need to switch laptop you idiot! Unfortunately once you been recognize touching in you cannot touch in again unless you touch out. This will alert security and your ass will be in jail.
I did a thesis on this particular activity a year ago after recent RF emplacements were undergone. It's a difficult method to counter, so expect to see this happen more often.
guy in the middle looks like mark zuccerberg
jayp28 8 months ago
Is this shit for real? And legal?
BonesxtoxPaste 10 months ago
WOW. amazin.g i really want to learn how to do this.... looks like fun =p
poledancerz1 11 months ago
And against Reader+keypad? Reader+biometric. Back to the library I guess.
rancidtruth 1 year ago
What is the software called at 1:18?
DeeJayBounce 1 year ago
@DeeJayBounce It is called: "Omnikey CardMan 5121 Contact-Less Demo Application Programming" search google for: "contactlessdemovc".
1O67 10 months ago
@1O67 Nice, thanks.
DeeJayBounce 10 months ago
The guy "sniffing" the card at that distance and speed is a joke. This is total rubbish.
mifareman 1 year ago
@mifareman Agreed, I would tail the guy and try to sit next to him on a train or in a restaurant etc.
OurBackToTheDark 10 months ago
Geniaal gewoon.
Ga zo door!
dvdcase56 1 year ago
What software program is used to read and write data to and from the card?
florianvandillen 1 year ago
@florianvandillen... Maybe is Crapto 1 but, I'm not sure, because in the video show the name card Mifare in the program, if u know, you let me know plz
korredor07 1 year ago
why not just use a big fuckin brick?
ttaylor667 1 year ago
Great video - thanks for posting it. Whilst we can appreciate that the technology has moved on since this was filmed, it nonetheless demonstrates how RFID 'contactless' systems are less than 100% secure, and also the modus operandi for gaining unauthorised access. It's crazy to think that for a tiny sum of money we can RFID protect Mr.Garcia's card - and in doing so , the potential to intercept data is removed, therefore there's no more problem. Whaddya think?
RFIDProtect 1 year ago
How do you gather data from an RFID reader? RFID is passive, so a serial attack is out of the question, because there's no "authenticated" signal to detect.
ross817 1 year ago
as if someone would try that... probly a terrorist would
Sikora360 1 year ago
duct tape can hack computers.
Epeated 1 year ago
@Epeated With the proper amount of duct tape you can hack anything.
stewie7griffin 1 year ago 3
Any specs for building a GHOST?
djphilipps 1 year ago
Problems arise when Mr Garcia is already in the building and they try to enter using the same Mr Garcia Card...
hikorishi 1 year ago
Hey, your not Mr. Garcia!
gregtestagent 1 year ago
@gregtestagent Hey! You're not spelling 'you're' correctly!
razordaave 1 year ago
Hi,
I liked very much what you' ve done!
I' m trying hacking rfid ski pass, could you just tell me which software did you use to copy the data on the cards?
Thanks in advance
alby83fox 2 years ago
This comment has received too many negative votes show
Hahaha!!!! Wow I can't believe some people believe this is real. Just look at the "data collector device" the ring on the end is made of duct tape. Lol, I don't believe duct tape can hack computer data.
Riokushinaku 2 years ago
You are so epically stupid, how do you even feed yourself?
scottylans 2 years ago
PRO :0
paularu542 2 years ago
This comment has received too many negative votes show
I work with RFID, this is bulllshitting
ZeljanAlduk 2 years ago
nope you are "bullshitting"
enkrypt3d 2 years ago
This has been flagged as spam show
game bot
There is a peripheral device that is used in MMORPGs.
This device is developed for MMORPG players all around the world.
It also allows users who have been playing games for long hours to sit back and relax while the game is still played automatically!
For more information, please visit our website.
(automouse2/com)
* Playing games for a long time can damage your health.
Automouse2 2 years ago
I dont get how the system works. What the point of cracking it if supposedly all you need to do is copy what ever is in the RFID. No?
fabr1c1om 2 years ago
Yep, but to copy it you need first to read it ! That's why you need to crack the "read" key , to read it and then copy it.
bernivdw 2 years ago
anyone knows how to make mta cards.. please tell me.. tired of paying 225 a ride..lol
knightcrawler10467 2 years ago
If you are serious, you have a lot of learning to do my friend.
awesome3165 2 years ago
This is like something out of a heist movie...now they just need the vault code and they're rich!
arbitterm 2 years ago
iemand buiten de uni die die proxmark3 al in bezit heeft? Ik ben al een tijdje bezig om dit zelf eens te proberen.. maarja 350 euro voor een proxmark3 is toch een aardig bedrag :(
FRNS2007 2 years ago
Key of all tag is F9AB23456432?
If each tag have a different key, can't hack ?
besbungjbuwj 2 years ago
fuckin geniuses how do they know that?
meinvent 2 years ago
Mr. Garcia would be entering that building about 500 times a day lmfao xD
The1stPoster 2 years ago 26
the signnature created is never the same on two transaction with the use of CDA, it uses unique number, amount etc. on the signure. the use of a static signature is rare, and can only be done so often by a card.
mankinPT 2 years ago
I work with contacless cards, and the only weak link here is the program implemented in the card, not the card itself. The use of CDA protocol makes this impossible to replicate, unless you discover the private key, but good luck with that (this with an asymetric key protocol).
mankinPT 2 years ago
It is useful to notice that an exact duplicate of a signature created by for example a 4096 bit key is still a valid signature.
The protocol could be as strong as you could make it, but if the data stored on the medium could be copied from a distance, there is no sense of security.
proxmark 2 years ago
How did you get started in RFID hacking? And where/how did you get the sniffer? It looked pretty DIY. Very interesting! I see our little green sea is pretty far in this technology, and hacking it. lol. A friend of mine has a system in his school that's pretty similar. I wanna try to clone his card. Any tips where I can start?
flashback1234 2 years ago
The eavesdropper that is used here is the proxmark.
proxmark 2 years ago
I'm going to do some research on that.
Thanks a lot!
flashback1234 2 years ago
lol thanks netbooks for making things like this sooo much easier
starshock01 2 years ago 2
䋏䌜䋰䋋䊹䊻䌇䊸䊤䉿䊢䉿䊖䊽䋐 this is crap XD
discusting01 2 years ago
jsommerlad: I agree with you, but what many people who view this video fail to realize is that RFID itself is not to blame here. The "implementation" is flawed. As you point out, the system SHOULD only let one person through but it's obviously not doing that.
YDsixstring 3 years ago
wats the point of giving multiple people the cards? only one person can be in the building at once
jsommerlad 3 years ago
Security guard seems as useless as the key card.
andrewbnkjv 3 years ago
it's obviously a demonstration, or did you think he wouldn't notice all the camera equipment sitting behind his head pointing right at the monitor?
itsumonihon 3 years ago
Is this the MIFARE Classic version? What about the DES, 3DES version - is it secure?
djbanizza 3 years ago 2
Yes, this is about the Mifare Classic. We have no information on the DESFire.
DigitalSecurityRUN 3 years ago
This has been flagged as spam show
This shit is so fucking easy to hack it's not funny. It's the dim witted dumb fucks that think they need to stop thinking once they get out of school that don't get it. I have got into almost every computer lab on many different campuses and planted so much shit by doing this very thing (well something very much like it). It was funny when everyone got Fs in Chemistry right before Spring Break... hehe
darthspeaks 3 years ago
NICE
control2970 3 years ago
hahahah fuck you governmend cunts looks like u'll have to come up with something else to keep track of us, u little bastards :@
psarlay 3 years ago
very interesting...
as a user of oyster PrePay in London I (and family members) have had problems too - not from hacking, but from the system not always reading cards properly and then charging the default 'maximum fare'. On complaining to the Oyster helpline (by telephone) I was told that sometimes there are problems with card readers at the ticket gates, but these are always corrected 'quickly'.
Simon
citytransportinfo 3 years ago
There is also someone being taken to court for failing to pay a bus fare - his card had enough money on it and he says that he did swipe it - so its not his fault if the system did not work correctly.
citytransportinfo 3 years ago
The first part is stupid ! The attacker can't connect data unless there's a card in the field. Reader gets data (from card) only after a succesful request+anticollision+select loop.
noeglups 3 years ago
The device that is used in the first part emulates a Mifare card and that is how the data gets collected.
DigitalSecurityRUN 3 years ago
@noeglups The first part is ok, it can be used to get crypto key, but it is not so easy to read the card just "meeting" the person on the street. You have to be really near the card (few centimeters) and it takes time to read all sectors and blocks, at least 2-3 seconds. Possible but not so easy like it looks in this video.
markomnen 5 months ago
Why no technical detail HERE?
Q:
#1 website says cost of hack was under $10K. This was no easy hack.
#2 Does RFID reader support Silent Tree Walking?
#3 Software should notice duplicate Entries without Exits - this would be an EASY red flag.
My office has similar solution but displays your Photo to the guard. Two factor authentication is always a good idea.
If I were asked to hack the system what would I do? ... slip a student $20 to borrow his card (much cheaper than $10K. fools).
YDsixstring 3 years ago
That depends on who is going to do what with it. Russian mafia copying millions of Oyster cards in London and selling them at busstops would make it worth it...
OlandezBukovinian 3 years ago
My point is not whether or not it's worth it (of course it is). The point is that RFID is NOT the culprit, it's poor IMPLEMENTATIONS that give the technology a bad rap.
YDsixstring 3 years ago 2
So Flavio's key is really F9AB23456432?
martijno 3 years ago 14
haha, good catch
realmahadeo 3 years ago
Yeah they are Clinton , Obama , and MCcain all got their passports hack in to today. Now everyone has control over you . CNN Look it up 3-21-2008
Sweetdreamsprelude 3 years ago
It's true about RFID chips being insecure.
Getting unauthorized access in a office building is one thing, BUT the really frightening thing is RFID is now being used for credit /Debit cards, and other financial accounts accessing as well.
grodenbarg 3 years ago 2
A lot of key cards still require a personal number to be punched in. It's impossible to find that number unless you can hack the main security server.
conspiracy777 3 years ago
... unless you use a camera (ATM skimming), or UV-sensitive ink, or heck, replace/alter the pinpad.
cyt0plas 3 years ago
which SW was used to record data on the Scard?
wifi4all 3 years ago
This comment has received too many negative votes show
Smartass! Unbelievably impossible! Why do yo need to switch laptop you idiot! Unfortunately once you been recognize touching in you cannot touch in again unless you touch out. This will alert security and your ass will be in jail.
shock111ave 3 years ago
what do we have here? a comedian hahaha
blauwepiet 3 years ago
This comment has received too many negative votes show
I don't buy it.
t4kne 3 years ago
I did a thesis on this particular activity a year ago after recent RF emplacements were undergone. It's a difficult method to counter, so expect to see this happen more often.
fluentinsilence 3 years ago
Great work!
MeriaDuck 3 years ago
These guys are really pro :P
jiquera 3 years ago
Of course they are ;) Kinda proud of yourself :P?
Plausebol 3 years ago