Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2018-02-20 20:55:15

fips
Contributor
Registered: 2018-02-17
Posts: 12

hardnested: response just "#db# AcquireNonces: Auth1 error " Why?

I use quit new iceman fork,...

Proxmark3 RFID instrument
          
 [ ARM ]
 bootrom: iceman/master/ice_v3.1.0-599-gfb31d6d3 2018-02-19 23:57:21
      os: iceman/master/ice_v3.1.0-599-gfb31d6d3 2018-02-19 23:57:25
 [ FPGA ]
 LF image built for 2s30vq100 on 2017/10/25 at 19:50:50
 HF image built for 2s30vq100 on 2017/11/10 at 19:24:16
          
 [ Hardware ]           
  --= uC: AT91SAM7S256 Rev B          
  --= Embedded Processor: ARM7TDMI          
  --= Nonvolatile Program Memory Size: 256K bytes, Used: 235516 bytes (90) Free: 26628 bytes (10)          
  --= Second Nonvolatile Program Memory Size: None          
  --= Internal SRAM Size: 64K bytes          
  --= Architecture Identifier: AT91SAM7Sxx Series          
  --= Nonvolatile Program Memory Type: Embedded Flash Memory     

.., to read my tag:

pm3 --> hf search
          
 UID : AE 07 A7 6E           
ATQA : 00 04          
 SAK : 09 [2]          
TYPE : NXP MIFARE Mini 0.3k          
proprietary non iso14443-4 card found, RATS not supported          
Answers to magic commands: NO          
[!] error:  selecting tag failed,  can't detect prng
Prng detection: HARDEND (hardnested)          

Valid ISO14443-A Tag Found

My fast check:

pm3 --> hf mf fchk 0
[+] No key specified, trying default keys          
[ 0] ffffffffffff          
[ 1] 000000000000          
[ 2] a0a1a2a3a4a5          
[ 3] b0b1b2b3b4b5          
[ 4] c0c1c2c3c4c5          
[ 5] d0d1d2d3d4d5          
[ 6] aabbccddeeff          
[ 7] 1a2b3c4d5e6f          
[ 8] 123456789abc          
[ 9] 010203040506          
[10] 123456abcdef          
[11] abcdef123456          
[12] 4d3a99c351dd          
[13] 1a982c7e459a          
[14] d3f7d3f7d3f7          
[15] 714c5c886e97          
[16] 587ee5f9350f          
[17] a0478cc39091          
[18] 533cb6c723f6          
[19] 8fd0a4f256e9          
[+] Running strategy 1          
.....
[-] Chunk: 11,2s | found 6/10 keys (20)          
[+] Running strategy 2          
.....
[-] Chunk: 10,8s | found 6/10 keys (20)          
[+] Time in checkkeys (fast):  22,0s
          
|---|----------------|---|----------------|---|          
|sec|key A           |res|key B           |res|          
|---|----------------|---|----------------|---|          
|000|  a0a1a2a3a4a5  | 1 |  b0b1b2b3b4b5  | 1 |          
|001|  a0a1a2a3a4a5  | 1 |  ------------  | 0 |          
|002|  a0a1a2a3a4a5  | 1 |  ------------  | 0 |          
|003|  a0a1a2a3a4a5  | 1 |  ------------  | 0 |          
|004|  a0a1a2a3a4a5  | 1 |  ------------  | 0 |          
|---|----------------|---|----------------|---|          

but if I hardnest the tag it just response

#db# AcquireNonces: Auth1 error  

till I press the button.

full response till button:

pm3 --> hf mf hardnested 0 A a0a1a2a3a4a5 4 A w s
--target block no:  4, target key type:A, known target key: 0x000000000000 (not set), file action: write, Slow: Yes, Tests: 0           


          
 time    | #nonces | Activity                                                | expected to brute force          
         |         |                                                         | #states         | time           
------------------------------------------------------------------------------------------------------          
       0 |       0 | Start using 8 threads and AVX2 SIMD core                |                 |          
       0 |       0 | Brute force benchmark: 205 million (2^27,6) keys/s      | 140737488355328 |    8d          
       5 |       0 | Using 235 precalculated bitflip state tables            | 140737488355328 |    8d          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
Error: No response from Proxmark.
          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          
#db# AcquireNonces: Auth1 error          

How can I get ride of this error?
Thanks

Offline

#2 2018-02-20 21:18:23

iceman
Administrator
Registered: 2013-04-25
Posts: 9,497
Website

Re: hardnested: response just "#db# AcquireNonces: Auth1 error " Why?

There seem to be more problems with communicating with the card.

[!] error:  selecting tag failed,  can't detect prng
Prng detection: HARDEND (hardnested)  

Which device do you have?
Whats your output for  HW TUNE?

Offline

#3 2018-02-20 22:18:07

fips
Contributor
Registered: 2018-02-17
Posts: 12

Re: hardnested: response just "#db# AcquireNonces: Auth1 error " Why?

proxmark3 easy

pm3 --> hw tune

[+] measuring antenna characteristics, please wait........
[+] LF antenna: 26,63 V - 125.00 kHz          
[+] LF antenna: 20,54 V - 134.00 kHz          
[+] LF optimal: 26,48 V - 123,71 kHz          
[+] LF antenna is OK 
          
[+] HF antenna: 23,62 V - 13.56 MHz          
[+] HF antenna is OK          

Fun fact:
After my cat took her place on my desk, hardnested went through:

pm3 --> hf mf hardnested 0 A a0a1a2a3a4a5 4 A w s
--target block no:  4, target key type:A, known target key: 0x000000000000 (not set), file action: write, Slow: Yes, Tests: 0           



 time    | #nonces | Activity                                                | expected to brute force          
         |         |                                                         | #states         | time           
------------------------------------------------------------------------------------------------------          
       0 |       0 | Start using 8 threads and AVX2 SIMD core                |                 |          
       0 |       0 | Brute force benchmark: 1185 million (2^30,1) keys/s     | 140737488355328 |   33h          
       1 |       0 | Using 235 precalculated bitflip state tables            | 140737488355328 |   33h          
       4 |       0 | Writing acquired nonces to binary file hf-mf-AE07A76E-nonces.bin | 140737488355328 |   33h          
       4 |     112 | Apply bit flip properties                               |     81593049088 |   69s          
       6 |     224 | Apply bit flip properties                               |      3865828864 |    3s          
       7 |     336 | Apply bit flip properties                               |      1732520576 |    1s          
       7 |     448 | Apply bit flip properties                               |      1393666560 |    1s          
       8 |     559 | Apply bit flip properties                               |      1267456896 |    1s          
       9 |     670 | Apply bit flip properties                               |      1267456896 |    1s          
      10 |     780 | Apply bit flip properties                               |      1247843200 |    1s          
      10 |     891 | Apply bit flip properties                               |      1247843200 |    1s          
      11 |    1001 | Apply bit flip properties                               |      1247843200 |    1s          
      12 |    1113 | Apply bit flip properties                               |      1247843200 |    1s          
      13 |    1223 | Apply bit flip properties                               |      1247843200 |    1s          
      15 |    1331 | Apply Sum property. Sum(a0) = 120                       |       348616576 |    0s          
      15 |    1331 | (Ignoring Sum(a8) properties)                           |       348616576 |    0s          
      18 |    1331 | Brute force phase completed. Key found: a0a1a2a3a4a5    |               0 |    0s

Next question:
How do I get hf-mf-AE07A76E-key.bin which I need for a dump?

Offline

#4 2018-02-20 22:19:58

iceman
Administrator
Registered: 2013-04-25
Posts: 9,497
Website

Re: hardnested: response just "#db# AcquireNonces: Auth1 error " Why?

there has been many posts on hardnested.  Search the forum.

Offline

Board footer

Powered by FluxBB