Proxmark3 community

Research, development and trades concerning the powerful Proxmark3 device.

Remember; sharing is caring. Bring something back to the community.


"Learn the tools of the trade the hard way." +Fravia

You are not logged in.

Announcement

Time changes and with it the technology
Proxmark3 @ discord

Users of this forum, please be aware that information stored on this site is not private.

#1 2018-05-11 16:25:18

trazodone
Contributor
Registered: 2015-11-25
Posts: 50

Infineon My-d vicinity SRF55V02P

Hello,

I am not sure this topic may relate to pm3. At lease pm3 can read this kind of tag in ISO15693 or hf 15
I am testing tag Infineon My-d vicinity SRF55V02S and SRF55V10P. Regarding the datasheet, Tag has 2 operation mode 1) Plain Mode 2) Secure mode
I have both kind of tags.
1) Plain mode can read data from any block while
2) Secure mode I can get only UID, when I tried to read block data it read failed.

I am wondering I can't/no permission to read block data so how the specific reader gets data from tag in secure mode? Is there a secret keys sending between specific reader and tag? Is it possible to sniff data using pm3?

Thank you.

Last edited by trazodone (2018-05-11 16:33:32)

Offline

#2 2018-05-11 16:32:06

trazodone
Contributor
Registered: 2015-11-25
Posts: 50

Re: Infineon My-d vicinity SRF55V02P

This is from hf 15 dumpmemory (SRF55V10P) plain mode
===================================
roxmark3> hf 15 dumpmemory
Reading memory from tag UID=E0050000012F7544         
Tag Info: Infineon; SRF55V10P [IC id = 00]  plain mode 10KBit         
Block 00   00 00 00 00    ....         
Block 01   12 34 56 78    .4Vx         
Block 02   62 54 02 65    bT.e         
Block 03   6E 32 46 39    n2F9         
Block 04   34 78 6D 52    4xmR         
Block 05   6A 4C 49 65    jLIe         
Block 06   6D 6D 75 4F    mmuO         
Block 07   6A 39 65 36    j9e6         
Block 08   44 54 79 38    DTy8         
Block 09   00 00 00 00    ....         
Block 0a   49 39 48 38    I9H8         
Block 0b   48 54 39 49    HT9I         
Block 0c   45 44 52 39    EDR9         
Block 0d   74 41 6B 6E    tAkn         
Block 0e   74 39 32 43    t92C         
Block 0f   4F 57 61 49    OWaI         
Block 10   43 75 73 76    Cusv         
Block 11   36 7A 56 46    6zVF         
Block 12   4E 39 43 57    N9CW         
Block 13   62 64 35 61    bd5a         
Block 14   64 4A 59 72    dJYr         
Block 15   36 33 4F 76    63Ov         
Block 16   56 30 41 73    V0As         
Block 17   52 38 39 4E    R89N         
proxmark3>

===================================
This is from hf 15 dumpmemory (SRF55V02S) secure mode
===================================
proxmark3> hf 15 dumpmemory
Reading memory from tag UID=E00550000AC2AA32         
Tag Info: Infineon; SRF55V02S [IC id = 80]  secure mode 2kBit         
Tag returned Error 16: The specified block is not available (doesn’t exist).         
proxmark3>


Thanks

Last edited by trazodone (2018-05-11 16:33:45)

Offline

#3 2018-10-30 12:55:47

b_osi
Contributor
From: Hamburg
Registered: 2018-05-01
Posts: 8

Re: Infineon My-d vicinity SRF55V02P

Hi,

I just have a secured one, tried to get some datasheets to get all commands for these tags, but unfortunately they are available with NDA - and the public ones you get do not reveal much about the secure mode...
In secure mode it looks like there is some negotiation, reader always starts this challenge/response with a0 0520030005
The token sends everytime different bytes back, and the next command from reader is also everytime different , but constant command start: a0 05f9fafafa <then random bytes>.
I sniffed with chameleon mini.

Cheers

Offline

#4 2019-01-15 16:33:36

Json50
Contributor
Registered: 2018-08-30
Posts: 21

Re: Infineon My-d vicinity SRF55V02P

I Have Infineon magic card

Offline

Board footer

Powered by FluxBB