RFID attacks and proxmark hands-on @ KirilsSolovjovs +4fd9 About - - PowerPoint PPT Presentation

rfid attacks and proxmark hands on
SMART_READER_LITE
LIVE PREVIEW

RFID attacks and proxmark hands-on @ KirilsSolovjovs +4fd9 About - - PowerPoint PPT Presentation

RFID attacks and proxmark hands-on @ KirilsSolovjovs +4fd9 About me Programming sysad networking IT security for the past 10+ y Owner and Lead Researcher at Possible Security Hacking and breaking things


slide-1
SLIDE 1

+4fd9

RFID attacks and proxmark hands-on

@KirilsSolovjovs

slide-2
SLIDE 2

+4fd9

  • Programming → sysad →

networking

  • IT security for the past 10+ y
  • Owner and Lead

Researcher at Possible Security

  • Hacking and breaking things

http://kirils.org/

http://possiblesecurity.com/news/

About me

slide-3
SLIDE 3

+4fd9

  • RFID basics
  • RFID standarts
  • Hacking tools
  • Proxmark

+ Lots of demos

Contents

slide-4
SLIDE 4

+4fd9

  • NFC is a subset of RFID

– 13.56MHz – ISO/IEC 14443 – NFC device can be both a reader and a tag

Let’s get this out of the way: RFID vs NFC?

slide-5
SLIDE 5

+4fd9

  • Microchip
  • Antenna
  • No power source

RFID tag

slide-6
SLIDE 6

+4fd9

  • Radio Frequency Identification

RFID

slide-7
SLIDE 7

+4fd9

  • LF
  • 125 kHz
  • 134.2 kHz
  • ...

Typical RFID frequencies

  • HF
  • 13.56 MHz
  • ...
slide-8
SLIDE 8

+4fd9

  • ISO/IEC 14443A

– Mifare

  • ISO/IEC 14443B
  • ISO/IEC 15693

RFID standards

  • em4xxx
  • HID Global

iClass

Hitag2

Indala

  • TI
slide-9
SLIDE 9

+4fd9

  • RFID readers
  • RFID duplication “gun”
  • Frequency scanner
  • BLEkey
  • hackRF… ?
  • Proxmark III !

Tools

slide-10
SLIDE 10

+4fd9

Proxmark III

slide-11
SLIDE 11

+4fd9

Proxmark III RDV 2 / 4

slide-12
SLIDE 12

+4fd9

  • Problematic for UID-based protocols
  • BLEKey

– Bluetooth connected UID

sniffer / storage

Wiegand interface

slide-13
SLIDE 13

+4fd9

  • Duplicating contents of one card into another
  • Often involves breaking some cryptography or defeating some other protection

Card cloning

slide-14
SLIDE 14

+4fd9

Mifare Ultralight

slide-15
SLIDE 15

+4fd9

Mifare Classic

slide-16
SLIDE 16

+4fd9

slide-17
SLIDE 17

+4fd9

  • https://github.com/Proxmark/proxmark3/wiki/Kali-Linux

Proxmark III setup

slide-18
SLIDE 18

+4fd9

  • reading cards...
  • attacks…

+ mfkey

Proxmark III magic

slide-19
SLIDE 19

+4fd9

Proxmark III snooping