Not an original title or problem. About 2.5 years ago xEM installed in my hand. I was excited to reprogram it and in hindsight I should have moved a little slower.
When I first attempted to read it, “lf search” using my Proxmark3 Rdv4 (latest official PM3 fw at the time), I didn’t read anything. This is the first point I should have stopped and taken a look at what was going on. I then assumed that the tag was blank, though now I realize it should have had a EM4100 ID already programmed. I attempted a “lf t5 detect” and it seemed to be responding, so then I decided to try to program it to a HID key with “lf clone hid deadbeef”, then a “lf search”. It did not read at this point and I tried several other things including a “lf t5 wipe”.
The end results is the tag doesn’t respond at all. After the fact I attempted to read my buddies newly implanted tag and it read easily with a EM4100 tag. I since learned there are known issues in trying to effectively couple the the antenna to a RFID tag this small.
I have been ignoring this useless lump in my hand in the mean time. So I recently picked up the ProxLF antenna and hoped it would be the magic bullet. That does not appear to be the case. I have updated my Proxmark3 RDV4 to a recent version of the Iceman repository.
I also originally posted over in the Proxmark forum and didn’t get anywhere. I just updated my post over there and decided to post here too.
Here are the hardware / software details:
[ Proxmark3 RFID instrument ]
[ CLIENT ]
client: RRG/Iceman/master/v4.9237-3004-g7034aa525 2021-02-04 14:38:20
compiled with MinGW-w64 10.2.0 OS:Windows (64b) ARCH:x86_64
[ PROXMARK3 ]
firmware.................. PM3RDV4
external flash............ present
smartcard reader.......... present
FPC USART for BT add-on... absent
[ ARM ]
bootrom: RRG/Iceman/master/v4.9237-3004-g7034aa525 2021-02-04 14:38:08
os: RRG/Iceman/master/v4.9237-3004-g7034aa525 2021-02-04 14:38:15
compiled with GCC 8.4.0
[ FPGA ]
LF image built for 2s30vq100 on 2020-07-08 at 23: 8: 7
HF image built for 2s30vq100 on 2020-07-08 at 23: 8:19
HF FeliCa image built for 2s30vq100 on 2020-07-08 at 23: 8:30
[ Hardware ]
--= uC: AT91SAM7S512 Rev B
--= Embedded Processor: ARM7TDMI
--= Nonvolatile Program Memory Size: 512K bytes, Used: 309545 bytes (59%) Free: 214743 bytes (41%)
--= Second Nonvolatile Program Memory Size: None
--= Internal SRAM Size: 64K bytes
--= Architecture Identifier: AT91SAM7Sxx Series
--= Nonvolatile Program Memory Type: Embedded Flash Memory
An “lf search” doesn’t produce anything particularly useful:
So I am hoping someone can help me determine if the tag is recoverable or completely toasted. I attempted to capture some data that I thought would be useful:
[usb] pm3 --> lf search
[=] NOTE: some demods output possible binary
[=] if it finds something that looks like a tag
[=] False Positives ARE possible
[=]
[=] Checking for known tags...
[=]
[!] (em4x50) timeout while waiting for reply.
[+] Indala (len 232) Raw: 80000000000000000000000000000000000000000000000000000000
[+] Valid Indala ID found!
[!] (em4x50) timeout while waiting for reply.
An “lf t5 wipe” followed by an “lf search” doesn’t do anything exciting:
[usb] pm3 --> lf t5 wipe
[=] Target T55x7 tag
[=] Default configuration block 000880E0
[=] Begin wiping...
[=] Writing page 0 block: 00 data: 0x000880E0
[=] Writing page 0 block: 01 data: 0x00000000
[=] Writing page 0 block: 02 data: 0x00000000
[=] Writing page 0 block: 03 data: 0x00000000
[=] Writing page 0 block: 04 data: 0x00000000
[=] Writing page 0 block: 05 data: 0x00000000
[=] Writing page 0 block: 06 data: 0x00000000
[=] Writing page 0 block: 07 data: 0x00000000
[usb] pm3 --> lf search
[=] NOTE: some demods output possible binary
[=] if it finds something that looks like a tag
[=] False Positives ARE possible
[=]
[=] Checking for known tags...
[=]
[+] Indala (len 232) Raw: 80000000000000000000000000000000000000000000000000000000
[+] Valid Indala ID found!
Couldn't identify a chipset
Finally a “lf t5 detect” doesn’t work.
[usb] pm3 --> lf t5 det
[!] Could not detect modulation automatically. Try setting it manually with 'lf t55xx config'
[usb] pm3 -->
I have also tried many other things, but nothing that produces any useful results.
All suggestions are appreciated. Otherwise it may be time to remove this things.