So I got the implant in today(Ouch), we have a nice video to upload later… However does anyone have a good way to get the xEm into HID mode? With the DT cloner not an option does anyone have any recommendations… I hoped the WaveID reader would pick up on it in EM mode but no go…
Alright I figure this might help someone else trying to get and HID badge to a xem. I was thinking you needed to flash a bootloader or some other more advance configuration to get it in HID Mode. Really its just clone and done…
After you get your Proxmark3 you will hit. The following site has just about everything you need to get going on windows. To get going right away use the GUI client created by Gaucho.
Place your HID badge or token on the coil of the prox reader.
Open the GUI Client and use the Search Lf option (Command is ‘lf search’) Write down the first part of the tag number before the ().
At this point we need to find the sweet spot on your implant. In the same Search menu position your hand and hit scan. If you got a good lock it should return as an EM tag (If you never cloned before). Leaving you hand in that same spot follow the next step.
At this point we are ready to clone. Place that number you copied into the HID ID slot then hit Clone to Tag. I personally had to clone twice to get a good write. (Command ‘lf clone XXXXXXXXX’)
Check your tag using the LF search option again, it should return as an HID tag with your assigned tag number. If so go try a door scanner or whatever your using it for.
Thanks for the info! I wasn’t able to get the GUI to work but found out how to do it on cmd line…Issue is I can’t seem to get a read on my implant. You got the Proxmark3 easy right? Can you let me know how you positioned your hand/implant?
Hey,
It’s just takes some time it took me a good 3 tries to find the correct position. I believe they where working on a new cylinder scanner but I’m not sure where that is in development.
I’ve followed this post and I’ve done everything right, but even after several attempts at cloning, it’ll still read a an EM410x. Any idea what I’m doing wrong?
EDIT: I am trying to clone an HID UID (10 hex characters), just like you were trying to do. I was using the HID Clone command and passing in the correct ID, but no luck.
Hey natemcd - one thing that could be a problem is your antenna. I did not have much luck with the proxmark before making a custom antenna to better couple with the xEM. Modifying the antenna from the xEM Access Kit was what I did. I’m working on what will be hopefully a pretty comprehensive post regarding this and the issues with Chinese cloners and passwords and hope to have it up in a few days.
With the original PM3 antenna you need PERFECT positioning for writes to work. You want your xEM to be laying across one edge of the coil with the edge of the coil right in the centre of the xEM. IF you can do a lf t55 detect and get output your half way there. One command you can use to be sure that you are in the “sweet spot” is lf t55 info. If you can get output from that you should be in a position that allows descent coupling.
I was finally able to get a lf t55 detect response with a Block0 of 0x0x80060060. Where do I go from here? Should I wait until I get a response from that, and then try the clone command?
Was very much half asleep when writing that post I’m sorry! replace the lf t55xx info with lf t55xx trace.
Try and get your implant exactly perpendicular with but over the top of the edge of the coil.
Make sure that EVERY TIME you try and do an lf t55xx dump / read that you do the lf t55xx detect first
To make sure that you are getting a clean dump / read after doing the lf t55xx detect, issue an lf t55 trace. If you can read the traceability data you are in the right spot position wise. If not keep slightly re-positioning until you get a clean read, And then try the lf hid clone command copying a valid HID hex. The reasoning behind this is that it takes almost perfect coupling to read out the data from page1 of the chip which is where that data is stored.
The default Block 0 configuration for a t55 is 00088040.
FYI - if you can actually issue the command lf t55xx detect, of lf t55xx info, or lf t55xx trace and get some valid output - your chip is NOT LOCKED. If it were, it would not let you read raw block data. You most likely have some antenna / placement issues.
I have done some testing for you. See the below proxmark output. I started with a clean t55 chip, wiped it, checked to make sure I could read the blocks cleanly and then wrote the Block 0 data 00088040 like you described to see what would happen.
After that I could not detect or dump data from the chip - it looked dead. BUT at this point I just issued the lf t55 wipe command resetting the Block 0 settings to default.
proxmark3> lf t5 wipe
Beginning Wipe of a T55xx tag (assuming the tag is not password protected)
Hi there, I’m wondering if I could get some help with my xEM, I’ve become stuck. I can consistently get a response to the t55xx detect, that usually looks like this:
But nothing changes if I try to clone (or write) to it. lf search always discovers it as an em410 card. If I run t55xx info, sometimes it tells me the modulation is wrong, other times it returns inconsistent nonsense (as far as I can figure…)
proxmark3> lf t55xx info
– T55x7 Configuration & Tag Information --------------------
Safer key : 13
reserved : 0
Data bit rate : 2 - RF/6
eXtended mode : Yes - Warning
Modulation : 0x1C (Unknown)
PSK clock frequency : 0
AOR - Answer on Request : No
OTP - One Time Pad : No
Max block : 2
Password mode : Yes
Sequence Start Terminator : Yes
Fast Write : Yes
Inverse data : Yes
POR-Delay : Yes
Raw Data - Page 0
Block 0 : 0xD00BC05F 11010000000010111100000001011111
proxmark3> lf t55xx info
– T55x7 Configuration & Tag Information --------------------
Safer key : 8
reserved : 2
Data bit rate : 7 - RF/16
eXtended mode : Yes - Warning
Modulation : 0 - DIRECT (ASK/NRZ)
PSK clock frequency : 0
AOR - Answer on Request : Yes
OTP - One Time Pad : No
Max block : 7
Password mode : Yes
Sequence Start Terminator : Yes
Fast Write : No
Inverse data : No
POR-Delay : No
Raw Data - Page 0
Block 0 : 0x805E02F8 10000000010111100000001011111000
Is this an antenna issue, or is it bricked? Any help is welcome.
Nope. I don’t have experience with the proxmark3 before this, but I did read the horror stories with other cloners before starting. I honestly haven’t had time to work on it, I’ve been trying to write my dissertation. I can pull out the proxmark this weekend or next and try again.
I agree with @NiamhAstra, The best, yes, BUT not the only way… it really depends on how frequently you will use it.
This is what I would recommend if it is just a “one off” for a work badge etc.
FREE DOLLAR-EST
I would ask around on this forum to see if there is anybody near you with a Proxmark to help you out.
MOST HIGHLY RECOMMENDED-EST
Buy a Proxmar3 Easy ~$35
BEST TOOL AND MOST EXPENSIVE-EST
Buy a Proxmark3 RDV4 $300 + DT LF Antenna $30
CHEAPEST AND EASIEST-EST
Buy a blue cloner (but this recommendation comes with a clause)
This should do the job, but in the future you may need a Proxmark to “fix” your write.
but really for a little more $, grab a ProxMark3 Easy How to Blue cloner clone