I got a Titan and a flexEM today, and my friend got an xEM. I’m programming both chips with the friends apartment key, and my flex worked perfectly, but his X series is proving difficult.
With my proxmark 3 easy lf search it shows up as an EM410X with no chipset and reads really well, but I just can’t find any trace of a t5577 in it.
I’ve tried:
lf t5 detect
lf t5 p1detect
lf t5 write -b 0 -d 00107071 -t (with a few different passwords as well)
lf t5 wipe
lf em 41 clone --id 0F0368568B
all with no luck. And this time it’s not even my fault, I know better what I’m doing compared to when I broke my NEXT, and didn’t write garbage directly to the config block.
If I didn’t know better I’d think you’d sent me a bog standard EM410X
done some tests of a random fob, and you’re right it doesn’t show as a t5577 when in em mode, but lf t5 det works, and I can’t replicate the able to read em but not t5. What’s the best way you’ve found to “break in” a chip? and why are they harder to write to?
EDIT:
Ok I’m kind of suspicious of my proxmark, for one the USB connector broke off so I had to solder a cable to it, and now some things aren’t working properly like it will say things like [!] Timeout while waiting for Proxmark LF initialization, aborting but not actually disconnect. I’ll see if re-flashing helps
Another thought (stabing in the dark) is could it have the 0x44 0x4E 0x47 0x52 ASCII of DNGR as the password? I’ll try that tomorrow
sending random password reads (that arent on the chip) to LF chips can damage them so be sparing with how much you do that, it can confuse and write instead, often not even writing the password you mean to send
what proxmark version are you running, can you post an output of the hw version command
when youre scanning make sure youre intersecting the implant with the antenna like this:
with the chip in that orientation run these commands it should refresh all important areas to default
Alright, I did a got pull then rebuilt and flashed the pm3, then I used data plot; lf read to find where I get the strongest signal, then ran your script, but still no change. Maybe I will wait a few weeks for the swelling to go down
If you’re able to, I would also try different readers. I’ve never been able to get a good read on the LF side of my NExT using my pm3, but the flipper zero reads it without much fuss. It sounds like the chip may actually need replacing, but it’s definitely worth trying different readers before going to the trouble of yanking and replacing.