Cloning to gen2 cuid tag

im trying to restore to gen 2 cuid tag but keep getting the following problem, ive tried with --force but that doesnt work either

[usb] pm3 → hf mf restore -f C:\data.bin -k C:\key.bin
[+] Loaded binary key file C:\key.bin
[+] Loaded 1024 bytes from binary file C:\data.bin

[=] blk | data | status
[=] -----±------------------------------------------------±---------------
[=] 0 | 0C 0C A5 63 C6 08 04 00 05 A8 69 80 1F 19 B4 90 | ( ok )
[=] 1 | 41 30 30 2D 4B 30 30 00 47 46 41 30 30 00 00 00 | ( ok )
[=] 2 | 50 4C 41 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 4 | 50 4C 41 20 42 61 73 69 63 00 00 00 00 00 00 00 | ( ok )
[=] 5 | 00 00 00 FF E8 03 00 00 00 00 E0 3F 00 00 00 00 | ( ok )
[=] 6 | 37 00 08 00 00 00 00 00 E6 00 BE 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 8 | 80 3E 80 3E E8 03 E8 03 CD CC 4C 3F CD CC 4C 3E | ( ok )
[=] 9 | 83 13 94 65 F5 89 4C AA A5 D1 A1 7C 85 93 F2 A2 | ( ok )
[=] 10 | 00 00 00 00 AC 0F 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 12 | 32 30 32 36 5F 30 34 5F 30 35 5F 30 38 5F 33 30 | ( ok )
[=] 13 | 32 36 5F 30 34 5F 30 35 5F 30 38 00 00 00 00 00 | ( ok )
[=] 14 | 00 00 00 00 4A 01 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 16 | 02 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 17 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 18 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 21 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 22 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 24 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 25 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 26 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 28 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 29 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 30 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 32 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 33 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 34 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 36 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 37 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 38 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 40 | 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 41 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ( ok )
[=] 42 | 2F D7 98 5A 2A 66 12 E8 43 83 11 40 57 A0 CB B2 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 44 | 61 FF 40 C8 5C B6 72 78 44 9D 90 38 40 D4 03 48 | ( ok )
[=] 45 | 88 9E 74 C9 FA 2C B1 EA 90 7E 44 56 89 03 B3 23 | ( ok )
[=] 46 | 75 25 E2 CC 81 C0 E1 0D 8E 51 FA 0C 8B A2 1F 12 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 48 | 0E EA B3 84 6A 07 1F E6 62 7F F8 18 D8 DD C8 AA | ( ok )
[=] 49 | 1C A5 8D 1F 24 1E 31 FD DE 62 88 68 F0 34 C1 F7 | ( ok )
[=] 50 | 91 33 C9 7D 64 BD 66 12 AF AD A8 93 21 7E D6 C9 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 52 | E6 2A 9A 04 E4 6A BF E1 0D 89 47 1F 13 DC 15 8E | ( ok )
[=] 53 | 94 4C E8 B2 01 0F 6D 9F CF 6F 2A 9F 49 7D FF 68 | ( ok )
[=] 54 | 05 2B AB BB 88 15 B3 E0 AC 35 B6 F9 12 F4 08 83 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 56 | F3 9A 35 F1 54 98 3E 9A B4 48 8F 4D 82 14 61 DE | ( ok )
[=] 57 | FB AE 5A 12 D0 74 A7 C7 48 AC 89 F0 C1 1C 37 E7 | ( ok )
[=] 58 | DB 3A 96 D9 4F 81 8D 7A A6 9E AA 13 5F 7B 0C AD | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] 60 | A9 3D 0B B7 4C C5 DF 8C 55 D4 16 3F 9E 5E 13 87 | ( ok )
[=] 61 | 44 8A D7 38 BB 3C 69 8B 39 6F EB 90 BD EA 64 8D | ( ok )
[=] 62 | 7F 0B CD 3A 25 71 4B B6 20 98 42 2B 11 E3 7E 64 | ( ok )
[!] Strict ReadOnly Access Conditions on block 0 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 1 detected
[=] Skipping, use --force to override and write this data
[!] Strict ReadOnly Access Conditions on block 2 detected
[=] Skipping, use --force to override and write this data
[=] -----±------------------------------------------------±---------------

[?] Hint: Try hf mf dump --ns to verify
[=] Done!

1 Like

Can you show us the output from hf mf info first, please?

What errors does it show then?

1 Like

[usb] pm3 → hf mf info

[=] — ISO14443-a Information -----------------------------
[+] UID: 0C 0C A5 63
[+] ATQA: 00 04

+\] SAK: 08 \[1

[=] — Keys Information
[+] loaded 2 user keys
[+] loaded 63 hardcoded keys
[+] Sector 0 key A… FFFFFFFFFFFF
[+] Sector 0 key B… FFFFFFFFFFFF
[+] Sector 1 key A… FFFFFFFFFFFF
[+] Sector 1 key B… FFFFFFFFFFFF
[+] Backdoor key… same as key A/B
[+] Block 0… 0C0CA563C608040005A869801F19B490 | ..i…

[=] — Fingerprint
[+] n/a

[=] — Magic Tag Information

[+] Magic capabilities… Gen 2 / CUID

[=] — PRNG Information
[+] Prng… weak

1 Like

the error is that it appears to only be copying the uid nothing else gets copied to the tag

The thing about Gen2 magic mifare chips is that they work just like a regular mifare chip, only sector 0 is able to be written to.

The thing that trips people up is that the chip respects access bits and key permission settings for each sector just like a real chip would. If you don’t have the keys for a sector, or if the sector has been written to improperly and locked, there is no recovery. The only difference.. the ONLY difference between a magic Gen2 chip and a real chip is that sector 0 is not locked. It is subject to the same access bits and key permissions as any other sector.

So the reason you can’t write to any other sector may just be that you don’t have keys for those sectors. Or, maybe those sectors are permanently locked.. but I doubt that. Thankfully, magic chips are just as shit at rng and crypto1 as real chips, so all you may need to do is run an autopwn on your magic gen2 chip first to get keys, then use that key file to overwrite your other sectors using proper keys.

This is the one advantage gen1a child have, they keys and access bits work as expected but you can literally sidestep them by using the backdoor command to directly write data to each sector. Of course readers can use this backdoor command to detect gen1a chips and refuse to work with them … hence gen2 chips.

7 Likes