Dump file is Partial complete

Hello,
I want to copy this key. (the *** I have add)

usb] pm3 → hf mf info

[=] — ISO14443-a Information -----------------------------
[+]  UID: 24 ** ** **
[+] ATQA: 00 04
[+]  SAK: 08 [1]

[=] — Keys Information
[+] loaded 2 user keys
[+] loaded 61 hardcoded keys
[+] Sector 0 key A… 484558414354
[+] Sector 1 key A… 484558414354
[+] Backdoor key… same as key A/B
[+] Block 0… 24********BD1001005 | G?.??..

[=] — Fingerprint
[+] NXP MF1ICS5006

[=] — Magic Tag Information
[=] <n/a>

[=] — PRNG Information
[+] Prng… weak

So I do the

[usb] pm3 → hf mf autopwn
And that was okay and get all the key A and B

[+] -----±----±-------------±–±-------------±—
[+] Sec | Blk | key A |res| key B |res
[+] -----±----±-------------±–±-------------±—
[+] 000 | 003 | 484558414354 | D | A22AE129C013 | N

[+] 001 | 007 | 484558414354 | D | 49FAE4E3849F | N

[+] 002 | 011 | 484558414354 | D | 38FCF33072E0 | N

[+] 003 | 015 | 484558414354 | D | 8AD5517B4B18 | N


But when try to get with the simulation I was not ok

[=] --[ FFFFFFFFFFFF ]-- has been inserted for unknown keys where res is 0

[=] Transferring keys to simulator memory ( ok )
[=] Dumping card content to emulator memory (Cmd Error: 04 can occur)
[#] Sector 0 - Auth error
[#] Sector 1 - Auth error
[#] Sector 2 - Auth error
[#] Sector 3 - Auth error
[#] Sector 4 - Auth error
[#] Sector 5 - Auth error
[#] Sector 6 - Auth error
[#] Sector 7 - Auth error
[#] Sector 8 - Auth error
[#] Sector 9 - Auth error
[#] Sector 10 - Auth error
[#] Sector 11 - Auth error
[#] Sector 12 - Auth error
[#] Sector 13 - Auth error
[#] Sector 14 - Auth error
[#] Sector 15 - Auth error
[-] ⛔ fast dump reported back failure w KEY A. Swapping to KEY B
[#] Sector 0 - Auth error
[#] Sector 1 - Auth error
[#] Sector 2 - Auth error
[#] Sector 3 - Auth error
[#] Sector 4 - Auth error
[#] Sector 5 - Auth error
[#] Sector 6 - Auth error
[#] Sector 7 - Auth error
[#] Sector 8 - Auth error
[#] Sector 9 - Auth error
[#] Sector 10 - Auth error
[#] Sector 11 - Auth error
[#] Sector 12 - Auth error
[#] Sector 13 - Auth error
[#] Sector 14 - Auth error
[#] Sector 15 - Auth error
[-] ⛔ fast dump reported back failure w KEY B
[-] ⛔ Dump file is PARTIAL complete
[=] downloading card content from emulator memory

why, and what can’t I do for not have this problem?
Thank for helps :slightly_smiling_face:

2 Likes

What command are you running exactly to emulate it?

1 Like

I just let the command run
hf mf autopwn

1 Like

Ah, I see now

You might try it with a dictionary then:

hf mf autopwn -f mfc_default_keys

1 Like

I get the same problem :disappointed_face:

[usb] pm3 → hf mf autopwn -f mfc_default_keys

[!] ⚠️  Known key failed. Can’t authenticate to block   0 key type A
[!] ⚠️  No known key was supplied, key recovery might fail
[+] loaded 5 user keys
[+] loaded 61 hardcoded keys
[+] Loaded 2471 keys from dictionary file /opt/homebrew/Cellar/proxmark3/4.20728/bin/../share/proxmark3/dictionaries/mfc_default_keys.dic
[=] Running strategy 1
[=] …
[=] .
[+] Target sector   0 key type A – found valid key [ 484558414354 ] (used for nested / hardnested attack)
[+] Target sector   0 key type B – found valid key [ A22AE129C013 ]
[+] Target sector   1 key type A – found valid key [ 484558414354 ]
*********** (all the key or find)
[+] Target sector  15 key type B – found valid key [ 484558414354 ]

[+] -----±----±-------------±–±-------------±—
[+]  Sec | Blk | key A        |res| key B        |res
[+] -----±----±-------------±–±-------------±—
[+]  000 | 003 | 484558414354 | D | A22AE129C013 | D
*********** (all the key or find)
[+]  015 | 063 | 484558414354 | D | 484558414354 | D
[+] -----±----±-------------±–±-------------±—
[=] ( D:Dictionary / S:darkSide / U:User / R:Reused / N:Nested / H:Hardnested / C:statiCnested / A:keyA  )

[+] Generating binary key file
[+] Found keys have been dumped to /Users/hf-mf-****-key-011.bin
[=] --[ FFFFFFFFFFFF ]-- has been inserted for unknown keys where res is 0
[=] Transferring keys to simulator memory ( ok )
[=] Dumping card content to emulator memory (Cmd Error: 04 can occur)
[#] Sector  0 - Auth error
[#] Sector  1 - Auth error
[#] Sector  2 - Auth error
[#] Sector  3 - Auth error
[#] Sector  4 - Auth error
[#] Sector  5 - Auth error
[#] Sector  6 - Auth error
[#] Sector  7 - Auth error
[#] Sector  8 - Auth error
[#] Sector  9 - Auth error
[#] Sector 10 - Auth error
[#] Sector 11 - Auth error
[#] Sector 12 - Auth error
[#] Sector 13 - Auth error
[#] Sector 14 - Auth error
[#] Sector 15 - Auth error
[-] ⛔ fast dump reported back failure w KEY A. Swapping to KEY B
[#] Sector  0 - Auth error
[#] Sector  1 - Auth error
[#] Sector  2 - Auth error
[#] Sector  3 - Auth error
[#] Sector  4 - Auth error
[#] Sector  5 - Auth error
[#] Sector  6 - Auth error
[#] Sector  7 - Auth error
[#] Sector  8 - Auth error
[#] Sector  9 - Auth error
[#] Sector 10 - Auth error
[#] Sector 11 - Auth error
[#] Sector 12 - Auth error
[#] Sector 13 - Auth error
[#] Sector 14 - Auth error
[#] Sector 15 - Auth error
[-] ⛔ fast dump reported back failure w KEY B
[-] ⛔ Dump file is PARTIAL complete
[=] downloading card content from emulator memory
[+] Saved 1024 bytes to binary file /Users/hf-mf-****-dump-014.bin
[+] Saved to json file /Users/hf-mf-****-dump-014.json
[=] Autopwn execution time: 16 seconds

I have the key but not all data that I understand

2 Likes

when you first start the pm3 client, there is some information that is spit out. can you screenshot or post that information?

2 Likes
[+] Using UART port /dev/tty.usbmodem13101
[+] Communicating with PM3 over USB-CDC


  8888888b.  888b     d888  .d8888b.   
  888   Y88b 8888b   d8888 d88P  Y88b  
  888    888 88888b.d88888      .d88P  
  888   d88P 888Y88888P888     8888"  
  8888888P"  888 Y888P 888      "Y8b.  
  888        888  Y8P  888 888    888  
  888        888   "   888 Y88b  d88P 
  888        888       888  "Y8888P"
    -----------------------------------
Release v4.20728 - Phrack
  [ I await your instructions! ☕ ]

  [ Proxmark3 ]

    MCU....... AT91SAM7S512 Rev A
    Memory.... 512 KB ( 70% used )
    Target.... device / fw mismatch

    Client.... Iceman/master/v4.20728 2025-09-11 20:31:08

I have to do some tests to copy some tags and I discovered that each time that I pass my tag on the door, the numbers change… have you already see this kind of tag ?
So I’m able to copy the tag on another but then the one that has been copy are no more working but the one who have received a copy is working.
Is it possible that the door read the tag and rewrite it with some different number?

1 Like

I need the lines that follow this as well.. all the way do the pm3$ prompt

yes this is most likely. this is a feature of certain yale locks and others.

1 Like

after that I have nothing :disappointed_face:

Can I type a command to have more information?
—–

So if this feature has been added, I will not be able to find a way to copy or added into their database I think?

2 Likes

Ehh.. so that’s not supposed to happen. I think your firmware is not synced with your client version. Try running pm3-flash-all instead of the pm3 client. Let it finish, then run pm3 and see if more info appears.

2 Likes

okay perfect I have update :smiley:


[+] Using UART port /dev/tty.usbmodem13101
[+] Communicating with PM3 over USB-CDC

8888888b.  888b     d888  .d8888b.
888   Y88b 8888b   d8888 d88P  Y88b
888    888 88888b.d88888      .d88P
888   d88P 888Y88888P888     8888"
8888888P"  888 Y888P 888      "Y8b.
888        888  Y8P  888 888    888
888        888   "   888 Y88b  d88P
888        888       888  “Y8888P”
-----------------------------------
Release v4.20728 - Phrack
[ too many secrets! ☕ ]

[ Proxmark3 ]

MCU....... AT91SAM7S512 Rev A
Memory.... 512 KB ( 77% used )
Target.... device / fw mismatch

Client....
 Iceman/master/v4.20728 2025-09-11 20:31:08
Bootrom... Iceman/master/v4.20728-suspect 2025-09-11 20:31:08 2689d7032
OS........ Iceman/master/v4.20728-suspect 2025-09-11 20:31:08 2689d7032
2 Likes

Ok now try your stuff again. The proxmark will act unpredictably if the firmware and client are not matched.

2 Likes

I think it’s still wrong somewhere

Are you using a PM3 Easy?

Did you edit Makefile.platform?

3 Likes

Yes it seems to work better thanks :slight_smile:
But for the other problem of having a tag that have “anti-copy” or having a rolling code by change the value each time I unlocked the door, have a solution ?? :thinking:

@Aoxhwjfoavdlhsvfpzha is correct.. you need to fix the mismatch first. Speculating on anything else is pointless at this stage. You are working with a broken tool. Fix that first then we can talk.

You have to change the device you are compiling the code for in the make file. After you change that, then you have to recompile and then reflash your proxmark hardware.

2 Likes

Okay perfect very nice tuto and now update :slight_smile:

[+] Using UART port /dev/tty.usbmodemiceman1
[+] Communicating with PM3 over USB-CDC

8888888b.  888b     d888  .d8888b.
888   Y88b 8888b   d8888 d88P  Y88b
888    888 88888b.d88888      .d88P
888   d88P 888Y88888P888     8888"
8888888P"  888 Y888P 888      "Y8b.
888        888  Y8P  888 888    888
888        888   "   888 Y88b  d88P
888        888       888  “Y8888P”

[ It’s not that simple! ☕ ]

[ Proxmark3 ]

MCU....... AT91SAM7S512 Rev A
Memory.... 512 KB ( 71% used )
Target.... PM3 GENERIC

Client.... Iceman/master/v4.20728-297-g7c8b361be 2026-01-12 12:18:52
Bootrom... Iceman/master/v4.20728-297-g7c8b361be-suspect 2026-01-12 12:18:38 7cdeebf82
OS........ Iceman/master/v4.20728-297-g7c8b361be-suspect 2026-01-12 12:18:41 7cdeebf82

[usb] pm3 → 
1 Like

Great!

Now you can try commands and be confident if there are problems it’s not because of the firmware mismatch.

2 Likes