Hack: store 2 to 3 different EM41xx on a single T5577

I really should stress one thing: like I explained in my original post, my goal was to turn my one-shot long-range Chinese-made readers into repeating readers. Reprogramming my foot implant with 2 UIDs did exactly that for $0. So as far as I’m concerned, job done.

Now I can go ahead with my butt implant project, and order a couple more of them readers to stick in my chair and in my sofa (which, incidentally, I scored the last two RS232 versions of available anywhere in Europe this afternoon. Yeah!)

I only tested with other readers for the sake of completeness before posting the hack. It works - at least with my readers - but it wasn’t my original purpose, so YMMV.

Oh yeah I didn’t want to downplay your work, 2 IDs in one xEM, crazy shit, 3 with luck, even better!

I’m just interested in this because they all imolement the same protocol but are SO different.

Cant wait for the butt implant thread xD

2 Likes

When you push the envelope of anything, even when you stay entirely within the specs, interesting things invariably happen. That’s the fun of hacking :slight_smile: it reveals the assumptions whoever coded the other end applied to their technical implementations.

2 Likes

Fun fact: dual-EMs crash the white cloner so hard you gotta take the batteries out to get it to reboot :slight_smile:

Pity it didn’t kill the hateful thing outright…

1 Like

Have you tried your blue cloner with dual+ UID’s yet?

Yeah it reads - whatever it reads - and doesn’t crash apparently. I don’t know what it would clone though, and I’m not about to find out, as I have no intention of spending time repairing a perfectly okay T5577 card for the sake of finding out what a cloner I never use does when I never clone a tag.

But… For Science!?

2 Likes

Yeah… no.

1 Like

Alright I tried it: it clones the first EM. Boring…

This is a 3-beep (HID-capable) blue cloner. Dunno if the 2-beep one works the same. Probably.

2 Likes

Turns out 7 hours will do a lot for the pursuit of science! Thank you for your service good sir, awesome discoveries here for sure.

3 Likes

Some science: if you’re have a dual EM, you have a Proxmark3 and you’re knowledgeable enough to hand-program a T5577 with it. So why on God’s green Earth would you use a blue cloner to copy it? :slight_smile:

2 Likes

2 Likes

Science doesn’t have to have an application! We do lots of things we don’t really need to do just to see what happens on this forum!

btw this works on flipper zero xtreme firmware now

4 Likes

Emulating or writing or both?

1 Like

looks like just write

2 Likes

Yeah, sure enough! It’s an app in the RFID folder. It allows you to write up to three keys from your list of saved tags. My mind’s been blown learning about this multi-tag process and it’s nice to see that there’s another way to pull it off. Edit: I guess with the new keyring multi-tags that have hit the store recently, you could use this method to have a truly ludicrous number of LF tags handy. (Just good luck keeping track of which tag is written where!)

6 Likes

I wonder if this make sniffing tags nefariously harder

edit not seeing that in the App Library… different firmware?

1 Like

Are you using stock firmware?

It’s on Momentum at least.

I don’t know what they’re using, but the colored backlight means probably not stock

1 Like

from memory, @Eriequiet is an Unleashed dude.
He could have changed of course.

I think xTreme and Momentum have the Multiwriter

1 Like