HID Iclass proxmark3

I finally got my pm3 rdv2 up and running Iceman repo (working on it a few min here and there when I had time.)

I have a multi-frequency card for my job for access control and clock in/out. I’ve cloned the LF chip to a t5577 card successfully (will be going to the lf of my NeXT), but would appreciate a little point in the right direction for the HF chip. I have the screenshot of the dump file. I’m trying to get it worked out while I patiently await my chance to get the new flexclass that’s going in the other hand :wink: @amal

Is it really as simple as:

hf ic wrbl --ki 0 -b 6 -d 03 03 03 03 00 03 E0 17

hf ic wrbl --ki 0 -b 7 -d D7 DE CF 2D 76 C9 FD 91

as much as I’ve read about iclass encryption etc etc…I just can’t see it being this easy.

thanks in advance guys! looking forward to joining the cyborg community!

I see you have done your research, I would have directed you to Amals thread, but I took like you have already found it.

To further your research, I would point you toward leumas95 thread

So, I’m gonna go out on a limb and say my card is
HID® iCLASS® Seos® + Prox Card 510x
or
HID® 520X iCLASS® Seos®/iCLASS®/Prox

seeing as the LF chip was a 5104 that I cloned to the T5577 and now have the Iclass to deal with. I guess my concern at this point is if writing those 2 blocks to the flexclass and be done? I may or may not have the master key saved in a txt file. Though, I’m still tip toe’n around some of the deeper cmds in the proxmark.

and again, I appreciate the help!

EDIT:

Iclass legacy it is!

Unfortunately, I don’t think cloning that to the HF side will work. NTAG 216 blocks are smaller than HID blocks.

@philidelphiaChickens Are you referring to the NeXT or the flexclass? I have the NeXT already (premature purchase on my part a while back, but I’ll find a use for the HF chip of it) I intended to clone the Iclass side of my work card to the flexclass, not the NeXT. Or, did I misunderstand the post about the flexclass?

Aha! Sorry. Misread. Yes, you should be able to clone legacy cards to flexclass.

That is a good premature accident :stuck_out_tongue_winking_eye:

2 Likes

Hey, no such things as too many implants!
At some point, I’ll just end up running out of space to put them all

@philidelphiaChickens @Pilgrimsmaster I’ve done a little looking around, and I mean a little as in only a few min, for a fob or card I could order a single of just to test the cloning before getting the flexclass. Haven’t found anything that seems to fit what I need. Any insight?

Unfortunately, I work in industrial maintenance so I get beat up and dinged up quite regularly. The traditional hand location is about the only place I feel safe putting the implants without things getting potentially sketchy.

https://redteamtools.com/iCLASS-RFID-card

@pac I’m getting site down for maintenance on that link. Have been since it was posted. Is it just me? I assume the site was up when you posted the link but I tried it not long after you posted. :man_shrugging:t2:

Me too

@DeviantOllam git yer store back online. We want to give you money :stuck_out_tongue_winking_eye:

2 Likes
1 Like

Not quite there yet

image

a few days of discount remaining

Hopefully their other products are better than the HID iClass card that I ordered 6 weeks ago and just arrived today…

It still works, but does not fit in my card folio very well

Although I didn’t order a wavy wonky 1/2 melty card, it does work and it is 100% still just a First World problem… I’m sure it happend I transit as I don’t imagine they would ever send out something like that

1 Like

Ironically, that’s the card that I need :grimacing: so we will see. And, it’s gonna be hard to use an October discount in November :upside_down_face: :crazy_face:

no worries, though. I’ll get there when I get there. I just can’t wait to see these guys faces at work when I get through the gate and clock in with “ThE dArK mArK” hahaha

1 Like

Good news everybody!

They are back.

2 Likes

:raised_hands: :raised_hands: will be ordering when I get home from work!!!

Okay guys, I had some time at work tonight to work on the project. I have the eview from the dump file
(hf ic dump)
showing all the block values. At this point am I able to wrbl each block value to the new card? Or, can I restore from dump file to the new card/chip?

Also, I know this sounds like a silly question, but what keys am I getting from the chk / managekeys here?

I’m away from my computer right now and can do a more in-depth write up later. TLDR is don’t restore the old card to the new one, manually clone over blocks 6 through 9.

1 Like