–ki 2 worked for me at least for rdbl/dump. (which is the same Kd key from picopass that I was using, but thanks for that tip! I’ll keep it in mind!) I did manually clone block 1 to the test card to match my functioning work badge. I’ll try it again omw out in a few hours.
I admit that I’m not that well versed in the key area. The debit and credit keys on my work badge vs the blank are very different. And, I’m not that familiar with the diversified keys either. Looks like I need to do some more reading!
at this point, I’m wondering if I done something that I shouldn’t have without realizing it, and I think I’m going to get a couple more cards from redteamtools. Support the business AND have spares is a double win!
here is the dump from my working badge and below it the cloned card. The only differences I see are the epurse and debit key. I may be missing something?
I have a post over on the proxmark forum (yes I mentioned there that I also had one here and sent a link) and actually got a reply from iceman himself!
anyways, carl55, mentioned that the redteamtools cards were shipped as unitialized/unprogrammed and that was part of the trouble that I was having getting it to work as a clone. Said that modifying the block 1 config and block 3 debit key for the card to behave as a programmed credential in order for the reader to see it and use the master authentication key vs default keys that the pm3 was already familiar with. I wasn’t expecting that and I’m pretty sure I let the smoke out of the card, as now I can’t get a successful read. I think frustration got the best of me and I pulled the trigger before I had fully wrapped my head around what I was trying to do. I have a couple new cards otw, so I guess a fresh start is a good thing!
I’ll keep one tucked away for safe keeping and document in detail every command issued and the results so I can learn from that little uh oh!
Top photo is my flexClass (though admittedly I Foolishly cloned blocks that won’t work). Bottom is the source data. I left blocks 1 and 3 unchanged.
Changing block 1 might have been your undoing. Block one has the data configuration stored in it, which means that you probably locked yourself out of the card. I think the first bitpair is the lock for writing data to the card.
okay so I just remembered something that I’ve wanted to ask, but I’m never at a good place to ask it when I think of it. Figures…
I get the data written in hex, what I don’t get is where that corresponding decimal value comes from? is there a reference that I haven’t been able to find? I’m not sure if it makes as much sense in a question form as it does in my head?
I’ve done some digging elsewhere, and came up with a question that I can’t find an answer for.
The iClasss cards from redteamtools come non programmed and unpersonalized. I’ve come across mentions of the picopass personalization procedure. But I can’t find any documentation on it other than one or two mentions in various forum threads about needing it for the reader to recognize the card and to use the iclass master key instead of the picopass default key.
At the point I’m fairly confident that the flexclass is easily cloneable for what I need. But, not 100% so I’d like to be sure before the implant procedure.
@amal ? Any insight? I have 2 new cards that should be delivered today before I go to work tonight. Hopefully I’ll have some time to work on it tonight at work.
And new cards came in the mail last night. I’ll work on it to ought at work
writing the authentication key to block 3…so the card from redteam is using the picopass default rather than the hid master. While the card is still in personalization mode, from what I gather on the proxmark forum, it’s a “true” write of the key to block 3 instead of the xor version of the key that would be necessary while in application mode. But, then how exactly do I put the card in application mode?
For the record, I have the same question posted over on the pm3 forum, but response times there aren’t quite what they are here. So, yea
SUCCESS! So, carl55 over on the pm3 forum helped me get over the hump. Ended up writing a config file to set the card in application mode and the new xor’d diversified key to use the HID master key vs the HID default. Then writing blocks 6-9 and viola!
I’m waiting on a reply from carl55 for a more detailed explanation so I can bring it over here! Huge thanks to everyone that’s helped out over here!
Just got a confirmation on what I was waiting on to do the write up for iclass cloning for unprogrammed credential. I’ll work on it tonight at work. Probably send you @philidelphiaChickens a rough draft for review before adding to your thread.