RFID fob encrypted?

Most options are in both versions.

What do you suggest? I don’t mind sacrifice distance for size. Meaning I can put my skin up to a reader I don’t need the distance. I also don’t mind implanting something bigger

1 Like

:underage:I don’t have the luxury of having my friends and co workers being MD’s​:joy: - I’m getting a few for different applications. mine will be the small form factor due to my extra curricular activities. We are climbers and out door people when work isn’t calling. The range would be better in the large. I don’t have enough peers locally to compare them too once “installed”. I’ve done ~30 of the NeXT’s for people. None for myself yet. September will be ~3-4 in me.

There are really three formats…

The glass X series. These have the worst range and can be tricky to get the antenna alignment just right based on lots of comments on here.

The Flex chips come in two types, one that looks like the outline of a pill capsule, and a round one. The round one is usually a lot larger (25mm to 37mm diameter if I remember correctly) but also is much easier to get a good read on. The smaller flex can be installed by using a 4g needle to make a pocket and then inserting the chip, or both flex can be installed with a scalpel and a dermal lifter to create the pocket.

Personally I am thinking the larger the antenna the better, so I would definitely go with a flex chip, and in the round configuration of it is available. But that is just me. The easier to use the better in my opinion.

Equally the larger chips can’t be implanted quite as easily in the hand (you really don’t want any of them being moved or flexed too much once they are healed).

1 Like

I’m just speculating and have no clue if this would actually work, but could the diagnostic card be used as a kind of range extender for the pm3 antenna? I know other people have used it for similar purposes, but I have no clue if it would work in this scenario.

This type of extension seems to work great for power extension but data has a hard time making it through

1 Like

OK all my proxmark arrived. Im gonna go to the website to learn how to use it then sneak about my building and unscrew my front door and reveal the mystery!

1 Like

ummm I don’t know how to code and I use a mac. I think Ill take @Jirvin up on his offer…

3 Likes

Sounds like a plan!

If I knew you used Mac beforehand, my offer may have been different :sweat_smile:
I personally have only used the proxmark on Windows and Linux but I know a few people who use it on Mac with no issues. So the setup may take more time than anticipated but really only needs to be done once before some card research can start.

Here are the Mac setup notes for the proxmark RRG client. Give them a stab if you have time, I think they were rewrote fairly recently so they should be quite straightforward.

Feel free to DM me with your Discord username or some alternative and we can sort out a time that aligns with both of our schedules.

1 Like

Hey!
No clue how to DM you directly, as stated above, hopeless doctor here. I up on discord, same handle 4220. Excited to become bionic and tunr my apartment building and eventually medical canter into chaos!

1 Like

Also happy to help out, have sent a friend request on discord just now

1 Like

You should be able to search, find and message him I’m on Discord

@Jirvin#5704


I believe I have added you on Discord or some unfortunate person with a similar username as yourself has received a random add from me. Lets hope its the former.

Personal thanks to @DonFire for walking me through set up with the Proxmark and helping to determine what kind of readers my dumb apartment building use. Good news, they were all LF so I just bought a FLEX-EM. Question for the hive mind - I plan on installing it myself - any suggestions or caveats where to place it?I plan to video it as I will be doing it alone, on myself to prove how easy it is!

3 Likes

Just for clarification for anybody joining in late :arrow_down:

You want it somewhere that you can easily use /present it.
May I suggest THIIS as a suitable option (It’s where I would put one)

@NoUsersLefft has his there and pretty sure @franskav also

For further reading/ideas

and this

Awesome

Yeah, @Donfire is awesome

2 Likes

My only suggestion should you choose this location is to make sure it’s far enough up on the hand to where the skin in the area does not fold if you bend your wrist all the way back. It makes healing kinda annoying

1 Like

@abacus this is the location that the member whose pic I sent you had their flexEM installed in :slight_smile:

Can’t wait to hear how it goes, and do let me know if you need any more help!

1 Like

I use mine on my MAC and Android devices without issues. “brew update” “brew update pm3”

Did you check your hospital keycard? Is it also LF? if that’s the case, both work and home using LF, then you would need two (2) separate flexEM chips.

Did he do it?, Did it work?

Don’t you just hate reading stories that have no ending?

2 Likes

I work in the apartment industry and can speak to this. The fobs are dual tech as stated previously.
The common area readers are probably just standard HID readers (H10301 format). That can easily be cloned, as we are all aware.
The unit lock is the Schlage BE467 (or adjacent model). They use HF MIFARE. Most of the time, the property manager doesn’t enable (or doesn’t pay for) DESFire, so you can probably crack the HF side of the fob using a PM3 (specifically hf mf autopwn). If they enabled DESFire, then good luck because they’re AES encrypted :slight_smile:

Regarding the ButterflyMX, there’s nothing to really attack. The RFID reader on it just passes Wiegand through to the common area access control system (DoorKing or whatever they used), but in most cases, that doesn’t get hooked up since a dedicated reader is normally installed right next to the BMX anyways.

1 Like