Hi.
I have a T55x7 card that is password protected from a blue cloner. I have snifft the cloners write data and got password 51243648
Version info and hw tune
[=] Session log /home/teeny/.proxmark3/logs/log_20201224.txt
[+] loaded from JSON file /home/teeny/.proxmark3/preferences.json
[=] Using UART port /dev/ttyACM0
[=] Communicating with PM3 over USB-CDC
██████╗ ███╗ ███╗█████╗
██╔══██╗████╗ ████║╚═══██╗
██████╔╝██╔████╔██║ ████╔╝
██╔═══╝ ██║╚██╔╝██║ ╚══██╗
██║ ██║ ╚═╝ ██║█████╔╝ Iceman
╚═╝ ╚═╝ ╚═╝╚════╝ bleeding edge
GitHub - RfidResearchGroup/proxmark3: Iceman Fork - Proxmark3
[ Proxmark3 RFID instrument ]
[ CLIENT ]
client: RRG/Iceman/master/v4.9237-2649-g83eea0532 2020-12-23 01:50:53
compiled with GCC 9.3.0 OS:Linux ARCH:x86_64
[ PROXMARK3 ]
firmware… PM3RDV4
external flash… present
smartcard reader… present
FPC USART for BT add-on… absent
[ ARM ]
bootrom: RRG/Iceman/master/v4.9237-2649-g83eea0532 2020-12-23 01:51:16
os: RRG/Iceman/master/v4.9237-2649-g83eea0532 2020-12-23 01:51:28
compiled with GCC 9.2.1 20191025 (release) [ARM/arm-9-branch revision 277599]
[ FPGA ]
LF image built for 2s30vq100 on 2020-07-08 at 23: 8: 7
HF image built for 2s30vq100 on 2020-07-08 at 23: 8:19
HF FeliCa image built for 2s30vq100 on 2020-07-08 at 23: 8:30
[ Hardware ]
–= uC: AT91SAM7S512 Rev A
–= Embedded Processor: ARM7TDMI
–= Nonvolatile Program Memory Size: 512K bytes, Used: 309684 bytes (59%) Free: 214604 bytes (41%)
–= Second Nonvolatile Program Memory Size: None
–= Internal SRAM Size: 64K bytes
–= Architecture Identifier: AT91SAM7Sxx Series
–= Nonvolatile Program Memory Type: Embedded Flash Memory
[usb] pm3 → hw tune
[=] REMINDER: ‘hw tune’ doesn’t actively tune your antennas, it’s only informative
[=] Measuring antenna characteristics, please wait…
9
[=] ---------- LF Antenna ----------
[+] LF antenna: 37,59 V - 125,00 kHz
[+] LF antenna: 27,32 V - 134,83 kHz
[+] LF optimal: 37,59 V - 125,00 kHz
[+] Approx. Q factor (): 5,8 by frequency bandwidth measurement
[+] Approx. Q factor (): 6,6 by peak voltage measurement
[+] LF antenna is OK
[=] ---------- HF Antenna ----------
[+] HF antenna: 47,07 V - 13.56 MHz
[+] Approx. Q factor (*): 8,2 by peak voltage measurement
[+] HF antenna is OK
(*) Q factor must be measured without tag on the antenna
[+] Displaying LF tuning graph. Divisor 88 (blue) is 134,83 kHz, 95 (red) is 125,00 kHz.
[usb] pm3 →
Sniff data
+] Downlink mode | password | Data | blk | page | 0 | 1 | raw
[+] ----------------------±---------±---------±----±-----±----±----±------------------------------------------------------------
[+] Default pwd write | 51243648 | 51243648 | 7 | 0 | 18 | 43 | 1001010001001001000011011001001000001010001001001000011011001001000111
[+] -----------------------------------------------------------------------------------------------------------------------------------------------------
But when i try and detect the card i get.
Detect
[usb] pm3 → lf t55xx detect
[!] Could not detect modulation automatically. Try setting it manually with ‘lf t55xx config’
[usb] pm3 → lf t55xx detect p 51243648
[!] Could not detect modulation automatically. Try setting it manually with ‘lf t55xx config’
[usb] pm3 → lf t55xx p1detect p 51243648
[!] Could not detect modulation automatically. Try setting it manually with ‘lf t55xx config’
i have tested to write to block 0 with lf t55 write b 0 d 00088048 p 51243648 with and without test mode
but i cant remove the password bit but when i try and change the id with the blue cloner i can change it.
Blue Cloner
[usb] pm3 → lf sea
[=] NOTE: some demods output possible binary
[=] if it finds something that looks like a tag
[=] False Positives ARE possible
[=]
[=] Checking for known tags…
[=]
[+] EM 410x ID 3100F87DDE
[+] EM410x ( RF/64 )
[=] -------- Possible de-scramble patterns ---------
[+] Unique TAG ID : 8C001FBE7B
[=] HoneyWell IdentKey
[+] DEZ 8 : 16285150
[+] DEZ 10 : 0016285150
[+] DEZ 5.5 : 00248.32222
[+] DEZ 3.5A : 049.32222
[+] DEZ 3.5B : 000.32222
[+] DEZ 3.5C : 248.32222
[+] DEZ 14/IK2 : 00210469682654
[+] DEZ 15/IK3 : 000601297501819
[+] DEZ 20/ZK : 08120000011511140711
[=]
[+] Other : 32222_248_16285150
[+] Pattern Paxton : 839695326 [0x320CBBDE]
[+] Pattern 1 : 16045439 [0xF4D57F]
[+] Pattern Sebury : 32222 120 7896542 [0x7DDE 0x78 0x787DDE]
[=] ------------------------------------------------
[+] Valid EM410x ID found!
Couldn’t identify a chipset
[usb] pm3 → lf sea
[=] NOTE: some demods output possible binary
[=] if it finds something that looks like a tag
[=] False Positives ARE possible
[=]
[=] Checking for known tags…
[=]
[+] EM 410x ID 010C8BE4A9
[+] EM410x ( RF/64 )
[=] -------- Possible de-scramble patterns ---------
[+] Unique TAG ID : 8030D12795
[=] HoneyWell IdentKey
[+] DEZ 8 : 09168041
[+] DEZ 10 : 0210494633
[+] DEZ 5.5 : 03211.58537
[+] DEZ 3.5A : 001.58537
[+] DEZ 3.5B : 012.58537
[+] DEZ 3.5C : 139.58537
[+] DEZ 14/IK2 : 00004505461929
[+] DEZ 15/IK3 : 000550574827413
[+] DEZ 20/ZK : 08000300130102070905
[=]
[+] Other : 58537_139_09168041
[+] Pattern Paxton : 27271849 [0x1A022A9]
[+] Pattern 1 : 3063301 [0x2EBE05]
[+] Pattern Sebury : 58537 11 779433 [0xE4A9 0xB 0xBE4A9]
[=] ------------------------------------------------
[+] Valid EM410x ID found!
Couldn’t identify a chipset
i have played with lf t55 config to try and set it and get it to work but im a bit stuck and runing out of ides.