So I spoke with Amal on this first and he wanted me to make a post
I am not going to talk about what tool was used, nor am I going to reveal what the token is
( if I can figure it out, others smarter than me can, but please don’t make it plainly viewable to the rest of the internet here, keep it discreet in case there’s a way to fix)
The xACv2 appears to have a PREloaded em4100 tag in its memory that will trigger it…
I do not believe I added this tag to any of my boards, I have tried the standard remove tag action and it remains an active tag on the board
The UID is very low security, so if a xACv2 is in a secure system be aware
I can’t make the claim at this time that all boards are effected, I hope maybe I did something to them, but it doesn’t appear to be the case
I hope it can be patched or removed that tag from memory… but it’s above my skill level
If you are a seasoned member of the board, PM me if you want specific details… I’ll share with you to try and have a larger sample size and try and rule myself out and or see if you can help remedy it
I just attempted the “clear all cards command” Immediately after that, I was able use the uid in question to open it
I wasn’t able to get around to trying the basic fix last night
One other user has confirmed that uid opens his board aswell :-/
Im going to try to keep it vague enough for random non users who visit the board can just copy paste the UID, but if you know what’s going on it’s pretty simple to piece together
From chatting with @darthdomo, he was thinking it could be an issue where the empty users are considered real instead of empty
His thought was to try to fill all the user slots and see if it persists
This is where the 50/2000 user slots is going to matter a lot lol
The flipper has a tool I believe I can use to have it emulate a list of uids with a set time delay between them, I just need to sit down and make a .txt with the right info
The order should be something like
“Master add tag”
Random uid 1
“Master add tag”
“Master add tag”
Random uid 2
“Master add tag”
Etc
Alternatively, I don’t know if the board allows you to add more than one uid at a time…
If it works this might be even easier
“Master add tag”
Random uid 1
Random uid 2
Random uid 3
Random uid 4
“Master add tag”
Trying to decide if it’s more secure to have 50 purely random uids, or a uid that’s random and 50 variations of it…. Probably the former since it’s more work
So I managed to semi brick my xac for a few minutes,
But during that experience, the UID issue went away lol
So it’s the first sign that it’s semi possible
On the downside, I managed to program the flippper to ram 50 different uids into the xac, and it appears that 50 is NOT the limit
(Also found original packaging which also states 2000 users)
Confirmed works on my XACv2 as well. If I know what you’re talking about. I’ve used it a few businesses (that I’m already granted access to) and 3/14 we’re vulnerable to the attack.
Wait… what exactly do you mean here? Do you mean there are 14 deployed xAC v2 units but the attack only worked in three of them, or there are 3 xAC v2 controllers installed and 11 other types of access controllers which were not vulnerable to such an attack?
I’ve found a variation of the board on aliexpress,
Looks similar but slightly different, blue pcb instead of green… and a few of the chips look different
I’ll order one in a week to see if it has the same issue