xEM Cloning, Emulation Modes and the perils of Chinese cloners!

Hey there, sorry to open back up an old thread. I’m currently facing similar issues with an RFID ring I bought. I’ve been poking around at it for a few hours with the ultimate goal of cloning an HID tag onto it. However it seems that like many of these chips, I got one password protected. I have a Proxmark3 I’m using, and I’ve been able to identify the ring as the following:
[+] Valid EM410x ID found!
[+] Chipset detection: T55xx

To my knowledge. This would be a t5577 emulating a EM410x right?
If so, I should be able to rewrite it to HID I think.
I’ve tried all of the steps in @TomHarkness’s very thorough writeup, but had no luck so far. What has been perplexing me so far is that lf t55 detect comes up empty but lf t55 p1detect shows there’s a T55xx chip.
By no means am I an RFID expert but I believe that because of some password protection the ring has data on page1 that I can’t overwrite in favor of HID data (page0). I know this isn’t a Dangerous Things product but I couldn’t take the plunge quite yet, so I’m using this as a step in-between. Any help would be appreciated!

Hello. I have a 6 in 1 t5577 tag that came locked from the factory. I am using a proxmark3 rdv4. I tried to write it in test mode with both em4100 no password and blank t5577 but it didn’t work. I had however another single t5577 tag which i wrote to with a chinese cloner which unlocked fine. And the reason i got the 6 in 1 tag is that i have another 6 in 1 that i have written to with the chinese cloner but couldn’t unlock it. I don’t know what to do more, can someone please help me?

Are you talking about something like this.

(ever since I saw one, I have always wanted one available as an implant, man that would be awesome)
Anyway, as you have a proxmark, hopefully we can find you a solution.
Just recently somebody else was having possible Chinese password issues. So I will copy and paste those instructions that may help.

Was this the same cloner as the other one you had success with?

What was the cloner?
there are many on the market, so the solution maybe slightly different.
The 2 main ones we see here are the
Blue cloner
And the
“White cloner”

Even each of those can have differences depending on where they came from.

So if you could post a picture or link to the product, that will help us to help you.

Depending on which cloner you used and what you have tried so far I will post this here :arrow_down_small: and let you give that a try, and let us know how it goes.
(just note that the commands may have changed slightly, just step your way through and follow the prompts your PM3 gives you)

I have a white cloner, i think it is newer than 2015, buttons light up white, screen has mostly red and white. It can decode mifare cards with a windows software and it displays them with a weird nonsence number but the thing is that if you write down this number and then enter it manually on the cloner it can write not only the uid but also the block data to a magic tag. The id 125khz mode can read em4100 and t5577 emulating the em4100. It displays the correct 26 bit id of the em tag (the number written on the card) and you can enter it manually and write it. If however you want to clone the whole uid of a tag you have to read the original and then write. I have written with it to my old 6in1 which is like the one you linked. My new one is called XBCOPY and even this cloner refused to write to it. It has the same number in all the chips, which is probably a number that the makers write and then read to verify that the tag is working correctly. I wrote to the seller, he said that the tag has been tested with the blue cloner and some sort of usb cloner, but not with the proxmark3. (Maybe i should try with the password for the blue cloner?) I asked him what do they use to write the test number to the tag. If he tells me i will post it here. I don’t know the performance of my cloner with HID because such cards and tags are not used in my country.

That is potentially good news.
Does it say “Zonsin” on it?
If so the white cloner password should work for it.

Regarding,

Then I think

This would be a good option

1 Like

I tried both passwords with and without test mode. Nothing worked. I might just pull out some t5577 chips out of some tags and replace them.
As of the cloner - it does not say zonsin. When i turn it on it goes straight to the legal notice screen where you press ok and you go in HF mode.

The Zonsin has red and white, It was worth a try

And then from there you can go into LF mode to do your reading and writing on the T5577 chips?

Yes. You press the mode button. The mode is called ID-125khz. But my new 6 in 1 tag which i am trying to unlock doesn’t want to write with this cloner and currently it is just a useless piece of plastic. The other one i have not tried but i will.