Zigfrid – A Passive RFID Fuzzer
z4ziggy.wordpress.com
z4ziggy.wordpress.com
125 kHz 2 bits/cycle = 250 bits /sec
A 2^40 bit string has 1099511627776 combinations, and would require 1099511627776 40 = 43980465111040 bits to besent to try all of them. That would take 43980465111040/250 seconds or about 5575 years
And that's under ideal "spherical object in a vacuum" conditions.
So yeah your right, unless they get lucky.
125kHz = 125,000 cycles/sec * 2 bits/cycle = 250,000 bits/sec
250,000 bits/sec / 40 bits/code = 6250 codes/sec
2^40 = 1,099,511,627,776 possible codes / 6250 codes/sec ~= 175,921,860 sec ~= 5.578 years
While this is still an extremely long time for the worst case, by the looks of other comments, as well as the author's video, it appears extremely doubtful that most RFID readers have anywhere near 40 bits of security - and it takes about 10 seconds (65536/6250) for the fuzzer to brute force all codes 16 bits or less.
The small amount of IT security work I've done has taught me that such hopes are quickly and frequently dashed. Even products specifically designed for security applications have silly glaring vulnerabilities.
However most keycard systems in the real world use a dumb unencrypted card that broadcasts an ID. This is vulnerable to sniffing, cloning as well as bruteforce (as this project demonstrates).
Modern fare systems (Vancouver Compass for example) use the DESfire EV1 and it's as secure as it gets.
The issue in their case was that 1) they didn't set the configuration of the card properly, so the blocks they were using weren't actually configured to be decrement only, and 2) the validation machines checked whether a card had enough trips and then decremented the block without checking whether the decrement was successful. I was able to make the remaining fares block read-only while the card was full, essentially making an infinite card.
Using a curtain capacitors combo might initiate a DoS attack on the reader which will prevent legitimate tags from being read correctly after placing it against a reader only once. A hard reset to the reader will be required to resume work. Just FYI.
Seems like a cute way to create a diversionary scene or frustrate physical security personnel in physical pen testing.
40 bits of bruteforce at 125khz, with every code being 40 bits long, results in 3125 codes/sec at best, thus it will take roughly 11 years.
There is absolutely no reason why anything RFID controlled, like a door mechanism, should allow key entries at full speed (3k keys/sec someone posted).
I don't waste time with closed systems, so I can't comment directly on iOS capabilities, but I would guess, that it's going to be almost impossible to make it working in such locked down iOS world.
http://cydia.saurik.com/package/net.limneos.nfcwriter/
Description Supports iOS 10.0 to 10.2
NFCWriter for iOS!
$3.99
Use your iPhone's NFC Chip to its maximum!
As pre-seen in 9to5mac
Features:
-Read most common tag types
-Write tags
-Host Emulation Mode with limitations for now
-Manage and save your tags in one place.
-Perform actions based on your tag's contents.
-Read/Write NDEF messages
-Display information about your tags like Manufacturer, Tag Type, Serial Number, ATQA, SAK, Memory Size etc.
-Supported tag types are ISO 14443, Mifare , ISO 15693 , iCode SLIX, all of the NTAG series.
-Supported protocols are ISO 14443 and Mifare.
-Host Emulation Mode currently only allows you to set a custom Serial Number to your device and emulate a tag's serial number, no tag content emulation yet.
This new achievement enables you to use the NFC chip beyond iOS's limitations.
A professional must-have tool for IoT experts, NFC researchers, hobbyists and all of you that make good use of NFC technology.
Research for more Tag types and protocols is constant.
This is the first time that NFC chip on iPhone is used to this extent.
Check the screenshots and... Enjoy!
Limitations: - Supported devices are iPhone 6S, iPhone 6S Plus, iPhone SE, iPhone 7, iPhone 7 Plus. - iPhone 6 is under testing and not yet supported. - iOS 10 only for now, still working on iOS 9 compatibility.