Research, development and trades concerning the powerful Proxmark3 device.
Remember; sharing is caring. Bring something back to the community.
"Learn the tools of the trade the hard way." +Fravia
You are not logged in.
Pages: 1
Hi Everyone,
we have to investigate our university system, which used the Legic Prime chip and is now changing to legic advant. So for our seminar we have to attack the old system which we succeed by writing valid values to the card. The next step would be to emulate "own" cards with the proxmark3 and it would be nice to sniff to the traces.
So first: Emulating: Proxmark has already a function: "hf legic sim" [phase drift [frame drift [req/resp drift]]] Start tag simulator (use after load or read)
Which we used after reading a valid card but it didn't worked. Maybe someone can help us with that.
Second: Sniff traffic: We'd like to sniff the traffic between card and reader. But proxmark has no function to sniff legic traffic. We can only sniff 14a traffic without annotations but that didn't worked neither. I hope someone can help us with that, cause deadline is september
Best regards Dominik
Offline
Sadly enough, I don't have access to a legic/legic advant. If I have that, I might be able to help out.
If you feel the love, https://www.patreon.com/iceman1001
modhex(hkhehghthbhudcfcdchkigiehgduiehg)
Offline
That is sad
But maybe you have already done something with the proxmark and a legic card in the past?
If you cant help us specificly maybe some hints or tricks?
Offline
Sorry, I havn't. Good luck with your thesis.
If you feel the love, https://www.patreon.com/iceman1001
modhex(hkhehghthbhudcfcdchkigiehgduiehg)
Offline
i had some success with legic prime reader. but simulating the card didnt succed. maybe bad timing... if you have 2 dumps from the original card while you change the writable segment values you can alter the bytes or hex values on the card with the write command successful. but simulating is still an issue.
this goes well for prime cards, the advant card i tested wasnt even recognised. not even with my selfbuild antennas.
if anyone wants to help please update the code to dump the card into a hexfile and not as ascii when using decode, which could then be analysed by normal hexdump toolset.
btw i have a valid prime dump but been aware of publishing it. pm me if you need it.
Offline
I can ( at least) provide some decoded tag-data ('hf legic decode' output) or samples
if that helps anyone
modhex(hkheiehvhtfchihtijduhfhg)
Offline
^^ legic prime - not legic advant
modhex(hkheiehvhtfchihtijduhfhg)
Offline
Sure, that data is always good to have.
The legic sourcecode has some issues with overflows, so remake and testing would be nice.
If you feel the love, https://www.patreon.com/iceman1001
modhex(hkhehghthbhudcfcdchkigiehgduiehg)
Offline
unfortunately I can not finf the possibility to PM you
modhex(hkheiehvhtfchihtijduhfhg)
Offline
you find my email all over this forum.
If you feel the love, https://www.patreon.com/iceman1001
modhex(hkhehghthbhudcfcdchkigiehgduiehg)
Offline
ok, I have used you github-email
modhex(hkheiehvhtfchihtijduhfhg)
Offline
Pages: 1