Уровень 0 · материалов: 6
В кластер входят документы, описывающие технические методы компрометации электронных систем доступа и бесконтактных карт, и не входят документы, не связанные с анализом аппаратных или программных механизмов аутентификации.
Общие признаки: реверс-инжиниринг, RFID и NFC карты, обход систем безопасности, клонирование ключей и карт, анализ протоколов передачи данных
Группа выше: Замки, СКУД и физическая безопасность
Смысл: The main idea is to demonstrate how to construct a low-cost alternative to professional RFID tools (like Proxmark3) to intercept and calculate encryption keys from Mifare-based intercom systems, specifically those by IronLogic, for the purpose of cloning key fobs.
A technical guide on building a custom STM32-based device to capture Mifare crypto-keys and clone IronLogic intercom fobs using an Android app.
Смысл: The text demonstrates how basic electronics and a brute-force programming approach can be used to crack simple, non-rolling code radio protocols used in older security barriers.
The author used an Arduino Uno and a 433 MHz transmitter to brute-force the 12-bit radio code of a Nice parking barrier.
Смысл: The main idea is to demonstrate that the MIFARE Classic 1K cards used in the Kyiv Metro are insecure and that their internal data, including travel history and balance, can be easily extracted and analyzed using readily available hardware and software.
A technical guide demonstrating how to extract and decode travel history and balance data from vulnerable MIFARE Classic 1K Kyiv Metro cards.
Смысл: The author demonstrates that it is possible to clone an EM-Marin RFID access card using only a photograph of the card's printed numbers. By analyzing the Proxmark3 source code and the Wiegand-26 protocol, the author proves that the printed numbers can be converted back into the card's digital ID, allowing for the creation of a working duplicate without ever having the original physical card.
The author demonstrates how to reverse-engineer an RFID card's ID from its printed numbers to create a working clone using a Proxmark3.
Смысл: The main idea is to document and reverse-engineer the working principle of an obscure, legacy induction-based key system used in Moscow intercoms, bridging the gap between historical hardware and modern electronic understanding.
A technical deep-dive into the induction-based ferrite keys of the Moscow-based 'Safe-Service' intercoms, explaining their hardware logic and patent-based operation.
Смысл: The text describes a security research project that successfully compromised the 'Troika' transport card system. By reverse engineering the official Android app, the author extracted access keys, analyzed the memory structure of the card, and developed a method to restore the card balance after use, effectively enabling free travel through a replay attack.
A researcher reverse engineered the 'My Pass' Android app to extract encryption keys and developed a replay attack to reset the balance of Moscow's Troika transport cards.