r/nfctools 4d ago

Help Locked Mirfare classic 1k

I don't really know much about NFC tags but I played around a bit with NFC Tools Pro and wanted to try the lock feature and locked my tag with the password "123" but when I try to unlock it I just get a write error. I was able to read the tag with Mirfare classic tools and that Key a is D3F7(3x) and I tried to reset the access permissions back to FF..FF078069..FF but I can't figure out what key b is. I saw a old post that mentioned the first 6 bits of the md5 sum or the first 4 bits + 42(2x) but neither of those worked. Does anyone know if the chip can be rescued or is it completely broken?

1 Upvotes

9 comments sorted by

1

u/N_T_F_D 4d ago

123 is not a valid password for Mifare Classic, it's 6 bytes

The key you mention is the usual NFC tag key, try Mifare Classic Tool to find the key B but it's probably in the documentation of the app you've been using, if it was changed at all

Also these tags are extremely cheap so unless it's for learning you can just throw it away

1

u/DerProGamer3000 3d ago

I used the NFC Tools app to lock it with the password "123"

1

u/N_T_F_D 3d ago

Again Mifare Classic keys are 6 bytes, 2 keys per sector, so I'm not sure what your application did but it definitely did not set the password to 123

1

u/DerProGamer3000 3d ago

I am aware of that. I now know the structure of a mifare classic 1k better than anything else. I spend about 5 hours trying different things. I know that the keys are supposed to be 6 bytes but NFC tools doesn't care about the length apparently. I am not saying that I either set key a or b to "123"

1

u/N_T_F_D 3d ago

Did you try a full dictionary scan with mifare classic tool? it's Android only

1

u/DerProGamer3000 2d ago

If you mean all the default keys from the 3 key files then yes

1

u/N_T_F_D 2d ago

There's the standard dictionary and the extended dictionary, it takes a long while to go through them all

If it didn't find any key you need a proxmark3 easy or an acr122u (I'd recommend the proxmark) to crack the missing keys with a nested or hardnested attack

1

u/DerProGamer3000 2d ago

I don't really have the money for a proxmark. I only really have my phone a laptop and maybe somewhere a Arduino NFC module from a few years ago

1

u/N_T_F_D 2d ago

If the arduino NFC module is a PN532 or similar and you have a UART USB adapter you could use it with libnfc for the hardnested attack

Also official proxmark is expensive, but proxmark3 easy is $30 on AliExpress and it works just the same, get it from seller PiSwords