The DESFire simulation now plays the EV1 protocol rather than just the activation and a handful of unauthenticated queries. A reader authenticates, enumerates, reads and writes files, and commits or aborts transactions against the card image `hf mfdes eload` put in emulator memory. Authentication covers 0x0A, 0x1A and 0xAA with DES, 2TDEA, 3K3DES and AES keys taken from the image. A key the image only holds a version for still refuses to authenticate rather than authenticating with zeros. Secure messaging follows the file's communication mode, with the rule that the mode only applies when a key right matching the authenticated key granted the operation -- access granted by the free-access right runs plain whatever the file settings say. Responses are MACed or enciphered accordingly, and the session CMAC is taken over every command and response in order so the two sides' IVs stay together even where neither puts a MAC on the wire. Reads cover ReadData, ReadRecords, GetValue and GetCardUID. Writes cover WriteData, WriteRecord, UpdateRecord, Credit, Debit and LimitedCredit, plus CommitTransaction, AbortTransaction and ClearRecordFile. Backup data, value and record files write into their shadow region and only move across on commit, so an abort really does discard. Three fixes were needed to interoperate with the client, and all three share a shape worth naming: the authentication handshake still succeeded, because it runs on the original key, and only the traffic afterwards was wrong. 1. A DES or 2TDEA key is stored as 16 bytes and the key itself decides which cipher the PICC uses -- if the second half equals the first it is a single DES key, and that governs session key generation too (M134034 8.1). The all-zero default key is the common case. Deriving a 2K3DES session key from it left the card MACing under a key the reader did not have. Confirmed by decrypting a captured GetCardUID response offline: under the session key the reader derives it yields the UID and a valid CRC32, under the other it does not. 2. Session keys are built here rather than through Desfire_session_key_new(), whose 3K3DES branch clears the low bit of the first eight bytes. Those bits are key version, which a session key does not have, and the reader keeps them. 3. The reader's 0xAF continuation is not a command, it continues one. Giving it its own CMAC restarted the running calculation halfway through a chained answer, so every chained response longer than one frame carried a wrong MAC while single-frame answers verified fine. The sample card in traces/mifare is rekeyed from all zeros to the sequence 01 02 .. 10, extended to .. 18 for 3TDEA. An all-zero key has matching halves, so it exercises only the degenerate path of fix 1 above and hides the bug; distinct halves surface a wrong derivation on the first MACed frame. tools/desfire_sim_test.sh loads an image, simulates it, drives the second Proxmark3 at it and reports. It stops the simulation the way the client does, a newline on its stdin, through a fifo held open for the run rather than a fixed timer -- a run that outlives its timer leaves the device simulating. A command counts as passing only if it prints something that says it worked: card errors, client side argument rejections and MAC or CRC complaints all fail, because several of those print a plausible result line as well and matching on the result alone reports passes that never happened. Tested on two RDV4s, one simulating and one reading: activation, info, application and file enumeration, all three key types, enciphered GetCardUID, plain and MACed reads up to 256 bytes over chained frames, and writes verified by reading the image back out with `hf mfdes esave`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Iceman Fork - Proxmark
The Proxmark is the swiss-army tool of RFID, allowing for interactions with the vast majority of RFID tags on a global scale. Originally built by Jonathan Westhues, the device is now the goto tool for RFID Analysis for the enthusiast.
Iceman repository is considered to be the pinnacle of features and functionality, enabling a huge range of extremely useful and convenient commands and Python/LUA scripts to automate chip identification, penetration testing, and programming.
| Latest Release | Coverity | Contributors |
|---|---|---|
| Actions OSX CI | Actions Ubuntu CI | Actions Windows CI |
|---|---|---|
Table of Contents
- Iceman Fork - Proxmark
- Table of Contents
- PROXMARK3 INSTALLATION AND OVERVIEW
- How to build?
- What has changed?
- Development
PROXMARK3 INSTALLATION AND OVERVIEW
Notes / helpful documents
How to build?
Proxmark5
The last hardware generation is called Proxmark5. It has
- MCU: AT32F435, a 288 MHz Artery Cortex-M4
- Gowin FPGA
- TypeC Extended Port (CEP)
- BLE / Wifi / Battery Addon, via a ESp32c2
- Swappable antennas (LF, HF, UHF)
- 125, 134, 250, 375, 500 KHz Low Frequency Antenna (LF)
- 13.56 MHz High Frequency Antenna (HF)
- as a addon: 860-960 MHz Ultra High Frequency Antenna (UHF), ** not developed yet **
At the moment, Proxmark5-specific instructions are all grouped in a single Getting Started guide. Read it to build, flash and run your Proxmark5 device. See the instruction links in the tables above to get the compilation environment.
- ⚠ The firmware is not stable at the moment and is actively being developed at.
- ⚠ Don't install the BWM addon board for now.
Proxmark3 RDV4
See the instruction links in the tables above to build, flash and run for your Proxmark3 RDV4 device.
Generic Proxmark3 platforms
In order to build this repo for generic Proxmark3 platforms we urge you to read Advanced compilation parameters
We define generic Proxmark3 platforms as following devices.
Supported
- RDV1, RDV2, RDV3 easy
- Ryscorp green PCB version
- Radiowar black PCB version
- numerous Chinese adapted versions of the RDV3 easy (kkmoon, PiSwords etc)
- Proxmark3 SE (Special Edition) (BLE enabled)
- Proxmark3 X
- Note: Community tested
- Note: unknown device hw
- iCopy-X
- Note: Compatible ONLY after installation of iCopy-X Open Source firmware
- Factory firmware is not compatible (Client Commands are different / Factory UI closed source / Factory Firmware enforces tag DRM)
Not supported
- ⚠ Proxmark Evolution (EVO)
- Note: unknown pin assignments.
- ⚠ Ryscorp Proxmark3 Pro
- Note: device has different fpga and unknown pin assignments.
- Note: Company have disappeared, leaving their customers in the dark.
Experimental support
- ⚠ Proxmark3 Ultimate
- Note: unknown device hw
- Note: FPGA images is building for it. Use on your own risk.
Unknown support status
- ⚠ VX
- Note: unknown device hw
When it comes to these new unknown models we are depending on the community to report in if this repo works and what they did to make it work.
256KB flash memory size of generic Proxmark3 platforms
⚠ Note: You need to keep a eye on how large your ARM chip built-in flash memory is. With 512KB you are fine but if its 256KB you need to compile this repo with even less functionality. When running the
./pm3-flash-allyou can see which size your device have if you have the bootloader from this repo installed. Otherwise you will find the size reported in the start message when running the Proxmark3 client./pm3.
What has changed?
See the Changelog file which we try to keep updated.
Development
⚠ Note: This is a bleeding edge repository. The maintainers actively is working out of this repository and will be periodically re-structuring the code to make it easier to comprehend, navigate, build, test, and contribute to, so DO expect significant changes to code layout on a regular basis.
👉 Remember! If you intend to contribute to the code, please read the coding style notes first. We usually merge your contributions fast since we do like the idea of getting a functionality in the Proxmark3 and weed out the bugs afterwards.
The public roadmap is an excellent start to read if you are interesting in contributing.
Supported operating systems
This repo compiles nicely on
- WSL1 on Windows 10
- WSL2 on Windows 10/11
- Proxspace environment release v3.xx
- Windows/MinGW environment
- Ubuntu, ParrotOS, Gentoo, Pentoo, Kali, NetHunter, Arch Linux, Fedora, Debian, Raspbian
- Android / Termux
- macOS / Homebrew (or MacPorts, experimental) / Apple Silicon M1
- iOS (Jailbroken, rootful)
- Docker container
Precompiled binaries
See Proxmark3 precompiled builds
Proxmark3 GUI
Most community driven GUI for Proxmark tends to be quite old and out-of-date. Here is a list of a few:
- Proxmark3 Universal GUI will work more or less.
- Proxmark3 GUI cross-compiled which is recently updated and claims to support latest source of this repo.
- Proxmark3_GUI simple gui in vb.net
Official channels
Where do you find the community?
Maintainers
To all distro, package maintainers, we tried to make your life easier.
make install is now available and if you want to know more.
This document will be helpful for you
Citation
Use this bibtex to cite this repository globally:
@misc{proxmark3,
author = {C. {Herrmann} and P. {Teuwen} and O. {Moiseenko} and M. {Walker} and others},
title = {{Proxmark3 -- Iceman repo}},
howpublished = {\url{https://github.com/RfidResearchGroup/proxmark3}},
keywords = {rfid nfc iceman proxmark3 125khz 134khz 13.56mhz},
}
If you need to refer to a specific state of the repository, use a commit number or a date of access, e.g.:
note = {Accessed: commit 12327f71a27da23831901847886aaf20e8ad3ca0}
note = {Accessed: 2021-01-01}
Copyright and licensing terms
Each contribution is under the copyright of its author. See AUTHORS.
The Proxmark3 source code is covered by the following licensing terms, usually referred as GPLv3 or later.
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
A copy of the GPLv3 is available in LICENSE.
Some dependencies may be under other free licensing terms compatible with the Proxmark3 licensing terms, see their respective description.