-
Notifications
You must be signed in to change notification settings - Fork 41
Description
I have trouble finding the keys for a hotel mfc1k card.
I used the Detect Reader method with little success so I tried the log method:
3095293 [D][MfClassic] e0858434 keyA block 3 nt/nr/ar: 0d0e3f7e c8e2ef8a a60f5948
3095303 [D][MfClassic] e0858434 keyA block 63 nt/nr/ar: 260abab3 563578ca f824b034
3095313 [D][MfClassic] e0858434 keyA block 63 nt/nr/ar: 0d42df2a 2eb08d20 56dacb58
3095324 [D][MfClassic] e0858434 keyA block 59 nt/nr/ar: 5a8045d6 7c3a9d4d 03c2ff31
3095334 [D][MfClassic] e0858434 keyA block 59 nt/nr/ar: 13ad9d34 4b6c8267 2c088dfe
3095345 [D][MfClassic] e0858434 keyA block 55 nt/nr/ar: 18af45f6 ff3e86bb df5d20f0
3095355 [D][MfClassic] e0858434 keyA block 55 nt/nr/ar: a0be2901 b52e43de 7b9d5038
3095365 [D][MfClassic] e0858434 keyA block 51 nt/nr/ar: f5f62110 1e353ff4 33f369c5
3095376 [D][MfClassic] e0858434 keyA block 51 nt/nr/ar: ec21a54e e97256d4 dc7f471e
3095387 [D][MfClassic] e0858434 keyA block 47 nt/nr/ar: e1fe7223 35aa0d4f ca7fa36e
3095397 [D][MfClassic] e0858434 keyA block 47 nt/nr/ar: b953bded 4a50ef23 607dd9f1
3095407 [D][MfClassic] e0858434 keyA block 43 nt/nr/ar: 1071fe7a c2fca009 7bbc271f
3095418 [D][MfClassic] e0858434 keyA block 43 nt/nr/ar: 00a00033 ae2e9609 80bf9122
3095428 [D][MfClassic] e0858434 keyA block 39 nt/nr/ar: c3e525a5 05a8e9d2 0d70e2bf
3095439 [D][MfClassic] e0858434 keyA block 39 nt/nr/ar: a201f393 8bd841d5 e20bf51b
3095449 [D][MfClassic] e0858434 keyA block 35 nt/nr/ar: c7aed8ff 29c6cdc9 d2c2c8fe
3095459 [D][MfClassic] e0858434 keyA block 35 nt/nr/ar: 447c3f1d 5ec88ccd 14bec958
3095470 [D][MfClassic] e0858434 keyA block 31 nt/nr/ar: 9319099e 0fccdcfa f20b61e4
3095481 [D][MfClassic] e0858434 keyA block 31 nt/nr/ar: 0678c7d8 e496ca10 a4ec3cb0
3095491 [D][MfClassic] e0858434 keyA block 27 nt/nr/ar: 59546693 c89683d5 a38fa69e
3095501 [D][MfClassic] e0858434 keyA block 27 nt/nr/ar: 5cbc22fb e0571666 a48bc973
3095512 [D][MfClassic] e0858434 keyA block 23 nt/nr/ar: 82f72e49 f08cff59 19d221b5
3095522 [D][MfClassic] e0858434 keyA block 23 nt/nr/ar: 76bc065b e7c9fbec 232c227d
3095533 [D][MfClassic] e0858434 keyA block 19 nt/nr/ar: dea19c52 90d0f535 b06ecb2c
3095543 [D][MfClassic] e0858434 keyA block 19 nt/nr/ar: 2d6bdac5 f1f25764 2de619d1
3095554 [D][MfClassic] e0858434 keyA block 15 nt/nr/ar: 0c7c6ef5 4a4ec52a 4a73fa4f
3095565 [D][MfClassic] e0858434 keyA block 15 nt/nr/ar: 6e7a6b3a f0f10eae 1f3ae8f3
3095576 [D][MfClassic] e0858434 keyA block 11 nt/nr/ar: c78fb093 c89256c7 b05baa36
3095586 [D][MfClassic] e0858434 keyA block 11 nt/nr/ar: f8b81e9e 2feb5c35 d0c58b7a
3095596 [D][MfClassic] e0858434 keyA block 7 nt/nr/ar: b7d1613b 6b48ca94 a3fe4bc3
3095607 [D][MfClassic] e0858434 keyA block 7 nt/nr/ar: 9f0ff73f 29c7d025 7bef2735
Side note, I tried multiple times, block 3 only every reported one line.
Converted the output to mfkey32 cmds:
./mfkey32v2 e0858434 260abab3 563578ca f824b034 0d42df2a 2eb08d20 56dacb58
./mfkey32v2 e0858434 5a8045d6 7c3a9d4d 03c2ff31 13ad9d34 4b6c8267 2c088dfe
./mfkey32v2 e0858434 18af45f6 ff3e86bb df5d20f0 a0be2901 b52e43de 7b9d5038
./mfkey32v2 e0858434 f5f62110 1e353ff4 33f369c5 ec21a54e e97256d4 dc7f471e
./mfkey32v2 e0858434 e1fe7223 35aa0d4f ca7fa36e b953bded 4a50ef23 607dd9f1
./mfkey32v2 e0858434 1071fe7a c2fca009 7bbc271f 00a00033 ae2e9609 80bf9122
./mfkey32v2 e0858434 c3e525a5 05a8e9d2 0d70e2bf a201f393 8bd841d5 e20bf51b
./mfkey32v2 e0858434 c7aed8ff 29c6cdc9 d2c2c8fe 447c3f1d 5ec88ccd 14bec958
./mfkey32v2 e0858434 9319099e 0fccdcfa f20b61e4 0678c7d8 e496ca10 a4ec3cb0
./mfkey32v2 e0858434 59546693 c89683d5 a38fa69e 5cbc22fb e0571666 a48bc973
./mfkey32v2 e0858434 82f72e49 f08cff59 19d221b5 76bc065b e7c9fbec 232c227d
./mfkey32v2 e0858434 dea19c52 90d0f535 b06ecb2c 2d6bdac5 f1f25764 2de619d1
./mfkey32v2 e0858434 0c7c6ef5 4a4ec52a 4a73fa4f 6e7a6b3a f0f10eae 1f3ae8f3
./mfkey32v2 e0858434 c78fb093 c89256c7 b05baa36 f8b81e9e 2feb5c35 d0c58b7a
./mfkey32v2 e0858434 b7d1613b 6b48ca94 a3fe4bc3 9f0ff73f 29c7d025 7bef2735
But. none the cmds produce a key:
./mfkey32v2 e0858434 b7d1613b 6b48ca94 a3fe4bc3 9f0ff73f 29c7d025 7bef2735
MfKey32v2 open source Mifare Classic key-recovery tool
Cracks keys by two 32bit keystream authenticationsRecovering key for:
uid: e0858434
nt_0: b7d1613b
{nr_0}: 6b48ca94
{ar_0}: a3fe4bc3
nt_1: 9f0ff73f
{nr_1}: 29c7d025
{ar_1}: 7bef2735
LFSR successors of the tag challenge:
nt': 327e8945
nt'': 76ae5665
Keystream used to generate {ar} and {at}:
ks2: 9180c286
Am I doing something wrong?