GithubHelp home page GithubHelp logo

Comments (15)

iceman1001 avatar iceman1001 commented on May 15, 2024 2

Hm, this firmware as it is shouldn't allow for uid (block0) re-writing.
it should set uid when we upload a dump etc. Then it shouldn't allow at all for block0.

Aha, I see in the source code there is no limit for block0 writes. ok. Fair enough, I agree.

from chameleonmini-rebooted.

ceres-c avatar ceres-c commented on May 15, 2024 1

Now I get it and I agree

from chameleonmini-rebooted.

ceres-c avatar ceres-c commented on May 15, 2024

I am not sure I understand what I'm reading...

from chameleonmini-rebooted.

iceman1001 avatar iceman1001 commented on May 15, 2024

Enable / Disable FUID ? UID for slot..

I'm not sure either but that could be of the french way of expressing things. There seem to be a wish for FUID to be optional per slot. What I'm curious is what functionality FUID stands for? use once? magic? ...

from chameleonmini-rebooted.

kevin2008-01 avatar kevin2008-01 commented on May 15, 2024
Block 0 can only be written once.
Even greater protection from a  system with "anti-clone" feature
Use normal commands. eg. hf mf  wrbl 0 B FFFFFFFFFFFF a473f601200804006263646566676869
Answers to chinese magic backdoor commands: NO

from chameleonmini-rebooted.

kevin2008-01 avatar kevin2008-01 commented on May 15, 2024

the reader must understand that writing block 0 is impossible, he must just read the chameleon. I do not know which command the reader sends to do the test or detect a tag copy. apparently, new readers are not blocked only in France, but also in other countries. see you

from chameleonmini-rebooted.

quantum-x avatar quantum-x commented on May 15, 2024

French readers implemented a 'magic check' where they send 0x43 0x40 to weed out magic tags.
However, the Chameleon Mini also has timing issues - which means they are often rejected by french readers. I'm assuming he's bumping up against problem 2 more than problem 1 - as the Chameleon should not respond to 0x43 0x40

from chameleonmini-rebooted.

slurdge avatar slurdge commented on May 15, 2024

By "magic", you mean Chinese backdoor command ?

from chameleonmini-rebooted.

quantum-x avatar quantum-x commented on May 15, 2024

from chameleonmini-rebooted.

securechicken avatar securechicken commented on May 15, 2024

@iceman1001 to be closed I think.

from chameleonmini-rebooted.

iceman1001 avatar iceman1001 commented on May 15, 2024

@ShinHub double check in code that block0 doesn't allow for Write commands...

from chameleonmini-rebooted.

securechicken avatar securechicken commented on May 15, 2024

@iceman1001 you were right... I took quantum-x answer as clue of a previous patch.
I checked and found nothing in Mifare code to prevent Block0 write.
I am patching this.

from chameleonmini-rebooted.

iceman1001 avatar iceman1001 commented on May 15, 2024

keep in mind for your patch, that the support-chinese-magic command macro defines, at compilation time, should allow for updating block0 etc..

from chameleonmini-rebooted.

securechicken avatar securechicken commented on May 15, 2024

I swear won't hurt any chinese.

from chameleonmini-rebooted.

iceman1001 avatar iceman1001 commented on May 15, 2024

You do have a sense of humor. Excellent.

from chameleonmini-rebooted.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.