TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zigfrid – A Passive RFID Fuzzer

128 pointsby wolframioalmost 8 years ago

5 comments

IshKebabalmost 8 years ago
Somehow this post skips an explanation of what it actually does. It's a passive RFID tag that sends 40 bits of data (5 bytes). The bits are changed in sequence. More of a brute force attack than a fuzzer.
评论 #14828334 未加载
评论 #14828350 未加载
评论 #14828882 未加载
contingenciesalmost 8 years ago
I found the following interesting.<p><i>Using a curtain capacitors combo might initiate a DoS attack on the reader which will prevent legitimate tags from being read correctly after placing it against a reader only once. A hard reset to the reader will be required to resume work. Just FYI.</i><p>Seems like a cute way to create a diversionary scene or frustrate physical security personnel in physical pen testing.
keymealmost 8 years ago
Why bruteforce when you can just passively listen for a working code (once someone else uses their card)?<p>40 bits of bruteforce at 125khz, with every code being 40 bits long, results in 3125 codes&#x2F;sec at best, thus it will take roughly 11 years.
评论 #14829004 未加载
评论 #14828972 未加载
ivanbakelalmost 8 years ago
Wonder if there&#x27;s some sort of low-power hardware-easy problem you could use to reduce the request rate for individuals, instead of just shutting the device down when it detects a brute-force attempt. Seems to me that having hardware that breaks inconspicuously means you can&#x27;t leave it as unmanned as you&#x27;d want to.
评论 #14829077 未加载
Goopplesoftalmost 8 years ago
This made me wonder if iOS 11&#x27;s CoreNFC API can be used in similar ways. It would be cool to consolidate my tags (building and office) if they speak NFC.
评论 #14829180 未加载
评论 #14843089 未加载
评论 #14830058 未加载