Skip to content

RFID and NFC

RFID and NFC are the technologies of access cards, hotel keys, transit passes, contactless cards, and inventory tags. Many implementations use old, weak technology (like MIFARE Classic) with broken or no encryption, which allows reading, cloning, and sometimes modifying cards with cheap hardware. It’s a pillar of physical red teaming: cloning an access card opens doors, literally.

LF (125 kHz) low-frequency RFID: old proximity cards (EM410x, HID Prox)
-> often UNENCRYPTED, just an ID that can be cloned
HF (13.56 MHz) high-frequency RFID/NFC: MIFARE, DESFire, phone NFC
-> from broken (MIFARE Classic) to robust (DESFire EV2)
Proxmark3 the RFID swiss-army knife (LF+HF): read, clone, crack, emulate
Flipper Zero convenient for basic LF/HF, clone simple cards, emulate
ACR122U cheap USB NFC reader (HF)
card readers/writers, blank tags (T5577 for LF, "magic" UID for HF)

Many LF cards only transmit a fixed unencrypted ID → cloning = read the ID and write it to a blank card:

# with Proxmark3
lf search # identify the type
lf em 410x read # read the ID (EM410x)
lf em 410x clone --id <ID> # clone to a T5577
# with Flipper Zero: read -> save -> emulate/write

MIFARE Classic uses the Crypto1 cipher, broken years ago. Keys are recovered and the card is dumped/cloned:

# key-recovery attacks
mfoc / mfcuk # exploit Crypto1 weaknesses (nested, darkside)
# with Proxmark3
hf mf autopwn # recover keys + dump the card
hf mf dump # dump all sectors
# clone to a "magic" card (writable UID)
hf mf restore

With the recovered keys you read all the content, clone it, and sometimes modify it (balance, permissions) if the logic trusts what’s on the card.

# cloning for physical access (red team): read an employee's card (up close) and clone it
# -> long-range readers / covert reading from a bag
# emulation: the Proxmark/Flipper poses as the card
# data modification: transit/cafeteria balance, access level, if validated on the card
# downgrade / misconfigured cards (DESFire with default keys)
# phone NFC: contactless payment read/relay, malicious tags (URLs/exploits)
  • Don’t use MIFARE Classic or unencrypted LF for access control; migrate to DESFire EV2/EV3 or technology with strong encryption and mutual authentication.
  • Don’t store sensitive logic/values on the card; always validate against a backend (the card is an identifier, not the source of truth).
  • Unique keys per installation (no default keys), rotation, and per-card diversification.
  • Protect against remote reading (shielded sleeves), and against cloning (mutual authentication, signed data).
  • Correlate access (same card in two places at once = clone).
  • Identify the frequency/technology (lf search / hf search)
  • LF: read and clone the ID (EM410x/HID) to a T5577
  • HF MIFARE Classic: recover keys (mfoc/autopwn) and dump
  • Clone to a “magic” card (writable UID)
  • Sensitive data on the card? Modifiable? (balance/access)
  • DESFire/others: default keys?
  • Emulation with Proxmark/Flipper for physical access
  • Blue: strong encryption, backend validation, unique keys?