PirateFuzzball
Earning My Ears
- Joined
- May 2, 2013
- Messages
- 17
The MagicBand has a NXP Semiconductors MIFARE DESFire EV1 tag and appears to have 512 Bytes of storage. It was scanned with a SGS4 which has a Broadcom BCM20794 NFC chipset. None of the serial numbers on the band matched the info that I was able to obtain from the tag. It does have a couple of sections that require an encryption key to access. It took about a second for my phone to read it; the wife's SGN2 with the NXP PN544 NFC chipset seemed to read it a few milliseconds faster. I used both NXP Semiconductors' NFC TagInfo and NFC Research Lab's NFC TagInfo apps to scan it.
My wife asked me to scan our bands, hop on here, and let you guys know. I don't frequent these forums much so please pardon me if my responses aren't prompt. Please know that I will not be attempting to write any data to our bands nor will I invest the time to break the encryption.
I don't have time to take a bunch of screen shots and upload them so below is the NXP's app output from the scan in XML format. I have X'd out the last four of any identifiable information.
My wife asked me to scan our bands, hop on here, and let you guys know. I don't frequent these forums much so please pardon me if my responses aren't prompt. Please know that I will not be attempting to write any data to our bands nor will I invest the time to break the encryption.
I don't have time to take a bunch of screen shots and upload them so below is the NXP's app output from the scan in XML format. I have X'd out the last four of any identifiable information.
Code:
<?xml version="1.0" encoding="UTF-8"?>
<scan>
<version>2.00</version>
<date>2013-09-12</date>
<title>NXP Semiconductors MIFARE DESFire EV1 tag</title>
<uid nxp="true">04:4D:35:XX:XX:XX:XX</uid>
<hasndef>false</hasndef>
<section>
<subsection title="IC manufacturer">
<block type="text">
<content>NXP Semiconductors</content>
</block>
</subsection>
<subsection title="IC type">
<block type="text">
<content>MIFARE DESFire EV1</content>
</block>
</subsection>
<subsection title="DESFire Applications">
<block type="text">
<content>Access control data for electronic locks #0
¶ Timelox AB<hexoutput> (0xF70090)</hexoutput>
and 1 unknown application<hexoutput>:
¶ Unknown application 0x78E127</hexoutput></content>
</block>
</subsection>
</section>
<section>
<subsection title="No NFC data set storage">
<block type="text">
<content></content>
</block>
</subsection>
</section>
<section>
<subsection title="Memory information">
<block type="text">
<content>Size: 0
kB
Available: 320 bytes</content>
</block>
</subsection>
<subsection title="IC detailed information">
<block type="text">
<content>Capacitance: 70
pF</content>
</block>
</subsection>
<subsection title="Version information">
<block type="text">
<content>Vendor ID: NXP<hexoutput> (0x04)</hexoutput>
Hardware info:
¶ Type/subtype: 0x01/0x02
¶ Version: 1.0
¶ Storage size: 512 bytes<hexoutput> (0x12)</hexoutput>
¶ Protocol: ISO/IEC 14443-2 and -3<hexoutput> (0x05)</hexoutput>
Software info:
¶ Type/subtype: 0x01/0x01
¶ Version: 1.4
¶ Storage size: 512 bytes<hexoutput> (0x12)</hexoutput>
¶ Protocol: ISO/IEC 14443-3 and -4<hexoutput> (0x05)</hexoutput>
Batch no: 0xBA3494XXXX
Production date: week 24, 2012<hexoutput> (0x2412)</hexoutput></content>
</block>
</subsection>
</section>
<section>
<subsection title="Technologies supported">
<block type="text">
<content>ISO/IEC 7816-4 compatible
Native DESFire APDU framing
ISO/IEC 14443-4 (Type A) compatible
ISO/IEC 14443-3 (Type A) compatible
ISO/IEC 14443-2 (Type A) compatible</content>
</block>
</subsection>
<subsection title="Android technology information">
<block type="text">
<content>Tag description:
¶ TAG: Tech [android.nfc.tech.IsoDep, android.nfc.tech.NfcA]
android.nfc.tech.IsoDep
¶ Maximum transceive length: 261 bytes
¶ Default maximum transceive time-out: 1000
ms
¶ Extended length APDUs not supported
android.nfc.tech.NfcA
¶ Maximum transceive length: 253 bytes
¶ Default maximum transceive time-out: 1000
ms
No MIFARE Classic support present in Android</content>
</block>
</subsection>
<subsection title="Detailed protocol information">
<block type="text">
<content>ID: 04:4D:35:XX:XX:XX:XX
ATQA: 0x4403
SAK: 0x20
ATS: 0x0675778102XXXX
¶ Max. accepted frame size: 64 bytes (FSCI: 5)
¶ Supported receive rates:
" 106, 212, 424, 848
kbit/s (DR: 1, 2, 4, 8)
¶ Supported send rates:
" 106, 212, 424, 848
kbit/s (DS: 1, 2, 4, 8)
¶ Different send and receive rates supported
¶ SFGT: 604.1
µs (SFGI: 1)
¶ FWT: 77.33
ms (FWI: 8)
¶ NAD not supported
¶ CID supported
¶ Historical bytes: 0x80 |·|</content>
</block>
</subsection>
<subsection title="Memory content">
<block type="text">
<content>PICC level (Application ID 0x000000)
¶ PICC key configuration:<hexoutput> (0x0F01)</hexoutput>
" AES key
" PICC key changeable
" PICC key required for:
~ directory list access: no
~ create/delete applications: no
" Configuration changeable
" PICC key version: 254</content>
</block>
<block type="text">
<content>
Application ID 0xF70090
¶ Key configuration:<hexoutput> (0x0B83)</hexoutput>
" 3 AES keys
" Master key changeable
" Master key required for:
~ directory list access: no
~ create/delete files: yes
" Configuration changeable
" Master key required for changing a key
" Key versions:
~ Master key: 0
~ Key #1: 0
~ Key #2: 0</content>
</block>
<block type="text">
<content>¶ 1 file present</content>
</block>
<block type="text">
<content>
" File ID 0x00: Standard data, 128 bytes
~ Communication: encrypted
~ Read key: master key
~ Write key: master key
~ Read/Write key: master key
~ Change key: master key</content>
</block>
<block type="text">
<content> ~ (No access)</content>
</block>
<block type="text">
<content>
Application ID 0x78E127
¶ Key configuration:<hexoutput> (0x0B82)</hexoutput>
" 2 AES keys
" Master key changeable
" Master key required for:
~ directory list access: no
~ create/delete files: yes
" Configuration changeable
" Master key required for changing a key
" Key versions:
~ Master key: 1
~ Key #1: 1</content>
</block>
<block type="text">
<content>¶ 2 files present</content>
</block>
<block type="text">
<content>
" File ID 0x01: Standard data, 16 bytes
~ Communication: plain
~ Read key: free access
~ Write key: free access
~ Read/Write key: blocked
~ Change key: free access</content>
</block>
<block type="text">
<content> ~ Contents:
</content>
</block>
<block type="DesFire">
<address addrwidth="4">0</address>
<data>68 8C 1F 00 00 00 00 00 05 FB 00 05 XX XX XX XX</data>
</block>
<block type="text">
<content>
" File ID 0x02: Standard data, 56 bytes
~ Communication: plain
~ Read key: key #1
~ Write key: free access
~ Read/Write key: blocked
~ Change key: free access</content>
</block>
<block type="text">
<content> ~ (No access)</content>
</block>
</subsection>
</section>
</scan>