Главная
Study mode:
on
1
Intro
2
DISCLAIMERS !!
3
RFID Billing Schemes
4
Mifare Classic Cards
5
A tiny history and some facts...
6
Security Features of Mifare Classic
7
Mifare Classic Structure
8
Partial Reverse Enginnering . In 2007 Karsten Noh and Henryk Plötz released at CCC the partial reverse engineering cipher initialization of CRYPTO-1 by hardware analysis
9
Weaknesses discovered
10
Full Disclosure of CRYPTO-1
11
Output Example Proxmark3
12
CRYPTO1 Cipher Cryptol Cipher
13
Proxmark3 + Active Sniffing
14
Card-only Attacks
15
Nested Attack
16
Curtouis Dark-Side Attack
17
Attack Steps
18
Proof of Concept
19
Running MFOC First Time
20
Running MFCUK
21
Running MFOC Second Time
22
Creating a Clone
23
Attack Cost
24
Analyzing PuntoBIP! Application
25
Problems Identified only analyzing PuntoBIP.akp
26
Countermeasures Against
27
"Decrement-counter" workaround
28
Conclusions
Description:
Explore the world of RFID hacking in this conference talk from Ekoparty 2014. Dive into the vulnerabilities of MIFARE Classic contactless cards, widely used in access control systems and public transportation. Learn about the card's features, major attack types, and potential security measures. Witness a practical demonstration of dumping and cloning old SUBE cards still in use in Buenos Aires' subway and bus services. Gain insights into the CRYPTO-1 cipher, its weaknesses, and various attack methods including Nested and Curtois Dark-Side attacks. Discover the tools and techniques used in RFID hacking, such as Proxmark3 and active sniffing. Analyze the PuntoBIP! application and understand potential countermeasures against these vulnerabilities. This comprehensive presentation covers the history, security features, and structure of MIFARE Classic cards, providing valuable knowledge for both security professionals and enthusiasts interested in RFID technology and its potential exploits.

Hacking RFID Billing Schemes for Fun and Free Rides - Marcio Almeida Macedo - Ekoparty Security Conference - 2014

Ekoparty Security Conference
Add to list