Skip to content

NXP

NXP

NTAG

Card Info:

[usb] pm3 --> hf mfu info

[=] --- Tag Information --------------------------
[+]       TYPE: NTAG 216 888bytes (NT2H1611G0DU) ( magic  )
[+]        UID: 11 22 33 55 66 77 88
[+]     UID[0]: 11, Emosyn-EM Microelectronics USA
      BCC0: 44, crc should be 88
      BCC1: FF, crc should be CC
[+]   Internal: FF ( not default )
[+]       Lock: FF FF  - 1111111111111111
[+] OneTimePad: E1 10 6D 00  - 11100001000100000110110100000000

[=] --- NDEF Message
[+] Capability Container: E1 10 6D 00
[+]   E1: NDEF Magic Number
[+]   10: version 0.1 supported by tag
[+]        : Read access granted without any security / Write access granted without any security
[+]   6D: Physical Memory Size: 872 bytes
[+]   6D: NDEF Memory Size: 872 bytes
[+]   00: Additional feature information
[+]   00000000
[+]   xxx..... - 00: RFU ( ok )
[+]   ...x.... - 00: don't support special frame
[+]   ....x... - 00: don't support lock block
[+]   .....xx. - 00: RFU ( ok )
[+]   .......x - 00: IC don't support multiple block reads

[=] --- Tag Counter
[=]        [02]: FF FF FF
[+]             - 00 tearing ( fail )

[=] --- Tag Version
[=]        Raw bytes: 00 04 04 02 01 00 13 03
[=]        Vendor ID: 04, NXP Semiconductors Germany
[=]     Product type: NTAG
[=]  Product subtype: 02, 50pF
[=]    Major version: 01
[=]    Minor version: 00
[=]             Size: 13, (1024 <-> 512 bytes)
[=]    Protocol type: 03, ISO14443-3 Compliant

[=] --- Tag Configuration
[=]   cfg0 [227/0xE3]: 00 00 00 FF
[=]                     - strong modulation mode disabled
[=]                     - pages don't need authentication
[=]   cfg1 [228/0xE4]: 00 05 00 00
[=]                     - Unlimited password attempts
[=]                     - NFC counter disabled
[=]                     - NFC counter not protected
[=]                     - user configuration writeable
[=]                     - write access is protected with password
[=]                     - 05, Virtual Card Type Identifier is default
[=]   PWD  [229/0xE5]: FF FF FF FF - (cannot be read)
[=]   PACK [230/0xE6]: FF FF       - (cannot be read)
[=]   RFU  [230/0xE6]:       FF FF - (cannot be read)

[+] --- Known EV1/NTAG passwords
[+] Found default password FF FF FF FF  pack FF FF
[=] ------------------------ Fingerprint -----------------------
[=] Reading tag memory...
[=] ------------------------------------------------------------

ICODE

Magic ICODE

Read Card:

[usb] pm3 --> hf 15 info
[+] UID.... E0 04 01 50 00 64 50 76
[+] TYPE... NXP (Philips); IC SL2 ICS2002/ICS2102 ( SLIX )


[=] --- Tag Information ---------------------------
[+]     TYPE... NXP (Philips); IC SL2 ICS2002/ICS2102 ( SLIX )
[+]      UID... E0 04 01 50 00 64 50 76
[+]  SYSINFO... 00 0F 76 50 64 00 50 01 04 E0 00 00 1B 03 01
[+]      - DSFID supported        [0x00]
[+]      - AFI   supported        [0x00]
[+]      - IC reference supported [0x01]
[+]      - Tag provides info on memory layout (vendor dependent)
[+]            4 (or 3) bytes/blocks x 28 blocks
[=]
[=]   EAS (Electronic Article Surveillance) is not active
[usb] pm3 -->

Dump Card:

[usb] pm3 --> hf 15 dump
[+] Reading memory
[-]blk  17
[-] iso15693 command failed

[=] ----------- Tag Memory ---------------

[=] block#   | data        |lck| ascii
[=] ---------+-------------+---+-------
[=]   0/0x00 | E1 40 0E 01 | 0 | .@..
[=]   1/0x01 | 03 00 FE 00 | 0 | ....
[=]   2/0x02 | 00 00 00 00 | 0 | ....
[=]   3/0x03 | 00 00 00 00 | 0 | ....
[=]   4/0x04 | 00 00 00 00 | 0 | ....
[=]   5/0x05 | 00 00 00 00 | 0 | ....
[=]   6/0x06 | 00 00 00 00 | 0 | ....
[=]   7/0x07 | 00 00 00 00 | 0 | ....
[=]   8/0x08 | 00 00 00 00 | 0 | ....
[=]   9/0x09 | 00 00 00 00 | 0 | ....
[=]  10/0x0A | 00 00 00 00 | 0 | ....
[=]  11/0x0B | 00 00 00 00 | 0 | ....
[=]  12/0x0C | 00 00 00 00 | 0 | ....
[=]  13/0x0D | 00 00 00 00 | 0 | ....
[=]  14/0x0E | 00 00 00 00 | 0 | ....
[=]  15/0x0F | 00 00 00 00 | 0 | ....
[=]  16/0x10 | 00 00 00 00 | 0 | ....
[=] ---------+-------------+---+-------

Bruteforce AFI:

[usb] pm3 --> hf 15 findafi
[=] Press pm3 button or press <Enter> to exit
[#] NoAFI UID = E0 04 01 50 00 64 50 76
[#] AFI = 0  UID = E0 04 01 50 00 64 50 76
[#] AFI Bruteforcing done.
[=] Done!

Change UID:

[usb] pm3 --> hf 15 csetuid -u E011223344556677
[=] Get current tag
[+] UID.... E0 04 01 50 00 64 50 76
[+] TYPE... NXP (Philips); IC SL2 ICS2002/ICS2102 ( SLIX )

[=] Writing...
[=] Verifying...
[+] UID.... E0 11 22 33 44 55 66 77
[+] TYPE... Emosyn-EM Microelectronics USA

[+] Setting new UID ( ok )