Open iceman1001 opened 5 years ago
China's clone T5577
2019-04-08T15:26:10Z remark: [SUMMARY] Success rate: 39/64 tests passed, help me improving that number!
majority of my bugs is Test 00000000 == FFFFFFFF Failed
Some of my cards: if PM writes there 0000... PM shows fffff.. but it writes correct. I see it from another reader
yes normally it always writes correctly, but there are issues reading back with some modulations. E.g. if you change only block0 to a stable one (e.g. biphase, middle rate), you'll be able to read the content again.
i cant read at EM 410x config( Manchester + RF/64 I look into code and found that it "shifts" modulation by 1/2 of RF/64 and founds 0xffff... instead of 0x0000 only card that works - one that i have from proxmark kit)
))))
some statistic: all works (with 0xff bug) ) except of: right top blue tokens: works only with professional duplicator. Have not managed to read it on any other reader. I look at them at oscilloscope and found that they not see a write commands... left down color tokens: works on many readers, but pm cant read it (maybe because of field)
if you used the token with the duplicator (like the blue gun) then the tag is password protected. Look into the dictionary file, the three most common pwd for those duplicators is in it
@merlokk you have the old LF dual antenna on your rdv4, it need the keyfob / tag to be direct over the antenna
another tip when trying individual configs, set the debug.
data setd 1
China's clone t5577, you can see the picture of the tag
yeah, I see a strong tendecy with 0xFF FF FF FF gets wrong,
And i dont see how to fix it(
it can be fixed with using of ST terminator (but its not a fix) )
or needs to grab t5577 from beginning of transmit. there is a 0
sequence and then a code
Yeah actually the FFFFFFFF is a corner case because you'll encounter it only when forcing a single block read (or emulating all FF UID, a bit pointless). The only way to distinguish it from 00000000 in some modulations (ASK, PSK1?) is to decide which one is the very first transition in Manchester signal. Some other modulations don't have that problem of distinguishing Manchester symbols, e.g. Biphase, FSK, PSK2
I have some more ideas to test. Since the new noise detection is in place, starting to sample the response a bit earlier makes use get the inital response better. Before we have trimmed the signal since we wanted to let the signal settle in.
as i saw biphase and manchester hard to separate too
Ok so these are all of the different t5577's that I have - 10 in total! Tested from left to tight and results pasted in the same order.
I will also test the Dangerous Things XEM implant with a custom coil that will be released soon. This t5577 is kind of backdoored to allow all blocks of page 1 written. The success rate is very bad even with the custom coil.
KEYCHAINS
CARDS
Now for the glass implant with the soon to be released antenna specifically for LF implants
This one seems to be atrociously bad!
ASK/Biphase demod is now 32 of 32 test pass :)
Describe the problems @doegox and me has spent some time in making lf t55xx commands better. Especially when it comes to demodulation of the different clockspeeds. In order to make testing easer we have created a lua script, test_t55xx.lua where you can edit in order to test a specific modulation or all of them. Our intention is that we should get 32/32 for a test, or 100% . Sadly it isn't that right now. Below I have added current biphase status, it gives a great result of 31/32. Try ASK and you be suppresed the fail tests.
To Reproduce Steps to reproduce the behavior:
2019-04-08T14:50:43Z remark: [SUMMARY] Success rate: 31/32 tests passed, help me improving that number!
Expected behavior We want the output on those tests to say, 32/32
Desktop (please complete the following information): -- running latest firmware/client
Please help us with testing and corrections!