Reverse Engineering HID iClass Master Keys

Reverse Engineering HID iClass Master Keys

#Security Testing#Malware Analysis

Collection of slides, materials, demos, crackmes, and writeups from r2con-2017 conference.

Visit Website

The HID iClass Line of Proximity Cards and Readers: A Security Concern

The HID iClass line of proximity cards and readers is recognized for its encryption and mutual authentication features. However, it has a vulnerability that allows the master authentication key to be retrieved. This vulnerability enables the cloning of cards and the alteration of reader settings.

The method involves utilizing debug pins

The method involves utilizing debug pins on specific readers to alter firmware and retrieve the key.