Directory of Access Control Research Tools

Published Oct 16, 2023 14:31 PM

This directory examines 11 commonly used tools to help research vulnerabilities and problems within physical access control systems.

IPVM Image

This is intended for those new to the space, aiming to explain at a high level what these tools can be, without exploring complexities or advanced topics.

Physical Devices And Apps

This directory covers physical devices and smartphone applications used for RFID pen-testing and analysis. This includes nine physical devices and two apps, including (in alphabetical order):

Each of these will be discussed in more detail further in the report.

Note that the field is constantly evolving, and IPVM is expanding its coverage in the area. As we learn more, we will keep updating this directory. If you feel that IPVM missed an important tool, please contact nikita@ipvm.com or leave a comment describing the tool you think we missed.

Chameleon ******* (*****, *****, ***, ***.)

***** *** * *** ********* *******, including********* *****,********* *****, ***., *** *** ***** *** multifunctional ******* **** *** ********* **** for ********** ********* *** ********* ** the *****, *** **** ******* ********, reading, ********, *** ******* ** ** and ** ***********.

IPVM Image

******** ** ********* *****, ********* ***** offers ********/******** ************, ** *** ******* below *****:

IPVM Image

********* ** *** ************** ********** ** ********* *****, *** ******** ***** ** ***** being ****** **, ** **** *************** can ** ***** ** *** ******.

***** ****** **** ********* ******* *** based ** **** ****** ***** (*** Github ************), *** *** ***** ********* device *** *** *************, ************ **************** ***** ****** ************* *** **** **** *,***+ ******* and ***** ** ~€***,*** ****** (*** context,*** ******* ***** ****** *** * "successful" ******** ** **** ******** ** ~$92,500, ********* ** *********** ****).

DL533N

*********** * ****** ***** ** ****** ***** ************ ** **** ***********, ***** ******* data **** *** ***********, *** ******* them.

IPVM Image

** *** ****** ** ***** ** an *** ****, *** ****** ******** most ** ****** *********, ********* ** the ******* **************, ********* ******* ***, EV2, *** ******.

IPVM Image

*******-****, *** ****** *** *** ****, SMS, ***** *******, ******, **** *****, etc. *** ***** *** **** ******* various *** ****, ************ **** **** ******** *, ********* ***** ********'* **************.

**** **** *** ****** ***** ** two **** *******: ** * *** drive *** ** * ****.

ESPKey **** ******* ************ ****

******** * *******-***** **** **** *** intercept ********** ******* ****** **** *** reader ** *** **** ********** *** store **** **** ** ***** ******** to *** **** ********** ***** *** web *********.

IPVM Image

***** ******* ** ******** ** **** as ** ****** *** **** ***-*** communication, *** **** ****** ************* ******* OSDP *** *** ********, **** *******-***** readers *** ********.

*** *** ***** ***** ******* *** the ****** *** ** **** ** intercept ******* ******* *** ****** *** the **********:

*** **** *********** ** ******, *** the*** **** ********'* **** *****.

Flipper ****

******* ****** * ******** **** **** ********** * ****** ***** *********. ** ** * ********* **** tool **** *** ** **** *** duplicating, *******, ********, ********, *** ********* various ****** ******* *********** (******* ***** things).

IPVM Image

******* ** ******** **** ***-***, ***-********* (125kHz), *** ****-********* (**.** ***) ********, as **** ** *********, ********, *** iButton ******** **********. *** ***** ******** can ****** *** ******** *******, ***** is ****** *** ********* *** ******** various ****** ******* ***********.

*** ****** *** **.*****, ******* ******** a ****** ** *********, ** *** excerpt **** *** ******'* ***** ***** shows:

IPVM Image

*******, ********* ** *** ********, *** Flipper's ************* *** ** *******. *** example, ******* ****** ******* *** *********** for **** ******* *********, **** ** DESFire ***/*, ** ***** ********* ****** uncracked ** ****.

*** **** **** ******* ** **** list, ******* ** ***** ** ****-****** code (****** ****** **********), ** **** ************* *** ** added ** *** *** ***** ********** code **********.

******* **** **** *** *** *** app ********* *****************. ********, ****** *** ******* **** environment, **** **** *** **** **** developed, *********'* ******* *****.

********* ** * ***** ** *******-********* developers (**** ***** ******* *** ******* called******* *******), ******* **** ******* ** *********** *********** ********, ******* **** **** $* ******* in *** ***** ** ***** ***** publishing *** ******** (*** ******* ****** a ***** ** ~$*.* *******).

HID ****** ****** ******** * ********** ******/******

***** ***** ******* ** **** ********* are *****-***** ******* ******* ********** ** companies ************* ****** ******* *******,**** *** ****** ******/******** ** ****** ************ ******. **** recognize *** ***** ** **** ******/******, as ** **** *** ********** *** the***** ** ******** ****** ******* ****** protocol. *** **** ******** (*******'* ******* ** **** *******) ********** **** **** ****** ** "highly ******" ** *********** ** **** field, ** *** ******* ****:

***** ******** ******* *** ****** ****** by *********** *** *** ************ ** hardware ******* ******* **** *** ******** block ********** *** **** *** ********** with *** ***-********** ****** ****** ******** that ****** *** **** ************* ************* with ****** ***** **** *****.

IPVM Image

**** **** **** ******/****** ** ** longer ************ ** ***, *** *** stock ********* ********* ***** ** *******.

iCopy-X *** *** ******* *** ******® ** / ****

*****-*** * ********** ****** ***** ** Proxmark * *** *.** ********* **** a **** ****-******** ********* **** * typical **** **** (*.*., *****-* *** a ******* *** *******). *************-****, *****-* can "****, *****, *********, ***** *** simulate ******* *** *** ** * PC," ********* ***** *******'* ******** *********** ********.

IPVM Image

*** ******* ***** ***** *****-* ********* protocols:

IPVM Image

*****-* **** *** ** ***-**, ****** ICS *******, ***** ****** *** ******* HID **/**** *****. *** ******* *** do **, ** ** ** ***** on ** *** ****** ** ****** modified ** ******** ********** **** **** USB * ** *** ****** **** unit. ********** *** ** ********* ** ~$***** *** ******** ****** *******.

IPVM Image

NARD *** *** ******

**** ***(*** ****** *** ****** ****** *****) is ** ********* ***** *** ******* Zero ****, ** *********** **** ********* ***, ****** *** ** *********** **** SIMs ** ****. **** ******* ** useful ** ** ******* ******* **** to **** *********** **** *** ******** keysets *** **** (****** ******** *******), such ** *******, ****, *** ****** SE.

IPVM Image

***** **** ********* ***** ***'* ***** one ** ****** **** *********** ********, it *** **** ******* * ********* attack, ** **** **** ********, ** educational ************ ** *** *****,********* ** *** *******.

*** **** *********** ** **** ***, see*** ****** **********.

RFID ** / ** ***** ******** ****

***** ******* **/** ******** ****** ************* **** ******* **** ***** devices ** **** ****, ** *** offer ******** ******* **** **** ********* is **** ** * ****** *** serve ** * ******** **** ** make **** **** *** ******** ** functioning ** ********.

IPVM Image

**** ****** *** ******** *** ******* low *** ****-********* ****** *** *** lights (*** *** **** *** ** and **, ************).

Proxmark * ****.**

******** **** *** ****** *******,*** *.**, ** *** ** *** **** recognizable ******* ** *** ******** ***** ****** "*** **** ******** ****" in **** ******** ** ****, ** ** *** ** **** for * ******* ** ********* *****, such ** *******, *******, ********, *********, and ******** ***********.

IPVM Image

********** ******* ** ******** ********, * prominent ***** ** *** **** ********, Chris *******, ***** ********,*********** ** *** ****** ******* ** Proxmark, ********* ** ******, * ********-***** reseller ** **** *********.

******** * *** * ****** ** different ***-** ******** ********** **** *** improve *** *****, *** ********* **********, etc.

*** **** *********** ** ******** *, see*** ****** **********.

Smartphone ***: *** *****

*** ***** ** ** *** (********* both *****************) **** *** ****, *****, ******, and ******* *** ***********.

IPVM Image

*** *** *** ***********, ** *** been ****** **** * ****** ** widely **** ********** *****, ********* ******* EV *-*, ** *** ******* ***** shows:

IPVM Image

***** ******* *** ***, *** *** will ******* *********** ***** *** ***'* maker, *** ******** ****, ***. ** writing ** *******, *** *** *** simple ****, ******* ***********, ****/********* *************, amongst ***** ******.

Smartphone ***: *** ****

*** **** ** ** ***-********* *** credential ******** *** (********* *****************) ******** *** ******* *** ****'* information *** ********** ** ******, **** as ******** * ***** **** ** opening * ******* ** **** ** action ** *******.

IPVM Image

*** *** *** *** *****, ****&****** and ****&****, **** ********* ********* ** each ****, ***** *** ******** *********:

IPVM Image

Comments