Flipper Zero Access Control Hacking Tested

Published Nov 13, 2023 15:43 PM

With half a million units sold and climbing, plus tens of millions of video views showing hacking all sorts of systems, Flipper Zero has become a sensation, but what can it actually hack?

IPVM Image

While scores of videos exist online, many of them are exaggerations or simply wrong or fail to cover key access control technologies that professionals care about.

We tested the following types:

  • Prox Cards (125 kHz)
  • iClass with Standard Keys (13.56 MHz) using the Picopass app (separately downloaded)
  • Mifare Classic/Ultralight (13.56 MHz) without Private Keys
  • iClass SE/Seos (13.56 MHz)
  • Mifare Classic (13.56 MHz) with Private Keys
  • iClass (13.56 MHz) with Elite Keys, without access to the associated reader
  • iClass SE/Seos (13.56 MHz) with Elite Keys
  • Mifare Desfire Ev1

Finally, we examine the firmware versions and hardware add-on options available that impact performance and hacking capabilities.

We include a 6-minute and 30-second video showing how this worked across each type.

Executive *******

**** ******** **** *** ******* **** could ****/*****:

  • **** ***** (*** ***)
  • ****** **** ******** **** (**.** ***) using *** ******** *** (********** **********)
  • ****** *******/********** (**.** ***) ******* ******* Keys

** ******** **** ***** ** *** SAM *** *** ****** *** (********** downloaded), ** *** **** *** **** to * ********* ******:

  • ****** **/**** (**.** ***)

******* ******** ******* ********** ******** (**** SAM) *** ******** (******), ******* ****** read ****** **/**** *****.

** ******** **** ** ***** *** copy/clone:

  • ****** ******* (**.** ***) **** ******* Keys
  • ****** (**.** ***) **** ***** ****, without ****** ** *** ********** ******
  • ****** **/**** (**.** ***) **** ***** Keys
  • ****** ******* ***

Flipper **** ****** ******* ******* ********

** ****** ******* **** ************* *** access ******* *******, ************* *** ******'* capabilities ***** ******* ********** *******.

Prox **** ****/*****

******* **** *** ****, *****, *** write **** ***** ***** *** *****-** antenna. **** ******* ********* ******* *** clone *** ****** **** *********** ** verifying *** **** **** **** ** HID ******.

IPVM Image

****** ****** ** *** **** ****** used****** *** **** ***** *** ** accepted ** *** ******** ** ****** control *******. ****** ** *** **-*** standard ****** **** *** ****** ****, eight ******** **** ****, *** ** card ****** ****.

iClass **** ****/***** *** *********

******* **** *** ****, *****, *** write ****** ***** **** ******** ******* using*** ******** ***, ***** ** ******** **** ********* firmware ******** ********* ***** ** *** report, ** ** * ******** ******** through *** ******* *** *****. **** testing ********* ******* *** ***** ******** keyed ****** *********** ** ********* **** data **** ** *** ******.

IPVM Image

*** ****** *********** *** **** ** downgraded ** * **** **** *** same ** ********.

IPVM Image

******* *** **** ** **** ** write ****** ***** ** ********* *******, including ****** **** ***** ****, ******** entered ** *** ****. *** **** can ** ******** **** ****** ****** readers ****** ******* *********** **** *** ******** ***, ** if ***** ** *** ****, **** can ** ******** *******. *******, ** is ******** ** ****** ***** **** in *** ***** ******* (*.*., ***** readers).

IPVM Image

iClass ** / **** **** **** *** *********

**** ********** **** ********** *** *********** **** ******* **** *** ************* ****** *** ***** *****.

***** *** ****** *** *** ** HID ***, ******* *** **** ****** SE/Seos ***** **** ******** **** *** save **** ** ******, ****, ** Mifare ******* *****. *** ***** ***** can ** ******** ** ****** **** rewritable *****, **** ******* *********** *** ID ** *** ******** ***********.

IPVM Image

******** ******** ******* ***** **.** *** SE / **** ** ********** ** Cracked *** *** *** ********* ******, *** ********* ****** ** ****** format ******** * ****** *************, ** both ****** *** **** *** **.** MHz *********.

****: **** **** ******* * ******** report ** ****** ** *** ****** weeks, ********** *** ***'* ******* *** how ** ******* ******* ** **** iClass **/**** *****.

****** ********* *** * *** ***** saving **-*** *********** ** **** **-*** and ****** *** ****** *********** ** one ****. **** ***** *** *** by ******** ********** *** ***-****** *********** to ****** ****** *** ******** *** prox ********** ** *** **** ** obtain *** ********* ********** ** *** Seos ****. *** ********* ********* ** is ******* ** * *** *** this ***.

Mifare *******/********** ****/*****

****** *******/********** *********** *** ** **** and ****** ** ******* **** ** not **** ******* ****. ********, ******* Mifare *******/********** ************ **** ** ******* IDs, **** ****** ******* *******, ******* cards, *** ***** ********* *** *** privately *****.

****** *******/********** ***** *** ***** ********* keyed *** ********** **** ***** (*.*., *******), ***** *** *****, *** ******** payment *****.

*** ******* *** ****** ** ******* keys * ****** *******/********** ********** ****, the ****** ** **** ** ** practically **** ****. **** ***** ***** some ***** *** ***** (* ** 4 ******* ****) **** ****** ** the ***** *** *** ****** *** could *** ***** ** ********** **** lock *** (** ** ** ******* keys) **** **** ****** ** *** card *** *** ****** *** ** extended ******, ** ***** ***** (**** 4 *** ** ** **** *****). Flipper **** ****** ******* **** *** private **** ** ******* *** ********** and *** ****** *********** **** ***** *** ***** ***********.

IPVM Image

Mifare ******* *** ****

***** ******* ***** **** *** ******* card, ** *** *** ******* *** PACS **** ****** *** **** *** did *** ************ ****/***** ** *** initial *******. *** **** **** ****** the ******* *** ******** ******* ******* was ******** ***** * ******** ****.

IPVM Image

** **** ******** ******* ******* *********** with ******* *** ******** *** ****** the ****** **** *** ********, ********* Desfire *** *** ***.

Flipper **** ***** *** ******** ********

******* **** ** ****** ** $*** on*** ******** ********** **** ******** * *** ***** in *** ***. *** ***** **** to ******** * ******** ** **** for ******* ******* ** **** *** full ************* ** *** ******. *** Flipper **** ** ********* ** *** China *** ******** ********** ******** ** its ***, ******* "********** *** ***, multi-tool *********** ******."

IPVM Image

Official ******** ********* ******** *************

***** ***** ********* ******* **** ******** ***** *** qFlipper ****** *** ** ** *** ****** app,*** ******** ***************** **** ******** ************* *** ** legal ***********. *** *******, ***** ******* "** ******* ** ********* ******* ** all *********** ** *** ***-*** ***, 387-464 ***, *** ***-*** *** *********** bands," ** ** ********** ** ******* ranges ****** ********* ******* (*.*.***.** - ***.** *** /***.** - ***.** *** ** **, and***.** - ***.** *** /***.** - ***.** *** /***.** - ***.** *** ** *** US).

IPVM Image

******* ***** ******* ******** ******* ********** hardware ***************, **** ** ***-*** ******** frequency ************, *** **** ****** ******* keys ** *** ********** (*.*., ****** Classic ****). *** ********** ******** *****, such ** *********, ****, "**** ******** is *** ************ ******** **** *** is *** ***** *** *** ******* activity/purposes," ************ *** ******** *** ** illegal **********.

IPVM Image

*** ********** ******* ******** *** ********** firmware *********** ** ***** ** **********-*********** ****** ****, ********* ********* *************** ******** ** the ******** ********.

Comments (23)
UM
Undisclosed Manufacturer #1
Nov 13, 2023

* ********** **** *******. **** **** weekend ** ****** *** ******* ****** with **** *** ****** ** ** can ****/******* ****** ***** **** *** stored ** ***** ****** **** ** unofficial ********. *'* ** ******* ** this *** ** **** *** ***** wallet *** *********** ** ****?

(1)
(5)
MK
Mert Karakaya
Nov 13, 2023
IPVMU Certified

** **#*,

***** ******* ***** ** *** "****" Apple ****** ***********, ** **** ***** the *** ********* ** *** ***** Wallet *** **** *** ******* *** usable ****. **** ** ** ***** showing *** **** **** **** ** Apple ****** ****** **********:

IPVM Image

** ********* **** ***** ******* ***** the ****** ** ******* **** ***, it **** *** ******* * ********** handshake **** *** ****** *** **** not **** ****** ** *** ****. I **** **** *** ***** *******.

(3)
(8)
UM
Undisclosed Manufacturer #1
Nov 13, 2023

***** *** *** *** ***** ********** on ********* ****!

MK
Mert Karakaya
Nov 13, 2023
IPVMU Certified

**** ** *** ***** ******* *** door ******** **** ***** ****** (*** light ***** *** ****** ***** ***), and ******* *** ********* *** **** (the ***** ***** **).

(3)
(12)
Avatar
Charles Baker
Nov 15, 2023

* **** *** **** *** *********** about ****-***** "*********" **** **** ****.

*** *** ******** **** ********* ** determine ******* *** ********-**** ** *** Bluetooth *********** *** **** ** **** with **** ********* **********?

MK
Mert Karakaya
Nov 15, 2023
IPVMU Certified

** *******,

** **** *** ****** ********* ******** with *******; *******, ** *** ********* testing *** ******* ** ******* ******** in*** ******* *** *** ****** *** DEF *** **** ********.

** *** ******* ******* **** ****** Seos ***********, ******* *** *** **** to **** ****.

(1)
U
Undisclosed #2
Nov 15, 2023

* *** * *** ** ******** on *** ******* **** (*** ******** like **) **** *** **** ****** and ******** **** **** ** ****. I *** *** ** ***** **** how **** *** ******* *** ******* because ** *****'* ******* *** ******. A *** ** ***** ******** **** negative ********* ***** **** **** ** thing ***** *****, *** **** ****** never *** ** **** * ***** of ** **** ** ****** ************ to ******** ** ********. **** ** do **** ****** * *** *** mouse ****. **** **** ****** ******* systems **** ****** **** **** ******** over * ****** *** ** ******* that ****** ****** *** ***** *** to ***** **** ** ******** ** systems **** *** *** **** *** alternatives ** **'* * ****** ****'* poorly ********** *** ****** *** *********** of ***********.

* ****** ******* **** ********* *******. Thanks *** ****** *** **** ** test *** ***** ** ** ****.

(4)
(2)
UE
Undisclosed End User #3
Nov 17, 2023

***** ***** ******* ***** ***'* **** quite ** ********** ** * **** our ***** ******** *** ****** ** us ***** * ** * ***** ago ***** ********* **** * *** CON **********. * ***'* ******** **** the **** ***, *** ****** **** just ***** * *****, *** **** was **** ** ******* *** **** it **** *** **** *** ******* of ********* **** ******* ************ ** a ***** ***** ****** ** * reader, ******* ********** ***** ** ** found ****.

*** ****** ****** ** ******* * lower ******** ******, **** ***** ***** the **** ** ******** *** **** number **** ** ** *** ******** to ** **** ** *** **** (which *** **** ** ******, ** the **** # *** ****** ******* directly ** *** ****), ***** ***** you ***** **** *** **** ** a ****** *** ***** *** ***** force ******, ***** *** **** ***** emulate *** **** ** * ****, starting **** *** *********** **** #, and **** ******** ** **** **** as **** ** *** ***** ****** would *****. **** **** ********* ** the **** **** **** ***** *** ordered ** * ********** *****.

** ******* ********:

  • *** *** ***** *** ***** (**** #1000), ******* ****, ******** ***********.
  • ********* ********** ***** ***** *** **** tool ** **** ***** ******.
  • ********* ********** ***** * **** **** a ***** ****** ** ***** ******.
  • **** ******** **** #****, #****, #****, #1003, #****, #**** (** ***** ***** the **** ******** *******), **** ******* each ******** **** ***** * **** second.
  • ********* ********** ****** #**** ** * valid *****, *** **** ********* *** attack.
  • ***** **** ***** ** ***** ***** attack ****** *******, **** **** ** seconds

****** ******* **** ***** **** ****** something ****:

  • ****** ******: *** *** [**** *****]
  • ****** ******: *** *** [** ****** rule]
  • ****** ******: ******* **********
  • ****** ******: *** ***** [******** **********]
  • ****** ******: *** ***** [*** ** schedule]
  • ****** *******: ***** ****

******* **** *** ******* **** *******, you ** ***** **** **** * lost ** ****** ***** **** ** reported *********** **** ********* *** ************ deactivated. ** ****** **** ***** ***** tool ***** *** **** ** *** if **** ************ **** * *** standard **** ******, ***** ***** ** why * *****'* ***** ******* ***** that **** ***** *** ******* ****/****.

(2)
MK
Mert Karakaya
Nov 17, 2023
IPVMU Certified

*** ** ********?

** **** ** ********* * ****** on ********, ********* *** ************. ** the *********, ** **** *********** *** of *** **** ************ ** ******** development,*** ****** ********* **** ************* ********.

MK
Mert Karakaya
Nov 27, 2023
IPVMU Certified

****** ********* *** * *** ***** saving **-*** *********** ** **** **-*** and ****** *** ****** *********** ** one ****. **** ***** *** *** by ******** ********** *** ***-****** *********** to ****** ****** *** ******** *** prox ********** ** *** **** ** obtain *** ********* ********** ** *** Seos ****. *** ********* ********* ** is ******* ** * *** *** this ***.

** **** ********* **** **** *** has **** *****, *** **** **** is ********** ** ****, *** **** data ******* *** ******** **********.

Avatar
Attila Kalcsó
Feb 06, 2024

**,

** ***** *** ********** **** **** Communications ******* *** *** ***********?

******,

******

MK
Mert Karakaya
Feb 06, 2024
IPVMU Certified

** ******,

** *** *** ***** *** *** readers *** *********** (*.*., ****), ***** will ** ********** ** ******* ** Flipper ****.

** *** *** **.** *** / NFC ******* *** ***********, *********** *** clone **** ** ***** ************. *********** include ****** ******, ****** **, *** Seos, *** ********* ** ***, *** Mifare *******, ****** ****, ****** **********, DesFire ***, ***, ***, ***. ********* by *** (****** *** ****** ******* *******).

******* ***** ***********, ******* **** *** clone ****** ****** *** ****** *******, as ********* ** *** *******.

(1)
Avatar
Attila Kalcsó
Feb 06, 2024

**,

**** **** ******* *** ** **** might ** ******** ** ****. * asked **** ** ******* ** **** information ** *********. **** ***** **** once * *** *********.

******

MK
Mert Karakaya
Feb 06, 2024
IPVMU Certified

** *** *********, ******* *** ** not *******, *** ******* ****** ***** ev2 ***.

(1)
Avatar
Nadav Doron
Mar 16, 2024

*** ** **** *** ****** **** Pyramid **** *********?

MK
Mert Karakaya
Mar 16, 2024
IPVMU Certified

** *****, ** **** *** ****** that ********** **********, *** **** ** research, ********* **** *********** ********** (*********) to **** ***** *********** ****** ** copy.

***** ***** ************** ******* ** ******* ********** ** ******* ******* *** **** it, ***** *** *********** ******* ** copy **** **********. **** ** *** pyramid ******** ** *******, **** ****** for****/**** **********, ****************** ******** **** ********* ** ******** *** **** *************.

** *** ***** ******* **** *** copy **** **********, ***** ** *** example.* ****** **** **** **** **** details*** *** ** ***** ** ***** Pyramid **** ********* (******* ******* ***). I ******** *** ***** *****:

******* ****** ** **** ** ** to *** **. ******'* *******.

*** **** ** ****** ******* ********/**** tools, ************ ** ****** ******* ******** *****.

(2)
UI
Undisclosed Integrator #4
Apr 15, 2024

**,

*** *** ******* **** ***** *** Coporate **** *****, ************ ** ***?

MK
Mert Karakaya
Apr 15, 2024
IPVMU Certified

** **#*,

** ***** *** ********* **** *****, the ******** ***** **** *** ********* 1000 **** **** *** ********** ******* the ***** *** *** *******.

*** *** ** ******** *** *** those **** ** ** **************** ** ****** ****** ***** *** readers *** **** **** *** ******. However, ** *** *** ***** ****** SE ******* ** *****, ******* ****** cannot ******* *** ****.

******* ****** ***** ** *** ******** disclosed ************* **** *************, ***** ** an ******** ***** ****** ** * configuration ****, **** *** ******* *** keys *** ***** *****.

*** ********* **** ******** *************** ** Configuration *****

(1)
UI
Undisclosed Integrator #5
Apr 23, 2024

** ****,

*** ********* **** ** ****** ** just *** **** ******, *** *** communication ***** ********* ***** *** ** keys ********, **** **** ****** *****, H10304 *****, ***.

**** *** **** ******** ** *** card ********** ********.

**** ****** ** ********* ** *** HID ************, ******, ****** ******, ****** SE *** ****, *********, ** *** have * ****** ****** **** **** Corp **** ** *** ******, ** long ** *** ******* **** *** read ** ****, *** *** **********.

(1)
MK
Mert Karakaya
Apr 23, 2024
IPVMU Certified

****** *** *** *************, **#*.

UI
Undisclosed Integrator #5
Apr 23, 2024

***** *******.

* **** ************* ** *********. *** writing ****** ****** ** *** **** can ** ****, *******, *** ***** shows *** *** **** ** **** the **** *** *** *** ****** SE.

** * ******* *********?

MK
Mert Karakaya
Apr 23, 2024
IPVMU Certified

** **#*, ** ****** *** ******* can **** ** *** **** ***** *** ****** *** ***** **** HID **** *** ******* ****.

UI
Undisclosed Integrator #5
Apr 23, 2024

***** *** ****.