RATB/Metrorex Card Activ Hacked

RATB/Metrorex Card Activ Hacked

11/14/09 | by zveriu | Categories: Hardware, Software, Hack, Hack, RFID

RATB/Metrorex Card Activ Hacked
…and “Mifare Classic Dark-Side Key Recovery Tool” released under GPL!

Well… It was about the time for RATB/Metrorex Card Activ in Bucharest to fall… And it is not even news. OV Chipkaart in Netherlands, Oyster Card in London were broken in the near and not so near past…

RATT Contactless Ticketing in Timisoara and EasyCard in Taipei are the next samples of cards to be “hacked", i.e. the keys are recovered, need only to analyze the data.

Mifare Classic is both theoretically and practically broken in both active (sniffing) and passive (card-only) attack scenarios.

Thanks to ignorance, lots of money/interest (14 Millions of Euros) and UTI/PMB (Primaria Municipiului Bucuresti/Bucharest City Hall) involvement, RATB/Metrorex still uses Mifare Classic.

Hell ya, where are they gonna go? It’s a logistic nightmare to upgrade the readers in the entire RATB fleet and all Metrorex entrances, manage the exchange of already 800.000 sold cards, not telling about additional several Millions of Euros for upgrade equipment and software upgrades…

Even though researches were blowing the whistle from last year, no system integrator or vendor seems to care :). Well it seems that few smart guys (and not pointing to me, I just implemented what other had know and researched for a long time) can fcuk up dozen of systems, each costing Millions of Euros.

Nice equation: (a dozen of smart guys * their brain IQs of Millions) >>>OUT-WEIGHTS>>> (the dozens of projects * XX Millions of Euros)

Long story short, here we go - food for the brain (yes - food for the brain, not spoon-feeding - note the difference):

RATB/Metrorex Mifare Card Security Assessment Document (PDF)

RATB/Metrorex Mifare Card Security Assessment Document (MS Word 2007)

MFCUK (MiFare Classic Universal toolKit) http://code.google.com/p/mfcuk/

Enjoy!

PS: (14 Nov 2009)
Ironically, on the night of publishing this paper/post and the open-source/binary for key recovery, UTI has posted these news “Cardurile de călătorie RATB se pot reîncărca online sau la bancomat (13 noiembrie 2009)” (i.e. “RATB cards can now be topped-up online or at some BCR ATMs”).

DISCLAIMER: The information and reference implementation source/binary contained herein is provided:

  • for informational use only as part of academic or research study, especially in the field of informational security, cryptography and secure systems
  • as-is without any warranty, support or liability - any damages or consequences obtained as a result of consulting this information if purely on the side of the reader
  • NOT to be used in illegal circumstances (for example to abuse, hack or trick a system which the reader does not have specific authorizations to - such as ticketing systems, building access systems or whatsoever systems using Mifare Classic as core technology)
Tags: mifare, classic, key recovery, mifare classic key recovery tool, mifare classic key hack tool, mifare key recovery source binary executable, key crack, ratb metrorex hack, ratb.ro metrorex.ro hack, ratb metrorex crack, ratb.ro metrorex.ro crack, crypto1, crapto1, lsfr_common_prefix, dark side attack, dark side paper, dark side implementation, darkside libnfc, darkside crapto1, darkside attack implementation, ratb metrorex card activ sat spart hackuit crackuit, uti ratb metrorex card activ hack hacked, ratt hack, ratt card hack, ratt.ro hack, ratt.ro card hack, ratt card crack, ratt crack, ratt card spart hackuit crackuit, easycard mifare classic taipei card hack crack, crypto1 crack, crypto1 hack, crapto1, libnfc key recovery, proxmark3 key recovery

Comments, Pingbacks:

Comment from: Theo [Visitor]
Eh, normally people are supposed to be honest and instead of trying to hack a fucking system, they should pay the bus or the tube or the train, etc

I think you won't like your employer instead of giving you the salary each end of month to try instead to hijack your salary account and raise the shoulders when you ask about money ... people should be honest, all of them.

If they're not, is not anyone's fault
PermalinkPermalink 11/14/09 @ 17:19
Comment from: zveriu [Member] · http://www.andreicostin.com
@Theo:

Of course people should be honest :), though most are not... I know your point and agree with it :P

The purpose of this demo and hack is not to encourage dishonesty, but to make people understand that they pay 14 Millions of Euro out of their pockets for a system which makes the life of dishonest people a lot easier when they want to take advantage of the system.

The shame is on vendor (NXP) who tried to cover a weak system in a secure&strong looking Xmas fancy box... The shame is on UTI and Bucharest PMB, of knowingly keeping a weak system just to avoid public scrutiny and to save their asses of additional effort of fixing the system even though they should know and should have been informed that the Mifare Classic they are using is weak and prone to hacking by dishonest persons...

Eh, it's more like a long debate on ethical aspects of technologically and (un)socially driven societies... ;)
PermalinkPermalink 11/14/09 @ 20:03
Comment from: Smartplastic [Visitor] Email · http://www.smartplastic.biz
It is endless war of armor and weapon. It is not possible to make absolutely protected system, so it is sound to be reasonable to hack the cards
PermalinkPermalink 01/17/10 @ 19:54
Comment from: Harry [Visitor] Email
The number of people able to use the "hack" is far smaller than the people who travel without paying at all and taking the chances to be caught.
Real illegal side begins when someone tries to compete the legal cards by cloning them for money.
Be smart just for yourself!

PMB may consider a few hundreds of "illegal cloned cards" as acceptable loss. What's a few thousands of euros when compared with millions spent for upgrading?
Free your mind!
PermalinkPermalink 07/14/10 @ 12:01

Leave a comment:

Your email address will not be displayed on this site.
Your URL will be displayed.

Allowed XHTML tags: <p, ul, ol, li, dl, dt, dd, address, blockquote, ins, del, span, bdo, br, em, strong, dfn, code, samp, kdb, var, cite, abbr, acronym, q, sub, sup, tt, i, b, big, small>
(Line breaks become <br />)
(Set cookies for name, email and url)
(Allow users to contact you through a message form (your email will NOT be displayed.))
This is a captcha-picture. It is used to prevent mass-access by robots.
Please enter the characters from the image above. (case insensitive)

Cognitive and Scientific Brainology

A deep dive into brain's curiosities

September 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Categories

Misc

XML Feeds

What is RSS?

powered by b2evolution free blog software