<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Proxmark3</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Proxmark3"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Proxmark3 rootpage-Proxmark3 skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Proxmark3</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox"><caption class="infobox-title">Proxmark3</caption><tbody><tr><td colspan="2" class="infobox-image"><span typeof="mw:File"></span><div class="infobox-caption">First version of Proxmark3 originally designed by Jonathan Westhues</div></td></tr><tr><th scope="row" class="infobox-label">Date invented</th><td class="infobox-data">2007</td></tr><tr><th scope="row" class="infobox-label">FPGA</th><td class="infobox-data">Xilinx Spartan-II</td></tr><tr><th scope="row" class="infobox-label">Processor</th><td class="infobox-data">Atmel AT91SAM7S64</td></tr><tr><th scope="row" class="infobox-label">Memory</th><td class="infobox-data">64 kB flash</td></tr></tbody></table>
<p><b>Proxmark3</b> is a multi-purpose hardware tool for <a href="Radio-frequency_identification" title="Radio-frequency identification">radio-frequency identification</a> (RFID) security analysis, research and development. It supports both <a href="Near-field_communication" title="Near-field communication">high frequency</a> (13.56 MHz) and <a href="Low_frequency" title="Low frequency">low frequency</a> (125/134 kHz) <a href="Proximity_card" title="Proximity card">proximity cards</a> and allows users to read, emulate, <a href="Fuzzing" title="Fuzzing">fuzz</a>, and <a href="Brute-force_attack" title="Brute-force attack">brute force</a> the majority of RFID protocols.<sup id="cite_ref-:0_1-0" class="reference"><a href="#cite_note-:0-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>Originally created by Jonathan Westhues and published as <a href="Open-source_hardware" title="Open-source hardware">open-source hardware</a>, it was later picked up by a community of developers who significantly improved both hardware and software in comparison with the original version. Proxmark3 gathered a large community of security researchers investigating RFID <a href="Access_control" title="Access control">access control</a> systems, who expand and maintain the project while using it in their own research.<sup id="cite_ref-:4_2-0" class="reference"><a href="#cite_note-:4-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> The original Proxmark3 hardware platform served as the basis for new device versions, including commercial ones.<sup id="cite_ref-:0_1-1" class="reference"><a href="#cite_note-:0-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Technical_specification">Technical specification</h2></div><p>
Proxmark3 is based on <a href="Field-programmable_gate_array" title="Field-programmable gate array">field-programmable gate array</a> (FPGA) technology, which allows the implementation of high-performance low-level analog signal processing, modulation and demodulation. A separate <a href="Microcontroller" title="Microcontroller">microcontroller</a> processes demodulated frames. Such setup potentially allows any RFID protocol to be implemented in Proxmark3's software. </p>
<div class="mw-heading mw-heading3"><h3 id="Antennas">Antennas</h3></div>
<p>2 independent antenna circuits are used for <a href="Low_frequency" title="Low frequency">low frequencies</a> (LF) 125 kHz and 134 kHz, and <a href="High_frequency" title="High frequency">high frequency</a> (HF) 13.56 MHz. Initially, both antennas were connected with a shared 4-pin Hirose USB connector, which was unreliable at times. Subsequent revisions have opted to use a separate connector for each antenna.
</p>
<div class="mw-heading mw-heading3"><h3 id="ADC">ADC</h3></div>
<p>8-bit <a href="Analog-to-digital_converter" title="Analog-to-digital converter">Analog-to-digital converter</a> (ADC) receives an analog signal from the antenna circuit, digitizes it and outputs the digital signal to the FPGA.
</p>
<div class="mw-heading mw-heading3"><h3 id="FPGA">FPGA</h3></div>
<p><a href="Field-programmable_gate_array" title="Field-programmable gate array">Field-programmable gate array</a> does both the low-level modulation when transmitting data from CPU and demodulation when receiving a signal from an ADC. It can process various modulations such as <a href="On%E2%80%93off_keying" title="On–off keying">on–off keying</a> (OOK), <a href="Amplitude-shift_keying" title="Amplitude-shift keying">amplitude-shift keying</a> (ASK), etc. The FPGA works in two ways: as reader generating electromagnetic field for cards, or as card waiting for reader field.
</p>
<div class="mw-heading mw-heading3"><h3 id="CPU">CPU</h3></div>
<p>The <a href="ARM_architecture" class="mw-redirect" title="ARM architecture">ARM</a> microcontroller is responsible for the protocol part. It encodes and decodes the frames (<a href="Manchester_code" title="Manchester code">Manchester</a>, <a href="Miller_code" class="mw-redirect" title="Miller code">Miller</a>, etc) and performs more advanced functions. The CPU can reply back to the FPGA after signal handling, thus implementing the transport layer. The CPU also manages the USB communication with the PC client application.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Flash_memory">Flash memory</h3></div>
<p><a href="Flash_memory" title="Flash memory">Flash memory</a> is used to store firmware. The early versions of Proxmark3 only had 64 kB of flash memory,<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> but as firmware developed that became scarce and versions with 512 kB appeared.<sup id="cite_ref-:2_5-0" class="reference"><a href="#cite_note-:2-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>The firmware itself consists of ARM code and an FPGA image (which is loaded by the ARM). The FPGA communicates with the ARM through either its <a href="Serial_Peripheral_Interface" title="Serial Peripheral Interface">SPI</a> port (the ARM is the master) or its generic <a href="Synchronous_Serial_Port" title="Synchronous Serial Port">SSP</a>. The SPI is used for FPGA configuration. The SSP is used for data sent over the air.<sup id="cite_ref-:1_6-0" class="reference"><a href="#cite_note-:1-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Software">Software</h2></div>
<p>At the time Proxmark3 was developed, <a href="Software-defined_radio" title="Software-defined radio">SDR</a> was a hard to access technology. For that reason a split <a href="Field-programmable_gate_array" title="Field-programmable gate array">FPGA</a>/<a href="Microcontroller" title="Microcontroller">MCU</a> architecture was designed: an FPGA handles low-level functionality such as modulation/demodulation, while a microcontroller cares for the high-level functionality (<a href="Command-line_interface" title="Command-line interface">command-line interface</a>, protocol encoding/decoding, etc). While the FPGA/MCU architecture is technically outdated, it remained unchanged throughout hardware revisions. This allowed different versions to use the same firmware and resulted in a large code-base. However, with time the Proxmark3 codebase became increasingly fractured and hardware instabilities started to appear. As a result, some implementations refine and optimize the code (for example Proxmark3 RDV4), while others use the original Proxmark3 codebase (for example Proxmark3 EVO).<sup id="cite_ref-:2_5-1" class="reference"><a href="#cite_note-:2-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p>
<p><b>Proxmark3 software is divided into three parts:</b>
</p>
<ul><li><b>PC client</b> (application layer) – <a href="Personal_computer" title="Personal computer">PC</a> application which calls the Proxmark3 functions. It is used to display data, analyze the signal and manage Proxmark3. Subsequently, in newer Proxmark3 versions a mobile app can be used to control the Bluetooth-connected device.</li>
<li><b>CPU firmware</b> (transport layer) – <a href="ARM_architecture" class="mw-redirect" title="ARM architecture">ARM</a> firmware that manages protocol messages, formats and queues. It also provides <a href="Command-line_interface" title="Command-line interface">CLI</a> tools.</li>
<li><b>FPGA</b> <b>firmware</b> (physical layer) – <a href="Xilinx_Spartan" class="mw-redirect" title="Xilinx Spartan">Xilinx Spartan II</a> firmware is responsible for the <a href="Digital_signal_processing" title="Digital signal processing">DSP</a>: modulating/demodulating of signals.</li></ul>
<p>Older firmware used USB <a href="Human_interface_device" title="Human interface device">HID</a> protocol to connect the client to the Proxmark3. It was not possible to stream the received samples in real-time to the PC. CPU received a command from the client, executed it and stored the result in the memory buffer. The client had to send a new command to retrieve the CPU buffered data.<sup id="cite_ref-:3_7-0" class="reference"><a href="#cite_note-:3-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> New firmware versions use <a href="USB_communications_device_class" title="USB communications device class">CDC</a> serial interface to communicate with the client.<sup id="cite_ref-:4_2-1" class="reference"><a href="#cite_note-:4-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>Signal samples may be handled by the PC client, it can plot received data to assist in analyzing unknown signals.
</p>
<div class="mw-heading mw-heading2"><h2 id="Community">Community</h2></div>
<p>Since Proxmark3's release in 2007 several RFID enthusiasts have been extending its functionality. Proxmark3 community has seen rapid growth after the release of firmware supporting the <a href="ISO/IEC_14443" title="ISO/IEC 14443">ISO/IEC 14443-A</a> standard and appearing successful attacks on <a href="MIFARE" title="MIFARE">Mifare Classic</a>. The Proxmark3 forum (registration required) became one of the main hubs for RFID system vulnerability discussion frequented by security researchers focusing on <a href="Electronic_access_control" class="mw-redirect" title="Electronic access control">electronic access control</a> (EAC) systems. The Proxmark community also houses developers of other RFID research tools: for example LibNFC.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> The community <a href="Discord_(software)" class="mw-redirect" title="Discord (software)">Discord</a> server was later created to host both text and voice discussions on the topic of EAC system security. It had about 3000 members at the end of 2021.
</p>
<div class="mw-heading mw-heading2"><h2 id="Researches_used_Proxmark3">Researches used Proxmark3</h2></div>
<p><a href="MIFARE" title="MIFARE">Mifare</a> Classic cards attacks:
</p>
<ul><li><b>Darkside attack</b> (Nijmegen/Oakland Group, 2009)– recovering at least one key from any sector of the card. Works for every card, takes a long time. Using mfoc (Mifare Offline Cracker) tool from libnfc stack.</li>
<li><b>Nested attack</b> (Nicolas T. Curtois, 2009) – If one sector is encrypted with a known key, other sectors are crackable in a short amount of time. There is also the updated version of this attack – Hardnested. Using mfcuk (Mifare Classic universal toolkit) tool from libnfc stack.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Mifare Classic paper:
</p>
<ul><li>A practical attack on the MIFARE Classic<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup></li></ul>
<p><a href="DESFire" class="mw-redirect" title="DESFire">Mifare DESFire</a> paper:
</p>
<ul><li>An investigation of possible attacks on the MIFARE DESFire EV1 <a href="Smart_card" title="Smart card">smartcard</a> used in public transportation<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup></li></ul>
<p><a href="HID_Global" title="HID Global">HID</a> iClass papers:
</p>
<ul><li>Heart of darkness – exploring the uncharted backwaters of HID iCLASS security<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Hitag paper:
</p>
<ul><li>Gone in 360 Seconds: Hijacking with Hitag2<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Megamos paper:
</p>
<ul><li>Dismantling Megamos Crypto: Wirelessly Lockpicking a Vehicle Immobilizer<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup></li></ul>
<p><a href="Near-field_communication" title="Near-field communication">NFC</a> papers:
</p>
<ul><li>Practical attacks on NFC enabled cell phones<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-:0-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-:0_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:0_1-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFChantzis2021" class="citation book cs1">Chantzis, Fotios (2021). <i>Practical IoT hacking : the definitive guide to attacking the internet of things</i>. Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods. San Francisco. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-7185-0091-4</bdi>. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/1178868866">1178868866</a>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite book}}</code>: CS1 maint: location missing publisher (link)</span></span>
</li>
<li id="cite_note-:4-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-:4_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:4_2-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFYang2018" class="citation book cs1">Yang, Qing (2018). <i>Inside radio : an attack and defense guide</i>. Lin Huang. Singapore. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-981-10-8447-8</bdi>. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/1029352620">1029352620</a>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite book}}</code>: CS1 maint: location missing publisher (link)</span></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFCrepaldiPimenta2017" class="citation book cs1">Crepaldi, Paulo; Pimenta, Tales (2017-11-29). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=vMOQDwAAQBAJ&q=proxmark&pg=PA40"><i>Radio Frequency Identification</i></a>. BoD – Books on Demand. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-953-51-3629-3</bdi>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cq.cx/proxmark3.pl">"A Test Instrument for HF/LF RFID"</a>. <i>cq.cx</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-09-15</span></span>.</cite></span>
</li>
<li id="cite_note-:2-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-:2_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:2_5-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://proxmark.com/proxmark-3-hardware/proxmark-3">"Proxmark 3 | Proxmark"</a>. <i>proxmark.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-09-15</span></span>.</cite></span>
</li>
<li id="cite_note-:1-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-:1_6-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/Proxmark/proxmark3">"Hardware Description · Proxmark/proxmark3 Wiki"</a>. <i>GitHub</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-09-15</span></span>.</cite></span>
</li>
<li id="cite_note-:3-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-:3_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFR.2012" class="citation book cs1">R., Garcia, F. D. Koning Gans, G.T de Verdult (2012). <i>Tutorial: Proxmark, the Swiss Army Knife for RFID Security Research : Tutorial at 8th Workshop on RFID Security and Privacy (RFIDSec 2012)</i>. Nijmegen : Radboud University Nijmegen, ICIS. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/1247335104">1247335104</a>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite book}}</code>: CS1 maint: multiple names: authors list (link)</span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFKoning_Gans2013" class="citation book cs1">Koning Gans, Gerhard de (2013). <i>Outsmarting smart cards</i>. [S.l.: s.n.] <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-94-6191-675-4</bdi>. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/830879913">830879913</a>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite id="CITEREFCourtois2009" class="citation web cs1">Courtois, Nicolas (2009). <a rel="nofollow" class="external text" href="https://discovery.ucl.ac.uk/id/eprint/196096/1/196096.pdf">"Card-Only Attacks on MiFare Classic or How to Steal Your Oyster Card and Break into Buildings Worldwide"</a> <span class="cs1-format">(PDF)</span>. <i>UCL Discovery</i><span class="reference-accessdate">. Retrieved <span class="nowrap">September 16,</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite id="CITEREFde_Koning_GansHoepmanGarcia2008" class="citation cs2">de Koning Gans, Gerhard; Hoepman, Jaap-Henk; Garcia, Flavio D. (2008), "A Practical Attack on the MIFARE Classic", <i>Smart Card Research and Advanced Applications</i>, Lecture Notes in Computer Science, vol. 5189, Berlin, Heidelberg: Springer Berlin Heidelberg, pp. <span class="nowrap">267–</span>282, <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/0803.2285">0803.2285</a></span>, <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F978-3-540-85893-5_20">10.1007/978-3-540-85893-5_20</a></span>, <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-3-540-85892-8</bdi>, <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:1280839">1280839</a></cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFFlynn" class="citation web cs1">Flynn, Rory. <a rel="nofollow" class="external text" href="http://www.proxmark.org/files/Documents/13.56%20MHz%20-%20MIFARE%20DESFire/FYP_Report_DESFireEV1.pdf">"An investigation of possible attacks on the MIFARE DESFire EV1 smartcard used in public transportation"</a> <span class="cs1-format">(PDF)</span><span class="reference-accessdate">. Retrieved <span class="nowrap">September 16,</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://fahrplan.events.ccc.de/congress/2010/Fahrplan/attachments/1770_HID-iCLASS-security.pdf">"Heart of Darkness - exploring the uncharted backwaters of HID iCLASS security"</a> <span class="cs1-format">(PDF)</span><span class="reference-accessdate">. Retrieved <span class="nowrap">September 16,</span> 2021</span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite id="CITEREFVerdultGarciaBalasch2012" class="citation book cs1">Verdult, Roel; Garcia, Flavio; Balasch, Josep (2012). <a rel="nofollow" class="external text" href="https://www.worldcat.org/title/1367211073"><i>Gone in 360 Seconds: Hijacking with Hitag2</i></a>. [S.l.] : USENIX Association. <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a> <a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/1247338434">1247338434</a>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite id="CITEREFVerdultGarciaEge" class="citation web cs1">Verdult, Roel; Garcia, Flavio; Ege, Baris. <a rel="nofollow" class="external text" href="https://www.usenix.org/system/files/conference/usenixsecurity15/sec15_supplement.pdf">"Dismantling Megamos Crypto: Wirelessly Lockpicking a Vehicle Immobilizer"</a> <span class="cs1-format">(PDF)</span>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20150910012742/https://www.usenix.org/system/files/conference/usenixsecurity15/sec15_supplement.pdf">Archived</a> <span class="cs1-format">(PDF)</span> from the original on 2015-09-10<span class="reference-accessdate">. Retrieved <span class="nowrap">February 4,</span> 2023</span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite id="CITEREFVerdultKooman2011" class="citation book cs1">Verdult, Roel; Kooman, Francois (February 2011). "Practical Attacks on NFC Enabled Cell Phones". <i>2011 Third International Workshop on Near Field Communication</i>. pp. <span class="nowrap">77–</span>82. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FNFC.2011.16">10.1109/NFC.2011.16</a>. <a href="Hdl_(identifier)" class="mw-redirect" title="Hdl (identifier)">hdl</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://hdl.handle.net/2066%2F92208">2066/92208</a></span>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>978-1-61284-176-2</bdi>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a> <a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:16296134">16296134</a>.</cite></span>
</li>
</ol></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-18" href="https://en.wikipedia.org/wiki/?title=Proxmark3&oldid=1301181433">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>