INTRODUCTION
Need to make perfect, undetectable clones of MIFARE Classic® 4K 4-Byte UID cards and tags ?
Our UID Modifiable "Magic" MIFARE Classic® Compatible 4K Gen3 allow for UID Modification, Block0 modification and permanently setting the UID - making them the only undetectable 4K cards availble.
| Feature | Information | Notes |
|---|---|---|
| Chipset | MIFARE Classic® Compatible | |
| Memory Size | 4K | |
| UID Size | 4 Byte / 7-byte | |
| UID Modifiable | ✔️ | Multiple times |
| Chip Generation | Gen 3 | Chipset Generation Guide |
| Write Method | APDU |
| UID Modifiable | Unlock Required | DirectWrite / Block 0 | APDU | One Time Write | Notes |
|---|---|---|---|---|---|
| ✔️ | ✔️ |
| Compatibility | UID | R/W | Config | Notes |
|---|---|---|---|---|
| Flipper Zero | ✔️ | |||
| Proxmark / iCopy-X | ✔️ | ✔️ | ✔️ | |
| Android & iOS | ✔️ | ✔️ | ✔️ | MTools BLE Recommended |
| LibNFC | ✔️ | ✔️ | ✔️ | Raw APDU commands required |
| ChameleonUltra | ✔️ | ✔️ | ✔️ | Requires Mtools BLE Premium |
Hands on: See the card in action
LibNFC - change UID
$ pn53x-tamashell
> 4a 01 00
> 42 02 90 FB CC CC 07 XX XX XX XX XX XX XX
Where xx xx xx xx xx xx xx is your target UID.
For 4-byte cards, your UID will be 4-bytes, for 7-byte cards, the UID will be 7-bytes.
LibNFC - Write to Block0
$ pn53x-tamashell
> 4a 01 00
> 42 02 90 F0 CC CC 10 04 12 19 c3 21 93 16 98 42 00 e3 20 00 00 00 00
Where 041219c3219316984200e32000000000 is the value for Block 0.
LibNFC - Lock the UID permanently:
$ pn53x-tamashell
> 4a 01 00
> 42 02 90 FD 11 11 00
Proxmark / iCopy-X - Change UID
hf mf gen3uid --uid 11223344556677 # 7-Byte UID: Replace 11223344556677 with the UID
hf mf gen3uid --uid 11223344` # 4-Byte UID: Replace 11223344 with the UID
Proxmark / iCopy-X - Set Block 0
hf mf gen3blk 041219c3219316984200e32000000000
# Replace 041219c3219316984200e32000000000 with the Block 0 Value
Proxmark / iCopy-X - Freeze UID
hf mf gen3freeze
# Freeze the currently set UID
Live Demonstration - Proxmark
Live Demonstration - LibNFC
Unbricking
"Soft-bricking" refers to when a magic card has been configured in a way that prevents it from being detected. Ways of soft-bricking tags include:
- Incorrect BCC
- Incorrect SAK
- Incorrect ATQA
- Incorrect ATS
- Incorrect ACL (Access Control) Values
Some "soft-brick" situations can be resolved with special commands. If your MIFARE Classic® Compatible 4K Gen3 UID Modifiable is "soft-bricked", you can try recovering it with the following methods:
With Proxmark / iCopy-X
hf mf gen3blk 11223344440804000102030405060708090A0B0C0D0E0F # 4-byte UID cards
hf mf gen3blk 112233445566770844000102030405060708090A0B0C0D # 7-byte UID cards
With LibNFC
4-byte UID$ pn53x-tamashell
> 4a 01 00
> 42 02 90 F0 CC CC 10 11 22 33 44 44 08 04 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F
7-byte UID
$ pn53x-tamashell
> 4a 01 00
> 42 02 90 F0 CC CC 10 11 22 33 44 55 66 77 08 44 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D
Via external reader/writer and MTOOLS
Select the "UID Changer" function in MTools, select "bricked" and run the task
IMPORTANT:
Lab401 cannot provide refunds under any circumstances for cards that were 'bricked' due to incorrect configurations.