mfoc¶
Key recovery for MIFARE Classic cards with at least one known key
- Version recorded: 0.10.7
- Categories:
rfid - Upstream: https://github.com/nfc-tools/mfoc
What it does¶
Implements the 'nested' attack against MIFARE Classic: given one known sector key -- often a factory default that was never changed -- it recovers the remaining keys and dumps the card.
Why you would want it¶
MIFARE Classic's cipher has been broken since 2008 and the cards remain in very wide use. Demonstrating that on a card you hold is the clearest possible illustration of why deployed access control needs auditing.
Before it will work¶
A libnfc-supported reader and a card that still has at least one default key. Cards with every key changed need mfcuk instead, which is much slower.
How it installs¶
- apt:
mfoc
Known problems¶
Fails outright against MIFARE Plus, DESFire and any card with no default key left. Timing-sensitive: results vary with the reader, and a run that fails on one PN532 may succeed on another. Upstream has been quiet since 2018.
Keeping it current¶
- probe: apt policy
- strategy: apt_upgrade
Source: catalog/packages/mfoc.yaml