Profile: rfid¶
RFID and NFC — card protocols, readers, and the tooling to study them
Stage: post-1.0
Who it is for¶
Someone studying RFID and NFC cards: how 13.56 MHz and 125 kHz credentials work, what a reader reports, and how weak schemes fail.
At a glance¶
| Stage | post-1.0 |
| Units | 6 |
| Disk | under 50 MB from apt; the Proxmark3 build is larger |
| Hardware | A card reader (a PN53x NFC reader, a PC/SC reader or a Proxmark3) and cards you own or are authorised to test. |
| Consent | none |
| Install | hammunition install rfid |
What it installs¶
Tools for two different card worlds. Five packages cover 13.56 MHz over libnfc and PC/SC -- reader diagnostics, MIFARE Classic key recovery, and DESFire management -- and one, the Proxmark3 client, covers both 13.56 MHz and the 125 kHz low-frequency cards nothing else here reaches.
Disk footprint: Under 50 MB from apt. The Proxmark3 source build is larger and pulls an ARM cross-compiler, because the client ships the firmware images it flashes; on Kali it is a package like any other.
Why these belong together¶
They are the same domain at two frequencies and two price points. The libnfc side runs on a reader costing a few pounds and is where most people start; the Proxmark3 is purpose-built hardware that reaches the low-frequency access-control cards actually deployed in buildings. Studying one without the other gives half the picture, and the two families of tool do not overlap in what they can talk to.
Packages (6)¶
libnfc-bin, libfreefare-bin, mfoc, mfcuk, pcsc-tools, proxmark3
What it deliberately excludes¶
Anything that is not card-range. Long-range RFID, UHF and the 900 MHz inventory-tag world are a different domain again and are not here. Nothing aimed at cloning credentials for use rather than for study, and no pre-loaded key dictionaries -- the tools take those as input if you supply them. Also excluded is the vendor tooling for proprietary readers, which is neither free software nor packaged anywhere.
Install it¶
Read the plan first. It changes nothing and prints every package, build, file and system change, and every consent gate you will meet:
Then do it. The engine asks for your sudo password once, near the start,
and shows the same plan again before it asks you to confirm:
A member your machine cannot take is deferred by name and the rest installs (D-039); the plan lists each under Will NOT happen, with the reason and the command that fixes it. Installation explains how to read every part of the plan.
What you configure by hand afterward¶
Membership of dialout and plugdev for the Proxmark3, from the hardware catalog. Serial PN53x readers need an entry in /etc/nfc/libnfc.conf; USB ones usually do not. The one that catches everyone: pcscd and libnfc compete for the same reader, whichever claims it first wins, and the other reports no device at all -- stop pcscd if libnfc tools suddenly stop seeing your hardware.
Your first ten minutes¶
- Read the plan:
hammunition install rfid --dry-run. The Proxmark3 client builds from source on most targets and pulls an ARM cross-compiler for the firmware images it ships. - Install:
hammunition install rfid. - Apply device rules:
hammunition hardware apply, then log out and back in, sodialoutandplugdevreach your session. - Plug a reader in and check it is seen:
nfc-listfor a libnfc reader, orpcsc_scanfor a PC/SC one. - If one tool stops seeing the reader, stop
pcscd; libnfc and pcscd compete for the same device and whichever claims it first wins. - Test only cards you own or have written permission to test.
Take it off again¶
This removes what Hammunition itself installed and nothing else. It does not remove dependencies apt pulled in, group memberships or configuration files it wrote; the plan says so and the transaction log records them (D-004).