Be the first to know about our latest articles!

Subscribe
2/28/2018

Copy or Clone Your Prox HID ID Card

⚠️Important update: as many as 80% of all keycards currently used within commercial facilities may be prone to hacking due to protocol vulnerabilities. We are launching a free service (U.S. and Canada only for now) where we assess if your cards are secure. Learn more here!

Since we’ve covered advanced ways to hack HID cards in this previous post, we wanted to show ways cloning or copying a card in a day-to-day kind of environment with standard proximity (prox) cards which are based on 125khz . There are cloning services out there (like Clone my Key) who charge $20 per RFID / Prox card clone. Plus you need to send it in and wait for it. At the same time you might be able to buy a clone machine off of ebay or Amazon (read below) which is faster and cheaper.

What we are trying is to explain it in the most easy to understand format - even easier than on pages like Proxclone.

Types of ID card hacks

To be upfront: You won’t be able to clone any card like this. There are different card formats and depending on the type (see e.g. prox card hack from 2004 (!), long range card hack, iclass or wiegand hacks) you might need different- and more advanced methods. The differences lay in the depth of encryption, e.g. in the picture below we have an iClass encryption which shows the challenge - response from an iClass card and iClass reader - and here how it’s hacked. Read more about different types of HID cards here.

iClass Authentication

Easy, fast way to copy or clone your ID card

The lowest cost, easiest way to quickly copy a simple keycard is to just get one of the RFID card ID copier (also called RFID 125Khz EM4100 ID Card Copier) from Amazon ($27 with free shipping) or eBay ($10.99 with free shipping).

Here are the instructions: “Easy to use : 1. Push the read button to read the card. 2. Take a new card and write on it. Very easy and comvenient :)” see it in action here:

Advance ways to build a key copy machine

If you are ready for more advanced prox cards, here is a schematic for a reader / writer of RFID prox cards pdf to download which as 4 main components:

1) The clocking circuit, which generates a 4 Mhz clock for the microcontroller and a 125Khz carrier signal for the RFID interface.

2) The RF front end consisting of a tuned LC resonator and an AM peak detector

3) A series of low pass and band pass filters to extract the 12.5Khz and 15.6Khz FSK signals.

4) The SX28 microcontroller which performs the following functions: LCD initialization, Decoding and storage of the FSK data from the op amp filter output. Parsing and formatting of the card data. Driving the LCD display. Programming the clone card by modulating the 125 Khz carrier (per the T55x7 datasheet).

Be aware: This is really only applicable for simple prox RFID cards. It will not work for more advanced cards where we’d need to build a better keycard copy machine. If you’d like to better understand RFID System Design, download the pdf guide here.

Here are some more advance links:

RFID Vendor Information

Atmel Corporation RFID Info

Videos

BlackHat Proximity Card Cloning Demonstration

RFID Hacking Demo - Sacramento Capitol Building

RFID Projects/Forums

Proxmark RFID Test Instrument

Arduino LF RFID Tag Spoofer

RFID Proximity Security System - Final Design Project

RFIDToys Forum

RFIDiot Library

Submit your content idea!

Get featured on the blog and tell us your unique story.

Access Your Office the Modern Way

Discover how we provide secure access to hundreds of fast-growing companies like yours

Kisi Reader

Download the Access Control Guide

Related Articles

Stay updated with Kisi about news and feature releases

Free access to our best guides, industry insights and more

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
How to Guide
Useful Resources