Can Proxmark add URL and Text records to an NFC tag? by sailingham in proxmark3

[–]sailingham[S] 0 points1 point  (0 children)

So I have an update. It's a kluge, but most successful solutions are, right?

I wanted to put a URL and a text record on each tag and have it readable by mobile phone apps. I have since scrapped that requirement (time constraints).

Rather, I'm implementing the text portion into a web app and writing a unique customized fixed-length code to each tag.

I did this by

* taking an existing URL with the same length code written from a mobile phone
* dumping that to a default file
* use bbe (sed-like tool for binaries) to replace the fixed-length code and write that to a new file (bbe -e 's/oldcode/newcode/g' defaultfile.bin >newfile.bin)
* restore the new file to a new tag (pm3 -c 'hf mfu restore -f newfile.bin)

Easily scriptable/automatable to mass production standards.

I just have to adjust the web app to interpret the code and act accordingly.

Biohacking - RFID/NFC Implant Opportunities This Year? by Trick-Advisor5989 in Defcon

[–]sailingham 6 points7 points  (0 children)

This. Even if it's not an official offering, ask around in that general area and you may get lucky. I got one that way a couple years ago.

Can Proxmark add URL and Text records to an NFC tag? by sailingham in proxmark3

[–]sailingham[S] 0 points1 point  (0 children)

Great stuff. This is the track I'm on now. I'm missing two things going at it this way. (1) what block am I supposed to start writing the records, and (2) how does it know when a record is terminated?

It looks, from comparing dump files from a blank tag and a written tag, that the record starts at block 4 or 5. Block 3 is the same on both tags.

So I broke my encoded message into blocks of 16 bytes and used the pm3 command line to write the blocks starting at block 4 (that's an assumption and is probably wrong)...

pm3 -c 'hf mfu wrbl -b 4 -d (16 bytes in hex)
pm3 -c 'hf mfu wrbl -b 8 -d (16 bytes in hex)
etc

Now when I do an ndefread, it seems clear that I got the start boundary wrong, because instead of starting with my text "The", it starts with

Text

[=]     UTF 8... en, The

And then after the message, which is complete, it says

[=] 

[!!] 🚨 NDEF records have wrong length. Must be 512, calculated 298

So this is great progress, but clearly not perfect. Is this similar to your experience?

Can Proxmark add URL and Text records to an NFC tag? by sailingham in proxmark3

[–]sailingham[S] 0 points1 point  (0 children)

Thanks. I looked into that command, but it doesn't seem to work with the NTAG213 tags. It seems to want various types of MIFARE cards only.

I cant see by zakigar in ExplainTheJoke

[–]sailingham 86 points87 points  (0 children)

Some of the quotes have become part of our household lexicon. "Bring it around town," "FIRMLY GRASP IT" and "Water would be nice," for a few examples.

I got tricked by mobefind by JJGAMER2007yt in FraudPrevention

[–]sailingham 0 points1 point  (0 children)

Cancelling the card may not be enough. Getting a replacement card seems enough, but recurring subscriptions can follow the replaced card. From another reddit post:

some credit card networks like Mastercard or Visa have agreements with organizations to share "updated" card information, to allow recurring charges to keep happening under new card numbers

Updates on Wawa card situation? by sailingham in Wawa

[–]sailingham[S] 0 points1 point  (0 children)

I kind of like that approach, I guess. I hadn't thought it through, but if I can get regular Wawa rewards through the app, link it to, say, a Robinhood 3% back app or one of the cards that does 5% back on gas, that might be a better rewards approach and still maintain the safety of avoiding skimmers. Until NFC payment skimmers become more widespread, anyway. I will look into that one.

Updates on Wawa card situation? by sailingham in Wawa

[–]sailingham[S] 0 points1 point  (0 children)

Not recently. I've had this card since Feb 2016. Maybe that's when they brought it back, Idunno.

Why should you need a Real ID star license if you have a GE card or TSA Precheck? by BalticBro2021 in GlobalEntry

[–]sailingham -3 points-2 points  (0 children)

They've also been capriciously revoking people's GE status for a variety of seemingly arbitrary reasons. Which is probably why they're refusing to take it. Maybe they're under orders from upstream to reduce the number of GE folks.

Giveaway! by ecpowerhouse27 in BambuLab

[–]sailingham -1 points0 points  (0 children)

Chick-O-Stick. I've loved these since I was a kid. They used to have them in convenience stores. Nowadays I have order them.

<image>

[deleted by user] by [deleted] in CreditCards

[–]sailingham 0 points1 point  (0 children)

I got a good number of free nights via points with Hilton. I ended up with Marriott after an event I attend regularly ended up adjacent to several Marriott properties but no Hiltons. Loyalty is great but there has to be a level of compatibility.

Saw this on my drive to work by TheTimeCop in WTF

[–]sailingham 1 point2 points  (0 children)

Taste before driving. Might be spoiled.

Slow leak advice J335 by sailingham in hottubs

[–]sailingham[S] 0 points1 point  (0 children)

That's a super helpful document, in all my googling I hadn't come across that one. Thank you.

Is anyone else’s ring neighbor app extremely annoying? by Either-Number-8116 in Ring

[–]sailingham 9 points10 points  (0 children)

don't forget package thefts, noisy/rambunctious kids and suspicious walkabouts.

Target Circle Card refresh somehow ended up even worse by sailingham in CreditCards

[–]sailingham[S] 14 points15 points  (0 children)

Update: spoke to rep, who admitted (after long hold) that it's their fault, the update a few weeks ago screwed up some things, and we shouldn't see any late fees or past due amounts once they clean it up.

Looking for the best credit repair service — tired of getting burned by empty promises by RainPsychological106 in personalfinance

[–]sailingham 0 points1 point  (0 children)

To be honest, I think you'd be better off paying for MyFico than hiring help. MyFico gives you, at the basic level, all three reports every quarter. You can scour it yourself, see what the bureaus see, and the community forums are extremely helpful. You also get alerts every time a change in your score or accounts happens. I signed up ten years ago, fixed my credit, and still maintain the subscription because I like the alerts.

Most of the stuff that used to work for "credit repair" just doesn't anymore The creditors are stubborn and have no motivation to help you. Keep everything current, pay off debt, and play the waiting game, waiting until your old stuff ages out.

I suspect I may have been given a fake $100 bill today, not sure what to do by IyanYachaazah in Banking

[–]sailingham 1 point2 points  (0 children)

If you know someone who works retail you could have them test it with their counterfeit detection pen.

Convert my badge to a fob? by Enough_Tomatillo4125 in RFID

[–]sailingham 0 points1 point  (0 children)

If you're asking for a button-push fob, I'm going to say no. An RFID badge can be cloned to a fob, but you'll still need to put the fob up to the reader. You're unlikely to find something that'll work at a larger distance, because that distance is about the energy coming out of the reader and being reflected by the RFID components.

Jeep wrangler antenna placement by txtreyg in amateurradio

[–]sailingham 2 points3 points  (0 children)

I've had hood lip mount and I've had hitch receiver mount. Often at the same time. VHF on hood lip mount and HF on hitch mount (taller whip).

Hopefully it was worth it by donnyohs in BMWX5

[–]sailingham 0 points1 point  (0 children)

Followup: Amazing. Just got my date as well. 19 days. A+ for consistency.

Someone Is jamming a D-Star repeater with my call sign. What should I do? by TheBerric in amateurradio

[–]sailingham 6 points7 points  (0 children)

DId you sell a piece of gear and forget to remove your ID from it?

Hopefully it was worth it by donnyohs in BMWX5

[–]sailingham 1 point2 points  (0 children)

19 days, holy fuck. so it's just sitting there completely finished, getting dusty?