SlideShare a Scribd company logo
NFC
                      Play on Real World!!
                                                  Speaker : singi
                                             Facebook : @sjh21a
                                                   Hackerschool



www.CodeEngn.com
7th CodeEngn ReverseEngineering Conference
Table of Contents

• What is

• A Standard to

• Just For Fun with
What is NFC
        Near Field Communication
•   13.56 Mhz – RFID??
•   424 kbit/s
•   15mA (for Reading)
•   < 0.2m
•   Possible to Read/Write
Where is it? and will be used?
  – In SmartPhone (is not you?)
    • NFC USIM
  – Some Smart Card (ID Card, T-money, …)
  – Payment Service Like Square
    • Square used only iPhone. (need some device)
  – Bluetooth and wifi network
    • without pairing?
  – A Smart(really?) Devices!
    • NFC Keyboard – elecom@japan
NFC USIM! – in my phone
•              Galaxy S3 LTE (800,000)
•              Micro USIM + NFC
•              Spec?

Nexus S used Same NFC Chip
If you don’t have any smart phone…
  – Give up NFC Hacking L ?

  – Buy RF Module
    •   EBRF700
    •   Mifareⓡ, ISO 14443A, 14443B
    •   Support to Good Test Program
    •   Here!
A Standard to NFC
So, talking about smart card!
  – Do you remember MSR Card?
      • Find That Now open your pocket!


  –




   (contact)         (contactless)
  smart card has CPU and OS! = COS
                                  (Card Operation System)
A little bit details for smart card




VCC : Power Supply   GND : Ground
RST : Reset Signal   VPP : Program Voltage(Not used)
CLK : Clock Signal    I/O : Input / Output
A Kind of Smart Cards




ATQA : Answer To Request acc. To ISO/IEC 14443-4
SAK : Select Acknowledge, Type A
ATS : Answer To Select acc. To ISO/IEC 1443-4
                    This table is Not @ All!!
   http://ludovic.rousseau.free.fr/softwares/pcsc-tools/smartcard_list.txt
If you need IC chip information?

• Use NXP App with Android – [Example]
  – About Iphone? Find it J
About Republic of korea?
• A famous and friendly T-money




• T-money card : KSX6924 (based ISO14443)
• T-money SAM : KSX6923 (based ISO14443)
• Kssn.net (KS), but…L
세상은 돈이 전부다
!!!!!!!!!!!!!!!!!!!!!!!!!!!
standard.go.kr




No capture, No C&P, Just Read That!!
But, support to “Windows 32bit” L
Play on Real World!



 Just For Fun
If you shy girl & !boy, connect to Facebook. @sjh21a

                      Thanks.
Reference
 •    http://nfc-forum.org
 •    http://www.embeddedworld.co.kr/atl/view.asp?a_id=5495
 •    http://www.hidglobal.com/korean/page.php?page_id=21#won
 •    NFC 기술 및 인증동향 - 한국정보통신기술협회
 •    http://www.e2box.co.kr/ - EBRF700
 •    http://ko.wikipedia.org/wiki/%EC%8A%A4%EB%A7%88%ED%8A%B8%EC%
      B9%B4%EB%93%9C
 •    http://www.libnfc.org/documentation/hardware/tags/iso14443




www.CodeEngn.com
7th CodeEngn ReverseEngineering Conference

More Related Content

Similar to [2012 CodeEngn Conference 07] singi - NFC, Play on real world

DefCon 2012 - Near-Field Communication / RFID Hacking - Lee
DefCon 2012 - Near-Field Communication / RFID Hacking - LeeDefCon 2012 - Near-Field Communication / RFID Hacking - Lee
DefCon 2012 - Near-Field Communication / RFID Hacking - Lee
Michael Smith
 
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
PROIDEA
 

Similar to [2012 CodeEngn Conference 07] singi - NFC, Play on real world (20)

DefCon 2012 - Near-Field Communication / RFID Hacking - Lee
DefCon 2012 - Near-Field Communication / RFID Hacking - LeeDefCon 2012 - Near-Field Communication / RFID Hacking - Lee
DefCon 2012 - Near-Field Communication / RFID Hacking - Lee
 
ibeacon lunchtime talk
ibeacon lunchtime talkibeacon lunchtime talk
ibeacon lunchtime talk
 
Near field communication
Near field communicationNear field communication
Near field communication
 
Programmable watches
Programmable watchesProgrammable watches
Programmable watches
 
Nfc in wp8
Nfc in wp8Nfc in wp8
Nfc in wp8
 
NFC Bootcamp Seattle Day 2
NFC Bootcamp Seattle Day 2 NFC Bootcamp Seattle Day 2
NFC Bootcamp Seattle Day 2
 
A brief introduction to making your own (Internet of Things) Thing
A brief introduction to making your own (Internet of Things) ThingA brief introduction to making your own (Internet of Things) Thing
A brief introduction to making your own (Internet of Things) Thing
 
Raspberry Pi, Arduino and the Maker Movement
Raspberry Pi, Arduino and the Maker MovementRaspberry Pi, Arduino and the Maker Movement
Raspberry Pi, Arduino and the Maker Movement
 
PCB Business Card (Singapore Power)
PCB Business Card (Singapore Power)PCB Business Card (Singapore Power)
PCB Business Card (Singapore Power)
 
IoT Intro and Demo
IoT Intro and DemoIoT Intro and Demo
IoT Intro and Demo
 
A 2018 practical guide to hacking RFID/NFC
A 2018 practical guide to hacking RFID/NFCA 2018 practical guide to hacking RFID/NFC
A 2018 practical guide to hacking RFID/NFC
 
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
CONFidence 2018: A 2018 practical guide to hacking RFID/NFC (Sławomir Jasek)
 
A 2018 practical guide to hacking RFID/NFC
A 2018 practical guide to hacking RFID/NFCA 2018 practical guide to hacking RFID/NFC
A 2018 practical guide to hacking RFID/NFC
 
PCB Business Card
PCB Business CardPCB Business Card
PCB Business Card
 
Making Sense of Wireless Technologies
Making Sense of Wireless TechnologiesMaking Sense of Wireless Technologies
Making Sense of Wireless Technologies
 
Esp8266 NodeMCU
Esp8266 NodeMCUEsp8266 NodeMCU
Esp8266 NodeMCU
 
Warsjawa 2014 NFC - case study
Warsjawa 2014 NFC - case studyWarsjawa 2014 NFC - case study
Warsjawa 2014 NFC - case study
 
NFC & RFID on Android
NFC & RFID on AndroidNFC & RFID on Android
NFC & RFID on Android
 
#EEE - Field programmable gate array
#EEE - Field programmable gate array#EEE - Field programmable gate array
#EEE - Field programmable gate array
 
Porte à puce
Porte à pucePorte à puce
Porte à puce
 

More from GangSeok Lee

More from GangSeok Lee (20)

[2014 CodeEngn Conference 11] 남대현 - iOS MobileSafari Fuzzer 제작 및 Fuzzing
[2014 CodeEngn Conference 11] 남대현 - iOS MobileSafari Fuzzer 제작 및 Fuzzing[2014 CodeEngn Conference 11] 남대현 - iOS MobileSafari Fuzzer 제작 및 Fuzzing
[2014 CodeEngn Conference 11] 남대현 - iOS MobileSafari Fuzzer 제작 및 Fuzzing
 
[2014 CodeEngn Conference 11] 김기홍 - 빅데이터 기반 악성코드 자동 분석 플랫폼
[2014 CodeEngn Conference 11] 김기홍 - 빅데이터 기반 악성코드 자동 분석 플랫폼[2014 CodeEngn Conference 11] 김기홍 - 빅데이터 기반 악성코드 자동 분석 플랫폼
[2014 CodeEngn Conference 11] 김기홍 - 빅데이터 기반 악성코드 자동 분석 플랫폼
 
[2014 CodeEngn Conference 11] 박세한 - IE 1DAY Case Study KO
[2014 CodeEngn Conference 11] 박세한 - IE 1DAY Case Study KO[2014 CodeEngn Conference 11] 박세한 - IE 1DAY Case Study KO
[2014 CodeEngn Conference 11] 박세한 - IE 1DAY Case Study KO
 
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis KO
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis KO[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis KO
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis KO
 
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis EN
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis EN[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis EN
[2014 CodeEngn Conference 11] 김호빈 - Android Bootkit Analysis EN
 
[2014 CodeEngn Conference 11] 정든품바 - 웹성코드
[2014 CodeEngn Conference 11] 정든품바 - 웹성코드[2014 CodeEngn Conference 11] 정든품바 - 웹성코드
[2014 CodeEngn Conference 11] 정든품바 - 웹성코드
 
[2014 CodeEngn Conference 10] 정광운 - 안드로이드에서도 한번 후킹을 해볼까 (Hooking on Android)
[2014 CodeEngn Conference 10] 정광운 -  안드로이드에서도 한번 후킹을 해볼까 (Hooking on Android)[2014 CodeEngn Conference 10] 정광운 -  안드로이드에서도 한번 후킹을 해볼까 (Hooking on Android)
[2014 CodeEngn Conference 10] 정광운 - 안드로이드에서도 한번 후킹을 해볼까 (Hooking on Android)
 
[2014 CodeEngn Conference 10] 노용환 - 디버거 개발, 삽질기
[2014 CodeEngn Conference 10] 노용환 -  디버거 개발, 삽질기[2014 CodeEngn Conference 10] 노용환 -  디버거 개발, 삽질기
[2014 CodeEngn Conference 10] 노용환 - 디버거 개발, 삽질기
 
[2014 CodeEngn Conference 10] 심준보 - 급전이 필요합니다
[2014 CodeEngn Conference 10] 심준보 -  급전이 필요합니다[2014 CodeEngn Conference 10] 심준보 -  급전이 필요합니다
[2014 CodeEngn Conference 10] 심준보 - 급전이 필요합니다
 
[2013 CodeEngn Conference 09] x15kangx - MS Office 2010 문서 암호화 방식 분석 결과
[2013 CodeEngn Conference 09] x15kangx - MS Office 2010 문서 암호화 방식 분석 결과[2013 CodeEngn Conference 09] x15kangx - MS Office 2010 문서 암호화 방식 분석 결과
[2013 CodeEngn Conference 09] x15kangx - MS Office 2010 문서 암호화 방식 분석 결과
 
[2013 CodeEngn Conference 09] proneer - Malware Tracker
[2013 CodeEngn Conference 09] proneer - Malware Tracker[2013 CodeEngn Conference 09] proneer - Malware Tracker
[2013 CodeEngn Conference 09] proneer - Malware Tracker
 
[2013 CodeEngn Conference 09] BlueH4G - hooking and visualization
[2013 CodeEngn Conference 09] BlueH4G - hooking and visualization[2013 CodeEngn Conference 09] BlueH4G - hooking and visualization
[2013 CodeEngn Conference 09] BlueH4G - hooking and visualization
 
[2013 CodeEngn Conference 09] wh1ant - various tricks for linux remote exploits
[2013 CodeEngn Conference 09] wh1ant - various tricks for linux remote exploits[2013 CodeEngn Conference 09] wh1ant - various tricks for linux remote exploits
[2013 CodeEngn Conference 09] wh1ant - various tricks for linux remote exploits
 
[2013 CodeEngn Conference 09] 제갈공맹 - MS 원데이 취약점 분석 방법론
[2013 CodeEngn Conference 09] 제갈공맹 - MS 원데이 취약점 분석 방법론[2013 CodeEngn Conference 09] 제갈공맹 - MS 원데이 취약점 분석 방법론
[2013 CodeEngn Conference 09] 제갈공맹 - MS 원데이 취약점 분석 방법론
 
[2013 CodeEngn Conference 09] Park.Sam - 게임 해킹툴의 변칙적 공격 기법 분석
[2013 CodeEngn Conference 09] Park.Sam - 게임 해킹툴의 변칙적 공격 기법 분석[2013 CodeEngn Conference 09] Park.Sam - 게임 해킹툴의 변칙적 공격 기법 분석
[2013 CodeEngn Conference 09] Park.Sam - 게임 해킹툴의 변칙적 공격 기법 분석
 
[2013 CodeEngn Conference 09] 김홍진 - 보안컨설팅 이해 및 BoB 보안컨설팅 인턴쉽
[2013 CodeEngn Conference 09] 김홍진 - 보안컨설팅 이해 및 BoB 보안컨설팅 인턴쉽[2013 CodeEngn Conference 09] 김홍진 - 보안컨설팅 이해 및 BoB 보안컨설팅 인턴쉽
[2013 CodeEngn Conference 09] 김홍진 - 보안컨설팅 이해 및 BoB 보안컨설팅 인턴쉽
 
[2010 CodeEngn Conference 04] Max - Fighting against Botnet
[2010 CodeEngn Conference 04] Max - Fighting against Botnet[2010 CodeEngn Conference 04] Max - Fighting against Botnet
[2010 CodeEngn Conference 04] Max - Fighting against Botnet
 
[2010 CodeEngn Conference 04] window31 - Art of Keylogging 키보드보안과 관계없는 키로거들
[2010 CodeEngn Conference 04] window31 - Art of Keylogging 키보드보안과 관계없는 키로거들[2010 CodeEngn Conference 04] window31 - Art of Keylogging 키보드보안과 관계없는 키로거들
[2010 CodeEngn Conference 04] window31 - Art of Keylogging 키보드보안과 관계없는 키로거들
 
[2010 CodeEngn Conference 04] hahah - Defcon 18 CTF 문제풀이
[2010 CodeEngn Conference 04] hahah - Defcon 18 CTF 문제풀이[2010 CodeEngn Conference 04] hahah - Defcon 18 CTF 문제풀이
[2010 CodeEngn Conference 04] hahah - Defcon 18 CTF 문제풀이
 
[2009 CodeEngn Conference 03] externalist - Reversing Undocumented File Forma...
[2009 CodeEngn Conference 03] externalist - Reversing Undocumented File Forma...[2009 CodeEngn Conference 03] externalist - Reversing Undocumented File Forma...
[2009 CodeEngn Conference 03] externalist - Reversing Undocumented File Forma...
 

Recently uploaded

Recently uploaded (20)

Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi"Impact of front-end architecture on development cost", Viktor Turskyi
"Impact of front-end architecture on development cost", Viktor Turskyi
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 

[2012 CodeEngn Conference 07] singi - NFC, Play on real world

  • 1. NFC Play on Real World!! Speaker : singi Facebook : @sjh21a Hackerschool www.CodeEngn.com 7th CodeEngn ReverseEngineering Conference
  • 2. Table of Contents • What is • A Standard to • Just For Fun with
  • 3. What is NFC Near Field Communication • 13.56 Mhz – RFID?? • 424 kbit/s • 15mA (for Reading) • < 0.2m • Possible to Read/Write
  • 4. Where is it? and will be used? – In SmartPhone (is not you?) • NFC USIM – Some Smart Card (ID Card, T-money, …) – Payment Service Like Square • Square used only iPhone. (need some device) – Bluetooth and wifi network • without pairing? – A Smart(really?) Devices! • NFC Keyboard – elecom@japan
  • 5. NFC USIM! – in my phone • Galaxy S3 LTE (800,000) • Micro USIM + NFC • Spec? Nexus S used Same NFC Chip
  • 6. If you don’t have any smart phone… – Give up NFC Hacking L ? – Buy RF Module • EBRF700 • Mifareⓡ, ISO 14443A, 14443B • Support to Good Test Program • Here!
  • 8. So, talking about smart card! – Do you remember MSR Card? • Find That Now open your pocket! – (contact) (contactless) smart card has CPU and OS! = COS (Card Operation System)
  • 9. A little bit details for smart card VCC : Power Supply GND : Ground RST : Reset Signal VPP : Program Voltage(Not used) CLK : Clock Signal I/O : Input / Output
  • 10. A Kind of Smart Cards ATQA : Answer To Request acc. To ISO/IEC 14443-4 SAK : Select Acknowledge, Type A ATS : Answer To Select acc. To ISO/IEC 1443-4 This table is Not @ All!! http://ludovic.rousseau.free.fr/softwares/pcsc-tools/smartcard_list.txt
  • 11. If you need IC chip information? • Use NXP App with Android – [Example] – About Iphone? Find it J
  • 12. About Republic of korea? • A famous and friendly T-money • T-money card : KSX6924 (based ISO14443) • T-money SAM : KSX6923 (based ISO14443) • Kssn.net (KS), but…L
  • 14. standard.go.kr No capture, No C&P, Just Read That!! But, support to “Windows 32bit” L
  • 15. Play on Real World! Just For Fun
  • 16. If you shy girl & !boy, connect to Facebook. @sjh21a Thanks.
  • 17. Reference • http://nfc-forum.org • http://www.embeddedworld.co.kr/atl/view.asp?a_id=5495 • http://www.hidglobal.com/korean/page.php?page_id=21#won • NFC 기술 및 인증동향 - 한국정보통신기술협회 • http://www.e2box.co.kr/ - EBRF700 • http://ko.wikipedia.org/wiki/%EC%8A%A4%EB%A7%88%ED%8A%B8%EC% B9%B4%EB%93%9C • http://www.libnfc.org/documentation/hardware/tags/iso14443 www.CodeEngn.com 7th CodeEngn ReverseEngineering Conference