SSR-Labs · Security Research & Reversing
A Windows workbench for NFC/RFID, LF transponders, automotive immobilisers and secure smartcard chips — from the card on the reader to a verified crypto kernel. Nothing painted on: every engine runs against known test vectors. And yes — in a pinch it resets your toothbrush.
01 Main window
On startup the crypto self-test runs — every cipher and recovery engine against known test vectors. Green means verified, not claimed.
One click on Connect identifies the attached reader by USB VID/PID and loads exactly its capability profile. From here you open every tool.
The self-test is the suite's honesty anchor: 68 of 68 engines green, ~14,000 samples with zero failures.
02 HF / NFC on the reader
Scan, crack sectors, dump — and get the result as a colored sector map. Green = key found & read, so you instantly see where a card “opens up".
Auto-Pwn cracks Crypto-1 (nested / darkside / Fudan RF08S); the dump lands directly in the tool — hex editor, save and clone all use it immediately.
DESFire & NTAG are detected and read the right way: NTAG recon decodes NDEF, DESFire shows type, storage, app count and PICC key.
03 Pay-TV · Irdeto · Nagra
A pure knowledge & reference module: an ATR parser plus a registry of secure microcontrollers — from Atmel AT90SC through ST19 to NXP SmartMX. Know the chip and you know its crypto axis. No attack, no emulation — identification only.
During authorized reversing the ATR tells you which security MCU sits in the card — including its crypto co-processor and publicly documented properties.
It is deliberately purely informational: the module reads, classifies and cites — it emulates nothing and attacks nothing.
04 Signal & protocol
The PulsPirat breaks recorded radio bursts into waveform and bitstream — PT2262 & friends with decoded address and data word, right on the diagram.
Recorded pulses are matched against common OOK/ASK encoders; the tool proposes protocol, clock width and data word — handy for remotes, RF sockets and simple RKE frames.
05 GPU recovery
Five automotive ciphers, each with its own engine and — where needed — its own OpenCL kernel. No CUDA toolkit, no third-party headers, results checked against KAT.
The reader is only a nonce oracle — the actual recovery runs in the native PC engine. GPU results are always oracle-gated: recovered keys are checked against real data, never guessed.
06 Public vulnerabilities
No hand-waving — the suite runs known, publicly documented NFC weaknesses as reproducible PoCs, each with a source reference.
Reading and analysing cards is legitimate dual use. What the tool deliberately does not build: turnkey forgery buttons. PoCs run on owned hardware, from public/open-source material — no leaked keys.
07 LF transponders
A guided flow — identify → dump → sniff → recovery. The Proxmark reads; the tool shows the exact PM3 commands.
PROXMARK3 for crypto fobs (Hitag2/Megamos/DST) — reads & sniffs and shows the PM3 commands; the data feeds key recovery. No writing/cloning of these fobs (honestly: not testable without a real fob).
FR-RATEL / iCopy as a 125-kHz/13.56-MHz cloner for EM4100/HID/T5577 + Mifare — honestly labelled: no crypto auto-keyfob.
08 Transponder knowledge
~1,200 vehicle→chip mappings and the full LF family table — from Philips PCF through Texas DST40/80 to Megamos and Hitag2.
Every transponder ID with chip type, crypto class and vehicle context — e.g. ID48 = Megamos Crypto, ID46 = Hitag2, ID4D = Texas DST80.
Plus catalogs for transit worldwide (29 systems), access-control systems and Chinese chip makers — all searchable.
09 Crypto workbench
Enter values, click an action — every crypto engine verified against test vectors. Not an info sheet, but ciphers that actually compute.
This surface makes the suite verifiable: anyone can feed their own test vectors and check the result against the literature. That is exactly what separates real reversing from marketing.
10 Automotive
Authorized repair & proof of ownership: seed-key, EEPROM bench, Wiegand/HID, chip ID, VIN — all in one hub, all computing.
Reference lookups (transponder status, EEPROM chips, vehicle→chip) and the crypto self-test right beside it. OBD/ELM327 (VIN decode, fault codes, UDS SecurityAccess) is built but 🟡 work in progress — not yet verified against a real dongle/vehicle.
11 LF cloning
Read source → write target, with the path in view. Pick a template or auto from the keyfob ID — config decoder included.
The clone flow is deliberately visual: first dump the source, then prompt for a blank card, then write and verify — with a clear statement of which card or token type works as the target.
Same principle for UID → Magic and EM4100 → T5577: always source → target.
✚ Collaboration
The tool is built for authorized testing, repair and research from public/open-source material. What is verified is green; what still needs hardware is honestly marked 🟡 open.
Some engines are only waiting on real hardware for a cross-check — automotive keyfobs (Hitag2/Megamos/DST), iCLASS/LEGIC cards, Tonie/SLIX, OBD/ECU dumps, ISM transmitters. Anyone who contributes such hardware is credited by name as a sponsor in the tool and in this brief.
Money or hardware, from wherever — every contribution turns a 🟡 engine green.
Contact · info@ssr-labs.de · SSR-Labs.de
Yes, the tool resets your toothbrush. Philips Sonicare brush heads carry an NTAG213C that tells the handle “I'm worn out" — once the usage counter is full, it throttles. The password is derivable from the UID (CRC16-CCITT), so the suite computes it, resets the counter, and the 20-euro head lives on.
Same technology, same chip, same thinking as the immobiliser — only this time the attack vector is called plaque. The very same principle sits behind printer DRM, vacuum bags and 3D-printer spools: your device, your call.
SSR-Labs · Robert Schilke. NFC/RFID · LF transponders · automotive immobilisers · secure smartcard MCU. Version 3.98 “Empire Edition", as of 2026-09-14.
For authorized security testing, repair and education only. Sources: public/open-source only — no leaked specifications or keys. Full version: CAPABILITIES.en.html (EN) · CAPABILITIES.html (DE).