SSR-Labs · Security Research & Reversing

What the tool
can actually do.

A Windows workbench for NFC/RFID, LF transponders, automotive immobilisers and secure smartcard chips — from the card on the reader to a verified crypto kernel. Nothing painted on: every engine runs against known test vectors. And yes — in a pinch it resets your toothbrush.

Version 3.98 “Empire Edition" As of 2026-09-14 Author Robert Schilke Scope Authorized · public-source
68 / 68crypto self-tests green
4own GPU kernels
95+modules
20+calculators
17smartcard-MCU profiles
~14ksamples · 0 failures
At a glance
  1. Cockpit & self-test
  2. Live Card Lab
  3. Secure smartcard MCU
  4. PulsPirat signal analysis
  5. Local cracking (GPU)
  6. Integrated CVEs
  7. Keyfob Studio
  8. Transponder catalog
  9. Transponder editor
  10. Immobiliser & calculators
  11. Smart clone to T5577
SSR-Labs.de
info@ssr-labs.de
Authorized testing only
SSR-Labs Feature Handout01 · Cockpit

01 Main window

A cockpit that proves itself

On startup the crypto self-test runs — every cipher and recovery engine against known test vectors. Green means verified, not claimed.

SSR-Labs main window with 68/68 self-test log
Home screen. Live self-test log, reader selection (PN532 · Proxmark3 · FR-RATEL) and the module launcher.

What happens here

One click on Connect identifies the attached reader by USB VID/PID and loads exactly its capability profile. From here you open every tool.

The self-test is the suite's honesty anchor: 68 of 68 engines green, ~14,000 samples with zero failures.

Key points

  • Reader profiles instead of “one driver for all"
  • Self-test against golden KATs at startup
  • GPL-free: Crypto-1 recovery from own code
  • Runs fully offline — no cloud required
SSR-Labs Feature Handout02 · Live Card Lab

02 HF / NFC on the reader

Place a card, see its structure

Scan, crack sectors, dump — and get the result as a colored sector map. Green = key found & read, so you instantly see where a card “opens up".

Live Card Lab with colored 16-sector map, MIFARE 1K
MIFARE Classic 1K (UID 59FB0CB6) via Proxmark3 — 16 sectors with key-A/key-B status, ready to hand straight to the hex editor.

What it does

Auto-Pwn cracks Crypto-1 (nested / darkside / Fudan RF08S); the dump lands directly in the tool — hex editor, save and clone all use it immediately.

DESFire & NTAG are detected and read the right way: NTAG recon decodes NDEF, DESFire shows type, storage, app count and PICC key.

Chips

  • MIFARE Classic 1K/4K — Crypto-1 recovery
  • MIFARE Ultralight / NTAG — recon + NDEF
  • DESFire EV1/2/3 — hf mfdes info
  • Magic gen1a / gen2 (CUID) — clone target
Proxmark3PN532FR-RATEL
SSR-Labs Feature Handout03 · Secure MCU

03 Pay-TV · Irdeto · Nagra

Looking up secure smartcard MCUs

A pure knowledge & reference module: an ATR parser plus a registry of secure microcontrollers — from Atmel AT90SC through ST19 to NXP SmartMX. Know the chip and you know its crypto axis. No attack, no emulation — identification only.

Secure smartcard-MCU registry and ATR analysis
Smartcard-MCU registry. ATR breakdown, chip family, crypto co-processor and documented capabilities — every line backed by a public datasheet. To understand, not to break.

What for

During authorized reversing the ATR tells you which security MCU sits in the card — including its crypto co-processor and publicly documented properties.

It is deliberately purely informational: the module reads, classifies and cites — it emulates nothing and attacks nothing.

Listed

  • Atmel AT90SC · secureAVR
  • ST ST19 / ST23 / ST31 / ST33
  • NXP P5 SmartMX · P8 · SmartMX2
  • Infineon SLE66/70/78 · Emosyn TT80
SSR-Labs Feature Handout04 · PulsPirat

04 Signal & protocol

Make raw signals visible

The PulsPirat breaks recorded radio bursts into waveform and bitstream — PT2262 & friends with decoded address and data word, right on the diagram.

PulsPirat signal analysis with PT2262 waveform
Signal analysis. A PT2262 frame (0x5A30) as a timing waveform — sync, pulse widths and tri-state decode at a glance.

What it does

Recorded pulses are matched against common OOK/ASK encoders; the tool proposes protocol, clock width and data word — handy for remotes, RF sockets and simple RKE frames.

Detects e.g.

  • PT2262 / EV1527 tri-state & learning
  • Manchester & biphase decode
  • Pulse-width statistics & sync detection
  • Export of the decoded bits
SSR-Labs Feature Handout05 · Local cracking

05 GPU recovery

Key recovery from sniffed data

Five automotive ciphers, each with its own engine and — where needed — its own OpenCL kernel. No CUDA toolkit, no third-party headers, results checked against KAT.

Local cracking window with keyfob engine selection
Local cracking. Engine choice Hitag2 · DST40 · DST80 · Megamos · AUT64 — sniffed auths in, key out.

Engines

  • Hitag2 / ID46 — 2 auths → key; full 2³⁵ on GPU (~1.1 bn/s)
  • DST40 — 2⁴⁰ GPU brute (~135 M/s)
  • DST80 — full 80 bit via keyL/keyR downgrade
  • Megamos ID48 — em4x70 partial → 96-bit key
  • AUT64 / TK5561 — kG-from-IDCode + pbox recover

Principle

The reader is only a nonce oracle — the actual recovery runs in the native PC engine. GPU results are always oracle-gated: recovered keys are checked against real data, never guessed.

RTX-verifiedzero-dependency
SSR-Labs Feature Handout06 · CVEs

06 Public vulnerabilities

Integrated, documented CVEs

No hand-waving — the suite runs known, publicly documented NFC weaknesses as reproducible PoCs, each with a source reference.

Telenot compasX DESFire key derivation, CVE-2021-34600
Telenot compasX (CVE-2021-34600). Publicly documented DESFire key derivation from the UID — as a verifiable PoC inside the tool.

Included

  • Telenot compasX — DESFire key from UID CVE-2021-34600
  • KioSoft laundry systems
  • Fudan FM11RF08S — static-nested backdoor key
  • Be-Tech & Saflok — public-KDF PoC (owned HW)

Stance

Reading and analysing cards is legitimate dual use. What the tool deliberately does not build: turnkey forgery buttons. PoCs run on owned hardware, from public/open-source material — no leaked keys.

SSR-Labs Feature Handout07 · Keyfob Studio

07 LF transponders

Keyfobs: identify → read → recover

A guided flow — identify → dump → sniff → recovery. The Proxmark reads; the tool shows the exact PM3 commands.

Keyfob Studio flow window with PM3 and RATEL paths
Keyfob Studio. Pick a fob or resolve it via Vehicle→Chip; FDX-B pet-chip and iCLASS-CSN calculators included.

Two paths

PROXMARK3 for crypto fobs (Hitag2/Megamos/DST) — reads & sniffs and shows the PM3 commands; the data feeds key recovery. No writing/cloning of these fobs (honestly: not testable without a real fob).

FR-RATEL / iCopy as a 125-kHz/13.56-MHz cloner for EM4100/HID/T5577 + Mifare — honestly labelled: no crypto auto-keyfob.

Helper calculators

  • FDX-B pet chip → T5577 blocks
  • iCLASS CSN → diversified key
  • Automotive ID-XX & Megamos-ID48 analysis
  • Read data optionally → cracker
SSR-Labs Feature Handout08 · Catalog

08 Transponder knowledge

The transponder catalog

~1,200 vehicle→chip mappings and the full LF family table — from Philips PCF through Texas DST40/80 to Megamos and Hitag2.

Keyfob catalog dropdown with transponder IDs
ID catalog. ID33–ID8E & the 4D series with plain-text mapping (maker, cipher, typical brand) — so you don't have to google the chip mid-job.

What's inside

Every transponder ID with chip type, crypto class and vehicle context — e.g. ID48 = Megamos Crypto, ID46 = Hitag2, ID4D = Texas DST80.

Plus catalogs for transit worldwide (29 systems), access-control systems and Chinese chip makers — all searchable.

Examples

  • ID46 Hitag2 (PCF7936/41/46/47)
  • ID48 Megamos Crypto (JMA TP08)
  • ID4D Texas DST80 (crypto, 2nd gen)
  • ID8C Temic/Atmel e5561 — AUT64
SSR-Labs Feature Handout09 · Editor

09 Crypto workbench

Transponder editor: real ciphers

Enter values, click an action — every crypto engine verified against test vectors. Not an info sheet, but ciphers that actually compute.

Transponder editor with Hitag2, Megamos, DST, KeeLoq, iCLASS/AUT64
Transponder editor. Hitag2 keystream/verify/dictionary, Megamos recover/generate, DST40/DST80 response, KeeLoq hop-decode and iCLASS/AN10922 diversification — in one window.

Engines live

  • Hitag2 — keystream, verify, dictionary, auth recovery
  • Megamos ID48 — partial/FRN/GRN → full key
  • DST40 / DST80 — challenge → response
  • KeeLoq — encrypt/decrypt/hop-decode
  • iCLASS · AN10922 · AUT64 — key diversification

Why it matters

This surface makes the suite verifiable: anyone can feed their own test vectors and check the result against the literature. That is exactly what separates real reversing from marketing.

SSR-Labs Feature Handout10 · Immobiliser

10 Automotive

Immobiliser & calculators

Authorized repair & proof of ownership: seed-key, EEPROM bench, Wiegand/HID, chip ID, VIN — all in one hub, all computing.

Immobiliser/automotive window with seed-key calculators
Immobiliser hub + calculators. Seed→Key for Hyundai/Kia, PSA/Stellantis (~120 ECUs), GM PCM, plus Wiegand/HID and NXP chip identification.

Computes live

  • Seed-Key 0x27 — Hyundai/Kia, PSA, VAG SA2, Nissan
  • EEPROM bench — patch .bin, CRC/checksum, VAG Σ-fix
  • VAG SKC/VIN extracted from a cluster dump
  • Wiegand/HID H10301 → raw & decode

Diagnostics

Reference lookups (transponder status, EEPROM chips, vehicle→chip) and the crypto self-test right beside it. OBD/ELM327 (VIN decode, fault codes, UDS SecurityAccess) is built but 🟡 work in progress — not yet verified against a real dongle/vehicle.

public-source cryptoauthorized
SSR-Labs Feature Handout11 · Smart clone

11 LF cloning

Smart cloning to T5577

Read source → write target, with the path in view. Pick a template or auto from the keyfob ID — config decoder included.

Smart cloning to T5577, EM4100 auto-clone
Smart clone. Plan EM4100/EM410x by ID onto a T5577; decode the block-0 config (00148040 = EM4100, 00107060 = HID).

The flow

The clone flow is deliberately visual: first dump the source, then prompt for a blank card, then write and verify — with a clear statement of which card or token type works as the target.

Same principle for UID → Magic and EM4100 → T5577: always source → target.

Targets

  • T5577 — emulate EM4100/HID
  • Magic gen1a — cload
  • Magic gen2 / CUID — restore --force
  • Config decoder for block-0 checks
SSR-Labs Feature HandoutScope & contact

✚ Collaboration

Scope, honesty & sponsoring

The tool is built for authorized testing, repair and research from public/open-source material. What is verified is green; what still needs hardware is honestly marked 🟡 open.

Sponsoring & test hardware

Some engines are only waiting on real hardware for a cross-check — automotive keyfobs (Hitag2/Megamos/DST), iCLASS/LEGIC cards, Tonie/SLIX, OBD/ECU dumps, ISM transmitters. Anyone who contributes such hardware is credited by name as a sponsor in the tool and in this brief.

Money or hardware, from wherever — every contribution turns a 🟡 engine green.

Contact · info@ssr-labs.de · SSR-Labs.de

P.S. · Department of “because we can"

Yes, the tool resets your toothbrush. Philips Sonicare brush heads carry an NTAG213C that tells the handle “I'm worn out" — once the usage counter is full, it throttles. The password is derivable from the UID (CRC16-CCITT), so the suite computes it, resets the counter, and the 20-euro head lives on.

Same technology, same chip, same thinking as the immobiliser — only this time the attack vector is called plaque. The very same principle sits behind printer DRM, vacuum bags and 3D-printer spools: your device, your call.

SSR-Labs · Robert Schilke. NFC/RFID · LF transponders · automotive immobilisers · secure smartcard MCU. Version 3.98 “Empire Edition", as of 2026-09-14.

For authorized security testing, repair and education only. Sources: public/open-source only — no leaked specifications or keys. Full version: CAPABILITIES.en.html (EN) · CAPABILITIES.html (DE).