Transform your Flipper Zero into a long range RFID attack platform. Instantly store, emulate and exfiltrate credentials on the move.
Designed by Phrack Labs in Australia
Buy with confidence.
Our Tindie Guarantee protects your purchase from fraud. Learn More
Overview The Flipper Zero is a swiss army knife for security researchers, but it has limitations when it comes to RFID. While the stock Flipper can read and emulate certain RFID tags, it lacks long …
Read More…The Flipper Zero is a swiss army knife for security researchers, but it has limitations when it comes to RFID. While the stock Flipper can read and emulate certain RFID tags, it lacks long range capture, storage, and exfiltration capabilities that would make it really useful in physical security testing. This is where the RFIDThief board for the Flipper Zero comes in - a custom RFID bridge module that transforms your Flipper Zero into a complete RFID attack platform.
The board presented at BSides Canberra 2024 bridges the Flipper Zero with the ESP-RFID-Tool to create a seamless, real-time RFID capture and replay system with offline exfiltration capabilities. Think of it as "ESP-RFID-Tool/ESPKey capabilities with Flipper Zero usability."
This board connects to an ESP-RFID-Tool:
watch the Demo:
The RFIDThief board features:
The RFIDThief board forms a bridge between the Flipper Zero and the ESP-RFID-Tool. The system consists of three main components:
ESP-RFID-Tool: This device connects directly to door access control readers via Wiegand lines. When a legitimate user swipes a card at the reader, the ESP-RFID-Tool captures the raw data, logs it, and makes it available through its HTTP API.
RFIDThief board: This custom board contains:
Flipper Zero: The main user interface running a custom .mjs application that provides:
The system supports eight API commands that can be sent from the Flipper Zero through the RFIDThief board to the ESP-RFID-Tool:
When a user swipes a badge at a door reader, the following sequence happens automatically:
The Flipper Zero then: - Saves the card data in its storage as an .rfid file - Shows the data in its GUI - Can replay the card data
The Flipper Zero can also send a pin, DOS or fuzz the reader at any time.
Each captured card is automatically written to the on-board NFC chip in NDEF URI format. This means: 1. Tap your NFC-capable phone to the board to retrieve the last captured credential 2. No need to power up the Flipper Zero or maintain a connection during exfiltration - no need to use the Flipper apps sharing function for sensitive data 3. Regardless of NFC all credentials are stored to SD card in flipper format upon capture
This system opens up several possibilities for physical security testing:
While the board is great at proxying and capturing credentials when an ESP-RFID-Tool is deployed in a mounted reader, its capabilities can be expanded by pairing it with a Tastic RFID Thief for on-the-move cred capture.
The Tastic RFID Thief originally created by bishop fox is a long-range weaponized RFID reader capable of reading cards at distances up to 50cm or more. By combining both tools, you can create a comprehensive credential harvesting system:
Extended Range Capture:
Bidirectional Attack:
Real-time Processing Pipeline:
Combined Exfil Options:
This approach gives both the mobility of the Tastic RFID Thief and the processing/replay capabilities of the ESP-RFID-Tool, which is a decent testing toolkit that works at every stage from credential harvesting, to capture, emulation and replay.
One useful feature of the board is the integrated IR blaster. When combined with the Flipper Zero's huge IR command library, this creates plenty of opportuinties for physical security testing:
Security Monitor Disruption: Many surveillance systems use IR remote control signals. The IR blaster can transmit power-off sequences or menu navigation commands to temporarily disable security monitors during red team operations.
CCTV Camera Control: Quite a few commercial CCTV cameras use IR protocols for configuration and control. The RFIDThief can transmit commands to:
Buy it @:
For use in legal, ethical, authorised penetration testing, red teaming or security research only. Do not modify, interfere or tamper with access control systems that you do not own.
No country selected, please select your country to see shipping options.
No rates are available for shipping to .
Enter your email address if you'd like to be notified when Flipper Zero RFIDThief can be shipped to you:
Thanks! We'll let you know when the seller adds shipping rates for your country.
Shipping Rate | Tracked | Ships From | First Item | Additional Items |
---|---|---|---|---|
:
|
Buy with confidence.
Our Tindie Guarantee protects your purchase from fraud. Learn More
$98.00
Free Shipping!
$8.65
Free Shipping!
$15.00
Free Shipping!
$31.98
Free Shipping!
By clicking Register, you confirm that you accept our Terms & Conditions
We recognize our top users by making them a Tindarian. Tindarians have access to secret & unreleased features.
We look for the most active & best members of the Tindie community, and invite them to join. There isn't a selection process or form to fill out. The only way to become a Tindarian is by being a nice & active member of the Tindie community!