{"id":775,"date":"2015-11-09T12:34:08","date_gmt":"2015-11-09T12:34:08","guid":{"rendered":"http:\/\/nethemba.com\/cs\/?page_id=775"},"modified":"2019-08-19T09:39:36","modified_gmt":"2019-08-19T08:39:36","slug":"vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach","status":"publish","type":"page","link":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","title":{"rendered":"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch"},"content":{"rendered":"<p lang=\"cs-CZ\" align=\"left\">Analyzovali jsme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (Bratislavsk\u00e1 j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty, pr\u016fkazy Slovak Lines a jin\u00e9) na Slovensku a v \u010cech\u00e1ch zalo\u017een\u00e9 na technologii Mifare Classic. Pomoc\u00ed r\u016fzn\u00fdch technologick\u00fdch postup\u016f a na z\u00e1klad\u011b dostupn\u00fdch v\u011bdeck\u00fdch publikac\u00ed jsme prakticky demonstrovali mo\u017enost kompletn\u00edho z\u00edsk\u00e1n\u00ed p\u0159\u00edstupov\u00fdch kl\u00ed\u010d\u016f pou\u017e\u00edvan\u00fdch na \u0161ifrov\u00e1n\u00ed obsahu uveden\u00fdch karet. Prakticky jsme tak\u00e9 ov\u011b\u0159ili mo\u017enost pln\u00e9 kontroly nad testovan\u00fdmi \u010dipov\u00fdmi kartami v\u010detn\u011b kompletn\u00edho na\u010d\u00edtan\u00ed, modifikace a vytvo\u0159en\u00ed duplik\u00e1tu \u010dipov\u00e9 karty. Odhadli jsme n\u00e1klady na realizaci samotn\u00e9ho \u00fatoku a navrhli vhodn\u00e9 bezpe\u010dnostn\u00ed protiopat\u0159en\u00ed \u2013 od nejbezpe\u010dn\u011bj\u0161\u00edch (kompletn\u00ed sta\u017een\u00ed zraniteln\u00fdch karet a nahrazen\u00ed bezpe\u010dn\u011bj\u0161\u00edmi) a\u017e po m\u00e9n\u011b bezpe\u010dn\u00e9 (sv\u00e1z\u00e1n\u00ed UID karty s identitou cestuj\u00edc\u00edho a ov\u011b\u0159ov\u00e1ni platnosti UID karty, digit\u00e1ln\u00ed podepisov\u00e1n\u00ed obsahu, &#8222;decrement counter&#8220; \u0159e\u0161en\u00ed).<\/p>\n<p lang=\"cs-CZ\" align=\"left\">Pro demonstraci z\u00e1va\u017enosti uveden\u00e9 zranitelnosti a nutnosti sou\u010dasn\u00e9 karty p\u0159estat pou\u017e\u00edvat a nahradit bezpe\u010dn\u011bj\u0161\u00edmi, jsme vytvo\u0159ili a zve\u0159ejnili vlastn\u00ed implementaci \u201eoffline nested&#8220; \u00fatoku pomoc\u00ed kter\u00e9ho je mo\u017en\u00e9 \u00fatokem na kartu (bez pou\u017eit\u00ed legitimn\u00ed RFID \u010dte\u010dky) z\u00edskat v\u0161echny kl\u00ed\u010de ke v\u0161em sektor\u016fm.<\/p>\n<p lang=\"cs-CZ\" align=\"left\">\u00a0<a href=\"https:\/\/nethemba.com\/resources\/mifare-classic-zranitelnosti.pdf\"><strong>Ofici\u00e1ln\u00ed zve\u0159ejn\u011bn\u00ed zranitelnost\u00ed slovensk\u00fdch a \u010desk\u00fdch Mifare Classic karet<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/nethemba.com\/resources\/mifare-classic-slides.pdf\"><strong>Technick\u00e1 prezentace Mifare Classic zranitelnost\u00ed (v angli\u010dtin\u011b)<\/strong><\/a><\/p>\n<div id=\"__ss_4738269\"><iframe src=\"https:\/\/www.slideshare.net\/slideshow\/embed_code\/4738269\" width=\"425\" height=\"355\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/div>\n<p><a href=\"https:\/\/github.com\/nfc-tools\/mfoc\"><strong>Mifare Classic Offline Cracker (nov\u00e1 verze 0.09 pre libnfc 1.3.9)<\/strong><\/a><\/p>\n<p>(otestovan\u00e9 s <a href=\"http:\/\/code.google.com\/p\/crapto1\/\">crapto1<\/a>, <a href=\"http:\/\/www.libnfc.org\/\">libnfc<\/a> a <a href=\"http:\/\/www.touchatag.com\/\">Tikitag\/Touchatag \u010dte\u010dkou<\/a>)<\/p>\n<p><strong>Prezentace:<\/strong><\/p>\n<p><a href=\"http:\/\/200902.confidence.org.pl\/prelegenci\/pavol-luptak\/\">Confidence 2.0 ve Var\u0161ave<\/a><\/p>\n<p><a href=\"http:\/\/konference.iinfo.cz\/tib-2010\/program\/\">Trendy v Internetov\u00e9 bezpe\u010dnosti v Praze<\/a><\/p>\n<p><strong>Medi\u00e1ln\u00ed reakcie:<\/strong><br \/>\n<strong>SME<\/strong> <a href=\"http:\/\/pocitace.sme.sk\/c\/5080757\/cipove-karty-je-lahke-precitat.html\">\u010cipov\u00e9 karty je \u013eahk\u00e9 pre\u010d\u00edta\u0165<\/a><\/p>\n<p><strong>IT\u00a0News <\/strong><a href=\"http:\/\/www.itnews.sk\/rozhovory\/2009-10-27\/c129884-publikovane-vazne-zranitelnosti-v-slovenskych-a-ceskych-kartach-mifare\">Publikovan\u00e9 v\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch kart\u00e1ch Mifare<\/a><\/p>\n<p><strong>eFocus<\/strong> <a href=\"http:\/\/www.efocus.sk\/webcasty\/kategoria\/nazory\/clanok\/bezpecnost-cipovych-kariet\">Bezpe\u010dnos\u0165 \u010dipov\u00fdch kariet prelomen\u00e1<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Analyzovali jsme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (Bratislavsk\u00e1 j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty, pr\u016fkazy Slovak Lines a jin\u00e9) na Slovensku a v \u010cech\u00e1ch zalo\u017een\u00e9 na technologii Mifare Classic. Pomoc\u00ed r\u016fzn\u00fdch technologick\u00fdch postup\u016f a na z\u00e1klad\u011b dostupn\u00fdch v\u011bdeck\u00fdch publikac\u00ed jsme prakticky demonstrovali mo\u017enost kompletn\u00edho z\u00edsk\u00e1n\u00ed p\u0159\u00edstupov\u00fdch kl\u00ed\u010d\u016f pou\u017e\u00edvan\u00fdch na \u0161ifrov\u00e1n\u00ed obsahu uveden\u00fdch karet. Prakticky jsme tak\u00e9 ov\u011b\u0159ili mo\u017enost [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":524,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-775","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba<\/title>\n<meta name=\"description\" content=\"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/\" \/>\n<meta property=\"og:locale\" content=\"cs_CZ\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba\" \/>\n<meta property=\"og:description\" content=\"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:modified_time\" content=\"2019-08-19T08:39:36+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Odhadovan\u00e1 doba \u010dten\u00ed\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minuty\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\",\"name\":\"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"datePublished\":\"2015-11-09T12:34:08+00:00\",\"dateModified\":\"2019-08-19T08:39:36+00:00\",\"description\":\"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\\\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/#breadcrumb\"},\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/home-new-2025\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"O n\u00e1s\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/?page_id=319\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"V\u00fdzkum\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"cs\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","description":"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","og_locale":"cs_CZ","og_type":"article","og_title":"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","og_description":"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.","og_url":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_modified_time":"2019-08-19T08:39:36+00:00","twitter_card":"summary_large_image","twitter_site":"@nethemba","twitter_misc":{"Odhadovan\u00e1 doba \u010dten\u00ed":"2 minuty"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","url":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","name":"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"datePublished":"2015-11-09T12:34:08+00:00","dateModified":"2019-08-19T08:39:36+00:00","description":"Analyzujeme ve\u0159ejn\u011b pou\u017e\u00edvan\u00e9 karty (j\u00edzdenka, univerzitn\u00ed\/ISIC pr\u016fkazy, parkovac\u00ed karty) zalo\u017een\u00e9 na technologii Mifare Classic.","breadcrumb":{"@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/#breadcrumb"},"inLanguage":"cs","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/cs\/home-new-2025\/"},{"@type":"ListItem","position":2,"name":"O n\u00e1s","item":"https:\/\/nethemba.com\/cs\/?page_id=319"},{"@type":"ListItem","position":3,"name":"V\u00fdzkum","item":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/"},{"@type":"ListItem","position":4,"name":"V\u00e1\u017en\u00e9 zranitelnosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"cs"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/comments?post=775"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/775\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/524"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/media?parent=775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}