{"id":777,"date":"2015-11-09T12:35:31","date_gmt":"2015-11-09T12:35:31","guid":{"rendered":"http:\/\/nethemba.com\/sk\/?page_id=777"},"modified":"2019-07-23T12:14:10","modified_gmt":"2019-07-23T11:14:10","slug":"vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach","status":"publish","type":"page","link":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","title":{"rendered":"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch"},"content":{"rendered":"<p lang=\"en-GB\">Analyzovali sme verejne pou\u017e\u00edvan\u00e9 \u010dipov\u00e9 karty (Bratislavsk\u00e1 elektri\u010denka, univerzitn\u00e9\/ISIC preukazy, parkovacie karty, preukazy Slovak Lines a in\u00e9) na Slovensku a v \u010cech\u00e1ch zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic. Pomocou viacer\u00fdch technologick\u00fdch postupov a na z\u00e1klade dostupn\u00fdch vedeck\u00fdch publik\u00e1ci\u00ed sme prakticky demon\u0161trovali mo\u017enos\u0165 kompletn\u00e9ho z\u00edskania pr\u00edstupov\u00fdch k\u013e\u00fa\u010dov pou\u017e\u00edvan\u00fdch na \u0161ifrovanie obsahu uveden\u00fdch kariet. Prakticky sme tie\u017e overili mo\u017enos\u0165 plnej kontroly nad testovan\u00fdmi \u010dipov\u00fdmi kartami vr\u00e1tane kompletn\u00e9ho pre\u010d\u00edtania, modifik\u00e1cie a vyklonovania. Odhadli sme n\u00e1klady na realiz\u00e1ciu samotn\u00e9ho \u00fatoku ako aj navrhli vhodn\u00e9 bezpe\u010dnostn\u00e9 protiopatrenia \u2013 od najbezpe\u010dnej\u0161\u00edch (kompletn\u00e9 stiahnutie zranite\u013en\u00fdch kariet a nahradenie bezpe\u010dnej\u0161\u00edmi) a\u017e po menej bezpe\u010dn\u00e9 (zviazanie UID karty s pasa\u017eierom, overovanie platnosti UID karty, digit\u00e1lne podpisovanie obsahu, &#8222;decrement counter&#8220; rie\u0161enie).<\/p>\n<p lang=\"en-GB\">Na demon\u0161tr\u00e1ciu z\u00e1va\u017enosti uvedenej zranite\u013enosti a nevyhnutnosti s\u00fa\u010dasn\u00e9 karty presta\u0165 pou\u017e\u00edva\u0165 a nahradi\u0165 bezpe\u010dnej\u0161\u00edmi, sme vytvorili a zverejnili vlastn\u00fa implement\u00e1ciu \u201eoffline nested&#8220; \u00fatoku pomocou ktor\u00e9ho je mo\u017en\u00e9 \u00fatokom na kartu (bez pou\u017eitia legit\u00edmnej RFID \u010d\u00edta\u010dky) z\u00edska\u0165 v\u0161etky k\u013e\u00fa\u010de ku v\u0161etk\u00fdm sektorom.<\/p>\n<p lang=\"en-GB\">\u00a0<a href=\"https:\/\/nethemba.com\/resources\/mifare-classic-zranitelnosti.pdf\"><strong>Ofici\u00e1lne zverejnenie zranite\u013enost\u00ed<\/strong> <strong>slovensk\u00fdch a \u010desk\u00fdch Mifare Classic kariet<\/strong><\/a><\/p>\n<p lang=\"en-GB\">\u00a0<a href=\"https:\/\/nethemba.com\/resources\/mifare-classic-slides.pdf\"><strong>Technick\u00e1 prezent\u00e1cia\u00a0Mifare Classic zranite\u013enost\u00ed (v angli\u010dtine)<\/strong><\/a><\/p>\n<div id=\"__ss_4738269\"><iframe src=\"https:\/\/www.slideshare.net\/slideshow\/embed_code\/4738269\" width=\"425\" height=\"355\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/div>\n<p lang=\"en-GB\"><a href=\"https:\/\/github.com\/nfc-tools\/mfoc\"><strong>Mifare Classic Offline Cracker\u00a0(nov\u00e1 verzia 0.09 pre libnfc 1.3.9)<\/strong><\/a><\/p>\n<p lang=\"en-GB\">(otestovan\u00e9 s <a href=\"http:\/\/code.google.com\/p\/crapto1\/\">crapto1<\/a>, <a href=\"http:\/\/www.libnfc.org\/\">libnfc<\/a> a <a href=\"http:\/\/www.touchatag.com\/\">Tikitag\/Touchatag \u010d\u00edta\u010dkou<\/a>)<\/p>\n<p lang=\"en-GB\">\u00a0<b>Prezent\u00e1cie:<\/b><\/p>\n<p><a href=\"http:\/\/200902.confidence.org.pl\/prelegenci\/pavol-luptak\/\">Confidence 2.0 vo Var\u0161ave<\/a><\/p>\n<p><a href=\"http:\/\/konference.iinfo.cz\/tib-2010\/program\/\">Trendy v Internetov\u00e9 bezpe\u010dnosti v Prahe<\/a><\/p>\n<p lang=\"en-GB\"><strong>Medi\u00e1lne reakcie:<\/strong><br \/>\n<strong>SME<\/strong> <a href=\"http:\/\/pocitace.sme.sk\/c\/5080757\/cipove-karty-je-lahke-precitat.html\">\u010cipov\u00e9 karty je \u013eahk\u00e9 pre\u010d\u00edta\u0165<\/a><\/p>\n<p lang=\"en-GB\"><strong>IT\u00a0News<\/strong> <a href=\"http:\/\/www.itnews.sk\/rozhovory\/2009-10-27\/c129884-publikovane-vazne-zranitelnosti-v-slovenskych-a-ceskych-kartach-mifare\">Publikovan\u00e9 v\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch kart\u00e1ch Mifare<\/a><\/p>\n<p lang=\"en-GB\"><strong>eFocus<\/strong> <a href=\"http:\/\/www.efocus.sk\/webcasty\/kategoria\/nazory\/clanok\/bezpecnost-cipovych-kariet\">Bezpe\u010dnos\u0165 \u010dipov\u00fdch kariet prelomen\u00e1<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Analyzovali sme verejne pou\u017e\u00edvan\u00e9 \u010dipov\u00e9 karty (Bratislavsk\u00e1 elektri\u010denka, univerzitn\u00e9\/ISIC preukazy, parkovacie karty, preukazy Slovak Lines a in\u00e9) na Slovensku a v \u010cech\u00e1ch zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic. Pomocou viacer\u00fdch technologick\u00fdch postupov a na z\u00e1klade dostupn\u00fdch vedeck\u00fdch publik\u00e1ci\u00ed sme prakticky demon\u0161trovali mo\u017enos\u0165 kompletn\u00e9ho z\u00edskania pr\u00edstupov\u00fdch k\u013e\u00fa\u010dov pou\u017e\u00edvan\u00fdch na \u0161ifrovanie obsahu uveden\u00fdch kariet. Prakticky sme tie\u017e overili [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":522,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-777","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba<\/title>\n<meta name=\"description\" content=\"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/\" \/>\n<meta property=\"og:locale\" content=\"sk_SK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba\" \/>\n<meta property=\"og:description\" content=\"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-23T11:14:10+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Predpokladan\u00fd \u010das \u010d\u00edtania\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 min\u00fata\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\",\"name\":\"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"datePublished\":\"2015-11-09T12:35:31+00:00\",\"dateModified\":\"2019-07-23T11:14:10+00:00\",\"description\":\"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\\\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/#breadcrumb\"},\"inLanguage\":\"sk-SK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/domov\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"O n\u00e1s\",\"item\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"V\u00fdskum\",\"item\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/o-nas-old\\\/vyskum\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sk-SK\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","description":"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","og_locale":"sk_SK","og_type":"article","og_title":"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","og_description":"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.","og_url":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_modified_time":"2019-07-23T11:14:10+00:00","twitter_card":"summary_large_image","twitter_site":"@nethemba","twitter_misc":{"Predpokladan\u00fd \u010das \u010d\u00edtania":"1 min\u00fata"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","url":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/","name":"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"datePublished":"2015-11-09T12:35:31+00:00","dateModified":"2019-07-23T11:14:10+00:00","description":"Bratislavsk\u00e9 elektri\u010denky, univerzitn\u00e9\/ISIC preukazy, parkovacie \u010dipov\u00e9 karty zalo\u017een\u00e9 na technol\u00f3gi\u00ed Mifare Classic sa n\u00e1m podarilo vyhackova\u0165 a n\u00e1js\u0165 zranite\u013enos\u0165.","breadcrumb":{"@id":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/#breadcrumb"},"inLanguage":"sk-SK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/vazne-zranitelnosti-v-slovenskych-a-ceskych-mifare-classic-cipovych-kartach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/sk\/domov\/"},{"@type":"ListItem","position":2,"name":"O n\u00e1s","item":"https:\/\/nethemba.com\/sk\/o-nas-old\/"},{"@type":"ListItem","position":3,"name":"V\u00fdskum","item":"https:\/\/nethemba.com\/sk\/o-nas-old\/vyskum\/"},{"@type":"ListItem","position":4,"name":"V\u00e1\u017ene zranite\u013enosti v slovensk\u00fdch a \u010desk\u00fdch Mifare Classic \u010dipov\u00fdch kart\u00e1ch"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sk-SK"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/pages\/777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/comments?post=777"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/pages\/777\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/pages\/522"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/media?parent=777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}