Hacking DIY amiibo cards

Julizi

Well-Known Member
Member
Joined
Jul 3, 2015
Messages
110
Trophies
0
Age
124
XP
348
Country
Germany
For dump I use Amiiqo app in Android or PC with https://github.com/socram8888/ulread this last recommended because it works to write blank tags
I don't understand. I don't have a NFC writer for PC at all so I have to do anything with my android smartphone. I heard it's possible, isn't it?
The amiiqo app doesn't work because it needs a blank tag to do so.
 

Julizi

Well-Known Member
Member
Joined
Jul 3, 2015
Messages
110
Trophies
0
Age
124
XP
348
Country
Germany
Everytime I want to scan an amiibo amiiqo app says that it found an unsupported tag which is really strange. So I concluded that it has to be a blank tag. Maybe it's my smartphones fault.
 
D

Deleted User

Guest
Then dumping a regular amiibo will work. Or, you can use that ISO site for the handheld console that amiibo work with, and get every Amiibo ever.
 

Julizi

Well-Known Member
Member
Joined
Jul 3, 2015
Messages
110
Trophies
0
Age
124
XP
348
Country
Germany
Naah I don't really wanna to use dat iso site. So just put my amiibo on my phone to dump with amiiqo app? It doesn't work maybe I should try on another smartphone.

EDIT: Same error on another S3 Mini. I will try on S4 this evening.
 
Last edited by Julizi,
D

Deleted User

Guest
Not at all. 215 has 540 bytes, Amiibo needs 540 bytes, and NTAG215s are 540 bytes. All others are lesser, on in the case with NTAG216s, too much
 

fiveighteen

Distractible Dabbler
Member
Joined
Jun 30, 2008
Messages
1,768
Trophies
2
XP
1,930
Country
United States
You need to send this ISO14443A APDU:

1B+4bytes-PWD+2bytes ISO14443A-CRC (7 bytes total).

and you should get 2bytes-PACK back as answer if the command got executed correctly.
I suggest you to find and app that is able to manage ALL the NTAG215 command set (not only ISO14443A standard commands because 1B command is not standard, it is NXP proprietary) or to send the raw command with or without automatically calculating the ISO14443A-CRC.
1) Decrypted the Amiibo dump
2) Read the NTAG215 with Android app NFC TagInfo to get the 7-byte UID.
3) Calculated the UID3 byte.
4) Opened the decrypted Amiibo dump in a hex editor and changed the UID to match the NTAG215
5) Created the keyfile for amiitool
6) Re-encrypted the Amiibo dump with "amiitool -e -k keys.bin -i decrypted.bin -o encrypted.bin"

Now where does this part that you posted come into play? I'm trying to make sure I have all of my ducks in a row so I don't waste any tags here.
 

Julizi

Well-Known Member
Member
Joined
Jul 3, 2015
Messages
110
Trophies
0
Age
124
XP
348
Country
Germany
I successfully dumped my amiibos via a Android S4 phone. Now I need to compile amiitool and try to decrypt them.
 
Last edited by Julizi,

Supercool330

Well-Known Member
Member
Joined
Sep 28, 2008
Messages
752
Trophies
1
XP
1,129
Country
United States
Now with the correct PACK0 and PACK1 (0x80, 0x80) I get an error 168-0413
I think there is another piece (hmac hash or something) that we are missing. I have checked everything about my clones, PWD, PACK, HMAC at 0x80, settings, etc. and everything checks out but they still don't work. As far as I can tell, 168-0413 is the Wii U equivalent of the 3DS 037-0524 error I have been getting. Has anybody successfully gotten a clone to work?

Not at all. 215 has 540 bytes, Amiibo needs 540 bytes, and NTAG215s are 540 bytes. All others are lesser, on in the case with NTAG216s, too much
Actually the problem isn't the size exactly, the problem is that the GET_VERSION command returns a different value on the NTAG216.
 
Last edited by Supercool330,

aracom

Well-Known Member
Member
Joined
Oct 1, 2015
Messages
476
Trophies
0
XP
363
Country
Gambia, The
I'd like to order a few tags as well and try them out, but it's a shame they're not rewritable. I don't want to pay 1$ for every false attempt, so I'm just gonna wait till the method is more refined.
 

Supercool330

Well-Known Member
Member
Joined
Sep 28, 2008
Messages
752
Trophies
1
XP
1,129
Country
United States
True, but he was using a modified version of amiitool that I'm guessing corrected one of the other signatures. My gut says that it is likely the 0x20 block at 0x34 as that is locked, and isn't used as part of the per amiibo key generation. It could also be the section at 0x60 using a different HMAC key though (like the master one, or another all together).

...They are rewritable!
No they aren't. Once you set the lock bits (which must be set to attempt a clone), the locked areas can't be rewritten.
 
Last edited by Supercool330,
  • Like
Reactions: aracom

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    "pine unf apple" doesn't count! Lol
  • Psionic Roshambo @ Psionic Roshambo:
    Employee code of conduct videos are awesome!!! Did you know eating the other employees is bad? I didn't know... Lol
    +1
  • AncientBoi @ AncientBoi:
    Anymore males there? :blush:
  • Psionic Roshambo @ Psionic Roshambo:
    All of us lol
  • Psionic Roshambo @ Psionic Roshambo:
    I got free every channel so that's awesome lol
    +1
  • AncientBoi @ AncientBoi:
    Give me ALL the gay pron channels, since you won't be watching them :blush::D
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Lol they exist?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Hmmm so Mario Does Luigi's plumbing is a bad movie? Lol
  • Psionic Roshambo @ Psionic Roshambo:
    These videos are soooo dry
  • Psionic Roshambo @ Psionic Roshambo:
    Please click all suspicious links sent your email
    +1
  • BigOnYa @ BigOnYa:
    What to do today? Cut grass for 3-4 hours, or just get drunk and play video games... Hmm
    +1
  • BigOnYa @ BigOnYa:
    I need a remote controlled mower, so I can sit on the couch and do both.
  • BigOnYa @ BigOnYa:
    Sounds good to me, video games and booze it is then.
    +1
  • denpafan @ denpafan:
    Good choice
    +1
  • BigOnYa @ BigOnYa:
    Now what to play, Starfield or Fallout4. And what to drink, beer or Whiskey and Coke. Such tough decisions.
  • BigOnYa @ BigOnYa:
    Looks like its whiskey & coke, only 4 beers left. And think ill start with Falllout. :grog:
  • rqkaiju2 @ rqkaiju2:
    THIS IMAGE IS SO SCARY WTF. THAT SURE AS HELL IS NOT A CAT THATS LIKE A FUCKING DEMON

    Untitled2.png
  • Psionic Roshambo @ Psionic Roshambo:
    Bonus points for running things over with the lawn mower?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Monster truck Lawn Mower extreme
    +1
  • BakerMan @ BakerMan:
    she was an apple appstore girl
    he was an uptodown boy
  • Psionic Roshambo @ Psionic Roshambo:
    He was an android boy
    Psionic Roshambo @ Psionic Roshambo: He was an android boy