Hacking DIY amiibo cards

HiddenRambler

Well-Known Member
Member
Joined
Nov 20, 2015
Messages
148
Trophies
0
XP
651
Country
@_Tim_ or anyone else who may have gotten this to work.

Do you set the write password of the blank tags to match what the console will anticipates (To the key derived from UID)?

If you do: could you link or explain to how to do this on a blank tag? (The command for setting the password not the password itself)

If you do not then I assume the console doesn't care about the write password not being there?

thanks
 

asper

Well-Known Member
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,030
Country
United States
You need to send this ISO14443A APDU:

1B+4bytes-PWD+2bytes ISO14443A-CRC (7 bytes total).

and you should get 2bytes-PACK back as answer if the command got executed correctly.
I suggest you to find and app that is able to manage ALL the NTAG215 command set (not only ISO14443A standard commands because 1B command is not standard, it is NXP proprietary) or to send the raw command with or without automatically calculating the ISO14443A-CRC.
 
  • Like
Reactions: HiddenRambler

HiddenRambler

Well-Known Member
Member
Joined
Nov 20, 2015
Messages
148
Trophies
0
XP
651
Country
Hi Asper,

Thank you for that. I think I get what you're saying. I'm waiting for the blank tags so I'll need to play with it to fully understand it as I've not played NFC before.

I suggest you to find and app that is able to manage ALL the NTAG215 command set

Is there a known app for android which can do this?

many thanks for your reply.
 
  • Like
Reactions: TotalInsanity4

fiveighteen

Distractible Dabbler
Member
Joined
Jun 30, 2008
Messages
1,768
Trophies
2
XP
1,930
Country
United States
Would any of these work as the NTAG215 tag sticker? What would be the best to use (in terms of usability, not actually making it into a card)? (http://www.bc-robotics.com/product-category/nfc-rfid/)
I believe I found this in this same thread (too lazy to go look) and ordered 5 of them a few days ago.

http://nfctags.tagstand.com/collect...cker-circle-30mm-diameter?variant=10452334593

$1 each, no tax, shipping was $2.99. If you create an account, keep the tags in your cart and close the page they'll send you an email for 5% off.
 
  • Like
Reactions: TotalInsanity4

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,377
Trophies
4
Location
Space
XP
13,995
Country
Norway
DIY amiibo cards... created using blank NTAG215 tags and a little bit of dark magic :)

You need:
- a blank NTAG215 tag sticker (Shop NFC, AliExpress, ...)
- an amiibo dump (dump your own amiibo, download it, ...)
- a way to decrypt/encrypt amiibo dumps (amiibo decryption service, amiitool, ...)
- NFC reader/writer hardware (USB NFC reader/writer, Android smartphone with NFC, ...)
- compatible software to write an amiibo dump to a blank NTAG215 tag (I could not find any so wrote my own)
- a hex editor (HxD, UltraEdit, ...)
- a picture of the amiibo (download it)
- a printer (printer at home, printer at work, photo kiosk, ...)
- a ruler and a cutter knife

Steps:
- decrypt amiibo dump
- use hex editor to change UID in amiibo dump to UID of blank NTAG215 tag
- encrypt amiibo dump
- write amiibo dump to blank NTAG215 tag
- print amiibo picture and cut it out
- put NTAG215 tag sticker on the back of amiibo picture



diy_amiibo_cards.jpg

How much did those tags cost you and do you have a link to where you bought them? Trying to judge whether it's worth it to get an Amiiqo instead since it's reusable.
 

fiveighteen

Distractible Dabbler
Member
Joined
Jun 30, 2008
Messages
1,768
Trophies
2
XP
1,930
Country
United States
How much did those tags cost you and do you have a link to where you bought them? Trying to judge whether it's worth it to get an Amiiqo instead since it's reusable.
See my post above yours, or go look up NTAG215 on Shop NFC and AliExpress...

If you don't like coding, jumping through hoops, and possible hardware setup, it's much, much, more convenient to just get an Amiiqo (n^2, whatever).

I don't/won't even use these tags much, since I finally got the only Amiibo I wanted (Villager). I just want to do it for the fun of the experience. I know all the pieces of the puzzle are accessible, just have to find a way to put them together.
 
  • Like
Reactions: TotalInsanity4

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,797
Country
Brazil
I have some questions here :/
-we can use an skylanders base (and some computer program lol) to read/burn the data on these tags?
- we can do the sabe with skylanders figures?:B
O aliexpress have a great price but the seller's shipping make it expensiveXD at leats t get something just to have a try, since I have nothing to read amiibos actually ... I mean, no wiiU or new3ds/basem so no use for me yet :B maybe gift some friends xp) if only was freeshipping ...
 
  • Like
Reactions: TotalInsanity4

fraret

A puffin
Member
Joined
Nov 22, 2015
Messages
100
Trophies
0
Location
Interblag
Website
localhost
XP
151
Country
I have some questions here :/
-we can use an skylanders base (and some computer program lol) to read/burn the data on these tags?
- we can do the sabe with skylanders figures?:B
O aliexpress have a great price but the seller's shipping make it expensiveXD at leats t get something just to have a try, since I have nothing to read amiibos actually ... I mean, no wiiU or new3ds/basem so no use for me yet :B maybe gift some friends xp) if only was freeshipping ...
Idk if you can use the skylanders base, but you won't be able to create skylanders the same way than you create amiibos, because they use different encryptation.
 
  • Like
Reactions: Sliter

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,797
Country
Brazil
Idk if you can use the skylanders base, but you won't be able to create skylanders the same way than you create amiibos, because they use different encryptation.
I see .. they are less interesting than amiibos XD (I'm only interested because got a game :P lol)
But yeah the base ieda would be nice .. I mean .. can be an "cheaper" header/writter, right ?
 

Monado_III

Well-Known Member
Member
Joined
Feb 8, 2015
Messages
722
Trophies
0
Location
/dev/null
XP
1,443
Country
Canada
I believe I found this in this same thread (too lazy to go look) and ordered 5 of them a few days ago.

http://nfctags.tagstand.com/collect...cker-circle-30mm-diameter?variant=10452334593

$1 each, no tax, shipping was $2.99. If you create an account, keep the tags in your cart and close the page they'll send you an email for 5% off.
I have a gift card to that website that I linked to that I want to use, seeing as I have a RPi2 + other accesories already there's nothing else there that I want or need.
 
  • Like
Reactions: TotalInsanity4

dkabot

Better With Others' Systems Than Their Own
Member
Joined
Sep 9, 2014
Messages
1,042
Trophies
0
XP
626
Country
United States
I have a gift card to that website that I linked to that I want to use, seeing as I have a RPi2 + other accesories already there's nothing else there that I want or need.
I'd place my bets on no, as they say 1KB of storage and NTAG215 is around 5XX bytes.
 
  • Like
Reactions: Monado_III

fiveighteen

Distractible Dabbler
Member
Joined
Jun 30, 2008
Messages
1,768
Trophies
2
XP
1,930
Country
United States
Alright, so I'm equipped with everything I need to give this a shot today:
- blank NTAG215 tags
- Amiibo dump
- hex editor
- the key to encrypt it
- Android smartphone with AmiiWrite

1) I decrypted the Amiibo dump
2) I read the NTAG215 with Android app NFC TagInfo to get the 7-byte UID.
3) I opened the Amiibo dump in a hex editor...

Where is the location of the UID to change it?
 

javiMaD

Active Member
Newcomer
Joined
Jan 31, 2015
Messages
37
Trophies
0
Location
0's and 1's
XP
315
Country
Alright, so I'm equipped with everything I need to give this a shot today:
- blank NTAG215 tags
- Amiibo dump
- hex editor
- the key to encrypt it
- Android smartphone with AmiiWrite

1) I decrypted the Amiibo dump
2) I read the NTAG215 with Android app NFC TagInfo to get the 7-byte UID.
3) I opened the Amiibo dump in a hex editor...

Where is the location of the UID to change it?
First decrypt Amiibo and go to offset 0x1D4 (8 bytes UID BCC0)
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    ShinyLuxio @ ShinyLuxio: Hi there, it's any way to recover original LFCS if I don't have a NAND backup?