{"id":372,"date":"2017-04-09T13:32:14","date_gmt":"2017-04-09T13:32:14","guid":{"rendered":"http:\/\/www.inguardians.com\/?p=86"},"modified":"2018-11-30T21:08:33","modified_gmt":"2018-11-30T21:08:33","slug":"make-your-tastic-fan-tastic","status":"publish","type":"post","link":"https:\/\/zed.inguardians.com\/blog\/make-your-tastic-fan-tastic\/","title":{"rendered":"Make your Tastic Fan-Tastic"},"content":{"rendered":"

[et_pb_section admin_label=”section” transparent_background=”off” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”on” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”off” custom_width_px=”1080px” custom_width_percent=”80%” make_equal=”off” use_custom_gutter=”off” fullwidth=”off” specialty=”off” disabled=”off”][et_pb_row admin_label=”row” make_fullwidth=”off” use_custom_width=”off” width_unit=”off” custom_width_px=”1080px” custom_width_percent=”80%” use_custom_gutter=”off” gutter_width=”3″ padding_mobile=”off” allow_player_pause=”off” parallax=”off” parallax_method=”on” make_equal=”off” column_padding_mobile=”on” parallax_1=”off” parallax_method_1=”on” parallax_2=”off” parallax_method_2=”on” parallax_3=”off” parallax_method_3=”on” parallax_4=”off” parallax_method_4=”on” disabled=”off”][et_pb_column type=”4_4″][et_pb_text admin_label=”Text” background_layout=”light” text_orientation=”left” use_border_color=”off” border_style=”solid” disabled=”off” border_color=”#ffffff”]<\/p>\n

Here at InGuardians, we are huge fans of the Tastic HiD card long-range reader. Designed and implemented by Bishop Fox, this long-range RFID reader allows us to silently and stealthily acquire sensitive data from things like employee badges, and has become a huge component of our physical penetration testing and red team methodology. For example, using the Tastic to obtain card data is great for cloning access badges, and obtaining HiD facility codes helps immensely when brute-forcing to gain elevated access.<\/p>\n

Part of why it\u2019s so convenient is that it\u2019s easy to smuggle on-site in an inexpensive and inconspicuous backpack that we found on sale at our local Swedish flat pack furniture store. Not only does it fit perfectly, it even allows for a little bit of spare room for transporting additional goodies to and from the engagement, including that always useful piece of kit: extra batteries.<\/p>\n

There is nothing worse than being in the middle of a recon mission and discovering the batteries are dead, especially when you know you could have just scored some awesome info. Plus, when you need to find some more batteries when on-site? This can also be its own kind of painful. Have you ever had to buy a pack of 25 name-brand AA batteries at the local bodega? Hear that sound? That\u2019s my wallet screaming.<\/p>\n

Carrying supplementary batteries is absolutely essential when using the Tastic. If it has a drawback, it\u2019s that it\u2019s a power hog.<\/p>\n

There has to be a better way, we thought.<\/p>\n

And there is!<\/p>\n

Please understand, we are far from criticizing the Tastic. It is a fantastic design that uses off-the-shelf, readily available parts in a unique and novel manner. It\u2019s only that we\u2019ve we found a way to make it better for our uses and want to share that with you.<\/p>\n

The best improvement we\u2019ve made to the battery situation is to switch to using six 18650 type rechargeable Lithium-ion batteries.<\/p>\n

There are several advantages to upgrading the battery component. Lithium-ion batteries are great for electronics, as they typically have higher capacities than their alkaline counterparts. For example, while various batteries and manufacturers can have different milliamp hour (mAh) ratings, the output voltage for 18650 batteries should run 3.7 volts, and typically around 2800 milliamp hours. Even as the standard brand name alkaline AA batteries only operate at 1.5 volts, and approximately 1800 mAh. Why is this mAh rating important? In simple terms, the larger the mAh, the longer the battery will last under load. (This a massive oversimplification of the complex math and several studies behind the discharge rate, but it will suffice for the purposes of this build.)<\/p>\n

Aside from output, basic operating costs are also a factor. Although rechargeable lithium ion batteries tend to cost a little more than standard alkaline batteries up front, over the long haul, these costs balance in your favor because you won\u2019t need to replace rechargeable batteries nearly as often as alkaline cells. For a similar cost of one or two painful trips to the bodega, (that will only net you a single-use tool which has to be discarded after, adding to landfill waste, too), you can have two sets of rechargeable batteries and a charger. To sweeten that deal, consider how the math only gets better the more you use the device.<\/p>\n

\"\"<\/center><\/p>\n
Figure 0x0: We can charge all of the batteries we need with this monster!<\/div>\n

 <\/p>\n

What\u2019s more, instead of purchasing the 18650 batteries directly from a supplier, they can be recycled from a number of sources for virtually free. One of our favorite sources is old laptop batteries. In several cases, we\u2019ve found that folks are willing to give their old, \u201dnon-working\u201d laptop batteries to us for free instead of having to pay for recycling. These larger batteries are often full of 18650 cells with only one or two that have failed. This renders the battery configuration too ineffective to power a laptop for longer periods of time, but with careful disassembly, harvesting cells from laptop batteries can result in an over-abundance of 3.7V fun! (Yes, we really do this kind of thing for fun, don\u2019t you?)<\/p>\n

\"\"<\/center><\/p>\n
Figure 0x1: Another fruitful harvest of 18650 cells.<\/div>\n

 <\/p>\n

Another advantage is increased read range. In most cases, providing more power to a radio will increase the effective radio power, thus boosting range, too! The standard Tastic implementation provides 18V, but because the 18650 batteries produce more than double the voltage of standard Alkaline batteries (3.7V versus 1.5V), we can supply about 24V by wiring 6 of the 18650\u2019s in series!<\/p>\n

It only requires a few minor technical changes to modify the original Tastic design to use the 18650 batteries, too. First, you need to find and install appropriate battery holders. We were lucky and had a few left over, some re-purposed, from the \u201cIf it Fits it Ships\u201d project. (Note: They were acquired from a Chinese importer for about $0.30 each. Super cheap, but we absolutely got what we paid for, as they needed a little help from some solder to reliably accept our batteries.)<\/p>\n

Once you have battery holders, be careful where you put them! The 18650 have a larger diameter than AA batteries, so be careful to place them out of the way of the LCD display, as reassembling the device with 18650 batteries behind the screen will result in one less LCD. If you don\u2019t trust us on this one, you can ask the broken LCD on our workbench how it feels right about now. (The answer is sad. Very, very sad.)<\/p>\n

\"\"<\/center><\/p>\n
Figure 0x2: 18650 batteries installed.<\/div>\n

 <\/p>\n

Second, swap out the resistors on the LM317LZ variable voltage regulator. Since\u00a0we are increasing the input voltage, we need to adjust the resistors to maintain the appropriate output voltage to correctly power the Arduino and the LCD display. Using the LM317LZ calculator and the reference tables at http:\/\/www.reuk.co.uk\/LM317-Voltage-Calculator.htm<\/a><\/em>, we swapped out R1 to be 370 ohms and R2 to 2700 ohms (by wiring a 2200 and 500 ohm resistor in series) to deliver 10.37V to the Arduino Vin<\/em> pin.<\/p>\n

\"\"<\/center><\/p>\n
Figure 0x3: Swapped R1 and R2. Yes, on a breadboard for modularity and upgrades.<\/div>\n

 <\/p>\n

Finally, we need to make sure to update the jumper settings on the MaxiProx by shunting pins 3 and 3 to reflect the new input voltage to account for increasing it from 18V to 24V.<\/p>\n

\"\"<\/center><\/p>\n
Figure 0x4: Forgetting to change this could let the \u201cmagic smoke\u201d out.<\/div>\n

 <\/p>\n

Now that everything is set, fire it up and give it a test to be sure you didn\u2019t do anything wrong. If it is working as expected, button it back up and you are off to the races!<\/p>\n

Enjoy combining your new found savings and longer read range for pwnage!<\/p>\n

Over and out.<\/p>\n

– L<\/p>\n

[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"

Here at InGuardians, we are huge fans of the Tastic HiD card long-range reader. Designed and implemented by Bishop Fox, this long-range RFID reader allows us to silently and stealthily acquire sensitive data from things like employee badges, and has become a huge component of our physical penetration testing and red team methodology. For example, […]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"Here at InGuardians, we are huge fans of the Tastic HiD card long-range reader. Designed and implemented by Bishop Fox, this long-range RFID reader allows us to silently and stealthily acquire sensitive data from things like employee badges, and has become a huge component of our physical penetration testing and red team methodology. For example, using the Tastic to obtain card data is great for cloning access badges, and obtaining HiD facility codes helps immensely when brute-forcing to gain elevated access.\r\n\r\nPart of why it\u2019s so convenient is that it\u2019s easy to smuggle on-site in an inexpensive and inconspicuous backpack that we found on sale at our local Swedish flat pack furniture store. Not only does it fit perfectly, it even allows for a little bit of spare room for transporting additional goodies to and from the engagement, including that always useful piece of kit: extra batteries.\r\n\r\nThere is nothing worse than being in the middle of a recon mission and discovering the batteries are dead, especially when you know you could have just scored some awesome info. Plus, when you need to find some more batteries when on-site? This can also be its own kind of painful. Have you ever had to buy a pack of 25 name-brand AA batteries at the local bodega? Hear that sound? That\u2019s my wallet screaming.\r\n\r\nCarrying supplementary batteries is absolutely essential when using the Tastic. If it has a drawback, it\u2019s that it\u2019s a power hog.\r\n\r\nThere has to be a better way, we thought.\r\n\r\nAnd there is!\r\n\r\nPlease understand, we are far from criticizing the Tastic. It is a fantastic design that uses off-the-shelf, readily available parts in a unique and novel manner. It\u2019s only that we\u2019ve we found a way to make it better for our uses and want to share that with you.\r\n\r\nThe best improvement we\u2019ve made to the battery situation is to switch to using six 18650 type rechargeable Lithium-ion batteries.\r\n\r\nThere are several advantages to upgrading the battery component. Lithium-ion batteries are great for electronics, as they typically have higher capacities than their alkaline counterparts. For example, while various batteries and manufacturers can have different milliamp hour (mAh) ratings, the output voltage for 18650 batteries should run 3.7 volts, and typically around 2800 milliamp hours. Even as the standard brand name alkaline AA batteries only operate at 1.5 volts, and approximately 1800 mAh. Why is this mAh rating important? In simple terms, the larger the mAh, the longer the battery will last under load. (This a massive oversimplification of the complex math and several studies behind the discharge rate, but it will suffice for the purposes of this build.)\r\n\r\nAside from output, basic operating costs are also a factor. Although rechargeable lithium ion batteries tend to cost a little more than standard alkaline batteries up front, over the long haul, these costs balance in your favor because you won\u2019t need to replace rechargeable batteries nearly as often as alkaline cells. For a similar cost of one or two painful trips to the bodega, (which will only net you a single-use tool which has to be discarded after, adding to landfill waste, too), you can have two sets of rechargeable batteries and a charger. To sweeten that deal, consider how the math only gets better the more you use the device.\r\n\r\n

\"\"<\/center>\r\n
Figure 0x0: We can charge all of the batteries we need with this monster!<\/div>\r\n\u00a0\r\n\r\nWhat\u2019s more, instead of purchasing the 18650 batteries directly from a supplier, they can be recycled from a number of sources for virtually free. One of our favorite sources is old laptop batteries. In several cases, we\u2019ve found that folks are willing to give their old, \u201dnon-working\u201d laptop batteries to us for free instead of having to pay for recycling. These larger batteries are often full of 18650 cells with only one or two that have failed. This renders the battery configuration too ineffective to power a laptop for longer periods of time, but with careful disassembly, harvesting cells from laptop batteries can result in an over-abundance of 3.7V fun! (Yes, we really do this kind of thing for fun, don\u2019t you?)\r\n\r\n
\"\"<\/center>\r\n
Figure 0x1: Another fruitful harvest of 18650 cells.<\/div>\r\n\u00a0\r\n\r\nAnother advantage is increased read range. In most cases, providing more power to a radio will increase the effective radio power, thus boosting range, too! The standard Tastic implementation provides 18V, but because the 18650 batteries produce more than double the voltage of standard Alkaline batteries (3.7V versus 1.5V), we can supply about 24V by wiring 6 of the 18650\u2019s in series!\r\n\r\nIt only requires a few minor technical changes to modify the original Tastic design to use the 18650 batteries, too. First, you need to find and install appropriate battery holders. We were lucky and had a few left over, some re-purposed, from the \u201cIf it Fits it Ships\u201d project. (Note: They were acquired from a Chinese importer for about $0.30 each. Super cheap, but we absolutely got what we paid for, as they needed a little help from some solder to reliably accept our batteries.)\r\n\r\nOnce you have battery holders, be careful where you put them! The 18650 have a larger diameter then AA batteries, so be careful to place them out of the way of the LCD display, as reassembling the device with 18650 batteries behind the screen will result in one less LCD. If you don\u2019t trust us on this one, you can ask the broken LCD on our workbench how it feels right about now. (The answer is sad. Very, very sad.)\r\n\r\n
\"\"<\/center>\r\n
Figure 0x2: 18650 batteries installed.<\/div>\r\n\u00a0\r\n\r\nSecond, swap out the resistors on the LM317LZ variable voltage regulator. Because we are increasing the input voltage, we need to adjust the resistors to maintain the appropriate output voltage to correctly power the Arduino and the LCD display. Using the LM317LZ calculator and the reference tables at http:\/\/www.reuk.co.uk\/LM317-Voltage-Calculator.htm<\/a><\/em>, we swapped out R1 to be 370 ohms and R2 to 2700 ohms (by wiring a 2200 and 500 ohm resistor in series) to deliver 10.37V to the Arduino Vin<\/em> pin.\r\n\r\n
\"\"<\/center>\r\n
Figure 0x3: Swapped R1 and R2. Yes, on a breadboard for modularity and upgrades.<\/div>\r\n\u00a0\r\n\r\nFinally, we need to make sure to update the jumper settings on the MaxiProx by shunting pins 3 and 3 to reflect the new input voltage to account for increasing it from 18V to 24V.\r\n\r\n
\"\"<\/center>\r\n
Figure 0x4: Forgetting to change this could let the \u201cmagic smoke\u201d out.<\/div>\r\n\u00a0\r\n\r\nNow that everything is set, fire it up and give it a test to be sure you didn\u2019t do anything wrong. If it is working as expected, button it back up and you are off to the races!\r\n\r\nEnjoy combining your new found savings and longer read range for pwnage!\r\n\r\nOver and out.\r\n\r\n- L","_et_gb_content_width":"","footnotes":""},"categories":[67],"tags":[35,11,9,10],"_links":{"self":[{"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/posts\/372"}],"collection":[{"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/comments?post=372"}],"version-history":[{"count":7,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/posts\/372\/revisions"}],"predecessor-version":[{"id":642,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/posts\/372\/revisions\/642"}],"wp:attachment":[{"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/media?parent=372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/categories?post=372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zed.inguardians.com\/wp-json\/wp\/v2\/tags?post=372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}