Skip to main content

NFC

Field Guide 08 · 35 min read

Read supported 13.56 MHz cards, use saved data, create profiles, recover MIFARE keys, and manage dictionaries.

Before you start​

Sensitive card data

NFC dumps, UIDs, keys, passwords, NDEF records, and transit data can be sensitive. Use only your cards or cards covered by explicit authorization.

Place one card flat against the NFC antenna area. Remove other contactless cards.

Read​

Read detects an NFC card, identifies its family, and retrieves the information available for that card type.

  1. Place one card against the antenna.
  2. Open Read and hold it still.
  3. Keep the card still while the M1 reads its pages, blocks, sectors, or applications.
  4. Review card family, UID, and completion state.
  5. Press Center for the actions valid for this result.
  6. Press Back to stop or return.
ActionWhen it appears and what to do
SaveUsable result: name it and save under nfc/.
Save PartialIncomplete MIFARE Classic data: save only if missing sectors are understood.
EmulateSupported full data is available; present M1 to the authorized reader and press Back to stop.
Emulate UIDOnly identity-level emulation is available.
WriteCompatible NTAG21x or MIFARE Classic result: align writable media and keep it still.
UnlockCompatible protected Type 2 tag: follow the AUTHLIM precautions below.
InfoOpen captured UID, NDEF, memory, sector, application, signature, or transit details.
  • A complete MIFARE Classic read covers every expected readable sector.
  • A partial result may contain UID and some sectors but is not a complete backup.
  • Type 2 and NTAG results can include pages, NDEF, signature, and protection state.
  • DESFire results expose card and discovered application information; protected content may remain unavailable.
  • Unknown cards may yield an identity without application data.

Saved​

Saved opens NFC profiles stored on the microSD card and shows the actions supported by each profile.

  1. Select a saved NFC file.
  2. Review its family and UID.
  3. Press Center for its applicable actions.
  4. Use Emulate or Emulate UID exactly as labeled.
  5. Use Edit UID only when changing stored identity is intentional.
  6. Use Write or Unlock only when offered.
  7. Open Info, or choose Rename or Delete to manage the file.
Capability labels

Emulate means the saved data supports the full-emulation path. Emulate UID means identity only.

Add a card profile​

Add creates a new saved NFC profile using the memory layout and UID format of the selected card family.

ItemWhat it creates
MFC 1KA MIFARE Classic 1K profile with an entered or generated UID.
MFC 4KA MIFARE Classic 4K profile with an entered or generated UID.
UltralightA MIFARE Ultralight profile with an entered or generated UID.
NTAG213An NTAG213 profile with the matching memory layout.
NTAG215An NTAG215 profile with the matching memory layout.
NTAG216An NTAG216 profile with the matching memory layout.
  1. Select the exact profile.
  2. Choose Enter UID for a known valid UID or Generate UID for a new identity.
  3. Check every hexadecimal byte.
  4. Press Center on Save.
  5. Enter a unique filename.
  6. Open the profile from Saved and review Info.
Profile is not application data

Creating a profile does not copy protected keys, balances, permissions, or account access.

Extract Keys​

Extract Keys captures supported MIFARE Classic authentication exchanges for key-recovery work.

  1. Insert a writable microSD card.
  2. Read the explanation and press Center on Start.
  3. Hold the M1 near the reader while it captures the authentication exchange.
  4. Wait for Authentication data captured, or press Back to stop.
  5. Save the recovery artifact under nfc/recover/ when offered.
  6. Use only recovered, validated keys in a later Read; a nonce capture does not guarantee a recovered key.
Protect recovery data

Reader-authentication capture can expose access-control secrets. Obtain written authorization and handle files like passwords.

Tools — MIFARE Classic Keys​

MIFARE Classic Keys manages the six-byte keys used automatically when reading Classic cards.

  1. Review System and Your keys counts. System keys are read-only.
  2. Press Center on Add.
  3. Enter exactly 12 hexadecimal characters for the six-byte key.
  4. Save; duplicate built-in or user keys are reported without another copy.
  5. Press Right on List to browse the keys you added.
  6. Select a user key and press Center.
  7. Confirm Delete only for the intended user key.

The combined dictionaries are used automatically during MIFARE Classic Read.

Tools — Ultralight Keys​

Ultralight Keys manages 16-byte keys for supported MIFARE Ultralight C workflows.

  1. Review system and user counts.
  2. Select Add Key.
  3. Enter exactly 32 hexadecimal characters for the 16-byte Ultralight C key.
  4. Save and verify the count.
  5. Select Your Keys to browse the keys you added.
  6. Press Center on Delete for the intended key.
Key management

Ultralight C keys can be stored, but full 3DES authentication may not be available during Read.

Tools — NTAG/UL Passwords​

NTAG/UL Passwords manages four-byte passwords and PACK values used with compatible protected Type 2 tags.

  1. Review system and user-password counts.
  2. Select Add Password.
  3. Enter the four-byte password as eight hexadecimal characters and provide PACK when requested.
  4. Save and verify the count.
  5. Open Your Passwords to browse owner entries.
  6. Select and confirm Delete only for the intended password.

The same dictionary is used by the compatible Type 2 Unlock workflow.

Unlock a protected tag​

Unlock authenticates to a compatible protected Type 2 tag using a known password or an available dictionary.

  1. Read the compatible protected tag first.
  2. Choose Unlock.
  3. Select Enter Password for one known four-byte password. An incorrect attempt may consume the tag’s authentication limit.
  4. Dictionary appears only when AUTHLIM is 0; otherwise it is hidden.
  5. Keep the tag still during authentication and automatic re-read.
  6. On Unlocked, press Center on View.
  7. Press Back during a running attempt to cancel.
AUTHLIM

Do not guess passwords on a limited authentication counter. Use one verified password or stop.

Troubleshooting​

ProblemWhat to do
Card not detectedRemove other cards, reposition, and keep the target still.
Classic read partialAdd authorized keys and read again.
Dictionary errorCheck matching files under nfc/system/ and the card filesystem.
Write unavailableThe family or captured data is not eligible for the current write path.
Unlock missingThe tag is unsupported, not detected as protected, or lacks required protection data.
Password rejectedStop before more attempts; verify PWD and PACK from an authorized source.

Visual guide​

NFC placement
NFC placementHold one NFC card flat against the rear surface and remove other contactless cards.
Key-assisted read
CaptureRecover keyAdd to dictionaryRead again

Need help? Email support@monstatek.com and include the firmware version and screen name.