Long Range RFID Theft (High Frequency)
In this article I will detail how I customised a high frequency HID reader to weaponise it for physical engagements. As with a previous writeup I have written on long range credential theft (LF), the best way to lift credentials at range is to weaponise a reader - no custom built device will perform better than a genuine commercial reader (as they say, if you can't beat them, join them).
Introduction
We all know that low frequency credentials are not designed with security in mind - this makes cloning trivial, and due to the nature of low frequency technologies, makes them easier to read at range.
High frequency (depending on the credential) makes things a little more difficult. Generally you can expect less range than you'd get from LF, and how much less comes down to the credential - Seos being the worst offender.
Technologies We Are Targeting
At a high level, the following high frequency cards are amongst the most likely to be encountered:
- MIFARE DESFire EV1/EV2/EV3 (Secure credentials)
- MIFARE Ultralight/Hospitality (Hotel keycards, etc)
- MIFARE Classic
- HID iCLASS (Standard / Legacy)
- HID iCLASS SE
- HID Seos
If an environment is grossly misconfigured, it is useful to obtain card UIDs, and is a good exercise in any case to determine what technology is in use by the estate. Beyond that, iCLASS legacy is the one with genuinely broken crypto we can exploit outright. SE and Seos hold up well on their own, so there you're really banking on a misconfiguration or a downgrade to a weaker credential (again, configuration dependent). See my article on HID iCLASS for more info.
- HID iCLASS (Standard / Legacy)
- HID iCLASS SE
- HID Seos
The Reader
Luckily for us, there is a family of HID readers that support all of the above (bar Ultralight/Hospitality and DESFIRE EV2/EV3) - the R90. They go for around £400-£700 on eBay.

HID's documentation on the R90 series readers describe read ranges varying between card technologies, ranging from 8cm (3.1") for MIFARE Classic in Fob format to 36cm (14.2") for iCLASS Standard/Legacy in Card format.

The reader's back is easily removed by using a plastic pry tool on the bottom side where the two screw holes are situated. The inside of the reader has a decent amount of space for additional components and wiring.

Design
So we have a reader, now we need two more things; a power supply, and a means of reading the wiegand data produced by valid reads. For the latter I will be using the Doppelgänger RFID Development Board from practical physical exploitation. If you want to read more about this particular board, refer to the Doppelgänger documentation.
Powering the Thing
If we refer again to HID's documentation, we can see the operating voltage range listed as "12 VDC or 24 VDC". The keen-eyed amongst you may have already spotted that my reader (listed as an R90) is actually an R90E:

This is an important distinction, because the R90E operates exclusively at 24VDC, whereas the R90 operates at 12VDC. The Doppelgänger RFID dev board is designed to operate at 12VDC, and its screw terminal module provides 12VDC outputs to route power to the reader.
This introduces a bit of a challenge, because the Doppelgänger RFID dev board operates at 12VDC and cannot be subject to higher voltages. I had originally planned to install a battery pack that holds 8x AA batteries, outputting 12VDC with a single barrel plug connector to power both
the dev board and the reader itself. If a regular R90 reader is being used, this would suffice, but in our case this will not be enough to power the reader.

We will have to adapt our design slightly, however there is a relatively simple solution. We can use a DC to DC step up conveter in between the RFID board's 12VDC power output and the reader's 24DVC input. These devices are commonly used in vehicles and are generally quite cheap. The R90's power draw is documented as 110mA, so there is no reason for a high-amp rated convertor; I chose the smallest one I could find rated at 2 amps. It's also worth mentioning that this converter's specification also includes input ranges of 9-20V with regulated 24V output. Batteries of any kind will have variations in voltage outputs, so even when the batteries dip in voltage below 12V, the reader will receive a sustained 24V.

Design Diagram

Finished Product and Testing
Here it is, looking all neat and tidy. I had to solder a few wires together and use heatshrink tubes for some of the wiring, as the reader only used female DuPont interfaces for connections.

Demo
After powering it on and completing the intial setup of the Doppelgänger board, we can present a standard iCLASS (legacy) credential to the reader. I got a read range of about 34cm, which is better than expected.
We can now open http://rfid.local/ on the same
network as configured on the board.

From the read we have a bit length of 26, with a facility code of 67 and a card number of 4697. If we use a genuine, standard-keyed iCLASS legacy card, we can rewrite it with a proxmark3:
Where:
- -w H10301 is the wiegand format
- --fc is the facility code
- --cn is the card number
- --ki 0 is the standard iCLASS key (key index 0)
References
HID iCLASS SE R90 ReaderHID iCLASS SE Readers Documentation
Doppelgänger RFID Development Board - Practical Physical Exploitation
Doppelgänger Assistant Documentation