Physical Access Control Systems
_
□
✕

Long Range RFID Theft (High Frequency)

Published: October 10, 2026
Warning: This is a security research article. Always obtain proper authorisation before testing any systems. Unauthorised testing is illegal and unethical.

In this article I will detail how I customised a high frequency HID reader to weaponise it for physical engagements. As with a previous writeup I have written on long range credential theft (LF), the best way to lift credentials at range is to weaponise a reader - no custom built device will perform better than a genuine commercial reader (as they say, if you can't beat them, join them).

Introduction

We all know that low frequency credentials are not designed with security in mind - this makes cloning trivial, and due to the nature of low frequency technologies, makes them easier to read at range.

High frequency (depending on the credential) makes things a little more difficult. Generally you can expect less range than you'd get from LF, and how much less comes down to the credential - Seos being the worst offender.

Technologies We Are Targeting

At a high level, the following high frequency cards are amongst the most likely to be encountered:

If an environment is grossly misconfigured, it is useful to obtain card UIDs, and is a good exercise in any case to determine what technology is in use by the estate. Beyond that, iCLASS legacy is the one with genuinely broken crypto we can exploit outright. SE and Seos hold up well on their own, so there you're really banking on a misconfiguration or a downgrade to a weaker credential (again, configuration dependent). See my article on HID iCLASS for more info.

The Reader

Luckily for us, there is a family of HID readers that support all of the above (bar Ultralight/Hospitality and DESFIRE EV2/EV3) - the R90. They go for around £400-£700 on eBay.

iCLASS SE R90 Reader
HID iCLASS SE R90 Reader

HID's documentation on the R90 series readers describe read ranges varying between card technologies, ranging from 8cm (3.1") for MIFARE Classic in Fob format to 36cm (14.2") for iCLASS Standard/Legacy in Card format.

R90 Read Ranges
R90 Read Ranges

The reader's back is easily removed by using a plastic pry tool on the bottom side where the two screw holes are situated. The inside of the reader has a decent amount of space for additional components and wiring.

R90 Reader Internals
R90 Reader Internals

Design

So we have a reader, now we need two more things; a power supply, and a means of reading the wiegand data produced by valid reads. For the latter I will be using the Doppelgänger RFID Development Board from practical physical exploitation. If you want to read more about this particular board, refer to the Doppelgänger documentation.

Powering the Thing

If we refer again to HID's documentation, we can see the operating voltage range listed as "12 VDC or 24 VDC". The keen-eyed amongst you may have already spotted that my reader (listed as an R90) is actually an R90E:

R90E Label
R90E Serial Label

This is an important distinction, because the R90E operates exclusively at 24VDC, whereas the R90 operates at 12VDC. The Doppelgänger RFID dev board is designed to operate at 12VDC, and its screw terminal module provides 12VDC outputs to route power to the reader.

This introduces a bit of a challenge, because the Doppelgänger RFID dev board operates at 12VDC and cannot be subject to higher voltages. I had originally planned to install a battery pack that holds 8x AA batteries, outputting 12VDC with a single barrel plug connector to power both the dev board and the reader itself. If a regular R90 reader is being used, this would suffice, but in our case this will not be enough to power the reader.

Battery Pack
12VDC Battery Pack

We will have to adapt our design slightly, however there is a relatively simple solution. We can use a DC to DC step up conveter in between the RFID board's 12VDC power output and the reader's 24DVC input. These devices are commonly used in vehicles and are generally quite cheap. The R90's power draw is documented as 110mA, so there is no reason for a high-amp rated convertor; I chose the smallest one I could find rated at 2 amps. It's also worth mentioning that this converter's specification also includes input ranges of 9-20V with regulated 24V output. Batteries of any kind will have variations in voltage outputs, so even when the batteries dip in voltage below 12V, the reader will receive a sustained 24V.

Step-up Converter
12VDC to 24VDC Step-up Converter

Design Diagram

Wiring Diagram
Wiring Diagram

Finished Product and Testing

Here it is, looking all neat and tidy. I had to solder a few wires together and use heatshrink tubes for some of the wiring, as the reader only used female DuPont interfaces for connections.

Finished Reader
Weaponised Reader

Demo

After powering it on and completing the intial setup of the Doppelgänger board, we can present a standard iCLASS (legacy) credential to the reader. I got a read range of about 34cm, which is better than expected.

We can now open http://rfid.local/ on the same network as configured on the board.

iCLASS Read
iCLASS Read

From the read we have a bit length of 26, with a facility code of 67 and a card number of 4697. If we use a genuine, standard-keyed iCLASS legacy card, we can rewrite it with a proxmark3:

[usb] pm3 --> hf iclass encode -w H10301 --fc 67 --cn 4697 --ki 0 [+] Using key[0] AE A6 84 A6 DA B2 32 78 [+] Loaded 16 bytes from binary file `iclass_decryptionkey.bin` [+] Write block 6/0x06 ( ok ) --> 030303030003E017 [+] Write block 7/0x07 ( ok ) --> AADBCE8059852B30 [+] Write block 8/0x08 ( ok ) --> 2AD4C8211F996871 [+] Write block 9/0x09 ( ok ) --> 2AD4C8211F996871

Where:

Now this card will hold the same PACS data as the original, and will function in the same way. The only difference will be the card's CSN, which largely does not factor into access decisions made by door controllers.

← Back to Home

References

HID iCLASS SE R90 Reader
HID iCLASS SE Readers Documentation
Doppelgänger RFID Development Board - Practical Physical Exploitation
Doppelgänger Assistant Documentation