# MTools Tec 文档：RFID/NFC、LoRa 与 Meshtastic 使用指南

MTools Tec 中文产品文档，包含 MTools App、PN532、Chameleon Ultra、GAT562、Meshtastic 与 MeshCore 的安装、固件升级、兼容性和故障排查。

这里汇集 MTools Tec 软件和硬件的使用指南、固件升级、兼容性说明及故障排查。请按照设备或订单中的产品名称选择对应分类。

{% hint style="info" %}
**第一次使用？** 请先确认产品型号和工作频率。不确定设备是否适合你的项目时，可以[联系 MTools 技术支持](https://shop.mtoolstec.com/contact-us/)。
{% endhint %}

## 按产品快速进入

{% content-ref url="<https://docs.mtoolstec.com/cn/ying-yong-yu-xia-zai>" %}
<https://docs.mtoolstec.com/cn/ying-yong-yu-xia-zai>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/cn/rfidnfc-yu-uhf-ying-jian>" %}
<https://docs.mtoolstec.com/cn/rfidnfc-yu-uhf-ying-jian>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/cn/lorameshtastic-yu-meshcore>" %}
<https://docs.mtoolstec.com/cn/lorameshtastic-yu-meshcore>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/cn/sdriot-yu-kuo-zhan-ying-jian>" %}
<https://docs.mtoolstec.com/cn/sdriot-yu-kuo-zhan-ying-jian>
{% endcontent-ref %}

## 软件与应用

* [查看全部官方应用与下载](https://docs.mtoolstec.com/cn/ying-yong-yu-xia-zai)
* **MTools Android：** [Google Play](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools)
* **MTools BLE：** [Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite) · [Apple App Store](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)
* **MIFARE Ultralight Tool：** [Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)
* **MCalc：** [Google Play](https://play.google.com/store/apps/details?id=cc.yuyeye.mcalc) · [中文文档](https://docs.mtoolstec.com/cn/help-and-info-mcalc)

## RFID 与 NFC 硬件

### MTools App

* [快速入门](https://docs.mtoolstec.com/cn/mtools-app/how-to-use-the-mtools-app)
* [完整使用指南](https://docs.mtoolstec.com/cn/mtools-app/mtools-app-wan-zheng-shi-yong-zhi-nan)
* [运算与表达式](https://docs.mtoolstec.com/cn/mtools-app/help-or-add-expression)
* [计算 CRC-8 / CRC-16](https://docs.mtoolstec.com/cn/mtools-app/ji-suan-crc8-crc16)

### Chameleon Ultra、Chameleon Lite 与 Pixl.js

MTools BLE 支持连接多款蓝牙 RFID 模拟器，并为部分设备提供固件升级与文件管理功能。

* [MTools BLE 中文指南](https://docs.mtoolstec.com/cn/bang-zhu-yu-xin-xi-mtools-lite)
* [购买 Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [购买 Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [购买 Pixl.js](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)
* [Chameleon Ultra 英文操作文档](https://docs.mtoolstec.com/how-to-use-chameleonultra)

### PN532、PCR532 与专业读卡器

* [购买 All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/)
* [购买 PCR532](https://shop.mtoolstec.com/product/pcr532/)
* [PN532 CLI 英文文档](https://docs.mtoolstec.com/pn532-cli/how-to-start)
* [Proxmark3 X 独立文档站](https://proxmark3x.mtoolstec.com/)
* [购买 Proxmark3 X](https://shop.mtoolstec.com/product/proxmark3-x/)

### Magic Cards、NFC 标签与 UHF

购买或写入标签前，请确认协议、UID 长度、卡片代际和写入方式。

* [购买 Gen4 Ultimate Magic Card](https://shop.mtoolstec.com/product/ultimate-magic-card-gen4/)
* [购买 ISO15693 可改 UID 标签](https://shop.mtoolstec.com/product/gen3-uid-changeable-iso15693-tag-80-block/)
* [购买 UHF TID 读写设备](https://shop.mtoolstec.com/product/uhf-reader-support-changing-tid/)
* [Flipper Zero UHF 扩展](https://shop.mtoolstec.com/product/uhf-expansion-for-flipperzero/)

## LoRa、Meshtastic 与 MeshCore

* [GAT562 30S 产品说明](https://docs.mtoolstec.com/lora-devices/gat562-30s-mesh-module)
* [GAT562 固件中文升级教程](https://docs.mtoolstec.com/cn/mtools-ble/how-to-upgrade-meshtastic-firmware-and-chinese-firmware-on-gat562)
* [购买 GAT562 30S](https://shop.mtoolstec.com/product/gat562-30s-kit-30dbm-mesh-device/)
* [购买 Meshtiny](https://shop.mtoolstec.com/product/meshtiny/)
* [GAT562 Meshtastic Tracker](https://shop.mtoolstec.com/product/gat562-mesh-tracker/)
* [GAT562 太阳能中继](https://shop.mtoolstec.com/product/gat562-30s-mesh-solar-repeater/)
* [Seeed Wio Tracker L1 Pro](https://shop.mtoolstec.com/product/seeed-wio-tracker-l1-pro/)
* [SenseCAP T1000-E](https://shop.mtoolstec.com/product/seeed-sensecap-card-tracker-t1000-e-for-meshtastic/)
* [Mesh Node T114](https://shop.mtoolstec.com/product/mesh-node-t114-rev-2-0-nrf52840-sx1262-lora-node-gps-meshtastic-and-lorawan-compatible/)

## SDR、IoT 与扩展硬件

* [RTL-SDR Blog V3](https://shop.mtoolstec.com/product/rtl-sdr-blog-v3-software-defined-radio-dongle-usb-c/)
* [SignalSDR Pro](https://shop.mtoolstec.com/product/signalsdr-pro/)
* [M5StickC PLUS SE](https://shop.mtoolstec.com/product/m5stickc-plus-se-mini-iot-dev-kit-esp32-pico/)
* [Flipper Zero 配件](https://shop.mtoolstec.com/product-category/accessories/flipper-zero-accessories/)
* [浏览全部商品](https://shop.mtoolstec.com/shop/)

## 商城与支持

* [MTools Tec 商城](https://shop.mtoolstec.com/)
* [查询订单物流](https://shop.mtoolstec.com/track-my-order/)
* [联系技术支持](https://shop.mtoolstec.com/contact-us/)

{% hint style="warning" %}
RFID、NFC 和无线研究工具仅限用于你拥有或已明确获得授权的系统与凭证。请遵守当地法律及无线电管理规定。
{% endhint %}


# 应用与下载

MTools Tec 官方 Android 与 iOS 应用、平台兼容性和下载链接。

请根据手机平台、硬件设备和标签类型选择合适的 MTools Tec 官方应用。

{% hint style="warning" %}
请仅通过下方 Google Play 或 Apple App Store 官方链接安装应用。应用可用性和设备兼容性可能因国家、系统版本及手机硬件而异。
{% endhint %}

## MTools

主要用于在 Android 设备上读取、写入、比较和分析支持的 MIFARE Classic 与 Ultralight 标签。支持兼容的手机内置 NFC，以及 ACR122U、PN532 等外接读卡器。

* **平台：** Android
* [从 Google Play 下载 MTools](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools)
* [查看快速入门](https://docs.mtoolstec.com/cn/mtools-app/how-to-use-the-mtools-app)
* [查看完整使用指南](https://docs.mtoolstec.com/cn/mtools-app/mtools-app-wan-zheng-shi-yong-zhi-nan)

## MTools BLE

用于连接支持的蓝牙 RFID 读卡器和模拟器，包括 PN532 BLE、PCR532、Chameleon Ultra、Chameleon Lite 和 Pixl.js，同时提供部分设备的固件及 OTA 升级工具。

* **平台：** Android、iPhone、iPad
* [从 Google Play 下载 MTools BLE](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite)
* [从 Apple App Store 下载 MTools BLE](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)
* [查看 MTools BLE 指南](https://docs.mtoolstec.com/cn/bang-zhu-yu-xin-xi-mtools-lite)

{% hint style="info" %}
在 iPhone 和 iPad 上进行 MIFARE Classic 操作时，需要 PN532 BLE、Chameleon Ultra 等受支持的外接设备；iPhone 内置 NFC 不提供相同的 MIFARE Classic 访问能力。
{% endhint %}

## MIFARE Ultralight Tool

专用于读取、写入、扫描和检查 MIFARE Ultralight 与 NTAG 产品的 Android 工具。

* **平台：** Android
* **支持系列包括：** MF0UL11、MF0UL21、MF0ULC、NTAG213、NTAG215、NTAG216
* [从 Google Play 下载 MIFARE Ultralight Tool](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)

## MCalc — Mifare Calculator

用于对十六进制数据计算 XOR、SUM、数据校验和、CRC-8 与 CRC-16。

* **平台：** Android
* [从 Google Play 下载 MCalc](https://play.google.com/store/apps/details?id=cc.yuyeye.mcalc)
* [查看 MCalc 文档](https://docs.mtoolstec.com/cn/help-and-info-mcalc)

## M Keys

用于在授权的卡片和工作流程中生成、保存和管理 MIFARE 密钥，可配合内置 NFC 或 ACR122U 使用。

* **平台：** Android
* [从 Google Play 下载 M Keys](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools.keygen)

## 全部 Android 应用

[查看 MTools Tec 在 Google Play 发布的全部应用](https://play.google.com/store/apps/dev?id=7994355636404806984)

## 兼容硬件

* [All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/)
* [PCR532](https://shop.mtoolstec.com/product/pcr532/)
* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Pixl.js](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)

不确定应选择哪款应用或读卡器？[联系 MTools 技术支持](https://shop.mtoolstec.com/contact-us/)。


# RFID、NFC 与 UHF 硬件

RFID、NFC 与 UHF 读卡器、模拟器、卡片和标签的产品入口及相关文档。

按照设备类型选择文档和产品。购买前请确认协议、频率、UID 长度以及目标卡片是否支持相应操作。

## 读卡器与开发工具

* [All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/) — USB 与蓝牙 PN532 读写设备
* [PCR532](https://shop.mtoolstec.com/product/pcr532/) — 便携式 RFID/NFC 工具
* [PN532 CLI 英文文档](https://docs.mtoolstec.com/pn532-cli/how-to-start)
* [Proxmark3 X](https://shop.mtoolstec.com/product/proxmark3-x/) · [独立文档站](https://proxmark3x.mtoolstec.com/)
* [Proxmark3 RDV4.01](https://shop.mtoolstec.com/product/proxmark3-rdv4-01/)
* [iCopy-XS](https://shop.mtoolstec.com/product/icopy-xs/)

## RFID 模拟器

* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [Chameleon Ultra SE](https://shop.mtoolstec.com/product/chameleonultra-se/)
* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Pixl.js](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)
* [MTools BLE 中文说明](https://docs.mtoolstec.com/cn/bang-zhu-yu-xin-xi-mtools-lite)

## Magic Cards 与 NFC 标签

* [Gen4 Ultimate Magic Card](https://shop.mtoolstec.com/product/ultimate-magic-card-gen4/)
* [MIFARE Classic UID 可改卡](https://shop.mtoolstec.com/product/uid-changeable-1k-s50-chinese-magic-card/)
* [NTAG213 / 215 / 216 UID 可改标签](https://shop.mtoolstec.com/product/uid-changeable-ntag-n213-n215-n216/)
* [ISO15693 Gen3 标签](https://shop.mtoolstec.com/product/gen3-uid-changeable-iso15693-tag-80-block/)
* [MIFARE Ultralight Tool](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)

## UHF RFID

* [支持 TID 操作的 UHF 读卡器](https://shop.mtoolstec.com/product/uhf-reader-support-changing-tid/)
* [UHF TID 标签套装](https://shop.mtoolstec.com/product/tid-changeable-uhf-tag-kit-with-reader/)
* [Flipper Zero UHF 扩展](https://shop.mtoolstec.com/product/uhf-expansion-for-flipperzero/)

{% hint style="warning" %}
请仅对自己拥有或明确获得授权的卡片、凭证和系统进行读写或安全研究。
{% endhint %}


# NFC 与 RFID 模拟器

对比 MTools Tec NFC 与 RFID 模拟器，包括 Chameleon Ultra、PN532Killer、Pixl.js、GroveNFC、Flipper Zero 和 ST25R3916 设备。

请根据频率、协议、连接方式和使用场景选择 NFC 或 RFID 模拟器。本栏目覆盖便携式标签模拟器、读写/模拟开发工具、Amiibo 兼容设备以及多功能安全研究硬件。

[浏览全部 RFID 模拟器](https://shop.mtoolstec.com/product-category/rfid-emulator/)

## 快速对比

| 产品系列                      | 适合场景                 | 频率 / 协议                               | 连接方式          |
| ------------------------- | -------------------- | ------------------------------------- | ------------- |
| Chameleon Ultra 系列        | 便携式 LF/HF 读取、模拟与授权测试 | 125 kHz 和 13.56 MHz；具体支持取决于固件         | 蓝牙和 USB       |
| Chameleon Mini / Lite     | 以 MIFARE 为主的紧凑型模拟    | 13.56 MHz，主要为 ISO14443A               | 依型号支持 USB 或蓝牙 |
| PN532Killer               | 读取、模拟、嗅探及多协议测试       | ISO14443A/B、ISO15693、EM4100           | 依型号而定         |
| Pixl.js                   | Amiibo 与交互式 NFC 标签集合 | 13.56 MHz NFC                         | 蓝牙 / USB 固件流程 |
| GroveNFC / ST25R3916 Unit | 嵌入式开发和自定义 NFC 项目     | ISO14443A/B、FeliCa、ISO15693；模拟能力依设备而定 | Grove / I2C   |
| Flipper Zero              | 多协议便携式实验             | NFC、低频 RFID 及其他无线功能                   | USB 和蓝牙       |

{% hint style="info" %}
不同型号和固件支持的协议、标签容量及读卡模式并不相同。“NFC 模拟器”不代表支持所有 NFC 或 RFID 协议，购买前请查看商品页规格。
{% endhint %}

## Chameleon 便携式模拟器

### Chameleon Ultra

面向读取、模拟及授权安全研究的开源 LF/HF RFID 工具。需要同时处理 125 kHz 与 13.56 MHz 工作流时，它是 Chameleon 系列中功能更完整的选择。

* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [Chameleon Ultra SE](https://shop.mtoolstec.com/product/chameleonultra-se/) — 更紧凑的硬件版本，共用相同软件生态
* [ChameleonUltra Dev Kit](https://shop.mtoolstec.com/product/chamleonultra-dev-kit/) — 开发与集成套装
* [英文设置与使用指南](https://docs.mtoolstec.com/how-to-use-chameleonultra)
* [英文固件升级指南](https://docs.mtoolstec.com/upgrade-the-firmware-of-chameleonultra-and-chameleonlite)

### Chameleon Lite 与 Chameleon Mini

适合专注于 13.56 MHz / MIFARE 模拟的轻量工作流，不需要 Chameleon Ultra 完整双频功能时可优先考虑。

* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Chameleon Mini Rev.E RDV 2.0](https://shop.mtoolstec.com/product/chameleon-mini-rev-e-rdv-2-0-2022/)

## NFC 模拟与开发工具

### PN532Killer

面向 ISO14443A、ISO14443B、ISO15693 与 EM4100 研究流程的多功能读卡、模拟和嗅探工具。

* [PN532Killer](https://shop.mtoolstec.com/product/pn532killer/)
* [M5StickC 转接器](https://shop.mtoolstec.com/product/m5stickc-adapter-for-pn532killer/)

### Pixl.js OLED for Amiibo

带屏幕的 NFC 设备，适合管理兼容的虚拟标签集合和 Amiibo 工作流。

* [Pixl.js OLED for Amiibo](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)
* [英文 Pixl.js 固件升级指南](https://docs.mtoolstec.com/upgrade-the-firmware-of-pixl.js)

### GroveNFC

适用于 M5Stick、AtomS3、CardPuter 及其他 Grove 主机的开放通信 NFC 模块，可通过开源演示固件进行读卡和模拟功能开发。

* [GroveNFC 开源 NFC 模块](https://shop.mtoolstec.com/product/grovenfc/)

### M5Stack NFC Universal Unit（ST25R3916）

通过 I2C 连接的 NFC 读写与开发单元，支持 ISO14443A/B、FeliCa、ISO15693，以及 NFC-A、NFC-F 卡模拟模式。

* [M5Stack NFC Universal Unit](https://shop.mtoolstec.com/product/m5stack-nfc-universal-unit-st25r3916-13-56mhz-rfid-reader-writer-module/)

## 多功能设备

### Flipper Zero

除 NFC 和低频 RFID 外，还提供其他无线及硬件接口。更适合需要综合实验能力的用户，而不是单一 NFC 工作流。

* [Flipper Zero](https://shop.mtoolstec.com/product/flipper-zero/)

## App、固件与下一步

* [MTools BLE 中文说明](https://docs.mtoolstec.com/cn/bang-zhu-yu-xin-xi-mtools-lite) — 支持部分 Chameleon 设备的移动端工作流
* [Chameleon Ultra 使用专题](https://shop.mtoolstec.com/how-to-use-chameleon-ultra/) — 产品设置、App 与桌面工具
* [RFID、NFC 与 UHF 硬件总览](https://docs.mtoolstec.com/cn/rfidnfc-yu-uhf-ying-jian)
* [浏览完整模拟器产品分类](https://shop.mtoolstec.com/product-category/rfid-emulator/)

{% hint style="warning" %}
模拟、复制、嗅探和安全测试功能只能用于自己拥有或已取得明确授权的标签、凭证与系统。不同地区的法律和合规要求可能不同。
{% endhint %}


# LoRa、Meshtastic 与 MeshCore 设备

对比 MTools Tec LoRa、Meshtastic、MeshCore 与 LoRaWAN 节点、Tracker、中继器、模组、固件和天线。

这里汇总 MTools Tec 当前 LoRa 产品线，包括便携节点、GNSS Tracker、太阳能中继、开发模组、固件和不同地区使用的天线。购买前请确认目标固件和当地允许的工作频率。

{% hint style="info" %}
不同设备支持的固件和频段并不完全相同。请在商品页确认芯片、频率、固件、显示屏、GNSS、外壳及供电方式。
{% endhint %}

## 便携与交互式 Mesh 节点

### GAT562 30S Kit

带显示和控制功能的高功率 Mesh 设备，适用于 Meshtastic 与 MeshCore 项目。

* [GAT562 30S 文档](https://docs.mtoolstec.com/lora-devices/gat562-30s-mesh-module)
* [购买 GAT562 30S Kit](https://shop.mtoolstec.com/product/gat562-30s-kit-30dbm-mesh-device/)

### Meshtiny

集成控制器和显示屏的紧凑型完整 Mesh 节点。

* [购买 Meshtiny](https://shop.mtoolstec.com/product/meshtiny/)

### Seeed Wio Tracker L1 Pro

带摇杆控制的便携节点，可选择 MTools Tec ADV Bootloader。

* [购买 Wio Tracker L1 Pro](https://shop.mtoolstec.com/product/seeed-wio-tracker-l1-pro/)

### M5 Unit C6L

M5Stack 形态的紧凑型 LoRa 单元，支持相应的 Meshtastic 与 MeshCore 工作流程。

* [购买 M5 Unit C6L](https://shop.mtoolstec.com/product/m5stack-unitc6l/)

## Tracker 与定位设备

### GAT562 Meshtastic Tracker

采用 nRF52840、SX1262、GNSS 和显示屏的离网定位设备。

* [购买 GAT562 Meshtastic Tracker](https://shop.mtoolstec.com/product/gat562-mesh-tracker/)

### SenseCAP T1000-E

信用卡尺寸的 IP65 Meshtastic Tracker，集成 GNSS 和多种传感器。

* [购买 SenseCAP T1000-E](https://shop.mtoolstec.com/product/seeed-sensecap-card-tracker-t1000-e-for-meshtastic/)

### Meshtiny FindMy

以定位功能为重点的紧凑型 Meshtiny 设备。

* [购买 Meshtiny FindMy](https://shop.mtoolstec.com/product/meshtiny-findmy/)

### SenseCAP T2000-A

面向设备和户外部署的 IP67 工业 LoRaWAN 资产 Tracker。

* [购买 SenseCAP T2000-A](https://shop.mtoolstec.com/product/sensecap-t2000-a-industrial-lorawan-asset-tracker-ip67-gps-ble-wi-fi-for-heavy-equipment/)

## 太阳能节点与中继器

### GAT562 30S Mesh Pod Solar Repeater

用于固定户外覆盖的 30 dBm 太阳能 Mesh 中继器。

* [购买 GAT562 30S Mesh Pod](https://shop.mtoolstec.com/product/gat562-30s-mesh-solar-repeater/)

### GAT562 Solar EVB

用于自定义太阳能节点的 22 dBm MPPT 开发板。

* [购买 GAT562 Solar EVB](https://shop.mtoolstec.com/product/gat562-solar-evb/)

### GAT562 Mesh Solar Relay

适合长期部署的独立离网太阳能 Mesh 中继器。

* [购买 GAT562 Mesh Solar Relay](https://shop.mtoolstec.com/product/gat562-mesh-solar-relay-autonomous-off-grid-repeater-for-mesh-networks/)

## 开发板与嵌入式模组

### GAT nRF52840 + SX1262 Mesh Module

用于在自定义硬件中集成 Mesh 功能的紧凑模组。

* [购买 GAT Mesh Module](https://shop.mtoolstec.com/product/gat-nrf52840-sx1262-mesh-module/)

### Mesh Node T114 Rev. 2.0

采用 nRF52840 与 SX1262、可选显示屏和 GPS 的 Meshtastic / LoRaWAN 开发板。

* [购买 Mesh Node T114](https://shop.mtoolstec.com/product/mesh-node-t114-rev-2-0-nrf52840-sx1262-lora-node-gps-meshtastic-and-lorawan-compatible/)

### N5262M Module

适用于嵌入式 Meshtastic 和自定义 LoRa 开发的紧凑型 nRF52840 + SX1262 模组。

* [购买 N5262M](https://shop.mtoolstec.com/product/nrf52840-sx1262-mesh-node-n5262m-module-meshtastic-compatible/)

## 固件与 OTA 工具

* [T1000-E TapTap 固件](https://shop.mtoolstec.com/product/t1000-e-taptap-firmware/)
* [浏览 LoRa 固件](https://shop.mtoolstec.com/product-category/lora/firmware/)
* [GAT562 Meshtastic 与中文固件升级](https://docs.mtoolstec.com/cn/mtools-ble/how-to-upgrade-meshtastic-firmware-and-chinese-firmware-on-gat562)
* [nRF52840 BLE OTA 英文指南](https://docs.mtoolstec.com/nrf52840-meshtastic-meshcore-firmware-ble-ota)
* [下载 MTools BLE Android 版](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite)
* [下载 MTools BLE iPhone/iPad 版](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)

## 天线与地区频段

* [868 MHz 20 cm 鞭状天线](https://shop.mtoolstec.com/product/868mhz-20cm-whip-antenna/)
* [868 MHz 40 cm 鞭状天线](https://shop.mtoolstec.com/product/868mhz-40cm-whip-antenna/)
* [915 MHz 20 cm 鞭状天线](https://shop.mtoolstec.com/product/915mhz-20cm-whip-antenna/)

{% hint style="warning" %}
请仅使用所在国家允许的频段和发射功率。发射前务必确认设备版本与天线频率一致。
{% endhint %}

[浏览完整 LoRa 商品分类](https://shop.mtoolstec.com/product-category/lora/)


# SDR、IoT 与扩展硬件

软件定义无线电、M5Stack、Flipper Zero 扩展及其他 IoT 产品入口。

这些产品目前主要通过商城商品页提供规格和兼容性信息，专门的技术文档将逐步补充。

## 软件定义无线电

* [RTL-SDR Blog V3](https://shop.mtoolstec.com/product/rtl-sdr-blog-v3-software-defined-radio-dongle-usb-c/)
* [SignalSDR Pro](https://shop.mtoolstec.com/product/signalsdr-pro/)

## M5Stack 与 IoT

* [M5StickC PLUS SE](https://shop.mtoolstec.com/product/m5stickc-plus-se-mini-iot-dev-kit-esp32-pico/)
* [M5StickC PLUS2](https://shop.mtoolstec.com/product/m5stickc-plus2-esp32-mini-iot-development-kit/)
* [M5StickS3](https://shop.mtoolstec.com/product/m5sticks3-esp32-s3-mini-iot-development-kit/)

## Flipper Zero 扩展

* [UHF RFID 扩展](https://shop.mtoolstec.com/product/uhf-expansion-for-flipperzero/)
* [CC1101 无线扩展](https://shop.mtoolstec.com/product/flipper-zero-cc1101-module-subghz-433mhz-multi-function-development-board/)
* [浏览全部 Flipper Zero 配件](https://shop.mtoolstec.com/product-category/accessories/flipper-zero-accessories/)

## 获取帮助

* [浏览全部商品](https://shop.mtoolstec.com/shop/)
* [联系技术支持](https://shop.mtoolstec.com/contact-us/)


# 帮助与信息 | MTools BLE

## 概述

MTools BLE 是一款以BLE 外设为主的的 MTools 系列软件，他支持通过内置 NFC 与 蓝牙RFID 读写器对 IOS14443 类型卡片进行读写操作。MTools BLE 由 Flutter 开发，同时支持 Android 与 iOS版本。

## 限制

### iOS系统

由于苹果系统的限制，内置 NFC 无法支持读写 Mifare Classic 1K/4K 卡片。

### Android系统

无硬件上的限制。


# 帮助与信息 | MCalc

MCalc使用指南

## MCalc 的作用

它用于计算具有不同逻辑计算的十六进制数。

## MCalc 支持的基础运算

* SUM
* CHECKSUM
* XOR

## MCalc 支持的高级运算

* CRC-8
  * CRC-8
  * CRC-8/CDMA2000
  * CRC-8/DARC
  * CRC-8/DVB-S2
  * CRC-8/EBU
  * CRC-8/I-CODE
  * CRC-8/ITU
  * CRC-8/MAXIN
  * CRC-8/ROHC
  * CRC-8/WCDMA
* CRC-16
  * CRC-16/CCITT-FALSE
  * CRC-16/ARC
  * CRC-16/AUG-CCITT
  * CRC-16/BUYPASS
  * CRC-16/CDMA2000
  * CRC-16/DDS-110
  * CRC-16/DECT-R
  * CRC-16/DECT-X
  * CRC-16/DNP
  * CRC-16/EN-13757
  * CRC-16/GENIBUS
  * CRC-16/MAXIN
  * CRC-16/MCRF4XX
  * CRC-16/RIELLO
  * CRC-16/T10-DIF
  * CRC-16/TELEDISK
  * CRC-16/TMS37157
  * CRC-16/USB
  * RC-A
  * CRC-16/KERMIT
  * CRC-16/MODBUS
  * CRC-16/X-25
  * CRC-16/XMODEM


# MTools App 完整使用指南

MTools App 完整使用指南，包括卡片管理、读写、规则、导入、导出及支持的文件格式。

## 1.概述

MTools 是一款可轻松读取、写入、分析和重置 Mifare Classic 标签的 Material 设计 APP。

你首先需要什么：

1. 支持读写 `Mifare 1K`的设备
   * 内置 NFC
   * USB: `ACR122U` `PN532`
   * 蓝牙: `PN532`
2. 扇区的密钥A与密钥B

**请遵守当地法律，仅作学习与测试使用！**

## 2.YouTube 频道

* [Use MTools to read/write/clone data on Mi Band 3 NFC](https://youtu.be/1Bl-FFALNic)
* [Hack Mifare 1K Card without ACR122U only MTools](https://youtu.be/hEwhJWAt3a8)
* [Burst Attack Mifare 1K Card with MKeys on NFC Android Phone](https://youtu.be/CKSBDwRg7Wo)

## 3. 列表

当在列表界面贴卡时，APP会自动检测卡片类型，并给出基本信息，状态和使用建议。

![MTools 标签信息对话框](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-MeFbxSPfjqbURVJv4CD%2F-MeFfaE3M6ae-hDPe7mQ%2FMTools-Tag-Info-Dialog.png?alt=media\&token=b636423a-38dd-47e3-902c-836ca170aa14)

### 3.1 添加卡片

点击 **+ 浮动按钮** 将会显示添加卡片的对话框，将 Mifare Classic 标签靠近 NFC天线即可。

### 3.2 移除卡片

向右滑动卡片项。

### 3.3 卡片排序

长按并拖动以重新给卡片排序。

### 3.4 卡片过滤

向下拖动可以根据名称、UID、SAK 或时间来过滤卡片。

### 3.5 导入文件

* \*.mto 文件是包含卡片信息，密钥和规则的特殊的 JSON 文件。
* \*.mfd | \*.bin 文件是由 libnfc库读取的 1K Mifare 转储文件。
* \*.mct 文件是由 Mifare Classic Tools 读取的转储文件。

### 3.6 导出文件

Supports exporting to 5 types: 支持5种类型的文件导出

* `*.mto` 包括扇区，密钥，转储与规则
* `card-list.csv` 包括卡片id、名称、SAK和时间
* `keys.txt` 包括所有添加的密钥
* `sniffer.csv` 包括所有的嗅探记录
* `record.csv` 包括所有的充值记录

## 4. 详情

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb77-S6oe8_phpt8Sru%2F-Mb78xrPmiTCaVSEGdeh%2Fbutton_func.jpeg?alt=media\&token=71285e78-8234-4c89-b2cd-9d7eb6752303)

### 4.1 添加 & 移除扇区

:new:点击 **+** 浮动按钮并选择 `添加扇区` ，再滑动滑块选择扇区号，并填入有效的密钥A 与密钥B，均为 6 个字节(12个字符) 。

:arrow\_backward:向右滑动扇区项以移除扇区和密钥。

### 4.2 修改密钥

点击 **修改按钮** 将会显示修改密钥对话框， 此时可选择新的扇区或修改现有密钥， 密钥为6个字节(12个字符)或为空。点击**完成**保存密钥和扇区号。

### 4.3 读取扇区

将卡片靠近NFC天线后，点击**读取扇区**按钮，将会显示改扇区的4个块数据。此时可修改并写入数据到卡片中。读写卡时请保持卡片靠近NFC天线。

### 4.4 管理规则

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6cAYKHeOMMPTJ9wUw%2Fmt%20handle%20block.jpg?alt=media\&token=1ebdb17c-ad14-4294-8f51-d3377f81c759)

* 选中块左侧的复现可以进行批量操作
* 点击**标记按钮**可以开始标记数据
* 点击**复制按钮**可以复制规则到其他块或其他卡片

#### **4.4.1 标记数值位**

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6dBobEv68KsF3qfQB%2Fmark_money.jpeg?alt=media\&token=c8c2a671-3eb9-4029-95c4-b7701179d9c1)

字节标记完成后，调节选项与倍率，数值正确后点击下一步。

#### **4.4.2 标记校验位**

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6dG-lcMqK6kJa8mru%2Fmark_check.jpeg?alt=media\&token=883d45a6-a09f-4f8a-8509-2ea87a4d40a5)

标记变化的字节并添加表达式，确保无误后点击OK。

#### **4.4.2.1 已支持运算**

> 基础: + - × ÷
>
> 求余: #
>
> 逻辑 : xor not
>
> CRC8: crc8, crc8cdma2000, crc8darc, crc8dvbs2, crc8ebu, crc8icode, crc8itu, crc8maxim, crc8rohc, crc8wcdma
>
> CRC16: crc16ccittfalse, crc16arc, crc16buypass, crc16cdma2000, crc16dds110, crc16dectr, crc16dectx, crc16dnp, crc16en13757, crc16genibus, crc16maxim, crc16mcrf4xx, crc16riello, crc16t10dif, crc16teledisk, crc16tms37157, crc16usb, crca, crc16kermit, crc16modbus, crc16x25, crc16xmodem

了解更多 >>

#### **4.4.2.2 表达式排序**

* 按住并上下拖动表达式
* 运算顺序为从上至下

### 4.5 数据嗅探

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6ewXofBHU-wvHIDDn%2F-Mb6fYg-EEcTZASVu1cJ%2F%20tips_sniffer.jpg?alt=media\&token=ea2c3f7a-14da-4f60-afd2-ac60c5aaf3f5)

注意：请先添加正确的密钥。字节标记完成后可以通过高亮的数据进行对比。

### 4.6 扇区排序

长按并上下拖动即可重新排序。

### 4.8 导入转储

点击 **+** 浮动按钮，点击添加转储后，选择文件类型。MTools 所支持的专车类型：

{% tabs %}
{% tab title="mfd" %}
全称为 Mifare Dump，此文件为 PN532 原生命令或相关程序读取到的 1K 转储文件
{% endtab %}

{% tab title="bin" %}
此格式文件来自于 Proxmark 3 等设备读取出的 1k 转储文件
{% endtab %}

{% tab title="mct" %}
此文件来自 Mifare Classic Tools 应用程序通过内置 nfc读取的带有扇区号的文本格式转储文件。
{% endtab %}
{% endtabs %}

## 5. 从卡片读取

点击 **+** 浮动按钮并选择 **从卡片读取**， 此时可以添加更多的密钥并尝试读取卡片内尽可能多的数据，完成后可以保存数据到转储文件。

### 5.1 密钥列表

启动时候会加载默认密钥与用户已添加的密钥。

### 5.2 开始读取

MTools 将会尝试使用密钥列表中的密钥读取卡片尽可能多的扇区数据。

## 6. 充值

### 6.1 设置定额

点击 **+** 按钮可以切换成 **=** 定额。

### 6.2 预览计算结果

长&#x6309;**$浮动按钮**可以预览生成的数据和规则信息。

## 7.依赖

感谢以下朋友们对开源社区的贡献，排名不分先后。

* `ikarus23` [MifareClassicTool](https://github.com/ikarus23/MifareClassicTool)
* `afollestad` [material-dialogs](https://github.com/afollestad/material-dialogs)
* `markormesher` [android-fab](https://github.com/markormesher/android-fab)
* `didikee` [AndroidDonate](https://github.com/didikee/AndroidDonate)
* `Ice-Box` [Ice-Box](http://catchingnow.com)
* `uccmawei` [FingerprintIdentify](https://github.com/uccmawei/FingerprintIdentify)


# Simple Startup

Firstly, it's the Mifare Classic Tool that I used to write hex data back to Mifare 1k card with my NFC phone - Moto X 2013. And after several steps of studies and development, I find a way to read the money data from the card and generate legal hex data then write back it to the card. And it works perfectly, which made me so happy. Seemed like I was a real hacker, can easily change the money on the card with a simple app. After that, I want to share this happiness with all guys who are interested in RFID. After about 3 weeks of development, the first version of MTools came out. Here're the things that you need to know to use it better.

1. Get the keys from all sectors
2. Compare to find the sector with money data
3. Add card, sector, and  keys to MTools
4. Record data from after every consumption in sniffer
5. Compare and analyze the rules of dynamic bytes
6. Finish the expression
7. Charge Mifare 1k  card with one click

## Get the keys from all sectors

Some cards using default keys like `FFFFFFFFFFFF` `000000000000` `A1B2C3D4E56F` etc, which you can try to dump keys with **Mifare Classic Tools** on the NFC android phone. If the card is not fully encrypted, it can be cracked with an RFID device to burst crack. Like **ACR122U** or **PN532**.

If the card is fully encrypted, only **PM3** can crack the keys.

## Compare to find the sector with money data

With keyA or keyB of all sectors of the card, data need to be gathered. And compare them after every consumption, so you can find the sector that data change, which means the money data may in that sector.

## Add card, sector, and  keys to MTools

The 4th block of every sector contains

`keyA(6 bytes) + Access Control(4) + keyB(6)`

## Record data from in sniffer

With sector number and valid keys added, it can be easy to compare data with different money amounts.

Mark the money bytes(contain money data) and check bytes(mostly the changing bytes)

## Compare and analyze the rules of dynamic bytes

Pay attention to HEX or DEC, Reverse or not and Rate on Money bytes.

Compare the Summation or XOR values with up and down check bytes.

## Finish the expression

MTools use [mXparser](http://mathparser.org/) to calculate expression in rules. Please follow the tips in MTools to add expression.

## Charge Mifare 1k  card with one click

Before charging a card, an accurate simulation is necessary, just by a long click on the $ button after tag card.

## What's More

MTools can work with an extra device like ACR122U, PN532, PN532 BLE, which means you can use the features on a phone without NFC hardware. MTools also supports Changing UID for Magic Cards with PN532 RFID Hardware.


# 如何使用嗅探

Depending on the Firebase of MTools, only 15% of MTools users have used Sniffer functions of MTools. It's really an easy tool for comparison and analysis. In this article, I'll show the tutorial of how to use Sniffer in MTools.

## 为什么需要嗅探

在获取包含有效数据的扇区的密钥后，我们需要比较不同数量的数据。因此我们制作了嗅探功能以便更轻松地收集和比较数据。 浅粉色和浅蓝色背景显示字节是否发生变化。&#x20;

![](https://why.yuyeye.cc/post-images/1574347906909.jpg)

## 嗅探功能在哪里

![](https://why.yuyeye.cc/post-images/1574347023367.jpg)

1. 在列表页面添加卡片后，便可以在详情页面添加扇区。
2. 可根据需要填充密钥A和密钥B。
3. 点击第三个部分。

## 如何使用嗅探

### 标记数据位

![](https://why.yuyeye.cc/post-images/1574349436660.jpg)

### 标记校验位

![](https://why.yuyeye.cc/post-images/1574349445281.jpg)

### 表达式的使用

```
运算符 
   • + - × ÷ 求余 ➡ + - * / # 
   • 异或 ➡ @^ ➡ xor 
   • 非 ➡ @～ ➡ not 
   • 与 ➡ @& ➡ and 
   • 或 ➡ @| ➡ or 
   • 左移n位 ➡ @<<n 
   • 右移n位 ➡ @>>n 

范例 
   • b2=b1 ➡ b2=b1 
   • b4=b2+0x1F ➡ b4=b2+31(十进制数) 
   • b15=b0 xor b1 ➡ b15=b0 xor b1 
   • b2=not b0 ➡ b2=not b0 Note 

 注意事项
   • 请将十六进制数转变为十进制数进行计算 
   • 上下拖送可以改变计算顺序
```

![](https://why.yuyeye.cc/post-images/1574350100574.jpg)

## 总结 <a href="#conclusion" id="conclusion"></a>

如果校验位的计算结果中没有删除线，意味着表达式运算结果与原数据匹配。


# 运算与表达式

## 可用运算符

|    Name    | Operator                                  | Example   |
| :--------: | ----------------------------------------- | --------- |
|   + - × ÷  | + - \* /                                  |           |
|   modulo   | #                                         |           |
|  brackets  | ( )                                       |           |
|     and    | @&                                        |           |
|     or     | @\|                                       |           |
|     xor    | @^                                        | b0 xor b1 |
|     not    | @\~                                       | not b3    |
|    连续求和    | b1+b2+···+b14                             | sum(1:14) |
|    连续异或    | b1 xor b2 xor ··· xor b10                 | sum(1:10) |
|    连续逻辑与   | b1 and b2 and ··· and b14                 | and(1:14) |
| CRC8/CRC16 | [了解更多](/cn/mtools-app/ji-suan-crc8-crc16) |           |

## 示例

| Rule              | Expression       |
| ----------------- | ---------------- |
| `b2 = b1`         | `b2=b1`          |
| `b4 = b2 + 0x1F`  | `b4 = b2 + 31`   |
| `b15 = b0 xor b1` | `b15 = b0 @^ b1` |
| `b2= not b0`      | b2 = @\~b0       |

* *请将十六进制数转化成十进制*
* *上下拖动表达式有改变计算顺序*
* *运算顺序为自上向下*

## 扩展用法

访问 [mXparser](http://mathparser.org/?s=Bitwise) 网站


# 计算CRC-8 / CRC-16

CRC - 循环冗余校验广泛用于数据传输。 根据 `wikipedia.org` 的描述，启用 CRC 的设备为要发送或存储的每个数据块计算一个短的、固定长度的二进制序列，称为校验值或 CRC，并将其附加到数据中，形成一个代码字。

`When a codeword is received or read, the device either compares its check value with one freshly calculated from the data block, or equivalently, performs a CRC on the whole codeword and compares the resulting check value with an expected residue constant.`\
`If the CRC values do not match, then the block contains a data error.`

`译文：当接收或读取代码字时，设备要么将其校验值与从数据块中新计算出的校验值进行比较，要么等效地对整个代码字执行 CRC，并将结果校验值与预期的剩余常数进行比较。 如果 CRC 值不匹配，则块包含数据错误。`

手动计算CRC值真的很难且浪费时间，因此我们在MTools中添加了CRC8 & CRC16算法。 这确实可以节省您通过一个表达式获取 CRC 值的时间。&#x20;

*注意：这是一个完整版的付费特性。*

## 字节变量

Mifare 1K 卡片的每一块中包含 16 个字节，可以使用`b0` `b1` `b2` ... `b14` `b15` 作为每一字节变量。

## CRC-8 校验

CRC-8的校验值只有一个字节，MTools支持的CRC-8算法如下：

|       算法       | 表达式                    |               运算结果              |
| :------------: | ---------------------- | :-----------------------------: |
|      CRC-8     | crc8(**0,1,5,8**)      |   `b0` `b1` `b5` `b8`的CRC-8校验值  |
| CRC-8/CDMA2000 | crc8cdma2000(**0:14**) | `b0` 到 `b14` 的CRC-8/CDMA2000校验值 |
|   CRC-8/DARC   | crc8darc(**0:14**)     |              参考上一条              |
|  CRC-8/DVB-S2  | crc8dvs2(**0:14**)     |              参考上一条              |
|    CRC-8/EBU   | crc8eu(**0:14**)       |              参考上一条              |
|  CRC-8/I-CODE  | crc8icode(**0:14**)    |              参考上一条              |
|    CRC-8/ITU   | crc8itu(**0:14**)      |              参考上一条              |
|   CRC-8/MAXIM  | crc8maxim(**0:14**)    |              参考上一条              |
|   CRC-8/ROHC   | crc8rohc(**0:14**)     |              参考上一条              |
|   CRC-8/WCDMA  | crc8wcdma(**0:14**)    |              参考上一条              |

## CRC-16 校验

CRC-16的校验值有两个字节。通过在表达式后加0或1，可以分布获得两个字节的值，MTools支持的CRC-16算法如下：

| 算法                 | 表达式 0                  | 表达式 1                  | 两字节异或值                |
| ------------------ | ---------------------- | ---------------------- | --------------------- |
| CRC-16/CCITT-FALSE | crc16ccittfalse(0:14)0 | crc16ccittfalse(0:14)1 | crc16ccittfalse(0:14) |
| CRC-16/ARC         | crc16arc(0:14)0        | crc16arc(0:14)1        | crc16arc(0:14)        |
| CRC-16/AUG-CCITT   | crc16augccitt(0:14)0   | crc16augccitt(0:14)1   | crc16augccitt(0:14)   |
| CRC-16/BUYPASS     | crc16buypass(0:14)0    | crc16buypass(0:14)1    | crc16buypass(0:14)    |
| CRC-16/CDMA2000    | crc16cdma2000(0:14)0   | crc16cdma2000(0:14)1   | crc16cdma2000(0:14)   |
| CRC-16/DDS-110     | crc16dds110(0:14)0     | crc16dds110(0:14)1     | crc16dds110(0:14)     |
| CRC-16/DECT-R      | crc16dectr(0:14)0      | crc16dectr(0:14)1      | crc16dectr(0:14)      |
| CRC-16/DECT-X      | crc16dectx(0:14)0      | crc16dectx(0:14)1      | crc16dectx(0:14)      |
| CRC-16/DNP         | crc16dnp(0:14)0        | crc16dnp(0:14)1        | crc16dnp(0:14)        |
| CRC-16/EN-13757    | crc16en13757(0:14)0    | crc16en13757(0:14)1    | crc16en13757(0:14)    |
| CRC-16/GENIBUS     | crc16genibus(0:14)0    | crc16genibus(0:14)1    | crc16genibus(0:14)    |
| CRC-16/MAXIM       | crc16maxim(0:14)0      | crc16maxim(0:14)1      | crc16maxim(0:14)      |
| CRC-16/MCRF4XX     | crc16mcrf4xx(0:14)0    | crc16mcrf4xx(0:14)1    | crc16mcrf4xx(0:14)    |
| CRC-16/RIELLO      | crc16riello(0:14)0     | crc16riello(0:14)1     | crc16riello(0:14)     |
| CRC-16/T10-DIF     | crc16t10dif(0:14)0     | crc16t10dif(0:14)1     | crc16t10dif(0:14)     |
| CRC-16/TELEDISK    | crc16teledisk(0:14)0   | crc16teledisk(0:14)1   | crc16teledisk(0:14)   |
| CRC-16/TMS37157    | crc16tms37157(0:14)0   | crc16tms37157(0:14)1   | crc16tms37157(0:14)   |
| CRC-16/USB         | crc16usb(0:14)0        | crc16usb(0:14)1        | crc16usb(0:14)        |
| CRC-A              | crc16a(0:14)0          | crc16a(0:14)1          | crc16a(0:14)          |
| CRC-16/KERMIT      | crc16kermit(0:14)0     | crc16kermit(0:14)1     | crc16kermit(0:14)     |
| CRC-16/MODBUS      | crc16modbus(0:14)0     | crc16modbus(0:14)1     | crc16modbus(0:14)     |
| CRC-16/X-25        | crc16x25(0:14)0        | crc16x25(0:14)1        | crc16x25(0:14)        |
| CRC-16/XMODEM      | crc16xmodem(0:14)0     | crc16xmodem(0:14)1     | crc16xmodem(0:14)     |

## 在嗅探中的应用

最后一个字节`b15`的计算方法为`CRC-8/MAXIM`，结果在一秒内可计算得出。

![](https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb9EWn7Hqb4Mn3bhfn9%2F-Mb9JHWEYlP8OyWsVqOY%2F1559024659102.png?alt=media\&token=7fd1586e-02db-4513-a7e7-44da3b4978cf)


# 如何为GAT562升级 Meshtastic原版和中文固件

\
感谢 MeshCN 社区伙伴的支持，现如今Meshtastic官方已支持 GAT562的固件支持，最新的固件都会发布并同步在<https://github.com/meshtastic/firmware/releases> 的仓库中。

以往的 nRF52840 Meshtastic设备或 GAT562 的固件升级方法有2种方式，

1. USB连接拓展从Github下载后解包出来适合GAT562的`uf2`文件
2. 通过nRF的`DFU App` 蓝牙上传从从Github下载后解包出来适合 GAT562 的`ota.zip`文件

如今 MTools BLE 已支持 GAT562 固件的一键下载和快速的Legacy DFU更新，整个过程大概花费3分钟。

<figure><img src="https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-750142621%2Fuploads%2FLaU56ohYYhfpwUl0isei%2Fimage.png?alt=media&amp;token=c1ce567f-2d68-4dbf-b1b3-d2f522c64e6e" alt=""><figcaption></figcaption></figure>

### 升级官方最新固件

1. 前往`工具` > `Meshtastic®`
2. 从列表中选择GAT562，固件将下载。
3. 连接到您的 nRF52 设备。
4. 点击开始上传固件。

<figure><img src="https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-750142621%2Fuploads%2FwdY2H4DsSgu9Uft0gUcw%2FMTools%20BLE%20GAT562%20Steps.jpeg?alt=media&amp;token=1a026b20-9494-4190-94cb-2e4ebf08d536" alt=""><figcaption></figcaption></figure>

### 升级中文消息固件

1. 前往`工具` > `Meshtastic®`
2. 在仓库设置中编辑 Meshtastic 设置，修改仓库链接\
   [`https://github.com/whywilson/meshtastic-firmwar`](https://github.com/whywilson/meshtastic-firmware)
3. 余下步骤参考上一节内容，即可获得消息的中文显示支持

<figure><img src="https://2926833552-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-750142621%2Fuploads%2F9mHa54hR4b1Ncqj0XH16%2F9a209b7823c6f81e59cb4be863cf2077.jpg?alt=media&amp;token=aee7d9cc-6aaa-4fe2-906c-f5f80c9cad8c" alt=""><figcaption></figcaption></figure>


# MTools Tec Docs: RFID, NFC, LoRa & Meshtastic Guides

Setup guides for MTools apps, PN532, Chameleon Ultra, Proxmark3 X, GAT562, Meshtastic and MeshCore hardware, firmware, and troubleshooting.

Documentation for MTools Tec RFID, NFC, UHF, LoRa, Meshtastic, MeshCore, SDR, IoT, and tracking products. Choose a product family below to find setup instructions, compatible software, firmware updates, and troubleshooting help.

{% hint style="info" %}
**New here?** Start with the product name printed on your device or shown in your order. If you are unsure which hardware fits your project, [contact MTools Support](https://shop.mtoolstec.com/contact-us/).
{% endhint %}

## Explore product documentation

{% content-ref url="<https://docs.mtoolstec.com/apps-and-downloads>" %}
<https://docs.mtoolstec.com/apps-and-downloads>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/rfid-nfc-and-uhf-hardware>" %}
<https://docs.mtoolstec.com/rfid-nfc-and-uhf-hardware>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/lora-meshtastic-and-meshcore-devices>" %}
<https://docs.mtoolstec.com/lora-meshtastic-and-meshcore-devices>
{% endcontent-ref %}

{% content-ref url="<https://docs.mtoolstec.com/sdr-iot-and-expansion-hardware>" %}
<https://docs.mtoolstec.com/sdr-iot-and-expansion-hardware>
{% endcontent-ref %}

## Software and apps

Use MTools Tec apps with built-in NFC or supported external readers and emulators.

* [View all official apps and downloads](https://docs.mtoolstec.com/apps-and-downloads)
* **MTools for Android:** [Google Play](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools)
* **MTools BLE:** [Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite) · [Apple App Store](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)
* **MIFARE Ultralight Tool:** [Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)
* **MCalc:** [Google Play](https://play.google.com/store/apps/details?id=cc.yuyeye.mcalc) · [Documentation](https://docs.mtoolstec.com/help-and-info-mcalc)

## RFID and NFC hardware

### Chameleon Ultra and Chameleon Lite

Open-source RFID emulation and research tools for authorized testing and development.

* [Set up Chameleon Ultra](https://docs.mtoolstec.com/how-to-use-chameleonultra)
* [Write a MIFARE dump](https://docs.mtoolstec.com/how-to-use-chameleonultra-to-write-mifare-dump)
* [Upgrade Chameleon firmware](https://docs.mtoolstec.com/upgrade-the-firmware-of-chameleonultra-and-chameleonlite)
* [Shop Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)

### PN532 readers and tools

Use PN532-based hardware over USB, Bluetooth, or the command line.

* [PN532 CLI quick start](https://docs.mtoolstec.com/pn532-cli/how-to-start)
* [Emulate an NDEF message](https://docs.mtoolstec.com/pn532-cli/ntag-emulate)
* [Use the terminal with ACR122U and PN532](https://docs.mtoolstec.com/mtools-app/terminal-for-acr122u-and-pn532)
* [Shop All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/)

### Proxmark3 X

Advanced RFID research hardware has a dedicated documentation site.

* [Open Proxmark3 X documentation](https://proxmark3x.mtoolstec.com/)
* [Shop Proxmark3 X](https://shop.mtoolstec.com/product/proxmark3-x/)

### Cards and tags

Check the exact protocol, UID length, generation, and write method before purchasing or programming a tag.

* [Use UID Changer](https://docs.mtoolstec.com/how-to-use-uid-changer)
* [Shop cards and tags](https://shop.mtoolstec.com/)

## LoRa and mesh devices

### GAT562 30S

Documentation for GAT562 30S Meshtastic and MeshCore hardware.

* [GAT562 30S overview and specifications](https://docs.mtoolstec.com/lora-devices/gat562-30s-mesh-module)
* [nRF52840 Meshtastic and MeshCore BLE OTA](https://docs.mtoolstec.com/nrf52840-meshtastic-meshcore-firmware-ble-ota)
* [Shop GAT562 30S](https://shop.mtoolstec.com/product/gat562-30s-kit/)

## Popular tasks

* [Read a supported card with MTools](https://docs.mtoolstec.com/mtools-app/how-to-use-the-mtools-app)
* [Compare MTools with MIFARE Classic Tool](https://docs.mtoolstec.com/mtools-app/mtools-vs-mifare-classic-tool)
* [Upgrade Chameleon Ultra or Chameleon Lite](https://docs.mtoolstec.com/upgrade-the-firmware-of-chameleonultra-and-chameleonlite)
* [Upgrade Pixl.js firmware](https://docs.mtoolstec.com/upgrade-the-firmware-of-pixl.js)
* [Configure a GAT562 30S mesh module](https://docs.mtoolstec.com/lora-devices/gat562-30s-mesh-module)

## Store and support

* [Browse MTools Tec products](https://shop.mtoolstec.com/)
* [Track an order](https://shop.mtoolstec.com/track-my-order/)
* [Contact technical support](https://shop.mtoolstec.com/contact-us/)

{% hint style="warning" %}
Use RFID, NFC, and wireless research tools only on systems and credentials you own or are explicitly authorized to test. Follow applicable laws and local radio regulations.
{% endhint %}


# Apps & Downloads

Official MTools Tec apps for Android and iOS, with platform compatibility and download links.

Download official MTools Tec software from Google Play or the Apple App Store. Select an app based on your hardware, tag type, and mobile platform.

{% hint style="warning" %}
Install MTools apps only from the official store links below. App availability and device compatibility can vary by country, operating-system version, and mobile hardware.
{% endhint %}

## MTools

The primary Android app for reading, writing, comparing, and analyzing supported MIFARE Classic and Ultralight tags. It works with compatible built-in NFC hardware and supported external readers such as ACR122U and PN532.

* **Platform:** Android
* [Download MTools from Google Play](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools)
* [Read the quick-start guide](https://docs.mtoolstec.com/mtools-app/how-to-use-the-mtools-app)
* [Open the complete user guide](https://docs.mtoolstec.com/mtools-app/mtools-app-user-guide)

## MTools BLE

The cross-platform app for supported Bluetooth RFID readers and emulators, including PN532 BLE, PCR532, Chameleon Ultra, Chameleon Lite, and Pixl.js. It also includes firmware and OTA tools for supported devices.

* **Platforms:** Android, iPhone and iPad
* [Download MTools BLE from Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite)
* [Download MTools BLE from the Apple App Store](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)
* [Read the MTools BLE guide](https://docs.mtoolstec.com/help-and-info-mtools-lite)
* [Unlock MTools BLE](https://docs.mtoolstec.com/how-to-unlock)

{% hint style="info" %}
On iPhone and iPad, MIFARE Classic workflows require a supported external reader such as PN532 BLE or Chameleon Ultra; the phone's built-in NFC interface does not provide the same MIFARE Classic access.
{% endhint %}

## MIFARE Ultralight Tool

A focused Android utility for reading, writing, scanning, and inspecting supported MIFARE Ultralight and NTAG products.

* **Platform:** Android
* **Supported families include:** MF0UL11, MF0UL21, MF0ULC, NTAG213, NTAG215, and NTAG216
* [Download MIFARE Ultralight Tool from Google Play](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)

## MCalc — Mifare Calculator

Calculate XOR, SUM, data sum-check values, CRC-8 variants, and CRC-16 variants from hexadecimal data.

* **Platform:** Android
* [Download MCalc from Google Play](https://play.google.com/store/apps/details?id=cc.yuyeye.mcalc)
* [Read the MCalc guide](https://docs.mtoolstec.com/help-and-info-mcalc)

## M Keys

Generate and manage MIFARE keys for authorized cards and supported workflows with built-in NFC or ACR122U.

* **Platform:** Android
* [Download M Keys from Google Play](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools.keygen)

## All Android apps

[View all apps published by MTools Tec on Google Play](https://play.google.com/store/apps/dev?id=7994355636404806984)

## Compatible hardware

* [All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/)
* [PCR532](https://shop.mtoolstec.com/product/pcr532/)
* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Pixl.js](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)

Need help choosing an app or reader? [Contact MTools Support](https://shop.mtoolstec.com/contact-us/).


# RFID, NFC & UHF Hardware

Documentation and product selection for RFID/NFC readers, emulators, magic cards, NFC tags, and UHF tools.

Find documentation and compatible products by device type. Before purchasing, confirm the protocol, frequency, UID length, card generation, and required write method.

## Readers and development tools

* [All-In-One PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532/) — USB and Bluetooth PN532 reader/writer
* [PCR532](https://shop.mtoolstec.com/product/pcr532/) — compact RFID and NFC tool
* [PN532 CLI quick start](https://docs.mtoolstec.com/pn532-cli/how-to-start)
* [Proxmark3 X](https://shop.mtoolstec.com/product/proxmark3-x/) · [dedicated documentation](https://proxmark3x.mtoolstec.com/)
* [Proxmark3 RDV4.01](https://shop.mtoolstec.com/product/proxmark3-rdv4-01/)
* [iCopy-XS](https://shop.mtoolstec.com/product/icopy-xs/)

## RFID emulators

* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/) · [setup guide](https://docs.mtoolstec.com/how-to-use-chameleonultra)
* [Chameleon Ultra SE](https://shop.mtoolstec.com/product/chameleonultra-se/)
* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Pixl.js](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/) · [firmware guide](https://docs.mtoolstec.com/upgrade-the-firmware-of-pixl.js)
* [MTools BLE guide](https://docs.mtoolstec.com/help-and-info-mtools-lite)

## Magic cards and NFC tags

* [Gen4 Ultimate Magic Card](https://shop.mtoolstec.com/product/ultimate-magic-card-gen4/)
* [MIFARE Classic UID-changeable cards](https://shop.mtoolstec.com/product/uid-changeable-1k-s50-chinese-magic-card/)
* [UID-changeable NTAG213 / 215 / 216](https://shop.mtoolstec.com/product/uid-changeable-ntag-n213-n215-n216/)
* [Gen3 ISO15693 tag](https://shop.mtoolstec.com/product/gen3-uid-changeable-iso15693-tag-80-block/)
* [MIFARE Ultralight Tool](https://play.google.com/store/apps/details?id=com.mtoolstec.mifareultralighttool)

## UHF RFID

* [UHF reader for supported TID workflows](https://shop.mtoolstec.com/product/uhf-reader-support-changing-tid/)
* [UHF TID tag kit](https://shop.mtoolstec.com/product/tid-changeable-uhf-tag-kit-with-reader/)
* [UHF expansion for Flipper Zero](https://shop.mtoolstec.com/product/uhf-expansion-for-flipperzero/)

{% hint style="warning" %}
Use RFID and NFC tools only with cards, credentials, and systems you own or are explicitly authorized to test.
{% endhint %}


# NFC & RFID Emulators

Compare NFC and RFID emulators from MTools Tec, including Chameleon Ultra, PN532Killer, Pixl.js, GroveNFC, Flipper Zero and ST25R3916 devices.

Choose an NFC or RFID emulator by frequency, protocol, connection and workflow. This collection covers portable tag emulators, reader/emulator development tools, Amiibo-compatible devices and multi-purpose security research hardware.

[Browse all RFID emulators](https://shop.mtoolstec.com/product-category/rfid-emulator/)

## Quick comparison

| Product family            | Best for                                                 | Frequency / protocols                                        | Connection                           |
| ------------------------- | -------------------------------------------------------- | ------------------------------------------------------------ | ------------------------------------ |
| Chameleon Ultra family    | Portable LF/HF reading, emulation and authorized testing | 125 kHz and 13.56 MHz; support varies by firmware            | Bluetooth and USB                    |
| Chameleon Mini / Lite     | Compact MIFARE-focused emulation                         | 13.56 MHz, primarily ISO14443A                               | USB or Bluetooth, depending on model |
| PN532Killer               | Reader, emulator, sniffer and protocol testing           | ISO14443A/B, ISO15693 and EM4100                             | Model-dependent                      |
| Pixl.js                   | Amiibo and interactive NFC tag collections               | 13.56 MHz NFC                                                | Bluetooth / USB firmware workflow    |
| GroveNFC / ST25R3916 Unit | Embedded development and custom NFC projects             | ISO14443A/B, FeliCa and ISO15693; emulation varies by device | Grove / I2C                          |
| Flipper Zero              | Multi-protocol portable experimentation                  | NFC, LF RFID and other radios                                | USB and Bluetooth                    |

{% hint style="info" %}
Protocol support, tag capacity and reader mode differ by model and firmware. Check the product page before ordering; “NFC emulator” does not mean every NFC or RFID protocol is supported.
{% endhint %}

## Chameleon portable emulators

### Chameleon Ultra

A portable open-source LF/HF RFID tool for reading, emulation and authorized security research. It is the most complete choice in the Chameleon family when both 125 kHz and 13.56 MHz workflows are required.

* [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra/)
* [Chameleon Ultra SE](https://shop.mtoolstec.com/product/chameleonultra-se/) — compact hardware variants with the same software ecosystem
* [ChameleonUltra Dev Kit](https://shop.mtoolstec.com/product/chamleonultra-dev-kit/) — development and integration package
* [Setup and usage guide](https://docs.mtoolstec.com/how-to-use-chameleonultra)
* [Firmware upgrade guide](https://docs.mtoolstec.com/upgrade-the-firmware-of-chameleonultra-and-chameleonlite)

### Chameleon Lite and Chameleon Mini

Choose these for smaller, focused 13.56 MHz / MIFARE emulation workflows where the full dual-frequency feature set of Chameleon Ultra is not required.

* [Chameleon Lite](https://shop.mtoolstec.com/product/chameleon-lite/)
* [Chameleon Mini Rev.E RDV 2.0](https://shop.mtoolstec.com/product/chameleon-mini-rev-e-rdv-2-0-2022/)

## NFC emulators and development tools

### PN532Killer

A multi-function reader, emulator and sniffer for ISO14443A, ISO14443B, ISO15693 and EM4100 research workflows.

* [PN532Killer](https://shop.mtoolstec.com/product/pn532killer/)
* [M5StickC adapter](https://shop.mtoolstec.com/product/m5stickc-adapter-for-pn532killer/)

### Pixl.js OLED for Amiibo

A display-equipped NFC device designed for managing compatible virtual tag collections and Amiibo workflows.

* [Pixl.js OLED for Amiibo](https://shop.mtoolstec.com/product/pixl-with-oled-for-amiibo/)
* [Pixl.js firmware upgrade guide](https://docs.mtoolstec.com/upgrade-the-firmware-of-pixl.js)

### GroveNFC

An open communication NFC module for M5Stick, AtomS3, CardPuter and other Grove-compatible hosts. It supports reader and emulator development with open-source demo firmware.

* [GroveNFC Open-Source NFC Module](https://shop.mtoolstec.com/product/grovenfc/)

### M5Stack NFC Universal Unit (ST25R3916)

An I2C NFC reader/writer and development unit supporting ISO14443A/B, FeliCa and ISO15693, plus NFC-A and NFC-F card emulation modes.

* [M5Stack NFC Universal Unit](https://shop.mtoolstec.com/product/m5stack-nfc-universal-unit-st25r3916-13-56mhz-rfid-reader-writer-module/)

## Multi-purpose device

### Flipper Zero

A portable multi-tool that includes NFC and LF RFID functions alongside other radio and hardware interfaces. Choose it for broader experimentation rather than a dedicated NFC-only workflow.

* [Flipper Zero](https://shop.mtoolstec.com/product/flipper-zero/)

## Apps, firmware and next steps

* [MTools BLE](https://docs.mtoolstec.com/help-and-info-mtools-lite) — mobile workflows for supported Chameleon devices
* [How to use Chameleon Ultra](https://shop.mtoolstec.com/how-to-use-chameleon-ultra/) — product setup, apps and desktop tools
* [RFID, NFC & UHF hardware overview](https://docs.mtoolstec.com/rfid-nfc-and-uhf-hardware)
* [Browse the full emulator collection](https://shop.mtoolstec.com/product-category/rfid-emulator/)

{% hint style="warning" %}
Use emulation, cloning, sniffing and security-testing functions only on tags, credentials and systems you own or have explicit authorization to test. Capabilities and legal requirements vary by jurisdiction.
{% endhint %}


# LoRa, Meshtastic & MeshCore Devices

Compare MTools Tec LoRa, Meshtastic, MeshCore and LoRaWAN nodes, trackers, repeaters, modules, firmware and antennas.

Explore the full MTools Tec LoRa range: portable mesh nodes, GPS trackers, solar repeaters, development modules, firmware, and regional antennas. Confirm your intended firmware and locally permitted frequency before ordering.

{% hint style="info" %}
Not every device supports the same firmware or radio region. Check the individual product page for its chipset, supported frequencies, firmware options, display, GNSS, enclosure, and power configuration.
{% endhint %}

## Portable and interactive mesh nodes

### GAT562 30S Kit

A high-power mesh device with display and controls for Meshtastic and MeshCore projects.

* [GAT562 30S documentation](https://docs.mtoolstec.com/lora-devices/gat562-30s-mesh-module)
* [Shop GAT562 30S Kit](https://shop.mtoolstec.com/product/gat562-30s-kit-30dbm-mesh-device/)

### Meshtiny

Compact complete mesh node with integrated controls and display.

* [Shop Meshtiny](https://shop.mtoolstec.com/product/meshtiny/)

### Seeed Wio Tracker L1 Pro

Joystick-controlled portable tracker sold with the MTools Tec ADV bootloader option.

* [Shop Wio Tracker L1 Pro](https://shop.mtoolstec.com/product/seeed-wio-tracker-l1-pro/)

### M5 Unit C6L

Compact M5Stack-format LoRa unit compatible with supported Meshtastic and MeshCore workflows.

* [Shop M5 Unit C6L](https://shop.mtoolstec.com/product/m5stack-unitc6l/)

## Trackers and location devices

### GAT562 Meshtastic Tracker

nRF52840 and SX1262 off-grid tracker with GNSS and display.

* [Shop GAT562 Meshtastic Tracker](https://shop.mtoolstec.com/product/gat562-mesh-tracker/)

### SenseCAP T1000-E

Card-size IP65 Meshtastic tracker with GNSS and integrated sensors.

* [Shop SenseCAP T1000-E](https://shop.mtoolstec.com/product/seeed-sensecap-card-tracker-t1000-e-for-meshtastic/)

### Meshtiny FindMy

Compact location-focused Meshtiny variant.

* [Shop Meshtiny FindMy](https://shop.mtoolstec.com/product/meshtiny-findmy/)

### SenseCAP T2000-A

Industrial IP67 LoRaWAN asset tracker for equipment and outdoor deployments.

* [Shop SenseCAP T2000-A](https://shop.mtoolstec.com/product/sensecap-t2000-a-industrial-lorawan-asset-tracker-ip67-gps-ble-wi-fi-for-heavy-equipment/)

## Solar nodes and repeaters

### GAT562 30S Mesh Pod Solar Repeater

30 dBm solar mesh repeater for fixed outdoor coverage.

* [Shop GAT562 30S Mesh Pod](https://shop.mtoolstec.com/product/gat562-30s-mesh-solar-repeater/)

### GAT562 Solar EVB

22 dBm MPPT solar development board for custom solar nodes.

* [Shop GAT562 Solar EVB](https://shop.mtoolstec.com/product/gat562-solar-evb/)

### GAT562 Mesh Solar Relay

Autonomous off-grid solar repeater for permanent mesh-network deployments.

* [Shop GAT562 Mesh Solar Relay](https://shop.mtoolstec.com/product/gat562-mesh-solar-relay-autonomous-off-grid-repeater-for-mesh-networks/)

## Development boards and embedded modules

### GAT nRF52840 + SX1262 Mesh Module

Compact module for integrating supported mesh functionality into custom hardware.

* [Shop GAT Mesh Module](https://shop.mtoolstec.com/product/gat-nrf52840-sx1262-mesh-module/)

### Mesh Node T114 Rev. 2.0

nRF52840 and SX1262 development board with optional display and GPS support for Meshtastic and LoRaWAN projects.

* [Shop Mesh Node T114](https://shop.mtoolstec.com/product/mesh-node-t114-rev-2-0-nrf52840-sx1262-lora-node-gps-meshtastic-and-lorawan-compatible/)

### N5262M Module

Compact nRF52840 and SX1262 module for embedded Meshtastic and custom LoRa development.

* [Shop N5262M](https://shop.mtoolstec.com/product/nrf52840-sx1262-mesh-node-n5262m-module-meshtastic-compatible/)

## Firmware and OTA tools

* [T1000-E TapTap firmware](https://shop.mtoolstec.com/product/t1000-e-taptap-firmware/)
* [Browse LoRa firmware](https://shop.mtoolstec.com/product-category/lora/firmware/)
* [nRF52840 Meshtastic and MeshCore BLE OTA guide](https://docs.mtoolstec.com/nrf52840-meshtastic-meshcore-firmware-ble-ota)
* [MTools BLE for Android](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite)
* [MTools BLE for iPhone and iPad](https://apps.apple.com/us/app/mtools-ble-rfid-reader/id1531345398)

## Antennas and regional frequency

* [868 MHz 20 cm whip antenna](https://shop.mtoolstec.com/product/868mhz-20cm-whip-antenna/)
* [868 MHz 40 cm whip antenna](https://shop.mtoolstec.com/product/868mhz-40cm-whip-antenna/)
* [915 MHz 20 cm whip antenna](https://shop.mtoolstec.com/product/915mhz-20cm-whip-antenna/)

{% hint style="warning" %}
Use only the frequency band and transmit power permitted in your country. Match the device variant and antenna frequency before transmitting.
{% endhint %}

[Browse the complete LoRa category](https://shop.mtoolstec.com/product-category/lora/)


# SDR, IoT & Expansion Hardware

Product selection for software-defined radio, M5Stack, Flipper Zero expansions, and other IoT hardware.

These products currently use their store pages as the primary source for specifications and compatibility. Dedicated technical guides will be added as the documentation library expands.

## Software-defined radio

* [RTL-SDR Blog V3](https://shop.mtoolstec.com/product/rtl-sdr-blog-v3-software-defined-radio-dongle-usb-c/)
* [SignalSDR Pro](https://shop.mtoolstec.com/product/signalsdr-pro/)

## M5Stack and IoT

* [M5StickC PLUS SE](https://shop.mtoolstec.com/product/m5stickc-plus-se-mini-iot-dev-kit-esp32-pico/)
* [M5StickC PLUS2](https://shop.mtoolstec.com/product/m5stickc-plus2-esp32-mini-iot-development-kit/)
* [M5StickS3](https://shop.mtoolstec.com/product/m5sticks3-esp32-s3-mini-iot-development-kit/)

## Flipper Zero expansions

* [UHF RFID expansion](https://shop.mtoolstec.com/product/uhf-expansion-for-flipperzero/)
* [CC1101 Sub-GHz expansion](https://shop.mtoolstec.com/product/flipper-zero-cc1101-module-subghz-433mhz-multi-function-development-board/)
* [Browse all Flipper Zero accessories](https://shop.mtoolstec.com/product-category/accessories/flipper-zero-accessories/)

## Store and support

* [Browse all products](https://shop.mtoolstec.com/shop/)
* [Contact technical support](https://shop.mtoolstec.com/contact-us/)


# Help & Info | MCalc

Guide book for MCalc app.

## What's this MCalc app for?

It is used to calculate HEX numbers with different logic calculations.

## Basic Algorithms MCalc supports

* SUM
* CHECKSUM
* XOR

## Advanced Algorithm MCalc supports

* CRC-8
  * CRC-8
  * CRC-8/CDMA2000
  * CRC-8/DARC
  * CRC-8/DVB-S2
  * CRC-8/EBU
  * CRC-8/I-CODE
  * CRC-8/ITU
  * CRC-8/MAXIN
  * CRC-8/ROHC
  * CRC-8/WCDMA
* CRC-16
  * CRC-16/CCITT-FALSE
  * CRC-16/ARC
  * CRC-16/AUG-CCITT
  * CRC-16/BUYPASS
  * CRC-16/CDMA2000
  * CRC-16/DDS-110
  * CRC-16/DECT-R
  * CRC-16/DECT-X
  * CRC-16/DNP
  * CRC-16/EN-13757
  * CRC-16/GENIBUS
  * CRC-16/MAXIN
  * CRC-16/MCRF4XX
  * CRC-16/RIELLO
  * CRC-16/T10-DIF
  * CRC-16/TELEDISK
  * CRC-16/TMS37157
  * CRC-16/USB
  * RC-A
  * CRC-16/KERMIT
  * CRC-16/MODBUS
  * CRC-16/X-25
  * CRC-16/XMODEM


# Help & Info | MTools BLE

Help & Info | MTools Lite

## Introduction

MTools BLE is used to study RFID cards with inner NFC and external Bluetooth LE RFID Reader.&#x20;

With inner NFC, you can read and write different types of tag depending on the Platform of your device. With the external Bluetooth LE RFID Reader, you can access all ISO1443-A Type tags with APDU command with optimized commands, also operate the UID changeable magic card with one click backdoor command.

## Download Link

|                                 iOS                                 |                                        Android                                       |
| :-----------------------------------------------------------------: | :----------------------------------------------------------------------------------: |
| [App Store](https://apps.apple.com/us/app/mtools-lite/id1531345398) | [Play Store](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite) |

## Supported Card Type by NFC

|        Type       | Android | iOS |
| :---------------: | :-----: | :-: |
|        NTAG       |    ✓    |  ✓  |
| Mifare Classic 1K |    ✓    |  ✘  |
| Mifare Classic 4K |    ✓    |  ✘  |
|      DESFire      |    ✓    |  ✓  |
|       Felica      |    ✓    |  ✓  |
|      ISO7816      |    ✓    |  ✓  |
|      ISO15693     |    ✓    |  ✓  |
|  other ISO14443-A |    ✓    |  ✓  |

## Supported Card Type by Reader

|        Type       |                                  PN532\_BLE                                  |
| :---------------: | :--------------------------------------------------------------------------: |
| Mifare Classic 1K |                                       ✓                                      |
| Mifare Classic 4K |                                       ✓                                      |
|       Felica      |                                       ✓                                      |
|    ISO14443-4A    |                                       ✓                                      |
|  Innovision Jewel |                                       ✓                                      |
|                   | [**Buy Now >>**](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532) |

## Terminal

Terminal for MTools Lite is a friendly-designed feature for the beginner and professionals. It shortens the complex command and checks byte calculation.&#x20;

### Video Guide

{% embed url="<https://www.youtube.com/watch?v=GgQkHbzhINI>" %}

### NXP Document

[PN532 User Manual.pdf](https://www.nxp.com/docs/en/user-guide/141520.pdf)

[PN532 Datasheet.pdf](https://www.nxp.com.cn/docs/en/nxp/data-sheets/PN532_C1.pdf)

## HEX Calculator

MTools BLE app can automatically calculate different types of check bytes, including **SUM**, **XOR**, **AND**, and **CS**(CheckSum).

## BCC Calculator

BCC stands for Block Check Character, which is the XOR value of the UID of the Mifare type card.

## ACS Decoder

ACS stands for Access Bits Controller of the Mfiare Classic 1K/4K tag. Fill in the 3 bits of the sector trailer, MTools app will show the permission of KeyA and KeyB while reading and writing the Mifare Sector.

## UID Changer

Support change the UID of Magic card from Gen1A, Gen2, Gen3 and Gen4. The functions support on the ChameleonUltra and PN532 Reader.

[Learn how to use UID Changer](/how-to-use-uid-changer)

### Chameleon Ultra

MTools BLE supports GUI and CLI for ChameleonUltra, ChameleonUltra SE and   ChameleonLite.&#x20;

[Learn how to use ChameleonUltra with MTools BLE](/how-to-use-chameleonultra)

### Pixl.js Tool

MTools BLE can manage the file and dump on Pixl.js devices. Also the firmware of Pixl.js OLED and LCD can be upgrade easily.

[Learn how to upgrade the firmware of Pixl.js with MTools BLE](/upgrade-the-firmware-of-pixl.js)&#x20;


# MTools App User Guide

Complete user guide for the MTools App, including card management, reading, writing, rules, import, export, and supported formats.

## 1.Overview

MTools is a Material Design APP to easily read, write, analyze and charge `Mifare Classic` Tag. What you need firstly:

1. `Mifare 1K`Supported Device.
   * Inner NFC
   * USB: `ACR122U` `PN532`
   * Bluetooth: `PN532`
2. KeyA and keyB of the sector.

**Please comply with local laws, only used for study and testing.**

## 2.YouTube Chanel

{% tabs %}
{% tab title="Magic Card" %}
{% embed url="<https://youtu.be/AWc7gp8vUKw>" %}
What's Magic Card and How to Clone
{% endembed %}
{% endtab %}

{% tab title="Mi Band" %}
{% embed url="<https://youtu.be/1Bl-FFALNic>" %}
MTools read/write/clone data on Mi Band 3 NFC
{% endembed %}
{% endtab %}

{% tab title="PN532" %}
{% embed url="<https://youtu.be/dN9B6behg88>" %}
All-in-one PN532 | USB & BLE
{% endembed %}
{% endtab %}

{% tab title="ACR122U" %}
{% embed url="<https://youtu.be/a7nUWIN7s-4>" %}
Read card with ACR122U on Android phone
{% endembed %}
{% endtab %}
{% endtabs %}

## 3. Lists

When the tag card on the list page, the tag info dialog will pop up. It will show status and suggestions depending on your card type.

![MTools Tag Info Dialog](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-MeFbxSPfjqbURVJv4CD%2F-MeFfaE3M6ae-hDPe7mQ%2FMTools-Tag-Info-Dialog.png?alt=media\&token=b636423a-38dd-47e3-902c-836ca170aa14)

### 3.1 Add Card

Click the **+ floating button** will display `Add Card Dialog`, put the Mifare Classic Card close to the NFC antenna, then you can add a card to the APP.

### 3.2 Remove Card

Slide the item toward the right to remove the card.

### 3.3 Sort Card

Press and drag to sort cards.

### 3.4 Filter Card

Drag down the list to filter cards by name, UID, SAK, or DateTime.

### 3.5 Import File

* \*.mto file is the specific JSON file that includes tag information, keys, and rules.
* \*.mfd | \*.bin file is the Mifare dump file read by libnfc library.
* \*.mct file is the dump file read by Mifare Classic Tool.

### 3.6 Export File

Supports exporting to 5 types:

* `*.mto` Includes card sectors, dumps, and rules.
* `card-list.csv` Includes card, id, name, SAK, and DateTime.
* `keys.txt` Includes all keys added.
* `sniffer.csv` Includes all sniffer records.
* `record.csv` Includes all charging records.

## 4. Details

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb2DALCot-JEfRfFzgw%2F-Mb2DWyQKcYyzP0PCBHI%2Fbutton_func.jpeg?alt=media\&token=0042f90f-0b3d-4f81-a0ee-36f4860c4e6e)

### 4.1 Add & Remove Sector

:new:Click the **+** floating butto**n** and choose `Add 1 Sector`, select the sector number by sliding the picker, and enter 6 bytes (12 characters) valid key A or key B, click `Complete` to save.

:arrow\_backward:Slide the item toward the right to remove the sector and keys.

### 4.2 Modify Key

Click the **modify button** will display the `Modify Key Dialog`, select new sector number by sliding the picker, and modify the 6 bytes (12 digits or letters) valid key A or key B, click `Complete`save new keys or sector.

### 4.3 Read Sector

After the card is close to the NFC antenna, click on the **read button** will read 4 blocks of data from the clicked sector, you can modify and write the new data.

### 4.4 Manage Rule

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6cAYKHeOMMPTJ9wUw%2Fmt%20handle%20block.jpg?alt=media\&token=1ebdb17c-ad14-4294-8f51-d3377f81c759)

* Check on the checkbox for the block to handle.
* Click on **MARK** to mark selected blocks.
* Click on **COPY TO** to copy the rule to another card.

#### **4.4.1 Mark Money Byte**

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6dBobEv68KsF3qfQB%2Fmark_money.jpeg?alt=media\&token=c8c2a671-3eb9-4029-95c4-b7701179d9c1)

Mark the byte, then verify the money is correct, and click Next.

#### **4.4.2 Mark Checked Byte**

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6Y_w4X-HiE9LY0Djm%2F-Mb6dG-lcMqK6kJa8mru%2Fmark_check.jpeg?alt=media\&token=883d45a6-a09f-4f8a-8509-2ea87a4d40a5)

Check the bytes that change and add expressions. Make sure that it's correct then click OK.

#### **4.4.2.1 Supported operations:**

> Basic: + - × ÷
>
> Advanced : #
>
> Logical : xor not
>
> CRC8: crc8, crc8cdma2000, crc8darc, crc8dvbs2, crc8ebu, crc8icode, crc8itu, crc8maxim, crc8rohc, crc8wcdma
>
> CRC16: crc16ccittfalse, crc16arc, crc16buypass, crc16cdma2000, crc16dds110, crc16dectr, crc16dectx, crc16dnp, crc16en13757, crc16genibus, crc16maxim, crc16mcrf4xx, crc16riello, crc16t10dif, crc16teledisk, crc16tms37157, crc16usb, crca, crc16kermit, crc16modbus, crc16x25, crc16xmodem

[Learn more about algorithms and expressions](https://docs.mtoolstec.com/mtools-app/help-or-add-expression#example)

#### **4.4.2.2 Sort Expressions**

Press and drag to sort Expressions.

The calculation is from top to end.

### 4.5 Data Sniffer

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mb6ewXofBHU-wvHIDDn%2F-Mb6fYg-EEcTZASVu1cJ%2F%20tips_sniffer.jpg?alt=media\&token=ea2c3f7a-14da-4f60-afd2-ac60c5aaf3f5)

Must add correct keys before. After marked, it can be compared with highlight data.\
Data Backups/Restore, Compare vertically, Rule Repository.

### 4.6 Sort Sector

Press and drag to sort sector.

### 4.8 Import Dump

Click the **+** floating button, `Add Dump File` choose dump type then select file. The dump file type MTools support:

{% tabs %}
{% tab title="mfd" %}
Mifare Dump is a 1K size file that is read by PN532 with the libnfc tools.
{% endtab %}

{% tab title="bin" %}
1K size file that is read from Mifare 1K card by Proxmark 3 devices.
{% endtab %}

{% tab title="mct" %}
Text type dump file from`Mifare Classic Tools` app.
{% endtab %}
{% endtabs %}

## 5. Read From Card

Click the **+** floating button and choose `Read From Card`, you can add more keys and try to read as much data as possible from the card, and then save it to a dump file.

### 5.1 Key List

Start with default keys and customed keys added by users

### 5.2 Start To Read

Try to read as much as possible data with all keys in Key List.

## 6. Charge

### 6.1 Set Quotas

Click **+** button to change to **=** as Quotas.

### 6.2 Clear Record

Long press **the recharge record list**, then pop up the dialog will allow you to clear the recharge record or not.

### 6.3 Show Calculate Result

Long press the floating button to preview the data generated on **Rule**.

## 7.Dependency

Thanks to the friends for the contribution to the open-source community, regardless of rank.

* `ikarus23` [MifareClassicTool](https://github.com/ikarus23/MifareClassicTool)
* `afollestad` [material-dialogs](https://github.com/afollestad/material-dialogs)
* `markormesher` [android-fab](https://github.com/markormesher/android-fab)
* `didikee` [AndroidDonate](https://github.com/didikee/AndroidDonate)
* `Ice-Box` [Ice-Box](http://catchingnow.com)
* `uccmawei` [FingerprintIdentify](https://github.com/uccmawei/FingerprintIdentify)


# Simple Startup

Firstly, it's the Mifare Classic Tool that I used to write hex data back to Mifare 1k card with my NFC phone - Moto X 2013. And after several steps of studies and development, I find a way to read the money data from the card and generate legal hex data then write back it to the card. And it works perfectly, which made me so happy. Seemed like I was a real hacker, can easily change the money on the card with a simple app. After that, I want to share this happiness with all guys who are interested in RFID. After about 3 weeks of development, the first version of MTools came out. Here're the things that you need to know to use it better.

1. Get the keys from all sectors
2. Compare to find the sector with money data
3. Add card, sector, and  keys to MTools
4. Record data from after every consumption in sniffer
5. Compare and analyze the rules of dynamic bytes
6. Finish the expression
7. Charge Mifare 1k  card with one click

## Get the keys from all sectors

Some cards using default keys like `FFFFFFFFFFFF` `000000000000` `A1B2C3D4E56F` etc, which you can try to dump keys with **Mifare Classic Tools** on the NFC android phone. If the card is not fullly encrypted, it can be cracked with an RFID device to burst crack. Like **ACR122U** or **PN532**.

If the card is fully encrypted, only **PM3** can crack the keys.

## Compare to find the sector with money data

With keyA or keyB of all sectors of the card, data need to be gathered. And compare them after every consumption, so you can find the sector that data change, which means the money data may in that sector.

## Add card, sector, and  keys to MTools

The 4th block of every sector contains

`keyA(6 bytes) + Access Control(4) + keyB(6)`

## Record data from in sniffer

With sector numbers and valid keys added, it can be easy to compare data with different money amounts.

Mark the money bytes(contain money data) and check bytes(mostly the changing bytes)

## Compare and analyze the rules of dynamic bytes

Pay attention to HEX or DEC, Reverse or not and Rate on Money bytes.

Compare the Summation or XOR values with up and down check bytes.

## Finish the expression

MTools use [mXparser](http://mathparser.org/) to calculate expression in rules. Please follow the tips in MTools to add expression.

## Charge Mifare 1k  card with one click

Before charging a card, an accurate simulation is necessary, just by a long click on the $ button after tag card.

## One more thing

MTools support work with an extra device like ACR122U, PN532, PN532 BLE, which means you can use the features on a phone without NFC hardware.


# How to Use Sniffer

Depending on the Firebase of MTools, only 15% of MTools users have used Sniffer functions of MTools. It's really an easy tool for comparison and analysis. In this article, I'll show the tutorial of how to use Sniffer in MTools.

## Why Need Sniffer

After getting the keys of a sector which contains valid data, we need to compare data in different amount. So I made the Sniffer in MTools to gather and compare data more easily.\
The light pink and light-blue background show if the bytes change.

![](https://why.yuyeye.cc/post-images/1574347906909.jpg)

## Where is Sniffer in MTools

![](https://why.yuyeye.cc/post-images/1574347023367.jpg)

1. After adding a card in List Fragment, you can add a sector in Detail Fragment.
2. Fill in the keyA and keyB on one sector depending on your needs.
3. Click the 3rd section.

## How To Use Sniffer

### Mark Money Bytes

![](https://why.yuyeye.cc/post-images/1574349436660.jpg)

### Mark Check Bytes

![](https://why.yuyeye.cc/post-images/1574349445281.jpg)

### Tips of Expression

```
Operator 
   • + - × ÷ Modulo ➡ + - * / # 
   • XOR ➡ @^ ➡ xor 
   • NOT ➡ @～ ➡ not 
   • AND ➡ @& ➡ and 
   • OR ➡ @| ➡ or 
   • Signed left shift n ➡ @<<n 
   • Signed right shift n ➡ @>>n 
   • More 

Examples 
   • b2=b1 ➡ b2=b1 
   • b4=b2+0x1F ➡ b4=b2+31(decimal) 
   • b15=b0 xor b1 ➡ b15=b0 xor b1 
   • b2=not b0 ➡ b2=not b0 

Note 
   • Convert constant to decimal 
   • Drag up/down to change the order of calculation
```

### After Expression added

![](https://why.yuyeye.cc/post-images/1574350100574.jpg)

## Conclusion <a href="#conclusion" id="conclusion"></a>

If there is no **Strikethrough** on check bytes, it means all expressions are correct.\
&#x20;Now you know another tip of MTools.


# Algorithm & Expression

## Available Operator

|          Name          | Operator                                                                           | Simple                                                                             |
| :--------------------: | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
|         + - × ÷        | + - \* /                                                                           |                                                                                    |
|         modulo         | #                                                                                  |                                                                                    |
|        brackets        | ( )                                                                                |                                                                                    |
|           and          | @&                                                                                 |                                                                                    |
|           or           | @\|                                                                                |                                                                                    |
|           xor          | @^                                                                                 |                                                                                    |
|           not          | @\~                                                                                |                                                                                    |
|  Continuous summation  | b1+b2+···+b14                                                                      | sum(1:14)                                                                          |
|     Continuous XOR     | b1 xor b2 xor ··· xor b10                                                          | sum(1:10)                                                                          |
| Continuous logical AND | b1 and b2 and ··· and b14                                                          | and(1:14)                                                                          |
|       CRC8/CRC16       | [Know more](https://why.yuyeye.cc/post/how-to-calculate-crc8-and-crc16-in-mtools/) | [Know more](https://why.yuyeye.cc/post/how-to-calculate-crc8-and-crc16-in-mtools/) |

## Example

| Rule              | Expression       |
| ----------------- | ---------------- |
| `b2 = b1`         | `b2=b1`          |
| `b4 = b2 + 0x1F`  | `b4 = b2 + 31`   |
| `b15 = b0 xor b1` | `b15 = b0 @^ b1` |
| `b2= not b0`      | b2 = @\~b0       |

* *Please convert the hexadecimal number to decimal*&#x20;
* *Drag expression up/down to change the sequence*
* The calculation starts from the top to the end.

## Extended Usage

Visit [mXparser](http://mathparser.org/?s=Bitwise) WebSite


# CRC-8 & CRC-16

CRC - Cyclic Redundancy Check is widely used in data transition. According to `wikipedia.org`, A CRC-enabled device calculates a short, fixed-length binary sequence, known as the check value or CRC, for each block of data to be sent or stored and appends it to the data, forming a codeword.

`When a codeword is received or read, the device either compares its check value with one freshly calculated from the data block, or equivalently, performs a CRC on the whole codeword and compares the resulting check value with an expected residue constant.`\
`If the CRC values do not match, then the block contains a data error.`

It's really hard to calculate CRC value by hand, so we add CRC8 & CRC16 algorithm in [MTools](https://play.google.com/store/apps/details?id=tk.toolkeys.mtools).\
And this can really save your time to get the CRC values by one expression.\
***Notice: This is the feature from the full version.***

## Byte values

There exist 16 bytes on each block of the Mifare 1k card.\
And you can use `b0` `b1` `b2` ... `b14` `b15` for calculation.

## CRC-8

The value of the CRC-8 result is only 1 byte.\
Supported CRC8 algorithm in MTools.

| Algorithm      | Expression             | Value                                     |
| -------------- | ---------------------- | ----------------------------------------- |
| CRC-8          | crc8(**0,1,5,8**)      | CRC8 of HEX String of `b0` `b1` `b5` `b8` |
| CRC-8/CDMA2000 | crc8cdma2000(**0:14**) | CRC8-/CDMA2000 of `b0` to `b14`           |
| CRC-8/DARC     | crc8darc(**0:14**)     | idem                                      |
| CRC-8/DVB-S2   | crc8dvs2(**0:14**)     | idem                                      |
| CRC-8/EBU      | crc8eu(**0:14**)       | idem                                      |
| CRC-8/I-CODE   | crc8icode(**0:14**)    | idem                                      |
| CRC-8/ITU      | crc8itu(**0:14**)      | idem                                      |
| CRC-8/MAXIM    | crc8maxim(**0:14**)    | idem                                      |
| CRC-8/ROHC     | crc8rohc(**0:14**)     | idem                                      |
| CRC-8/WCDMA    | crc8wcdma(**0:14**)    | idem                                      |

## CRC-16

The value of CRC16 contains 2 bytes.\
To get these two separately, `0` or `1` need to be added after the expression.\
Supported CRC16 algorithm in MTools.

| Algorithm          | Expression 0           | Expression 1           | Xor Value             |
| ------------------ | ---------------------- | ---------------------- | --------------------- |
| CRC-16/CCITT-FALSE | crc16ccittfalse(0:14)0 | crc16ccittfalse(0:14)1 | crc16ccittfalse(0:14) |
| CRC-16/ARC         | crc16arc(0:14)0        | crc16arc(0:14)1        | crc16arc(0:14)        |
| CRC-16/AUG-CCITT   | crc16augccitt(0:14)0   | crc16augccitt(0:14)1   | crc16augccitt(0:14)   |
| CRC-16/BUYPASS     | crc16buypass(0:14)0    | crc16buypass(0:14)1    | crc16buypass(0:14)    |
| CRC-16/CDMA2000    | crc16cdma2000(0:14)0   | crc16cdma2000(0:14)1   | crc16cdma2000(0:14)   |
| CRC-16/DDS-110     | crc16dds110(0:14)0     | crc16dds110(0:14)1     | crc16dds110(0:14)     |
| CRC-16/DECT-R      | crc16dectr(0:14)0      | crc16dectr(0:14)1      | crc16dectr(0:14)      |
| CRC-16/DECT-X      | crc16dectx(0:14)0      | crc16dectx(0:14)1      | crc16dectx(0:14)      |
| CRC-16/DNP         | crc16dnp(0:14)0        | crc16dnp(0:14)1        | crc16dnp(0:14)        |
| CRC-16/EN-13757    | crc16en13757(0:14)0    | crc16en13757(0:14)1    | crc16en13757(0:14)    |
| CRC-16/GENIBUS     | crc16genibus(0:14)0    | crc16genibus(0:14)1    | crc16genibus(0:14)    |
| CRC-16/MAXIM       | crc16maxim(0:14)0      | crc16maxim(0:14)1      | crc16maxim(0:14)      |
| CRC-16/MCRF4XX     | crc16mcrf4xx(0:14)0    | crc16mcrf4xx(0:14)1    | crc16mcrf4xx(0:14)    |
| CRC-16/RIELLO      | crc16riello(0:14)0     | crc16riello(0:14)1     | crc16riello(0:14)     |
| CRC-16/T10-DIF     | crc16t10dif(0:14)0     | crc16t10dif(0:14)1     | crc16t10dif(0:14)     |
| CRC-16/TELEDISK    | crc16teledisk(0:14)0   | crc16teledisk(0:14)1   | crc16teledisk(0:14)   |
| CRC-16/TMS37157    | crc16tms37157(0:14)0   | crc16tms37157(0:14)1   | crc16tms37157(0:14)   |
| CRC-16/USB         | crc16usb(0:14)0        | crc16usb(0:14)1        | crc16usb(0:14)        |
| CRC-A              | crc16a(0:14)0          | crc16a(0:14)1          | crc16a(0:14)          |
| CRC-16/KERMIT      | crc16kermit(0:14)0     | crc16kermit(0:14)1     | crc16kermit(0:14)     |
| CRC-16/MODBUS      | crc16modbus(0:14)0     | crc16modbus(0:14)1     | crc16modbus(0:14)     |
| CRC-16/X-25        | crc16x25(0:14)0        | crc16x25(0:14)1        | crc16x25(0:14)        |
| CRC-16/XMODEM      | crc16xmodem(0:14)0     | crc16xmodem(0:14)1     | crc16xmodem(0:14)     |

## CRC-8 / CRC16 in Sniffer

The expression of the last byte `b15` is `CRC-8/MAXIM`, and the results are calculated correctly in a second.&#x20;

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-MbBnNjrs1_0wKJN_feT%2F-MbBngCneYcjPehEpWlX%2F1559024659102-1.png?alt=media\&token=0a7e9a64-15bb-4268-9c81-c4dc8a10b88e)


# Mifare Classic Tool vs MTools

## Supported Card

* R - Read
* W - Write
* C - Clone

|                    | Mifare Classic Tool |    MTools   |
| :----------------: | :-----------------: | :---------: |
|  Mifare Classic 1K |        R / W        |    R / W    |
|  Mifare Classic 4K |        R / W        |    R / W    |
| 1st gen Magic Card |        R / W        |  R / W / C  |
| 2nd gen Magic Card |        R / W        |  R / W / C  |
|     UFUID Card     |        R / W        |  R / W / C  |
|  Mifare Ultralight |                     |  R / W / C  |
|        NTAG        |                     |  R / W / C  |
|         羊城通        |                     |      R      |
|     More Cards     |                     | Coming Soon |

## **External Device**

|                 |                                    Mifare Classic Tool                                   |                         MTools                        |
| :-------------: | :--------------------------------------------------------------------------------------: | :---------------------------------------------------: |
|     ACR122U     | <p>Compatible </p><p><code>• Rooted need</code></p><p><code>• Plugin require</code> </p> | <p>USB Connection<br><code>Built-in driver</code></p> |
|      PN532      |                                        Not support                                       |                     USB Connection                    |
| PN532 Bluetooth |                                        Not Support                                       |                  Bluetooth Connection                 |

## **Card Clone**

The real cloning of the Mifare classic card must have a changeable UID.

| Magic Card Type | Mifare Classic Tool |                           MTools                          |
| :-------------: | :-----------------: | :-------------------------------------------------------: |
|       UID       |     Not Support     | <p>Support</p><p><code>Require External Device</code></p> |
|       CUID      |       Support       |                          Support                          |
|      UFUID      |     Not Support     | <p>Support</p><p><code>Require External Device</code></p> |

## Operation Features

| Magic Card Type |  Mifare Classic Tool |                        MTools                       |
| :-------------: | :------------------: | :-------------------------------------------------: |
|     Reading     |      All sectors     |        <p>All Sectors</p><p>Single Sector</p>       |
|     Writing     |    Dump to sectors   |    <p>Dump to sectors</p><p>Sector to sector</p>    |
|     Cloning     |    Only CUID card    |               All UID Changeable Card               |
|    Analyzing    |    Between 2 dumps   |                  Between 24 blocks                  |
|   Highlighting  | 1 Standard Structure | <p>5 built-in structure</p><p>User can add more</p> |
|   Calculating   |      Not Support     |                       mXparser                      |
|     Charging    |      Not Support     |                      One-click                      |

## Data Comparision

|     Mifare Classic Tool     |      MTools     |
| :-------------------------: | :-------------: |
| Between 2 blocks in 2 dumps | Among 24 blocks |

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mc7GH9cMSA42hXstA4C%2F-Mc7LMZ7BSLLSvwhkEcl%2FMCT%20vs%20MTools%20Data%20Comparision.jpg?alt=media\&token=04523a8c-1bf4-4795-b11e-54e8b301483d)

## Dump Type

|      | Mifare Classic Tool |  MTools |
| :--: | :-----------------: | :-----: |
| text |       Support       | Support |
|  mfd |       Support       | Support |
|  bin |       Support       | Support |

## **Import/Export Type**

|            |                       Mifare Classic Tool                      |                                                                               MTools                                                                              |
| :--------: | :------------------------------------------------------------: | :---------------------------------------------------------------------------------------------------------------------------------------------------------------: |
| **Import** | <p><code>• Dump File</code></p><p><code>• Keys File</code></p> |                                   <p><code>• Dump File</code></p><p><code>• Keys File</code></p><p><code>• Card Rule</code></p>                                   |
| **Export** | <p><code>• Dump File</code></p><p><code>• Keys File</code></p> | <p><code>• Card Rule</code></p><p><code>• Card List</code></p><p><code>• Dump File</code></p><p><code>• Keys List</code></p><p><code>• Charging Record</code></p> |

## Bcc Calculator

| Mifare Classic Tool |     MTools     |
| :-----------------: | :------------: |
|   Inner Calculator  | Auto calculate |

## Access Condition De-/Encoder

| Mifare Classic Tool |    MTools   |
| :-----------------: | :---------: |
|   Inner Calculator  | Not Support |


# Terminal for ACR122U & PN532

MTools App brings Terminal functions for ACR122U and PN532 via USB. Also bluetooth connection to PN532 with SPP module. You can run raw commands easily and debug PN532 or ACR122U with Android devices.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FN1oWOJT8ubdQzsUlk1Fk%2Fimage.png?alt=media&amp;token=4e4d5c9d-bd0f-46aa-a2c6-35bffde37f0d" alt="" width="365"><figcaption><p>Entry of Terminal for ACR122U &#x26; PN532 in MTools</p></figcaption></figure>

## Terminal for ACR122U

The connection of ACR122U is USB. If you’re connecting it with your Android phone, an OTG adapter is necessary.

### Get Presented Tag info&#x20;

Before running on the command, the tag needs to be put on the reader. \
To get the UID of the connected PICC.&#x20;

<pre><code>> FF CA 00 00 <a data-footnote-ref href="#user-content-fn-1">04</a>
&#x3C; <a data-footnote-ref href="#user-content-fn-2">11 22 33 44</a> <a data-footnote-ref href="#user-content-fn-3">90 00</a>
</code></pre>

To get the ATS of the connected ISO 14443 A PICC.

<pre><code>> FF CA 01 00 00
&#x3C; <a data-footnote-ref href="#user-content-fn-4">6A 81</a> 00
</code></pre>

### Load Mifare Key&#x20;

ACR122U allows loading 2 Mifare Keys(6 Bytes) in 2 locations.&#x20;

<pre><code>> FF 82 00 <a data-footnote-ref href="#user-content-fn-5">00</a> <a data-footnote-ref href="#user-content-fn-6">06</a> <a data-footnote-ref href="#user-content-fn-7">FF FF FF FF FF FF</a>  //Load key FFFFFFFFFFFF to 00 location
&#x3C; 90 00
</code></pre>

### Verify Mifare Block

<pre><code>> FF 86 00 00 05 01 00 <a data-footnote-ref href="#user-content-fn-8">04</a> <a data-footnote-ref href="#user-content-fn-9">60</a> <a data-footnote-ref href="#user-content-fn-10">00</a>
&#x3C; 90 00
</code></pre>

*<mark style="color:blue;">Note: The MIFARE Classic 1K Card, has a total of 16 sectors and each sector consists of 4 consecutive blocks.</mark>* \
*<mark style="color:blue;">E.g. Sector 00h consists of Blocks {00h, 01h, 02h and 03h};</mark>* \
*<mark style="color:blue;">Sector 01h consists of Blocks {04h, 05h, 06h and 07h};</mark>* \
*<mark style="color:blue;">the last sector 0F consists of Blocks {3Ch, 3Dh, 3Eh and 3Fh}.</mark>* \
*<mark style="color:blue;">Once the authentication is done successfully, there is no need to authenticate again if the blocks to be accessed belong to the same sector.</mark>* \
*<mark style="color:blue;">Please refer to the MIFARE Classic 1K/4K specification for more details.</mark>*

Note: **MIFARE Ultralight** does not need to do any authentication. The memory is free to access.

### Read Mifare Block&#x20;

Once the sector is successfully authenticated, the commands to read or write the block can be executed with the problem.

1. Read Mifare Classic Block (16 Bytes)

   <pre><code>> FF B0 00 <a data-footnote-ref href="#user-content-fn-8">04</a> <a data-footnote-ref href="#user-content-fn-11">10</a>
   &#x3C; 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 90 00
   </code></pre>
2. Read Mifare Ultralight Page (4 Bytes)

   <pre><code>> FF B0 00 <a data-footnote-ref href="#user-content-fn-12">04</a> <a data-footnote-ref href="#user-content-fn-13">04</a>
   &#x3C; 00 01 02 03 90 00
   </code></pre>
3. Read Mifare Ultralight 4 Pages (16 Bytes)

   <pre><code>> FF B0 00 <a data-footnote-ref href="#user-content-fn-14">04</a> <a data-footnote-ref href="#user-content-fn-15">10</a>
   &#x3C; 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 90 00
   </code></pre>

### Write Mifare Block&#x20;

1. Write Mifare Classic Block

   <pre><code>> FF D6 00 <a data-footnote-ref href="#user-content-fn-8">04</a> <a data-footnote-ref href="#user-content-fn-16">10</a> <a data-footnote-ref href="#user-content-fn-17">00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F</a>
   &#x3C; 90 00
   </code></pre>
2. Write Mifare Ultralight Page

   <pre><code>> FF D6 00 <a data-footnote-ref href="#user-content-fn-18">04</a> <a data-footnote-ref href="#user-content-fn-19">04</a> <a data-footnote-ref href="#user-content-fn-20">00 01 02 03</a>
   &#x3C; 90 00
   </code></pre>

### Set Buzzer and LED

The bi-color LED and Buzzer all can be configured with commands. This command makes ACR122U much more cool and flexible to use.

<table><thead><tr><th align="center">Class</th><th width="122" align="center">INS</th><th align="center">P1</th><th width="160" align="center">P2</th><th width="79" align="center">Lc</th><th align="center">Data In(4 B)</th></tr></thead><tbody><tr><td align="center">FF</td><td align="center">00</td><td align="center">01</td><td align="center"><p>LED </p><p>State Control (Bit 7 --- Bit 0)</p></td><td align="center">04</td><td align="center">Blinking Duration Control</td></tr></tbody></table>

#### **LED State Control**

Bi-Color LED and Buzzer Control Format (1 byte)

<table><thead><tr><th width="104">CMD</th><th>Item</th><th>Description</th></tr></thead><tbody><tr><td>Bit 0</td><td>Final State : Red LED</td><td>1 = On ; 0 = Off</td></tr><tr><td>Bit 1</td><td>Final State : Green LED</td><td>1 = On ; 0 = Off</td></tr><tr><td>Bit 2</td><td>State Mask : Red LED</td><td>1 = Update the State<br>0 = No change</td></tr><tr><td>Bit 3</td><td>State Mask : Green LED</td><td>1 = Update the State<br>0 = No change</td></tr><tr><td>Bit 4</td><td>Initial Blinking State : Red LED</td><td>1 = On ; 0 = Off</td></tr><tr><td>Bit 5</td><td>Initial Blinking State : Green LED</td><td>1 = On ; 0 = Off</td></tr><tr><td>Bit 6</td><td>Blinking Mask : Red LED</td><td>1 = Blink<br>0 = Not Blink</td></tr><tr><td>Bit 7</td><td>Blinking Mask : Green LED</td><td>1 = Blink<br>0 = Not Blink</td></tr></tbody></table>

#### **Blinking Duration Control**

Bi-Color LED Blinking Duration Control Format (4 Bytes)

| Byte 0                                                            | Byte 1                                                           | Byte 2                         | Byte 3         |
| ----------------------------------------------------------------- | ---------------------------------------------------------------- | ------------------------------ | -------------- |
| <p>T1 Duration<br>Initial Blinking State<br>( Unit = 100 ms )</p> | <p>T2 Duration<br>Toggle Blinking State<br>( Unit = 100 ms )</p> | <p>Number of<br>repetition</p> | Link to Buzzer |

#### **Byte 3 Options**

Link to the Buzzer and control the buzzer state during the LED Blinking.&#x20;

```
00h: The buzzer will not turn on 
01h: The buzzer will turn on during the T1 Duration 
02h: The buzzer will turn on during the T2 Duration 
03h: The buzzer will turn on during the T1 and T2 Duration.
```

#### Response

<pre><code> &#x3C; 90 <a data-footnote-ref href="#user-content-fn-21">00</a>
 &#x3C; 63 00
</code></pre>

#### **Buzzer and LED Notes**

```
1. LED Blinking will take effect only if the corresponding LED Blinking Mask is enabled and the 
number of repetitions is greater than zero. 
2. The term Initial Blinking State means that the LED of the chosen color will either be turned 
ON or OFF during the first blink in the duty cycle. For example, if the Initial Blinking State is 
turned ON for the Green LED and OFF for the Red LED, then the blinking will start with Green, 
followed by Red, and so on. 
3. The change in LED State will take effect only if the corresponding LED State Mask is enabled.
4. If controlled at the same time, the LED State operation will be performed after the LED 
The blinking operation has been completed.
5. Under Blinking Duration Control, Both T1 and T2 duration parameters are used for controlling 
the duty cycle of LED blinking and Buzzer Turn-On duration. For example, if T1=1 and T2=1, 
the duty cycle = 50%. #Duty Cycle = T1/(T1 + T2).
6. To control the buzzer only, set the P2 “LED State Control” to 00.
7. To make the buzzer operate, the “number of repetitions” must be greater than zero.
8. To control the LED only, set the parameter “Link to Buzzer” to 00.

```

### Direct Transmit to PN532

This is the payload to be sent to the tag or reader with a specific command ahead.

<pre><code> > FF 00 00 00 <a data-footnote-ref href="#user-content-fn-22">DataLength</a> <a data-footnote-ref href="#user-content-fn-23">[Playload]</a>
 &#x3C; [ResponseData] 90 00
</code></pre>

Check the checkbox of **Direct Transmit** and send the command of PN532. The command of PN532 is listed in [the next section](#terminal-for-pn532).

## Terminal for PN532

Coming soon

[^1]: Full Length

[^2]: UID

[^3]: The operation completed successfully.

[^4]: Function not supported.

[^5]: 00h \~ 01h = Key Location.&#x20;

    The keys will disappear once the reader is power down.

[^6]: Key Length

[^7]: Mifare Key

[^8]: Block 04

[^9]: 60h = Key is used as a TYPE A key for authentication. \
    61h = Key is used as a TYPE B key for authentication.

[^10]: 00h \~ 01h = Key Location.

[^11]: Number of Bytes to Read

[^12]: Page 04

[^13]: Page byte count

[^14]: Start from Page 04

[^15]: Page date length, 10h is 16 bytes, which means page 4, 5, 6 and 7 will be read

[^16]: Number of Bytes to write

[^17]: Block data to write

[^18]: Page Index

[^19]: Data length

[^20]: Page data to write

[^21]: Current LED Status\
    000000<mark style="color:green;">**0**</mark><mark style="color:red;">**0**</mark>

    &#x20;               <mark style="color:red;">bit 0 - current Red LED</mark>

    &#x20;             <mark style="color:green;">bit 1 - current Green LED</mark>

[^22]: 1 byte. Number of bytes to send Maximum 255 bytes

[^23]: Data Bytes


# How To Unlock

MTools Lite supports accessing full features in 2 methods. In-App purchase and the activation code order.

## In-App Purchase

MTools Lite app is available on Play Store and App Store. The platform will charge from the client directly. The price of In-App Purchase may be different under different currencies.

There is no limit for devices under same account.

If you have purchased before, just click restore transaction to access full features.

## Activation Code

MTools Lite app also supports the activation code for the MTools app. It can be unlocked and unbonded on 1 Android device and 1 iOS device.&#x20;

### How to bind device

1. Log in with the account on <https://shop.mtoolstec.com>.
2. View all orders.
3. Bind the device.

![](https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LD97pa04tZLvlPyG5f6%2F-Mjy7MDvKMs1QfOXXZWA%2F-Mjy7eHT3QAyhrTHZgeM%2FMTools-Lite-link-device.jpg?alt=media\&token=68b03ead-575b-4be9-a2cf-2bb4ca84d196)

### Why can not bind

* Already unlocked.
* There is no order contains MTools Activation Code.
* Already bind on another device. It needs to unbind from the original device firstly.


# How To Use ChameleonUltra

The instruction of using ChameleonUltra, ChameleonLite, and Dev Kit with MTools Lite App. MTools Lite is the first RFID App supports on both Android and iOS platforms to use ChameleonUltra devices.

## What's Chameleon Ultra

[ChameleonUltra](https://shop.mtoolstec.com/product/chameleon-ultra) is a newly launched RFID Simulator for 8 HF tags and 8 LF tags. It also supports read functions on Ultra and Dev Kit.&#x20;

## Connections of ChameleonUltra

* Bluetooth - Support BLE on Both Android and iOS.
* USB - Support dual-side plugging USB cable.

## How to connect with Bluetooth in MTools Lite

1. Click the **A** or **B** button to power on.
2. Click the **Bluetooth List** icon to search devices.
3. Click the **Connect** button on the right.

### **Notice for Bluetooth Connection**

1. Grant the Bluetooth permission for the app on iOS.
2. Allow Location permission to scan Bluetooth devices on Android.

## Functions for ChameleonUltra in MTools Lite

### Command Line Tool

1. Quick action buttons
2. Battery indicator
3. Mifare Magic Checker
4. `hf 14a raw` Supports

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FTaXZGDj3z2ehyvLBFqVj%2FChameleon%20Ultra%20Terminal.jpg?alt=media&amp;token=6b73cbbc-7b40-497d-9a37-4808c2e31fe1" alt=""><figcaption></figcaption></figure>

### Slot Manager

1. Fetch all slot statuses.
2. Enable or disable Slots.
3. Change LF and HF Slot name.
4. Set LF and HF Tag Type.
5. Delete and reset all slots.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FA3LNa29LyKvbN0J7X9z1%2FChameleon%20Ultra%20Slot%20Manage.jpg?alt=media&amp;token=e8215773-5e78-40a8-9a98-38be3715701f" alt=""><figcaption></figcaption></figure>

### HF LF Reader

1. Fast-read LF and HF Tag.
2. Simulate Mifare Classic Tag with UID, SAK, ATQA, and empty dump.
3. Simulate the EM410X LF tag or manually set the ID then simulate.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FuZgpT4dk241yWUOs0xhk%2FChameleon%20Ultra%20Reader.jpg?alt=media&amp;token=80c37922-a474-4863-9a1b-f5f4ab745805" alt=""><figcaption></figcaption></figure>

### Dump Manage

1. Mifare Keys Manage.
2. Get a dump of Mifare Classic Mini, 1K, 2K, and 4K with known keys.
3. Modify block data and save it to a new dump file.
4. Do a quick simulation of the current active slot.
5. Upload the full dump to the current active slot.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2F0KDspZXn2TxTQX7eoqoh%2FChameleon%20Ultra%20Dump%20Manage.jpg?alt=media&amp;token=65b385f1-0e68-48d0-806a-9ba3828f559f" alt=""><figcaption></figcaption></figure>

### Settings of Interaction

1. Set the Animation of LEDs.
2. Set press and long press buttons of A and B.
3. Set the **Mifare Classic Emulation** of the current slot.
4. Get the Mfkey32 Detection log
5. Enter DFU Mode.
6. Reset Chameleon Device.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2Fn7Z6BiXJAcW6P8ESPJZb%2FChameleon%20Ultra%20Mifare%20Configuration.jpg?alt=media&amp;token=5d419af4-23f8-4993-a8c9-f7c4ae6b5593" alt=""><figcaption></figcaption></figure>


# How to use ChameleonUltra to write Mifare Dump

The Python-based CLI only supports writing single blocks for the moment. With MTools BLE App you can view and write the whole Mifare Dump to a magic card.

### Supported Mifare Type

* Mifare Classic mini
* Mifare Classic 1k
* Mifare Classic 2K
* Mifare Classic 4K

### Supported Magic Card Type

* Gen1A
* Gen2(Default)
* Gen3
* Gen4(Ultimate Magic Card): Comming soon

### Steps

1. Connect Chameleon Ultra with MTools BLE
2. Import Mifare Dump with mct, bin or json file.
3. Write dump to magic cards<br>


# How to use TAG Scanner

Tag Scanner is used to scan the UID of 13.56MHz Tags and the tag list can be shared. The function is based on PN532 BLE reader and the Chameleon Ultra device in reader mode.

### Supported Readers

1. [All-in-one PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532)  - The PN532 Reader with Bluetooth Extension Board.
2. [PCR532](https://shop.mtoolstec.com/product/pcr532) - The smallest PN532 Reader with Bluetooth.
3. [DIY PN532 Board with Bluetooth Module.](https://shop.mtoolstec.com/how-to-make-pn532-work-on-bluetooth.html)
4. [Chameleon Ultra](https://shop.mtoolstec.com/product/chameleon-ultra)
5. [Chameleon Ultra Dev Kit](https://shop.mtoolstec.com/product/chamleonultra-dev-kit)

### Steps to Scan Tag

1. Connect reader in MTools Lite App.
2. Enter Tool > TAG Scanner.
3. Wait for the power icon turn to <mark style="color:green;">**green**</mark>.
4. Click the PAUSE button to the **PLAY** button.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2F7GrGJHRTtnOADv4Rz5FA%2FMTools%20Lite%20TAG%20Scanner.jpg?alt=media&amp;token=6a8b262e-1526-4355-ba0b-00226ac8adc0" alt="" width="375"><figcaption><p>TAG Scanner - PN532 - MTools Lite</p></figcaption></figure>

### Share TAG Records

1. Click the LABEL button to show TAG Records
2. Click the TAG Records to share the number ID, UID, and ID as text content.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FIxrT7g4X7GRIUTX3gwrE%2FMTools%20Lite%20TAG%20Scanner%20Label.jpg?alt=media&amp;token=5acd55fb-514f-4271-a8c1-acbdcee1e3b1" alt="" width="375"><figcaption><p>TAG Scanner Labels - PN532 - MTools Lite</p></figcaption></figure>


# How to use UID Changer

PN532 and ChameleonUltra can change the UID of Gen1A, Gen2, Gen3 and Gen4 Magic Card. And MTools Lite brings the UID Changer for all magic cards.

### Supported Readers

1. [PN532 BLE](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532) or [PCR532](https://shop.mtoolstec.com/product/pcr532)
2. [ChameleonUltra](https://shop.mtoolstec.com/product/chameleon-ultra)

### Supported Magic Cards

#### Gen1A

* [Mifare S50 with 4 Byte UID](https://shop.mtoolstec.com/product/uid-changeable-nfc-mifare-s50-keychain)

#### Gen2

* [Mifare S50 with 4 Byte UID](https://shop.mtoolstec.com/product/uid-changeable-1k-s50-chinese-magic-card?attribute_pa_card-type=cuid\&attribute_pa_amount=1-pc)

#### Gen3

* [Mifare S70 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-s70-4k-magic-key-fob)
* [Mifare S70 with 4 Byte UID](https://shop.mtoolstec.com/product/4-byte-uid-s70-4k-magic-key-fob)
* [Mifare S50 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-s50-1k-magic-key-fob)
* [Mifare S20 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-changeable-mifare-mini-s20-card)
* [Mifare S20 with 4 Byte UID](https://shop.mtoolstec.com/product/4-byte-uid-changeable-mifare-mini-card)

#### Gen4

* [Ultimate Magic Card](https://shop.mtoolstec.com/product/ultimate-magic-card-gen4)

### Card Type Selection

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FzchIwUhoyUlmswYVZpNA%2FUID%20Changer%20-%20Card%20Type.png?alt=media&amp;token=161c6907-8d1c-4fe3-85a4-e7886895ecd0" alt=""><figcaption></figcaption></figure>

### Configuration

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FgYQgih0tjm9ZQS5jNCAy%2FUID%20Changer%20-%20Configuration.png?alt=media&amp;token=16e11468-ed36-45d7-8cca-7a48368c28e9" alt=""><figcaption></figcaption></figure>

### How to change

1. Input the valid information.
2. Click **Execute** to change the UID.


# Change UID of Gen3 Magic Card(Deprecated)

MTools Lite supports changing the UID of the Gen3 Magic Card with the PN532 BLE reader and the built-in terminal tools with one click.

### ## Notice

The UID Changing functions for Gen3 have been upgraded to [UID Changer](/how-to-use-uid-changer).&#x20;

### Gen3 Magic Card Introduction

Proxmark3 firstly supports the 3rd generation of magic cards. The Gen3 Magic Cards include the cards below:

* [Mifare S70 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-s70-4k-magic-key-fob)
* [Mifare S70 with 4 Byte UID](https://shop.mtoolstec.com/product/4-byte-uid-s70-4k-magic-key-fob)
* [Mifare S50 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-s50-1k-magic-key-fob)
* [Mifare S50 with 4 Byte UID](https://shop.mtoolstec.com/product/uid-changeable-nfc-mifare-s50-keychain)
* [Mifare S20 with 7 Byte UID](https://shop.mtoolstec.com/product/7-byte-uid-changeable-mifare-mini-s20-card)
* [Mifare S20 with 4 Byte UID](https://shop.mtoolstec.com/product/4-byte-uid-changeable-mifare-mini-card)

### Supported Readers

1. [All-in-one PN532](https://shop.mtoolstec.com/product/mtools-all-in-one-pn532)  - The PN532 Reader with Bluetooth Extension Board.
2. [PCR532](https://shop.mtoolstec.com/product/pcr532) - The smallest PN532 Reader with Bluetooth.
3. [DIY PN532 Board with Bluetooth Module.](https://shop.mtoolstec.com/how-to-make-pn532-work-on-bluetooth.html)

### How does it work with Proxmark3?

Proxmark3 support changed with the UID of the Gen3A magic card with commands quickly.

```
hf mf gen3uid --uid 11223344556677
```

This command can be run with the Command line tool or GUI Program on [Proxmark3 X](https://shop.mtoolstec.com/product/proxmark3-x) or [iCopy-XS](https://shop.mtoolstec.com/product/icopy-xs).&#x20;

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FoRl4milpQytejhSyRkSq%2Fpm3-change-gen3uid.jpg?alt=media&amp;token=172df75d-889e-4f20-b35b-5734790218c7" alt=""><figcaption></figcaption></figure>

### How does it work with ACR122U?

The PCSC Program is a Windows Program for changing the UID of the Gen3 Magic card. Learn more about this program at the link below.

{% embed url="<https://shop.mtoolstec.com/pcsc-mifare-program>" %}

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2F20Shy3dNQv0P4AelkUSe%2FPCSC-Mifare-Main.jpg?alt=media&amp;token=ad154855-b359-4e19-b485-2c669eb89f1e" alt="" width="563"><figcaption></figcaption></figure>

### How does it work with All-in-one PN532?

MTools Lite App supports changing the UID of the Gen1 and Gen3 Magic Card in the Terminal Tools. This can be the first App to change the UID of the gen3 Magic Card on both Android and iOS devices.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FrJU9xXioWXwvpwByGYK1%2FMTools%20Lite%20Terminal.jpg?alt=media&amp;token=a33ea51b-a6ce-4e8a-9d56-72592d1b148d" alt="" width="375"><figcaption><p>MTools Lite Terminal</p></figcaption></figure>


# Upgrade the firmware of ChameleonUltra and ChameleonLite

MTools BLE provides a super easy DFU Tool for the firmware of ChameleonUltra and ChameleonLite from official repository or custom repository.

### DFU Tool for ChameleonUltra & ChameleonLite

<div align="left" data-full-width="false"><figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FjSpIHjQVrg3qB4y9WEwr%2FChameleonUltra%20DFU.png?alt=media&amp;token=cb5a9ab4-2ca8-4f78-8df2-bdc355c116be" alt="" width="375"><figcaption></figcaption></figure></div>

### Steps

1. Connect the Chameleon device with the Bluetooth icon
2. Enter ChameleonUltra tool > GUI > Settings > Firmware Upgrade
3. Click ChameleonUltra or ChameleonLite to fetch the latest firmware
4. Click to choose **CU-XXXX** or **CL-XXXX** device
5. Click start to flash the firmware

### Video Tutorial

Upgrade firmware with MTools BLE App on MacOS.

{% embed url="<https://www.youtube.com/watch?v=fE0uT1NAFzA>" %}


# Upgrade the firmware of Pixl.js

MTools BLE provides a super easy DFU Tool for the firmware of Pixl.js devices with Bluetooth.

### DFU Tool for ChameleonUltra & ChameleonLite

<div align="left"><figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FOwcn923p0TDzozRW4B42%2FPixl.js%20DFU.png?alt=media&amp;token=c04f6c5c-9fb0-4e5a-b33d-423a76662d0f" alt="" width="375"><figcaption></figcaption></figure></div>

### Steps

1. Enter **Pixl.js** Tool in MTools BLE
2. Connect Pixl.js by clicking the title
3. Click to choose **Pixl.js OLED** or **Pixl.js LCD** to download the latest firmware
4. Click to choose **pixl dfu** device
5. Click start to flash the firmware


# nRF52840 Meshtastic MeshCore Firmware BLE OTA

MTools BLE provides the unified operation method for Android and iOS clients, and provides convenient features such as fast firmware download and one-click upgrade for nRF52 device DFU.

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FsTAfxC6kTAgtS2cysdaP%2Fgat562%20devices%20dfu.jpeg?alt=media&amp;token=eec0fa9b-2819-4f43-aac2-e931147ba1b2" alt="GAT562 Pro, GAT562 30s DFU with MTools BLE"><figcaption></figcaption></figure>

### Downloads MTools BLE

* [Play Store](https://play.google.com/store/apps/details?id=com.mtoolstec.mtoolsLite)
* [App Store](https://apps.apple.com/us/app/mtools-lite/id1531345398)
* [Learn More](https://shop.mtoolstec.com/mifare-classic-tool-for-ios)

### Steps

1. Go to `Tool` > `Device` in App, and select Meshtastic or MeshCore Powered Firmware.
2. Select the device from list and the firmware will be downloaded.
3. Connect to your nRF52 device.
4. Start to upload the firmware.

### Settings

#### Meshtastic Firmware Repository

For Officially Supported Devices: [github.com/meshtastic/firmware](https://github.com/meshtastic/firmware)

For Community Supported Devices: [github.com/mtoolstec/mt-firmware](https://github.com/mtoolstec/mt-firmware)&#x20;

#### MeshCore Firmware Repository

Original MeshCore: [github.com/meshcore-dev/MeshCore](https://github.com/meshcore-dev/MeshCore)&#x20;

WhisperOS: [https://ssaprus.works](https://ssaprus.works/)

TapTap FW: [http://taptap.mtoolstec.com](http://taptap.mtoolstec.com/)

#### Number of packet

For original bootloader: Recommand 5 to 8. If larger it will result failures during OTA.

For [Advanced Bootloader](https://shop.mtoolstec.com/enhanced-nrf52-bootloader-with-oled.html): Recommand 30, which take around 90 seconds for firmware OTA.

#### Single Firmware Download

Enable download single firmware will download only the firmware for you device instead of the whole nRF52 package.&#x20;

### Notice

1. OTA firmware updates come with an increased risk of failure. If the update process fails, your device will be left in a non-working state and require the Drag and Drop actions for recover the firmware.
2. The legacy DFU service can only provide around 1KB/s speed for data transfer. The speed and remaining time will be show when uploading.
3. nRF52 devices from RAK are able to accept OTA firmware updates from a mobile device over bluetooth. Older T-Echo bootloaders do not have OTA support.

### Trademark

Meshtastic® is a registered trademark of Meshtastic LLC.


# How to Start

### Hardware Requirement

* PN532 + USB Serial Chip such as CH340
* All-in-one PN532 board from MTools Tec

### Software Requirement

* Python 3.5+
* Download [PN532 Python](https://github.com/whywilson/pn532-python)

### Steps to emulate NDEF with PN532

1. Enter *script* and install requirement.

```mipsasm
cd script
pip install -r requirements.txt
```

2. Connect PN532 to the device and run the cli

```vim
cd script
python pn532_cli_main.py
```

3. Connect PN532 in the cli

```arduino
hw connect
```

{% embed url="<https://youtu.be/vJWdFYFY1zI>" %}
PN532 Python CLI
{% endembed %}


# NTAG Emulate

Use PN532 to Emulate NDEF Message

PN532 CLI supports TgInitAsTarget as the NTAG with NDEF Message such as website link, email, phone number and etc.

### How to connect PN532

```
hw connect
```

### How to emulate website link

```
ntag emulate --uri https://pn532kiler.com
```

### How to emulate email

```
ntag emulate --uri mailto:info@pn532killer.com
```

### Video

{% embed url="<https://youtu.be/RY3yHRz2pBE>" %}
PN532 Emulate NDEF
{% endembed %}


# GAT562 30S Mesh Module

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FNQmJSShOGZYvWaY7IVEm%2Fimage.png?alt=media&amp;token=5ee7eac2-6c03-4dd8-9eda-d832b942c266" alt=""><figcaption></figcaption></figure>

### Product Overview

The GAT562 30S Mesh Module is a communication module designed based on the nRF52840 and SX1262. It supports Bluetooth 5.0 and LoRa Mesh, featuring powerful remote networking communication capabilities, scalability, and a low-power design.

The GAT562 30S Mesh Module is fully compatible with Meshtastic or MeshCore, allowing users to update and experience the latest features within these networks. Meshtastic (or MeshCore) is a community-driven open-source project that enables the reasonable use of LoRa radios for long-range off-grid communication in areas without existing or reliable communication infrastructure.

#### Key Advantages

* Decentralized: Does not rely on a central server or base station. Every device can act as a relay node to forward information. There is no single point of failure in the network; even if some nodes fail, the overall communication is not affected, resulting in higher network reliability and stability.
* Long-Range Communication: Utilizes wireless communication technologies like LoRa to achieve communication over several kilometers or even further. It has significant advantages in remote areas without network coverage or vast outdoor spaces.
* Off-Grid Communication: Does not rely on the internet or mobile networks. It can communicate normally in places without mobile signals or Wi-Fi, meeting communication needs in special scenarios.
* Low Power Consumption: Adopts low-power technologies such as Bluetooth Low Energy (BLE), consuming less battery power on hardware devices. This allows for long-term use and is suitable for portable devices, reducing the frequency and difficulty of charging.
* Open Source & Customizable: The software is open source, allowing developers to freely modify and extend the code according to their needs. Secondary development can add new features or optimize existing ones to meet personalized user requirements.
* Cross-Platform Compatibility: Supports a variety of hardware devices and operating systems. Users can choose devices that suit them (such as mobile phones, tablets, etc.) to access the network, facilitating communication between users on different devices.
* Low Cost: Uses hardware modules that are generally low-cost open-source hardware. Compared to professional communication equipment, the cost is significantly reduced, making it easy to promote and use.
* User-Friendly Interface: Designed with an intuitive and concise user interface, allowing even non-technical personnel to get started quickly. It facilitates device configuration, message sending, location sharing, and other operations.

#### Application Scenarios

1. Industrial Manufacturing: Production manufacturing, equipment O\&M, data visualization, logistics/freight, inspection and diagnosis, etc.
2. Smart City: Infrastructure, smart buildings, environmental construction, health and elderly care, transportation.
3. Smart Park: Smart office, smart parking, smart hotels, security and fire protection, energy efficiency management.
4. Smart Retail: Smart water meters, smart electricity meters, smart gas meters, new energy.
5. Smart Agriculture: Smart irrigation, smart agricultural tools, smart fertilization, soil monitoring, water quality monitoring.
6. Wireless Alarm Systems and Security Systems.

***

### Main Features

* Frequency Support:
  * China: 470M-510M
  * Europe: 865M-872M
  * Americas, Asia, Australia: 902M-928M
* Security: Encrypted point-to-point and mesh network communication.
* Ease of Use: UART interface, supports Bluetooth connection to mobile Apps.
* High Power: Maximum output power 1W (30dBm). Default output is 29.5dBm (Output power adjustable from 5\~30dBm).
* High Sensitivity: Receiver sensitivity up to -136dBm.
* Strong Anti-Interference: Forward Error Correction (FEC) technology. Transmission distance of 5km in urban areas and over 25km in open areas.
* Modulation: Supports FSK / GFSK / OOK modulation, bidirectional half-duplex communication.
* Buffering: Multi-channel, dual data buffers (256 bytes each).

***

### System Block Diagram

The following figure shows the system block diagram of the GAT562 30S Mesh Module:

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2F3FC4py62HVwNXHOhEgNL%2Fgat562%2030s%20system.jpeg?alt=media&amp;token=eca74ffd-49e3-4279-ad11-88bccf16c210" alt=""><figcaption></figcaption></figure>

***

### Hardware Description

#### Pin Package Definition

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FqeETROkIXhmSa3YHpuVj%2Fgat562%2030s%20pin%20out.jpeg?alt=media&amp;token=af3a1009-9384-4cfc-91c4-5104e3366a0b" alt=""><figcaption></figcaption></figure>

#### Pin Definitions

<table data-header-hidden><thead><tr><th width="75.76171875"></th><th width="124.3671875"></th><th width="81.87890625"></th><th></th></tr></thead><tbody><tr><td><strong>NO</strong></td><td><strong>Name</strong></td><td><strong>Type</strong></td><td><strong>Description</strong></td></tr><tr><td>1</td><td>VBUS</td><td>Input</td><td>DC 5V Power Supply Voltage</td></tr><tr><td>2</td><td>USB_D-</td><td>I/O</td><td>USB Data Interface</td></tr><tr><td>3</td><td>USB_D+</td><td>I/O</td><td>USB Data Interface</td></tr><tr><td>4</td><td>GND</td><td>－</td><td>Ground</td></tr><tr><td>5</td><td>VBAT_NRF</td><td>I/O</td><td>Battery Power Supply Voltage</td></tr><tr><td>6</td><td>I2C_SDA</td><td>I/O</td><td>I2C (SDA) P0.13</td></tr><tr><td>7</td><td>I2C_SCL</td><td>I/O</td><td>I2C (SCL) P0.14</td></tr><tr><td>8</td><td>GND</td><td>－</td><td>Ground</td></tr><tr><td>9</td><td>UART2_RX</td><td>Input</td><td>UART2 Interface P0.15</td></tr><tr><td>10</td><td>UART2_TX</td><td>Output</td><td>UART2 Interface P0.16</td></tr><tr><td>11</td><td>UART2_DE</td><td>I/O</td><td>UART DE Interface P0.17</td></tr><tr><td>12</td><td>NRF_RST</td><td>Input</td><td>Reset Pin</td></tr><tr><td>13</td><td>VDD_NRF</td><td>I/O</td><td>DC 3V3 Power Supply Voltage (Output when powered by 5V/VBAT)</td></tr><tr><td>14</td><td>GND</td><td>－</td><td>Ground</td></tr><tr><td>15</td><td>UART1_TX</td><td>Output</td><td>UART1 Interface P0.19</td></tr><tr><td>16</td><td>UART1_RX</td><td>Input</td><td>UART1 Interface P0.20</td></tr><tr><td>17</td><td>UART1_DE</td><td>I/O</td><td>UART DE Interface P0.21</td></tr><tr><td>18</td><td>SWDIO</td><td>I/O</td><td>SWD Debug Pin (SWDIO)</td></tr><tr><td>19</td><td>SWCLK</td><td>I/O</td><td>SWD Debug Pin (SWCLK)</td></tr><tr><td>20</td><td>VCC_5V</td><td>Input</td><td>VCC_5V Power Supply Voltage (For PA)</td></tr><tr><td>21</td><td>VBAT_SX</td><td>Input</td><td>DC 3V3 Power Supply Voltage</td></tr><tr><td>22</td><td>I2C_SDA2</td><td>I/O</td><td>I2C (SDA) P0.24</td></tr><tr><td>23</td><td>I2C_SCL2</td><td>I/O</td><td>I2C (SCL) P0.25</td></tr><tr><td>24</td><td>SW1</td><td>Output</td><td>GPIO P1.01</td></tr><tr><td>25</td><td>SW2</td><td>Output</td><td>GPIO P1.02</td></tr><tr><td>26</td><td>LED1</td><td>Output</td><td>GPIO P1.03</td></tr><tr><td>27</td><td>LED2</td><td>Output</td><td>GPIO P1.04</td></tr><tr><td>28</td><td>NFC1</td><td>Output</td><td>NFC / GPIO P0.09</td></tr><tr><td>29</td><td>NFC2</td><td>Output</td><td>NFC / GPIO P0.10</td></tr><tr><td>30</td><td>QSPI_CLK</td><td>I/O</td><td>SPI Interface / GPIO P0.03</td></tr><tr><td>31</td><td>QSPI_DIO3</td><td>I/O</td><td>SPI Interface / GPIO P0.02</td></tr><tr><td>32</td><td>QSPI_DIO1</td><td>I/O</td><td>SPI Interface / GPIO P0.29</td></tr><tr><td>33</td><td>P0.31/AIN7</td><td>Input</td><td>ADC Interface / GPIO P0.31</td></tr><tr><td>34</td><td>QSPI_DIO0</td><td>I/O</td><td>SPI Interface / GPIO P0.30</td></tr><tr><td>35</td><td>QSPI_DIO2</td><td>I/O</td><td>SPI Interface / GPIO P0.28</td></tr><tr><td>36</td><td>P0.05/AIN3</td><td>Input</td><td>ADC Interface / GPIO P0.05</td></tr><tr><td>37</td><td>P0.04/AIN2</td><td>Input</td><td>ADC Interface / GPIO P0.04</td></tr><tr><td>38</td><td>QSPI_CS</td><td>I/O</td><td>SPI CS / GPIO P0.26</td></tr><tr><td>39</td><td>GND</td><td>－</td><td>Ground</td></tr><tr><td>40</td><td>LoRa RF</td><td>Output</td><td>RF Port (For models without IPEX connector)</td></tr></tbody></table>

#### Package Dimensions

*(Unit: mm)*

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2F32uMdBwJiO8CjvMiBhET%2F30s%20%E6%A8%A1%E7%BB%84%E5%B0%81%E8%A3%85%E5%B0%BA%E5%AF%B8%E5%9B%BE.jpeg?alt=media&amp;token=7bdf2d1d-da14-4d4a-a06a-c56d7887c2e8" alt=""><figcaption></figcaption></figure>

***

### Electrical Characteristics

#### General Characteristics

<table data-header-hidden><thead><tr><th width="226.6796875"></th><th></th></tr></thead><tbody><tr><td><strong>Name</strong></td><td><strong>Description</strong></td></tr><tr><td>Model</td><td>GAT562 30S Mesh Module</td></tr><tr><td>Dimensions</td><td>26.5 x 28 x 3.0 mm (L x W x H)</td></tr><tr><td>Interfaces</td><td>UART1, UART2, GPIOs, ADC</td></tr><tr><td>Operating Temp</td><td>-40°C to 85°C</td></tr><tr><td>Storage Temp</td><td>-40°C to 85°C</td></tr></tbody></table>

#### Operating Conditions

<table data-header-hidden><thead><tr><th></th><th width="117.52734375"></th><th width="116.03125"></th><th width="120.7265625"></th><th width="138.91015625"></th></tr></thead><tbody><tr><td><strong>Parameter</strong></td><td><a data-footnote-ref href="#user-content-fn-1"><strong>Min.</strong></a></td><td><strong>Typ.</strong></td><td><strong>Max.</strong></td><td><strong>Unit</strong></td></tr><tr><td>Operating Temperature</td><td>-40</td><td>25</td><td>85</td><td>°C</td></tr><tr><td>BT LoRa Voltage</td><td>3.15</td><td>3.3</td><td>3.45</td><td>V</td></tr><tr><td>PA Operating Voltage</td><td>4.8</td><td>5.0</td><td>5.2</td><td>V</td></tr></tbody></table>

#### RF Characteristics

General

* Frequency Range: 470M-510M / 865M-928M
* Interfaces: UART1, UART2, GPIOs, ADC

Performance Data

| **Feature**       | **Status**      | **Min** | **Typ** | **Max** | **Unit** |
| ----------------- | --------------- | ------- | ------- | ------- | -------- |
| RF Transmission   | RF Output Power | 28.5    | 30      | -       | dBm      |
| RX Sensitivity    | RSSI            | -130    | -       | -       | dBm      |
|                   | SNR             | -15     | -       | -       | dB       |
| Power Consumption | TX mode (30dBm) | -       | 490     | -       | mA       |
|                   | RX mode         | -       | 7.2     | -       | mA       |
|                   | Sleep mode      | -       | 7.2     | -       | uA       |

***

### Design Reference Footprint

*(Unit: mm)*

<figure><img src="https://3395533350-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LD97pa04tZLvlPyG5f6-887967055%2Fuploads%2FDZ7SZWvnZUWmhne68B5A%2F30s%20%E8%AE%BE%E8%AE%A1%E5%8F%82%E8%80%83%E5%B0%81%E8%A3%85%E5%9B%BE.jpeg?alt=media&amp;token=e1db0254-2e54-4a52-987d-11ddddae540c" alt=""><figcaption></figcaption></figure>

***

### Reflow Soldering Temperature Curve

Refer to IPC/JEDEC standards.

* Peak Temperature: < 250°C

* Cycles: Not more than 2 times.

* Ramp up rate: Max 2°C/sec

* Preheat: 150\~200°C (60\~120 sec)

* Peak: 245 +0/-5°C

* Time above 217°C: 40\~70 sec

* Ramp down rate: Max 2.5°C/sec

[^1]:


