{"id":153,"date":"2007-12-17T23:45:10","date_gmt":"2007-12-17T21:45:10","guid":{"rendered":"http:\/\/blackbag.toool.nl\/?p=153"},"modified":"2007-12-17T23:45:10","modified_gmt":"2007-12-17T21:45:10","slug":"toools-field-test-on-axa-locks","status":"publish","type":"post","link":"https:\/\/blackbag.toool.nl\/?p=153","title":{"rendered":"Toool&#8217;s field test on AXA locks"},"content":{"rendered":"<p>An image can say more then a thousand words &#8230;.<\/p>\n<p><a href=\"http:\/\/toool.nl\"><img decoding=\"async\" src=\"http:\/\/blackbag.toool.nl\/images\/axa-profiles.jpg\" alt=\"Toool.nl\" \/><\/a><\/p>\n<p>I guess by now quite some people are comparing their key to the above image, hoping their key has the same profile as the AX1RP blank (on the right)&#8230;..<\/p>\n<p>Why?!? <\/p>\n<p>In cooperation with Kassa TV and one other organisation we performed a little test. In and around Amsterdam we tried to open over 150 bicycles. We got help from random bicyclists, bike shops, and even received assistance from local law-enforcement. Result: we managed to open around 50% of them&#8230;.<\/p>\n<p>By far the most interesting and intriguing thing we found is that almost all locks we could open used the so called &#8216;standard key profile&#8217; (blank AX1P). Locks using the &#8216;mirror image profile&#8217; (AX1RP) seemed almost impossible to open. And we are still investigating why. And we do warn people the flaw might be exploitable in the mirror image profile someday soon &#8230; many people are now looking into it, and it could be a matter of time. But for now it seems ok &#8230;<\/p>\n<p>One other interesting fact: we managed to open almost all <a href=\"http:\/\/blackbag.toool.nl\/images\/583.jpg\">583<\/a> models (over 90%), as well as a high percentage of <a href=\"http:\/\/blackbag.toool.nl\/images\/sl7.jpg\">SL7<\/a> and <a href=\"http:\/\/blackbag.toool.nl\/images\/sl9.jpg\">SL9<\/a> locks&#8230;. if they used a &#8216;standard key profile&#8217; that is. And a lot of SL9 locks were equipped with a mirror image profile. <\/p>\n<p>Axa by now admits more locks are vulnerable as they expected before, and they will come out with a report themselves any day now. Curious if they found the same things we did (in our relatively small test).<\/p>\n<p>More about this test and the findings (in Dutch) on <a href=\"http:\/\/kassa.vara.nl\/portal?_scr=kassa_artikel&#038;number=3777286\">Kassa TV<\/a> or <a href=\"http:\/\/toool.nl\">http:\/\/toool.nl<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An image can say more then a thousand words &#8230;. I guess by now quite some people are comparing their key to the above image, hoping their key has the same profile as the AX1RP blank (on the right)&#8230;.. Why?!? In cooperation with Kassa TV and one other organisation we performed a little test. In [&hellip;]<\/p>\n","protected":false},"author":171,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"_links":{"self":[{"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=\/wp\/v2\/posts\/153"}],"collection":[{"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=\/wp\/v2\/users\/171"}],"replies":[{"embeddable":true,"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=153"}],"version-history":[{"count":0,"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=\/wp\/v2\/posts\/153\/revisions"}],"wp:attachment":[{"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blackbag.toool.nl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}