EvilZone
Hacking and Security => Mobile Hacking => : imation December 21, 2011, 12:55:26 PM
-
Quick Response (QR) Codes are a rapidly emerging and prevalent medium for connecting users of smartphone technologies with online content. The codes, or ciphers, are digitally generated black and white space that when scanned by a capable smart device, will decipher the code and direct the devices web browser to the embedded, associated, URL.
QR Codes themselves can be very easily created using a variety of online generators that are becoming increasingly free and available to use. The generation process for a QR Code is no more difficult than inserting a URL into creation tool whereby a code is automatically generated as an image file ready for physical and/or digital distribution.
From an hackers perspective, QR codes ‘potentially’ offer a new medium by which to ‘force direct’ unsuspecting users to a malware laden/malicious sites. The key reason for this is that the site URL represented by the QR code is obviously no longer identifiable/visible to the user, as the code is nothing more than a series of unmeaning black and white blocked spaces.
This being said, obviosuly using this combined with BeEF Project could have some awesome results.
So, you find a website with a Sql vuln, maybe put a post on the blog or front page with a QR code Picture or link to your malicius site/app, Keep it up for a little while, see how many users process it and have some fun..
Just another way of hiding links...
Here are some links
http://qrcode.kaywa.com/ (http://qrcode.kaywa.com/)
http://www.qrstuff.com/ (http://www.qrstuff.com/)
http://www.racoindustries.com/barcodegenerator/2d/qr-code.aspx (http://www.racoindustries.com/barcodegenerator/2d/qr-code.aspx)
there are fucking loads tbh... just google
Here is an interesting one
http://wordpress.mrreid.org/2011/08/06/hacking-qr-codes/ (http://wordpress.mrreid.org/2011/08/06/hacking-qr-codes/)
http://hackaday.com/2011/08/11/how-to-put-your-logo-in-a-qr-code/ (http://hackaday.com/2011/08/11/how-to-put-your-logo-in-a-qr-code/)
http://mashable.com/2011/04/18/qr-code-design-tips/ (http://mashable.com/2011/04/18/qr-code-design-tips/)
Have Fun
*DONT GET CAUGHT* *USE AT YOUR OWN RISK*
-
hanging up qr codes with a tinyurl to goatse pic, oops
-
http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/ (http://www.theregister.co.uk/2012/01/11/qr_codes_mobile_spam/)
lol
-
Imagine if we could execute code through it :P
-
Imagine if we could execute code through it :P
Well if you combine it with BeEF like imation suggested, you can.