Hacking QR Codes with QRGen to Attack Scanning Devices [Tutorial]

preview_player
Показать описание
How to Use QR Codes to Hack Mobile Phones & Scanners

QR Codes are a fun way of scanning information with your mobile device on the go. However, this popular technique can be taken advantage of and used to inject malicious code and commands by a knowledgeable hacker. On this episode of Cyber Weapons Lab, we'll introduce you to a malicious QR code generator called QRGen.

Do not attempt to scan any malicious QR codes with a scanner you don't own. Only use for testing on your own devices and networks.

Follow Null Byte on:
Рекомендации по теме
Комментарии
Автор

NullByte hacked his own body and has rewritten the eye lubrication code: saving energy wasted on blinking.

eakerz
Автор

I'm happy you're liking my tool lmao

hnus
Автор

Imagine posting a qr code arround the city that links you to a virus, it would be insane

wolf-war-master
Автор

Can you put a donate link so we can support you when ever we can .

aoaar
Автор

It’s nice that you always troubleshoot and point out fixes for problems you had in the video. But you could also fix it for everybody and just do a pullrequest since all those tools are open source. Especially if it is just a typo in the readme.

ChillerDragon
Автор

QR codes have always been a security concern. Some phones (I think iphone as well, but not sure) can autolaunch a URL, leading to downloading an actual payload.

blakryptonite
Автор

Since it is written in python you can generate codes on Android phone via termux and then show the payload QRcode via any image viewer.

Trekeyus
Автор

what script for
when i scan QR code then directely jump to website ..????

Rexsisodia
Автор

“This one’s trying to etc into the password directory.”

WHAT?
It said cat /etc/passwd which would display the contents of the file ‘passwd’ in /etc/ on screen. Passwd is not a directory.

bbaovanc
Автор

kODY! Your my favorite person on YouTube since i start watching your videos i wanna thank you again and again for the education your providing us i can't thank you enough brother because your the best we've ever got and believe me no one can take your place.

FarazKhan-yyer
Автор

It annoys me so much that you don't have more subs! Been here for a long time now as you know think it was about 20k subs when we last spoke, your content is superb and yet still you're quality and extremely detailed content is still not getting the recognition you deserve! Your amazing keep it up and thank you for everything you do xxx

WhileyisaEskiboy
Автор

At 5:02 shouldn't that be the wordlist defined there as wordlist.txt rather than requirements.txt?

brianfreund
Автор

You should have named your channel : ZeroBlindByte

daqa
Автор

Imagine doing this to bitcoin atm's

TechDark
Автор

One word to describe your channel "Awesome!!"

hritishkumar
Автор

if you don't have a system in place to first detect the environment and then pick a known working payload, this is like the bruteforce of qr codes where you get auto-banned the second the person at the til looks at the screen. But definitely a start in bulletproofing your own setup.

MrRandsauce
Автор

i don't understand, shouldn't the command is -w wordlist.txt not -w requirements.txt?

dewasembiring
Автор

Here in Russia there was an attempt to attack camcorders on the roads, using combinations to exploit vulnerability sql injections, changing car numbers with malicious characters.
It can also work on cameras installed on parking.

Алексей-обг
Автор

Great video as always!
Also: do you know if it is possible to find someone if you have their google voice number?

fivedice
Автор

So in the state that I live in we have gas stations that have slot machines you can put money into and gamble. If you win and choose to "cash out" you simply hit the "cash out" button on the machine that you are playing and it prints a ticket with a QR code and you take it to the "prize redemption" machine that scans the QR code on the ticket that your machine printed and voila it spits out the amount you cashed out. Would there possibly be a way to manipulate the QR scanner into thinking that it scanned a winning ticket and to dispense money?

BrandonHadley-kwjr