Barcode attack technique (Badbarcode)

"The barcode attack that @Tk described on PacSec and included in his
demo video on twitter are so cool that I bought a scanner for research
as well. During my research, I went through all information whether it
is at home or abroad, but none covers the possible attack techniques.
So here is one.
The concept of using barcode to launch attack is raised years ago, but
no one digs deep. By using SQL barcode, it’s able to launch SQL
injection, XSS and overflow attack.

Whatever the device is, once part of the input can be manipulated, it
is risky."

  Wednesday, 02 Mar 2016
  • Sumber

