QR code security

QR code security
复制标题

DOI:
10.1145/1971519.1971593
复制
发表时间:
2010-11
期刊:
--
影响因子:
--
通讯作者:
Peter Kieseberg;Manuel Leithner;M. Mulazzani;Lindsay Munroe;S. Schrittwieser;Mayank Sinha;E. Weippl
Peter Kieseberg;Manuel Leithner;M. Mulazzani;Lindsay Munroe;S. Schrittwieser;Mayank Sinha;E. Weippl
中科院分区:
其他
文献类型:
--
作者:
Peter Kieseberg;Manuel Leithner;M. Mulazzani;Lindsay Munroe;S. Schrittwieser;Mayank Sinha;E. Weippl

文献摘要

被引文献

相似文献

本文研究了QR码以及它们如何被用来攻击人类互动和自动化系统。由于编码的信息只能是机器可读的,人类无法区分有效的QR码和恶意操纵的QR码。虽然人类可能会受到网络钓鱼攻击,但自动读取器最容易受到SQL注入和命令注入的攻击。我们的贡献包括对QR码作为攻击向量的分析,从攻击者的角度展示不同的攻击策略,并探索其可能的后果。
This paper examines QR Codes and how they can be used to attack both human interaction and automated systems. As the encoded information is intended to be machine readable only, a human cannot distinguish between a valid and a maliciously manipulated QR code. While humans might fall for phishing attacks, automated readers are most likely vulnerable to SQL injections and command injections. Our contribution consists of an analysis of the QR Code as an attack vector, showing different attack strategies from the attackers point of view and exploring their possible consequences.