Skip to main content

QRLJacking Attack Can Bypass Any QR Login System

posted onJuly 31, 2016
by l33tdawg

Egyptian security researcher Mohamed Baset has published details about a new type of attack that successfully bypasses SQRLs (Secure QR Logins, aka Secure, Quick, Reliable Logins).

Dubbed QRLJacking, this is a social engineering attack that relies on phishing and other similar techniques to trick a victim into scanning the wrong QR code.

The attack works by requesting a QR code for the service the victim is trying to login into and modifying the QR code to send the confirmation message to the attacker's computer. The crook can modify these login details, add the data belonging to his PC, relay the data from his phone to the default login server, and access the victim's account from his PC.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th