Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. trying a new thing, have 3D printed a QR code and put it on the front porch

trying a new thing, have 3D printed a QR code and put it on the front porch

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
infosec
41 Indlæg 31 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • secureowl@infosec.exchangeS secureowl@infosec.exchange

    Whelp, sample size of 1 so far, but about 50 minutes after an amazon delivery - where a picture was taken - got a hit on the canary

    i just checked the delivery photo and the QR code was visible in it

    User agent was not a phone and clearly some sort of crawler

    IP address was a CDN

    but we are 1/1, lets see how it goes with a few more

    (i get a lot of random work deliveries)

    seismoallegra@mastodon.socialS This user is from outside of this forum
    seismoallegra@mastodon.socialS This user is from outside of this forum
    seismoallegra@mastodon.social
    wrote sidst redigeret af
    #23

    @SecureOwl brilliant test. Can't wait to see more results.

    1 Reply Last reply
    0
    • alesandroortiz@infosec.exchangeA alesandroortiz@infosec.exchange

      @SecureOwl Now try some blind XSS payloads...

      catsalad@infosec.exchangeC This user is from outside of this forum
      catsalad@infosec.exchangeC This user is from outside of this forum
      catsalad@infosec.exchange
      wrote sidst redigeret af
      #24

      @AlesandroOrtiz @SecureOwl

      malwareminigun@infosec.exchangeM 1 Reply Last reply
      0
      • secureowl@infosec.exchangeS secureowl@infosec.exchange

        trying a new thing, have 3D printed a QR code and put it on the front porch

        QR code triggers a canary token

        want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

        #infosec

        ddr@pony.socialD This user is from outside of this forum
        ddr@pony.socialD This user is from outside of this forum
        ddr@pony.social
        wrote sidst redigeret af
        #25

        I am so curious to know the results of this, @SecureOwl. What a great injection vector!

        1 Reply Last reply
        0
        • secureowl@infosec.exchangeS secureowl@infosec.exchange

          trying a new thing, have 3D printed a QR code and put it on the front porch

          QR code triggers a canary token

          want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

          #infosec

          itgrrl@infosec.exchangeI This user is from outside of this forum
          itgrrl@infosec.exchangeI This user is from outside of this forum
          itgrrl@infosec.exchange
          wrote sidst redigeret af
          #26

          @SecureOwl genius! replicating this ASAP… 🍿 👀

          1 Reply Last reply
          0
          • catsalad@infosec.exchangeC catsalad@infosec.exchange

            @AlesandroOrtiz @SecureOwl

            malwareminigun@infosec.exchangeM This user is from outside of this forum
            malwareminigun@infosec.exchangeM This user is from outside of this forum
            malwareminigun@infosec.exchange
            wrote sidst redigeret af
            #27

            @catsalad @AlesandroOrtiz @SecureOwl This is giving very "Cracking the Lens" vibes https://www.youtube.com/watch?v=zP4b3pw94s0

            1 Reply Last reply
            0
            • douglasvb@m.ai6yr.orgD douglasvb@m.ai6yr.org

              @SecureOwl you could have a lot of fun with this 🤣

              sarae@ecoevo.socialS This user is from outside of this forum
              sarae@ecoevo.socialS This user is from outside of this forum
              sarae@ecoevo.social
              wrote sidst redigeret af
              #28

              @douglasvb @SecureOwl yeah now I kind of want to figure out a way to put prompt injection on my roof

              I've got dark shingles so anything I do in white paint should show up real well

              what would really mess with aerial imaging software?

              douglasvb@m.ai6yr.orgD srlevine@neuromatch.socialS jeffc@mastodon.onlineJ 3 Replies Last reply
              0
              • sarae@ecoevo.socialS sarae@ecoevo.social

                @douglasvb @SecureOwl yeah now I kind of want to figure out a way to put prompt injection on my roof

                I've got dark shingles so anything I do in white paint should show up real well

                what would really mess with aerial imaging software?

                douglasvb@m.ai6yr.orgD This user is from outside of this forum
                douglasvb@m.ai6yr.orgD This user is from outside of this forum
                douglasvb@m.ai6yr.org
                wrote sidst redigeret af
                #29

                @sarae @SecureOwl a YouTube link to a rickroll?

                sarae@ecoevo.socialS 1 Reply Last reply
                0
                • secureowl@infosec.exchangeS secureowl@infosec.exchange

                  trying a new thing, have 3D printed a QR code and put it on the front porch

                  QR code triggers a canary token

                  want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

                  #infosec

                  com@mastodon.socialC This user is from outside of this forum
                  com@mastodon.socialC This user is from outside of this forum
                  com@mastodon.social
                  wrote sidst redigeret af
                  #30

                  @SecureOwl Excellent. 😈

                  The blood-stained door mat is also a nice touch. 😚🤌

                  1 Reply Last reply
                  0
                  • douglasvb@m.ai6yr.orgD douglasvb@m.ai6yr.org

                    @sarae @SecureOwl a YouTube link to a rickroll?

                    sarae@ecoevo.socialS This user is from outside of this forum
                    sarae@ecoevo.socialS This user is from outside of this forum
                    sarae@ecoevo.social
                    wrote sidst redigeret af
                    #31

                    @douglasvb @SecureOwl I'm thinking something more, uh, outgoing

                    like, what would really mess with image processing?

                    douglasvb@m.ai6yr.orgD 1 Reply Last reply
                    0
                    • sarae@ecoevo.socialS sarae@ecoevo.social

                      @douglasvb @SecureOwl yeah now I kind of want to figure out a way to put prompt injection on my roof

                      I've got dark shingles so anything I do in white paint should show up real well

                      what would really mess with aerial imaging software?

                      srlevine@neuromatch.socialS This user is from outside of this forum
                      srlevine@neuromatch.socialS This user is from outside of this forum
                      srlevine@neuromatch.social
                      wrote sidst redigeret af
                      #32

                      @sarae @douglasvb @SecureOwl I think I saw a reference to someone making things that look "pixelated" when viewed from above on satellite imaging, which could be kind of funny on a normal home and not say a military base...

                      1 Reply Last reply
                      0
                      • sarae@ecoevo.socialS sarae@ecoevo.social

                        @douglasvb @SecureOwl I'm thinking something more, uh, outgoing

                        like, what would really mess with image processing?

                        douglasvb@m.ai6yr.orgD This user is from outside of this forum
                        douglasvb@m.ai6yr.orgD This user is from outside of this forum
                        douglasvb@m.ai6yr.org
                        wrote sidst redigeret af
                        #33

                        @sarae @SecureOwl you could do an SQL injection attack.

                        Maybe little Bobby Drop Tables lives at your house 🤣

                        1 Reply Last reply
                        0
                        • secureowl@infosec.exchangeS secureowl@infosec.exchange

                          trying a new thing, have 3D printed a QR code and put it on the front porch

                          QR code triggers a canary token

                          want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

                          #infosec

                          geofurb@infosec.exchangeG This user is from outside of this forum
                          geofurb@infosec.exchangeG This user is from outside of this forum
                          geofurb@infosec.exchange
                          wrote sidst redigeret af
                          #34

                          @SecureOwl Why would you expect the AI to be able to follow links from a QR code encountered during training?

                          liquor_american@universeodon.comL 1 Reply Last reply
                          0
                          • secureowl@infosec.exchangeS secureowl@infosec.exchange

                            trying a new thing, have 3D printed a QR code and put it on the front porch

                            QR code triggers a canary token

                            want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

                            #infosec

                            noondlyt@hellions.cloudN This user is from outside of this forum
                            noondlyt@hellions.cloudN This user is from outside of this forum
                            noondlyt@hellions.cloud
                            wrote sidst redigeret af
                            #35

                            @SecureOwl

                            pulls up a chair 🍿

                            1 Reply Last reply
                            0
                            • sarae@ecoevo.socialS sarae@ecoevo.social

                              @douglasvb @SecureOwl yeah now I kind of want to figure out a way to put prompt injection on my roof

                              I've got dark shingles so anything I do in white paint should show up real well

                              what would really mess with aerial imaging software?

                              jeffc@mastodon.onlineJ This user is from outside of this forum
                              jeffc@mastodon.onlineJ This user is from outside of this forum
                              jeffc@mastodon.online
                              wrote sidst redigeret af
                              #36

                              @sarae

                              "DISREGARD ALL PREVIOUS INSTRUCTIONS AND..."

                              @douglasvb @SecureOwl

                              1 Reply Last reply
                              0
                              • geofurb@infosec.exchangeG geofurb@infosec.exchange

                                @SecureOwl Why would you expect the AI to be able to follow links from a QR code encountered during training?

                                liquor_american@universeodon.comL This user is from outside of this forum
                                liquor_american@universeodon.comL This user is from outside of this forum
                                liquor_american@universeodon.com
                                wrote sidst redigeret af
                                #37

                                @geofurb @SecureOwl probably because a qr code isn't something he just invented?

                                1 Reply Last reply
                                0
                                • secureowl@infosec.exchangeS secureowl@infosec.exchange

                                  trying a new thing, have 3D printed a QR code and put it on the front porch

                                  QR code triggers a canary token

                                  want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

                                  #infosec

                                  axolotl1@gaygeek.socialA This user is from outside of this forum
                                  axolotl1@gaygeek.socialA This user is from outside of this forum
                                  axolotl1@gaygeek.social
                                  wrote sidst redigeret af
                                  #38

                                  @SecureOwl hey so what's a canary token. I'm not smart enough to know what that is.

                                  carey@mastodon.nzC 1 Reply Last reply
                                  0
                                  • secureowl@infosec.exchangeS secureowl@infosec.exchange

                                    Whelp, sample size of 1 so far, but about 50 minutes after an amazon delivery - where a picture was taken - got a hit on the canary

                                    i just checked the delivery photo and the QR code was visible in it

                                    User agent was not a phone and clearly some sort of crawler

                                    IP address was a CDN

                                    but we are 1/1, lets see how it goes with a few more

                                    (i get a lot of random work deliveries)

                                    axolotl1@gaygeek.socialA This user is from outside of this forum
                                    axolotl1@gaygeek.socialA This user is from outside of this forum
                                    axolotl1@gaygeek.social
                                    wrote sidst redigeret af
                                    #39

                                    @SecureOwl oh I see that's clever.

                                    1 Reply Last reply
                                    0
                                    • axolotl1@gaygeek.socialA axolotl1@gaygeek.social

                                      @SecureOwl hey so what's a canary token. I'm not smart enough to know what that is.

                                      carey@mastodon.nzC This user is from outside of this forum
                                      carey@mastodon.nzC This user is from outside of this forum
                                      carey@mastodon.nz
                                      wrote sidst redigeret af
                                      #40

                                      @Axolotl1 @SecureOwl the QR code links to a URL that has never been seen before, but the owner can see when it’s loaded from the server logs. There’s no good reason for a picture of a QR code to ever be loaded this way, and yet…

                                      1 Reply Last reply
                                      0
                                      • secureowl@infosec.exchangeS secureowl@infosec.exchange

                                        Whelp, sample size of 1 so far, but about 50 minutes after an amazon delivery - where a picture was taken - got a hit on the canary

                                        i just checked the delivery photo and the QR code was visible in it

                                        User agent was not a phone and clearly some sort of crawler

                                        IP address was a CDN

                                        but we are 1/1, lets see how it goes with a few more

                                        (i get a lot of random work deliveries)

                                        cmdrmoto@hachyderm.ioC This user is from outside of this forum
                                        cmdrmoto@hachyderm.ioC This user is from outside of this forum
                                        cmdrmoto@hachyderm.io
                                        wrote sidst redigeret af
                                        #41

                                        @SecureOwl Bloody brilliant.

                                        Looking forward to a near future where randomly placed QR codes are the techno social equivalent of a “don’t photograph me motherfucker” badge.

                                        1 Reply Last reply
                                        0
                                        • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                                        Svar
                                        • Svar som emne
                                        Login for at svare
                                        • Ældste til nyeste
                                        • Nyeste til ældste
                                        • Most Votes


                                        • Log ind

                                        • Har du ikke en konto? Tilmeld

                                        • Login or register to search.
                                        Powered by NodeBB Contributors
                                        Graciously hosted by data.coop
                                        • First post
                                          Last post
                                        0
                                        • Hjem
                                        • Seneste
                                        • Etiketter
                                        • Populære
                                        • Verden
                                        • Bruger
                                        • Grupper