Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. This. Just, this.

This. Just, this.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
151 Indlæg 112 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • ireneista@adhd.irenes.spaceI ireneista@adhd.irenes.space

    @cstross oh, but this exists. someone on here did a small batch of sew-on patches a few years ago that were QR codes of the EICAR test file. we have a couple...

    ireneista@adhd.irenes.spaceI This user is from outside of this forum
    ireneista@adhd.irenes.spaceI This user is from outside of this forum
    ireneista@adhd.irenes.space
    wrote on sidst redigeret af
    #46

    @cstross it isn't technically a virus, it's a file that virus scanners per their spec are supposed to treat as if it's a virus. so, for example, if a badly-written surveillance camera decodes the QR code and stores it in a way that a virus scanner can see (which is not what it should do, but...), then the virus scanner will quarantine the file which may break the camera

    ireneista@adhd.irenes.spaceI 1 Reply Last reply
    0
    • flippac@types.plF flippac@types.pl

      @neurovagrant @cstross @unknownbinaries How big a zip bomb can you get in one, anyway? And can you fit the EICAR string in an unpleasantly long way in?...

      earthshine@masto.hackers.townE This user is from outside of this forum
      earthshine@masto.hackers.townE This user is from outside of this forum
      earthshine@masto.hackers.town
      wrote on sidst redigeret af
      #47

      @flippac @neurovagrant @cstross @unknownbinaries if you're executing arbitrary code from a QR code, I think a zip bomb is the least of your worries.

      flippac@types.plF cstross@wandering.shopC 2 Replies Last reply
      0
      • ireneista@adhd.irenes.spaceI ireneista@adhd.irenes.space

        @cstross it isn't technically a virus, it's a file that virus scanners per their spec are supposed to treat as if it's a virus. so, for example, if a badly-written surveillance camera decodes the QR code and stores it in a way that a virus scanner can see (which is not what it should do, but...), then the virus scanner will quarantine the file which may break the camera

        ireneista@adhd.irenes.spaceI This user is from outside of this forum
        ireneista@adhd.irenes.spaceI This user is from outside of this forum
        ireneista@adhd.irenes.space
        wrote on sidst redigeret af
        #48

        @cstross that said, to know whether it actually works and when would require a lot of testing, which to our knowledge nobody has done

        1 Reply Last reply
        0
        • earthshine@masto.hackers.townE earthshine@masto.hackers.town

          @flippac @neurovagrant @cstross @unknownbinaries if you're executing arbitrary code from a QR code, I think a zip bomb is the least of your worries.

          flippac@types.plF This user is from outside of this forum
          flippac@types.plF This user is from outside of this forum
          flippac@types.pl
          wrote on sidst redigeret af
          #49

          @earthshine @neurovagrant @cstross @unknownbinaries it doesn't need to be executed - just mishandled by careless AV

          1 Reply Last reply
          0
          • cstross@wandering.shopC cstross@wandering.shop

            This. Just, this.

            jmvars@mastodon.socialJ This user is from outside of this forum
            jmvars@mastodon.socialJ This user is from outside of this forum
            jmvars@mastodon.social
            wrote on sidst redigeret af
            #50

            @cstross my phone does not automatically scan QR codes, is this a feature on newer phones?

            cstross@wandering.shopC 1 Reply Last reply
            0
            • earthshine@masto.hackers.townE earthshine@masto.hackers.town

              @flippac @neurovagrant @cstross @unknownbinaries if you're executing arbitrary code from a QR code, I think a zip bomb is the least of your worries.

              cstross@wandering.shopC This user is from outside of this forum
              cstross@wandering.shopC This user is from outside of this forum
              cstross@wandering.shop
              wrote on sidst redigeret af
              #51

              @earthshine @flippac @neurovagrant @unknownbinaries QR code to download a PDF containing Javascript (which the PDF standard now incorporates) to dynamically generate a zip bomb containing infinite copies of itself.

              earthshine@masto.hackers.townE 1 Reply Last reply
              0
              • jmvars@mastodon.socialJ jmvars@mastodon.social

                @cstross my phone does not automatically scan QR codes, is this a feature on newer phones?

                cstross@wandering.shopC This user is from outside of this forum
                cstross@wandering.shopC This user is from outside of this forum
                cstross@wandering.shop
                wrote on sidst redigeret af
                #52

                @Jmvars If so, it's a mis-feature. (iOS recognizes QR codes but then tells you to tap to confirm you want to open the URL it points to.)

                1 Reply Last reply
                0
                • agathos@mastodon.babb.noA This user is from outside of this forum
                  agathos@mastodon.babb.noA This user is from outside of this forum
                  agathos@mastodon.babb.no
                  wrote on sidst redigeret af
                  #53

                  @neurovagrant @trainguyrom @anotherdaniel @cstross @unknownbinaries I am not saying that a huge grocery store chain in norway is vulnerable to this "attack" in their self service tills, I would not know anything about that, no need to ask any further questions

                  cadbury_moose@wandering.shopC tirrimas@beige.partyT 2 Replies Last reply
                  0
                  • cstross@wandering.shopC cstross@wandering.shop

                    This. Just, this.

                    lydialurch@mastodon.socialL This user is from outside of this forum
                    lydialurch@mastodon.socialL This user is from outside of this forum
                    lydialurch@mastodon.social
                    wrote on sidst redigeret af
                    #54

                    @cstross Fuck yeah, I want one too and accessories as well!

                    1 Reply Last reply
                    0
                    • cstross@wandering.shopC cstross@wandering.shop

                      This. Just, this.

                      lispi314@udongein.xyzL This user is from outside of this forum
                      lispi314@udongein.xyzL This user is from outside of this forum
                      lispi314@udongein.xyz
                      wrote on sidst redigeret af
                      #55
                      @cstross @alice Arguably if their camera does that it's /already/ infested with malware, a dropper specifically.
                      1 Reply Last reply
                      0
                      • cstross@wandering.shopC cstross@wandering.shop

                        @earthshine @flippac @neurovagrant @unknownbinaries QR code to download a PDF containing Javascript (which the PDF standard now incorporates) to dynamically generate a zip bomb containing infinite copies of itself.

                        earthshine@masto.hackers.townE This user is from outside of this forum
                        earthshine@masto.hackers.townE This user is from outside of this forum
                        earthshine@masto.hackers.town
                        wrote on sidst redigeret af
                        #56

                        @cstross @flippac @neurovagrant @unknownbinaries isn't modern software great?

                        1 Reply Last reply
                        0
                        • cstross@wandering.shopC cstross@wandering.shop

                          This. Just, this.

                          n_dimension@infosec.exchangeN This user is from outside of this forum
                          n_dimension@infosec.exchangeN This user is from outside of this forum
                          n_dimension@infosec.exchange
                          wrote on sidst redigeret af
                          #57

                          @cstross

                          I thought that's why Hentai TShirts are printed!

                          1 Reply Last reply
                          0
                          • cstross@wandering.shopC cstross@wandering.shop

                            This. Just, this.

                            aspragg@ohai.socialA This user is from outside of this forum
                            aspragg@ohai.socialA This user is from outside of this forum
                            aspragg@ohai.social
                            wrote on sidst redigeret af
                            #58

                            @cstross Sounds like the sort of thing that Adversarial Fashion would do/be interested in:

                            https://adversarialfashion.com/

                            1 Reply Last reply
                            0
                            • cstross@wandering.shopC cstross@wandering.shop

                              This. Just, this.

                              xs4me2@mastodon.socialX This user is from outside of this forum
                              xs4me2@mastodon.socialX This user is from outside of this forum
                              xs4me2@mastodon.social
                              wrote on sidst redigeret af
                              #59

                              @cstross

                              Great idea actually!

                              1 Reply Last reply
                              0
                              • datterich@darmstadt.socialD This user is from outside of this forum
                                datterich@darmstadt.socialD This user is from outside of this forum
                                datterich@darmstadt.social
                                wrote on sidst redigeret af
                                #60

                                @neurovagrant @cstross @unknownbinaries
                                There's an older discussion on the topic here in my and @catsalad's timeline, not only with the EICAR, but also with a nice SQL bomb (remember Bobby Tables? 😉). Please feel free to make a shirt out of it.

                                On German ambulances are QR codes leading to pages informing about why it's bad to film victims and rescuers. A good idea. Makes filming impossible if your camera app opens QR codes right away without user consent...

                                qgustavor@urusai.socialQ catsalad@infosec.exchangeC 2 Replies Last reply
                                0
                                • cstross@wandering.shopC cstross@wandering.shop

                                  This. Just, this.

                                  alandvalonline@mastodon.socialA This user is from outside of this forum
                                  alandvalonline@mastodon.socialA This user is from outside of this forum
                                  alandvalonline@mastodon.social
                                  wrote on sidst redigeret af
                                  #61

                                  @cstross Put me on the wait list. I'm in.

                                  1 Reply Last reply
                                  0
                                  • jqmcd@sfba.socialJ This user is from outside of this forum
                                    jqmcd@sfba.socialJ This user is from outside of this forum
                                    jqmcd@sfba.social
                                    wrote on sidst redigeret af
                                    #62

                                    @cstross I feel sorry for the photographer covering the protest for the school newspaper over at the community college

                                    1 Reply Last reply
                                    0
                                    • datterich@darmstadt.socialD datterich@darmstadt.social

                                      @neurovagrant @cstross @unknownbinaries
                                      There's an older discussion on the topic here in my and @catsalad's timeline, not only with the EICAR, but also with a nice SQL bomb (remember Bobby Tables? 😉). Please feel free to make a shirt out of it.

                                      On German ambulances are QR codes leading to pages informing about why it's bad to film victims and rescuers. A good idea. Makes filming impossible if your camera app opens QR codes right away without user consent...

                                      qgustavor@urusai.socialQ This user is from outside of this forum
                                      qgustavor@urusai.socialQ This user is from outside of this forum
                                      qgustavor@urusai.social
                                      wrote on sidst redigeret af
                                      #63

                                      @Datterich @neurovagrant @cstross @unknownbinaries @catsalad Which camera opens QR codes right away?! Well, to be fair I have to use a FOSS QR scanner because the camera app from my phone doesn't scan those at all, but I never saw any phone that opens QR codes right away ever.

                                      datterich@darmstadt.socialD 1 Reply Last reply
                                      0
                                      • cstross@wandering.shopC cstross@wandering.shop

                                        This. Just, this.

                                        madargon@is-a.catM This user is from outside of this forum
                                        madargon@is-a.catM This user is from outside of this forum
                                        madargon@is-a.cat
                                        wrote on sidst redigeret af
                                        #64

                                        @cstross damn, it's even more creative than my fantasies about brain implant generating white noise to interrupt others' phones cloud connectivity

                                        1 Reply Last reply
                                        0
                                        • cstross@wandering.shopC cstross@wandering.shop

                                          This. Just, this.

                                          catswhocode@twoot.siteC This user is from outside of this forum
                                          catswhocode@twoot.siteC This user is from outside of this forum
                                          catswhocode@twoot.site
                                          wrote on sidst redigeret af
                                          #65

                                          @cstross It's already happened to me several times! Need one of these!

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper