Can a QR code run malware? Canada requires proof of Vax via QR Code. Asking for a fren
(media.greatawakening.win)
You're viewing a single comment thread. View all comments, or full comment thread.
Comments (17)
sorted by:
Short answer yes. Longer answer. The qr can link to a drop, or script address that "theoretically" could load some additional items.
I still won't get one, but the best approach I could think would be to look at how their app reads the code, then using the input part to figure a way to create the code in such a way that it will cause their reader to crash from an overflow or something.
Actually, given Canada's privacy act, even finding out if the app leaks data to 3rd parties would mean they are liable. (That lawsuit would be worth 100k, but that assumes the justice system here wasn't comped to the gills)
Or, assuming the app scanning the QR code itself has poor input sanitization (a very good assumption, btw), a specially crafted string could exploit the app itself.
It would be cool to fuzz the hell out of it and see what we can do. Maybe find a cheat code.
Will try to find the APK, I'm Alberta. Ontario is doing the same, we should find collaborators to try to break this thing.