Call Girls in Mayur Vihar âïž 9711199171 âïž Delhi âïž Enjoy Call Girls With Our...
Â
Null dec 2014
1.
2. Myself â Self Boasting/ Self D**ba
ï Authored a book at an age of 21 (2nd
edition WIP)
ï ISO 27001:2013 ISMS LA, CEH, CCNA, ECSA , JNCIP- SEC,
JNCIS-SEC etc.
ï Featured in Deccan Chronicle, The Hindu, The HANS India, Eenadu,
Vaartha, Saakshi, AndhraJyothi, Andhrabhoomi etc.
ï Interviewed by HMTV news channel
ï Reported vulnerabilities on 100+ popular websites and got lucky with
more than 2 dozen of CVE-IDs
ï Reported BOF on Yahoo Messenger
ï Trained more than 10,000 people (Corporate + Students)
ï Currently working with TCS as Security Analyst
Enough âŠâŠâŠ.Just Stop itâŠâŠâŠ!
3. Where am I taking you now?
ï Hell, why do I need to listen to this ?
ï Introduction to barcodes
ï Breaking down EAN â 13
ï Your Weapons
ï Here comes the âheartâ of this power-point deck
ï My experience with Barcode cracking
a) XYZ MNC well-known barcode crack
b) XYZ shopping mall etc
ï Brief Introduction on
XSS, SQL etc. attacks via Paper, yeah itâs
via PAPERâŠ! or NEWS PAPERâŠ! OMGâŠ!
4. With barcode cracking, you can
a) Buy a costly product at the rate of a cheap one
b) Free entry to parties â free beers etc
c) Free parking
d) Bypassing access control - Get free attendance / break your friendâs
attendance etc.
Disclaimer:
I am no way responsible for any mis-use of this technique. I am sharing it just
for informational purposes.
Why do I need to listen to this ?
5. ï Introduced by Joseph Woodland and Bernard Silver in 1952
ï First used in ACI but failed and then started commercially on
Wrigley company - chewing gum
ï Optical representation of data to uniquely identify items
ï Used for tickets, market items, books , parcel tracking,
parking etc
ï Barcodes , Scanners / Verifiers
ï Barcode verifier standards
a) Â ISO/IECÂ 15416Â (linear)
     b)  ISO/IEC 15426-2 (2D)
Introduction to Barcodes
6. Classification
1. 1D
a) EAN â 13 (World-wide)
b) UPC (USA, Canada etc)
c) Code 128
d) CodeBar
e) Plessey etc
2. 2D (More information)
a) QR code
b) Maxi code
c) Aztec code etc
3. 3D (Basing on height)
- To withstand high temperature
or chemical environments
14. Verifying check sum digit
1. Numbers at Even position are summed to value A
#0+#2+#4+#6+#8+#10 = Value A [7+0+0+4+3+1 = 15 ]
2. Numbers at Odd position are summed and multiplied by 3
3*(#1+#3+#5+#7+#9+#11) = Value B [3* (5+1+5+5+0+0) = 48 ]
3. Value A + Value B = Value C [ 63 ]
4. Remainder of (value C /10) is taken as value D [ 3 ]
5. If check digit = (10 value D), the code read by the machine is correct. [ 7 ]â
15. Initial Bit â Part 1 â Part 2
Ever wondered, How are those lines generated?
7 - 501054 - 530107
16. ï Black â 1 and white space â 0
ï Borders: 101 (left and right) and Center: 01010 (middle)
7 â ABABAB
<left border> 101
<part generated from A/B> 0110001 0100111 0011001 0100111 0110001 0011101
+<central > 01010
+< part generated from C > 1001110 1000010 1110010 1100110 1110010 1000100
<right border> 101
Fuzzy BuzzyâŠâŠ
20. XYZ Shopping Mall
Buy a product worth INR Rs 5000/- for INR Rs 1000/-
Demo experience
(Social Engineering*)
21.
22. Other scenarios
ïDrink beer at free of cost
ïAccess Control Magicâs
ïFree Parking
ïCorporate Asset Management etc
23. My Journey with âBeeeeeepâ â MNC (well known)
Demo Experience
24. XSS, SQL etc via PAPERâŠâŠâŠâŠ..!
ï QR codes
ï Below QR code for <script>alert("test")</script> (Demo)
http://qrcode.kaywa.com/
More demo and in-details in next talk ï