Abandoned QR code subdomains open to hijacking, researcher says

By
Follow google news

'QR Jacking' easy and fast way to exploit a vulnerability in a trusted ecosystem.

A security researcher has shown how attackers can take over companies' legitimately branded QR code web addresses by abusing a weakness in vendors' custom domain feature, sending anyone who scans a genuine code to a site of the attacker's choosing.

Abandoned QR code subdomains open to hijacking, researcher says

Farzan Karimi, who previously led red teams at Google and Electronic Arts, published the research this week under the label "QR Jacking". 

"Every QR code pointed to a real corporate domain… but every destination was mine," Karimi said in a blog post.

Karimi demonstrated the flaw via popular code provider QR Tiger, using the company's "Own Short Domain" feature.

This lets businesses serve codes from a branded address such as qr.company.com, set up with a CNAME record, a domain name system (DNS) entry that points the subdomain at QR Tiger's servers.

However, Karimi said the platform only checked that the record existed, never who was claiming it.

That let any QR Tiger account holder claim a subdomain still pointing at the platform but no longer registered, typically because a company had stopped using the service without removing its DNS record.

"The entire takeover takes under a minute," Karimi said.

Karimi confirmed to iTnews that the flaw affects existing QR codes as well.

"Absolutely. If the QR code was generated for a campaign and the company doesn't clean up the DNS record after the campaign ends, every existing QR code printed for that campaign is at risk of compromise through this methodology," Karimi explained.

He said he had found hundreds of vulnerable companies across manufacturing, healthcare, financial services and technology, though Karimi did not publish a count or name any of them. 

Karimi said QR Tiger had not fixed the flaw five months after he reported it to the company.

To mitigate the vulnerability, Karimi proposed a check most software-as-a-service (SaaS) platforms already use, namely a unique ownership token published in a TXT record. 

Karimi said people who distrust email links rarely question a code on packaging or a conference stand, particularly when the phone shows the company's own domain.

Printed codes also can't be recalled with a software update.

Still, the attack has limits as each vulnerable subdomain exists only because a company left a stale DNS record in place, a basic hygiene failure on the customer's side.

"If the [DNS] record exists and nobody on your team owns that integration, remove it today," Karimi said.

The security researcher said he was disclosing similar findings for other QR vendors, and planned to release his scanning tool, QR Tiger King, on GitHub.

The QR Jacking technique is not be confused with QRLJacking, a similarly named attack published in 2016 by Egyptian researcher Mohamed Abdelbasset Elnouby and hosted as an OWASP project.

QRLJacking targets "log in with a QR code" features, such as WhatsApp Web, by showing victims an attacker's live login code so that scanning it hands over their session.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

ASD says prompt injection in AI cannot be fixed

ASD says prompt injection in AI cannot be fixed

Australian Medicare data portal "infiltrated" by OpenAI agent

Australian Medicare data portal "infiltrated" by OpenAI agent

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Security researcher says don't install Meta's Muse AI assistant

Security researcher says don't install Meta's Muse AI assistant

Log In

  |  Forgot your password?