SlideShare a Scribd company logo
Myself – Self Boasting/ Self D**ba
 Authored a book at an age of 21 (2nd
edition WIP)
 ISO 27001:2013 ISMS LA, CEH, CCNA, ECSA , JNCIP- SEC,
JNCIS-SEC etc.
 Featured in Deccan Chronicle, The Hindu, The HANS India, Eenadu,
Vaartha, Saakshi, AndhraJyothi, Andhrabhoomi etc.
 Interviewed by HMTV news channel
 Reported vulnerabilities on 100+ popular websites and got lucky with
more than 2 dozen of CVE-IDs
 Reported BOF on Yahoo Messenger
 Trained more than 10,000 people (Corporate + Students)
 Currently working with TCS as Security Analyst
Enough ……….Just Stop it………!
Where am I taking you now?
 Hell, why do I need to listen to this ?
 Introduction to barcodes
 Breaking down EAN – 13
 Your Weapons
 Here comes the “heart” of this power-point deck
 My experience with Barcode cracking
a) XYZ MNC well-known barcode crack
b) XYZ shopping mall etc
 Brief Introduction on
XSS, SQL etc. attacks via Paper, yeah it’s
via PAPER…! or NEWS PAPER…! OMG…!
With barcode cracking, you can
a) Buy a costly product at the rate of a cheap one
b) Free entry to parties – free beers etc
c) Free parking
d) Bypassing access control - Get free attendance / break your friend’s
attendance etc.
Disclaimer:
I am no way responsible for any mis-use of this technique. I am sharing it just
for informational purposes.
Why do I need to listen to this ?
 Introduced by Joseph Woodland and Bernard Silver in 1952
 First used in ACI but failed and then started commercially on
Wrigley company - chewing gum
 Optical representation of data to uniquely identify items
 Used for tickets, market items, books , parcel tracking,
parking etc
 Barcodes , Scanners / Verifiers
 Barcode verifier standards
a)  ISO/IEC 15416 (linear)
      b)  ISO/IEC 15426-2 (2D)
Introduction to Barcodes
Classification
1. 1D
a) EAN – 13 (World-wide)
b) UPC (USA, Canada etc)
c) Code 128
d) CodeBar
e) Plessey etc
2. 2D (More information)
a) QR code
b) Maxi code
c) Aztec code etc
3. 3D (Basing on height)
- To withstand high temperature
or chemical environments
Slide – Manideep
QR code Aztec Code Code 128
Why EAN 13? - Everywhere
Book
Deodorant
Shirt
Moisturizer Shampoo
Face wash
Powder
Breaking down EAN 13 into pieces
Do I need to learn this for doing hacks based on barcode??? - Yes…!
Country Code - 1st
two/three digits
Manufacturer – Product code
Verifying check sum digit
1. Numbers at Even position are summed to value A
#0+#2+#4+#6+#8+#10 = Value A [7+0+0+4+3+1 = 15 ]
2. Numbers at Odd position are summed and multiplied by 3
3*(#1+#3+#5+#7+#9+#11) = Value B [3* (5+1+5+5+0+0) = 48 ]
3. Value A + Value B = Value C [ 63 ]
4. Remainder of (value C /10) is taken as value D [ 3 ]
5. If check digit = (10 value D), the code read by the machine is correct. [ 7 ]‐
Initial Bit – Part 1 – Part 2
Ever wondered, How are those lines generated?
7 - 501054 - 530107
 Black – 1 and white space – 0
 Borders: 101 (left and right) and Center: 01010 (middle)
7 – ABABAB
<left border> 101
<part generated from A/B> 0110001 0100111 0011001 0100111 0110001 0011101
+<central > 01010
+< part generated from C > 1001110 1000010 1110010 1100110 1110010 1000100
<right border> 101
Fuzzy Buzzy……
Finally…!
101 0110001 0100111 0011001 0100111 0110001
0011101 01010 1001110 1000010 1110010 1100110
1110010 1000100 101
At your own risk…!
Your weapons
Barcode generators
Online : http://www.terryburton.co.uk/barcodewriter/generator/
Offline : ByteScout barcode generator
Barcode decoders
http://www.onlinebarcodereader.com/
http://zxing.org/w/decode.jspx
http://www.onlinebarcodescan.com/
http://online-barcode-reader.inliteresearch.com/
1 – stop point for printers, stickers, labels, scanners etc
http://www.barcodesinc.com/
http://www.3sindustries.in/
XYZ Shopping Mall
Buy a product worth INR Rs 5000/- for INR Rs 1000/-
Demo experience
(Social Engineering*)
Other scenarios
Drink beer at free of cost
Access Control Magic’s
Free Parking
Corporate Asset Management etc
My Journey with “Beeeeeep” – MNC (well known)
Demo Experience
XSS, SQL etc via PAPER…………..!
 QR codes
 Below QR code for <script>alert("test")</script> (Demo)
http://qrcode.kaywa.com/
More demo and in-details in next talk 
Questions????
Resources:
www.barcodeisland.com
http://www.phenoelit-us.org/stuff/StrichAufRechnung.pdf
http://en.wikipedia.org/wiki/International_Article_Number_%28EAN%29
How can you reach me?
https://in.linkedin.com/in/manideepk
mani [ dot ] konakandla [at] gmail [dot] com

More Related Content

Viewers also liked

Función BUSCARV
Función BUSCARVFunción BUSCARV
Función BUSCARV
Francisco Monteverde
 
Nomadic Display Instand Instructions
Nomadic Display Instand InstructionsNomadic Display Instand Instructions
Nomadic Display Instand Instructions
Nomadic Display
 
Xss 101 by-sai-shanthan
Xss 101 by-sai-shanthanXss 101 by-sai-shanthan
Xss 101 by-sai-shanthanRaghunath G
 
Marvella city a complete township in haridwar
Marvella city a complete township in haridwarMarvella city a complete township in haridwar
Marvella city a complete township in haridwar
Marvella city
 
Seh based exploitation
Seh based exploitationSeh based exploitation
Seh based exploitation
Raghunath G
 
So you want to retire in florida 1997 far
So you want to retire in florida 1997 farSo you want to retire in florida 1997 far
So you want to retire in florida 1997 farJames Lavigne
 
Securitynewsbytes april2015-150418153901-conversion-gate01
Securitynewsbytes april2015-150418153901-conversion-gate01Securitynewsbytes april2015-150418153901-conversion-gate01
Securitynewsbytes april2015-150418153901-conversion-gate01Raghunath G
 
Heartbleed by-danish amber
Heartbleed by-danish amberHeartbleed by-danish amber
Heartbleed by-danish amber
Raghunath G
 
Uga Webinar Series: building credibility as a young professional
Uga Webinar Series: building credibility as a young professionalUga Webinar Series: building credibility as a young professional
Uga Webinar Series: building credibility as a young professional
steffan
 
Raspberry pi 2
Raspberry pi 2Raspberry pi 2
Raspberry pi 2
Raghunath G
 
Buying a business in florida
Buying  a business in floridaBuying  a business in florida
Buying a business in floridaJames Lavigne
 
8800117436 Projects in Haridwar in MARVELLA CITY
8800117436 Projects in Haridwar in MARVELLA CITY8800117436 Projects in Haridwar in MARVELLA CITY
8800117436 Projects in Haridwar in MARVELLA CITY
Marvella city
 
The art of_firewalking-by-sujay
The art of_firewalking-by-sujayThe art of_firewalking-by-sujay
The art of_firewalking-by-sujayRaghunath G
 
World Cup! Young Germany Guest Blogging
World Cup! Young Germany Guest BloggingWorld Cup! Young Germany Guest Blogging
World Cup! Young Germany Guest Blogging
steffan
 

Viewers also liked (14)

Función BUSCARV
Función BUSCARVFunción BUSCARV
Función BUSCARV
 
Nomadic Display Instand Instructions
Nomadic Display Instand InstructionsNomadic Display Instand Instructions
Nomadic Display Instand Instructions
 
Xss 101 by-sai-shanthan
Xss 101 by-sai-shanthanXss 101 by-sai-shanthan
Xss 101 by-sai-shanthan
 
Marvella city a complete township in haridwar
Marvella city a complete township in haridwarMarvella city a complete township in haridwar
Marvella city a complete township in haridwar
 
Seh based exploitation
Seh based exploitationSeh based exploitation
Seh based exploitation
 
So you want to retire in florida 1997 far
So you want to retire in florida 1997 farSo you want to retire in florida 1997 far
So you want to retire in florida 1997 far
 
Securitynewsbytes april2015-150418153901-conversion-gate01
Securitynewsbytes april2015-150418153901-conversion-gate01Securitynewsbytes april2015-150418153901-conversion-gate01
Securitynewsbytes april2015-150418153901-conversion-gate01
 
Heartbleed by-danish amber
Heartbleed by-danish amberHeartbleed by-danish amber
Heartbleed by-danish amber
 
Uga Webinar Series: building credibility as a young professional
Uga Webinar Series: building credibility as a young professionalUga Webinar Series: building credibility as a young professional
Uga Webinar Series: building credibility as a young professional
 
Raspberry pi 2
Raspberry pi 2Raspberry pi 2
Raspberry pi 2
 
Buying a business in florida
Buying  a business in floridaBuying  a business in florida
Buying a business in florida
 
8800117436 Projects in Haridwar in MARVELLA CITY
8800117436 Projects in Haridwar in MARVELLA CITY8800117436 Projects in Haridwar in MARVELLA CITY
8800117436 Projects in Haridwar in MARVELLA CITY
 
The art of_firewalking-by-sujay
The art of_firewalking-by-sujayThe art of_firewalking-by-sujay
The art of_firewalking-by-sujay
 
World Cup! Young Germany Guest Blogging
World Cup! Young Germany Guest BloggingWorld Cup! Young Germany Guest Blogging
World Cup! Young Germany Guest Blogging
 

Similar to Null dec 2014

Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
Binary Hash Tree based Certificate Access Management for Connected Vehicles (...Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
OnBoard Security, Inc. - a Qualcomm Company
 
Barcode invention &amp; evolution
Barcode  invention &amp; evolutionBarcode  invention &amp; evolution
Barcode invention &amp; evolution
FACTS Computer Software L.L.C
 
Barcode invention & evolution
Barcode  invention & evolutionBarcode  invention & evolution
Barcode invention & evolution
FACTS Computer Software L.L.C
 
Barcode invention & evolution
Barcode  invention & evolutionBarcode  invention & evolution
Barcode invention & evolution
FACTS Computer Software L.L.C
 
The (Io)Things you don't even need to hack. Should we worry?
The (Io)Things you don't even need to hack. Should we worry?The (Io)Things you don't even need to hack. Should we worry?
The (Io)Things you don't even need to hack. Should we worry?
SecuRing
 
BARCODE TECHNOLOGY
 BARCODE TECHNOLOGY BARCODE TECHNOLOGY
BARCODE TECHNOLOGY
054JaiganeshM
 
Hyperchem Ma, badbarcode en_1109_nocomment-final
Hyperchem Ma, badbarcode en_1109_nocomment-finalHyperchem Ma, badbarcode en_1109_nocomment-final
Hyperchem Ma, badbarcode en_1109_nocomment-final
PacSecJP
 
Just Mouse Jack Init
Just Mouse Jack InitJust Mouse Jack Init
Just Mouse Jack Init
antitree
 
Digipass Instrumentation for Fun and Profit - DefCamp 2012
Digipass Instrumentation for Fun and Profit - DefCamp 2012Digipass Instrumentation for Fun and Profit - DefCamp 2012
Digipass Instrumentation for Fun and Profit - DefCamp 2012DefCamp
 
Cant touch this: cloning any Android HCE contactless card
Cant touch this: cloning any Android HCE contactless cardCant touch this: cloning any Android HCE contactless card
Cant touch this: cloning any Android HCE contactless card
Slawomir Jasek
 
Project_report_on_Attendance_system
 Project_report_on_Attendance_system Project_report_on_Attendance_system
Project_report_on_Attendance_system
Ami Goswami
 
seminar-on-barcodes
seminar-on-barcodesseminar-on-barcodes
seminar-on-barcodes
alibefkani
 
Barcode Decoder
Barcode DecoderBarcode Decoder
Barcode Decoder
ArijitDhali
 
smartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdfsmartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdf
ssuser5b47c8
 
Sprague Ackley, Technologist, Intermec
Sprague Ackley, Technologist, IntermecSprague Ackley, Technologist, Intermec
Sprague Ackley, Technologist, Intermec
MIT Enterprise Forum Cambridge
 
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
Syeduzzaman Sohag
 
How does a barcode scanner work.pdf
How does a barcode scanner work.pdfHow does a barcode scanner work.pdf
How does a barcode scanner work.pdf
Barcode Live
 
GDGPH Hack Fair Presentation
GDGPH Hack Fair PresentationGDGPH Hack Fair Presentation
GDGPH Hack Fair Presentation
Mithi Sevilla
 
Lesson 4 binary numbers
Lesson 4   binary numbersLesson 4   binary numbers
Lesson 4 binary numbers
tmoncrieff
 
Lesson 4 binary numbers
Lesson 4   binary numbersLesson 4   binary numbers
Lesson 4 binary numbers
tmoncrieff
 

Similar to Null dec 2014 (20)

Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
Binary Hash Tree based Certificate Access Management for Connected Vehicles (...Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
Binary Hash Tree based Certificate Access Management for Connected Vehicles (...
 
Barcode invention &amp; evolution
Barcode  invention &amp; evolutionBarcode  invention &amp; evolution
Barcode invention &amp; evolution
 
Barcode invention & evolution
Barcode  invention & evolutionBarcode  invention & evolution
Barcode invention & evolution
 
Barcode invention & evolution
Barcode  invention & evolutionBarcode  invention & evolution
Barcode invention & evolution
 
The (Io)Things you don't even need to hack. Should we worry?
The (Io)Things you don't even need to hack. Should we worry?The (Io)Things you don't even need to hack. Should we worry?
The (Io)Things you don't even need to hack. Should we worry?
 
BARCODE TECHNOLOGY
 BARCODE TECHNOLOGY BARCODE TECHNOLOGY
BARCODE TECHNOLOGY
 
Hyperchem Ma, badbarcode en_1109_nocomment-final
Hyperchem Ma, badbarcode en_1109_nocomment-finalHyperchem Ma, badbarcode en_1109_nocomment-final
Hyperchem Ma, badbarcode en_1109_nocomment-final
 
Just Mouse Jack Init
Just Mouse Jack InitJust Mouse Jack Init
Just Mouse Jack Init
 
Digipass Instrumentation for Fun and Profit - DefCamp 2012
Digipass Instrumentation for Fun and Profit - DefCamp 2012Digipass Instrumentation for Fun and Profit - DefCamp 2012
Digipass Instrumentation for Fun and Profit - DefCamp 2012
 
Cant touch this: cloning any Android HCE contactless card
Cant touch this: cloning any Android HCE contactless cardCant touch this: cloning any Android HCE contactless card
Cant touch this: cloning any Android HCE contactless card
 
Project_report_on_Attendance_system
 Project_report_on_Attendance_system Project_report_on_Attendance_system
Project_report_on_Attendance_system
 
seminar-on-barcodes
seminar-on-barcodesseminar-on-barcodes
seminar-on-barcodes
 
Barcode Decoder
Barcode DecoderBarcode Decoder
Barcode Decoder
 
smartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdfsmartcard-120830090352-phpapp02.pdf
smartcard-120830090352-phpapp02.pdf
 
Sprague Ackley, Technologist, Intermec
Sprague Ackley, Technologist, IntermecSprague Ackley, Technologist, Intermec
Sprague Ackley, Technologist, Intermec
 
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
Building of heart beat rate monitor &amp; object detector by md syeduzzaman s...
 
How does a barcode scanner work.pdf
How does a barcode scanner work.pdfHow does a barcode scanner work.pdf
How does a barcode scanner work.pdf
 
GDGPH Hack Fair Presentation
GDGPH Hack Fair PresentationGDGPH Hack Fair Presentation
GDGPH Hack Fair Presentation
 
Lesson 4 binary numbers
Lesson 4   binary numbersLesson 4   binary numbers
Lesson 4 binary numbers
 
Lesson 4 binary numbers
Lesson 4   binary numbersLesson 4   binary numbers
Lesson 4 binary numbers
 

More from Raghunath G

Whats app forensic
Whats app forensicWhats app forensic
Whats app forensic
Raghunath G
 
Analysis of malicious pdf
Analysis of malicious pdfAnalysis of malicious pdf
Analysis of malicious pdf
Raghunath G
 
Mobile application security 101
Mobile application security 101Mobile application security 101
Mobile application security 101
Raghunath G
 
Security News Bytes
Security News BytesSecurity News Bytes
Security News Bytes
Raghunath G
 
Is iso 27001, an answer to security
Is iso 27001, an answer to securityIs iso 27001, an answer to security
Is iso 27001, an answer to security
Raghunath G
 
Null HYD Playing with shodan null
Null HYD Playing with shodan nullNull HYD Playing with shodan null
Null HYD Playing with shodan null
Raghunath G
 
Null HYD VRTDOS
Null HYD VRTDOSNull HYD VRTDOS
Null HYD VRTDOS
Raghunath G
 
Metasploit
MetasploitMetasploit
Metasploit
Raghunath G
 
Null July - OWTF - Bharadwaj Machiraju
Null July - OWTF - Bharadwaj MachirajuNull July - OWTF - Bharadwaj Machiraju
Null July - OWTF - Bharadwaj Machiraju
Raghunath G
 
Security News Bytes
Security News BytesSecurity News Bytes
Security News Bytes
Raghunath G
 
Decoy documents
Decoy documentsDecoy documents
Decoy documents
Raghunath G
 
Spear phishing attacks-by-hari_krishna
Spear phishing attacks-by-hari_krishnaSpear phishing attacks-by-hari_krishna
Spear phishing attacks-by-hari_krishnaRaghunath G
 
Netcat 101 by-mahesh-beema
Netcat 101 by-mahesh-beemaNetcat 101 by-mahesh-beema
Netcat 101 by-mahesh-beemaRaghunath G
 

More from Raghunath G (13)

Whats app forensic
Whats app forensicWhats app forensic
Whats app forensic
 
Analysis of malicious pdf
Analysis of malicious pdfAnalysis of malicious pdf
Analysis of malicious pdf
 
Mobile application security 101
Mobile application security 101Mobile application security 101
Mobile application security 101
 
Security News Bytes
Security News BytesSecurity News Bytes
Security News Bytes
 
Is iso 27001, an answer to security
Is iso 27001, an answer to securityIs iso 27001, an answer to security
Is iso 27001, an answer to security
 
Null HYD Playing with shodan null
Null HYD Playing with shodan nullNull HYD Playing with shodan null
Null HYD Playing with shodan null
 
Null HYD VRTDOS
Null HYD VRTDOSNull HYD VRTDOS
Null HYD VRTDOS
 
Metasploit
MetasploitMetasploit
Metasploit
 
Null July - OWTF - Bharadwaj Machiraju
Null July - OWTF - Bharadwaj MachirajuNull July - OWTF - Bharadwaj Machiraju
Null July - OWTF - Bharadwaj Machiraju
 
Security News Bytes
Security News BytesSecurity News Bytes
Security News Bytes
 
Decoy documents
Decoy documentsDecoy documents
Decoy documents
 
Spear phishing attacks-by-hari_krishna
Spear phishing attacks-by-hari_krishnaSpear phishing attacks-by-hari_krishna
Spear phishing attacks-by-hari_krishna
 
Netcat 101 by-mahesh-beema
Netcat 101 by-mahesh-beemaNetcat 101 by-mahesh-beema
Netcat 101 by-mahesh-beema
 

Recently uploaded

原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
3ipehhoa
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
3ipehhoa
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
3ipehhoa
 
Multi-cluster Kubernetes Networking- Patterns, Projects and Guidelines
Multi-cluster Kubernetes Networking- Patterns, Projects and GuidelinesMulti-cluster Kubernetes Networking- Patterns, Projects and Guidelines
Multi-cluster Kubernetes Networking- Patterns, Projects and Guidelines
Sanjeev Rampal
 
The+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptxThe+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptx
laozhuseo02
 
BASIC C++ lecture NOTE C++ lecture 3.pptx
BASIC C++ lecture NOTE C++ lecture 3.pptxBASIC C++ lecture NOTE C++ lecture 3.pptx
BASIC C++ lecture NOTE C++ lecture 3.pptx
natyesu
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
ufdana
 
This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
nirahealhty
 
Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
JungkooksNonexistent
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Brad Spiegel Macon GA
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
laozhuseo02
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
eutxy
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
Arif0071
 
Internet-Security-Safeguarding-Your-Digital-World (1).pptx
Internet-Security-Safeguarding-Your-Digital-World (1).pptxInternet-Security-Safeguarding-Your-Digital-World (1).pptx
Internet-Security-Safeguarding-Your-Digital-World (1).pptx
VivekSinghShekhawat2
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
JeyaPerumal1
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
Rogerio Filho
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
GTProductions1
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
Javier Lasa
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
Gal Baras
 

Recently uploaded (20)

原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
 
Multi-cluster Kubernetes Networking- Patterns, Projects and Guidelines
Multi-cluster Kubernetes Networking- Patterns, Projects and GuidelinesMulti-cluster Kubernetes Networking- Patterns, Projects and Guidelines
Multi-cluster Kubernetes Networking- Patterns, Projects and Guidelines
 
The+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptxThe+Prospects+of+E-Commerce+in+China.pptx
The+Prospects+of+E-Commerce+in+China.pptx
 
BASIC C++ lecture NOTE C++ lecture 3.pptx
BASIC C++ lecture NOTE C++ lecture 3.pptxBASIC C++ lecture NOTE C++ lecture 3.pptx
BASIC C++ lecture NOTE C++ lecture 3.pptx
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
 
This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
 
Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
 
Internet-Security-Safeguarding-Your-Digital-World (1).pptx
Internet-Security-Safeguarding-Your-Digital-World (1).pptxInternet-Security-Safeguarding-Your-Digital-World (1).pptx
Internet-Security-Safeguarding-Your-Digital-World (1).pptx
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
 

Null dec 2014

  • 1.
  • 2. Myself – Self Boasting/ Self D**ba  Authored a book at an age of 21 (2nd edition WIP)  ISO 27001:2013 ISMS LA, CEH, CCNA, ECSA , JNCIP- SEC, JNCIS-SEC etc.  Featured in Deccan Chronicle, The Hindu, The HANS India, Eenadu, Vaartha, Saakshi, AndhraJyothi, Andhrabhoomi etc.  Interviewed by HMTV news channel  Reported vulnerabilities on 100+ popular websites and got lucky with more than 2 dozen of CVE-IDs  Reported BOF on Yahoo Messenger  Trained more than 10,000 people (Corporate + Students)  Currently working with TCS as Security Analyst Enough ……….Just Stop it………!
  • 3. Where am I taking you now?  Hell, why do I need to listen to this ?  Introduction to barcodes  Breaking down EAN – 13  Your Weapons  Here comes the “heart” of this power-point deck  My experience with Barcode cracking a) XYZ MNC well-known barcode crack b) XYZ shopping mall etc  Brief Introduction on XSS, SQL etc. attacks via Paper, yeah it’s via PAPER…! or NEWS PAPER…! OMG…!
  • 4. With barcode cracking, you can a) Buy a costly product at the rate of a cheap one b) Free entry to parties – free beers etc c) Free parking d) Bypassing access control - Get free attendance / break your friend’s attendance etc. Disclaimer: I am no way responsible for any mis-use of this technique. I am sharing it just for informational purposes. Why do I need to listen to this ?
  • 5.  Introduced by Joseph Woodland and Bernard Silver in 1952  First used in ACI but failed and then started commercially on Wrigley company - chewing gum  Optical representation of data to uniquely identify items  Used for tickets, market items, books , parcel tracking, parking etc  Barcodes , Scanners / Verifiers  Barcode verifier standards a)  ISO/IEC 15416 (linear)       b)  ISO/IEC 15426-2 (2D) Introduction to Barcodes
  • 6. Classification 1. 1D a) EAN – 13 (World-wide) b) UPC (USA, Canada etc) c) Code 128 d) CodeBar e) Plessey etc 2. 2D (More information) a) QR code b) Maxi code c) Aztec code etc 3. 3D (Basing on height) - To withstand high temperature or chemical environments
  • 7. Slide – Manideep QR code Aztec Code Code 128
  • 8. Why EAN 13? - Everywhere Book Deodorant Shirt
  • 10. Breaking down EAN 13 into pieces Do I need to learn this for doing hacks based on barcode??? - Yes…!
  • 11. Country Code - 1st two/three digits
  • 13.
  • 14. Verifying check sum digit 1. Numbers at Even position are summed to value A #0+#2+#4+#6+#8+#10 = Value A [7+0+0+4+3+1 = 15 ] 2. Numbers at Odd position are summed and multiplied by 3 3*(#1+#3+#5+#7+#9+#11) = Value B [3* (5+1+5+5+0+0) = 48 ] 3. Value A + Value B = Value C [ 63 ] 4. Remainder of (value C /10) is taken as value D [ 3 ] 5. If check digit = (10 value D), the code read by the machine is correct. [ 7 ]‐
  • 15. Initial Bit – Part 1 – Part 2 Ever wondered, How are those lines generated? 7 - 501054 - 530107
  • 16.  Black – 1 and white space – 0  Borders: 101 (left and right) and Center: 01010 (middle) 7 – ABABAB <left border> 101 <part generated from A/B> 0110001 0100111 0011001 0100111 0110001 0011101 +<central > 01010 +< part generated from C > 1001110 1000010 1110010 1100110 1110010 1000100 <right border> 101 Fuzzy Buzzy……
  • 17. Finally…! 101 0110001 0100111 0011001 0100111 0110001 0011101 01010 1001110 1000010 1110010 1100110 1110010 1000100 101
  • 18. At your own risk…!
  • 19. Your weapons Barcode generators Online : http://www.terryburton.co.uk/barcodewriter/generator/ Offline : ByteScout barcode generator Barcode decoders http://www.onlinebarcodereader.com/ http://zxing.org/w/decode.jspx http://www.onlinebarcodescan.com/ http://online-barcode-reader.inliteresearch.com/ 1 – stop point for printers, stickers, labels, scanners etc http://www.barcodesinc.com/ http://www.3sindustries.in/
  • 20. XYZ Shopping Mall Buy a product worth INR Rs 5000/- for INR Rs 1000/- Demo experience (Social Engineering*)
  • 21.
  • 22. Other scenarios Drink beer at free of cost Access Control Magic’s Free Parking Corporate Asset Management etc
  • 23. My Journey with “Beeeeeep” – MNC (well known) Demo Experience
  • 24. XSS, SQL etc via PAPER…………..!  QR codes  Below QR code for <script>alert("test")</script> (Demo) http://qrcode.kaywa.com/ More demo and in-details in next talk 
  • 27. How can you reach me? https://in.linkedin.com/in/manideepk mani [ dot ] konakandla [at] gmail [dot] com