OWASP / QRLJacking

QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.
GNU General Public License v3.0
1.35k stars 615 forks source link

QR code is not generating #184

Open pandu455 opened 2 years ago

pandu455 commented 2 years ago

QR code is not generating after the page launch

Zehir568 commented 2 years ago

same...

ifood318 commented 1 year ago

same

princekrvert commented 1 year ago

any solution??

coeurgrand commented 1 year ago

QRLJacker: whatsapp Now you have a local webserver hosting your QRLJacking payload, Here's some instructions to be done:

  1. This is your always updated whatsapp QR Code Scan me!
  2. Edit phishing_page.html file by adding your phishing page source code, style, resources, etc.. (located inside framework in path core/templates/phishing_page.html)
  3. Point your victim to your phishing URL, Convince to scan the QR code and Bob is your uncle!