OWASP / QRLJacking

QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.
GNU General Public License v3.0
1.37k stars 618 forks source link

Not session after scan QR #245

Open bmstu-stas opened 2 months ago

bmstu-stas commented 2 months ago

Hi, all! May be you help me, pls.

I install step by step this framework. So ok, but only i scan qr on page QRLJacking, i see session in my WhatsApp, but in QRLJacking in terminal write: "No captured sessions" (if i write comand "sessions"). But in WhatsApp session i see that its active and last time it.

Whats problem?

Big thx!

levo-777 commented 1 week ago

I made a similar tool can you try it out and give me feedback please

https://github.com/levo-777/whats_app_qr_code_phisher