24C3 Toying with barcodes
posted Dec 30th 2007 12:31pm by Eliot Phillipsfiled under: laser hacks
[FX] from Phenoelit gave an entertaining talk about barcode security. He covered both how the systems are implemented and how they’ve been exploited. The first example was a parking garage in Dresden that issues non unique barcodes for the unlimited passes that hotels give out. Anyone code print out an image of that particular code and park for free. German grocery stores have automated machines that refund you for your empty beer bottles. The barcode generated just states the refund amount (5 digits) that you’ll get at the register. Just stick the barcode under something like a six pack and it’ll scan even without the cashier seeing it.
Check out the video to find out more silliness involving DVD rentals, boarding passes, asset management, and SQL injection via the scanner. You can even find higher res versions in the 24C3 media archives.





cool article… :)
i would have thought that such a widely used system would have been more secure tbh :)
even the magnetic bar-codes used in some clothing stores (the ones that set the alarms off at the door) can be rendered useless by rubbing the front onto a hard surface.
not as advance but along the same lines :)
Posted at 1:11 pm on Dec 30th, 2007 by jojmoj