<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>QR-Code on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/qr-code/</link>
    <description>Recent content in QR-Code on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 19 Dec 2014 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/qr-code/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Getting 20k Inline-QR-Codes out of Burp</title>
      <link>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</link>
      <pubDate>Fri, 19 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</guid>
      <description>&lt;p&gt;Lately we had to analyze QR-Codes in a pentest. Those held some random data which was used as a token for login and we wanted to know if that data was really random.&lt;/p&gt;&#xA;&lt;p&gt;If you ever worked with the Burp Suite you may know the Burp Sequencer, which offers some statistical analysis regarding the randomness of tokens which appear in requests (you just have to tell Burp what or where the token is). In our case the QR-Code was delivered as an inline-image in HTML to the browser, like this:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
