Barcode Sensors Can Be Used to Hack Computers
Rick
From Yumite
2015-11-23 12:32:29
As you can see in the image below, the ASCII protocol includes characters for system's combinations keys (e.g. Ctrl). An attacker could use these combinations and open a shell and type commands.
Yu further explained that because most barcode scanners use Advanced Data Formatting (ADF), scanned data can be manipulated by an attacker before the data is transmitted to host device. Moving along, a specified key can also be sent to a computer, for this reason even barcode scanners that don't have a touch interface are vulnerable, Yu writes.
"According to our research, almost all of the keyboard wedge barcode scanners are affected to varying degrees. So, we think this is a big threat," Yu told Gadgets 360 in an emailed statement Tuesday. "BadBarcode is not a vulnerability of a certain product. We even may not make it clear that BadBarcode is the problem of scanners or host systems."
"It affects the entire barcode scanner-related industries. That is why we hope that manufacturers will see our research. In fact, we are pleased to know, there are some manufacturers have begun to consider to solve this problem after they knew BadBarcode."

Yu further explained that because most barcode scanners use Advanced Data Formatting (ADF), scanned data can be manipulated by an attacker before the data is transmitted to host device. Moving along, a specified key can also be sent to a computer, for this reason even barcode scanners that don't have a touch interface are vulnerable, Yu writes.
"According to our research, almost all of the keyboard wedge barcode scanners are affected to varying degrees. So, we think this is a big threat," Yu told Gadgets 360 in an emailed statement Tuesday. "BadBarcode is not a vulnerability of a certain product. We even may not make it clear that BadBarcode is the problem of scanners or host systems."
"It affects the entire barcode scanner-related industries. That is why we hope that manufacturers will see our research. In fact, we are pleased to know, there are some manufacturers have begun to consider to solve this problem after they knew BadBarcode."
