Exploitation Tools

OhMyQR – Hijack Services That Relies On QR Code Authentication

OhMyQR - Hijack Services That Relies On QR Code Authentication


QRLJacking or Quick Response Code Login Jacking is a simple social engineering attack vector capable of session hijacking affecting all applications that rely on the “Login with QR code” feature as a secure way to login into accounts. In a nutshell, the victim scans the attacker’s QR code which results in session hijacking.


  • Port Forwarding using Ngrok

Legal disclaimer:
Usage of OhMyQR for attacking targets without prior mutual consent is illegal. It’s the end user’s responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program


git clone https://github.com/thelinuxchoice/ohmyqr
cd ohmyqr
bash ohmyqr.sh

Author: https://github.com/thelinuxchoice/ohmyqr
Twitter: https://twitter.com/linux_choice

About the author

Mazen Elzanaty

1 Comment

Click here to post a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: