2

I have been thinking about security concerns in regards to OCR programs such as Tesseract.

My theory is that malicious code printed out in plain text can be photographed and saved an image file. ( This leaves the hex and headers free from a year change )

Then using OCR the JPEG could be converted to greyscale and the characters then read and executed. Perhaps via an exploit within the OCR application.

Looking back at the way certain worms could self execute in windows via preview perhaps something similar can be done using the abike method.

I imagine it's one of the key security concerns for a company developing an OCR application so this may be very hard to provide a proof of concept.

If anyone would like to explore this concept or perhaps explain why it's is, or indeed is not possible I would appreciate it.

This is my first post so sorry if any forum rules have been missed.

0 Answers0