Jump to content
Hak5 Forums


  • Content count

  • Joined

  • Last visited

About LGee

  • Rank
  1. misteriously behaving new bunny

    I am using Norwegian keyboard conf. So, that explains the æææ's. But it does not explain why the powershell command shows up when I don't have any powershell commands in my script. Also, I've tried the bunny under linux, and ATTACKMODE seemed to work correctly, whereas when I tried to plug it in under Win7 (tried two different win machines) it always turns up as storage, accessible. No matter what switch position or payload I use.
  2. misteriously behaving new bunny

    sorry for the bad formatting. here it goes: powershell .))gwmi win32?volume +f ælabel\ææBashBunnyæææ=.Name`æpayloads'switch2'd.cmdæ= so, the error is, I am not getting any of the expected behavior per my ducky script above. instead, when I insert the bunny with switch in pos. 1., I only get this powershell-like line in the Run window and an ENTER after. nothing else happens. really cannot see where this line is coming from. not to mention why my actual commands are not executing... BTW, I also struggle with the ATTACKMODE setting. no matter what payload I use, and what ATTACKMODE I configure in payload.txt, I am always getting the bunny mounted as storage, no matter which setting the hardware switch is in. I could not find any forum entry related to that, but please point me to one if this has been observed before.
  3. I have recently started playing around with my new bashbunny, and payloads. Can't figure out what I see when running my first basic payloads on Win7. Take this for example...: Here is a payload I wrote, where I am trying to use ducky script commands and at the same time use the storage on the bunny, e.g. to store stuff on it later while running ducky commands. Here is my payload for switch1: #!/bin/bash # Set LED Red while setting up attack LED R ATTACKMODE HID STORAGE Q DELAY 10000 LED R G Q GUI r Q DELAY 2000 Q STRING cmd Q DELAY 4000 Q ENTER Q DELAY 5000 Q STRING e: Q ENTER Q DELAY 5000 Q STRING dir Q ENTER Q DELAY 2000 # Light turns green - trap is clean. LED R G B And this results in a single command given in GUI+r: powershell .))gwmi win32?volume +f ælabel\ææBashBunnyæææ=.Name`æpayloads'switch2'd.cmdæ= I have flashed the bunny to latest (1.3) firmware. What am I doing wrong? I can't seem to get my new bunny hopping. :(
  4. Some feedback on clomac. This is a really great module I heavily depend on, as in the test environment I have deployed my turtle to, strict port security is used and I can easily get the switch port I am connecting to shut down if something is not right. However, I am not getting the correct MAC cloned from the laptop I am using, which is an HP, with Intel 82577LM Gigabit. So, I am expecting to see an HP MAC on eth1 of the turtle. Instead I am getting a realtek semiconductor MAC. Any ideas how to debug this would be really appreciated. :-)