Jump to content

quentin_lamamy

Active Members
  • Posts

    122
  • Joined

  • Last visited

  • Days Won

    2

About quentin_lamamy

  • Birthday 05/09/1990

Profile Information

  • Gender
    Male
  • Location
    France

Recent Profile Visitors

1,315 profile views

quentin_lamamy's Achievements

  1. Description : Exfiltrate github username and email Target : OSX Download : Github
  2. whatever the way, the goal is to trigger payload run after downloading the new one
  3. My bad, typing too fast, and my english not as good as i want ^^ If in command line bb is unmounted and mounted does it trigger the run of the payload like if you unplug the bb and plug it again ?
  4. The best idea i have for you at the moment is to create a generic payload that download from an anonymous link like we transfer or whatever the real payload, store it on the BB storage, open a terminal on the host, unmount the bb and mount it. After your attack use the host terminal to delete your payload. If you set your dl link to one time use there will remain nothing "public" of your malicious payload This idea need to be tested, not sure for the mount unmount @dark_pyrro When unmount -> mount it is the same for the bb than remove it -> plug it in
  5. and if custom protocol don't work, local agent running a web server do the work OR a regular desktop app or shell script
  6. yes Edit: After some check seems possible without server, just register the custom protocol and do thing, will make a test after my work day
  7. Need a local server to make hack5 payload "store" communicate with the bashbuny So that we can have an install button on for example (or in payload studio)
  8. Need a staff info, don't know who know the roadmap More simple, just use arming mode and use the OS mount point to transfer file for ex on osx /Vollumes/Bashbunny
  9. It's a still a need ? Can work on it. My idea is : A node js local agent or a local app (as you want) Add on the website install button that post to an url like bashbunny://payload/install , this king of button could be added to payload studio
  10. Please be respectful, i just mention that your contact information are strange an sounds like a scam. Btw goodbye
  11. Is this a scam ? Phone number (which is a bit weird) and discord (which is not a valid one) are the same
  12. Description : Exfiltrate file or string through discord webhook Download : Github
×
×
  • Create New...