Thanks! URL to script is wrong in first post, you typo'd it with wificreds instead of chromecreds.

Question, can you please make a version that stores the powershell script locally for extraction on devices that are offline at the time of capture? Cheers!

unsure if this is working for me. the script opens a powershell window, which stays open and reads;


Windows PowerShell
Copyright (C) 2016 Microsoft Corporation. All rights reserved.

PS C:\Users\RoM> $Bunny = (gwmi win32_volume -f 'label=''BashBunny''' | Select-Object -ExpandProperty DriveLetter)
PS C:\Users\RoM>
PS C:\Users\RoM>

and then the bunny blinks purple endlessly. is this a bug when there is no saved passwords in chrome or a syntax error in the script?

Good stuff!

Suggestion, throw in RNDIS_ETHERNET as well, spin up a simple python web server `python -m SimpleHTTPServer 80` on the BB and serve the powershell via the bunny instead of the internet. Self-contained, more easily updated.

Then you can use the payload for many other purposes with ease.

my many creds payloads are not working! for instance when i plug the bash bunny, for  browser creds it shows green light and then red light starts blinking, also it make a folder in loot but there is nothing inside it. i tries quick creds and mr.robot also nothing is working please help!

