Jump to content

Recommended Posts

Posted

When inserting the device with switch1/2 it executes all commands in the payload file as expected, however windows then opens the folder of the newly inserted drive. Is there a way to surpress this without changing the attackmode?

Posted

Sorry, couldnt find the edit button.

The problem is that when the device-window is opened, the focus is on it, too. so that Quack commands will be executed while having the wrong window focused.

Posted

thanks for the answer, but you cannot be sure whether the user has turned off autorun, so your solution would lead to maybe undesired actions.

Posted

thats a better approach.

it really doesnt matter what i want to do - as soon as i insert the device the actions i want to execute could be compromised by the popping autorun window

Posted

I would think that autorun wouldn't activate until you entered "mass storage" mode.  Could you start your payload in HID keyboard mode, send the commands to edit the registry to turn off autorun, and THEN switch to mass storage mode?

  • Upvote 1
Posted

One solution would be to use HID only in stage 1, then switch from HID to just STORAGE in stage 2.

Not knowing what payload you're referring to I'm not sure exactly what the stager would look like - so if you can provide any insight on that it would be helpful. 

 

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...