Jump to content
qdba

[PAYLOAD] DrumpCreds 2.0 ( SMB, w/o Internet, w/o USB Storage )

Recommended Posts

4 hours ago, qdba said:

OK helps a lot. So the handshake Ting works fine.

Now the error message would be helpfull. On very fast fanishing error messages I do a trick. I make a video with the smartphone and forward slow manually until the error messages is seen.  

Just modify the script so have verbose or debug option and then have it fire off with debug switch.  For part that may have errors I usually wrap it in a try  on catch I log it to a local file if debug flag is used.  Helps during testing.  Better yet, do not run the script hidden. go to cmd, run his stager without the windowstyle option.  Or launch powershell and take the code after the -C in his powershell command and run it straight.  You should then have the PS session still open to scroll back through the errors.

 

Share this post


Link to post
Share on other sites

DumpCreds_2.1 New Version

Changelog

  • Complete new payload.txt code for BashBunny 1.1
  • Added a lot of debug code into the payload
    For Debugging create a File "DEBUG" to payload Folder. You got the debug log in \loot\Dumpcreds_2.1
  • Impacket.deb included for easy impacket installation
  • Some Ducky languages included (from DuckyInstall Payload)

 

Share this post


Link to post
Share on other sites

As I'm having a problem with this payload (slowly blinking in red), I'd love to see the debug-output, however I cannot seem to make the debugging work. I created an ampty text file called "DEBUG" in the switchfolder, without any results. Any suggestion? Thanks!

Share this post


Link to post
Share on other sites

I've been using 2.1. Just gave 2.3 a go, ended up with the same red-blinking LED (about once a second). Great enhancements in 2.2 though.

Share this post


Link to post
Share on other sites

Okay, been entering the critical part manually, logged into the bunny. Accepting all commands, except the required GET. get.sh resides in /payloads/extensions on my bunny (1.3).

Share this post


Link to post
Share on other sites
On 15.9.2017 at 3:10 PM, Alim said:

Dude, 

This is Beta, you reference to an Fodhelper.exe in the system32?
That is not an default app.

Cheers

It's for Windows 10 only

 

Share this post


Link to post
Share on other sites
On 9/21/2017 at 4:28 PM, qdba said:

It's for Windows 10 only

 

I know, and this executable is not available in my Win10 (Enterprise) 10.0.15063

Share this post


Link to post
Share on other sites
8 hours ago, Alim said:

I know, and this executable is not available in my Win10 (Enterprise) 10.0.15063

New Version added You can set UAC_MODE=0 in payload.txt

Share this post


Link to post
Share on other sites

Please go the right forum........ :cool:

 

 

Share this post


Link to post
Share on other sites
8 hours ago, qdba said:

Please go the right forum........ :cool:

 

 

Can you please not create a forum post for every version? Just set it all out on one of them with the downloads section having multiple links and a changelog.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...