Joe2525 Posted August 4, 2018 Share Posted August 4, 2018 I'm looking forward to buy the bash bunny but i have a question can i use it to get reverse shell on locked windows pc an android phone? Link to comment Share on other sites More sharing options...
theUNK0WN Posted August 4, 2018 Share Posted August 4, 2018 In my experience with my BB, no. The machine has to be in an 'unlocked' state unless you brute force the password. Link to comment Share on other sites More sharing options...
Joe2525 Posted August 4, 2018 Author Share Posted August 4, 2018 3 hours ago, _0NiTy said: In my experience with my BB, no. The machine has to be in an 'unlocked' state unless you brute force the password. Brute force won't work in my case and the rubber ducky can do it Link to comment Share on other sites More sharing options...
b0N3z Posted August 4, 2018 Share Posted August 4, 2018 if the rubber ducky can do it, so can the bunny. The bunny has functionality of the ducky, but is a bit slower because your powering on a linux OS vs just a microprocessor that runs instantly Link to comment Share on other sites More sharing options...
Joe2525 Posted August 5, 2018 Author Share Posted August 5, 2018 5 hours ago, b0N3z said: if the rubber ducky can do it, so can the bunny. The bunny has functionality of the ducky, but is a bit slower because your powering on a linux OS vs just a microprocessor that runs instantly I have the rubber ducky and as far as i know it can not do it.. It acts like a keyboard and i don't think i can hack an android phone with only a keyboard. That what takes me to the bash bunny it can do more than only being a keyboard so my question is : is the bash bunny with everything it can do, can it be used to hack a locked Android phone ? Link to comment Share on other sites More sharing options...
MB60893 Posted August 5, 2018 Share Posted August 5, 2018 The idea is that a locked PC can't have data exfiltrated from it, without having some method of transmitting/receiving data from behind the scenes (see Mubix example for snagging creds from a locked machine.) For a reverse-shell to be started, you need to actually be able to copy the file to the computer and execute it, meaning that you would have to have access to the machine through a graphical user interface of command line to copy the file and execute it. The best way of knowing whether the Bash Bunny can do something is to look at other people's examples, or try things out on a computer beforehand by typing everything on the keyboard yourself. This will give you an indication as to what is possible, and what is not. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.