Jump to content

Issue with PID/VID setting (Razer)


GeneralBison
 Share

Recommended Posts

I noticed that MG was able to replicate the RazerInstaller Privesc by setting the OMG cable's VID and PID to emulate a Razer keyboard, I've been trying to do the same rather than lugging my Blackwidow into work to use on a test and it doesn't work, the VID is detected as Razer but the PID seems to be unknown.

I also noticed that the BashBunny is showing as an "RNDIS/Ethernet Gadget" even though I only have HID set in the payload.

Does anyone know how to fix these issues?

KeajOji.png

Link to comment
Share on other sites

Try adding the MAN_ and SN_ parameters to your ATTACKMODE.

You probably also need to add another mode in addition to just HID because simply HID by itself (or any one attack mode for that matter) will enumerate as a single-interface device rather than a multi-interface "composite" device, which is what the target is expecting.

See https://docs.microsoft.com/en-us/windows-hardware/drivers/install/standard-usb-identifiers

 

  • Upvote 1
Link to comment
Share on other sites

On 8/24/2021 at 2:46 PM, GeneralBison said:

the VID is detected as Razer but the PID seems to be unknown

Adding SERIAL to ATTACKMODE seems to have solved some attempts to get this working according to discussions on Discord. Try using the payload that is available on the Hak5 GitHub.

https://github.com/hak5/bashbunny-payloads/tree/master/payloads/library/execution/RazerSystemShell

MG has posted a link on Twitter to a list of about 2500 devices that possibly can be used, extra parameters may be found there

 

Edited by chrizree
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...