Jump to content

Bricked?


mELLoMaN
 Share

Recommended Posts

Did some testing with the OooohThatsHandy payload which worked fine, but had some issues. Installed the right language, got some loot and so on. Then installed some tools from the forum (impacket, gohttp, etc.). Then I tried to delete the loot from the usb drive but one file I couldn't delete. Using the serial console I tried to locate that file, but it wasn't there...

So I went on and modified the script and did a new run, but now it didn't work anymore. All the periods were gone during execution, some "GUI r" line got split apart during execution, as if the keyboard was wrong, but the rest was ok, it isn't a locale problem. Then I factory reset the bunny, but after that all the files were still on it and it wasn't reset at all...

 

So now my question, did I already brick it the first day?? It is running FW 1.7

Thanks

Link to comment
Share on other sites

Just because the files on the storage part (that gets mounted to the target in arming mode) is still there, doesn't mean that the factory reset was unsuccessful. The udisk (the part that gets mounted to the target in arming mode) is left untouched on a reset. For how long did it flash red/blue during the reset process? For minutes or just some seconds?

Link to comment
Share on other sites

I don't think any of those tools available should affect the Bunny typing things. Did you install the tools after the factory reset or just before the reset? What OS does the target have? Have you tried several different target computers? Are you using internal storage or a Micro SD card? You could try to format the internal udisk storage if you have files that you can't seem to be able to remove. Use the "udisk reformat" command to start from scratch when it comes to the udisk.

Link to comment
Share on other sites

I did some testing where it worked, then installed the tools and tested another payload. Thats when it stopped working. Then I did the reset and it still doesn't work. The targets are Windows 10, and both aren't working. I'm using the internal storage. I'll try the reformat, maybe it helps...

Thanks

Link to comment
Share on other sites

can't I delete or edit posts?
It also doesn't work on the workstation, but the output is different...

 

Quote

powershell -W Hidden bel=''BashBunny'''").Name); robocopy $en /W:1 /R:1 /NP /MT /XDDATA" "$env:USERPROFILE\AppData"


powershell -W Hiddlabel=''BashBOOK $destination\loot\copy $env:TEMP\LOOK $destination\loot\


powershell -W Hidden -c \$out-File $env:TEMP\LOOK\CheckForUnquoted.txt $env:TEMP\LOOK\CheckForUnquoted.txt


cmd /minimized /DNSCache.txt & dsregcmd /status > re >EMTEMP%\LOOK\Shares.txt net share > %TEMP%\LOOK\Shares.txt net share > %TEMP%\LOOK\Shares.txt


cmd /minimized /c mkdiile * key=clear > %T5TMP%p%\LOOK\UserGroupsPrivs.txt > %TEMP%\LOOK\UserGroupsPrivs.txt

That's from the workstation...

> re >EMTEMP%\LOOK\
> %T5TMP%p%\LOOK\
> %TEMP%\LOOK\

Link to comment
Share on other sites

I think you have made too few posts yet to be able to edit or delete. If I remember it correctly you need to make 5-6 posts before you can start uploading pictures, edit and such.

OK, I've seen similar but only on Windows 11 (and sometimes on Ubuntu). I.e. that it messes up the chars entered by the Bunny (or leave some out).

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...