Learn Polymorphic Powershell Payload Techniques! [PAYLOAD]

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ก.พ. 2023
  • Learn polymorphic PowerShell techniques from this epic payload by 0iphor13 -- a polymorphic TCP Reverse shell executed hidden in the background using the magic of DuckyScript 3
    This Payload: hak5.org/blogs/payloads/rever...
    PayloadStudio: PayloadStudio.Hak5.org
    More Payloads: Payloads.Hak5.org
    Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Our Site → www.hak5.org
    Shop → shop.hak5.org
    Discord → / discord
    Subscribe → th-cam.com/users/Hak5Darr...
    Support → / threatwire
    Contact Us → / hak5
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 42

  • @c0ri
    @c0ri ปีที่แล้ว +7

    nice! BTW.. I typically use nc -lnvp so you can see the first connection without having to hit enter. Give it a go next time.

  • @ramosel
    @ramosel ปีที่แล้ว +1

    You're BACK!!

  • @thestarsahil
    @thestarsahil ปีที่แล้ว +1

    That's nice 🕊️ Something unique

  • @elbowsout6301
    @elbowsout6301 ปีที่แล้ว

    Great stuff!

  • @therealbamtech
    @therealbamtech ปีที่แล้ว +2

    This is epic!

  • @RealCyberCrime
    @RealCyberCrime ปีที่แล้ว +11

    I’m thinking about making a similar video but more documentary style

  • @SourceCodeDeleted
    @SourceCodeDeleted ปีที่แล้ว

    I love this show

  • @tis_is_sparta6559
    @tis_is_sparta6559 ปีที่แล้ว

    Will it work on older rubber ducky?

  • @p.martin9954
    @p.martin9954 ปีที่แล้ว +1

    🔥

  • @leninanciani4375
    @leninanciani4375 ปีที่แล้ว +1

    Are you sure there was an antivirus and windows defender in the target machine?

  • @9595luke
    @9595luke ปีที่แล้ว

    How does it run as an elevated powershell on the victim machine though surly they would get a UAC prompt if they wasn’t local admin..

  • @numoru
    @numoru ปีที่แล้ว

    Gorgeous

  • @bushmaster101
    @bushmaster101 ปีที่แล้ว

    so can i just download it and save on my usb ?

  • @rlpetty13
    @rlpetty13 ปีที่แล้ว

    Neat!

  • @taiquangong9912
    @taiquangong9912 ปีที่แล้ว +2

    Nice. So can the old rubber ducky input PowerShell commands?

    • @lordhelix1458
      @lordhelix1458 ปีที่แล้ว +1

      Yes

    • @taiquangong9912
      @taiquangong9912 ปีที่แล้ว

      @@lordhelix1458 Thank you, I will play with it and figure out things

  • @ronratliff8320
    @ronratliff8320 ปีที่แล้ว +1

    Hey there ! Where can we get those sweet bash bunny and ducky canvas's in the background. I am confident I am not the only one who wants one.

    • @statistical-anomaly
      @statistical-anomaly ปีที่แล้ว

      Lmao I was thinking the same thing as soon as I saw them!

  • @r3d53v3n
    @r3d53v3n ปีที่แล้ว +1

    I have the Payload Studio Pro but don't see version 1.3.0 only 1.2.2. Does this update automatically or do I need to enter a beta channel. Can't find any options for a beta channel

    • @hak5
      @hak5  ปีที่แล้ว

      PayloadStusio updates automatically; 1.3 is currently in beta which you can find here beta.payloadstudio.hak5.org

    • @idontwantahandle231
      @idontwantahandle231 ปีที่แล้ว

      I was wondering the same. I can get the payload to run successfully but my lister wont connect, I was wondering if the 1.2.2 had anything to with it 🤷🏻‍♂️

    • @r3d53v3n
      @r3d53v3n ปีที่แล้ว

      @@hak5 Thank you! Much appreciated

  • @kamikaze_sno
    @kamikaze_sno ปีที่แล้ว

    nice

  • @Canadian789119
    @Canadian789119 ปีที่แล้ว

    Capslock & capslock
    :)

  • @SupermotoZach
    @SupermotoZach ปีที่แล้ว +1

    Anyone know why HAK5 don't do the old around the table studio style eps anymore ? I miss that format.

  • @leninanciani4375
    @leninanciani4375 ปีที่แล้ว +1

    And what about a firewall and rules for outside connections, ain’t it better to set 80 port for the connection?

    • @statistical-anomaly
      @statistical-anomaly ปีที่แล้ว

      In practice yes, but for the purposes of the video it wasn't necessary (and frankly unless someone's a script kiddy then they'll know to change the port to something innocuous like you suggested.)

  • @MiguelGomez-qx7qc
    @MiguelGomez-qx7qc ปีที่แล้ว +1

    can you have persistence with this payload?

    • @statistical-anomaly
      @statistical-anomaly ปีที่แล้ว

      I imagine if it were to create a .bin as a startup process it could maintain persistence (anyone with more knowledge feel free to correct me if I'm wrong.)

  • @fiftyshades1413
    @fiftyshades1413 ปีที่แล้ว

    1 wat is rubber ducky?
    2 wat is payload n how to use?
    3 to learn code wat r the basic characters to start with...?
    4.How to get any wifi password?
    5 wat is Kali Linux on how to use it?

  • @cleightthejw2202
    @cleightthejw2202 ปีที่แล้ว

    @Hak5
    What happened to Cody and the other gentleman's live show? I haven't seen them in a while now, a couple months I believe.

  • @userou-ig1ze
    @userou-ig1ze ปีที่แล้ว

    blueteam is like ... time for some regex

  • @ip7427
    @ip7427 ปีที่แล้ว

    memory for holding random variables is too small :( anything more elaborate and it stops working at some point as no more randoms are generated/stored

  • @Pronobozo
    @Pronobozo ปีที่แล้ว

    please be responsible when using.

  • @az.tek.00
    @az.tek.00 ปีที่แล้ว

    Love seeing D.K. - FKN 1337.
    💜☮💙🌐💚👽💛😎🧡🏴‍☠️❤💯

  • @ac9206
    @ac9206 ปีที่แล้ว +3

    That is some terrible "polymorphism" (too easily detected/blocked)

  • @UNcommonSenseAUS
    @UNcommonSenseAUS ปีที่แล้ว

    Roflmao