Staged and non-staged payloads for the USB Rubber Ducky [PAYLOAD]

แชร์
ฝัง
  • เผยแพร่เมื่อ 31 ม.ค. 2023
  • In this episode, Darren Kitchen digs into the cApS-Troll payload for the USB Rubber Ducky by Atomiczsec to discuss the workings and best practices of staged and non-staged payloads.
    cApS-Troll by Atomiczsec: hak5.org/blogs/payloads/caps-...
    PayloadStudio: payloadstudio.hak5.org
    Discover Payloads: payloads.hak5.org
    Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Our Site → www.hak5.org
    Shop → shop.hak5.org
    Discord → / discord
    Subscribe → th-cam.com/users/Hak5Darr...
    Support → / threatwire
    Contact Us → / hak5
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 31

  • @rationalbushcraft
    @rationalbushcraft ปีที่แล้ว +11

    Great to see you back Darren. I always enjoy your enthusiasm.

  • @georgecole9190
    @georgecole9190 หลายเดือนก่อน

    How do you stop the payload from continuing tho? how would we stop the caps lock from happening? is there a timer of how long the payload runs before it shuts down or somert?

  • @squiddymute
    @squiddymute ปีที่แล้ว

    do these work with an older version of rubber ducky ? i bought mine back in 2016

  • @prithvirajghorpade5538
    @prithvirajghorpade5538 ปีที่แล้ว +3

    Thank you sir thanks a lot for your great contribution to the free education content of cyber security I am here with you and gonna watch all your upcoming and recent videos.

  • @CliffordMiller-fu7nu
    @CliffordMiller-fu7nu ปีที่แล้ว +4

    Finally! Darren is back! What happened to van life?????

  • @azoicxx
    @azoicxx ปีที่แล้ว +3

    Very cool payload to troll friends, but then how do you remove it?

  • @Rob_Turner_UK
    @Rob_Turner_UK ปีที่แล้ว +3

    Glad to see Darren back, will be a regular viewer again

  • @ElbowNi1
    @ElbowNi1 ปีที่แล้ว

    All well and good till someone looses an eye! So how does the victim stop it from blinking, is the hidden PS running somewhere visible?

  • @christopheradrift5058
    @christopheradrift5058 ปีที่แล้ว +1

    Now what would it take so when the caps lock being pressed it will drop a L

  • @user-zw8xt5dm8g
    @user-zw8xt5dm8g ปีที่แล้ว

    What's the name of your book

  • @AdnanKhan-sc6hh
    @AdnanKhan-sc6hh 11 หลายเดือนก่อน

    Hay Darran, nice to see you back.. I have Question how would one stop this script?

    • @RDog1732
      @RDog1732 7 หลายเดือนก่อน

      idk

  • @69nunyabidness
    @69nunyabidness ปีที่แล้ว +2

    This would be a great troll on someone trying to type a password. I know, all of you use Keypass or something similar to aggregate your passwords, but I'm kinda old school.

  • @Braddeman
    @Braddeman ปีที่แล้ว +3

    Not to mention only allowing signed powershell script so it might not run anyway. Might not be able to use a script and use keystroke injections instead is preferred for that reason.

    • @geroffmilan3328
      @geroffmilan3328 ปีที่แล้ว

      So many ways round script signing & execution policy, yet I see almost as many determined fools on reddit who are certain they're useful defences 😁

    • @Braddeman
      @Braddeman ปีที่แล้ว

      @@geroffmilan3328 yes you are right but it is called defense in depth. It is one part of the many process that should be implemented and as this current payload stands it will not get around the powershell execution policy. EDR is more than likely going to pick up your techniques anyway. They have gotten pretty good at that.

  • @geroffmilan3328
    @geroffmilan3328 ปีที่แล้ว

    I'm not sure why this script persistently creates a New-Object every 2 lines - the one it made first time around hasn't gone anywhere if this is all 1 script or session?

  • @Counterhackingsafe
    @Counterhackingsafe ปีที่แล้ว +2

    I really like the video, very insightful

  • @YahIsLife90
    @YahIsLife90 8 หลายเดือนก่อน

    These things are why I don't trust buying USBs off of Amazon anymore lol.

  • @bestelevated
    @bestelevated 4 หลายเดือนก่อน

    Any telemetry?

  • @bnk28zfp
    @bnk28zfp ปีที่แล้ว

    darren is come back 😮 wow great to see you back!!!!

  • @deucekiller022
    @deucekiller022 ปีที่แล้ว

    Why was he missing from all the other videos

  • @itzusmanidrees5916
    @itzusmanidrees5916 ปีที่แล้ว +1

    It bypass windows 10 / 11 defender

  • @m.m.m.c.a.k.e
    @m.m.m.c.a.k.e ปีที่แล้ว

    Lolz

  • @brand_hacker
    @brand_hacker ปีที่แล้ว +1

    1st

  • @FutureWarCultist
    @FutureWarCultist ปีที่แล้ว +4

    His heart is still kickin! 🎉

  • @UNcommonSenseAUS
    @UNcommonSenseAUS ปีที่แล้ว +1

    Bwahaha he believes things go to "space" 🤣🤣

    • @minchy83
      @minchy83 ปีที่แล้ว

      Well he said Atlas V but showed a picture of a Falcon 9 so we really can’t trust his space expertise 😉.

    • @geroffmilan3328
      @geroffmilan3328 ปีที่แล้ว

      And what, you believe NASA & the Chinese are *co-operating* to hide the flat earth from us all?
      How's JFK Junior doing, & ya wanna buy this bridge off me? Need a quick sale

  • @WiseguyKevIn2
    @WiseguyKevIn2 ปีที่แล้ว

    This will be so fun lol 😂