Staged and non-staged payloads for the USB Rubber Ducky [PAYLOAD]

Sdílet
Vložit
  • čas přidán 31. 01. 2023
  • In this episode, Darren Kitchen digs into the cApS-Troll payload for the USB Rubber Ducky by Atomiczsec to discuss the workings and best practices of staged and non-staged payloads.
    cApS-Troll by Atomiczsec: hak5.org/blogs/payloads/caps-...
    PayloadStudio: payloadstudio.hak5.org
    Discover Payloads: payloads.hak5.org
    Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    Our Site → www.hak5.org
    Shop → shop.hak5.org
    Discord → / discord
    Subscribe → czcams.com/users/Hak5Darr...
    Support → / threatwire
    Contact Us → / hak5
    -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Věda a technologie

Komentáře • 31

  • @rationalbushcraft
    @rationalbushcraft Před rokem +11

    Great to see you back Darren. I always enjoy your enthusiasm.

  • @prithvirajghorpade5538
    @prithvirajghorpade5538 Před rokem +3

    Thank you sir thanks a lot for your great contribution to the free education content of cyber security I am here with you and gonna watch all your upcoming and recent videos.

  • @CliffordMiller-fu7nu
    @CliffordMiller-fu7nu Před rokem +4

    Finally! Darren is back! What happened to van life?????

  • @georgecole9190
    @georgecole9190 Před 2 měsíci

    How do you stop the payload from continuing tho? how would we stop the caps lock from happening? is there a timer of how long the payload runs before it shuts down or somert?

  • @squiddymute
    @squiddymute Před rokem

    do these work with an older version of rubber ducky ? i bought mine back in 2016

  • @Rob_Turner_UK
    @Rob_Turner_UK Před rokem +3

    Glad to see Darren back, will be a regular viewer again

  • @christopheradrift5058
    @christopheradrift5058 Před rokem +1

    Now what would it take so when the caps lock being pressed it will drop a L

  • @azoicxx
    @azoicxx Před rokem +3

    Very cool payload to troll friends, but then how do you remove it?

  • @AdnanKhan-sc6hh
    @AdnanKhan-sc6hh Před rokem

    Hay Darran, nice to see you back.. I have Question how would one stop this script?

  • @69nunyabidness
    @69nunyabidness Před rokem +2

    This would be a great troll on someone trying to type a password. I know, all of you use Keypass or something similar to aggregate your passwords, but I'm kinda old school.

  • @ElbowNi1
    @ElbowNi1 Před rokem

    All well and good till someone looses an eye! So how does the victim stop it from blinking, is the hidden PS running somewhere visible?

  • @Braddeman
    @Braddeman Před rokem +3

    Not to mention only allowing signed powershell script so it might not run anyway. Might not be able to use a script and use keystroke injections instead is preferred for that reason.

    • @geroffmilan3328
      @geroffmilan3328 Před rokem

      So many ways round script signing & execution policy, yet I see almost as many determined fools on reddit who are certain they're useful defences 😁

    • @Braddeman
      @Braddeman Před rokem

      @@geroffmilan3328 yes you are right but it is called defense in depth. It is one part of the many process that should be implemented and as this current payload stands it will not get around the powershell execution policy. EDR is more than likely going to pick up your techniques anyway. They have gotten pretty good at that.

  • @user-zw8xt5dm8g
    @user-zw8xt5dm8g Před rokem

    What's the name of your book

  • @EyeseeUriP
    @EyeseeUriP Před 9 měsíci

    These things are why I don't trust buying USBs off of Amazon anymore lol.

  • @bnk28zfp
    @bnk28zfp Před rokem

    darren is come back 😮 wow great to see you back!!!!

  • @bestelevated
    @bestelevated Před 5 měsíci

    Any telemetry?

  • @Counterhackingsafe
    @Counterhackingsafe Před rokem +2

    I really like the video, very insightful

  • @geroffmilan3328
    @geroffmilan3328 Před rokem

    I'm not sure why this script persistently creates a New-Object every 2 lines - the one it made first time around hasn't gone anywhere if this is all 1 script or session?

  • @deucekiller022
    @deucekiller022 Před rokem

    Why was he missing from all the other videos

  • @itzusmanidrees5916
    @itzusmanidrees5916 Před rokem +1

    It bypass windows 10 / 11 defender

  • @FutureWarCultist
    @FutureWarCultist Před rokem +4

    His heart is still kickin! 🎉

  • @m.m.m.c.a.k.e
    @m.m.m.c.a.k.e Před rokem

    Lolz

  • @brand_hacker
    @brand_hacker Před rokem +1

    1st

  • @UNcommonSenseAUS
    @UNcommonSenseAUS Před rokem +1

    Bwahaha he believes things go to "space" 🤣🤣

    • @minchy83
      @minchy83 Před rokem

      Well he said Atlas V but showed a picture of a Falcon 9 so we really can’t trust his space expertise 😉.

    • @geroffmilan3328
      @geroffmilan3328 Před rokem

      And what, you believe NASA & the Chinese are *co-operating* to hide the flat earth from us all?
      How's JFK Junior doing, & ya wanna buy this bridge off me? Need a quick sale

  • @WiseguyKevIn2
    @WiseguyKevIn2 Před rokem

    This will be so fun lol 😂