Ext.: http://www.tuicool.com/articles/nyY3i2
Kautilya is a toolkit which provides various payloads for a Human Interface Device which could help in breaking in a compute R during penetration tests.
Payloads List
Windows
get the class get information Hashdump and exfiltrate keylogger sniffing WLAN keys export Get destination Certificate export LSA key Dump passwords in plain copy SAM export memory data Dump Win Dows Vault Credentials
perform class sethc and Utilman backdoor timed execution payload Http Backdoor DNS TXT Backdoor wireless AP Tracking Target Connectivity
Upgrade class remove upgrade Force browse
Admin class Add administrator change default DNS server IP edit Hosts file add an available RDP user add an available telnet user add a user who can remote PowerShell
other Browse and accept Java applet signature Speak on Target
Linux Download and Execute Reverse shells using built in tools Code execution DNS TXT Code execution Perl Reverse Shell (MSF)
OSX Download and Execute DNS TXT Code execution Perl Reverse Shell (MSF) Ruby Reverse Shell (MSF)
Usage:
Run kautilya.rb, more Kautilya prompts to select the appropriate menu, and then generate payload to Kautilya directory.
The generated payload needs to be compiled in the Arduino IED and then uploaded to Teensy.
Supported devices (Human Interface Devices)
In principal Kautilya should work with any HID capable of acting as a keyboard. Kautilya have been tested on teensy++2.0 and teensy 3.0 from pjrc.com. Updates about Kautilya can is found most of the Times at my blog http://labofapenetrationtester.com/and Google Group.
Related articles
A Five part blog post on my blog could is useful for those new to HID and Kautilya:
Part 1:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers.html
Part 2:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_04.html
Part 3:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_25.html
Part 4:http://labofapenetrationtester.blogspot.in/2012/05/teensy-usb-hid-for-penetration-testers.html
Part 5:http://labofapenetrationtester.blogspot.in/2012/09/usb-hid-for-pen-testers-part5.html
All posts related to Kautilya Http://www.labofapenetrationtester.com/search/label/Kautilya
HID (Human Interface Devices) attack is not popular at present, but the attack mode is novel, the practicability is very high, the risk coefficient should still be relatively high, worth studying.
Baidu Disk Download: Http://pan.baidu.com/s/1i3wwfXj
GitHub Download: Https://github.com/samratashok/Kautilya