Learn notes---teensy USB HID

Source: Internet
Author: User
Ext.: http://www.tuicool.com/articles/nyY3i2

Kautilya is a toolkit which provides various payloads for a Human Interface Device which could help in breaking in a compute R during penetration tests.

Payloads List

Windows

get the class get information Hashdump and exfiltrate keylogger sniffing WLAN keys export Get destination Certificate export LSA key Dump passwords in plain copy SAM export memory data Dump Win Dows Vault Credentials

perform class sethc and Utilman backdoor timed execution payload Http Backdoor DNS TXT Backdoor wireless AP Tracking Target Connectivity

Upgrade class remove upgrade Force browse

Admin class Add administrator change default DNS server IP edit Hosts file add an available RDP user add an available telnet user add a user who can remote PowerShell

other Browse and accept Java applet signature Speak on Target

Linux Download and Execute Reverse shells using built in tools Code execution DNS TXT Code execution Perl Reverse Shell (MSF)

OSX Download and Execute DNS TXT Code execution Perl Reverse Shell (MSF) Ruby Reverse Shell (MSF)

Usage:

Run kautilya.rb, more Kautilya prompts to select the appropriate menu, and then generate payload to Kautilya directory.

The generated payload needs to be compiled in the Arduino IED and then uploaded to Teensy.

Supported devices (Human Interface Devices)

In principal Kautilya should work with any HID capable of acting as a keyboard. Kautilya have been tested on teensy++2.0 and teensy 3.0 from pjrc.com. Updates about Kautilya can is found most of the Times at my blog http://labofapenetrationtester.com/and Google Group.

Related articles

A Five part blog post on my blog could is useful for those new to HID and Kautilya:

Part 1:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers.html

Part 2:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_04.html

Part 3:http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_25.html

Part 4:http://labofapenetrationtester.blogspot.in/2012/05/teensy-usb-hid-for-penetration-testers.html

Part 5:http://labofapenetrationtester.blogspot.in/2012/09/usb-hid-for-pen-testers-part5.html

All posts related to Kautilya Http://www.labofapenetrationtester.com/search/label/Kautilya

HID (Human Interface Devices) attack is not popular at present, but the attack mode is novel, the practicability is very high, the risk coefficient should still be relatively high, worth studying.

Baidu Disk Download: Http://pan.baidu.com/s/1i3wwfXj

GitHub Download: Https://github.com/samratashok/Kautilya

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.