学习笔记---Teensy USB HID

来源:互联网 发布:淘宝立即购买没反应 编辑:程序博客网 时间:2024/05/16 15:59
转:http://www.tuicool.com/articles/nyY3i2

Kautilya is a toolkit which provides various payloads for a Human Interface Device which may help in breaking in a computer during penetration tests.

Payloads列表

Windows

获取类

  • 获取信息
  • Hashdump and Exfiltrate
  • 键盘记录
  • 嗅探
  • WLAN Keys导出
  • 获取目标证书
  • 导出LSA秘钥
  • Dump passwords in plain
  • 拷贝SAM
  • 导出内存数据
  • Dump Windows Vault Credentials

执行类

  • sethc 和Utilman 后门
  • 定时执行payload
  • Http 后门
  • DNS txt 后门
  • 无线AP
  • Tracking Target Connectivity

升级类

  • 移除升级
  • 强制浏览

管理类

  • 添加管理员
  • 更改默认DNS服务器IP
  • 编辑Hosts 文件
  • 添加一个可用的RDP用户
  • 添加一个可用的Telnet用户
  • 添加一个可以远程powershell的用户

其他

  • 浏览并接受Java Applet签名
  • Speak on Target

Linux

  • Download and Execute
  • Reverse Shells using built in tools
  • Code Execution
  • DNS TXT Code Execution
  • Perl reverse shell (MSF)

OSX

  • Download and Execute
  • DNS TXT Code Execution
  • Perl Reverse Shell (MSF)
  • Ruby Reverse Shell (MSF)

用法:

运行kautilya.rb,更具Kautilya的提示选择相应菜单,然后生成payload到Kautilya的目录。

生成的payload需要在Arduino IED中编译,然后上传到teensy。

支持的设备(Human Interface Devices)

In principal Kautilya should work with any HID capable of acting as a keyboard. Kautilya has been tested on Teensy++2.0 and Teensy 3.0 from pjrc.com. Updates about Kautilya can be found most of the times at my blog http://labofapenetrationtester.com/ and google group.

相关文章

A five part blog post on my blog could be useful for those new to HID and Kautilya:

Part 1: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers.html

Part 2: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_04.html

Part 3: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_25.html

Part 4: http://labofapenetrationtester.blogspot.in/2012/05/teensy-usb-hid-for-penetration-testers.html

Part 5: http://labofapenetrationtester.blogspot.in/2012/09/usb-hid-for-pen-testers-part5.html

All posts related to Kautilya http://www.labofapenetrationtester.com/search/label/Kautilya

HID(Human Interface Devices)攻击当前不流行,但是攻击方式新颖,实用性很高,危险系数应该还是比较高的,值得研究。

百度盘下载: http://pan.baidu.com/s/1i3wwfXj

github下载: https://github.com/samratashok/Kautilya

0 0
原创粉丝点击