Bash Bunny is a simple and powerful multi-function USB attack device and automation platform for all pentesters and sysadmins, designed by Hak5, which allows you to easily perform multiple USB (badUSB) based attacks.. It's a tiny and portable Debian based linux computer with a USB interface designed specifically to execute payloads when plugged into a target computer. You can find all my Bash Bunny payloads on GitHub.

Fill in your details below or click an icon to log in: You are commenting using your account.

Getting started is easy with a huge library of payloads that blend the power of Bash with the simplicity of Ducky Script. It's cross-platform USB flash which is small, portable and most importantly powerful Linux computer with a USB interface. The possibilities are limitless.

Bash Bunny Payload: Garfield steals passwords with LaZagne The Bash Bunny is a USB attack platform developed by Hak5 a security research group.

It doesn't enable attackers to do anything they can't already do, but it puts the whole deal in a small, stealthy form factor.

It's an exciting and fun tool for any pentester, hacker and security professional, but we must say that it's a bit expensive ($100). If you want to get in touch with me please feel free to use the comments, Twitter or my contact form. Staying up to date with all of the latest attacks is just a matter of downloading files from git.

Start by downloading the Bash Bunny updater for your host OS – Windows 32/64, Linux 32/64 and Mac versions are available. Even drop into a root shell on this fully equipped quad-core Linux box.

Payloads from this repository are contributed from the Bash Bunny community.

WARNING: Community payloads come with absolutely no warranty.

Then I ran a bunch of more advanced scripts, each attempting to harvest credentials from the local computer, browser, or Wi-Fi connection.

I began by modifying a simple script that would start notepad.exe and type in text. Mimic trusted devices like keyboards, serial, storage, and Ethernet for multi-vector attacks.

Bush Bunny can be used to preform attacks on the following operating systems: This amazing, small and powerful device can run anything that a normal Debian-based linux machines can (linux commands, custom payloads, python scripts, etc.).

Seriously, that simple.

An attacker could even modify Bash Bunny to offer the typical USB storage media view in Windows Explorer, enabling malicious scripts to execute while an unwitting victim thinks it's a normal USB drive.

For more information I wrote a Bash Bunny Primer article here. Avoiding the snags and snares in data breach reporting: What CISOs need to know, Zix wins 5-vendor email encryption shootout, 7 Wi-Fi vulnerabilities beyond weak passwords, Sponsored item title goes here as designed, How to get your infrastructure in shape to shake off scriptable attacks, Best new Windows 10 security features: Biometric authentication, Edge browser, The 10 Windows group policy settings you need to get right, How to rob a bank: A social engineering walkthrough, 10 common cloud security mistakes that put your data at risk, 12 cheap or free cybersecurity training resources, 11 types of hackers and how they will harm you, Securing Microsoft Teams: The options are limited, What is security's role in digital transformation?/a>, The 10 most powerful cybersecurity companies, Keyboard man-in-the-middle intercept devices. Slide the device switch to "arming mode".

This network of two (the Bash Bunny and your target) provides direct access to the target – bypassing any would-be firewalls, countermeasures or intrusion detection systems from the legitimate LAN. Bash Bunny Payload: Garfield steals passwords with LaZagne, Elevating Permissions To Disable Windows Defender. Below, I walk through the payload and explain my process.

Bash Bunny, Hacking, Research, Walkthrough, Bash Bunny, Cyber Security, Duckyscript, Hacking, Hak5, Penetration Testing, PowerShell, Security Research, Windows 10.

Want to mimic a HID keyboard and USB Ethernet adapter? Copy the firmware upgrade file downloaded in step 1 to the root of the Bash Bunny flash drive.

