Comments (1)
@jonas18z Thanks for your request,
this idea makes sense for payloads which run longterm attacks. Or it would maybe make sense to design a payload, allowing to do the basic setup from a web interface (only on Pi Zero W, if not connected in device mode).
If you have the backdoor payload in mind, SSH won't be replaced for the following reasons:
- flexibility (one could dettach the backdoor server screen and get a shell to the raspbian instantly)
- extensibility: SSH allows to tunnel TCP sockets. As soon as the HID channel got socket tunneling implemented, this could be used to relax SSH based sockets through the target (pivoting)
- usability: beside nice things, like auto completion a console allows all the things I haven't got in mind during development, while a webinterface only allows to do the things the developer had in mind
- a web interface runs in "request & response" style, due to the nature of HTTP. Getting output of remote processes to the screen (which is more push like) would become hard. On a web interface this means polling or choosing more complex techniques (f.e. AJAX)
Additionally, the backdoor shell could be bound to a PTY an made available via bluetooth serial connection
So there are a few reasons not to change the backdoor servers interface.
I leave it up to the community to develop payloads with web frontend.
from p4wnp1.
Related Issues (20)
- HIDscript keyboard outputs (volume keys)
- Mass storage Image? HOT 4
- FireStage1 and errors
- Where is the Code for the Web Interface? HOT 2
- [FIX] Office Opens [FIX] HOT 20
- Not very covert HOT 1
- error: (4, 'Interrupted system call')
- Inpossible to create or use default Mass Storage HOT 3
- No sessions when trying to gain shell access HOT 2
- I cant use special characters in hid scrip, how can I? HOT 3
- HIDscript directory location HOT 1
- Windows Key remains active after GUI command HOT 1
- Print Spooler LPE Possible? HOT 1
- unable to ssh
- microsoft office opening
- Does this work on Banana Pi HOT 2
- raspbery pi 2 w HOT 1
- is Rasbian STRETCH required or can I use the latest rasbian Image? HOT 1
- How to encrypt the FireStage1 file and where is it? HOT 1
- i want to help
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from p4wnp1.