The USB Rubber Ducky

preview_player
Показать описание
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
____________________________________________
Since 2010 the USB Rubber Ducky has been a favorite among hackers, penetration testers and IT professionals. With origins as a humble IT automation proof-of-concept using an embedded dev-board, it has grown into a full fledged commercial Keystroke Injection Attack Platform. The USB Rubber Ducky captured the imagination of hackers with its simple scripting language, formidable hardware, and covert design.

-~-~~-~~~-~~-~-
Please watch: "Bash Bunny Primer - Hak5 2225"
-~-~~-~~~-~~-~-
____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Рекомендации по теме
Комментарии
Автор

"Keystroke injection within only seconds of physical access and full penetration"
 I'm sold.

DavidOkeif
Автор

0:03 Isaac Asimov's Three Laws of Robotics :D

jonathaniel
Автор

Is there any way to save word documents onto the rubber ducky and open them when the USB ports access is blocked?

raylenialittlecrow
Автор

hey all, i have a question: is the ducky able to store the logged information about username and password on his local sd card (to watch the information later on my second machine) or has it to send the data to an external server (like teensy does). ? I hope you know what i mean :D

ColeTurner
Автор

So, is there a reason why it's so expensive? I'd like to know the process of creating one of these

Ausar
Автор

Does this still work on Windows 7?
Edit : Will the Payload be executed correctly, if the User on the PC is a limited User (not Administrator) ??

CoolPikachu
Автор

Very nice presentation video. Have had fun some time with my malicious animal of the Avian variety.

AndreiAldea
Автор

How come it says it was uploaded 6 hours ago yet there is a comment from 11 months ago ?

stevolution
Автор

does it work for andriod mobile 4digit unlock? its not avaliable in australia any one helpe me to get it

manilara
Автор

Can you write a script that enables developer options and Android debug bridge by sending a command similar to the payload script you use to install the apk when performing a blueducky attack?

Shdwbrkr-fkvx
Автор

just wondering if you have a USB gadget that can plug into a laptop  and another  gadget that can plug directly into a cellphone that immediately copies everything from the cellphone or laptop onto the USB  ?     Sort of thing that would be on an episode of 24. (would also be nice if if could automatically sort the data out (eg GPS locational data, files recently accessed, pdf file names etc).

JN
Автор

16 comments,   71222 views  yeah right in 6 hrs

stevolution
Автор

If it's so dangerous, why is it even sold ?

coopaing
Автор

I need to compile a duckyscript txt file that I wrote originally for my USB Rubber Ducky.
But now I need to find a way to run the script as an exe file locally.



¿How can I make this posible? ¿How can I compile the script to an exe file?

valentinnavarro
Автор

Hello, I would like to buy,
But, can ship to Peru?

distroyedtna
Автор

It is a macro system built into a USB flash size drive.    Why is this such a big deal sorry?
 
Thank you

OxAO
Автор

Two Questions.
1. Will this work on Mac
2. Is this basically a Key Logger?

ArmorUpOfficial
Автор

I dont really see the point of this. May work with some crappy android phone I guess. Any modern android or iphone wont allow this. Any computer your not logged into wont allow this and I believe most will lock you out if you guess the wrong password too many times. I suppose if your logged in it could type something, but it probably wont be able to give you SU unless you already have a 0 day in the OS. If anyone has a good password even if this thing could do a dictionary attack it would probably fail. I suppose it could install a RAT or Virus if you already have access to a system but even then unless its linux or something the AV would probably see it. If you plug it into a server it likely wouldnt be able to login. In order to get data it would need to be logged in. This could be a useful tool but idk if it really can do that much...

zfer