Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FIX] Office Opens [FIX] #337

Open
DonaldDucker34 opened this issue Apr 18, 2020 · 20 comments
Open

[FIX] Office Opens [FIX] #337

DonaldDucker34 opened this issue Apr 18, 2020 · 20 comments

Comments

@DonaldDucker34
Copy link

when i enter firestage 1 on my pc office opens. So i thought why dont edit the firestage1 command but i dont know how or is there an fix?

@DonaldDucker34
Copy link
Author

So here is a FIX for everyone i looked trough the internet and found this :(https://superuser.com/questions/1455857/how-to-disable-office-key-keyboard-shortcut-opening-office-app) when you paste the command "REG ADD HKCU\Software\Classes\ms-officeapp\Shell\Open\Command /t REG_SZ /d rundll32" in the admin command prompt the Hotkey for office isnt working any more 😄

@furiousduckling
Copy link

@DonaldDucker34 How do you go about automating this using ducky script?

@DonaldDucker34
Copy link
Author

that is the 'problem' i cant connect to a pc without entering the firestage1 command that means i cant send ducky scripts to a pc

@DonaldDucker34
Copy link
Author

but i dont know if you could edit the firestage1 command that it first enters the cmd string and then connects the idea is not that bad

@furiousduckling
Copy link

furiousduckling commented Apr 21, 2020 via email

@furiousduckling
Copy link

Trying to think of a way to stick it on my duckberry without any interaction with the pc itself

@DonaldDucker34
Copy link
Author

DonaldDucker34 commented Apr 24, 2020

so i didnt knew what a Duckyberry is but now i do. The duckberry is an bad usb and a rubber ducky then the Duckberry should use the .duck format i think you should look at the .duck scripts from P4wnP1 and make your own for the Duckberry
(sry for the english have a good day)

@furiousduckling
Copy link

furiousduckling commented Apr 24, 2020 via email

@DonaldDucker34
Copy link
Author

could you show me that script i think its very interesting to look at something like that

@furiousduckling
Copy link

furiousduckling commented Apr 25, 2020 via email

@DonaldDucker34
Copy link
Author

if you look in the bottom area of the script it tells the pc to type notepad.exe but why explorer opens is unknown

@DonaldDucker34
Copy link
Author

is the keyboard language equal to your keyboard language? Its a really common issue

@furiousduckling
Copy link

furiousduckling commented Apr 26, 2020 via email

@DonaldDucker34
Copy link
Author

this is getting really interesting i will look trough Pwnpi and search for a fix :)

@DonaldDucker34
Copy link
Author

It's just the default one in p4wnp1 located here : https://github.com/RoganDawes/P4wnP1/blob/master/payloads/hid_keyboard.txt

On Sat, 25 Apr 2020 at 23:11, Lasse.B @.***> wrote: could you show me that script i think its very interesting to look at something like that — You are receiving this because you commented. Reply to this email directly, view it on GitHub <#337 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/APJDV47LF2M3W6Z7TWGW55TRONN2BANCNFSM4MLPZ54Q .

is it really the exact same? i had a look at the script an nothing seemed wrong it just types win+r to open the execute window and then it types notepad.exe to open the editor last it types "Keyboard is running" but where does it open the explorer? i did a bit research and found that the explorer is opened by the key combination Win+E (GUI e) so i think we should search a bit more 😄

@DonaldDucker34
Copy link
Author

and what did you actually type to start the script?

@furiousduckling
Copy link

furiousduckling commented Apr 26, 2020 via email

@DonaldDucker34
Copy link
Author

did you selected the right payload in the setup.cfg? (cd P4wnP1 then nano setup.cfg and on the bottom there are the payloads)

@furiousduckling
Copy link

furiousduckling commented Apr 26, 2020 via email

@DonaldDucker34
Copy link
Author

@DonaldDucker34 How do you go about automating this using ducky script?

to this older comment: i think it would be cool if i wrote a script and then i could execute it but i cant execute ducky scripts without connection to a PC but i also cant connect to a PC without the cmd string then i thought about an autorun.inf on a smaller usb stick (2-4gb) but since win10 you cant or windows wont execute autorun.inf because its an security leak. Would it be possible that the rpi runs the ducky script on rpi startup then pwnpi uses its HID capability and sends the cmd string without the remote shell even activated that means i cant enter things in the remote shell but theoretically it should disable the office hotkey and then i could enter FireStage1 to connect to the rpi and get an reverse shell

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants