rapid7 / metasploit-framework

Metasploit Framework
https://www.metasploit.com/
Other
34.3k stars 14.02k forks source link

Flipper zero msf badusb payload generator/executor #17274

Closed hastalamuerte closed 2 years ago

hastalamuerte commented 2 years ago

Hello, I am a big fan of your software. Especially metasploit. Respect to Egypt )

Write you with one help request. There is a tool called Flipper Zero. Its a education tool for hackers , radio enthusiasts and others techs people community. Soon they will present flipper one with kali or other linux onboard.

I am not present any company. I just simple security engineer. But i very want to test one feature which i imagine.

That tool flipper - support bad usb mode. I think it use some rubber ducky scripts. I was try it on kali lin, win 10. Default templates with some text file creation and ASCII graphic. Seems it work.

Can you made plz msf payload generator , executor with simple pre usage like change parameters and etc. Saving , ip database with easy switch in payload setting. And etc. I can help with gui, logical. Sorry i am noob in coding ( or maybe you can connect with devs of flipper. Or with developer of some extra firmware called "unleashed"( it more powerfull)

I can send you one flipper , or buy one to develop. Maybe someone from dev team will be interested. Thank you for your work and your products. Nexpose also is great ^_^

Useful Links: https://flipperzero.one/ https://github.com/DarkFlippers/unleashed-firmware https://github.com/I-Am-Jakoby/Flipper-Zero-BadUSB https://forum.flipperzero.one/c/badusb/20 https://github.com/flipperdevices/flipperzero-firmware/issues/1902 Wraps a powershell script from kali linux to https://github.com/Blackn0va/Flipper_BadUSB_Wrapper https://github.com/AGO061/BadBT Before opening a new issue, please search existing issues https://github.com/rapid7/metasploit-framework/issues

Motivation

Why are we doing this? What use cases does it support? What is the expected outcome?

Cause its cool! And cows must be free. Case - is security checks in company's, with bad usb via Bluetooth attack. Outcome is - respect and love ❤️

h00die commented 2 years ago

Seems like an msfvenom function. It would need to be all ASCII, so a b64 decode or something similar.

I have a flipper zero to test with

hastalamuerte commented 2 years ago

And !!!! I found i think the best one off https://github.com/nocomp/Flipper_Zero_Badusb_hack5_payloads @_@ Look awesome. Will try too.

And the second one unofficial firmware https://github.com/RogueMaster/flipperzero-firmware-wPlugins He also got awesome..git with big list

Maybe it can be helpful.

Thanks for your answer, its sound quite cool! I think some brand msf module , app will be very stylish ~_~. Dolphin and cow )))

hastalamuerte commented 2 years ago

And !!!! I found i think the best one off https://github.com/nocomp/Flipper_Zero_Badusb_hack5_payloads @_@ Look awesome. Will try too.

Thanks for answer, its sound quite cool! I think some brand msf module , app will be very cool. Dolphin and cow )))

Update https://github.com/flipperdevices/flipperzero-firmware/blob/dev/documentation/fbt.md https://github.com/flipperdevices/flipperzero-firmware/blob/dev/documentation/AppsOnSDCard.md Some dev docs

h00die commented 2 years ago

https://docs.hak5.org/hak5-usb-rubber-ducky/ducky-script-quick-reference

smcintyre-r7 commented 2 years ago

This will be part of the 6.2.28 release tomorrow.