mirror of
https://github.com/hak5/bashbunny-payloads.git
synced 2025-10-29 16:58:25 +00:00
* Adding the MacPhish payload, uses HID and STORAGE modes on BashBunny. For OS X, uses spotlight to launch terminal, then uses osascript command to phish for the users password, then saves the phished password back to the bashbunny. * Update readme.md
Mac Phish
Author: ahhh Version: Version 1.0
Description
Credz to Fuzzynop for introducing me to the technique: http://fuzzynop.blogspot.com/2014/10/osascript-for-local-phishing.html Using ducky script, it opens a terminal and uses the osascript command in an attempt to social engineer the root password, then saves this back to bash bunny in the loot dir
Configuration
This is configured for Macbooks as a keyboard, opens terminal via spotlight
STATUS
| LED | Status |
|---|---|
| Blue | Setup |
| Amber | Running the scripts |
| Green | Finished |