[00:06.840 --> 00:09.080] Oh, she only stalled a couple more seconds. [00:09.260 --> 00:10.280] I got to get stuff out of my pocket. [00:13.630 --> 00:14.070] Props. [00:14.550 --> 00:15.690] I need my props. [00:22.860 --> 00:23.800] Oh, see? [00:24.820 --> 00:25.620] That did it. [00:30.600 --> 00:32.920] Okay, I'm going to try to shift it just a little bit more. [00:33.480 --> 00:35.340] I might be tempting fate too much here. [00:36.980 --> 00:37.460] Yay. [00:41.300 --> 00:42.880] Keep going between blue screen. [00:44.740 --> 00:46.180] Oh, come on, cable. [00:47.700 --> 00:49.200] This is not my desktop. [00:50.020 --> 00:51.680] This is... [00:51.680 --> 00:52.340] Yeah. [00:53.540 --> 00:56.240] I don't even want to touch it and say change slides now. [00:56.360 --> 00:59.240] So this is going to be the only slide we see the entire time. [01:00.240 --> 01:00.480] Yeah. [01:01.840 --> 01:02.760] Yeah, yeah. [01:03.700 --> 01:05.100] I'll turn it off and on again. [01:06.280 --> 01:06.640] Okay. [01:10.060 --> 01:10.540] All right. [01:10.740 --> 01:12.780] So, yeah. [01:13.600 --> 01:16.340] I kind of am looking over there because it's weird looking down on the screen. [01:16.520 --> 01:17.740] So I might switch in between. [01:18.020 --> 01:19.400] So yeah, I'm JP Dunning. [01:19.560 --> 01:21.020] I go by handle Ronin. [01:21.240 --> 01:23.060] This is my first time at HOPE. [01:23.220 --> 01:25.100] So I'm really excited about the weekend and stuff. [01:25.260 --> 01:26.740] And it seems to be a really cool crowd. [01:26.740 --> 01:31.180] And I'm going to talk today about the hideous methods of keystroke injection. [01:32.420 --> 01:34.260] So what is keystroke injection? [01:34.940 --> 01:37.000] It's the emulation of a keyboard. [01:37.260 --> 01:39.520] So it's without actually having the physical keyboard there. [01:39.700 --> 01:45.700] You're using something else to emulate the signals that are sent, that are interpreted by your computer as keys. [01:46.620 --> 01:48.280] So it's like you press a key. [01:49.140 --> 01:50.400] Benefits of leveraging this. [01:50.400 --> 01:54.000] So I'm going to talk about this from a security perspective as kind of pin testing. [01:54.180 --> 01:57.180] And you're using this as sort of an attack method. [01:57.480 --> 02:00.460] So some of the benefits of using, you know, hid injections. [02:00.820 --> 02:03.480] So hid is human interface device. [02:03.700 --> 02:05.420] And I might rotate between those terms. [02:05.640 --> 02:07.760] Because hid is kind of like a larger scope. [02:07.940 --> 02:09.620] There's a lot of hid devices out there. [02:09.920 --> 02:12.490] And they often use keystrokes. [02:13.100 --> 02:14.900] But they're not considered a keyboard. [02:15.320 --> 02:19.000] So hid injection is probably a more accurate way of stating. [02:19.000 --> 02:21.120] And that's what I normally use in my lingo. [02:22.020 --> 02:23.700] So yeah, you type accurately. [02:24.000 --> 02:24.920] You can pre-program it. [02:25.000 --> 02:26.580] So you're going to tell it what to do. [02:27.040 --> 02:28.740] You can type very, very quickly. [02:29.260 --> 02:32.640] You can type way faster than most operating systems can handle. [02:32.920 --> 02:35.480] And in my demos, I'm using VirtualBox. [02:35.620 --> 02:36.800] So there's a buffering there. [02:37.000 --> 02:39.740] And so you can sometimes have to slow it down. [02:39.860 --> 02:41.460] But you type very quickly and accurately. [02:41.880 --> 02:43.500] It doesn't require a human. [02:43.720 --> 02:45.600] By that I mean nobody's at a keyboard. [02:45.860 --> 02:48.020] You don't have to be there to make something happen. [02:48.020 --> 02:51.320] You can plug in something and then not be there. [02:51.440 --> 02:52.720] And it injects later on. [02:53.460 --> 02:55.680] It works against a lot of computers. [02:55.880 --> 02:56.800] So that's a benefit. [02:57.700 --> 02:59.460] What computers use a keyboard? [03:00.000 --> 03:01.860] Most desktops, laptops. [03:03.120 --> 03:06.500] Our phones and PDAs or whatever do. [03:07.180 --> 03:12.240] But has anybody ever tried to hook up a USB keyboard to a phone? [03:12.240 --> 03:13.340] I know, that sounds crazy. [03:13.920 --> 03:14.280] Yeah? [03:14.640 --> 03:15.200] Oh, yeah. [03:15.340 --> 03:16.260] Does it work, Oliver? [03:16.540 --> 03:17.120] It does. [03:17.460 --> 03:18.200] Yeah, nice. [03:18.400 --> 03:19.620] So you got it on the N900? [03:19.940 --> 03:20.340] Oh, yeah. [03:20.420 --> 03:20.740] Yeah. [03:21.000 --> 03:23.160] So I'm not going to rant about that. [03:23.300 --> 03:25.560] Coolness, the N900, the Pwn phone is good stuff. [03:25.680 --> 03:26.780] But it's got USB host mode. [03:26.880 --> 03:28.220] So you can plug things into it. [03:28.680 --> 03:30.540] Which most devices don't. [03:30.880 --> 03:33.080] Because it's really only cool for this kind of crowd. [03:33.200 --> 03:35.620] And most people are like, why would I hook that keyboard up to my phone? [03:35.620 --> 03:37.720] Because you can hook your keyboard up to your phone. [03:37.820 --> 03:38.300] Come on, people. [03:42.020 --> 03:43.560] So, most likely not on those. [03:43.720 --> 03:49.380] But, you know, it's this specific, what I'm talking about today, I targeted Windows, Linux, and OSX. [03:49.640 --> 03:53.020] Which are, you know, the most common desktop, laptop platforms. [03:53.860 --> 03:55.120] Probably not in that order. [03:55.280 --> 03:56.600] Unfortunately, not in that order. [03:59.400 --> 04:00.620] So what is hideous? [04:01.040 --> 04:03.060] It's human interface device, which is hid. [04:03.740 --> 04:05.660] Injection over USB suite. [04:05.860 --> 04:08.960] Because you have to come out with some cool acronym. [04:09.600 --> 04:11.500] It's a library for keystroke injection. [04:11.740 --> 04:13.460] It's designed for the Arduino platform. [04:13.820 --> 04:16.980] So you're going to be leveraging Arduino type hardware for this. [04:17.500 --> 04:19.920] It reads payloads from micro SD card. [04:20.100 --> 04:23.060] Which is different from some of the other projects that are out there. [04:23.740 --> 04:25.180] So you don't have to... [04:25.180 --> 04:28.880] All the configuration is done by the user on the micro SD card. [04:29.020 --> 04:30.260] Which makes it fairly convenient. [04:30.640 --> 04:32.840] And the user select payloads on the fly. [04:32.840 --> 04:33.840] With a dip switch. [04:34.120 --> 04:36.020] So you can change between payloads. [04:36.020 --> 04:37.460] Without having to do... [04:37.460 --> 04:38.000] You know, you just... [04:38.000 --> 04:38.800] At a moment's notice. [04:38.820 --> 04:40.600] You can decide you want to run something else. [04:40.800 --> 04:42.180] Than what you had previously planned. [04:44.300 --> 04:45.880] So what are the different payloads? [04:46.420 --> 04:48.840] As I said, they're loaded on the micro SD card. [04:49.120 --> 04:51.320] Most of them are plain text files. [04:51.520 --> 04:52.300] That you have set up. [04:52.480 --> 04:54.400] And these are user configured text files. [04:54.560 --> 04:54.840] You don't... [04:54.840 --> 04:56.240] Nothing is preset in there. [04:56.920 --> 04:58.260] The operating systems. [04:58.520 --> 04:58.740] Windows. [04:58.960 --> 04:59.140] Linux. [04:59.280 --> 04:59.720] OSX. [05:00.580 --> 05:01.420] So the... [05:01.420 --> 05:03.540] These payloads work differently on each one. [05:04.040 --> 05:05.400] So you think of typing isn't the same. [05:05.540 --> 05:07.080] But the way these payloads are gonna work. [05:07.880 --> 05:10.720] They act differently depending on the operating system. [05:10.820 --> 05:12.220] To make it convenient for the user. [05:12.900 --> 05:15.100] So the types of payloads I have set up. [05:15.620 --> 05:17.260] I brought a laser pointer with me. [05:17.340 --> 05:18.100] And I left it downstairs. [05:18.340 --> 05:20.280] Because I really want a laser point. [05:20.800 --> 05:21.800] Anybody in the crowd? [05:22.880 --> 05:23.860] I have a flashlight. [05:24.020 --> 05:25.240] But it really just doesn't do the same. [05:26.420 --> 05:26.780] No. [05:27.080 --> 05:27.200] No. [05:27.480 --> 05:27.600] No. [05:28.080 --> 05:28.700] That's amazing. [05:28.880 --> 05:30.720] I can't believe nobody has a laser pointer in here. [05:31.160 --> 05:32.080] Ten years too late. [05:32.080 --> 05:32.160] Ten years too late. [05:32.720 --> 05:33.160] Come on. [05:33.840 --> 05:34.160] Alright. [05:34.480 --> 05:37.880] So the different types of payloads that I have configured in this library. [05:38.120 --> 05:38.460] Oh yeah. [05:44.210 --> 05:44.990] Well that's a light. [05:45.010 --> 05:45.670] That's the light one. [05:46.290 --> 05:47.050] What is the other one? [05:47.150 --> 05:47.330] Okay. [05:47.510 --> 05:47.590] Cool. [05:48.510 --> 05:51.270] So for the people at home that are obviously seeing what I'm pointing to. [05:52.270 --> 05:56.550] So command, script, binary, and something called red button that I'll discuss. [05:56.770 --> 05:59.170] So this is a payload that's going to be one command. [05:59.950 --> 06:03.650] Or versus a script or a binary executable. [06:04.330 --> 06:05.270] And red button. [06:05.710 --> 06:07.730] So a little bit of the selection process. [06:07.970 --> 06:12.370] As I said you're gonna use the dip switch to go between them. [06:12.590 --> 06:14.670] I decided to incorporate a safe mode. [06:14.930 --> 06:17.090] Because this is launching stuff when it's plugged in. [06:17.090 --> 06:17.910] So you want that. [06:18.650 --> 06:22.490] As a developer I realized that you want it not to do that stuff sometimes. [06:23.310 --> 06:24.430] So when I have... [06:24.430 --> 06:26.150] When it's flipped to binary zero. [06:26.470 --> 06:27.450] It's not gonna do anything. [06:27.610 --> 06:28.530] That is the safe mode. [06:28.710 --> 06:30.750] You know you can plug it into your computer then. [06:32.310 --> 06:33.370] If it's in one. [06:33.610 --> 06:34.750] Then it's gonna type out help. [06:34.950 --> 06:37.250] Because I figured there's a lot of possible modules there. [06:37.410 --> 06:38.530] And you might not have that. [06:38.630 --> 06:38.790] You know. [06:38.850 --> 06:40.410] You might not want to take out the SD card. [06:40.590 --> 06:41.150] And plug it in. [06:41.270 --> 06:41.810] And look through that. [06:41.810 --> 06:42.050] So. [06:43.110 --> 06:44.370] How the modules work. [06:44.490 --> 06:45.610] They're self encapsulated. [06:45.850 --> 06:46.690] So you have a folder. [06:46.810 --> 06:47.990] So like that's advanced. [06:48.110 --> 06:48.810] You just have a folder. [06:48.950 --> 06:49.990] And all the files are in there. [06:50.110 --> 06:50.650] That you're gonna... [06:50.650 --> 06:52.050] All the resources that you need. [06:52.250 --> 06:54.130] And one of those files is help.txt. [06:54.490 --> 06:57.350] And that's just the description you want to give that particular module. [06:57.610 --> 06:58.450] Of what it's gonna do. [06:58.810 --> 07:00.410] So this reads through all those folders. [07:00.550 --> 07:01.710] And just prints that out for you. [07:01.810 --> 07:02.550] To make it convenient. [07:03.090 --> 07:04.950] And then the rest of the modules are these payloads. [07:05.490 --> 07:07.170] That you're gonna inject onto the system. [07:07.350 --> 07:08.490] These user defined ones. [07:10.210 --> 07:11.970] So the terminal is key here. [07:13.390 --> 07:15.590] And I'll talk a little bit more about... [07:15.590 --> 07:16.010] You know. [07:16.250 --> 07:19.290] We generally think a mindset of you need the mouse to interact. [07:19.290 --> 07:22.610] We all interact with the mouse to do stuff on our everyday life. [07:23.390 --> 07:24.550] As I've done this project. [07:24.710 --> 07:26.550] I've tried to interact less and less with the mouse. [07:26.710 --> 07:27.150] Just to see. [07:27.350 --> 07:30.590] Because you can really get almost everything done on your computer. [07:31.310 --> 07:33.670] You can unplug your mouse and see how your day goes. [07:33.830 --> 07:34.330] And you can... [07:34.330 --> 07:37.550] If you have, you know, some help into how all the keys work. [07:37.550 --> 07:39.870] You can pretty much do everything you were doing before. [07:40.190 --> 07:41.010] Without a mouse. [07:41.150 --> 07:42.030] Entirely without a mouse. [07:42.410 --> 07:43.950] Interacting with the GUI interface. [07:44.130 --> 07:46.110] I'm not talking like using a terminal only. [07:46.490 --> 07:48.910] You can interact with the system. [07:49.250 --> 07:49.690] So... [07:49.690 --> 07:52.010] But I'm leveraging the terminal to start out with. [07:52.150 --> 07:54.010] So the payloads are gonna be run. [07:54.210 --> 07:57.050] As I mentioned, the scripts are gonna be run obviously in a terminal. [07:57.850 --> 07:58.610] Most of them. [07:58.770 --> 07:59.550] And there's one that's not. [07:59.710 --> 08:00.490] That I'll talk about later. [08:01.110 --> 08:01.990] To control. [08:02.270 --> 08:02.650] So... [08:03.310 --> 08:04.830] The functions that I've written. [08:05.170 --> 08:06.770] Go ahead and open up the terminal for you. [08:06.770 --> 08:07.450] To make it easy. [08:07.570 --> 08:09.690] You don't have to know these keystrokes to open that up. [08:10.030 --> 08:11.450] You just pass it parameters. [08:11.690 --> 08:12.510] And it says, I'm... [08:12.510 --> 08:15.250] My starting point is I will load a terminal for you. [08:15.410 --> 08:18.510] And then I'm going to run these payloads that you've set for me. [08:19.010 --> 08:22.290] So, it's gonna use the graphical interface to open the terminal. [08:22.610 --> 08:26.770] In Windows, I have it go through and you run an administrative terminal. [08:27.010 --> 08:29.570] So, most of the time you have administrative access. [08:29.570 --> 08:33.830] But when you open the terminal, it's a little pop-up that says, are you sure you wanna run this as admin? [08:34.270 --> 08:36.390] Which, darn those viruses, they can't click on things. [08:36.410 --> 08:41.330] But, when you are designed to hit enter as a keyboard, that's a... [08:41.330 --> 08:41.630] Oh, yeah. [08:41.710 --> 08:42.630] That was difficult to bypass. [08:42.770 --> 08:43.270] Let me hit enter. [08:43.930 --> 08:44.950] So, yeah. [08:45.110 --> 08:45.770] You can just... [08:45.770 --> 08:47.470] It opens up an administrative one. [08:48.170 --> 08:51.050] It's harder to do in, you know, Linux and OSX. [08:51.170 --> 08:52.010] You have to pseudo. [08:52.230 --> 08:54.670] And most likely, they have permissions and stuff. [08:54.670 --> 08:59.210] So, that's an option out there, but I didn't implement that as the, you know, baseline. [08:59.950 --> 09:03.110] So, then, you know, once the terminal's up, you have the administrative privileges. [09:03.330 --> 09:06.370] It's going to run these payloads that you've configured. [09:07.750 --> 09:09.170] You have the command line one. [09:09.710 --> 09:14.570] So, it runs one line of a command line, but it's not necessarily one command. [09:15.070 --> 09:19.170] So, how many people have typed in more than one command on a command line at once? [09:19.290 --> 09:20.130] You know what I'm talking about. [09:20.290 --> 09:20.530] Okay. [09:20.690 --> 09:20.830] Good. [09:21.050 --> 09:21.470] Great crowd. [09:21.650 --> 09:22.870] So, this is exactly it. [09:23.970 --> 09:34.410] You have, you can use the ampersand or the semicolon in, you know, Linux and Windows to, to add additional commands that says, after this one's finished, run this one. [09:34.570 --> 09:35.930] And after that one's finished, run this one. [09:36.050 --> 09:37.170] Or run these two together. [09:37.310 --> 09:37.970] Or if this one fails. [09:38.090 --> 09:40.830] There's a lot of different combinations you can do just with one line. [09:41.410 --> 09:46.070] It, you, I've seen some people that are really good at, you know, not even writing scripts. [09:46.250 --> 09:50.650] Because they can write everything that would be in a script in one really long, long line. [09:50.650 --> 09:52.730] And it's really, really hard to read. [09:53.110 --> 09:55.510] But, it's like, once you read it, you're like, that is really cool. [09:55.650 --> 09:57.070] That it's just all fit, you know, one line. [09:57.210 --> 09:57.590] You hit enter. [09:57.770 --> 09:58.990] And it's gonna do all that stuff. [09:59.650 --> 10:03.210] So, you can actually get a lot done just with a single command line. [10:03.370 --> 10:06.210] And it's sometimes easier to put that together. [10:07.130 --> 10:08.370] It makes timing easy. [10:08.590 --> 10:13.490] So, a big part of the hit injection is you need to predict how the environment's going to react. [10:13.670 --> 10:15.190] Because you, you're not getting feedback. [10:15.410 --> 10:16.410] You're saying, go. [10:16.590 --> 10:17.390] And it's doing things. [10:17.510 --> 10:19.070] So, you didn't know how long things are going to take. [10:19.370 --> 10:21.530] With a single command, you bring up the command prompt. [10:21.630 --> 10:22.050] You run it. [10:22.190 --> 10:23.510] And it's, you know, it's gonna do its thing. [10:23.610 --> 10:25.130] And you don't care what happens after that. [10:25.130 --> 10:28.990] You've, you've got all the timing is built in because you're running that one line. [10:30.070 --> 10:33.250] So, there's no, and there's also no need to write anything to disk like the other two. [10:33.430 --> 10:34.190] You're just running the command. [10:34.350 --> 10:35.310] So, it's gonna do that stuff. [10:35.450 --> 10:38.270] And then at the end, to have it exit the terminal once you've finished. [10:38.530 --> 10:42.750] So, does its stuff, leaves the terminal, and then, you know, basically nobody's the wiser. [10:43.430 --> 10:45.830] A lot of this is trying to be nobody's the wiser. [10:46.610 --> 10:47.910] Unseen hidden detection. [10:48.130 --> 10:52.210] You're trying to get these injections to work while nobody's observing it. [10:53.630 --> 10:55.890] So, scripts make things a little, things a little easier. [10:56.190 --> 10:58.470] I'm sure there's a lot of people who use scripts in here. [10:59.790 --> 11:01.610] And we use them in our daily lives. [11:01.730 --> 11:06.970] But thinking of the basic languages that we use as attack platforms, there's a lot you can do with a batch script. [11:07.550 --> 11:10.130] You can destroy a system with a batch script really easily. [11:10.250 --> 11:13.390] Or you can gain information just with the local resources. [11:14.230 --> 11:17.930] So, it type, basically it opens the terminal, types it into an editor. [11:18.150 --> 11:24.110] I used to, I originally developed it with edit, which is one of the 16-bit old commands in Windows, which was awesome. [11:24.230 --> 11:24.850] I was so proud. [11:24.990 --> 11:27.190] I was like, I don't have to leave the command prompt to do this. [11:27.310 --> 11:31.350] And then I tried it on a 64-bit version of Windows, and it was like, what is that? [11:32.010 --> 11:32.350] Six... [11:32.770 --> 11:33.460] It's like, you... [11:34.330 --> 11:36.790] I was so proud that I didn't have to use Notepad. [11:36.930 --> 11:38.490] And it was like, well, crap. [11:39.150 --> 11:40.190] I have to use Notepad. [11:40.290 --> 11:46.110] So, this types it into Notepad in Windows, and then in the terminal in Linux and OSX. [11:46.670 --> 11:47.070] But... [11:47.070 --> 11:50.630] So, types it in, saves it, runs it, deletes it. [11:50.970 --> 11:53.330] So, this is, again, like a long command. [11:53.550 --> 11:57.430] But it's gonna save it in a temporary directory, run it, and then delete it once it's done. [11:57.730 --> 11:58.610] So, it kind of... [11:58.610 --> 12:00.930] A lot of this, what I designed was it's self-cleaning. [12:01.170 --> 12:02.850] So, you do, you know, your stuff. [12:03.170 --> 12:05.710] And then by the end, it's gone. [12:06.310 --> 12:11.690] I'm not talking like hardcore forensics, but to the naked eye, it's pretty much gone, and it, you know, never existed. [12:12.890 --> 12:14.030] So, you can use, yeah. [12:14.510 --> 12:20.670] Leveraging native scripting languages, a lot of what we wanna do with hit injection, is, is use the resources that are there. [12:20.930 --> 12:25.650] Unlike, you know, if you're gonna be downloading an application, or like using, like, or something. [12:25.810 --> 12:27.170] You're thinking, like, the backdoor shell. [12:27.850 --> 12:29.670] You have to get that on the box. [12:29.830 --> 12:34.630] We're not putting, necessarily, we don't have to put anything, any new software on here at all. [12:34.910 --> 12:36.810] So, we're using what's already on there. [12:36.990 --> 12:45.070] The only difference between how I run these is, you know, it's either dot forward slash, or python space, or, that's the only reason there. [12:45.250 --> 12:47.410] If all of it's gonna be dot forward slash, that would be fine. [12:47.610 --> 12:51.370] And running it in Linux, or, you know, a batch file, you just wanna type in the file name and hit enter. [12:51.730 --> 12:56.610] So, they're run a little bit differently, which is why I'll list them out there, as opposed to saying all scripting languages. [12:57.610 --> 13:05.090] But, you know, if people want to add more, it's just for, like, one line of code for me to say, okay, now I support Ruby, or another language. [13:05.370 --> 13:08.830] So, it'll be really easy for me to update that later on. [13:08.830 --> 13:11.190] But, and then you have more advanced options. [13:11.950 --> 13:13.850] Yeah, the single command entry. [13:16.410 --> 13:18.310] So, a binary, you can run. [13:19.510 --> 13:25.350] The idea is you've got a binary on your flash drive, and you want it to execute on the host system, the target system. [13:25.530 --> 13:26.590] So, how do you do that? [13:27.150 --> 13:46.030] All of the scripts that I use across the board on these operating systems read in the binary, binary, and then convert it into hexadecimal format, then type that hexadecimal format into the system, in the command line, or in notepad, or whatever, and then convert that back into a binary, [13:46.230 --> 13:47.930] and then run the binary, and then delete the binary. [13:48.590 --> 13:57.110] Which is really cool sounding, and it is really cool, except it is super slow, because if you try to convert a binary into hex, it takes forever. [13:57.110 --> 14:03.750] And as I mentioned before, the device can, can type in way faster than the computers can handle. [14:03.950 --> 14:06.430] So there's always, I have to like write in a lag time. [14:06.590 --> 14:10.130] So you type in a bunch of stuff and then wait for the computer to catch up and then type in a bunch of stuff. [14:10.250 --> 14:16.910] So it ends up taking a long time for even like notepad.exe or really small, you know, Netcat. [14:17.130 --> 14:18.790] Typing over Netcat takes a while. [14:18.870 --> 14:31.050] If you have a couple hours and the, the, you know, there's a really high-end networking security system, IDS, IPS, whatever that's blocking you from getting anything else on the box and that's your way of doing it, okay. [14:31.390 --> 14:32.790] But otherwise, it's there. [14:32.990 --> 14:40.690] It might be fun to play around with once or twice, but it's going to be really a lot slower than just using a script to download something and then run it for you. [14:42.370 --> 14:44.790] But this definitely took the most time to implement. [14:45.030 --> 14:46.130] There's a lot of testing here. [14:47.330 --> 14:48.070] Red button. [14:49.210 --> 14:50.610] Never use red button. [14:52.130 --> 14:56.070] So what I decided to do was like, I don't want a script. [14:56.150 --> 15:00.550] I want something that's basically going to randomly wreak havoc on the system. [15:00.930 --> 15:04.450] Because, you know, sometimes later now you get bored of the project you're working on. [15:04.550 --> 15:06.290] You're like, I want to add something new and fun. [15:06.750 --> 15:10.590] So I thought, what are like the worst things you can do randomizing with the keyboard? [15:10.790 --> 15:13.390] So it does a mouse movement in a random direction. [15:14.570 --> 15:16.750] It'll click a random mouse button. [15:16.930 --> 15:20.390] So the three mouse button, right click, middle click, left click, it'll do one of those randomly. [15:21.230 --> 15:22.870] It'll randomly hit the GUI key. [15:23.110 --> 15:25.850] So in Windows, the GUI key is like the start, opens the start menu. [15:26.230 --> 15:30.110] And then then it'll hit arrows up and down and then hit enter. [15:30.570 --> 15:34.490] It'll open up the command, the run command in Windows. [15:34.650 --> 15:36.950] Like you hit Alt R and you have that little run. [15:37.210 --> 15:37.790] It'll do that. [15:37.930 --> 15:39.110] It'll type in... No, sorry. [15:39.190 --> 15:40.150] It does the start menu. [15:40.270 --> 15:45.870] It does the start menu, types in two characters, waits a second for Windows to recommend something, and then hits enter. [15:47.550 --> 15:48.630] That's what I would like. [15:49.030 --> 15:50.950] So it launches random applications. [15:51.190 --> 15:54.410] The GUI one is... I think it runs a random command. [15:56.030 --> 15:56.470] And... [15:56.470 --> 15:59.170] So it's also random timing between all of this. [15:59.290 --> 16:04.850] So it's going to wait... I think it's like between one and ten seconds for all these things to go on. [16:05.310 --> 16:08.510] So don't... I accidentally had this running on my computer once. [16:08.750 --> 16:12.770] And, you know, I walked away, went to the bathroom, came back, and just like all these apps were up. [16:12.970 --> 16:13.770] Nothing was running. [16:13.810 --> 16:14.550] Everything was frozen. [16:14.990 --> 16:16.310] It's like, this is a cool way. [16:16.370 --> 16:17.810] I should implement this. [16:18.290 --> 16:19.590] So it's there. [16:19.710 --> 16:21.690] It's in... It's a function you can call. [16:21.850 --> 16:27.750] The one thing... A reason that it actually might be useful is if you're trying to break out of a kiosk. [16:28.010 --> 16:37.770] If you have access through USB to a kiosk, which some of them do, then, you know... But kiosk, I mean like a public computer that's, you know, got an interface that's not like Windows. [16:38.130 --> 16:42.070] You may be able to click around or search their website or whatever. [16:42.230 --> 16:45.630] But a lot of times, one of my hobbies is breaking out of kiosks. [16:45.770 --> 16:50.090] And so I thought it'd be really cool because a lot of times you can end up doing it if you spend enough time. [16:50.490 --> 16:54.810] So the goal with this is it's going to click around and try every key combination you can possibly think of. [16:54.950 --> 16:58.930] And it's either going to crash the sort of thing or probably wiggle its way out eventually. [16:59.270 --> 17:05.810] So you kind of plug it in, walk away, come back and see if it's either crashed or broken out or what's happened and maybe do it a couple of different times. [17:06.410 --> 17:08.730] But... Or, you know, it's a fun prank. [17:08.970 --> 17:13.970] Hey, plug it in, walk away, come back and your computer can be completely foobarred. [17:14.090 --> 17:16.550] Like, it can really, really mess some stuff up. [17:17.750 --> 17:18.910] So that's why I wrote it. [17:20.450 --> 17:23.110] So I mentioned there's one exception to running native scripts. [17:23.530 --> 17:25.250] I wrote something called the Hidscript. [17:25.510 --> 17:26.210] It's a... [17:26.210 --> 17:27.470] It's a parsed language. [17:27.710 --> 17:31.430] So it's weird to say, like, I wrote a language because it's really not a lot of a language. [17:31.450 --> 17:33.190] It's really just parsing some syntax. [17:33.470 --> 17:35.670] And I'll show you an example so you know what I'm talking about. [17:36.550 --> 17:40.470] So running Python and batch scripting and stuff, that's cool. [17:40.470 --> 17:43.830] But it's harder to interact with the GUI doing that. [17:44.310 --> 17:47.610] Unless you are an awesome... How many people think they can do that in Python? [17:47.770 --> 17:56.190] Like, how many people have the skill to run a lot of the stuff or like Perl or something that you would... Like, can you emulate a keyboard click in any of those languages? [17:56.210 --> 17:56.470] languages? [17:57.370 --> 17:58.090] I'm asking. [17:58.210 --> 17:59.230] I really didn't look it up. [17:59.310 --> 18:02.530] And I figured asking a broad crowd was easier than me searching online. [18:02.990 --> 18:04.670] That's... That was the laziest there. [18:04.850 --> 18:05.550] Just send it out there. [18:05.710 --> 18:06.110] Okay. [18:06.350 --> 18:07.450] So maybe, maybe not. [18:08.570 --> 18:10.210] But... So I created this language. [18:10.650 --> 18:15.370] It's parsed and it will use the keys that you're not able to type directly. [18:15.650 --> 18:16.950] So, like, you can type A. [18:17.070 --> 18:17.590] That's fine. [18:17.750 --> 18:23.270] But when you... How do you type function or, you know, F7? [18:23.690 --> 18:28.210] Well, you can't like... When you type in F7 and it's read in, it's going to type out F7. [18:28.410 --> 18:29.990] So it's not going to actually hit the F7 key. [18:30.270 --> 18:32.130] So this script is kind of the answer to that. [18:32.250 --> 18:39.430] So that when it's parsed, it's actually going to hit these keys that are mapped on your keyboard and not just read it in as is, as like ASCII text. [18:40.170 --> 18:41.530] So it translates the script. [18:42.050 --> 18:44.170] There are four main components to it. [18:44.250 --> 18:45.190] So you have plain text. [18:45.270 --> 18:47.850] So you don't have to use the scripting language for everything. [18:48.110 --> 18:51.590] In the middle, when you want to type in, like, hello world, you just type in hello world. [18:51.590 --> 18:55.130] And then when you need to use the special keys, at that point, you can use the language. [18:56.250 --> 18:59.650] There are special modifier keys, like Ctrl, Alt, Shift. [18:59.990 --> 19:02.190] So you hold them on their own and they don't really do much. [19:02.290 --> 19:07.270] But when you hit, like, Ctrl S, the combination of the two means something significant. [19:07.790 --> 19:14.450] So you have these special modifier keys that when they're in sequence with either themselves or another key, they mean something else. [19:14.590 --> 19:16.550] So those are a little more significant in language. [19:16.950 --> 19:18.930] You have, as I call it, just regular parsed keys. [19:18.990 --> 19:21.570] All the other keys on the keyboard, when you hit them, they do something. [19:21.570 --> 19:25.150] Or they do something in combination with the modifiers. [19:25.770 --> 19:27.330] And then I have commands. [19:28.810 --> 19:30.690] And I'll just demonstrate what that is. [19:30.810 --> 19:34.710] So this is an example of the script right here. [19:34.850 --> 19:35.850] Very simple, basic. [19:36.230 --> 19:38.170] And it kind of gets to all the points I was talking about. [19:38.430 --> 19:39.630] So you have a command. [19:41.070 --> 19:42.470] A modifier key right here. [19:42.610 --> 19:44.310] The right GUI key on the keyboard. [19:44.830 --> 19:45.530] And then R. [19:45.990 --> 19:46.910] Does anybody know what that does? [19:48.730 --> 19:49.210] Run. [19:49.330 --> 19:50.930] That starts the run dialog in Windows. [19:51.690 --> 19:54.730] So another thing, you know, this is the command that I have right now. [19:54.970 --> 19:57.990] I might probably add other commands as it gets more robust. [19:58.230 --> 19:59.410] But it's the wait command. [19:59.590 --> 20:02.170] So a lot of this, as I mentioned before, is timing. [20:02.670 --> 20:07.790] So the wait command, it says, right now it interprets that as one second. [20:08.050 --> 20:11.690] And I think I'm going to change that to be milliseconds. [20:12.670 --> 20:17.870] Most of the time, when you're doing something like this, you want to be able to delay, you know, you're in this environment. [20:18.110 --> 20:20.350] A second versus two seconds doesn't really matter. [20:20.970 --> 20:22.570] But there might be exceptions to that. [20:22.670 --> 20:25.550] I did this to make it easy because we normally think of something in a second. [20:25.770 --> 20:28.310] And thinking in milliseconds is weird. [20:29.350 --> 20:29.730] Normally. [20:30.070 --> 20:42.390] But it makes a little more sense to say if there's certain things like, you know, if you're, for instance, if you're trying to do like a video game or something that's really quick paced, those kind of milliseconds might even matter to, you know, operate your bot in WoW. [20:42.590 --> 20:44.590] You really need those milliseconds to do their stuff. [20:45.010 --> 20:46.450] So I might end up changing that. [20:46.450 --> 20:48.670] But anyway, that waits for one second. [20:48.790 --> 20:49.450] So that's a delay. [20:49.850 --> 20:53.110] You know, waiting for the terminal to pop or the run command to pop up. [20:53.250 --> 20:54.130] Types in Notepad. [20:54.890 --> 20:55.750] Hits Enter. [20:56.690 --> 20:59.550] Waits two seconds for Notepad to pop up. [20:59.970 --> 21:00.890] Types in Hello World. [21:01.310 --> 21:01.810] Hits Enter. [21:02.470 --> 21:05.750] And then hits Alt F4 which closes an application. [21:06.030 --> 21:08.550] So this is the hid version of Hello World. [21:10.350 --> 21:12.150] So yeah, you have your regular keys here. [21:12.270 --> 21:12.890] That's a regular key. [21:12.990 --> 21:13.450] Regular key. [21:13.650 --> 21:14.210] Regular key. [21:15.070 --> 21:15.690] Regular key. [21:15.690 --> 21:15.790] Regular key. [21:15.930 --> 21:17.470] And then you're, you're just plain text. [21:18.170 --> 21:20.790] And you can actually have multiple of these. [21:20.910 --> 21:23.790] Like if you want to hit Control Alt Delete, sometimes you use multiple modifiers. [21:24.150 --> 21:27.050] So all of the key sequences are one liners. [21:27.190 --> 21:31.410] So any like time you want to inject the key like that, I have it set to parse in one line. [21:32.170 --> 21:34.890] It's easier to parse and it's a lot easier to look at. [21:35.010 --> 21:40.630] Because if you had to look at typing it all out and it's just like wraps around, It's not a calendar, it's randomly there, it's gonna be gobbledygook. [21:40.810 --> 21:47.550] So, you know, I'm taking the Python method and kind of like saying you have to do these certain things just so it'll look better. [21:48.150 --> 21:49.350] What language are you using? [21:49.650 --> 21:50.050] What? [21:50.190 --> 21:51.290] What language are you using? [21:51.910 --> 21:52.930] This is my language. [21:53.170 --> 21:54.230] This is a plain text file. [21:54.350 --> 21:55.390] Like, this is it right there. [21:55.490 --> 21:58.010] You would put that in a text file and it will interpret it. [21:59.210 --> 22:01.110] He's asking what language am I using? [22:01.270 --> 22:02.230] So this is the language. [22:02.410 --> 22:07.030] So, it's going to read in this as a flat text file and then interpret it. [22:07.030 --> 22:10.630] The device, I'll talk about that in a second, the actual device that I'm using. [22:10.930 --> 22:12.110] It's an Arduino-based device. [22:12.390 --> 22:21.110] So the device is reading this file from the SD card, parsing it, and then reacting accordingly and producing those keystrokes. [22:21.910 --> 22:22.370] Yeah, yeah. [22:22.470 --> 22:23.810] We're gonna get a couple demos in. [22:27.190 --> 22:35.770] So, to make it easier, after even like putting together all the demos, I realize it's a pain to type out because you have to, the sequence is important. [22:35.770 --> 22:40.010] This also matches a library that I'm leveraging too. [22:40.310 --> 22:44.550] So, it was easy to keep the same syntax as they did. [22:44.690 --> 22:49.770] So, you have like key, write, gooey, which is a lot to type out and not get wrong. [22:49.930 --> 22:53.490] All of it needs to be uppercase, at least right now. [22:53.730 --> 23:01.270] The problem is you can make a more robust language, but these microcontrollers are really not designed to handle text. [23:01.270 --> 23:02.930] Because text takes a byte. [23:03.390 --> 23:05.830] And a byte to a microcontroller is a lot of space. [23:06.030 --> 23:07.830] We're talking like kilobytes. [23:08.050 --> 23:11.550] Like anybody programmers out there, you need to work with less than a kilobyte of memory. [23:11.750 --> 23:20.390] And if you type in any word document you have on your system that you've turned in at work, it's probably more than a kilobytes worth of plain ASCII text. [23:20.830 --> 23:26.850] So, you have to really strip down as much as possible and restrict these languages. [23:27.070 --> 23:28.010] So, I'm taking it this way. [23:28.170 --> 23:32.890] This looks a little bit easier to read because if it could be uppercase, lowercase, I think in the end it would be harder to look at. [23:33.250 --> 23:35.930] So, anyway, typing all that uppercase is something we're not used to. [23:36.610 --> 23:41.490] So, a friend of mine put together a head script generator, which makes things a lot easier. [23:42.250 --> 23:44.550] So, it's a point and click web interface. [23:45.290 --> 23:47.010] It's written in HTML and Java. [23:47.350 --> 23:51.770] And when we talked about it, I specifically wanted it not to rely on a backend server. [23:51.950 --> 23:56.250] So, I didn't want to have to host this site and I didn't want to have people go online to do it. [23:56.490 --> 23:59.610] So, having HTML and Java will run natively in your browser. [23:59.810 --> 24:01.750] You just double click on the file and it will run. [24:02.050 --> 24:03.070] So, it runs the browser. [24:03.210 --> 24:04.030] There's no server backend. [24:04.230 --> 24:05.350] And it's a copy and paste. [24:05.530 --> 24:07.330] So, it will generate what you want it to see. [24:07.330 --> 24:10.130] And then you can copy and paste that into the text file. [24:10.290 --> 24:11.610] And that's my first demo. [24:19.540 --> 24:22.440] I want to move the laptop up here, but that's not going to happen. [24:23.120 --> 24:23.860] Like cable. [24:24.280 --> 24:25.320] I don't want to breathe heavy. [24:25.580 --> 24:28.040] So, I want to be shifting over there a little bit. [24:28.180 --> 24:29.260] This is what it looks like now. [24:29.420 --> 24:32.700] This was like, this is the beta version of how it looks. [24:32.820 --> 24:33.800] This is functional. [24:34.380 --> 24:36.820] And, you know, color schemes are fine, whatever. [24:37.300 --> 24:38.100] It's pretty simple. [24:38.300 --> 24:41.200] So, let me just show you kind of emulating what I just did. [24:41.720 --> 24:43.700] So, I want to hit, what is it? [24:44.640 --> 24:45.280] GUI key. [24:46.500 --> 24:47.800] And I want to hit R. [24:48.540 --> 24:50.920] So, these are the normal keys. [24:51.320 --> 24:53.200] So, you just hit, I want to put in a normal key. [24:53.400 --> 24:54.980] And then you type in R. [24:55.540 --> 24:57.000] And it gives you that new line. [24:57.360 --> 24:59.260] And then next, I want to wait. [25:00.100 --> 25:01.940] And I want to wait one second. [25:03.320 --> 25:04.620] And then I want to type in notepad. [25:06.680 --> 25:08.860] And then wait two seconds. [25:10.000 --> 25:13.640] And then type in hello world. [25:16.020 --> 25:16.700] Hit enter. [25:17.040 --> 25:17.940] You can do whatever you want. [25:18.020 --> 25:18.640] There's nothing, you know. [25:19.140 --> 25:20.260] Enter, enter, enter, enter, enter. [25:20.960 --> 25:22.920] And then I want to close the application. [25:23.440 --> 25:30.180] So, I hit Alt and key F4. [25:30.400 --> 25:31.140] Oh, F4. [25:31.920 --> 25:32.240] Okay. [25:32.500 --> 25:34.900] So, that's the, basically the entire script I just did real quick. [25:35.040 --> 25:35.120] Yeah. [25:35.620 --> 25:36.920] After notepad, you need to enter. [25:38.440 --> 25:39.080] Oh, yeah. [25:39.220 --> 25:39.500] You're right. [25:39.880 --> 25:40.160] Thank you. [25:40.460 --> 25:42.400] After notepad, I need to enter to, to run the command. [25:42.840 --> 25:43.400] So, go back up. [25:44.480 --> 25:46.100] And you can type it in too if you want. [25:50.900 --> 25:52.540] It's just like a plain text box. [25:52.700 --> 25:54.340] So, you can, you know, it, it generates the stuff. [25:55.460 --> 25:56.040] Oh, yeah, yeah. [25:57.480 --> 25:59.180] I was telling you, this is not easy to look. [26:00.700 --> 26:01.020] Okay. [26:01.080 --> 26:01.680] That was a good demo. [26:01.780 --> 26:02.540] I copy and pasted it. [26:02.600 --> 26:06.300] So, this isn't like a crazy, Flash, Java, front end. [26:06.820 --> 26:08.740] I, I just don't believe in those things. [26:08.880 --> 26:10.880] Like, wait, just like, why not make it like this? [26:11.000 --> 26:15.640] Why does it have to have Flash running and slow down my browser and take forever and crash all the time? [26:16.100 --> 26:18.800] This simple JavaScript in a text box works really well. [26:18.980 --> 26:20.740] So, it's just plain text box. [26:20.860 --> 26:24.420] And in the end, you know, you highlight it, copy it over, and you've got your script. [26:24.560 --> 26:27.720] So, that makes it a lot easier to generate. [26:27.940 --> 26:29.700] You can still, you know, accidentally screw it up. [26:29.800 --> 26:34.620] If you type in, like, that's going to mess it up. [26:34.880 --> 26:37.020] And error handling is difficult. [26:37.200 --> 26:39.160] Again, I said that there's very limited memory. [26:39.600 --> 26:42.480] So, a lot of times it'll just, that'll, that'll break it. [26:42.640 --> 26:44.700] I have some error handling involved. [26:45.300 --> 26:47.760] And maybe more if, if it gets required. [26:47.960 --> 26:50.620] But it's, you just kind of, kind of cringe at handling errors. [26:50.820 --> 26:53.100] Not because I can't, I don't know how to do it. [26:53.200 --> 26:58.540] It's because it takes that additional amount of memory that when it's running will crash the device. [26:59.000 --> 27:02.080] So, you know, this is a good safe method to generate these scripts. [27:09.020 --> 27:11.080] And I talked about this just a minute ago. [27:11.280 --> 27:15.040] You know, how to interact with the, the host operating system without using a mouse. [27:15.500 --> 27:17.580] There are a crazy number of, of keys. [27:17.720 --> 27:18.640] And I'm still learning them. [27:18.820 --> 27:22.620] And I, like, I get amazed at how many of these, you know, and a lot of it's like weird stuff. [27:22.740 --> 27:24.960] It's not like alt, alt tab is something we're used to. [27:25.040 --> 27:27.400] But it can be like control function three. [27:27.680 --> 27:29.640] And it'll do something really cool and crazy. [27:29.820 --> 27:31.500] There's just all kinds of commands out. [27:31.560 --> 27:32.180] That's not a real one. [27:32.240 --> 27:32.800] I don't know what that does. [27:33.140 --> 27:36.480] But there are lots of these modifier key combinations out there. [27:36.660 --> 27:38.700] And they're different for different operating systems. [27:38.840 --> 27:43.100] Which is why I mentioned before I, I targeted, you know, OSX, Windows, and Linux. [27:43.360 --> 27:45.580] Because they each have different ways to run stuff. [27:45.860 --> 27:47.360] So I had to write them separately. [27:47.820 --> 28:00.020] But, yeah, if you look online, Microsoft actually has a really good, if you can find them, has good documentation and different chunks about certain types of keyboard combinations to do these types of things. [28:00.340 --> 28:01.680] So there's a lot out there. [28:01.800 --> 28:03.560] As I said, you can pretty much do everything without them all. [28:05.160 --> 28:06.460] So some hit attacks. [28:07.520 --> 28:08.960] Leveraging hit to do an attack. [28:09.120 --> 28:10.680] What are the pros and cons in general? [28:11.320 --> 28:15.240] So it's, as far as I know, it's not detected by antivirus. [28:15.320 --> 28:15.840] I don't know of any. [28:16.000 --> 28:19.960] Because, again, you're not leveraging, you're not adding anything to the system. [28:20.060 --> 28:24.020] You're not modifying the system in any way before you're, you know, running these scripts. [28:24.160 --> 28:24.860] You're running batch. [28:25.060 --> 28:26.920] The system is designed to run batch. [28:27.140 --> 28:30.520] So you're modifying the system where you're doing a back door or whatever through that. [28:31.420 --> 28:34.000] Using native resources, again, not going to detect that. [28:34.300 --> 28:36.360] And, you know, you just use the common ones. [28:36.480 --> 28:37.220] So that's super simple. [28:37.620 --> 28:40.460] Works very, very quickly, as we'll see later on. [28:41.020 --> 28:42.280] It can interact with the GUI. [28:42.340 --> 28:42.960] I've covered that. [28:43.260 --> 28:45.040] The cons, you have to plug it in. [28:45.180 --> 28:46.600] Or somebody, it has to be plugged in. [28:46.640 --> 28:47.660] I shouldn't say you have to plug it in. [28:47.700 --> 28:48.740] It has to be plugged in. [28:48.900 --> 28:50.040] This is a piece of hardware. [28:50.220 --> 28:51.100] So it has to get there. [28:51.700 --> 28:52.820] That could mean you doing it. [28:52.900 --> 28:53.980] That could mean somebody else doing it. [28:54.000 --> 28:57.420] That could mean somebody gets tricked into doing it accidentally. [28:58.820 --> 29:00.380] And you have to have previous knowledge. [29:00.720 --> 29:03.000] You should have previous knowledge of the system. [29:03.180 --> 29:10.000] That might just mean, well, I assume that I'm doing my pen-test, you know, at a corporate site. [29:10.580 --> 29:12.100] And they're probably going to use Outlook. [29:12.560 --> 29:13.980] Most likely, they're going to use Outlook. [29:14.100 --> 29:16.760] So my targeted attack is leveraging Outlook. [29:16.960 --> 29:18.500] It might they use Thunderbird. [29:19.200 --> 29:19.560] Potentially. [29:19.980 --> 29:21.480] But, you know, you think of your environment. [29:21.700 --> 29:23.340] You check out the resources that are there. [29:23.680 --> 29:26.120] Command line is often the way to go, if you can. [29:26.340 --> 29:28.320] Or like, I'd like to run this in Firefox. [29:28.580 --> 29:29.500] But they might not have Firefox. [29:29.660 --> 29:30.480] So you use Internet Explorer. [29:30.620 --> 29:33.240] Because Internet Explorer is going to be there, most likely. [29:34.280 --> 29:35.940] Different versions can mess things up. [29:36.100 --> 29:38.120] So it's good to do a little prep work beforehand. [29:39.400 --> 29:40.140] And results. [29:40.260 --> 29:41.620] I said results can be unpredictable. [29:41.980 --> 29:43.540] Most of the time, that's in the delay. [29:43.760 --> 29:46.660] So it's better to do a longer delay than a shorter one. [29:46.780 --> 29:48.000] Because you run it in your system and it's great. [29:48.140 --> 29:50.860] But their system happens to be running three VMs. [29:51.020 --> 29:52.880] Or, you know, it's doing some other application. [29:52.880 --> 29:53.880] Or it's just slow. [29:54.120 --> 29:56.780] So you want to give a little bit more buffer room there. [29:59.340 --> 30:03.060] So, oh, I'll show you just a little bit of the library for anybody who wants to program. [30:03.360 --> 30:04.500] And I'll talk about a little bit more. [30:04.680 --> 30:09.740] But this project started out as a library and has actually expanded into not having to code. [30:11.060 --> 30:12.380] Or program these devices. [30:12.660 --> 30:15.200] So this will be for the programmers out there who want to use the library. [30:15.340 --> 30:19.520] And then I'm going to talk about, for everybody else who doesn't program, I got you covered. [30:29.900 --> 30:31.580] So I'm not going to go through all of the code. [30:34.180 --> 30:36.200] Just looking at the header file real quick. [30:36.360 --> 30:37.960] So this is all you really need to leverage. [30:38.180 --> 30:40.840] And it's basically exactly what I've described so far. [30:42.760 --> 30:44.440] It's, yeah, you've got your... [30:44.830 --> 30:45.940] I want to run a binary. [30:46.180 --> 30:48.180] And it's just got it for the different operating systems. [30:48.460 --> 30:50.680] So here's all the Windows binary functions. [30:50.940 --> 30:52.120] This to run a script. [30:52.340 --> 30:53.120] To run a command. [30:53.680 --> 30:54.720] And to run the head script. [30:54.920 --> 30:56.580] And the all important red button. [30:56.820 --> 31:02.180] All you're doing is basically telling it where to put that file on the operating system. [31:02.200 --> 31:03.920] And where to read it off the SD card. [31:04.040 --> 31:05.440] And it takes care of everything else. [31:05.900 --> 31:07.040] Makes it very simple. [31:07.160 --> 31:08.300] All that's done in the background. [31:08.540 --> 31:10.460] Just say, hey, here's where the file is. [31:10.580 --> 31:12.060] Here's where I want you to load it on there. [31:12.400 --> 31:14.080] I would suggest the temp directory. [31:14.720 --> 31:16.140] And, you know, you're off and running. [31:17.300 --> 31:18.140] So that's it. [31:18.180 --> 31:19.720] That's the whole thing that you need to worry about. [31:19.840 --> 31:21.720] There's a bunch of code in the back end that makes it run. [31:22.020 --> 31:24.120] And does all that start menu stuff for you. [31:24.320 --> 31:26.220] But that makes it much more... [31:26.220 --> 31:27.280] much easier to use. [31:34.260 --> 31:35.280] So what can you do? [31:35.440 --> 31:36.880] We talked about different commands and stuff. [31:37.060 --> 31:38.720] And this is just the tip of the iceberg. [31:39.060 --> 31:41.180] Like, took two seconds to think of these things. [31:41.180 --> 31:44.920] So coming from a security perspective, you leverage stored credentials. [31:45.660 --> 31:50.480] So since you're on their system, say you want to log into their Twitter account and tweet something. [31:51.100 --> 31:51.800] You can. [31:52.000 --> 31:59.020] Because if their credentials are stored, you just go into their web browser, you type in twitter.com, and it says, oh, welcome, so-and-so. [31:59.160 --> 31:59.900] And you say, cool. [32:00.020 --> 32:02.460] And then you, you know, hit tab a couple times. [32:02.900 --> 32:04.580] And then you tweet. [32:05.540 --> 32:09.720] Because, you know, especially in the web interface, hitting tab goes to the next link or the next button. [32:10.040 --> 32:11.980] So you know what the interface looks like. [32:12.120 --> 32:12.860] So you just practice it. [32:12.920 --> 32:15.640] You say, tab, once, two, three, four, okay, five times. [32:15.880 --> 32:18.420] And that gets me into where I want to click go. [32:19.400 --> 32:19.500] Yeah? [32:19.820 --> 32:22.000] So what is the word Twitter also has keyboard no use? [32:22.260 --> 32:25.430] To do what? [32:25.630 --> 32:27.510] He said it has keyboard mapping to do what? [32:27.790 --> 32:30.940] Hit in the bar. [32:31.300 --> 32:37.040] Oh, so when you're in their website, if you hit in, and you're not connect, you're not clicking on anything, it'll open up the box? [32:37.240 --> 32:37.460] Yes. [32:37.960 --> 32:40.140] That, I'm glad I threw that as a random example. [32:40.280 --> 32:42.840] Because apparently it's even easier to do on Twitter. [32:44.860 --> 32:45.480] Thanks, Twitter. [32:46.480 --> 32:48.180] Okay, I should, that would have been a cool demo. [32:48.360 --> 32:49.660] I didn't even try that. [32:49.840 --> 32:51.120] But that's definitely doable. [32:51.300 --> 32:55.040] And that's even simpler than hitting tab through a couple times. [32:55.280 --> 32:57.440] But you're thinking about, do I have credentials stored? [32:57.600 --> 32:59.060] What do I have credentials stored for? [32:59.360 --> 33:03.500] You know, bank accounts, corporate information, and you need to be able to predict it. [33:03.640 --> 33:07.300] So living like a bank account, you, if you had one, you could go through the login process. [33:07.940 --> 33:12.800] Corporate internal resources, if it's something, a common internal resource, you could log into that. [33:13.420 --> 33:22.100] Other things you might, you know, their Facebook page, other things you might think they had to post, or steal information from and send it to yourself. [33:22.260 --> 33:24.140] There's a lot of things you can do when you're on the box. [33:24.640 --> 33:25.940] Download something from the web. [33:26.220 --> 33:31.520] So you can type in a URL that has the binary, the whole full path, and then, you know, download it that way. [33:31.840 --> 33:33.000] Add a user account. [33:33.820 --> 33:34.960] Set up a back door. [33:35.920 --> 33:38.980] You can set up a back door natively in almost all, in all of these. [33:39.520 --> 33:42.040] You don't need to download anything, really, to set up these back doors. [33:42.240 --> 33:45.920] And by back door, I mean, it's gonna connect out to you, or allow you to connect in. [33:46.080 --> 33:50.460] And the user, it wasn't a previously running service, or it's not supposed to act like that. [33:51.020 --> 33:53.580] You can reconfigure the, the system settings. [33:53.800 --> 33:55.740] It's way easier to do through the command line. [33:55.740 --> 33:59.460] I think point and click confuses me in Windows especially. [33:59.880 --> 34:03.000] It's nice to be able to go into a command and be able to change things. [34:03.360 --> 34:03.840] And you can. [34:04.380 --> 34:08.300] Most people don't know that, most people have never used the command prompt in Windows in their life. [34:08.520 --> 34:10.600] It is a lot easier to type in. [34:10.840 --> 34:13.620] You're typing in, like, ten characters, and you can add a user. [34:14.220 --> 34:21.500] Versus clicking around, trying to remember, oh, I want to go back to the classic settings, so I don't know how many things I have to click through to get to add user. [34:21.720 --> 34:23.660] And then you have to go through all these different steps. [34:23.660 --> 34:25.500] Yes, yes, that is a fine picture. [34:25.640 --> 34:26.160] I like that one. [34:26.280 --> 34:26.920] Add a new account. [34:30.380 --> 34:31.180] So, yeah. [34:31.580 --> 34:34.640] And then, of course, there's the classic RM-R-F star. [34:35.540 --> 34:36.640] So, what does that do? [34:38.460 --> 34:39.100] Bye-bye. [34:40.840 --> 34:43.360] I didn't do root, but, you know, where it's running from. [34:44.440 --> 34:48.020] So, the hardware platform I'm talking about, I'm calling the glitch. [34:48.640 --> 34:51.200] And this is my prototyping of it. [34:51.200 --> 34:52.400] So, it's tiny. [34:52.620 --> 34:55.500] And that's specifically designed to be that small. [34:56.420 --> 34:58.540] And this is performing all the stuff. [34:58.700 --> 35:02.140] You can see, this is the 3D printed case that I have for it. [35:02.400 --> 35:05.020] There's the little USB port, the micro SD slot. [35:05.160 --> 35:05.900] It's got the dip switches. [35:06.700 --> 35:09.260] Actually, I guess I should just go to the next slide and describe that. [35:09.760 --> 35:11.160] Because this is exactly what I'm talking about. [35:11.340 --> 35:16.200] So, the prototype is based on the TNC++, which is an Arduino compatible board. [35:18.100 --> 35:19.580] It's using an Atmel processor. [35:19.840 --> 35:22.140] So, again, we're looking at Arduino compatible projects here. [35:23.080 --> 35:26.320] Micro SD, dip switch, solderless pins. [35:26.740 --> 35:28.360] So, you don't have to solder it. [35:28.460 --> 35:30.160] The goal of this is not to... [35:30.160 --> 35:32.580] Well, I'll talk about some of the goals later on. [35:32.740 --> 35:35.740] But you want to be able to just plug in additional modules later. [35:35.940 --> 35:37.460] And it has the USB interface. [35:37.680 --> 35:42.560] So, obviously, when you're emulating keyboard, it's good to somehow be a normal-looking keyboard. [35:42.760 --> 35:45.040] So, this particular device goes in through USB. [35:47.940 --> 35:48.740] So, configuration. [35:49.400 --> 35:52.280] I mentioned before, like, they're self-encapsulated modules. [35:54.240 --> 35:57.080] The SD card, so these files are just plain text files. [35:57.200 --> 36:00.180] I'll probably come up with some sort of interface to generate it like the hid one. [36:00.360 --> 36:04.660] But this is just like, you know, you can open up a notepad and type it out for all these things. [36:04.980 --> 36:05.580] Right now. [36:05.700 --> 36:08.660] They'll be an easier point-and-click interface later on for people. [36:09.400 --> 36:10.120] Basic modules. [36:10.380 --> 36:14.020] You basically have... you have a configuration file that it reads in first. [36:14.240 --> 36:18.360] And it tells it, oh, I want to run this... this payload that I have is for Windows. [36:18.680 --> 36:19.660] And it's a Python file. [36:19.900 --> 36:20.960] So, okay, that's a Python. [36:21.160 --> 36:21.700] I'll run it accurately. [36:22.220 --> 36:23.600] I'll run it as a Python script. [36:23.780 --> 36:25.560] Or, hey, this is the hitty script. [36:25.740 --> 36:26.980] You can run it in this way. [36:27.200 --> 36:29.060] So, that's what the configuration file is. [36:29.100 --> 36:30.020] It's very tiny. [36:30.180 --> 36:31.760] It's a couple... it's a couple lines. [36:32.020 --> 36:33.180] So, you tell the operating system. [36:33.300 --> 36:34.000] You have a couple other things. [36:34.080 --> 36:35.320] You can set a delay. [36:36.260 --> 36:36.980] Which is... [36:36.980 --> 36:37.720] I'll talk about it now. [36:37.720 --> 36:40.920] The delay is important because the drivers install in, like, Windows. [36:41.240 --> 36:42.960] They just work natively in most other things. [36:43.080 --> 36:45.680] But generally, when Windows sees anything new, it tries to install drivers. [36:45.880 --> 36:47.780] So, you get that pop-up for a couple seconds. [36:48.000 --> 36:54.600] So, I like to set a delay in any time I'm going to be targeting a new system just for the drivers to set up. [36:55.140 --> 36:56.640] And then, from there on... [36:56.640 --> 36:58.640] Because the drivers... it should work right away. [36:58.800 --> 37:01.460] But it might get funky with how they set it up and whatever. [37:01.460 --> 37:02.500] So, I have a... [37:02.500 --> 37:03.520] There's a delay in there. [37:03.680 --> 37:07.580] There's some other options you can do to tell more about the configuration. [37:08.200 --> 37:09.000] But it is... [37:09.000 --> 37:10.420] It's very, very simple, very short. [37:10.860 --> 37:12.200] And a lot of it's optional. [37:12.940 --> 37:15.740] So, again, you can select modules on the fly. [37:15.980 --> 37:17.040] Right now, I have 32. [37:17.360 --> 37:19.480] You can select up to 32 different options. [37:21.180 --> 37:22.840] Which I think is a lot. [37:23.020 --> 37:25.020] And that's why I wrote the help option in there. [37:25.020 --> 37:27.320] Because remembering 32 different payloads is difficult. [37:27.620 --> 37:29.320] Most likely, you won't need that many. [37:29.520 --> 37:31.060] For whatever you're doing, you might need a couple. [37:31.560 --> 37:33.580] But, you know, that's what's on it right now. [37:33.680 --> 37:35.460] There's a lot of them there to select from. [37:38.060 --> 37:38.940] Alright, so... [37:40.560 --> 37:41.540] Demo number one. [37:44.000 --> 37:45.840] So, now I'm going to be demonstrating... [37:45.840 --> 37:53.940] So, there's the prototype of what it's going to look like and the prototype of what I have right now for just running these demos. [37:55.620 --> 37:57.820] So, I've got a couple demos that I'm going to run through. [37:58.160 --> 38:01.220] You're going to see how this works, you know, actively. [38:07.960 --> 38:10.700] So, the first one I'm going to do is Katana. [38:10.920 --> 38:11.960] Has anybody here used Katana? [38:12.840 --> 38:13.240] Yay! [38:13.480 --> 38:14.020] I wrote Katana. [38:14.520 --> 38:20.980] And you can see the difference between this one and the others is there's a little 3.0 up there. [38:22.120 --> 38:25.180] This is the new version that will be coming out soon. [38:25.180 --> 38:29.200] My goal is to do a beta release at Defcon. [38:29.740 --> 38:32.240] My goal, nobody hold me to that, but that's what I hope to. [38:32.240 --> 38:33.760] I'm very, very close to having it done. [38:33.960 --> 38:36.880] So, that's a sidebar and another project I'm working on. [38:37.300 --> 38:40.500] This is a multi-boot USB drive. [38:40.500 --> 38:42.260] So, it's all running off my flash drive. [38:42.400 --> 38:43.520] You can select from all of them and stuff. [38:45.420 --> 38:49.420] So, I'm going to try to use this. [38:53.350 --> 38:55.670] I decided, actually, I put these pins going out. [38:55.790 --> 39:00.570] They're going to pin, they're going to go in just to make it look a little bit better. [39:00.710 --> 39:04.070] And they actually fit underneath really well and you can still put stuff into it. [39:04.070 --> 39:05.650] But that's kind of what it looks like. [39:06.690 --> 39:08.230] This is, this is again, this is just for my demo. [39:08.430 --> 39:10.590] It's going to be much smaller than this. [39:23.780 --> 39:24.140] Okay. [39:24.300 --> 39:27.040] So, I have a delay set in the system right now. [39:27.260 --> 39:29.280] And actually, I had two delays. [39:29.420 --> 39:31.400] I had one built in to the software. [39:31.720 --> 39:34.860] And then I had the one that was configurable in the config file. [39:35.020 --> 39:36.440] And I have them both running. [39:37.640 --> 39:39.860] So, let's see if it starts up. [39:39.980 --> 39:41.580] It should take, it takes a couple seconds. [39:41.580 --> 39:42.620] Unfortunately. [39:43.240 --> 39:44.880] I should have reprogrammed it before. [39:45.800 --> 39:47.100] But, let's see. [39:48.440 --> 39:48.640] Oh. [39:49.300 --> 39:49.460] Huh. [39:50.260 --> 39:50.840] No. [39:52.800 --> 39:53.380] Okay. [39:53.560 --> 39:55.000] I'm going to try to plug in from the other side. [39:56.420 --> 39:57.120] Not good. [39:57.480 --> 39:58.820] So, I had it set on zero. [39:59.580 --> 40:00.780] What does zero do? [40:01.860 --> 40:02.440] Nothing. [40:03.700 --> 40:04.740] Best demo ever. [40:05.520 --> 40:05.810] Success. [40:06.660 --> 40:06.900] Success. [40:07.380 --> 40:08.580] That was the first demo. [40:09.620 --> 40:10.920] But it did nothing. [40:13.320 --> 40:14.380] I'll see you guys later. [40:16.280 --> 40:16.720] Okay. [40:25.840 --> 40:26.280] Oh. [40:26.800 --> 40:30.020] I'm so close to this VGA cable. [40:30.320 --> 40:31.440] I wish I had a cord. [40:31.480 --> 40:38.000] If anybody has a cord that's like a, just an extension, a USB extension cable, that would be good. [40:38.080 --> 40:41.020] Because I don't, I'm very nervous about this plugging in here. [40:42.520 --> 40:43.900] I had one earlier, but. [40:44.640 --> 40:45.080] Okay. [40:45.240 --> 40:45.960] So, now it's off. [40:47.800 --> 40:48.200] Sure. [40:48.520 --> 40:49.500] A little bit better. [40:50.500 --> 40:51.580] So, it's off and running. [40:51.760 --> 40:52.480] So, it just started up. [40:52.600 --> 40:53.360] And I, you know, I'm not. [40:53.640 --> 40:53.820] Thanks. [40:56.080 --> 40:56.480] Wee. [40:56.700 --> 40:58.000] So, okay. [40:58.340 --> 40:59.140] Leveraging this one. [40:59.340 --> 41:03.280] So, the idea for this attack is it's got to wait for backtrack to boot. [41:03.380 --> 41:03.940] So, it takes a little while. [41:03.940 --> 41:05.380] So, you're on site. [41:05.660 --> 41:07.060] You want to set up a back door. [41:07.360 --> 41:12.440] You walk into an unoccupied office that's got a computer sitting there, but it looks like that nothing's going on. [41:12.580 --> 41:14.660] You plug in your Katana flash drive. [41:14.980 --> 41:17.360] You plug in your glitch. [41:18.100 --> 41:19.940] You power off the machine if it's off. [41:20.040 --> 41:24.660] You put the, you push the power button and you turn off the monitor and you walk away. [41:25.260 --> 41:28.100] And then everything else happens like this. [41:28.320 --> 41:33.240] So, that's your 15, 20 seconds inside the room and then you've walked away. [41:33.480 --> 41:35.720] So, it's going to boot into... [41:35.720 --> 41:36.920] I'm using backtrack here. [41:38.160 --> 41:39.100] So, it's Katana. [41:39.260 --> 41:40.220] It's booting into backtrack. [41:40.240 --> 41:44.780] You could do this just with a backtrack live CD or a backtrack flash drive for this particular demo. [41:46.740 --> 41:47.620] Oh, no. [41:47.620 --> 41:48.680] This is going to be hard. [41:49.700 --> 41:52.500] The problem is that it's not full screen and I don't want to... [41:54.400 --> 41:54.800] No. [41:56.140 --> 41:57.040] I'm starting over. [42:00.860 --> 42:02.500] It's, it's not worth, I can... [42:11.600 --> 42:13.040] No, I don't care about that anymore. [42:29.600 --> 42:31.300] Let's just take a second to restart up. [42:31.360 --> 42:36.380] So, I'm actually booting in VirtualBox off my flash drive, which is super cool. [42:36.840 --> 42:39.000] I was really psyched when I found out I could do that. [43:02.870 --> 43:03.270] Okay. [43:03.490 --> 43:04.990] Now, when it full screens, it should be good. [43:04.990 --> 43:07.750] The problem is like the boot menu is really small and then it gets full screen. [43:07.910 --> 43:09.890] I had to change the resolution and blah, blah, blah. [43:10.150 --> 43:13.370] So, if this starts, we should be good because it should be able to see the whole screen. [43:13.830 --> 43:14.150] What I... [43:14.150 --> 43:18.710] The reason I pulled it out is everything it typed in was going to be below the viewing area. [43:20.230 --> 43:20.550] Okay. [43:20.690 --> 43:22.130] So, I got halfway through what I was saying. [43:22.770 --> 43:23.930] You have the Dropbox. [43:24.110 --> 43:24.390] You've got it. [43:24.570 --> 43:24.810] It's going to... [43:24.810 --> 43:27.150] It's going to SSH back to you. [43:30.370 --> 43:30.730] Okay. [43:30.970 --> 43:31.030] Whew. [43:32.530 --> 43:34.750] Seen enough blank screens so far today. [43:36.650 --> 43:38.610] Well, that was going to be my filler while it booted. [43:38.670 --> 43:41.930] So, now I have to wait for it to actually finish booting. [43:42.010 --> 43:44.970] So, there was no good way to make it boot any further. [43:45.150 --> 43:47.810] So, but when it does boot, we're going to see some awesomeness. [43:47.810 --> 43:51.850] So, but, you know, you could do all kinds of stuff here. [43:52.050 --> 43:52.470] I'm just... [43:52.470 --> 44:02.110] This particular demo was just trying to leverage adding, you know, getting into the box really quickly and, you know, creating this back door. [44:04.830 --> 44:06.310] So, song and dance. [44:07.870 --> 44:08.310] Yeah. [44:08.390 --> 44:09.050] Good time for questions. [44:09.170 --> 44:09.470] Thank you. [44:12.230 --> 44:17.690] So, the documentation says it can type 500 keys a second for this library. [44:19.050 --> 44:21.090] But the operating systems do not handle it. [44:21.170 --> 44:23.050] Especially when you're going through a virtual machine. [44:23.650 --> 44:24.670] I had a lot... [44:24.670 --> 44:29.670] I spent a lot of time figuring out that I had to delay a lot more in the virtual machines because of the pass-through and stuff. [44:30.950 --> 44:32.250] So, it's hard to say. [44:32.450 --> 44:33.270] And you generally... [44:33.270 --> 44:34.170] It buffers up. [44:34.810 --> 44:35.190] 10 minutes. [44:36.510 --> 44:37.490] I had an idea. [44:37.670 --> 44:44.250] You were saying that it was difficult to copy over a binary or doing it in Pax and then converting it to a binary. [44:44.610 --> 44:44.910] Okay. [44:45.070 --> 44:45.270] Sorry. [44:45.490 --> 44:46.030] I'll cut you off. [44:46.210 --> 44:47.330] So, it's generating a password. [44:47.330 --> 44:48.630] I'll get to you later. [44:48.830 --> 44:49.150] I apologize. [44:49.670 --> 44:50.830] Generating an SSH key. [44:52.450 --> 44:53.550] Starting the service. [44:55.970 --> 44:57.230] There's delays involved. [44:57.430 --> 44:58.010] It's hard to predict. [44:58.370 --> 45:00.850] And now it's creating a back door to my computer. [45:01.110 --> 45:04.490] It says, yes, I would like to accept that RSA key. [45:04.750 --> 45:06.770] And now it's asking for a password. [45:07.070 --> 45:07.770] What's my password? [45:08.230 --> 45:09.070] You know my password? [45:09.270 --> 45:09.570] Yay! [45:09.850 --> 45:10.850] You're connected to my box. [45:10.850 --> 45:12.590] So, let's see if I can connect into you. [45:25.110 --> 45:25.590] Oh. [45:26.170 --> 45:27.050] Not the right terminal. [45:30.630 --> 45:31.110] Oh. [45:31.530 --> 45:31.810] Hold on. [45:43.500 --> 45:43.980] Yay! [45:48.700 --> 45:50.480] I got out of your network. [45:51.420 --> 45:54.020] I'm connected back to me through SSH. [45:54.240 --> 45:55.620] So, this is not... [45:55.620 --> 45:56.660] You know, normally you think you're going in. [45:56.760 --> 45:57.700] This is reverse back. [45:57.860 --> 46:00.800] It connected to my computer from inside somebody else's network. [46:01.000 --> 46:05.700] And now I'm able to connect through one of my local ports to that remote box and control it completely. [46:06.250 --> 46:12.140] So, I am sad that I have 10 minutes because I had a lot of other cool demos to do. [46:13.660 --> 46:14.060] What? [46:18.210 --> 46:18.610] Yeah. [46:19.070 --> 46:19.470] Yeah. [46:25.470 --> 46:26.510] I'm going to do the second one. [46:26.750 --> 46:27.670] I'm going to skip the third one. [46:29.130 --> 46:30.110] Or do the... [46:30.110 --> 46:30.170] Sorry. [46:30.330 --> 46:31.710] Skip the... [46:31.710 --> 46:31.730] Let's see. [46:35.690 --> 46:36.090] Darn... [46:36.090 --> 46:36.670] Darn... [46:36.670 --> 46:36.890] Darn... [46:37.450 --> 46:37.930] Thank you. [46:37.970 --> 46:39.050] Are you selling kits for this? [46:39.650 --> 46:40.050] Yeah. [46:40.310 --> 46:41.810] I'm going to cover that at the end. [46:42.030 --> 46:42.670] So, I'll talk about it. [46:42.750 --> 46:43.350] It's like how to... [46:43.350 --> 46:44.350] How to... [46:44.350 --> 46:44.530] Use it. [46:47.370 --> 46:49.250] It's like a stupid word on the Internet. [46:49.510 --> 46:50.670] It's not the Internet. [46:52.990 --> 46:54.050] Or you'd have to be on it. [46:58.120 --> 46:58.860] Also, yes. [47:00.360 --> 47:01.900] And yes, the thing that works. [47:05.480 --> 47:05.860] Oh. [47:25.710 --> 47:27.130] Here we have our pretty files. [47:28.890 --> 47:29.710] Now we're going to wait. [47:29.970 --> 47:30.810] So, this one... [47:30.810 --> 47:31.450] I'm going to skip... [47:31.450 --> 47:32.450] I didn't go back to my slides. [47:32.610 --> 47:34.730] This one was called, Where's My Money? [47:35.050 --> 47:40.610] And the idea is that your roommate or cohabitant owes you for the rent. [47:40.850 --> 47:42.490] And you want to punish them. [47:42.630 --> 47:43.910] And you want your rent money. [47:44.390 --> 47:44.890] So... [47:48.320 --> 47:48.820] Oh! [47:53.720 --> 47:54.600] What happened? [47:55.000 --> 47:55.760] Oh, crap. [48:11.230 --> 48:13.150] It'd be nice to know when you're running up here. [48:15.310 --> 48:15.810] Ah! [48:17.570 --> 48:18.450] So close. [48:18.450 --> 48:19.950] I need two of them. [48:30.940 --> 48:32.060] I'm the fail here. [48:33.140 --> 48:33.960] I'm the fail. [48:34.160 --> 48:34.920] That works right. [48:35.060 --> 48:35.780] I failed. [48:35.920 --> 48:36.500] I failed it. [48:38.160 --> 48:41.460] So, I'm going to speed through the rest of my slides after this. [48:42.040 --> 48:42.580] Yeah, wow. [48:42.720 --> 48:44.380] I had a lot more to show. [48:45.300 --> 48:50.140] So, I'm going to be at the Hackers for Charity booth most of the weekend and would love to talk to people about this. [48:50.540 --> 48:51.400] Come on. [48:52.560 --> 48:52.960] Okay. [48:53.200 --> 48:53.300] Good. [48:53.800 --> 48:55.320] So, they owe you money. [48:55.440 --> 48:56.360] What do you want to do against them? [48:56.420 --> 48:57.960] We want to download this batch script. [48:58.800 --> 48:59.720] What does it do? [49:00.360 --> 49:01.580] It runs very quickly. [49:03.480 --> 49:06.060] And you're not going to see the code, but I'm going to tell you what it does. [49:07.340 --> 49:10.700] So, now it's going to go to the download directory that it downloaded the file in. [49:11.360 --> 49:12.300] It's going to run it. [49:13.360 --> 49:14.720] It runs it very quickly. [49:15.880 --> 49:16.960] What are those files doing? [49:16.960 --> 49:18.380] Oh, you didn't see it real quick. [49:18.520 --> 49:19.520] Let me tell you what they did. [49:21.440 --> 49:22.680] Oh, my files are gone. [49:22.800 --> 49:23.460] Where did they go? [49:24.420 --> 49:25.120] They're hidden. [49:25.420 --> 49:27.180] And I wrote 13 the name. [49:30.060 --> 49:32.980] So, the script, it's a batch script that I wrote. [49:33.140 --> 49:34.980] And it wrote 13 and hides the name. [49:35.100 --> 49:36.340] So, they're like, you deleted everything. [49:36.540 --> 49:37.520] No, not quite. [49:45.590 --> 49:46.810] What the what is that? [49:47.350 --> 49:49.630] Well, I have the .13 extension. [49:49.850 --> 49:52.170] I wrote 13 the name and the extension. [49:52.610 --> 49:56.530] So, if you don't know what you're doing, Windows is never going to let you run those files again. [49:57.390 --> 50:01.350] I have a reverse that I can do, but that's obviously when they've paid their rent. [50:07.220 --> 50:07.580] Okay. [50:07.720 --> 50:08.560] So, this is going to be tough. [50:08.680 --> 50:09.320] I'm going to go through this. [50:09.420 --> 50:10.620] Oh, I finished these demos. [50:10.820 --> 50:12.240] My power went out the night before. [50:12.240 --> 50:14.260] So, I did most of these demos by candlelight. [50:15.900 --> 50:17.020] So, I covered that. [50:17.140 --> 50:17.660] I'm going to skip it. [50:17.700 --> 50:18.460] I apologize for this. [50:18.620 --> 50:21.460] The library is up online right now. [50:22.280 --> 50:24.140] My project page, you'll see at the end. [50:24.140 --> 50:26.140] I have a lot of slides I've got to go through. [50:26.540 --> 50:27.880] So, let's play hide the glitch. [50:29.220 --> 50:30.040] Computer mouse. [50:30.500 --> 50:31.240] That's right. [50:31.480 --> 50:32.680] My friendly computer mouse. [50:34.180 --> 50:34.820] Excuse me. [50:34.840 --> 50:39.440] I should say my fully functional, still fully functional computer mouse. [50:40.100 --> 50:42.980] Questions are going to be held to the end because I have like 35 seconds. [50:43.260 --> 50:43.960] Building it. [50:44.080 --> 50:45.600] This is a USB hub. [50:46.200 --> 50:47.600] Took some parts apart. [50:47.820 --> 50:48.480] Soldered it together. [50:48.840 --> 50:49.980] Took it apart there. [50:50.200 --> 50:50.780] Plug it in. [50:51.520 --> 50:52.860] So, I'm going through this quickly. [50:53.600 --> 50:54.900] So, this is the end result. [50:55.060 --> 50:56.940] And I plug it into that micro USB port. [50:58.300 --> 50:59.100] Stick it in there. [50:59.280 --> 50:59.980] Close the lid. [51:00.080 --> 51:00.900] It's a working device. [51:00.900 --> 51:03.040] And it will wait however long I want to inject the keys. [51:04.340 --> 51:07.160] So, I took about everything in my house to hook up to a computer. [51:08.560 --> 51:09.740] It fits in a keyboard. [51:09.960 --> 51:10.900] It fits in a USB drive. [51:11.240 --> 51:13.660] If it's in your desktop, you have those little pin ports inside. [51:13.660 --> 51:14.500] Wa-bam! [51:17.680 --> 51:18.320] This is... [51:18.320 --> 51:19.660] Obviously, the hard drive is gone. [51:23.110 --> 51:25.490] So, the hard drive is gone. [51:25.690 --> 51:28.170] But I was like, what can I use as an enclosure that's just around? [51:28.350 --> 51:30.530] Because I took that out and that's the hard drive in my laptop. [51:30.770 --> 51:33.970] Because it was cheaper to buy an external hard drive than an internal one. [51:34.310 --> 51:36.290] And they're the exact same thing with a little adapter. [51:36.830 --> 51:37.770] I can't rant too much. [51:37.790 --> 51:38.510] I have to work quickly. [51:38.990 --> 51:41.430] Then I got bored and I decided, well, I want to update it a little bit. [51:41.530 --> 51:44.230] So, I added a micro SD card reader in it as well. [51:44.230 --> 51:45.230] So, everything... [51:45.230 --> 51:48.150] That katana attack I showed you, that will run from this mouse. [51:50.750 --> 51:51.570] So, okay. [51:51.690 --> 51:52.850] Once we're on the payload. [51:53.070 --> 51:55.290] The one thing that I'm going to add is it'll run once. [51:55.470 --> 51:56.790] So, it'll run that one time. [51:56.930 --> 51:57.570] And then every time that... [51:57.570 --> 52:00.010] Subsequently that it's rebooted, it will not run. [52:00.150 --> 52:01.370] So, you have that one shot. [52:01.490 --> 52:06.190] And then they're not going to see it, you know, acting weird every time when you're trying to attack them. [52:06.810 --> 52:08.350] Goals of the project of the glitch. [52:08.530 --> 52:11.350] So, this is only one component of this project that I'm working on. [52:11.430 --> 52:12.290] It was kind of the baseline. [52:12.290 --> 52:18.070] But the goals of the glitch hardware project is to provide a hardware security testing. [52:18.470 --> 52:22.670] So, not testing hardware, but leveraging these open hardware projects for the masses. [52:23.030 --> 52:24.910] So, you don't have to solder it yourself. [52:25.270 --> 52:26.270] You can just... [52:26.270 --> 52:27.550] You know, you'll get it. [52:27.630 --> 52:29.950] And you'll be able to configure it very quickly and easily. [52:30.430 --> 52:30.970] No coding. [52:31.350 --> 52:32.810] Or, you know, scripting maybe a little bit. [52:33.070 --> 52:34.450] Configuration, but no coding. [52:34.990 --> 52:36.110] No hardware use. [52:36.230 --> 52:38.110] You're going to be plugging everything in. [52:38.210 --> 52:38.710] Two minutes. [52:39.170 --> 52:40.330] Some projects I'm working on. [52:40.490 --> 52:41.730] I've got a key logger working. [52:42.670 --> 52:46.350] So, the key logger will record keys in the same manner that the script works. [52:46.390 --> 52:48.550] So, you can record them and then replay them. [52:48.750 --> 52:49.830] Exactly the same way. [52:50.050 --> 52:51.950] So, this is working pretty well. [52:53.030 --> 52:55.150] I'm going to do more with wireless. [52:55.150 --> 52:58.230] I have RFID as my next thing that I want to add to it. [52:58.410 --> 53:00.090] So, that I can test the security. [53:00.310 --> 53:03.430] Leveraging this device with RFID and some Bluetooth and maybe Wi-Fi. [53:03.930 --> 53:05.470] Do like audio, video recording. [53:05.590 --> 53:08.810] It depends on where the other projects that I find to add onto here. [53:08.950 --> 53:09.770] But more with a... [53:09.770 --> 53:11.990] It's more of a security standpoint. [53:13.270 --> 53:14.370] The HOPE workshop. [53:14.790 --> 53:16.150] You're asking if we can get one. [53:16.250 --> 53:20.090] I'm going to be doing a workshop tomorrow on the 6th floor at 1 o'clock. [53:20.850 --> 53:25.010] It's going to be $100, but the proceeds are going to benefit Hackers for Charity. [53:26.050 --> 53:27.470] There's only 25 slots. [53:27.670 --> 53:31.150] So, I'll be at the Hackers for Charity booth tomorrow morning and throughout the day. [53:31.370 --> 53:34.110] If you want to buy the kits from me before, you know, they sell out. [53:34.230 --> 53:34.990] We'll do the workshop. [53:34.990 --> 53:35.630] We'll build it. [53:35.950 --> 53:40.190] As I went really quickly here, we'll have more time and we can talk about how these injections work. [53:41.890 --> 53:44.550] And I'm trying to make the glitch a hardware reality. [53:44.770 --> 53:46.950] So, right now, I have to solder a lot of stuff together. [53:47.150 --> 53:48.810] I'm trying to actually build one. [53:48.930 --> 53:53.930] So, I'm going to be using Kickstarter, which is an awesome website for kind of starting your own projects. [53:54.650 --> 53:55.750] There are various levels. [53:56.850 --> 53:59.170] The lowest levels, I made the glitch, which is just a sticker. [53:59.370 --> 54:00.190] It's going to cost like $10. [54:00.710 --> 54:04.210] And then you have levels up where you're going to buy one or you're going to buy with the keylogger. [54:04.370 --> 54:09.170] Or a couple of people are going to be able to buy one with modified keyboards and modified mice. [54:10.110 --> 54:11.330] Two glitches and a logger. [54:11.430 --> 54:13.650] And it's like the complete bundle version of it. [54:13.770 --> 54:15.570] But I'm hand-making the keyboard and mouse. [54:15.650 --> 54:16.910] There's only a couple of those available. [54:16.910 --> 54:20.430] The first 25 people that sign up will get the case. [54:20.750 --> 54:22.510] The Kickstarter page is not up. [54:23.070 --> 54:24.570] It'll be up early next week. [54:24.750 --> 54:26.110] I got the approval stuff. [54:26.670 --> 54:27.630] I'm waiting on... [54:27.630 --> 54:27.890] Yeah. [54:28.290 --> 54:29.850] So, there's a lot of steps you have to go through. [54:30.230 --> 54:31.750] I've got confirmed for a lot of stuff. [54:31.850 --> 54:32.510] I just need... [54:32.510 --> 54:33.270] I just came here. [54:33.430 --> 54:34.350] I had to get here. [54:34.490 --> 54:36.270] So, it'll be up. [54:37.330 --> 54:39.530] That's the website to check out. [54:39.690 --> 54:40.830] That's the QR code for it. [54:40.870 --> 54:44.890] That's the project page for on SourceForge that I will be using for the code here. [54:44.890 --> 54:49.510] The hideous stuff can be downloaded at my website, hackfromacave.com. [54:50.630 --> 54:51.850] That's my Twitter account. [54:52.130 --> 54:58.730] I'll be at the Hackers for Charity booth for the rest, on and off, while I'm not teaching the class. [54:59.610 --> 55:00.090] I'll take the... [55:00.090 --> 55:00.290] Okay. [55:00.430 --> 55:00.630] Stop. [55:00.870 --> 55:01.430] She said stop. [55:01.530 --> 55:02.110] And it says thanks. [55:02.310 --> 55:03.430] So, that's the end. [55:05.270 --> 55:05.870] Thank you. [55:05.990 --> 55:06.270] Thank you. [55:12.210 --> 55:12.610] Yeah. [55:13.070 --> 55:13.370] Yeah. [55:13.510 --> 55:14.510] I'm going to do questions. [55:14.690 --> 55:17.250] I'll be at the Hackers for Charity booth in like 10 minutes, which is down. [55:17.410 --> 55:18.670] You can go upstairs in the hardware hacking area. [55:18.690 --> 55:18.730] You can go upstairs in the hardware hacking area.