Kautilya is a toolkit which provides various payloads for a Human Interface Device which may help in breaking in a computer during penetration tests.
Payloads列表
Windows
获取类
- 获取信息
- Hashdump and Exfiltrate
- 键盘记录
- 嗅探
- WLAN Keys导出
- 获取目标证书
- 导出LSA秘钥
- Dump passwords in plain
- 拷贝SAM
- 导出内存数据
- Dump Windows Vault Credentials
执行类
- sethc 和Utilman 后门
- 定时执行payload
- Http 后门
- DNS txt 后门
- 无线AP
- Tracking Target Connectivity
升级类
- 移除升级
- 强制浏览
管理类
- 添加管理员
- 更改默认DNS服务器IP
- 编辑Hosts 文件
- 添加一个可用的RDP用户
- 添加一个可用的Telnet用户
- 添加一个可以远程powershell的用户
其他
- 浏览并接受Java Applet签名
- Speak on Target
Linux
- Download and Execute
- Reverse Shells using built in tools
- Code Execution
- DNS TXT Code Execution
- Perl reverse shell (MSF)
OSX
- Download and Execute
- DNS TXT Code Execution
- Perl Reverse Shell (MSF)
- Ruby Reverse Shell (MSF)
用法:
运行kautilya.rb,更具Kautilya的提示选择相应菜单,然后生成payload到Kautilya的目录。
生成的payload需要在Arduino IED中编译,然后上传到teensy。
支持的设备(Human Interface Devices)
In principal Kautilya should work with any HID capable of acting as a keyboard. Kautilya has been tested on Teensy++2.0 and Teensy 3.0 from pjrc.com. Updates about Kautilya can be found most of the times at my blog http://labofapenetrationtester.com/ and google group.
相关文章
A five part blog post on my blog could be useful for those new to HID and Kautilya:
Part 1: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers.html
Part 2: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_04.html
Part 3: http://labofapenetrationtester.blogspot.in/2012/04/teensy-usb-hid-for-penetration-testers_25.html
Part 4: http://labofapenetrationtester.blogspot.in/2012/05/teensy-usb-hid-for-penetration-testers.html
Part 5: http://labofapenetrationtester.blogspot.in/2012/09/usb-hid-for-pen-testers-part5.html
All posts related to Kautilya http://www.labofapenetrationtester.com/search/label/Kautilya
HID(Human Interface Devices)攻击当前不流行,但是攻击方式新颖,实用性很高,危险系数应该还是比较高的,值得研究。
百度盘下载: http://pan.baidu.com/s/1i3wwfXj
github下载: https://github.com/samratashok/Kautilya