Introducing the Bash Bunny - Hak5 2125

Поділитися
Вставка
  • Опубліковано 10 лют 2025
  • Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:
    ____________________________________________
    Hop on over to www.bashbunny.com to grab your Bash Bunny!
    RSVP to our launch event: goo.gl/forms/3...
    Hit up www.hackacrosst... to find out where we’re heading next!
    Find out more about the Bash Bunny at www.bashbunny.com/
    -------------------------------
    Shop: www.hakshop.com
    Support: / threatwire
    Subscribe: / hak5
    Our Site: www.hak5.org
    Contact Us: / hak5
    Threat Wire RSS: shannonmorse.p...
    Threat Wire iTunes: itunes.apple.c...
    ------------------------------
    ~-~~-~~~-~~-~
    Please watch: "Bash Bunny Primer - Hak5 2225"
    • Bash Bunny Primer - Ha...
    ~-~~-~~~-~~-~
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.

КОМЕНТАРІ •

  • @ChristAlmightyJesus
    @ChristAlmightyJesus 8 років тому +328

    Elliot better have this in the next season.

    • @Jeffiechan
      @Jeffiechan 8 років тому +11

      But there aren't any computers in Fillory

    • @DrewryPope
      @DrewryPope 8 років тому +2

      Hack the telephones

    • @Cpgeekorg
      @Cpgeekorg 8 років тому +2

      this was my first thought as well ;)

    • @Blakhawk1703
      @Blakhawk1703 8 років тому +3

      Not Elliot From Fillory, the Elliot from Mr. Robot. lol

    • @GabREAL1983
      @GabREAL1983 7 років тому

      are you srsly smoking a bong on your avatar pic HAHA

  • @aortizc82
    @aortizc82 8 років тому +43

    This is totally going to appear in Mr Robot Season 3.

  • @JonesAndGriesmann
    @JonesAndGriesmann 8 років тому +83

    This is beyond evil. I need one.

    • @fahadalkamli
      @fahadalkamli 8 років тому

      HHHHHH

    • @mr.impian2733
      @mr.impian2733 6 років тому

      Hey guys i'm Indonesia

    • @Blue-we5sm
      @Blue-we5sm 4 роки тому

      66 likes, lets keep it that way :)

    • @PNCNDNOB
      @PNCNDNOB 4 роки тому

      @@mr.impian2733
      Wow! A country on the interwebzz

    • @user-hy2ry3if8h
      @user-hy2ry3if8h 3 роки тому

      @@mr.impian2733 Where is Donesia? sorry - I had to ;p

  • @whollymindless
    @whollymindless 8 років тому +34

    "I heard a great disturbance in the force, as if millions of IT drones had massive coronaries..."

  • @greedsin555
    @greedsin555 8 років тому +15

    Awwwwww Darren looks like a proud dad (23:22 - 23:39)

  • @ShannonMorse
    @ShannonMorse 8 років тому +381

    first

    • @epicguitar1602
      @epicguitar1602 8 років тому

      Lol, friggin troll machine

    • @theboffin2474
      @theboffin2474 8 років тому +2

      I kek'd so hard at the bunny glasses

    • @tedmosby9409
      @tedmosby9409 8 років тому

      hay snubs

    • @RuleC
      @RuleC 8 років тому

      .

    • @SilvianDragan
      @SilvianDragan 8 років тому

      Shannon Morse this is the best thing I've ever seen. I love you guys! Keep up this amazing work. :)

  • @animalitosynaturaleza8769
    @animalitosynaturaleza8769 5 років тому +1

    Muchas gracias chicos, Por tanto esfuerzo. Y por hacer que la emoción llegue hasta los que no sabemos. Estoy contento por probarlo en mis equipos. A ver se lo consigo😅

  • @PosiP
    @PosiP 8 років тому

    Thanks for the update on Bash Bunny. Just picked one up, can't wait to start hopping with the Bunny.

  • @BuddyJesus
    @BuddyJesus 8 років тому +3

    Awesome, and I was over here simply wanting a way to have multiple payloads on one USB. Awesome work!

  • @digitaltinker7813
    @digitaltinker7813 8 років тому +21

    I think you missed your chance to put a rabbit's foot on the key ring. /s With the logic of bash though, This seems like a good tool for IT automation as well in places that don't have better network managed tools for common tasks. Knowing common issues and having a library of scripts to fix them that I can plug into any machine, have it know the OS and the exact steps to fix would be amazing. I would also assume you could set up detection and have Switch 1 change what Switch 2 would do.

    • @IncendiarySolution
      @IncendiarySolution 8 років тому +1

      Adam Morgan Tech support on a keyring

    • @hak5
      @hak5  8 років тому +7

      Absolutely. Consider that you have both a DHCP server and TFTP server. There's PXE potential here :) ~Darren

  • @JHarkness80
    @JHarkness80 8 років тому +1

    So excited for the Bash Bunny, another awesome tool from those smart guys at Hak5!
    Mine is going to be here tomorrow and I cant wait to play!
    The Bunny is going to become the goto Swiss Army Knife for Pentesters...

  • @makezi7
    @makezi7 8 років тому +5

    my most favorite episode. I love you two!

  • @Jeffreysuper61McELroy
    @Jeffreysuper61McELroy 8 років тому

    just ordered one. gotta add this to my bag of tricks. love all your hard work and products!!

  • @RRASGUYS
    @RRASGUYS 8 років тому +4

    Darren and Seb are legendary. This is insane!!!!!!

  • @brianchandler3346
    @brianchandler3346 7 років тому

    Not sure if anyone has posted this yet, but as for the boot time, if there's enough room, you could squeeze in a small rechargeable battery, pre-charge it, boot it in your pocket, and the connect in hot. Then boot could suck and the vector could be hit as soon as you can get it in the jack.

  • @NateCrownwell
    @NateCrownwell 8 років тому +1

    Great episode Darren and Shannon! You guys are so awesome!

  • @ahut10
    @ahut10 8 років тому

    yay just purchased mine, can't wait to see what the community develops. yay thank you HAK5

  • @skiddietech3654
    @skiddietech3654 8 років тому

    This is nuts, already got my head titling all possible degrees. Preorder complete.

  • @magneto417x
    @magneto417x 8 років тому

    Loving this little Bunny. I ordered mine. You guys are awesome!!!

  • @fsevilla1
    @fsevilla1 8 років тому

    couldn't wait so had to order.
    like always. you're tools are the best. thanks

  • @Corvid117
    @Corvid117 8 років тому

    I'M SO EXCITED!! I want to learn so much more about this! Please more vidzzzz!!

  • @TechnomancerTheWise
    @TechnomancerTheWise 8 років тому

    Buying one right now, you guys are my hero

  • @st00ch
    @st00ch 8 років тому +3

    I've never seen Darren so excited.

  • @smokingiscool599
    @smokingiscool599 8 років тому

    This is probably the most cyberpunk infomercial ever. 10/10

  • @SteveJones172pilot
    @SteveJones172pilot 8 років тому +1

    Had to order TWO while watching video.. Can't wait!

  • @a2ashraf
    @a2ashraf 8 років тому

    Wow, just wow. There is much potential with Bash + trust.

  • @Agent_Orange_Peel
    @Agent_Orange_Peel 8 років тому +1

    This looks awesome! Hope more videos on it are coming.

  • @frankescu
    @frankescu 7 років тому

    The make it look way more exiting than it actually is. Like in an informercial. I guess this is an infomercial.

  • @pmc3027
    @pmc3027 8 років тому +24

    WAIT A MINUTE... DID I SEE THAT YOU CAN UPLOAD THE PAYLOADS AS .TXT?!?!?!?!?!? SUCH EASE

    • @hak5
      @hak5  8 років тому +38

      The idea is to be ridiculously convenient. We've gone as far as to even make it compatible with the ASCII files that Windows notepad makes regardless of its awkward carriage returns. ~Darren

    • @ericmin6055
      @ericmin6055 7 років тому

      Hi Darren

  • @rayerdinc2441
    @rayerdinc2441 8 років тому +1

    Hi Both, great video as usual, however, I am new to this stuff so learning and making a decision as to what kit to buy. I am gong to for the nano tact kit but then which one between bash bunny, lan turtle or ducky. While you briefly mention the "difference" between these three tools, could please explain in a little ore detail or even a video as to which may useful or why may need all three, please. I just find this stuff so interesting and want to experiment once I get the tools. Thank you.

  • @neoninsv
    @neoninsv 8 років тому +1

    At the 11:07 mark, we get a tip from Darren that the Bash Bunny also works as an Ecto-Containment System. Perfect for catching those pesky ghost images.

  • @jmortproductions8704
    @jmortproductions8704 8 років тому

    Ever since I saw the release i couldn't wait till this came out and when i did it was the most amazing thing i have ever saw awesome job guys.

  • @carlwcampbell
    @carlwcampbell 8 років тому +2

    03:55 - One must have nerves of steel, to pull that off. No mercy

  • @hiehavoc
    @hiehavoc 8 років тому

    already ordered. great work.

  • @scriptkiddie2677
    @scriptkiddie2677 7 років тому +1

    JUST GOT ONE IN MY HANDS SO HAPPY!!

  • @PyraxV
    @PyraxV 8 років тому +1

    I just bought the elite field kit ughhh. I wish this came with it!

  • @DJZofPCB
    @DJZofPCB 8 років тому

    I think I will read the support forums and see just how smooth the ride is for others. Always research a products performance based on end user experiences and not the ADVERTISEMENT.

    • @hak5
      @hak5  8 років тому

      Absolutely. Feel free to check out our forums at: forums.hak5.org/index.php?/forum/92-bash-bunny/ where the developers have been actively helping out new users.

  • @pmc3027
    @pmc3027 8 років тому +28

    anyone else stay up just to watch this? also can you do giveaways plz

  • @PosiP
    @PosiP 8 років тому

    Got my Bunny and the new stickers. Much love to Hak5

  • @vincviertytaccount2608
    @vincviertytaccount2608 8 років тому +10

    SHUT UP AND TAKE MY MONEY! Oh, you already did... SHUT UP AND TAKE MY MONEY AGAIN (cwl)

  • @kewis07
    @kewis07 8 років тому

    I RSVP'd for tonight and I can't make it 😭
    ...I wish I was going to be there to witness greatness with everyone. Can't wait to get my hands on one, Have fun!

  • @russwickless7332
    @russwickless7332 8 років тому +1

    Just ordered mine!

  • @lebouski
    @lebouski 8 років тому

    i love looking at you guys

  • @MindMeetMaker
    @MindMeetMaker 8 років тому

    You should definitely make a NTC Pocket Chip type screen keyboard peripheral for the bash bunny that would be sweet. Great work crazy cool hardware love it.

  • @limpopo171
    @limpopo171 8 років тому

    very cool indeed, crazy what you came with i had a fought in my had if this is what you can do what is out there that government has in possession to use. It is a next level device for shore.

  • @richf69
    @richf69 5 років тому

    Thumbs up 5 seconds into the video just for the bunny glasses.

  • @Braedley
    @Braedley 8 років тому

    So I don't work for a bank, but I do work for a company where I need to store sensitive data on my computer, and where my computer has implicit trust on the network for access to sensitive data stored on the network. It's been ingrained in me to lock my work computer whenever I get up from it, like the employee at the bank should have been doing in the clip shown. Locking a computer isn't the be all and end all (a LAN Turtle can still attack a locked computer), but it quickly and easily cuts down on the attack vectors available.

  • @jotto917
    @jotto917 8 років тому +14

    I want to trust my technolust... but its telling me to buy twelve and somehow I think thats overkill >.

  • @IanKen
    @IanKen 8 років тому

    Awesome can't wait to get one

  • @ThatNateGuy
    @ThatNateGuy 8 років тому

    You flip the switch and it does The Thing!

  • @WA4OSH
    @WA4OSH 7 років тому

    Sounds like an essential component of a Hacker EDC (Everyday Carry Kit) ;)

  • @caseysutherland
    @caseysutherland 8 років тому

    Ordered! Oh the places we will go.... :D

  • @MidnightCoup
    @MidnightCoup 8 років тому

    This is dope af Darren - getting one for sure

  • @MauricioFernandezF
    @MauricioFernandezF 7 років тому

    You guys continue to be the best.

  • @AJMansfield1
    @AJMansfield1 7 років тому

    All you need now is to stick a wifi chipset on the thing, so it can be left in place and exfiltreate/controlled remotely.

  • @ByDesignation
    @ByDesignation 8 років тому

    wait so do you still have to encode the rubber ducky payloads for bash bunny or no?

  • @greedsin555
    @greedsin555 8 років тому +6

    All I need now money is money to buy it.

  • @0150r
    @0150r 8 років тому +1

    Would be great to use as a "plug in" VPN client. Just plug it in and it tunnels all traffic through your VPN server. It would be similar to what Darren does with the Pineapple via wifi, but done by just plugging the BB into an open USB port. Instant secure web browsing everywhere you go on any machine with no configuration!

    • @andrewtowell6074
      @andrewtowell6074 8 років тому

      0150r have u not seen same thing for TOR?

    • @0150r
      @0150r 8 років тому

      I've seen a TOR/VPN router that uses a RPI and Darrent did cover using a Pineapple to make an openVPN access point. I'm looking more towards having the BB be a "plug in the USB, be on the VPN" type device.

  • @PJDuffield
    @PJDuffield 8 років тому

    damn, gunna have to wait till next payday now! Cant wait to get my hands on this baby

  • @93davve93
    @93davve93 8 років тому

    You guys are awesome!

  • @Illuminati242
    @Illuminati242 7 років тому

    Can you do an episode on the Raz Reverse shell. I tried this one on a windows 10 machine I got the solid white color which indicated that the payload completed successfully. However when i ran netstat on the windows box i did not see the open port, nor didi see it on my linux box when i did the netcat. Also the powershell window was supposed to be hidden, well it was not as i saw it open. And could also uses the clean up at the end to remover the powershell code from the run line.

  • @TheTrueSmitch
    @TheTrueSmitch 8 років тому

    Amazing work!

  • @milsonhq6330
    @milsonhq6330 8 років тому

    Am I missing something, I see links to RSVP I see links that point to the sales page, but I don't see any link that takes me to this repository they talk about containing the library of code?

  • @Simpleeh
    @Simpleeh 8 років тому

    This is kinda like all the hak5 tools in one :O

  • @tylorbray
    @tylorbray 8 років тому

    So more colors coming soon, whats in the yellow and orange bags?

  • @danking9974
    @danking9974 8 років тому

    Can you tell me what camera was used to record the rubber duck drop? I've been looking for something to do those kinds of videos but have come up short on quality hidden cameras.

    • @DarrenKitchen
      @DarrenKitchen 8 років тому

      I don't know for sure -- it was Nat Geo's button camera. I do know it was a custom made job. Something from "a guy in a garage" using a similar SONY chip found in the RX100 line -- IIRC. Could be wrong.

  • @rcook0001
    @rcook0001 8 років тому

  • @mcfly12345
    @mcfly12345 8 років тому

    I am excited!

  • @GaryIV
    @GaryIV 7 років тому

    Sooooo the bash bunny can be used for keyboard scripts like a rubber ducky USB right? so if I get one I no longer need my rubber ducky?

  • @EchoXIIIGO
    @EchoXIIIGO 8 років тому

    My little Digispark seems like nothing to this now ahah

  • @jonathanemery9557
    @jonathanemery9557 8 років тому +13

    NOO I JUST SPENT $100 DOLLARS ON PARTS FOR A ROBOT AND NOW YOU RELEASED THIS I NEED TO GET A ACTING JOB NOW BECAUSE IM ONLY 12!

    • @GiQQ
      @GiQQ 8 років тому +4

      Jonathan Emery When I was 12 I was playing outside.. But hey..

    • @jonathanemery9557
      @jonathanemery9557 8 років тому +1

      Pr0ton Haha Yeah Thats What Most Of My Friends Do

    • @IncendiarySolution
      @IncendiarySolution 8 років тому +1

      Pr0ton playing hoop stick?

    • @stevenhubbard3117
      @stevenhubbard3117 8 років тому

      what is an acting job?

    • @jonathanemery9557
      @jonathanemery9557 8 років тому

      steven hubbard Like Tv Shows.

  • @NateCrownwell
    @NateCrownwell 8 років тому

    Can you make an episode on all the really technical details of how the BashBunny works that would be really interesting, thank you!

  • @IncendiarySolution
    @IncendiarySolution 8 років тому

    Been working on this with a RpiZ for a little while. I want one.

  • @evolve101
    @evolve101 8 років тому

    Kewl.
    This device seems to be awesome. I also got all excited when he got into how this device works! Hehe.. Need to check out that library! Keep it up. Peace!
    (Trust your technolust.)

  • @amoconote181
    @amoconote181 4 роки тому

    looved her description of the cdc

  • @edwardamarh8959
    @edwardamarh8959 8 років тому

    this is ridiculously limitless, I like this over rubber duckies because it does what a rubber duckie can do and more

  • @haxhxm841
    @haxhxm841 8 років тому

    I'm just waiting for a RPI zero mock up of this to emerge

  • @ZeroCool-1995
    @ZeroCool-1995 8 років тому

    Dumb question. Do y'all plan on any USB-C variants? Obviously Bash Bunny isn't really made for random drops. Will the rubber ducky ever have a USB-C version because they are awesome for hiding in random cases. Trying to avoid dongle hell with these things.

  • @zacharywentworth7844
    @zacharywentworth7844 4 роки тому

    When will you guys have more to sell, it the keysly be in????

  • @stevenlowry1586
    @stevenlowry1586 8 років тому

    just In time for Easter

  • @tgfasmo
    @tgfasmo 8 років тому

    for some reason Bashbunny on Device Manager Port com does not show up just says CDC serial but no com port displayed

  • @voiceoftreason1760
    @voiceoftreason1760 8 років тому

    What is the usb controller speed of the device? I can't find it so I assume it's only 2.0 since I believe you also said it's not usb 1.1

  • @pgbilbo
    @pgbilbo 8 років тому

    Will there be updated Field kits including the BashBunny at some time?

    • @hak5
      @hak5  8 років тому

      Yes, no specified date yet.

  • @StillTrustNo1
    @StillTrustNo1 8 років тому

    just 4 info - 13:49 use the windows command "mode" - its faster

  • @barikhan
    @barikhan 8 років тому +1

    What's the difference in comparison to rubber ducky?
    Apart from the look and speed mentioned in the video...i feel Bunny is kind of adv version of ducky emulating a variety of trusted devices.
    Was planning to buy ducky...but now i am confused.

    • @vincviertytaccount2608
      @vincviertytaccount2608 8 років тому

      bari khan The Bunny also simulates and LAN-Adapter like the LAN Turtle, so you have many more attack posslibilities, the Ducky, in compatibility, simulates only a Keyboard (the Bunny can so this too) but is way faster than the bunny

    • @barikhan
      @barikhan 8 років тому

      Vinc viert YT Account thanks... It's only the time of execution that gives ducky the upper hand.. Got it.

  • @kevindelbegue6403
    @kevindelbegue6403 8 років тому

    Wich are the computer models that you are using, and with Wich OS ?

  • @ZukaroTravon
    @ZukaroTravon 8 років тому +1

    Do you think something like this would be possible with an Android phone? As in, writing an app for an Android phone which would essentially let you choose your payload from a list (or even connect to a server to pull the payload you wanna use) while in the middle of an attack (with a mode to run in a similar manner to the Bash Bunny so you don't need to unlock the device to execute a payload). And if doing it that way, you could even connect to a smart watch to get updates about the attack without looking too suspicious. :p
    I also feel like doing it from an Android phone opens up more possibilities in terms of social engineering as you could potentially ask if you could plug your phone into their computer to "charge". 'w' Whereas asking to plug in a USB is an immediate red flag.
    Although I'm not sure how doable that would be, and I certainly doubt it could be done on a non-rooted device, but it would certainly be cool.

  • @patrickgauthier5580
    @patrickgauthier5580 8 років тому

    I can see super glue being used as a security measure until your remove the side of the case and go to the pads.

  • @NateCrownwell
    @NateCrownwell 8 років тому

    How long did it take you to develop the BashBunny?

  • @bigpinar89
    @bigpinar89 8 років тому

    So what im getting is the power of Wi-Fi pinapple + bash bunny = doing attack without being on the physical device?

  • @Canadian789119
    @Canadian789119 8 років тому +1

    There is no white hat hacking unless you only hack yourself :) So if auto play off is not enough! Can't add any Adapters, hard to cover all the angles :P

    • @zacharywentworth7844
      @zacharywentworth7844 4 роки тому

      That’s not true we get hired alll the time by big companies like FB and more than countable amount that hire us to find their gaps in the network and their cyber security, thats where the money is at. Penetrate and be paid!

  • @dutchgh0st540
    @dutchgh0st540 8 років тому +1

    holy bunny's THIS IS AWESOMMEEEEEE

  • @clintonknight9798
    @clintonknight9798 8 років тому

    More stuff! Hop to it.

  • @sergesieniejo1
    @sergesieniejo1 8 років тому

    very awesome :) im going to give it a few month before i buy so there are more pre created payloads. time to get rid of my rubberducky and move on

  • @quillometer
    @quillometer 5 років тому

    "HIER NIET POEPEN A.U.B."
    Omg I'm dying

  • @patrickgauthier5580
    @patrickgauthier5580 8 років тому

    I can see super glue being used as a security measure until you remove the side of the case and go to the pads.

  • @n8sdesign
    @n8sdesign 8 років тому

    4:27 Keep on Keeping on💪👊 props😎🍻

  • @JustinHyneswashplant26
    @JustinHyneswashplant26 8 років тому

    Where do we summit our payloads for the bash bunny competition?

  • @hectorsandoval7810
    @hectorsandoval7810 7 років тому

    when i try to open the terminal on the bash bunny its a empty blank screen

  • @deyo2794
    @deyo2794 8 років тому

    Ordered mine...