OMG Cable - Android Reverse Shell - Payload & Detections

Поділитися
Вставка
  • Опубліковано 13 січ 2022
  • Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005
    ____________________________________________
    SHOW NOTES:
    Testing was done on out of box Android devices with default settings.
    O.MG Cable: hak5.org/omg
    Payload:
    hak5.org/blogs/payloads/andro...
    github.com/hak5/omg-payloads/...
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • Наука та технологія

КОМЕНТАРІ • 84

  • @evodefense
    @evodefense 6 місяців тому +1

    Amazing payload and appreciate covering the detections also!

  • @GuyMassicotte
    @GuyMassicotte 2 роки тому +2

    Always top, thanks 👌🏼

  • @elbowsout6301
    @elbowsout6301 2 роки тому

    Good stuff. I'm going to have to get one of these :)

  • @hermesvoeglein535
    @hermesvoeglein535 2 роки тому +28

    Thats why one of the first things to do with a new android device, to toggle off data transfer via usb and just allow it for recharging, unless you actually need it. Just like with wlan on any "smart"-phone, toggle it off when not in use and unallow the automatic connection to any wlan-network even those you deem save. Does a lot for your personal and professional safety, with minimal effort and zero cost.

    • @O.MG-MG
      @O.MG-MG 2 роки тому +4

      This isn’t using data transfer.

    • @hermesvoeglein535
      @hermesvoeglein535 2 роки тому +5

      Uhm yes, you are totaly right, it uses peripheral usb access ... so toggle that off too.

    • @O.MG-MG
      @O.MG-MG 2 роки тому +4

      @@hermesvoeglein535 now you’ve blocked the ability to do it with an external device. But with a bit more time someone can do it manually. Android really just needs to prompt for passcode for high risk activities, the same way iOS has done for years.

    • @simonstergaard
      @simonstergaard 2 роки тому +4

      who needs a phone...my nokia 3310 hammer edition is doing well

    • @crypto-radio8186
      @crypto-radio8186 2 роки тому

      @@simonstergaard Is Nokia the hardest phone in the world? The world's 'most indestructible phone' - Iconic Nokia 3310 is coming back.

  • @shoutshollers
    @shoutshollers 2 роки тому

    Thanks guys

  • @bababooeyhacks9601
    @bababooeyhacks9601 2 роки тому

    Magnificent...

  • @Username8281
    @Username8281 2 роки тому +1

    Lit

  • @Jianju69
    @Jianju69 2 роки тому +2

    Int80, what is the name of your band? Ah, got it at the end: "Dual-Core". Thanks.

  • @ashtonalmond9024
    @ashtonalmond9024 Рік тому

    Interesting

  • @drewsec8715
    @drewsec8715 2 роки тому +8

    Appreciate the shout out!!

  • @RashadPrince
    @RashadPrince 2 роки тому

    My boy 🖖🙏

  • @SkunkCity_RC
    @SkunkCity_RC Рік тому

    Woo

  • @-Rishikesh
    @-Rishikesh 2 роки тому +8

    Doesn't Android 12 show notification when you access camera or location ?
    Does this payload bypass these security measures ?

    • @norvarg712
      @norvarg712 2 роки тому

      Android 12 does, and I don't think this would do anything about that since they didn't account for that, but you could always add some code to go in their settings and turn that off so yeah

  • @gloriagm8452
    @gloriagm8452 Рік тому +2

    Hello, u make it all seem so easy, it's been 5 yrs, that my phone has been hacked, been through 100s of phone and changed providers but some how they hack into it and get into my my bank accounts and don't know how they hide their transactions, am tracked every move I make and continue to break into my home, text friends as well and become victims as well... Where can I go to get help with this issue as law inforcement seem not to be much help without proof

  • @BrandiXo
    @BrandiXo Рік тому +1

    Omg!! What if you think you may have used a hacked charger?How do you find out on your phone and how do you get it off your phone?? What if you plugged the USB c into laptop and USB into chsrger?

  • @scriptkiddieclub9267
    @scriptkiddieclub9267 2 роки тому +7

    dont u need to have usb debugging on in settings?

  • @xxigotruktdxx3387
    @xxigotruktdxx3387 2 роки тому +5

    does it still need to be connected to a computer for it to work or can you just have it plugged into a charger

  • @nonymous1852
    @nonymous1852 Рік тому

    Where do you get the O.M.G. software? Is there an app to use once remote access has been achieved with the target device?

  • @julymugale
    @julymugale Рік тому

    Shipping restrictions: I am in South Africa and i need a OMG cable for android. How do i bypass shipping restrictions to certain regions of the world. I dont even understand why shipping restrictions. Please help

  • @hobofilms4596
    @hobofilms4596 2 роки тому +3

    What happened to Nullbytes he hasn't made a videos in a while

  • @SouthSaxonMan
    @SouthSaxonMan 2 роки тому

    What if you have disabled Chrome. Does this still work?

  • @myktabesarab607
    @myktabesarab607 Рік тому +2

    Its not that simple if you are beginner. Firstly this will work only if you are in same network and if you are not in same network you need to set up a server which can be accessed publicly and send the data to server.

    • @O.MG-MG
      @O.MG-MG Рік тому

      Setting up an internet accessible server should be well within the capabilities of someone doing security work.

    • @jamesmckee9017
      @jamesmckee9017 Рік тому

      @@O.MG-MG Linode anyone?

  • @ashlie-fv4dw
    @ashlie-fv4dw Рік тому

    Hey, I've been a target by some psycho who's been using a cable and r.a.t against Me to ddoss and drain my assets and rob my house. Is there anyway to reverse the connection and use a honey pot from the infected device

  • @ceovenusworld4108
    @ceovenusworld4108 2 роки тому

    How can you identify a OMG cable Android please?

  • @Kogitto11
    @Kogitto11 8 місяців тому

    Does anything of this work with turned off screen?

  • @gnorbsl4194
    @gnorbsl4194 2 роки тому +9

    So this means a phone has to be unlocked to deliver the payload correct? Just plugging it in is not enough

    • @romein138
      @romein138 2 роки тому +1

      yes

    • @mahesh71188
      @mahesh71188 2 роки тому

      Yes it needs to be unlocked to inject the payload

    • @CokesAndTokes
      @CokesAndTokes 2 роки тому +5

      If it was able to work while locked you may aswell use a rubber ducky the whole point of these cables are for the social engineering part of an attack like leaving this ordinary looking charging cable in a target building

  • @PepeTostado
    @PepeTostado Рік тому

    How do you do it without showing the process on the phone? Like as a daemon

  • @xsTaoo
    @xsTaoo 5 місяців тому

    Is there any way to make remote control persistent? The connection will be lost every time the phone is turned off.

  • @JigziPep
    @JigziPep 2 роки тому +1

    Thanks guys. Do anti malware apps help against these hacks

    • @samuelsamuel4099
      @samuelsamuel4099 2 роки тому +2

      Mostly no, because the anti malware hat for itself very little privileges. Regular anti malware on mobile can't do much.

    • @salpertia
      @salpertia 2 роки тому +2

      The omg cable mimics a keyboard so that's a big no. Just a natural feature for android to plug and play auto.

    • @CokesAndTokes
      @CokesAndTokes 2 роки тому +2

      @@salpertia I second this. There's pretty much no way for devices to protect against HID attacks because the attack is literally used to mimic what a human would be doing on that device there's no way for the device to distinguish between human input or HID input. That being said if a hacker gets physical access you have been pwned the worst way possible

    • @Lishamisha22
      @Lishamisha22 Рік тому

      @@CokesAndTokes so.... not even updating the ios or doing a factory reset helps? its just a game over?

    • @CokesAndTokes
      @CokesAndTokes Рік тому +1

      @LinguistsCorner 9 times out of 10 no, It's unfixable. Along as phones allow a keyboard to be connected this attack will remain a threat.

  • @woah-thats-cyber761
    @woah-thats-cyber761 2 роки тому

    you write that script or came across it,.,,?>

  • @ignror
    @ignror Рік тому

    I want to purchase one but it's price....

  • @hannesskirgard
    @hannesskirgard 2 роки тому

    To be a HID does OTG have to be active?

  • @charleneduggins8449
    @charleneduggins8449 2 місяці тому +1

    I am pretty possitive this is happening to my family can you please help us reverse it and make it stop please it's ruining my life

  • @zmmermn
    @zmmermn Місяць тому

    Does it matter if the phone screen is locked?

  • @sinclairakoto8564
    @sinclairakoto8564 Рік тому

    Hi guys I have the same cable as the one in the video. My one is the Plus, I should be able to save up to 200 payloads according to the website but on the device i can only save 7 does anyone know how to save more?

    • @chrisokeefe1884
      @chrisokeefe1884 Рік тому

      The plus does not offer 200 payloads. That is reserved for the Elite version that won't be out until next year.

  • @GamingKing545
    @GamingKing545 2 роки тому

    i finally found that song from kanga

  • @RG6Snipers
    @RG6Snipers 2 роки тому +1

    Can this be used to pull the userdata with root access?

    • @georgedhmosxakhs2498
      @georgedhmosxakhs2498 2 роки тому

      unless the phone is rooted no you don't have root access in an android phone.

    • @pranaythammineni256
      @pranaythammineni256 2 роки тому

      @@georgedhmosxakhs2498 i have tried rooting for an year but unsuccessful. Do you have way i could try

    • @georgedhmosxakhs2498
      @georgedhmosxakhs2498 2 роки тому +1

      ​@@pranaythammineni256 One way to do it is by flashing TWRP recovery image into your phone and after that flashing through TWRP, Magisk root apk to install sudo command into your android device. If you are total beginner i will advice you not to do it, because you could damage your phone if you screw it up.

    • @pranaythammineni256
      @pranaythammineni256 2 роки тому

      @@georgedhmosxakhs2498 not that beginner but i do have a spare phone. i want to learn rooting that phone soo

    • @pranaythammineni256
      @pranaythammineni256 2 роки тому +1

      @@georgedhmosxakhs2498 actually am not able to unlock bootloader thats where am struck

  • @pi1392
    @pi1392 2 роки тому +2

    Mr Robot style.

  • @TheMinatozzz
    @TheMinatozzz 2 роки тому

    Is it possible to send commands to burn or or delete totally?

    • @Wock_597
      @Wock_597 2 роки тому

      Yes u can

    • @Wock_597
      @Wock_597 2 роки тому

      Is it illigal to buy it ?

  • @user-yc5fq9bv3u
    @user-yc5fq9bv3u 2 роки тому

    this does not even touch the question what protocol the cable is using to manipulate the phone

    • @youtubegaveawaymychannelname
      @youtubegaveawaymychannelname 2 роки тому +4

      It's just a HID style attack. You can plug a physical keyboard into an android phone and type commands to get the same result.

    • @O.MG-MG
      @O.MG-MG 2 роки тому +4

      The payloads are posted for anyone who wants to step through every detail.

    • @jamesmckee9017
      @jamesmckee9017 Рік тому

      @@youtubegaveawaymychannelname Yeah but you can control it remotely... That's the difference.

  • @mukto2004
    @mukto2004 2 роки тому

    that music tho whats the name ?

    • @O.MG-MG
      @O.MG-MG 2 роки тому

      Dual Core - Fear & Chaos
      ua-cam.com/video/ra0HChk1oEc/v-deo.html

  • @midnitekisses9559
    @midnitekisses9559 Рік тому

    These people are evil and should be sentenced to 10 years in federal prison