Rubber Ducky Credential Payload
Budget: $10 – $30 USD
I’m putting together a proof-of-concept that shows how quickly login credentials can be siphoned from a Windows machine with a Hak5 USB Rubber Ducky. What I need from you is a single stealthy payload whose sole job is data exfiltration: plug the ducky in, harvest the active user’s credentials, ship them off-box, wipe its tracks, done.
Target platform
– Fully-patched Windows 10 and 11 in their default configuration.
Objective
– Exfiltrate login credentials (hashes or clear text—whichever you can obtain most reliably) without triggering UAC or mainstream AV.
I’m flexible on the transport channel—HTTP(S) POST, DNS tunnel, even discreet email—so long as the data lands on a listener I specify and the operation stays quiet.
Deliverables
1. Obfuscated DuckyScript (.txt) payload ready to flash
2. Any auxiliary listener / decoder script (PowerShell, Python, etc.)
3. A concise README covering flashing, execution flow, required listeners, and cleanup
I’ll test immediately and provide rapid feedback. If you live and breathe DuckyScript v3, PowerShell one-liners, and Windows credential dumping techniques, this should be straightforward.
Target platform
– Fully-patched Windows 10 and 11 in their default configuration.
Objective
– Exfiltrate login credentials (hashes or clear text—whichever you can obtain most reliably) without triggering UAC or mainstream AV.
I’m flexible on the transport channel—HTTP(S) POST, DNS tunnel, even discreet email—so long as the data lands on a listener I specify and the operation stays quiet.
Deliverables
1. Obfuscated DuckyScript (.txt) payload ready to flash
2. Any auxiliary listener / decoder script (PowerShell, Python, etc.)
3. A concise README covering flashing, execution flow, required listeners, and cleanup
I’ll test immediately and provide rapid feedback. If you live and breathe DuckyScript v3, PowerShell one-liners, and Windows credential dumping techniques, this should be straightforward.