How to Pull Wireless Credentials with the Bash Bunny
ID: 0026d467-0df9-5739-b9a5-2cedb4f11493
STIX ID: report--0026d467-0df9-5739-b9a5-2cedb4f11493
Feed Name: Black Hills Infosec Blog
This blog post demonstrates the Hak5 Bash Bunny 'WiPassDump' payload which, when plugged into an unlocked Windows workstation, automates running "netsh wlan export profile key=clear" to export saved WEP/WPA/WPA2-PSK wireless profiles and plaintext passphrases; the author details setup, language/keyboard considerations, test results (including that it can work from a standard user account), and recommended mitigations such as avoiding PSK on corporate networks, locking workstations, using full disk encryption, and restricting USB access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
