SudoSnatch
sudoSnatch: sudoSnatch payload grabs sudo password in plain text, imediately after victim uses `sudo` command and sends it back to attacker remotely/locally.
Install / Use
/learn @drapl0n/SudoSnatchREADME
About:
- Title: sudoSnatch
- Description: sudoSnatch grabs plain text passwords remotely/locally.
- AUTHOR: drapl0n
- Version: 1.0
- Category: Credentials
- Target: Unix-like operating systems with systemd.
- Attackmodes: HID, Storage
sudoSnatch: sudoSnatch is BashBunny's payload which grabs sudo password in plain text and sends it back to attacker remotely/locally.
Features:
- Plain text passwords.
- Detailed password logs.
- Persistent
- Autostart payload on boot.
Workflow:
- Injecting payload on target's system.
- Checks whether internet is connected to the target system.
- If internet is connected then it sends clear text passwords to attacker.
Changes to be made in payload.sh:
- Replace ip(0.0.0.0) and port number(4444) with your servers ip address and port number on line no
10. - Increase/Decrease time interval to restart service periodically (Default is 15 mins), on line no
14.
LED Status:
SETUP: MAGENTAATTACK: YELLOWFINISH: GREEN
Directory Structure of payload components:
| FileName | Directory | | -------------- | ----------------------------- | | payload.txt | /payloads/switch1/ | | payload.sh | /payloads/ | | shell | /payloads/library/sudoSnatch/ | | systemMgr | /payloads/library/sudoSnatch/ |
- Note: Create directory named
sudoSnatchin/payloads/library/
Usage:
- Inject payload into target's system.
- Start netcat listner on attacking system:
nc -l -p <port number>use this command to fetch passwords.
Support me if you like my work:
- https://twitter.com/drapl0n
Related Skills
node-connect
344.1kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
96.8kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
344.1kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
344.1kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
