WHID Injector - An Attacking USB


WHID Injector
   Black Hat Arsenal EU

   WiFi HID Injector for Fun & Profit
   Hardware Design Author: @LucaBongiorni
   Initial sw based on ESPloit by Corey Harding of www.LegacySecurityGroup.com

   Available at:
    * Aliexpress Shop
    * April Borther Online Shop
    * eBay

   The Author has no profit out of the Cactus WHID sales.

HOW TO START [Newbies Edition]
   Since July 2017 all Cactus WHID are delivered with pre-loaded ESPloitV2 and are ready to Plug-n-Hack ✌
   Thus, even if you are not an Arduino expert, you can immediately have fun!

   Just plug it in an USB port and connect to the WiFi network:
    * SSID "Exploit"
    * Password "DotAgency"

   Open a web browser pointed to "http://192.168.1.1"
   The default administration username is "admin" and password "hacktheplanet".

   For cool payloads or more info check the Wiki or the Payloads directory.

Hardware Snapshot

USB Pinouts
   In order to make easier the process of weaponizing USB gadgets, you can solder the USB wires to the dedicated pinouts.

   The pin closer to USB-A is GND. The pins are:
    * GND
    * D+
    * D-
    * VCC

   [ If also an USB HUB is needed (i.e. to weaponize a wired mouse), usually, I do use this one "NanoHub - tiny USB hub for hacking projects"]

Documentation WIKI

Third-Party Softwares Compatible with WHID's Hardware
    * GitHub.com/exploitagency/ESPloitV2 An improved version of WHID GUI
    * GitHub.com/sensepost/USaBUSe
    * GitHub.com/spacehuhn/wifi_ducky
    * GitHub.com/basic4/WiDucky

Possible Applications
   Classic: Remote Keystrokes Injection Over WiFi
      Deploy WHID on Victim's machine and remotely control it by accessing its WiFi AP SSID. (eventually you can also setup WHID to connect to an existing WiFi network)

   Social Engineering: Deploy WHID inside an USB-enable gadget
      The main idea behind it is to test for Social Engineering weaknesses within your target organization (e.g. DLP policy violations) and to bypass physical access restrictions to Target's device. Usually, I create a fancy brochure (sample template https://github.com/whid-injector/WHID/tree/master/tools/Social_Engineering_Lures) attached with a weaponized USB gadget and then use a common delivery carrier (e.g. UPS, DHL, FedEx).

Video Tutorials

Visit WHID Injector on Github