MADHURA M
3RD YEAR, CSE
USB RUBBER DUCKY
WHAT IS IT?
KEYSTROKE INJECTION TOOL.
DISGUISED USB FLASH DRIVE, RECOGNISED BY THE
COMPUTER AS A KEYBOARD.
EXPLOITS THE INHERENT TRUST THAT COMPUTERS HAVE
ON HID(HUMAN INTERFACE DEVICES).
HISTORY
7 YEARS OF DEVELOPMENT
FEATURES
SPEED – CAN INJECT KEYSTROKES AT 1000
WORDS/MINUTE.
FAST 60 MHZ 32-BIT PROCESSOR.
UNDETECTABLE BY ANTI VIRUS.
EXPANDABLE MEMORY VIA MICRO SD CARD.
SIMPLE SCRIPTING LANGUAGE.
DUCKY SCRIPT
WHAT NEXT?
COMPILE THE SCRIPT TO CONVERT IT
INTO A HEX FILE.
THE HEX FILE IS CALLED PAYLOAD, AND
NAMED AS INJECT.BIN
HOW TO GET IT?
OR MAKE ONE!
DEVELOPMENT BOARDS-ARDUINO/RASPBERRY PI.
ANDROID PHONE WITH KALI NETHUNTER.
FROM A NORMAL USB DRIVE
FIRMWARES
TWIN DUCK
MULTI-DUCK AND TWIN DUCK
DRAWBACKS
REAL WORLD EFFECTIVENESS IS QUESTONABLE.
THE INITIAL DELAY REQUIRED TO INSTALL THE
HID DRIVERS.
ONLY ONE PAYLOAD AT A TIME.
PREVENTION AGAINST ATTACK
DON’T LOGIN AS AN ADMINISTRATOR.
DISABLE USB KEYBOARD.
REFERECES
 TO PURCHASE-
 GITHUB PAYLOADS
 PAYLOAD GENERATOR
 ENCODER
 NETHUNTER
 REGULAR USB FLASH DRIVE TO DUCKY.

Usb rubber ducky