X-Frame-Options Scanner

X-Frame-Options Scanner
Download Copy
Title: X-Frame-Options Scanner
Author: TW-D

Uses the "Microsoft Edge" web browser to search for web servers within a range of IPv4 addresses that do not have an "X-Frame-Options" header. Then exports the results to a PDF file accessible in the Rubber Ducky. The results contain the tested IPv4 addresses and the HTML rendering.

🏆   Recognized with a Payload Award in September 2023

 

Reconnaissance, or recon, is all about gathering information on a target — be it an individual computer or the network at large. Individual computers may be scanned using a hotplug tool like the Bash Bunny or USB Rubber Ducky coupled with keystroke injection techniques to obtain valuable information without the need to elevate privileges.

Network reconnaissance techniques involve active scans, which may be observed by intrusion detection systems, or passive scans, which may go quietly undetected. The information obtained in a recon operation may assist in the red team's audit plan for future missions such as phishing campaigns or exfiltration. On the network enumeration side, many techniques exist for scanning the network from the outside. The same techniques may be applied to scanning inside the network, which is where hotplug Ethernet attack tools like the Shark Jack excel. See all recon payloads.

This payload is for the USB Rubber Ducky — a "flash drive" that types keystroke injection payloads into unsuspecting computers at incredible speeds. It's no wonder this little quacker has made appearances on Mr. Robot, FBI, Blacklist, National Geography and more!

Submit your own payload, or browse more featured USB Rubber Ducky Payloads.

 

 

Related Payloads

Cookie Monster
Cookie Monster
Recreates the 1969 program from Brown University. This version types messages asking for a cookie. Until the user type c
Read More
FileHunter
FileHunter
Crawls all drives of the target system for a specific file or file type, to then compress and exfiltrate them to the Duc
Read More
Silent File Exfiltrator
Silent File Exfiltrator
This DS1 payload executes a stealthy script that silently collects and exfiltrates specific file types through Discord w
Read More