Skip to main content

Hak5 Plunder Bug Comprehensive Technical Manual

The Plunder Bug is an essential tool in the Hak5 pentesting ecosystem, engineered for stealth, efficiency, and full operational reliability.


Table of Contents​


1. Product Overview & Hardware Architecture​

This chapter details the 1. product overview & hardware architecture specifications, procedures, and operational methodologies for the Plunder Bug.

Technical Specifications & Ground Truth Hardware Baseline​

Hardware ComponentOfficial Specification Value
ArchitecturePocket-Sized Passive/Active USB LAN Tap
Ethernet InterfacesDual 10/100 Fast Ethernet Ports (Inline Tap RJ-45)
Tap Output Interface1x USB Type-C High-Speed Port
Power Requirements5V DC via USB Type-C Connection (< 250mA Draw)
Operating ModesPassive Tap Mode, Active Emulated NIC Mode, Simple Switch Mode
ChipsetHigh-Performance Low-Power ASIX / Realtek Ethernet Controller
Cross-Platform CompatibilityLinux (Native), macOS (Native/Driver), Windows (ASIX Driver), Android

1.1 Plunder Bug by Hak5​

The Plunder Bug by Hak5 is pocket-sized LAN Tap that lets you "bug" Ethernet connections with USB-C convenience.

[!WARNING] The e-book PDF generated by this document may not format correctly on all devices. For the most-to-date version, please see https://docs.hak5.org


2. Hardware Setup, Connectivity & Drivers​

This chapter details the 2. hardware setup, connectivity & drivers specifications, procedures, and operational methodologies for the Plunder Bug.

Getting Started

The Plunder Bug by Hak5 is pocket-sized LAN Tap that lets you "bug" Ethernet connections with USB-C convenience.

Using a USB-C cable, connect the Plunder Bug to a computer running a network analyzer such as Wireshark. The light on the Plunder Bug will illuminate green to indicate that it is powered, and you will notice on the computer a new network interface (ASIX AX88772C USB Ethernet).

You will most likely wish to switch the Plunder Bug into passive mode, which mutes the tap port, preventing the host computer from transmitting anything downstream on the tap port. See instructions for your operating system here.

Using two Ethernet cables, plug the Plunder Bug inline between any two devices, such as a PC and a LAN switch. Packets between the two ports will be mirrored on the USB-C tap port, which may be viewed using common open source packet analyzers such as Wireshark or tcpdump.


2.2 Drivers​

While most systems will automatically recognize and install drivers for the Plunder Bug's USB Ethernet interface (ASIX AX88772C chipset), some Windows and Mac systems may not.

To manually download and install the driver, please visit the ASIX driver download page for the AX88772C.


3. Active and Passive Operating Modes & Cross-Platform Switching​

This chapter details the 3. active and passive operating modes & cross-platform switching specifications, procedures, and operational methodologies for the Plunder Bug.

3.1 About Mode Switching​

By default the Plunder Bug's USB-C tap port will act in an active, bidirectional manner. This means that in addition to receiving a mirror of the traffic flowing between the two RJ45 Ethernet ports, it will also act as an additional Ethernet port on the target LAN.

This is useful for simultaneously performing active network scans (such as with nmap) while passively sniffing packets. To switch between passive (muted) and the default active (unmuted) modes, use the Plunder Bug mute script specific to your operating system.


3.2 Windows Mode Switching​

Using plunderbug.ps1​

Download the plunderbug.ps1 PowerShell script for modern Windows platforms from the Hak5 Download Center.

Open PowerShell bypassing the default execution policy so that the script may run. For example, from the Run dialog (WIN+R) enter powershell -exec bypass

Change to the directory of the downloaded plunderbug.ps1 script and execute with the mute or unmute parameter (eg: .\plunderbug.ps1 mute)

If necessary, allow User Access Control to run the script as an administrator.

The script will execute muting or unmuting the port as directed. Press Enter to close the command prompt. The setting will stay in effect until the script is run again with the opposite directive.

Manually​

If preferred, the Plunder Bug can be muted or unmuted by opening Network Connections (Start > Run > ncpa.cpl > [ENTER])

Then right-click the Plunder Bug interface and select Properties

Uncheck the boxes next to each of the protocols and click OK.


3.3 MacOS Mode Switching​

USING PLUNDERBUG.SH​

Download the plunderbug.sh script for *nix platforms from the Hak5 Download Center.

Open a terminal, change to the directory of the downloaded plunderbug.sh script, make it executable (chmod +x ./plunderbug.sh) and run it as root.

plunderbug.sh accepts the arguments --mute and --unmute to switch between active and passive modes

MANUALLY​

If preferred, the Plunder Bug can be muted and unmuted by opening Network from System Preferences. Click Advanced, then select "Off" from the Configure IPv4 and IPv6 menus, then click OK and Apply.


3.4 Linux Mode Switching​

USING PLUNDERBUG.SH​

Download the plunderbug.sh script for *nix platforms from the Hak5 Download Center.

Open a terminal, change to the directory of the downloaded plunderbug.sh script, make it executable (chmod +x ./plunderbug.sh) and run it as root.

plunderbug.sh accepts the arguments --mute and --unmute to switch between active and passive modes

MANUALLY​

If preferred, the Plunder Bug can be muted and unmuted by opening Network Manager, clicking the configure gear icon next to the Plunder Bug interface, then selecting the disable option from the IPv4 and IPv6 tabs and clicking Apply.


4. Advanced Network Usage, Packet Capture & Maintenance​

This chapter details the 4. advanced network usage, packet capture & maintenance specifications, procedures, and operational methodologies for the Plunder Bug.

4.1 Using as a Simple Switch​

In a way, the Plunder Bug can be used as a simple switch. In the following example, the Plunder Bug is used to provide the laptop (via USB-C) and the Shark Jack (or any ordinary Ethernet device) network access via the WAN/Uplink port (closest to the Plunder Bug's status LED).