Phising with Setoolkit in Local Network

M3m0ry

Kıdemli Üye
3 Haz 2017
4,410
126
3
xD
Hi TurkHackTeam members,

I'll show you how can we capture all informations which is entering to computer.

giphy.gif


Scenario

We set all things about Setoolkit, and we tested them. It works good. But how our victim visit to that address ?

Of course with Ettercap tool! For example, if you want to hack Google account, you provide to your victim reachs to your IP address when he/she entered to Google. Your victim will see phising website which we created. By this means, we will reach her/his email and password easily.


THSe2J.png


Phising with Setoolkit in Local Network!

First, open your terminal and get Root permissions.

G3Pwtn.png


Command;

Kod:
su

Now run Setoolkit tool.

Setoolkit; This tool already exists in Linux distribution like Kali Linux, Parrot etc.

If you dont have that tool;

Kod:
git clone https://github.com/trustedsec/social-engineer-toolkit/
chmod  +x setoolkit
./setoolkit

Type setoolkit in terminal for run the tool.

pNhyiz.png


5eRBJd.png


Our tool worked. There are so many features. We'll make phising in local network. So, should select number 1) Social-Engineering Attacks.

U4Btiq.png


Like is said, there are so many features. You can test them for learn what do they do.

Now select 2) Website Attack Vectors.

SE5rva.png


We'll see 7 different methods.

I generally select 3) Credential Harvester Attack Method. I'll select this method in this topic too.

jVKI5w.png


This point is important. If you want to create page automatically, you need to select 1) Web Templates option. (There are 3 websites in that option)

Kod:
1. Java Required
2. Google
3. Twitter

I will create my own clon website. So, I'll select 2) Site Cloner option.

FXHyDl.png


It is asking to us our IP address now. I will type my 192.168.1.51 IP address.

If you dont know your IP addrees;

bzxbcq.png


You can type this command;

Kod:
ifconfig

for learn your IP address.

ZVhxDc.png


It is asking "which website you want to clone" to us.

I want to make clone of Facebook. So, I'll type;

Kod:
http://facebook.com/login

this.

TvnNbs.png


It says "Type IP address which machine you want to attack". Leave it blank.

UMSQOu.png


All things are ready. Now press Enter for start to attack.

LxGeie.png


You will see some texts in here. They are unnecessary.

Press enter.

a41KUm.png


Our attack is started.

Now direct your victim to that address and steal password.

CeEK5t.png


As you can see, There is no different thing in our page from real page.

Now wait your victim's mail and password :)).

pHkOjZ.png


Now, we got that mail and password.

oKEKz1.gif

Source: https://www.turkhackteam.org/sosyal-muhendislik/1923814-local-agda-setoolkit-ile-phising.html
Translator: @M3m0ry​
 
Moderatör tarafında düzenlendi:
Üst

Turkhackteam.org internet sitesi 5651 sayılı kanun’un 2. maddesinin 1. fıkrasının m) bendi ile aynı kanunun 5. maddesi kapsamında "Yer Sağlayıcı" konumundadır. İçerikler ön onay olmaksızın tamamen kullanıcılar tarafından oluşturulmaktadır. Turkhackteam.org; Yer sağlayıcı olarak, kullanıcılar tarafından oluşturulan içeriği ya da hukuka aykırı paylaşımı kontrol etmekle ya da araştırmakla yükümlü değildir. Türkhackteam saldırı timleri Türk sitelerine hiçbir zararlı faaliyette bulunmaz. Türkhackteam üyelerinin yaptığı bireysel hack faaliyetlerinden Türkhackteam sorumlu değildir. Sitelerinize Türkhackteam ismi kullanılarak hack faaliyetinde bulunulursa, site-sunucu erişim loglarından bu faaliyeti gerçekleştiren ip adresini tespit edip diğer kanıtlarla birlikte savcılığa suç duyurusunda bulununuz.