RE: Credential Harvesting Using SET [A Beginner's Guide] 05-14-2013, 05:58 PM
#11
(02-01-2013, 01:05 PM)Ex094 Wrote: Hello Guys! This is my first tutorial in this section, this tutorial will guide you step by step on how to harvest credentials using Social Engineering Toolkit (SET). To continue this tutorial you'll need:
Code:1) BackBox or Any other pentest OS having SET (Backtrack Recommended!) 2) Social Engineering Toolkit (Updated) 3) Set of Social Engineering Skills to lure your prey 4) Patience! 5) VPN (Just in case)
First step:
Navigate -> Menu -> Auditing -> Social Engineering -> SET -> set-console
Second Step:
Choose the "Social Engineering Attacks" (DUH! We are using SET!!!!)
Third Step:
Then choose "Website Attack Vector"
Foruth Step:
Now the method we are going to use is "Credential Harvester Attack Method". Now lets stop here for a moment and understand what this method does:
Code:Credential Harvester Attack Method uses Web Cloning feature to make a clone of a website having Username and Password fields e.g Facebook. When the prey ( TARGET ) enters the user and pass, it harvests it and sends it back to the hunter (YOU) .
Fifth Step:
As we are using the method that uses site cloning so choose "Site Cloner". Next it will ask you your IP so goto http://www.whatismyip.org get your IP.
Sixth Step:
Now it will ask you to input the site url that you want to clone, For this tutorial I'm using Facebook. You can use any site but remember it should have a Username and Password Fields! and Now you are ready!
Seventh Step:
Inorder to avoid suspicion we will maks our IP using a link shortner, head over to http://www.goo.gl. Input your IP from step 5 and get the link.
Eighth Step:
Now with your SE Skills lure your prey to goto that link and enter his/her credentials.
Ninth Step:
Once they enter their credentials you'll get em automatically on your SET Console like
Thats all for now, I hope you guys like my tutorial
For any questions or help PM me, I'll be willing to help ya!
Regards,
Ex094
Well, can you make post on doing this on outside lan. Because i want to know about the hacking this outside LAN.Pls bro... TQ
![[Image: BfeZXSf.png]](http://i.imgur.com/BfeZXSf.png)
![[Image: IK4i7bf.png]](http://i.imgur.com/IK4i7bf.png)
![[Image: 8rInRdw.png]](http://i.imgur.com/8rInRdw.png)
![[Image: SKL0dq1.png]](http://i.imgur.com/SKL0dq1.png)
![[Image: 7ddGjm4.png]](http://i.imgur.com/7ddGjm4.png)
![[Image: UcQNx0H.png]](http://i.imgur.com/UcQNx0H.png)
![[Image: SCXT4LJ.png]](http://i.imgur.com/SCXT4LJ.png)
![[Image: 0XQO4i9.png]](http://i.imgur.com/0XQO4i9.png)
![[Image: U3x30Pq.png]](http://i.imgur.com/U3x30Pq.png)

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)

