Login Register


Credential Harvesting Using SET [A Beginner's Guide] filter_list
Author
Message
RE: Credential Harvesting Using SET [A Beginner's Guide] #11
(02-01-2013, 01:05 PM)Ex094 Wrote: Hello Guys! This is my first tutorial in this section, this tutorial will guide you step by step on how to harvest credentials using Social Engineering Toolkit (SET). To continue this tutorial you'll need:
Code:
1) BackBox or Any other pentest OS having SET (Backtrack Recommended!) 2) Social Engineering Toolkit (Updated) 3) Set of Social Engineering Skills to lure your prey 4) Patience! 5) VPN (Just in case)

First step:
Navigate -> Menu -> Auditing -> Social Engineering -> SET -> set-console
[Image: BfeZXSf.png]

Second Step:
Choose the "Social Engineering Attacks" (DUH! We are using SET!!!!)
[Image: IK4i7bf.png]

Third Step:
Then choose "Website Attack Vector"
[Image: 8rInRdw.png]

Foruth Step:
Now the method we are going to use is "Credential Harvester Attack Method". Now lets stop here for a moment and understand what this method does:
Code:
Credential Harvester Attack Method uses Web Cloning feature to make a clone of a website having Username and Password fields e.g Facebook. When the prey ( TARGET ) enters the user and pass, it harvests it and sends it back to the hunter (YOU) .
[Image: SKL0dq1.png]

Fifth Step:
As we are using the method that uses site cloning so choose "Site Cloner". Next it will ask you your IP so goto http://www.whatismyip.org get your IP.
[Image: 7ddGjm4.png]

Sixth Step:
Now it will ask you to input the site url that you want to clone, For this tutorial I'm using Facebook. You can use any site but remember it should have a Username and Password Fields! and Now you are ready!
[Image: UcQNx0H.png]

Seventh Step:
Inorder to avoid suspicion we will maks our IP using a link shortner, head over to http://www.goo.gl. Input your IP from step 5 and get the link.
[Image: SCXT4LJ.png]

Eighth Step:
Now with your SE Skills lure your prey to goto that link and enter his/her credentials.
[Image: 0XQO4i9.png]

Ninth Step:
Once they enter their credentials you'll get em automatically on your SET Console like
[Image: U3x30Pq.png]

Thats all for now, I hope you guys like my tutorial Smile
For any questions or help PM me, I'll be willing to help ya!
Regards,
Ex094

Well, can you make post on doing this on outside lan. Because i want to know about the hacking this outside LAN.Pls bro... TQ

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #12
(02-01-2013, 01:05 PM)Ex094 Wrote: Hello Guys! This is my first tutorial in this section, this tutorial will guide you step by step on how to harvest credentials using Social Engineering Toolkit (SET). To continue this tutorial you'll need:
Code:
1) BackBox or Any other pentest OS having SET (Backtrack Recommended!) 2) Social Engineering Toolkit (Updated) 3) Set of Social Engineering Skills to lure your prey 4) Patience! 5) VPN (Just in case)

First step:
Navigate -> Menu -> Auditing -> Social Engineering -> SET -> set-console
[Image: BfeZXSf.png]

Second Step:
Choose the "Social Engineering Attacks" (DUH! We are using SET!!!!)
[Image: IK4i7bf.png]

Third Step:
Then choose "Website Attack Vector"
[Image: 8rInRdw.png]

Foruth Step:
Now the method we are going to use is "Credential Harvester Attack Method". Now lets stop here for a moment and understand what this method does:
Code:
Credential Harvester Attack Method uses Web Cloning feature to make a clone of a website having Username and Password fields e.g Facebook. When the prey ( TARGET ) enters the user and pass, it harvests it and sends it back to the hunter (YOU) .
[Image: SKL0dq1.png]

Fifth Step:
As we are using the method that uses site cloning so choose "Site Cloner". Next it will ask you your IP so goto http://www.whatismyip.org get your IP.
[Image: 7ddGjm4.png]

Sixth Step:
Now it will ask you to input the site url that you want to clone, For this tutorial I'm using Facebook. You can use any site but remember it should have a Username and Password Fields! and Now you are ready!
[Image: UcQNx0H.png]

Seventh Step:
Inorder to avoid suspicion we will maks our IP using a link shortner, head over to http://www.goo.gl. Input your IP from step 5 and get the link.
[Image: SCXT4LJ.png]

Eighth Step:
Now with your SE Skills lure your prey to goto that link and enter his/her credentials.
[Image: 0XQO4i9.png]

Ninth Step:
Once they enter their credentials you'll get em automatically on your SET Console like
[Image: U3x30Pq.png]

Thats all for now, I hope you guys like my tutorial Smile
For any questions or help PM me, I'll be willing to help ya!
Regards,
Ex094

Well, can you make post on doing this on outside lan. Because i want to know about the hacking this outside LAN.Pls bro... TQ

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #13
Thank you Ex094 Smile

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #14
Thank you Ex094 Smile

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #15
great tutorial on using this feature of SET i was able to get this to work immediately

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #16
So this is how it work,. i have couple email that try to make me change my fb passwd for security reason, and i tought they really set up a website clone,. Smile) thanks for share this, now i know a little about 'harvesting'

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #17
Thanks for the tutorial, very easy and straight forward.
I have acouple of questions though,
does the person who "logs in" actually get to their facebook/gmail etc..page ?
and if that person writes in (accidentaly or on purpose) wrong credentials do we get them ?

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #18
(08-26-2013, 01:33 PM)codyb Wrote: Thanks for the tutorial, very easy and straight forward.
I have acouple of questions though,
does the person who "logs in" actually get to their facebook/gmail etc..page ?
and if that person writes in (accidentaly or on purpose) wrong credentials do we get them ?

1) No they don't, they just get redirected to their original Facebook login page
2) Yes, whatever the person types it's gonna get displayed to you on via SET console
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #19
Huummm I've a question ...

In your tutorial you used a private IP address which mean you did it on a LAN. Will it work on WAN using public IP address ?

Reply

RE: Credential Harvesting Using SET [A Beginner's Guide] #20
(09-06-2013, 04:29 AM)hunt3r972 Wrote: Huummm I've a question ...

In your tutorial you used a private IP address which mean you did it on a LAN. Will it work on WAN using public IP address ?

Yes it can work on normal WAN but you'll have to take precautions for that because if you are using your IP you can get traced back..
My Blog: http://www.procurity.wordpress.com
Donations: 1HLjiSbnWMpeQU46eUVCrYdbkrtduX7snG

Reply







Users browsing this thread: 1 Guest(s)