Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


S.E.T. Credential Harvester filter_list
Author
Message
S.E.T. Credential Harvester #1
Credential Harvester Tutorial

What is the social engineer toolkit?

The Social-Engineer Toolkit (SET) was created and written by the founder of TrustedSec. It is an open-source Python-driven tool aimed at penetration testing around Social-Engineering. SET has been presented at large-scale conferences including Blackhat, DerbyCon, Defcon, and ShmooCon. With over two million downloads, SET is the standard for social-engineering penetration tests and supported heavily within the security community.

The Social-Engineer Toolkit has over 2 million downloads and is aimed at leveraging advanced technological attacks in a social-engineering type environment. TrustedSec believes that social-engineering is one of the hardest attacks to protect against and now one of the most prevalent. The toolkit has been featured in a number of books including the number one best seller in security books for 9 months since its release,“Metasploit: The Penetrations Testers Guide” written by TrustedSec’s founder as well as Devon Kearns, Jim O’Gorman, and Mati Aharoni.

SET is included in the latest version of the most popular Linux distribution focused on security, Back|Track. It can also be downloaded through github using the following command:
git clone https://github.com/trustedsec/social-engineer-toolkit/ set/
https://www.trustedsec.com/downloads/soc...r-toolkit/

Alright so getting started! first navigate to S.E.T. : Applications>Kali Linux>Exploitation tools>Social Engineer Toolkit

Now we should be at the main S.E.T screen as shown
Spoiler:
[Image: Screenshotfrom2014-03-10161229_zpsea1e1d68.png]


Now if you noticed there all numbered so i am just going to direct you which numbers to choose from here on out as to avoid tons of pics!

First choose 1: Social Engineering attacks
Second choose 2: Website attack vectors
Third choose 3: Credential Harvester Attack Method
Fourth choose 2: Site cloner


Now if your on linux (which you should be Superman) lol Do a "ifconfig" really quick in terminal and get your IP
If your on windows CMD "ipconfig"


Now type in your IP where it asks for it!
Then it will prompt you for a Website to clone really quick for example i used gmail! http://www.gmail.com

Now you should have a Blue text saying Credential Harvester with the port number as shown below
Spoiler:
[Image: Screenshotfrom2014-03-10161229_zpsea1e1d68.png]



If your shit looks like the pic above your good to go Pirate haha
Now everything is quite simple ( as if it wasnt already Blush) all we are going to do is send our IP to our victim! i suggest shortening the link so he dosnt see a random sketch IP Lol

As soon as our victim clicks the link he will be directed to a IDENTICAL gmail login page and hopefully dumb enough to log in :troll:
Spoiler:
[Image: Screenshotfrom2014-03-10161457_zpsdef1ffd4.png]





As soon as he fills this out and clicks login The username and password will be captured and sent to your S.E.T session as shown below
Spoiler:
[Image: Screenshotfrom2014-03-10161603_zps8db9a190.png]



Well that's it for today folks hope you've enjoyed the Tut and find it useful!!!
Any question feel free to ask :Nerd:

Reply

RE: S.E.T. Credential Harvester #2
Thanks for sharing...
nice tutorial Smile
atleast someone is showing how to use kali Tongue

Reply

RE: S.E.T. Credential Harvester #3
(07-02-2014, 07:19 PM)kIngfAw Wrote: Thanks for sharing...
nice tutorial Smile
atleast someone is showing how to use kali Tongue

It's better to do things manually if you can, though. I really don't reccomend going out and just trying to learn kali.


However, this is a nice tutorial and this kind of thing IS tedious to do on your own, good job on writing it up.

Reply

RE: S.E.T. Credential Harvester #4
Seeing as in this method we use a local IP, does that mean we can only refer this link to users on the same network? If so, is there a method we could use to send this cloned page to others across the internet and still harvest their credentials?

Reply