Warning - This Website is only for education purposes, By reading these articles you agree that HackingBytes is not responsible in any way for any kind of damage caused by the information provided in these articles.

Tuesday, April 30, 2013

Hacking Facebook Accounts on LAN

Hacking Facebook Accounts on LAN

By : JamesLove

Hello Everyone,
Today i want to share my tutorial on how to Phish usernames & passwords using Credential Harvester found in Backtrack 5/ Social Engineering Kit (SET).

This tutorial is aimed for LAN usage only, This means that this will only work on people connected to the same local area network as you. It will not work if you try it on someone outside your network.
Enjoy!
Tools Needed :
  • Backtrack 5
  • Social Engineering Toolkit (SET)
INSTALLATION :
1) Firstly, click Applications –> Backtrack –> Exploitation Tools –> Social Engineering Toolkit –> SET.
2) The screen shown below will appear, next choose 5 to update your SET and choose “4″ to update your Metasploit Framework. Updating will take awhile depending on your connection. Maybe go have a joint and enjoy some zeppelin?
3) Welcome back Stonie, lets continue. As seen in the picture below we are back to the default screen. Here choose “1″ to choose “Social Engineering Attacks”.
http://zyphyto1.host56.com/snapshot-1.png
4) Next choose “2″ to choose “Website Attack Vendors” as shown below.
http://zyphyto1.host56.com/snapshot2.png
5) Choose “3″ for “Credential Harvester Attack Method”. This is our main ingredient in this exploit.
http://zyphyto1.host56.com/snapshot3.png
6) For this tutorial lets choose “2″ for “Site Cloner” as shown below.
http://zyphyto1.host56.com/snapshot4.png
7) Here you will need to key in your internal IP address, keying your external IP address will only route it back to your internal IP address. So if you do not know where to find your IP address, open up another terminal and type in “IFCONFIG” as shown below.
http://zyphyto1.host56.com/snapshot5.png
http://zyphyto1.host56.com/snapshot6.png
8) After keying in your IP address, you will be prompted to key in the site to clone.
http://zyphyto1.host56.com/snapshot7.png
9) Upon keying in your site to clone, you will be shown the screen below, press the enter button.
http://zyphyto1.host56.com/snapshot8.png
http://zyphyto1.host56.com/snapshot9.png
10) Next open up your Firefox (or whatever browser you use). Type in your IP address in you browser as shown below and press enter.
http://zyphyto1.host56.com/snapshot-10.png
11) The bait is set! If you have done everything correctly, your IP address will now show you a cloned facebook login page as shown below. This is the link we must make our VICTIMS CLICK and LOGIN so you can successfully “PHISH” their credentials.
http://zyphyto1.host56.com/snapshot11.png
12) Now the minute someone opens your link, your terminal will prompt you as shown below.
http://zyphyto1.host56.com/snapshot12.png
13) When the victim types in their username & password, it will lead them to the real Facebook page but the credentials keyed into the cloned site are sent to our terminal.
http://zyphyto1.host56.com/snapshot13.png
14) Voila! As you can see below, email = jameslove & pass = computers.
http://zyphyto1.host56.com/snapshot14.png
OBJECTIVE :
Basically we are using our internal IP address to host a cloned website. We must then proceed to find ways and methods to get our LAN victims to click and login to our cloned sites.

No comments:

Post a Comment

LinkWithin

Related Posts Plugin for WordPress, Blogger...