How To Use Set Kali Linux
( Social Engineering Toolkit (SET): Lesson 1)
{ Clone website to gain victim's passwords }
Section 0. Groundwork Data
- What is the Social-Engineering Toolkit (Prepare)
- The Social-Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the homo element of penetration testing.
- Information technology'due south main purpose is to augment and simulate social-engineering attacks and allow the tester to effectively exam how a targeted attack may succeed.
- Social-Engineering toolkit available on backtrack like on backtrack five, backbox, blackbuntu, Gnacktrack and other Linux distribution that are used for penetration testing.
- Legal Disclaimer
- As a condition of your utilise of this Web site, you warrant to computersecuritystudent.com that you will not employ this Spider web site for whatever purpose that is unlawful or that is prohibited past these terms, conditions, and notices.
- In accord with UCC § 2-316, this product is provided with "no warranties, either limited or implied." The information independent is provided "equally-is", with "no guarantee of merchantability."
- In improver, this is a teaching website that does not condone malicious behavior of whatever kind.
- Your are on find, that standing and/or using this lab outside your "own" test environment is considered malicious and is against the police.
- © 2012 No content replication of whatsoever kind is allowed without express written permission.
Section 1. Configure BackTrack Virtual Machine Settings
- Open up Your VMware Player
- Instructions:
- On Your Host Computer, Become To
- Outset --> All Program --> VMWare --> VMWare Player
- Instructions:
- Edit BackTrack Virtual Auto Settings
- Instructions:
- Highlight BackTrack5R1
- Click Edit virtual machine settings
- Instructions:
- Edit Network Adapter
- Instructions:
- Highlight Network Adapter
- Select Bridged
- Do not Click on the OK Button.
Section ii. Login to BackTrack
- Get-go BackTrack VM Instance
- Instructions:
- Get-go Upwardly VMWare Thespian
- Select BackTrack5R1
- Play virtual car
- Instructions:
- Login to BackTrack
- Instructions:
- Login: root
- Password: toor or <whatever you changed information technology to>.
- Instructions:
- Bring upward the GNOME
- Instructions:
- Type startx
- Instructions:
Department iii. Open Console Final and Recall IP Address
- Open a panel terminal
- Instructions:
- Click on the console terminal
- Instructions:
- Go IP Address
- Instructions:
- ifconfig -a
- Notes(FYI):
- As indicated below, my IP address is 192.168.ane.108.
- Please record your IP address.
- If you don't obtain an IP Address, type "dhclient".
- Instructions:
Department 4. Offset the Social Engineering ToolKit
- Start Social Technology ToolKit
- Instructions:
- cd /pentest/exploits/prepare
- ./set
- Instructions:
- Website Attack Vector
- Instructions:
- Select 2
- Instructions:
- Select Credential Harvester Method
- Instructions:
- Select 3
- Instructions:
- Select Site Cloner
- Instructions:
- Select 2
- Instructions:
- Enter URL to Clone
- Instructions:
- https://world wide web.facebook.com/login.php
- Press <Enter>
- Instructions:
- Website Cloning
- Instructions:
- It might take a few minutes to clone the site.
- Just Press <Enter>
- Then Proceed to the Next Section to text this exploit.
- Note(FYI):
- Now you have created a cloned facebook login webpage that is listening on port lxxx.
- Instructions:
Section 5. Start Up Windows Machine
- Social Engineering Note
- The Victim does non take to utilize the below VMware Instance.
- It can be any type of web browser (i.east., Internet Explorer, Firefox, Chrome, etc) for any type of Operating Organization (Windows, Linux, MacOS, etc).
- Image an aggressor sending an email to the victim that reads, "Hey Cheque out the new beta version of facebook", or whatever website that was cloned.
- Commencement Up Damn Vulnerable WXP-SP2.
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Edit virtual automobile Settings
- Note(FYI) :
- For those of you not function of my grade, this is a Windows XP machine running SP2.
- Instructions:
- Edit Virtual Machine Settings
- Instructions:
- Click on Network Adapter
- Click on the Bridged Radio push button
- Click on the OK Push
- Instructions:
- Play Virtual Machine
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Play virtual auto
- Instructions:
- Logging into Damn Vulnerable WXP-SP2.
- Instructions:
- Username: administrator
- Countersign: Use the Form Password or whatever you set information technology.
- Instructions:
- Open a Command Prompt
- Instructions:
- Get-go --> All Programs --> Accessories --> Control Prompt
- Instructions:
- Obtain Damn Vulnerable WXP-SP2's IP Address
- Instructions:
- ipconfig
- Note(FYI) :
- In my case, Damn Vulnerable WXP-SP2'southward IP Accost 192.168.1.109.
- This is the IP Address of the Victim Automobile that will be attacked by Metasploit.
- Record your Damn Vulnerable WXP-SP2's IP Address.
- Instructions:
Section six. First Up a Web Browser
- Start Upwardly Internet Explorer
- Instructions:
- Kickoff --> All Programs --> Internet Explorer
- Instructions:
- Victim Clicks on Link
- Notation(FYI) :
- Replace 192.168.1.108 with BackTrack's IP Address obtain from (Department 3, Step 2).
- Instructions:
- Place the BackTrack IP in the Address Bar.
- In my example, http://192.168.1.108
- Provide a test UserID.
- Provide a test Password.
- Click Login.
- Place the BackTrack IP in the Address Bar.
- Notation(FYI) :
- Analyzing Results Later Login
- Instructions:
- Observe that the Address URL changed to Facebook.
- This is to give the victim a sense of perhaps a failed login try instead of invoking suspicion and alarm.
- Discover the Electronic mail textbox is populated with the Login you previous supplied to Cloned Webpage.
- Proceed to the next department to see the victim's username and password.
- Observe that the Address URL changed to Facebook.
- Instructions:
Department seven. View Victim's Username and Countersign
- Viewing Victim'due south Username and Password
- Instructions: (On BackTrack)
- Notice that now you have information showing the victim's username and password.
- Let's say y'all sent this cloned link to many victim's and left Set run for a while, you volition run into a lot of username and password combinations.
- To Exit, press the <Ctrl> and "c" key at the same time.
- Notice that now you have information showing the victim's username and password.
- Instructions: (On BackTrack)
- Copy Study Link
- Instructions:
- Highlight the XML link and Right Click
- Click on Copy
- Press <Enter>
- Instructions:
- Exit Web Attack Menu
- Instructions:
- Type 99
- Press <Enter>
- Instructions:
- Go out Web Assault Menu
- Instructions:
- Type 99
- Press <Enter>
- Instructions:
- Go out Spider web Attack Menu
- Instructions:
- cat "reports/2014-02-08 05:10:21.784846.xml "
- Note : In your case, this is the written report created in Footstep ii or this Section.
- Notice the Victim'due south Login Credentials
- cat "reports/2014-02-08 05:10:21.784846.xml "
- Notes(FYI):
- Make sure y'all put quotes(") around your file name.
- Instructions:
- Proof of Lab
- Instructions:
- Clone http://www.linkedin.com
- (See Section 5)
- For the Victim Login utilise the following address
- offset.concluding@victim.com
- Eastward.g., john.grey@victim.com
- true cat the log you created for the cloned linkedin website.
- (See Section 6, Stride five)
- date
- echo "Your Name"
- due east.thousand., echo "John Gray"
- Clone http://www.linkedin.com
- Proof of Lab Instructions :
- Do a Print Screen using the <PrtScn> button.
- Paste into a discussion document.
- Upload to Moodle.
- Instructions:
How To Use Set Kali Linux,
Source: https://www.computersecuritystudent.com/UNIX/BACKTRACK/BACKTRACK5R1/lesson3/index.html
Posted by: torresthislumakin.blogspot.com
0 Response to "How To Use Set Kali Linux"
Post a Comment