Skip to main content

The Social Engineering Toolkit: Creating Fake Web Sites to Own Boxes

In the Linux Distribution BackTrack 4 it has the Social Engineering Toolkit otherwise known as SET. The homepage for SET is http://www.secmaniac.com/ and there is more useful information there. I am particularly impressed by the new java applet function is SET which allow the tester to effectively test how a targeted attack may succeed. Currently SET has two main methods of attack, one is utilizing Metasploit payloads and Java-based attacks by setting up a malicious website (which you can clone whatever one you want) that ultimately delivers your payload. The second method is through file-format bugs and e-mail phishing. The second method supports your own open-mail relay, a customized sendmail open-relay, or Gmail integration to deliver your payloads through e-mail.

To see this operation in action Click Here. If you want to install it on your own machine then there will be a tutorial on how to set this up on Saturday.

Comments

Popular posts from this blog

Learning Linux

Learning linux from the ground up is really a challenge. As you progress even more you start customizing your OS from how it starts and how it shutdown. As soon as you start on a Live CD your x server is pretty much either gnome or KDE. I mean it looks easy to do, but as soon as you start research how the x server it can get trick. My recommendation is to also learn the bash line or command prompt. if your good with the line commands then reconfiguring your computer shouldn't be a problem, but you just learn the GUI layer of it and not the line commands believe me your going to have hard time restoring your computer. As I ask people around they say linux is hard to install. The easiest way to partition your drive manually is like this. sda1 /home -- This is where you want to store all your data in case your linux gets corrupted. This space can be as big as you want sda2 /swap -- Linux is just like windows it needs it virtual space. The swap size depends on your phys...

WPA Encryption

Yes it can be crack the only issue is that you really need a huge dictionary list the more the better. what does this mean it just means that you just have to think of a long pass-phrase for your password. Back in mid 2005 you just needed a good CPU to process large amount of data, but now on curtain NVidia cards it can speed up decryption 8 characters - This is consider weak password to industry standards. 20 characters - This is the minimum for industry standards. 63 characters - This is the maximum and consider tough to crack. You may start thinking that any wireless connection is unsafe well its like a catch-22. There are tools out there that can alert you when a hacker is attempting to get in your network. I know most large corporations do have these tools they can either software or hardware. Remember, doing this illegal without the person or corporations permission, but its legal to try it at your own home router. Want to see the process of cr...

Windows 7 - 19 Tips

As I used Windows 7 through out the months there features that have been improved such as performance issue.  It's more compatible with Windows XP applications, but more importantly responsive with applications crashing for locking up. Now if your a windows 7 user these are tips that you need to know now this article comes from maximum pc. Click on the link to read on ahead, http://www.maximumpc.com/article/features/nix_friction_your_win7_system?page=0%2C0