This is how easy to phish someone with good Social engineering Techniques
Its
been a while since I posted my last post. So I decided to do a quick
writeup on social engineering attack. I will show how easy it is to
phish someone using a Good social engineering attack. I will try to make
this post noob-friendly to proof that how easy it is for anyone with
good social engineering skills but with little to zero technical
knowledge can phish a user. Even though I am not an expert at soc
engineering I was able to take down some accounts.
Attack scenario
This time I decide to attack random people, this was to see how difficult or easy to phish some random people.
Preparing the Attack
First
I need to make a fake Facebook profile and it’s better to not use those
type of profile which could be easily reverse search like some
celebrity photo etc, so I used “thispersondoesnotexist.com”
which generate fake person pic using AI techniques every time you
refresh the page, so it would be good the choice for making this type of
fake profiles. As shown below I decided to choose below pic which looks
easy to convince people.
I updated the profile pic.
Then
I sent a friend request to some girls profile, this can make it easy to
lure the target if a girl’s profile has more female friends then any
male that will look more legit.
Then I got some request from some male profiles and also got comments on my profile pic.
I
did some usual chat with both of them for some time, I did not reply
immediately to their message when I was AFK. After some long
conversation, when they will get comfortable with the fake
person, I will ask them to do a favor
Preparing The Attack
This time I decided to use automation for this phishing attack, this can save some time also. For the attack, I am going to use socialphish
this comes with some phishing template and also with ngrok as my
current target isn’t techie this time this is a good choice for
tunneling.
I installed it
I chose the first template FbRobotCaptcha on visiting this page will ask to proof if the person is not some bot which looks like as shown below.
On visiting the page will show something like this
Now when the user will choose login with FB it will get redirected to the Facebook login page as shown below
Now on after submitting the password, the user will be redirected to URL shown below
Now the server is up and it’s time to send the link
Sending The link
The first target seems to get offended by asking about his career so I move on to the second target and ask him to do me a favor
Then I told him how to sign up for this petition and then sent the short link.
Now I waited for him to make the login attempt and after some minutes I got the credentials.
Final words
Above
article proof that don't believe everything you see online second never
open any link without complete verification by scanning on virustotal or urlscan.io which is send by some stranger
Comments
Post a Comment