Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
After explaining what is social engineering toolkit and after explaining how effective is this tool
and after showing you if you face any problem using social engineering toolkit in Linux How can you
fix it.
Now let's do some attacks using social engineering toolkit.
So I'm going to go to my college Linux machine and we going to launch a program so you know
and let me open a terminal
and type set to get.
Now many of them can be used using social engineering toolkit targeting immobile or a computer.
In my second hacking course my previous As you can hack in from scratch to advance a technique course
I explain how to use set hacking computers and this course we will focus more about compromising Android
devices mobile phone or tablet.
So I'm going to launch the tools by typing one and we're going start to his website attack victim number
two and then we're going to choose a very simple attack which is a credential harvest attack number
three.
Now this attack can only create a fake Web site that will captures the username and password.
So it's very easy.
It will not be detected by any antivirus or any security software and it's quite easy to implement except
it will need some social engineering skills.
On a separate section in this course I'm going explains a different technique for social engineering.
How can you spoof your email or fake an email and send the fake email.
Or how can you spoof an assessment so how can you spoof the mobile number.
So the tools that we have right now online it's very very helpful when it comes to spoofing or faking
our real information.
So let's focus on this section about the attacks and on the previous and on.
And the separate section on this course we will be talking about the tools that you can use to create
yourself to fake your identities so social engineer will be very convenient.
So we'll talk about that in a separate section in this course.
But now let's talk about that.
So the first attack that we can explain this letter B number three which is a credential.
And when you type credential harvest which is creating a fake Web site and this fake Web site will be
hosted on this Kelly Linux machine.
So it's important to know the IP of Siskin the next machine.
And once you send it by email or by s.m.m was a victim and you click on the link and type username and
password.
It could be capturing a very very simple attack.
We're going to take some advance that.
But the concept is very simple and very easy to implement.
You can create a hiccup site from the web template which is the major Web site like G-mail or Yahoo
or some other.
Or you can use site cloner which if you need to create a fake upside for a specific like bank or for
a specific website.
So you need to create an additional website
or I'm sorry a copy from the site from any known website so you can you can to site cloner.
And he will ask you what is seitan when you type in him he will create a similar one for him but for
simplicity let's take number one which is the web template.
So let me choose one and we're going to ask OK
what is the IP address of your machine which is the supposed back I mean the username and password that
will be sent from the victim to each IP address should be delivered.
You should put here your IP.
Now if you do that locally open as a term you can use the private IP to the terminal and you type IP
config to check IP of your machine.
I'm sorry I ifconfig config to check the IP of your local machine which in my case is one that's.
This would be the IP used here and this would be IP that you need to send to the victim after doing
some manipulation.
If you do that remotely You need to use your public IP and you can have some different section to explains
that I'm going to show you how to do that remotely but the IPs that you need to use what is my IP IPs
that you need to use to to to to do this attack remotely not on the same network.
Is your public IP sounds since in this phase we are doing that remotely and certainly locally.
So I'm going to right here as the IP of my is it.
So I use a private IP of my computer which is 1 9 2 8 1 6 8 1 2 1 0.
See if you didn't need to do that remotely as I just mentioned it was a public IP but there is some
network settings that we can explain later on during this course and.
OK.
OK.
Which website would you like to create a fake one.
So let's take a number to Google
and it's creating a Google web site
to start the process.
Yes.
And yeah I think he's up and running.
Now what I can do I need to send to the victim is the IP that I just brought here as IP of my local
machine.
Of course it will not be sent as an IP as an IP.
I mean I'm going to show you later on how can we change that.
But we need to send it.
We need to send them the IP.
So let's do that together.
When I open my men and send to the victim Zelenka IP as I told you it will beat you and it will be enhanced
it will not be that easy.
So I'm sending from my computer an e-mail.
Let me compose
and send to my email
you go and subject for instant your mail is full.
Then
your mailbox
is full.
Of course you are getting this message all the time that you know you are out of storage and your mean
books is.
Please click
below.
Name it this will be much more convenient if you use it like a fake e-mail.
And actually this will be explained in a different section where how can we spoof the e-mail.
And then I need to put the IP here.
GTP and that's poods IPO was the victim 1 9 2 1 6 8 8 1 8 1 0 3 M.T..
So
the idea should be clear.
But later on you can see that we should not sends IPs this way because you know this is not the right
way but you'll see later how to use that.
Let's just test the concept.
So I sent an in.
Now let me go to my device and let's see it in
a given few seconds.
Here and go.
And when I opened this e-mail and I click on the link
key he would request me for the email and password.
I'm going to type a b c at g mail.
But come and let's put any password 4:44 in and sync and sign in.
Now number one this would be directed to the Google website which is very good because he would think
that maybe he wrote the wrong username and password.
Why here we should be getting the user name and password.
That has just been captured.
So it is it should be here.
Yeah it can go.
This is the username and this is the password.
So it's very simple and it's very easy to implement just as I told you if you use the right tools like
using a website that fake your identity this will be explained in a separate chapter in this course.
Or you can send that through and it's a mess using some software that fake hemis so it will be easy
to complain.
Regarding the IP that we should not use IP the same way it is.
Most people will be using those shortened website.
So if you go here and you go to this like a site like that bit dot NY.
This is a Web site that allows you to change or to shorten it.
It has been created for a good purpose which is if you have a very good read it can be shortened.
But some people are using that in a bad way that for instance if I need to since I was a victim instead
of sending the IP number which would be very suspicion I can do it this way.
1 and 2 to 1 6 8 1 2 1 0 3 and I can type on
shortend and we'll get a different tour and see this is who you are and that you can send to the victim.
So we usually see this kind of you are in Twitter and Facebook and stuff like that to show you how you
know how suspicions this is.
So this was a credential harvest attacks that has for a scoop to capture the username and pass not necessarily
Facebook or Holtman but you can use any web site that has a credential you can clone this website and
send that into the victim.
And you just need to convince them to click on this link next lecture you can see and select another
attack so let's see how to do it.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.