Saturday 16 January 2016

Hacking Facebook using Facebook Scam Method


Requirements:

1. Facebook Scam source code

2. HTML and javascript knowledge

How to Hacking Facebook using Facebook Scam Method:
1. Download the facebook scam file above and extract it.

2. Open the file using your favourite text editor.

3. We will start from the meta tag.


Information:

og:title –> this will be used for the post title on facebook

og:url –> your website address

og:site_name –> the name of the website how you call it

og:description –> the description to display the short information in the facebook post

og:image –> image will be displayed as a thumbnail on facebook post

You can check the result with help from facebook tools to debug webpage https://developers.facebook.com/tools/debug

4. The next step we need to edit is the redirector after user successfully input the comments.

we can change the window.location from google.com to another website. The website will be loaded after users submit the comment.

5. Wait, where is the facebook hacking according to the post title Hacking Facebook using Facebook Scam Method? We've already posted many simple hacking tutorials and if combined you can create something more useful.

View the last hacking tutorial about hacking facebook scam.

Conclusion:

1. If you don't know about legality of links that shown on facebook, don't directly open it from your browser where your facebook account was logged in, instead open a new browser and open the link from the new browser to prevent and minimize the facebook scam.

2. This tutorial is for education use only!, malicious use will lead you to be banned by facebook or even banned by your hosting or they will send you to the court. We hope you already know about this.


15 Steps to Hacking Windows Using Social Engineering Toolkit and Backtrack 5


What is Social Engineering Toolkit?
“The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the http://www.social-engineer.org launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has incorporated attacks never before seen in an exploitation toolset. The attacks built into the toolkit are designed to be targeted and focused attacks against a person or organization used during a penetration test.”

Actually this hacking method will works perfectly with DNS spoofing or Man in the Middle Attack method. Here in this tutorial I’m only write how-to and step-by-step to perform the basic attack, but for the rest you can modified it with your own imagination  .

In this tutorial we will see how this attack methods can owned your computer in just a few steps….

FYI : The success possibility of this attack depend on victim browser. If the victim never update their browser, the possibility can be 85% or more.

Requirement :
1.  Backtrack 5 (or Backtrack 4)

15 Steps to Hacking Windows Using Social Engineering Toolkit and Backtrack 5 :
1. Change your work directory into /pentest/exploits/set/



2. Open Social Engineering Toolkit(SET) ./set and then choose "Website Attack Vectors" because we will attack victim via internet browser. Also in this attack we will attack via website generated by Social Engineering Toolkit to open by victim, so choose "Website Attack Vectors" for this options.



3. Usually when user open a website, sometimes they don’t think that they are opening suspicious website that including malicious script to harm their computer. In this option we will choose "The Metasploit Browser Exploit Method" because we will attack via victim browser.



4. The next step just choose "Web Templates", because we will use the most famous website around the world that already provided by this Social Engineering Toolkit tools.

5. There are 4 website templates Ready To Use for this attack methods, such as GMail, Google, Facebook, and Twitter. In this tutorial I will use Google, but if you think Facebook or Twitter more better because it’s the most accessed website, just change into what do you want.



6. For the next step…because we didn’t know what kind of vulnerability that successfully attack the victim and what type of browser, etc, in this option we just choose "Metasploit Browser Autopwn" to load all vulnerability Social Engineering Toolkit known. This tools will launch all exploit in Social Engineering Toolkit database.



7. For payload options selection I prefer the most use Windows Shell Reverse_TCP, but you also can choose the other payload that most comfortable for you.

8. The next step is set up the Connect back port to attacker computer. In this example I use port 4444, but you can change to 1234, 4321, etc



9. The next step just wait until all process completed and also wait until the server running.





10. When the link given to user, the victim will see looks-a-like Google(fake website). When the page loads it also load all malicious script to attack victim computer.



12. In attacker computer if there’s any vulnerability in victim computer browser it will return sessions value that mean the exploit successfully attacking victim computer. In this case the exploit create new fake process named "Notepad.exe".
13. To view active sessions that already opened by the exploit type "sessions -l" for listing an active sessions. Take a look to the ID…we will use that ID to connect to victim computer.



14. To interract and connect to victim computer use command "sessions -i ID". ID is numerical value that given when you do sessions -l. For example you can see example in picture below.



15. Victim computer already owned.