• We just launched and are currently in beta. Join us as we build and grow the community.

Embed Malicious URL in Popular Websites

scamorza

Performance Tuner
S Rep
0
0
0
Rep
0
S Vouches
0
0
0
Vouches
0
Posts
157
Likes
49
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
Rigger-Son-Electricians.png


Hey Folks, in this tutorial we will show you that how you can embed your malicious URL in popular websites such as : Youtube, Facebook and Google etc. These kind of techniques are useful during the social engineering attacks because we can embed our malicious URLs in well known domains and send to the victim.

Reuirements

Kali Linux = Attacker

Lets take a look 🙂 !!

URLCADIZ TOOL

It is open source tool that is hosted on github page. This allow an attacker to embed his malicious code or URL in well known domains. To do our work, we have to download it from the github page.

git clone https://github.com/PerezMascato/URLCADIZ.git1git clone

Install the requirements using the pip command and go to the directory of this tool.

sudo pip3 install pyshorteners
cd URLCADIZ
python3 URLCADIZ.py123sudo pip3 install pyshortenerscd URLCADIZpython3 URLCADIZ.py

1-12.png


It provide us various features as you can see below. For an example we will select the option second.

2-11.png


Here we will paste the original URL of youtube in the first section and our malicious URL in the post link section.

3-13.png


Finalize URL has come before us. Now we can sent this URL to the victim.

4-14.png


You can see that the URL has been successfully redirected to our website.

5-10-1024x473.png

Manual Method

Now we can embed the URL automatically. The usage guide is given below.
Usage 🙂 < orignal URL > < any keywork > @< malicious URL >

https://[email protected]

6-9.png


As soon we will click on ‘Yes’ button the URL will be redirected on malicious website.

7-8-1024x412.png


Great 🙂 !! Similarly we can add phishing page and take the advantage of this technique.

8-8-1024x494.png
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.
 

435,564

313,956

313,965

Top