• We just launched and are currently in beta. Join us as we build and grow the community.

Metasploit Pro – Create Phishing Campaign and Get Social Media Credentials

vinafamily

DeFi Protocol Auditor
V Rep
0
0
0
Rep
0
V Vouches
0
0
0
Vouches
0
Posts
67
Likes
94
Bits
1 MONTH
1 1 MONTH OF SERVICE
LEVEL 1 400 XP
Blue-and-White-Simple-Digital-Advertising-Presentation-3.png


Hey Folks, In our previous articles we discussed about the installation and some features of the Metasploit tool, but in this article we will discuss the leftover features of this tool. You can check both article from here.

Let’s take a look 😛 !!

Boot Metasploit Pro

Let’s boot up your Metasploit framework and select the “Phishing Campaign” option. Through this feature of this tool we can easily host phishing pages on our localhost web server and get the victim’s credentials easily.

1-8.png


Hmm 🙂 !! We have to give the name of the project which we can give as per our own.

2-8.png


After that we have to name the phishing page which will appear in the link and also on the browser. In our case we give the name of the phishing page as “login“. After that select “Custom Campaign” option and click on “Web page“, a sub-feature of “Custom Campaign” option.

3-8.png


Again, you have to give the same name that we gave in the beginning. Then select the type of attack as phishing and enter the address where you want to redirect the victim.

4-8.png


Move to the content section and click on the “Clone Website” option to clone the entire website in just a second. After that give the name of the website you want to clone and then click on “clone” button.

5-9.png


Great 😛 !! You can see the preview of the clone page side by side and it look like same as original facebook page.

6-9.png


Done 🙂 !! All the work is finished and now we need to start the campaign by clicking on it.

7-8.png


Link 🙂 !! The tool generates a phishing link and places it in the “task log” section. Just we need to send it to the victim.

8-7.png


As you can see in the image below what the phishing page looks like after the victim opens the link.

9-5.png


You can see that the credentials has been submit by the victim twice.

10-3.png


Nice 😛 !! Finally, after opening it, we get the credentials of his social media account entered by the victim. Thus, you can host any social media phishing page on metasploit framework and perform phishing attack easily.

11-4.png
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.
 

427,549

310,984

310,993

Top