madman333
Brute Force Master
LEVEL 1
300 XP
data:image/s3,"s3://crabby-images/6202d/6202d1850e049e6bc8a6ee3d95815484ddb8d7e1" alt="Red-and-White-Modern-Corporate-Sports-Youtube-Outro-1.png.webp"
Hey Folks, in this tutorial we are going to discuss on an interesting tool called “seeker” through which we can get exact location and more thing about the target. Concept behind Seeker is simple, just like we host phishing pages to get credentials why not host a fake page that requests your location like many popular location based websites. Seeker Hosts a fake website on In Built PHP Server and uses Serveo to generate a link which we will forward to the target, website asks for Location Permission and if the target allows it, we can get :
- Longitude
- Latitude
- Accuracy
- Altitude – Not always available
- Direction – Only available if user is moving
- Speed – Only available if user is moving
Let’s take a look
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
Installation
Simply download the tool using the git command and then go to the directory. After all, execute the bash command to setup it completely.
git clone https://github.com/thewhiteh4t/seeker.git
cd seeker/
chmod 777 install.sh
bash install.sh1234git clone
https://github.com/thewhiteh4t/seeker.gitcd seeker/chmod777install.shbash install.sh
data:image/s3,"s3://crabby-images/647ae/647aeeeceed592871245ef6f3daaa5b9a4cd92fb" alt="1-22.png"
Error
Done
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/7a5e8/7a5e80f7b48c588b184c6616a76ba94b98cadc59" alt="Slightly frowning face :slight_frown: 🙁"
python3 seeker.py1python3 seeker.py
data:image/s3,"s3://crabby-images/228d5/228d5b27356b9c4f59f61cce713afb0a574a2b04" alt="2-21.png"
Ngrok Setup
To solve this error we have to setup ngrok service. Now firstly we will go to ngrok’s web page, create an account and download ngrok service. After downloading is done then we will unzip the file and start the ngrok service by using the following command.
Loading…
ngrok.com
unzip ngrok-stable-linux-amd64.zip
./ngrok http 80801234
https://ngrok.comcd<location of downloaded file>unzip ngrok-stable-linux-amd64.zip./ngrok http8080
data:image/s3,"s3://crabby-images/0c887/0c887a3f7c51be2b71f27c5acb24957f97641d26" alt="3-22.png"
As you see the ngrok service is finally running in our localhost machine. The highlighted URL will be used to send the victim.
data:image/s3,"s3://crabby-images/9b3d2/9b3d2bebd60531ece2d8d8907833ea26adff4fcd" alt="4-20.png"
Done
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
python3 seeker.py -t manual1python3 seeker.py-tmanual
data:image/s3,"s3://crabby-images/c3989/c39893ea65ffe4b0fb126b48f444021ff0cb31e5" alt="5-17.png"
After selecting the template you need to enter the details according to you.
data:image/s3,"s3://crabby-images/e5cea/e5cea1bad2f57060193275320183a0e75515ef55" alt="6-19.png"
Move
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/d3b2c/d3b2ce4d91b2367c1a42952c631a2bc900abc662" alt="7-15.png"
As soon as the victim opens the attacker’s link, the interface of the phishing template will look like the image below.
data:image/s3,"s3://crabby-images/5caef/5caefbfdcfcd1bc96570f58a746d7bdff9e0f5d5" alt="8-14.png.webp"
After clicking on the “view in telegram” button the error will show on the browser but in reality the victim will allow an attacker to grab their exact location and device details.
data:image/s3,"s3://crabby-images/318fb/318fb569b56b28a15cc988c63a9f7b862a36910c" alt="9-12.png"
BOOM
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/21550/21550c00ba699ccf937464b92ab56b84fce75493" alt="10-10.png"
Even this gives us the link from which we can see the exact location of the victim without using any longitude, latitude. Great
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
data:image/s3,"s3://crabby-images/080b9/080b99afc0b597a2fbc05f61e4dca6b345db9200" alt="11-7.png.webp"
Similarly, you can cheat the victim by sending such fake phishing page and get more information about him.
data:image/s3,"s3://crabby-images/aa711/aa711ec001d3af373b35467e9d669233ade1ddf4" alt="12-6.png"