Thursday, August 29, 2013

Step by Step Phishing Tutorial-2

Many people ask me that they want to hack Gmail, Facebook or yahoo id’s of their friends. Today I am sharing with you the concept of Phishing. This is similar to Fishing, where the fisherman puts a bait at the hook, thus, pretending to be a genuine food for fish. But the hook inside it takes the complete fish out of the lake.

Phishing is a way of attempting to acquire sensitive information such as usernames, passwords and credit card details by letting victim login on a fake page. In Phishing We Create a fake page of the social networking site on which victim has their profile. By gaining trust of Victim We force him to login to our fake page, When Victim login through fake page he will be redirected to a script which saves the information like username and passwords and then let the user login into their original profile.

I am demonstrating the Phishing attack on Gmail id’s. There are basically three steps Which We have to follow.

Just create an account on any free hosting service like t35.com,000webhost,my3gb.com, or heliohost.org so that you can upload your files on a server and let victim login through it.

Go to http://www.gmail.com and save the page on your desktop by going to File Menu. Now open this HTML Page with notepad and find action.Change action to action =”script.php”. script.php is the file on which we want to redirect Victim it contains the programming logic to steal information. Save This Gmail HTML Page as index.html

You can Download the script.php file from here. Just copy the content of this file to a notepad and save it as script.php and don’t forget to choose all documents in Save as Type Textbox.

  Now create a blank Text Document and save it as “Passwords.txt”.Now upload index.html, script.php and Passwords.txt to your Web server like example.t35.com.Now give path of http://example.t35.com/index.html to victim and when he try to login his username, password will be saved in Passwords.txt file and you can read username and password from there.


Note : This tutorial is for Educational and Awareness Purpose only.Please do not use Scripts provided in this tutorial to harm anyone’s resources or steal any confidential information...

Step by Step Phishing Tutorial


What is Phishing ?

In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites
, auction sites, online payment processors or IT Administrators are commonly used to lure the unsuspecting. Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Even when using server authentication, it may require tremendous skill to detect that the website is fake.









How To Do Phishing ?

STEP 1:Firstly U Must Signup For A Free Web Hosting Service Like:
www.freehostia.com
www.ripway.com 

www.000webhost.com
www.my3gb.com
www.blackapplehost.com
etc.....

And Register A Domain Or Subdomain.


After Getting Your Signup Done, You Have Your Own Subdomain Like For Instance You Registered With Freehostia,


Then Your Domain Is Like "Www.Yourname.Freehostia.Com"

STEP 2:
Now Login To Your Freehostia Account And Go To "File Manager" In The Freehostia Control Panel.
 

STEP 3:Now what you have to do is, go to your domain folder like "yourname.freehostia.com" and create a seperate folder in that directory.with the name of the site, for eg. Gmail , if you want to phish a gmail account!

STEP 4:
Now (   click here   )to Download and extract the file "phishers created by me" to your desktop. And then open your "gmail" folder. You'll find three files there viz. "mail.php" , "Log.txt" & "gmail.html" (each phisher folder contains same files)

STEP 5:
Now upload "mail.php" & "index.html" "log.txt" to the "gmail" folder you created inside "yourname.freehostia.com"

So when you're done with the uploading part, the link to your gmail phisher is "www.yourname.freehostia.com/gmail/gmail.html".

STEP 6:
Congrats!! That is your gmail phisher!! Now all you have to do is copy the link to the phisher file i.e. "www.yourname.freehostia.com/gmail/index.htm"
And send it to the victim you want to hack! When he/she'll open that link, it'll be directed to your gmail phisher and when he/she logins that page
He/she'll be redirected to the original "gmail" website and you'll get the password in the "jafar.txt" file which will be created in the gmail folder. You created in your freehostia domain and the path to that file will be "www.yourname.freehostia.com/gmail/jafar.txt" ...