Go Back   All Net Tools - Forum > Main > Internet Privacy
Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #1  
Old 04-25-2007, 06:04 AM
trickytap trickytap is offline
Registered User
 
Join Date: Nov 2006
Posts: 16
my first fake login page

i'm nervous about my first foray into social engineering, i have the fake login page but i don't know how long it's going to be up (assuming hosting sites take down these sorts of things as i have read they do) and i'm not sure what's the best approach to take with my mark(s)... although i feel with the right story i could trick them into using it...

here are the cons with my fake login:

it will only be useful for yahoo passwords
the newest version of ie has phishing security, and it will tell you that the page is suspicious
when the mark types in the password, it doesnt show up in asterisks

here are the pros:

if someone actually is tricked into putting in their password i will get it... lol

does anyone have any marks for me to test run it on?

Last edited by trickytap; 04-25-2007 at 06:08 AM.
Reply With Quote
  #2  
Old 04-25-2007, 01:55 PM
Ezekiel's Avatar
Ezekiel Ezekiel is offline
Moderator
 
Join Date: Sep 2005
Location: UK
Posts: 2,071
Quote:
Originally Posted by trickytap View Post
i'm nervous about my first foray into social engineering, i have the fake login page but i don't know how long it's going to be up (assuming hosting sites take down these sorts of things as i have read they do) and i'm not sure what's the best approach to take with my mark(s)... although i feel with the right story i could trick them into using it...
This part is really up to you and your own creativity. Try to imagine the times when you've been convinced to click a link, either by legitimate people or other social engineers. E-mail spoofing can help.

Quote:
the newest version of ie has phishing security, and it will tell you that the page is suspicious
Those filters only work with lists of known bad URLs. It depends on how long it takes for someone to report your site.

Quote:
when the mark types in the password, it doesnt show up in asterisks
Why? The input tag should have its type set to password (<input type="password" />. Fake pages should be copied from the original website, URLs modified to fit the new location and the form pointed to your new processing script. There's no need to write the whole HTML page from scratch (as this would be pointless and not look genuine).
Reply With Quote
  #3  
Old 04-25-2007, 02:37 PM
Evilthoutz Evilthoutz is offline
Registered User
 
Join Date: Apr 2007
Location: USA
Posts: 14
Send a message via MSN to Evilthoutz Send a message via Yahoo to Evilthoutz
if ur looking for hosting i can host ur fake login for cheap and it wont be taken down
Reply With Quote
  #4  
Old 04-25-2007, 02:45 PM
trickytap trickytap is offline
Registered User
 
Join Date: Nov 2006
Posts: 16
evilthoutz, i may take you up on that if i need to.

mike, where would i need to edit this: (<input type="password" />

can i just open the html in notepad and replace all? what is the original text that i need to replace with this code? all the input values are "hidden". should i change to "password" instead?

oh never mind. i figured it out but it did make a few minor changes to the rest of the page. but the password does type in in asterisks now.

Last edited by trickytap; 04-25-2007 at 03:35 PM.
Reply With Quote
  #5  
Old 04-25-2007, 07:30 PM
trickytap trickytap is offline
Registered User
 
Join Date: Nov 2006
Posts: 16
ok if anybody wants to try it out on someone they know, i can give you the link and if they use it, i can give you the pw too... for a small fee
Reply With Quote
  #6  
Old 04-25-2007, 07:44 PM
nozf3r4tu nozf3r4tu is offline
Registered User
 
Join Date: Aug 2006
Posts: 223
if you have hosted on domains like geocities,tripod ect,best is not to publish it,keep it private and just send out a link to the victim with a spoofed email.
The redirection after they click on sign in or submit should be a obvious one.
__________________
What's New in Politics? Washington Scandals!
Sign My Guestbook!
Internet security is as real as your Dreams!
Reply With Quote
  #7  
Old 04-25-2007, 08:24 PM
trickytap trickytap is offline
Registered User
 
Join Date: Nov 2006
Posts: 16
its not on any of those popular sites, i had to (didnt necessarily want to) go out of my way to find a somewhat obscure hosting site, and im not planning on making it public but will send it out on an individual basis... the redirect is to the REAL login page so you are just under the impression that its not registering or something
Reply With Quote
  #8  
Old 04-26-2007, 02:51 PM
Ezekiel's Avatar
Ezekiel Ezekiel is offline
Moderator
 
Join Date: Sep 2005
Location: UK
Posts: 2,071
Quote:
Originally Posted by nozf3r4tu View Post
if you have hosted on domains like geocities,tripod ect,best is not to publish it,keep it private and just send out a link to the victim with a spoofed email.
The redirection after they click on sign in or submit should be a obvious one.
Geocities, Tripod, Freewebs and all the other hosts from the 90s are for static HTML pages only -- unless you pay for a hosting plan, you won't be able to use any PHP or Perl scripts on them. Without that, you can't really host any phishing pages without resorting to form mailing services.
Reply With Quote
  #9  
Old 05-01-2007, 04:19 PM
Trait Trait is offline
Registered User
 
Join Date: Dec 2006
Posts: 54
lol i wish i knew how to create one of those fake pages, it would sure be usefull to me.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Powered by vBulletin®
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.