Mata-i grasa _|_
RST  

Go Back   RST > >> General << > Stiri Securitate

Stiri Securitate NewsLetter

Reply
Old 03-09-2010, 09:01 AM   #1 (permalink)
Registered user
Bautor de whiskey
 
hozarares's Avatar
 
Join Date: Nov 2009
Location: cluj-napoca
Posts: 302
Rep Power: 1
hozarares se balangane pe drum
Send a message via Skype™ to hozarares
hozarares is offline

Default Malicious Email Social Engineer Attack using Social Engineers Toolkit (SET)


hotel regim hotelier
hotel yahoo domain
The Social-Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing. It's main purpose is to augment and simulate social-engineering attacks and allow the tester to effectively test how a targeted attack may succeed. Currently SET has two main methods of attack, one is utilizing Metasploit[1] payloads and Java-based attacks by setting up a malicious website that ultimately delivers your payload. The second method is through file-format bugs and e-mail phishing. The second method supports your own open-mail relay, a customized sendmail open-relay, or Gmail integration to deliver your payloads through e-mail. The goal of SET is to bring awareness to the often forgotten attack vector of social-engineering. SET was created by Rel1k for social-engineer.org.

This video created by loganWHD demonstrates how to use the Social Engineers Toolkit to perform an email attack using a maliciously encoded PDF. The first step is actually dumpster diving and finding an internal email list of the company. Then he creates a malicious PDF file vulnerable to the util.printf security bug. Then loganWHD uses the SET to create a spoofed email about an important memo to check out the attached PDF for more details. Once the victim opens the attachment, the exploit gets executed and of couse ... GAME OVER! Nicely done!

[Doar userii inregistrati pot vedea linkurile. ]


Sursa : [Doar userii inregistrati pot vedea linkurile. ]
__________________
Decat sa traiesti pentru nimic mai bine sa mori pentru ceva !
  Reply With Quote
Sponsored Links
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump




Copywr0ng (c) 2009 Miercuri catre Joi - RST
All logos and trademarks in this site are property of their respective

Hosted by powerhost.ro