Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Exploit the User with SET – The Social Engineering Toolkit
EH-Net
May 25, 2013, 12:40:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Exploit the User with SET – The Social Engineering Toolkit  (Read 9601 times)
0 Members and 1 Guest are viewing this topic.
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« on: March 15, 2010, 05:33:25 PM »

Another Tool Post, full link with videos at the bottom of quote:

Quote
I have to say… SET is just plain awesome. The Social Engineering Toolkit (SET) is a set of python scripts created by David Kennedy (aka rel1k) to automate many client side penetration testing vectors. In conjunction with Social-Engineer.org, which is also a top-notch resource, it provides for some of best extensibility in this type testing. A couple of weekends ago Dave released 0.4 of SET at Shmoocon. I’ll be honest, i hadn’t used it much until now but, after a good bit of research I now appreciate its full glory.

SET’s Python scripts allow you to easily create phishing email attacks, create clones of any given URLs you provide it in a web based attack, and then on that page exploit the users machine using a java applet or browser exploits. It can create Malicious PDFs as well. In 0.4 there are many improvements:

- An improved java applet that is multi-platform and deals well with any permission type
- 0.4 adds Metasploit browser exploits in addition to the java applet
- Can launch the “Aurora” style attacks with Metasploit
- Improved cloned sites and redirect to legit site.
- Integrates with Backtrack’s sendmail or gmail addresses
- Spear phishing with input of email lists improved

The SET is highly tied to the Backtrack and Social-Engineer.org communities. Training authors and contributors to these sites are well recognized penetration testers with a high level of interest on client-side and social engineering based attack vectors. You’ll recognize names like Paul Hand, Chris Nickerson, Mati Aharoni, Chris Hadnagy, of course Dave Kennedy, etc, all working on these projects. In addition a whole section of the free Metasploit Unleashed training is dedicated to SET and they have an excellent setup and usage article here. Also Social-Engineer.org has an excellent writeup as well.

SET has a large fanbase with many useful videos on usage and customized scopes. The First video is actually the new SET 0.4 updates presentation and a recording of all the Firetalks (shorter than regular presentations) at Shmoocon, recorded by Adrian Crenshaw (Irongeek).

Check it and some of the other vids below =)

Videos Here:

http://www.securityaegis.com/exploit-the-user-with-set-the-social-engineering-toolkit/#more-979
Logged

Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: March 15, 2010, 06:06:45 PM »

Very cool app.  I am going to have to give a try.  Thanks for sharing!
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #2 on: March 15, 2010, 07:34:19 PM »

David and company release yet another great tool.  Went to look him up today (he and I were talking last year about some possibilities while he was at SecureState,) and I didn't realize he left for Diebold.  I need to get in touch with him, again, and congratulate him.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #3 on: March 16, 2010, 03:45:02 AM »

SET is really great, already used it a few times. Haven't seen the Shmoocon FireTalks: Both Nights video, thanks for posting.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #4 on: March 16, 2010, 04:55:43 AM »

sounds good! cant wait to get an opportunity to try this! working on your social engineering skills improves not only the success of the attack, but gives you more advantage in "real life" too!
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #5 on: March 16, 2010, 02:19:21 PM »

I've been playing around with this tool, and it definitely saves time.   It has a nice interface with msf, and even ettercap for DNS / ARP poisoning.   The only issue I am having so far is that some of the msf paths to exploits in SET seem to be incorrect. 
Logged

~~~~~~~~~~~~~~
Ketchup
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #6 on: March 16, 2010, 02:32:57 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin
Logged

Knowledge Resource is Power.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #7 on: March 16, 2010, 02:41:41 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin

SET?  (or msf?)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #8 on: March 16, 2010, 03:10:08 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin

SET?  (or msf?)

SET

I just tell the person to go to my IP, and all they have to do after that is run(java prompt) and i can help or do whatever..
Logged

Knowledge Resource is Power.
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #9 on: April 01, 2010, 01:58:47 PM »

http://www.secmaniac.com/april-2010/omfg-set-v0-5-teaser/

you guys have to see it!
its awesome.
Logged

Knowledge Resource is Power.
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #10 on: April 01, 2010, 04:03:12 PM »

Looks like there a few more automation features coming in the next release.   Very nice!   A few less tasks I will have to do manually.
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #11 on: April 01, 2010, 04:07:05 PM »

No kidding.  David's got SET rolling full-steam ahead, and it's nice to see.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #12 on: April 02, 2010, 11:58:23 AM »

Indeed, very nice. Smiley
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.06 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.