Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 44 guests online
You are here:
Home
Resources
Tools
Exploit the User with SET – The Social Engineering Toolkit
EH-Net
May 25, 2013, 12:40:03 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tools
(Moderator:
don
) >
Exploit the User with SET – The Social Engineering Toolkit
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Exploit the User with SET – The Social Engineering Toolkit (Read 9601 times)
0 Members and 1 Guest are viewing this topic.
Jhaddix
Sr. Member
Offline
Posts: 317
Exploit the User with SET – The Social Engineering Toolkit
«
on:
March 15, 2010, 05:33:25 PM »
Another Tool Post, full link with videos at the bottom of quote:
Quote
I have to say… SET is just plain awesome. The
Social Engineering Toolkit (SET)
is a set of python scripts created by David Kennedy (aka rel1k) to automate many client side penetration testing vectors. In conjunction with Social-Engineer.org, which is also a top-notch resource, it provides for some of best extensibility in this type testing. A couple of weekends ago Dave released 0.4 of SET at Shmoocon. I’ll be honest, i hadn’t used it much until now but, after a good bit of research I now appreciate its full glory.
SET’s Python scripts allow you to easily create phishing email attacks, create clones of any given URLs you provide it in a web based attack, and then on that page exploit the users machine using a java applet or browser exploits. It can create Malicious PDFs as well. In 0.4 there are many improvements:
- An improved java applet that is multi-platform and deals well with any permission type
- 0.4 adds Metasploit browser exploits in addition to the java applet
- Can launch the “Aurora” style attacks with Metasploit
- Improved cloned sites and redirect to legit site.
- Integrates with Backtrack’s sendmail or gmail addresses
- Spear phishing with input of email lists improved
The SET is highly tied to the Backtrack and Social-Engineer.org communities. Training authors and contributors to these sites are well recognized penetration testers with a high level of interest on client-side and social engineering based attack vectors. You’ll recognize names like Paul Hand, Chris Nickerson, Mati Aharoni, Chris Hadnagy, of course Dave Kennedy, etc, all working on these projects. In addition a whole section of the free Metasploit Unleashed training is dedicated to SET and they have an
excellent setup and usage article here
. Also Social-Engineer.org has an
excellent writeup
as well.
SET has a large fanbase with many useful videos on usage and customized scopes. The First video is actually the new SET 0.4 updates presentation and a recording of all the Firetalks (shorter than regular presentations) at Shmoocon, recorded by Adrian Crenshaw (Irongeek).
Check it and some of the other vids below =)
Videos Here:
http://www.securityaegis.com/exploit-the-user-with-set-the-social-engineering-toolkit/#more-979
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
Ketchup
Hero Member
Offline
Posts: 1021
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #1 on:
March 15, 2010, 06:06:45 PM »
Very cool app. I am going to have to give a try. Thanks for sharing!
Logged
~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
Offline
Posts: 1633
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #2 on:
March 15, 2010, 07:34:19 PM »
David and company release yet another great tool. Went to look him up today (he and I were talking last year about some possibilities while he was at SecureState,) and I didn't realize he left for Diebold. I need to get in touch with him, again, and congratulate him.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
Offline
Posts: 1235
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #3 on:
March 16, 2010, 03:45:02 AM »
SET is really great, already used it a few times. Haven't seen the Shmoocon FireTalks: Both Nights video, thanks for posting.
Logged
j0rDy
Hero Member
Offline
Posts: 590
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #4 on:
March 16, 2010, 04:55:43 AM »
sounds good! cant wait to get an opportunity to try this! working on your social engineering skills improves not only the success of the attack, but gives you more advantage in "real life" too!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Ketchup
Hero Member
Offline
Posts: 1021
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #5 on:
March 16, 2010, 02:19:21 PM »
I've been playing around with this tool, and it definitely saves time. It has a nice interface with msf, and even ettercap for DNS / ARP poisoning. The only issue I am having so far is that some of the msf paths to exploits in SET seem to be incorrect.
Logged
~~~~~~~~~~~~~~
Ketchup
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #6 on:
March 16, 2010, 02:32:57 PM »
I like this tool, I helped someone out using it(reverse vnc payload).
Logged
Knowledge
Resource is Power.
hayabusa
Hero Member
Offline
Posts: 1633
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #7 on:
March 16, 2010, 02:41:41 PM »
Quote from: pizza1337 on March 16, 2010, 02:32:57 PM
I like this tool, I helped someone out using it(reverse vnc payload).
SET? (or msf?)
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #8 on:
March 16, 2010, 03:10:08 PM »
Quote from: hayabusa on March 16, 2010, 02:41:41 PM
Quote from: pizza1337 on March 16, 2010, 02:32:57 PM
I like this tool, I helped someone out using it(reverse vnc payload).
SET? (or msf?)
SET
I just tell the person to go to my IP, and all they have to do after that is run(java prompt) and i can help or do whatever..
Logged
Knowledge
Resource is Power.
pizza1337
Full Member
Offline
Posts: 156
Resource is Power.
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #9 on:
April 01, 2010, 01:58:47 PM »
http://www.secmaniac.com/april-2010/omfg-set-v0-5-teaser/
you guys have to see it!
its awesome.
Logged
Knowledge
Resource is Power.
Ketchup
Hero Member
Offline
Posts: 1021
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #10 on:
April 01, 2010, 04:03:12 PM »
Looks like there a few more automation features coming in the next release. Very nice! A few less tasks I will have to do manually.
Logged
~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
Offline
Posts: 1633
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #11 on:
April 01, 2010, 04:07:05 PM »
No kidding. David's got SET rolling full-steam ahead, and it's nice to see.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
Offline
Posts: 1235
Re: Exploit the User with SET – The Social Engineering Toolkit
«
Reply #12 on:
April 02, 2010, 11:58:23 AM »
Indeed, very nice.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.