Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 68 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Exploit the User with SET – The Social Engineering Toolkit
EH-Net
May 25, 2012, 08:09:13 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Exploit the User with SET – The Social Engineering Toolkit  (Read 8501 times)
0 Members and 5 Guests are viewing this topic.
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« on: March 15, 2010, 05:33:25 PM »

Another Tool Post, full link with videos at the bottom of quote:

Quote
I have to say… SET is just plain awesome. The Social Engineering Toolkit (SET) is a set of python scripts created by David Kennedy (aka rel1k) to automate many client side penetration testing vectors. In conjunction with Social-Engineer.org, which is also a top-notch resource, it provides for some of best extensibility in this type testing. A couple of weekends ago Dave released 0.4 of SET at Shmoocon. I’ll be honest, i hadn’t used it much until now but, after a good bit of research I now appreciate its full glory.

SET’s Python scripts allow you to easily create phishing email attacks, create clones of any given URLs you provide it in a web based attack, and then on that page exploit the users machine using a java applet or browser exploits. It can create Malicious PDFs as well. In 0.4 there are many improvements:

- An improved java applet that is multi-platform and deals well with any permission type
- 0.4 adds Metasploit browser exploits in addition to the java applet
- Can launch the “Aurora” style attacks with Metasploit
- Improved cloned sites and redirect to legit site.
- Integrates with Backtrack’s sendmail or gmail addresses
- Spear phishing with input of email lists improved

The SET is highly tied to the Backtrack and Social-Engineer.org communities. Training authors and contributors to these sites are well recognized penetration testers with a high level of interest on client-side and social engineering based attack vectors. You’ll recognize names like Paul Hand, Chris Nickerson, Mati Aharoni, Chris Hadnagy, of course Dave Kennedy, etc, all working on these projects. In addition a whole section of the free Metasploit Unleashed training is dedicated to SET and they have an excellent setup and usage article here. Also Social-Engineer.org has an excellent writeup as well.

SET has a large fanbase with many useful videos on usage and customized scopes. The First video is actually the new SET 0.4 updates presentation and a recording of all the Firetalks (shorter than regular presentations) at Shmoocon, recorded by Adrian Crenshaw (Irongeek).

Check it and some of the other vids below =)

Videos Here:

http://www.securityaegis.com/exploit-the-user-with-set-the-social-engineering-toolkit/#more-979
Logged

Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #1 on: March 15, 2010, 06:06:45 PM »

Very cool app.  I am going to have to give a try.  Thanks for sharing!
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #2 on: March 15, 2010, 07:34:19 PM »

David and company release yet another great tool.  Went to look him up today (he and I were talking last year about some possibilities while he was at SecureState,) and I didn't realize he left for Diebold.  I need to get in touch with him, again, and congratulate him.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #3 on: March 16, 2010, 03:45:02 AM »

SET is really great, already used it a few times. Haven't seen the Shmoocon FireTalks: Both Nights video, thanks for posting.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #4 on: March 16, 2010, 04:55:43 AM »

sounds good! cant wait to get an opportunity to try this! working on your social engineering skills improves not only the success of the attack, but gives you more advantage in "real life" too!
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #5 on: March 16, 2010, 02:19:21 PM »

I've been playing around with this tool, and it definitely saves time.   It has a nice interface with msf, and even ettercap for DNS / ARP poisoning.   The only issue I am having so far is that some of the msf paths to exploits in SET seem to be incorrect. 
Logged

~~~~~~~~~~~~~~
Ketchup
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #6 on: March 16, 2010, 02:32:57 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin
Logged

Knowledge Resource is Power.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #7 on: March 16, 2010, 02:41:41 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin

SET?  (or msf?)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #8 on: March 16, 2010, 03:10:08 PM »

I like this tool, I helped someone out using it(reverse vnc payload).  Grin

SET?  (or msf?)

SET

I just tell the person to go to my IP, and all they have to do after that is run(java prompt) and i can help or do whatever..
Logged

Knowledge Resource is Power.
pizza1337
Full Member
***
Offline Offline

Posts: 156

Resource is Power.


View Profile
« Reply #9 on: April 01, 2010, 01:58:47 PM »

http://www.secmaniac.com/april-2010/omfg-set-v0-5-teaser/

you guys have to see it!
its awesome.
Logged

Knowledge Resource is Power.
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #10 on: April 01, 2010, 04:03:12 PM »

Looks like there a few more automation features coming in the next release.   Very nice!   A few less tasks I will have to do manually.
Logged

~~~~~~~~~~~~~~
Ketchup
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #11 on: April 01, 2010, 04:07:05 PM »

No kidding.  David's got SET rolling full-steam ahead, and it's nice to see.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #12 on: April 02, 2010, 11:58:23 AM »

Indeed, very nice. Smiley
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.081 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.