In this attack, we'll be setting up a fake website of a known site. Our copy, however, will allow us to capture the credentials used by the user. To have the user visit our site, you'll need to deliver it via an email with a heading or subject line that will pique the user's interest to visit it. They'll be prompted to log in and that's it, the credentials will be captured:
- Enter setoolkit, then at the main menu, choose option 1 for the social engineering menu.
- Enter 2 at the prompt to choose Website Attack Vectors:
- Enter 3 for Credential Harvester:
At this point, you've successfully loaded Credential Harvester ...