Showing posts with label phising. Show all posts
Showing posts with label phising. Show all posts
Wednesday, May 4, 2011
Hack Facebook Accounts For Free (Disclaimer) :- This guide is for education purpose only. Do not hack others Account, This is illegal and may put you behind jail and high penalty can be exposed. Learn Hacking For Good Purposes. Read Full Article.

Whenever I do chat, all friends asks me that How Can I Hack A Facebook Account. And I probably say please go through my site, And my friends gives me response that Its not working, I am not getting, All methods are old, etc !! . So I rethink and made a mind to create a new fresh tutor on the same topic, though this article is based on old tutor only but its loaded with new tricky part which most hacker apply.
How To Hack Facebook Account For Free Using New Facebook Phishing
How To Hack Facebook Account For Free Using New Facebook Phishing
1. Download Facebook Phishing Script ( This is the latest version created by me )
2. Extract that three files on desktop and then create account on (www.my3gb.com)
3. Upload all three files to my3gb.com and so you will see something like this :
4. Now shorten (name.my3gb.com/index.html) in goo.gl every time for new victim .
4. Now, you have to send this link (goo.gl/------) to victim and make him login.
5. Once you know that victim logined via our Facebook Phishing Page check log.txt
6. In log.txt you will his/her username and password and thus he/she is hacked
Note : If you don't want to create phisher, here is the free openphisher for all
http://fbfbfbfb.my3gb.com/index.html
http://fbfbfbfb.my3gb.com/log.txt
(just send above index.html link to victim and make him login and then check tha username and password in log.txt)
If you think that this is much to trap victim in our phishing net?? And the answer is a BIG NO ! . Now a days all are becoming smart and thus Hackers are also becoming smart, and Hackers hack account using Smart Phishing, also known as Scam.
How To Hack Facebook Account With Smart Facebook Phishing Technique
See the sample of Smart Phishing in below image :-
3. Upload all three files to my3gb.com and so you will see something like this :
4. Now shorten (name.my3gb.com/index.html) in goo.gl every time for new victim .
4. Now, you have to send this link (goo.gl/------) to victim and make him login.
5. Once you know that victim logined via our Facebook Phishing Page check log.txt
6. In log.txt you will his/her username and password and thus he/she is hacked
Note : If you don't want to create phisher, here is the free openphisher for all
http://fbfbfbfb.my3gb.com/index.html
http://fbfbfbfb.my3gb.com/log.txt
(just send above index.html link to victim and make him login and then check tha username and password in log.txt)
If you think that this is much to trap victim in our phishing net?? And the answer is a BIG NO ! . Now a days all are becoming smart and thus Hackers are also becoming smart, and Hackers hack account using Smart Phishing, also known as Scam.
How To Hack Facebook Account With Smart Facebook Phishing Technique
See the sample of Smart Phishing in below image :-
I have included this above html file along with facebook phishing. You have to edit it a bit to replace my phishing link to yours one..
How to edit this file : First open the fake.html in Notepad and do search for "http://goo.gl/Er8JC" without quota ( their are two links, replace that both ) with your fake login link. ( You can make more changes if you are good in HTML ), Now save it and follow the below steps..
1. Go to Fake Email Sender http://emkei.cz/ 2. Now do settings according to the below image only (right click and open image)
How to edit this file : First open the fake.html in Notepad and do search for "http://goo.gl/Er8JC" without quota ( their are two links, replace that both ) with your fake login link. ( You can make more changes if you are good in HTML ), Now save it and follow the below steps..
1. Go to Fake Email Sender http://emkei.cz/ 2. Now do settings according to the below image only (right click and open image)
Note : First check this full trick on yourself for only two times and not more.
4. If all steps were right and victim logined via Facebook Phisher then you can see the password in (log.txt)
4. If all steps were right and victim logined via Facebook Phisher then you can see the password in (log.txt)
5. Thats it, this is the end of Hack Facebook Account using Facebook Phishing.
Wednesday, May 4, 2011 by Rishikesh · 0
Tuesday, March 15, 2011
1. THE SUBJECT LINE
The subject line of an email is much like your first impression - you will get away with nearly anything if you have a good one, and you'll rarely ever recover if you have a bad one. Unfortunately, most of us write bad email subject lines - our subject lines in SE situations tend to be vague and unimaginative.
While it's a natural instinct to want to be as unobtrusive as possible (i.e. when performing most SE engagements, we don't exactly strive to be memorable), this is exactly the logic that will get your emails moved immediately to the "trash" folder (especially if you do a bad job with the next four secrets).
Of course, the subject of the email has to be relevant to what you’ re attempting. If it's not, then you're going to be remembered (and you're going to get reported to the local security team by any moderately responsive workforce).
The subject line of an email is much like your first impression - you will get away with nearly anything if you have a good one, and you'll rarely ever recover if you have a bad one. Unfortunately, most of us write bad email subject lines - our subject lines in SE situations tend to be vague and unimaginative.
While it's a natural instinct to want to be as unobtrusive as possible (i.e. when performing most SE engagements, we don't exactly strive to be memorable), this is exactly the logic that will get your emails moved immediately to the "trash" folder (especially if you do a bad job with the next four secrets).
Of course, the subject of the email has to be relevant to what you’ re attempting. If it's not, then you're going to be remembered (and you're going to get reported to the local security team by any moderately responsive workforce).
Phishing Scenario
Typical Subject Line
Good Subject Line
Fake Administrative Update Security Update Important: Patch Your Computer
Malicious PDF Document from a colleague The Documents you Requested Can you believe that he sent me this?
Direct to an entertaining malicious web link You should see this site Have you seen this one?
Typical Subject Line
Good Subject Line
Fake Administrative Update Security Update Important: Patch Your Computer
Malicious PDF Document from a colleague The Documents you Requested Can you believe that he sent me this?
Direct to an entertaining malicious web link You should see this site Have you seen this one?
2. THE EMAIL ADDRESS
The number of phishing attacks that fail because the email address is too "phishy" probably is nearly innumerable. Many of us intuitively understand this and choose phishing emails that appear to come from the target domain; however, this can limit our ability to perform some of the scenarios that we may hope to accomplish.
This can all be avoided with heavy use of your GoDaddy (or other domain registrar) account and some creativity. Some ideas we have tossed around to make incredibly effective phishing email addresses have included the obvious ones (e.g. .net / .org analogues of our clients' domains) as well as some more esoteric tricks to replicate domains (internationalized domain names that have foreign characters that appear similar to the domain we're attempting to replicate).
An interesting one that we've actually used (effectively) was against a customer who we knew to be heavily dependent on Oracle products within their environment. In attacking their IT staff, we knew that a link sent from Oracle was likely to be acted on quickly. Of course, appearing as though we were Oracle was going to be somewhat difficult. We also realized that the letters "c" and "l" placed next to each other look very much like a "d." So, we registered the domain "orade-support.com" (because "orade.com" was taken).
If you're creative, you can come up with any number of opportunities like this given who you're trying to impersonate.
The number of phishing attacks that fail because the email address is too "phishy" probably is nearly innumerable. Many of us intuitively understand this and choose phishing emails that appear to come from the target domain; however, this can limit our ability to perform some of the scenarios that we may hope to accomplish.
This can all be avoided with heavy use of your GoDaddy (or other domain registrar) account and some creativity. Some ideas we have tossed around to make incredibly effective phishing email addresses have included the obvious ones (e.g. .net / .org analogues of our clients' domains) as well as some more esoteric tricks to replicate domains (internationalized domain names that have foreign characters that appear similar to the domain we're attempting to replicate).
An interesting one that we've actually used (effectively) was against a customer who we knew to be heavily dependent on Oracle products within their environment. In attacking their IT staff, we knew that a link sent from Oracle was likely to be acted on quickly. Of course, appearing as though we were Oracle was going to be somewhat difficult. We also realized that the letters "c" and "l" placed next to each other look very much like a "d." So, we registered the domain "orade-support.com" (because "orade.com" was taken).
If you're creative, you can come up with any number of opportunities like this given who you're trying to impersonate.
3. SALUTATIONS
fontThe salutation of an email tells us much about the sender and their intent. This all goes back to the way that we learned about letter writing when we were growing up – the difference between "Dear Mike," "Hi Mike" "Mike" and "To whom it may concern" is pronounced in our understanding of what is to follow.
This is one of the fundamental failures of most traditional phishing emails sent from overseas (especially those countries with school systems based on British English like India and Nigeria) – they tend to be far more deferential and formal in their salutations than those in the US and Canada are. Imagine, for example, you are sitting at work and get an email from a co-worker that begins with, "Dear Esteemed Colleague." How suspicious would you be?
Similarly, choosing the correct salutation for your email (and, often, the answer "no salutation" is the right one) is required to ensure that your emails don't set off the target's suspicion.
fontThe salutation of an email tells us much about the sender and their intent. This all goes back to the way that we learned about letter writing when we were growing up – the difference between "Dear Mike," "Hi Mike" "Mike" and "To whom it may concern" is pronounced in our understanding of what is to follow.
This is one of the fundamental failures of most traditional phishing emails sent from overseas (especially those countries with school systems based on British English like India and Nigeria) – they tend to be far more deferential and formal in their salutations than those in the US and Canada are. Imagine, for example, you are sitting at work and get an email from a co-worker that begins with, "Dear Esteemed Colleague." How suspicious would you be?
Similarly, choosing the correct salutation for your email (and, often, the answer "no salutation" is the right one) is required to ensure that your emails don't set off the target's suspicion.
4. SIGNATURES
Much like the salutation, we learned from a young age that we needed to sign our letters. Consequently, our reaction to the signature of an email is impressed deeply on our unconscious minds. The right signature can soothe a budding suspicion, while the wrong one will set off alarm bells in even the most otherwise perfect email. As an example, take one of the companies that you interact with often (e.g. Paypal, Google, eBay, etc.) and examine the signatures that accompany each.
You will likely discover a constancy of signature across the emails that unconsciously reassures you of who you're dealing with. Likewise, you probably will notice that your friends all sign their emails in a similar way each time.
For example, anyone receiving an email from me will notice that my notes are signed "-Mike" or "-M" nearly every single time. When I don’ t sign my notes that way, people notice. And anybody attempting to impersonate me had better get that right.
Much like the salutation, we learned from a young age that we needed to sign our letters. Consequently, our reaction to the signature of an email is impressed deeply on our unconscious minds. The right signature can soothe a budding suspicion, while the wrong one will set off alarm bells in even the most otherwise perfect email. As an example, take one of the companies that you interact with often (e.g. Paypal, Google, eBay, etc.) and examine the signatures that accompany each.
You will likely discover a constancy of signature across the emails that unconsciously reassures you of who you're dealing with. Likewise, you probably will notice that your friends all sign their emails in a similar way each time.
For example, anyone receiving an email from me will notice that my notes are signed "-Mike" or "-M" nearly every single time. When I don’ t sign my notes that way, people notice. And anybody attempting to impersonate me had better get that right.
5. TESTING YOUR EMAILS
There are two types of tests that every phishing email should be put through, before it hits the wire to ensure that it has the best chance of success. The first test is to ensure that your email will reach its target, while the second is about ensuring that you're being as appropriate as possible in the way that you write your email.
Tuesday, March 15, 2011 by Rishikesh · 0
Saturday, January 8, 2011
Hi friends I hope you all are fine , After my previous post on " Hack Facebook Account With This Methods " I am again here with the old but new trick that is " Facebook Phisher " . You might be thinking what is new in this but yes in this post I have explained new trick that can perfectly trap your victim in our spider net. Just read on.....
Today I will tell you the latest approach of Hacking Facebook Passwords or Accounts i.e "Smart Phishing with Email trap". And guys you will be surprised to listen that what is the victim's trap ratio in Smart phishing trap is above 70% means , at least 70% people will going to come into your trap and success ratio is 100% means their accounts is yours success. First of all What is "Smart Phishing with Email trap"
Today I will tell you the latest approach of Hacking Facebook Passwords or Accounts i.e "Smart Phishing with Email trap". And guys you will be surprised to listen that what is the victim's trap ratio in Smart phishing trap is above 70% means , at least 70% people will going to come into your trap and success ratio is 100% means their accounts is yours success. First of all What is "Smart Phishing with Email trap"
What Is Smart Phishing With Email Trap
Normal phishing is technique to hack passwords by fooling the victim make him login to particular website suing your phish or fake page. But normal phishing is easily detectable. But Smart Phishing with Email trap is almost undetectable and I will show you How its undetectable. In smart phishing we send HTML mails to the victim with same header as that of original mails by email address that looks similar to original one. And ask user to join some Group or watch video or read comment etc.. And mail looks that user has to enter in it and his password is ours. Here we exploit the fact that Most users who uses Facebook are subscribed to notification by their friends. So its quite easier to exploit fact.
Normal phishing is technique to hack passwords by fooling the victim make him login to particular website suing your phish or fake page. But normal phishing is easily detectable. But Smart Phishing with Email trap is almost undetectable and I will show you How its undetectable. In smart phishing we send HTML mails to the victim with same header as that of original mails by email address that looks similar to original one. And ask user to join some Group or watch video or read comment etc.. And mail looks that user has to enter in it and his password is ours. Here we exploit the fact that Most users who uses Facebook are subscribed to notification by their friends. So its quite easier to exploit fact.
Hack Facebook Account Using Phishing Easily
1. First download our latest " facebook phisher "
2. Extract that folder and you will see two files in that
a. index.html
b. write.php
3. Upload all the Three files to any of the free Web hosting server.
my choice : www.ripway.com
Once you have uploaded all the three files to web hosting server now you have to send these to your victim. This is the most important step regarding smart phishing technique.
Below are some sample mails that will help you to understand how to TRAP victim effectively.
Now You have to edit this mail. Open this email and click on forward now you will see this email in editable mode now remove the forwarded headers etc and forward from Header.
Remember your Name in Gmail must be Facebook and email account should be like noreplyfacebook@gmail.com etc... Now you have to put the Fake link of index.html file that u have got after uploading on the Web hosting server in place of Two exploit points. Remember always put link in href and original text should be as such. And also try to keep the link as much as closer to facebook original link.
Or you can use our own " Fake Email Sender " Two increase the changes
Now After sending phisher to victim, once the user logs in to his Facebook account using your Phisher, his user ID and password are ours..And these are stored in passes.txt ( will created automatically )What you have to do is just refresh your Web hosting account files.
1. First download our latest " facebook phisher "
2. Extract that folder and you will see two files in that
a. index.html
b. write.php
3. Upload all the Three files to any of the free Web hosting server.
my choice : www.ripway.com
Once you have uploaded all the three files to web hosting server now you have to send these to your victim. This is the most important step regarding smart phishing technique.
Below are some sample mails that will help you to understand how to TRAP victim effectively.
Now You have to edit this mail. Open this email and click on forward now you will see this email in editable mode now remove the forwarded headers etc and forward from Header.
Remember your Name in Gmail must be Facebook and email account should be like noreplyfacebook@gmail.com etc... Now you have to put the Fake link of index.html file that u have got after uploading on the Web hosting server in place of Two exploit points. Remember always put link in href and original text should be as such. And also try to keep the link as much as closer to facebook original link.
Or you can use our own " Fake Email Sender " Two increase the changes
Now After sending phisher to victim, once the user logs in to his Facebook account using your Phisher, his user ID and password are ours..And these are stored in passes.txt ( will created automatically )What you have to do is just refresh your Web hosting account files.
4. Now After sending phisher to victim, once the user logs in to his Facebook account using your Phisher, his user ID and password are ours..And these are stored in passes.txt What you have to do is just refresh your Web hosting account files.
5. The passes.txt file will contain the passwords and look like this:
Thats all Now you have hacked the password of victim. I hope you all have Liked It
Saturday, January 8, 2011 by Rishikesh · 1
Subscribe to:
Posts (Atom)


