How To Hack Gmail, Paypal Account of Your Friends Using Phishing Link
How To Hack Gmail, Paypal Account of Your Friends Using Phishing Link
INTRODUCTION
Nowadays phishing attack is going high. Using these phishing attacks, hackers are stealing the user
credentials by provoking the victim to open the link. The same technique can be used to hack GMail,
Facebook, Paypal accounts of your friends using phishing links generated by you. These steps will help you
to understand, on how phishing really happens.
Today we will talk about an Advanced Phishing tool. Using this tool we can create Fake webpage in a minute
and send the link to the victim to steal credentials. This tool creates a replica of a website and generates a
public link for you to share with the victim. Earlier ethical hacking researcher of International Institute of Cyber
Security demonstrated on how easy is to create fake website in minutes for Local Network environment.
ENVIRONMENT
OS: Kali Linux 2019.3 64 bit
Kernel version: 5.2.0
INSTALLATION STEPS
Use this command to clone the project
git clone https://github.com/htr-tech/nexphisher.
root@kali:/home/iicybersecurity# cd nexphisher/
root@kali:/home/iicybersecurity/nexphisher#
Use this command to bash setup to install the packages for the tool and set up the environment.
Splitting up /var/lib/apt/lists/partial/http.kali.org_kali_dists_kali-rolling_InRelease
into data and signature failed
=========================================================================================
=====================SNIP================================================================
===============================================
The following packages were automatically installed and are no longer required:
Now, let’s choose the options and see the how these fake webpages work.
Fist we will try to create a phishing page for GMail.
Now, choose option 3 and then select option 2 Gmail New Login Page.
Now this will create a fake webpage for GMail.
We will now have to create a public URL to send it to the victim.
Now this tool will ask you to select Port Forwarding Option.
In the above picture, we see five different traffic collector tools, these tools collects the traffic from the
victim’s machine and sends back to the hacker console.
Here, choose option 2 Ngrok.
If Ngrok is not installed it will ask you to install Ngrox with API keys.
It will generate a phishing link. Now send this link to the victim.
If victim open the link and enter the credentials in the phishing page.
The server captures the credentials and sends to the hacker. We can see in the below picture.
On the victim’s machine, it will redirect to the original GMail pages to ask the security questions,
which will let the victim believe that everything is working fine.
As you we can see in the below images.
Victim will enter the password and enter into original account.
But victim is unaware of the fact that his/her password has gone to hacker console.
CONCLUSION
We saw how to create a phishing page and steal the victim’s login credentials. Most of the hackers do it the
same. We must be more conscious while entering our login credentials or personal details. Always check the
Green padlock or the Lock sign next to the URL you open. This will ensure that you are opening a safe website.
Contact https://www.securitynewspaper.com/
MEXICO
538, Homero #303, Chapultepec Morales,
Mexico D.F (Distrito Federal) 11570
INDIA
Fifth Floor, HB Twin Tower
Netaji Subhash Place, Delhi NCR, 110034