- Open Kali Linux, go to : application – Kali Linux – Exploitation Tools – Social Engineering Toolkit – se-toolkit

2. Type Y to agree to the terms and conditions

3. After that, Menu will be shown and select 1 from the menu

4. List of attack will appears, select 2 for website attack vectors

5. Next step, select 3 for credentials harvester attack

6. Select Site Cloner which is number 2

7. Type IP address of Kali Linux virtual machine and press enter.

8. Enter the URL to clone. This time, www.facebook.com is the example.

9. After cloning completed, it will start Credential Harvester

10. Allow credentical harvester attack to fetch infromation from the victim machine. Next step, try to send email to the target so he / she can open and fill the website. Edit the link before sending the email like this.

11. Send the email to the target. Now, try to log into victim windows and open the link. Open the site and fill the email and passwords.

12. Click Log in after fill the email & password, then it will redirect to the real facebook log in page but the email and password data that filled already saved at the set terminal kali linux

13. Open Kali Linux terminal to see the result

Posted by :
Bonfilio Aldrino Sugiarto – CS2020 – 2001611794