Author Topic: How to pass anti phishing software in browsers  (Read 1022 times)

0 Members and 11 Guests are viewing this topic.

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
How to pass anti phishing software in browsers
« on: October 16, 2014, 07:45:00 pm »
Hi guys,


dont know if this is the right thread and i didnt found anything relating my question...


how can i pass the build in anti phishing software in browsers like in google chrome?




my phishing page always gets blocked by chrome, IE and firefox allow it






Offline M1lak0

  • Peasant
  • *
  • Posts: 129
  • Cookies: 10
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #1 on: October 16, 2014, 07:56:26 pm »
Are you sure its done by your browser?? Because its the AV who does or the place where you are hosting..! I neva see or neva came across any of the plugin which does this as you havn't even added any plugin.. Check once again what is blocking and what is happning! :)
"Security is just an illusion"

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #2 on: October 16, 2014, 08:31:54 pm »
thanks for the answer...i guess you mean antivirus when you said av, right?




edit:
i am pretty sure that chrome itself is blocking the site
https://www.google.com/transparencyreport/safebrowsing



« Last Edit: October 16, 2014, 08:37:08 pm by 650m »

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #3 on: October 16, 2014, 09:58:19 pm »
Are you sure its done by your browser?? Because its the AV who does or the place where you are hosting..! I neva see or neva came across any of the plugin which does this as you havn't even added any plugin.. Check once again what is blocking and what is happning! :)


No Chrome does block phishing sites, but only poor made ones (Copy/Paste HTML on free host like 000webhost and a tiny script to retrieve the email + passwd or whatever)however it doesn't detect phishing made with se-toolkit or any advanced phishing website
« Last Edit: October 16, 2014, 10:00:44 pm by Khofo »
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #4 on: October 16, 2014, 10:57:33 pm »

No Chrome does block phishing sites, but only poor made ones (Copy/Paste HTML on free host like 000webhost and a tiny script to retrieve the email + passwd or whatever)however it doesn't detect phishing made with se-toolkit or any advanced phishing website


im relatively new to this topic, no wonder that the sites gets blocked


i also looked into xss, which is still a bit confusiong to me but i got the point


can anyone post a link for some good phishing guides?








Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #5 on: October 16, 2014, 11:03:08 pm »

im relatively new to this topic, no wonder that the sites gets blocked



i also looked into xss, which is still a bit confusiong to me but i got the point


can anyone post a link for some good phishing guides?



Phishing doesn't need any special guide don't bother creating complicates scripts or modifying HTML code just use SET,
Social Engineering Toolkit it automates phishing and gives it an easy look (I had a video tuto on youtube but it got removed cz I gave Facebook as example), SET is integrated in most security distros under, se-toolkit and can be downloaded easily :)
Here is the link to the website: https://www.trustedsec.com/downloads/social-engineer-toolkit/
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #6 on: October 16, 2014, 11:16:43 pm »
sounds good, the thing is that i already got a modified website, so nothing you could easily clone from the original website


is this also compatible?
« Last Edit: October 16, 2014, 11:17:44 pm by 650m »

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #7 on: October 17, 2014, 12:15:24 am »
I think u can import your own website but since I never used used this option I am not sure. Set is extremely easy to use a 10yr old kid can do it: they give u choices and U just have to click on the number corresponding to your choice and this on multiple steps:)
Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #8 on: October 17, 2014, 07:02:26 am »
ok, i will look into it - what about Hosting?

i tried phpnet.us, but after one day the site is offline

i also secured my site with an extra .php script which reveals the original site online if the correct code was entered in the URL
otherwise it will just show "404"

the original .html files were reneamed to .jpg

so im wondering how the crawler could reveal the phishing site


which free hosters are good for hosting phishing sites? i know there are alot of topics for this question , but domains like 000webhosting and co. are just to suspicious.


Offline M1lak0

  • Peasant
  • *
  • Posts: 129
  • Cookies: 10
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #9 on: October 17, 2014, 09:22:45 am »
Hack a site n use it for phishing.. I hacked more than 30 accounts in 2days.. Using some diff SE trick..
"Security is just an illusion"

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #10 on: October 17, 2014, 09:39:32 am »
Sorry, guys, but I will lock this topic for further discussion what to do with it. The content is drifting to assistance in illegal activity. You get notice about the decision later. Promised.

-temporarily locked-

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #11 on: October 18, 2014, 10:25:25 am »
Reopened.

Offline 650m

  • /dev/null
  • *
  • Posts: 10
  • Cookies: -2
    • View Profile
Re: How to pass anti phishing software in browsers
« Reply #12 on: October 18, 2014, 02:42:39 pm »
Reopened.

Thank you, this discussion is not for illegal purpose

So I tried encoding the page with Base64 - useless

-->google chrome runs every site in sandbox mode to test it
So I'm just wondering which method would bypass it