Credential harvesting with SET
Credential harvesting can be used with many different types of attacks, but the ultimate goal is to make the user believe he has reached the site that he was trying to get to, such as Facebook or Google, and steal their credentials when they attempt to log in.
In this recipe, we will mimic a site and perform credential harvesting for accounts for that site.
Getting ready
Let's ensure the following prerequisites:
- Kali Linux is running, and you are logged in as root
- Move the interface from one of your Windows test machines to the NAT network temporarily
How to do it...
We will now impersonate a real web site to gather credentials:
- From the
Applications
menu, selectSocial Engineering Tools
|SET Social Engineering Toolkit
. You will be presented with the following screen:

Initial setoolkit screen
- Select the top option,
1) Social-Engineering Attacks
. - Select
2) Website Attack Vectors
. - Select
3) Credential Harvester Attack Method
. - Select
1) Templates
.
- You will then be asked...