"Sumando y Construyendo Conocimiento"

SET 0.7 Liberado con nuevos vectores de ataque

Como se habia anunciado en las sec-list ya esta disponible publicamente la version 0.7 de SET (Social-Engineer Toolkit) que entre sus novedades destacan:

  • Multi-Attack Vector
  • Web Jacking

Les dejo un video donde se muestran las novedades de SET en acción:

Leer Más....

Para los iniciados en SET, indicar que SET es un pequeño script orientado a Ataques de Ingenieria Social en combinación con Metasploit y ayuda enormemente en el montado de escenarios de Phising y de muuuy facil uso (Lease Script-kiddie).

Aqui esta el listado de bug fixes y nuevas funciones en SET v0.7:

* Fixed the NAT/Port FWD descriptions to be a little bit more descriptive
* Bug fixes on payload gen with x64 bit payloads in Metasploit
* Added new Multi-Attack Payload option to utilize multiple attack vectors
* Incorporated Multi-Attack into each web attack vector
* Added a PID management system in SET for stray processes
* Cleaned up payloadgen code and SET code to reflect new multiattack changes
* Added the web jacking attack vector by white_sheep, emgent, and the Back|Track team
* Fixed an issue with ARP Cache defaulting, it should now poison everyone
* Added better error handling within the SET menus, still needs a bit more work
* Cleaned up color schema and removed old code
* Added the Adobe CoolType SING Table ‘uniqueName’ Overflow zero day from Metasploit in spear phishing
* Added two more Teensy based payloads, thanks Garland!
* Added HTML support for Spear-Phishing Attack Vector
* Added HTML support when WEBATTACK_EMAIL=ON for web attack vector
* Added the Adobe Cooltype SING Table Overflow zero day for browser exploit
* Added the new SET User Manual to readme/. This is a big update and has updated content for 0.7
* Fixed a simple yes or no answer when requirements for SET were not met

Mas información en:

Saludos

Manuel Moreno

Insecure Team