hacking Facebook accounts with html

Social engineering is the art of manipulating people into performing actions or divulging confidential information. While similar to a confidence trick or simple fraud, the term typically applies to trickery for information gathering or computer system access and in most cases the attacker never comes face-to-face with the victim.

hacking Facebook accounts with html

Post by tyler040496 on Mon Apr 05, 2010 8:14 pm
([msg=37743]see hacking Facebook accounts with html[/msg])

well, i have this website that all my friends know i have. they go on it often and what not but i was wondering, is it possible for someone to create a html or something of the like, that looks like a Facebook login and sends e-mails. eg a Facebook themed html button that brings up the little popup, Facebook themed login screen, and they type in there username and password and it emails it to you. i think it could work, don't refrain from asking questions!

@@@I am not advising anyone to use this code for malicious reasons and is for educational purposes only@@@
User avatar
tyler040496
New User
New User
 
Posts: 6
Joined: Mon Apr 05, 2010 8:04 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by Goatboy on Mon Apr 05, 2010 9:28 pm
([msg=37746]see Re: hacking Facebook accounts with html[/msg])

Not with raw HTML. You'd need a server language to do that, like PHP or ASP. And this is called "phishing" pronounced as "fishing" and is a fairly common attack.
Assume that everything I say is or could be a lie.
1UHQ15HqBRZFykqx7mKHpYroxanLjJcUk
User avatar
Goatboy
Expert
Expert
 
Posts: 2752
Joined: Mon Jul 07, 2008 9:35 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by sanddbox on Mon Apr 05, 2010 9:53 pm
([msg=37749]see Re: hacking Facebook accounts with html[/msg])

HTML is static - it has no functionality. You can't send emails with it.
Image

HTS User Composition:
95% Male
4.98% Female
.01% Monica
.01% Goat
User avatar
sanddbox
Expert
Expert
 
Posts: 2337
Joined: Sat Jul 04, 2009 5:20 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by jpzricacho on Mon Apr 05, 2010 10:56 pm
([msg=37752]see Re: hacking Facebook accounts with html[/msg])

yes that way of hacking is called phising. there are lot of facebook html page that is used for phising that is complete with javascript, images and more almost completely the same as facebook's log in page.
jpzricacho
New User
New User
 
Posts: 3
Joined: Mon Apr 05, 2010 10:36 am
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by tyler040496 on Tue Apr 06, 2010 9:23 am
([msg=37767]see Re: hacking Facebook accounts with html[/msg])

so html wont work, what scripting language would? btw i'm talking about the popup you get on the screen that you get when you go to a different website and press connect with Facebook button, i suggested html because its more graphical. i have seen a few downloads where you make your own free site like webs.com and get people to sign up on there but i think its way too obvious and people would figure it out. i know it can be done because my old website used to have one that let people email me.
User avatar
tyler040496
New User
New User
 
Posts: 6
Joined: Mon Apr 05, 2010 8:04 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by NeoAtHTS on Tue Apr 06, 2010 11:04 am
([msg=37771]see Re: hacking Facebook accounts with html[/msg])

tyler040496 wrote:so html wont work, what scripting language would? btw i'm talking about the popup you get on the screen that you get when you go to a different website and press connect with Facebook button, i suggested html because its more graphical. i have seen a few downloads where you make your own free site like webs.com and get people to sign up on there but i think its way too obvious and people would figure it out. i know it can be done because my old website used to have one that let people email me.


PHP is one of several server-side scripting languages widely used, and facebook uses PHP.
If you'd like, you can use other scripting languages to impersonate facebook pages, and after you're done with it, you just need to find a way for your intended person to visit your fake facebook page.

And it looks like you need to know more on web pages.
So, please: http://en.wikipedia.org/wiki/Web_page

Hope that helped! ;)
Run.
User avatar
NeoAtHTS
Experienced User
Experienced User
 
Posts: 58
Joined: Tue Apr 28, 2009 9:04 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by sanddbox on Tue Apr 06, 2010 11:18 am
([msg=37774]see Re: hacking Facebook accounts with html[/msg])

jpzricacho wrote:yes that way of hacking is called phising. there are lot of facebook html page that is used for phising that is complete with javascript, images and more almost completely the same as facebook's log in page.


First of all, phishing isn't hacking.

Second of all, you still need a server side language to phish - otherwise you can't record what they entered into the form.
Image

HTS User Composition:
95% Male
4.98% Female
.01% Monica
.01% Goat
User avatar
sanddbox
Expert
Expert
 
Posts: 2337
Joined: Sat Jul 04, 2009 5:20 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by tyler040496 on Wed Apr 07, 2010 8:57 pm
([msg=37871]see Re: hacking Facebook accounts with html[/msg])

im pretty sure that php is something that you use to CREATE a webpage, i'll give you a picture because i'm not sure your getting it.
Image
i would like that to pop up on my website when you press this button
Image
if someone could post a code of that, that would be great :)
User avatar
tyler040496
New User
New User
 
Posts: 6
Joined: Mon Apr 05, 2010 8:04 pm
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by circuitboardsushi on Thu Apr 08, 2010 1:46 am
([msg=37879]see Re: hacking Facebook accounts with html[/msg])

im afraid your not the one whos not getting it

html just formats your content

javascript can do animations and can have a lot of user interaction but again all the data you want (like their password and username) will stay with the user. This is why javascpript is called a client-side scripting language.

What you need to do any kind of phishing is a server-side scripting language. This could be php or it could be something else. You need a script that will store the password the user enters on a computer or server that you will have access to.

I recommend you hit the books a little bit. You should at least know the purposes of the different languages and technology that you're talking about before you make statements about other peoples understanding.

EDIT
Thinking about your question some more there might be way to exploit the connect with facebook buttons that seem to be popping up everywhere. Some kind of user data is interchanged between different servers and is probably interceptable without phishing. Weather such data could be used to exploit facebook pages is a question I cant answer. But that would not be anything like creating a fake connect with facebook button, more like snooping.

The way I would investigate this is to build some kind of legit site (on a server you can access) that has a real connect with facebook button. That should give you plenty of info to find any possible exploits.
circuitboardsushi
New User
New User
 
Posts: 31
Joined: Fri Mar 05, 2010 2:48 am
Blog: View Blog (0)


Re: hacking Facebook accounts with html

Post by tyler040496 on Fri Apr 09, 2010 7:06 pm
([msg=37968]see Re: hacking Facebook accounts with html[/msg])

i'm sorry, this is getting frustrating, i only want a piece of code. i don't want to save anything to my server, i don't want to collect any information, i don't want to be told i don't understand something that all you have to judge me on is the information i provided to you. in case the word "e-mail" outgrows your mental capacity, i would like to transmit a external message across the internet to myself at the receiving end. i would get pretty scared if Hotmail was saving all my messages to their server. but thank you to all the people who gave a positive input, and to you guys who think your being all smart, no, this is not my strong point as i would never post a question on here if it was, and you think your really smart don't you, going around giving people advice, but if there is someone here, on this forum that can make a post without a cocky remark, and without telling them self that they are intelligent, obviously not intelligent enough to answer my question in the first place as it seems, and crawled out of the way of the general meaning if the post, being a request for knowledge, and realize that in avoiding the question in hand, makes you no more intelligent and computer handy as i, in which i highly doubt. now, if anyone peering over this message with knowledge of such task, could point me in the direction of a tutorial, video tutorial, or in fact post some code into their reply,well that would be splendid. sorry if i'm coming across as rude in this post, but don't people like this just get on your nerves.
User avatar
tyler040496
New User
New User
 
Posts: 6
Joined: Mon Apr 05, 2010 8:04 pm
Blog: View Blog (0)


Next

Return to Social Engineering

Who is online

Users browsing this forum: No registered users and 0 guests