kgretzky / evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
BSD 3-Clause "New" or "Revised" License
10.94k stars 1.97k forks source link

Phishlets creation step by step #19

Closed yahirlevine closed 6 years ago

yahirlevine commented 6 years ago

Awesome tool! I have tried to play around with the script and create a new phishlet. However i get an error. There is no cookie and no username and password captured. I am possitive that i dont know how to create a new phishlet.

Santa131 commented 6 years ago

Lay out the manual on creating a phishlet!

kgretzky commented 6 years ago

@yahirlevine Check the blog post part where I outlined how the phishlet files are structured and experiment with the ones already released. It is all about trial and error and checking the Network tab in Chrome, in Web Inspector, to see if all redirections worked properly.

@Santa131 I'm pretty confident this will get you banned sooner than I release the manual you wish so much for.

maisonmargiela0 commented 5 years ago

kgretzky Please HELP ME!!!

Everytime I am write a phishlet even I only put a letter and delete it and save the .yaml document, I don't know why but the phishlet does not work anymore. It saves only the user and the pass but the token not. For example I have this phishlet who which has to go perfectly but it does not take the cookies.

author: '@amazonit' min_ver: '2.3.0' proxy_hosts:

PLEASE HELP ME!! I don't know why, as I already said, If I only write and save a phishlet made by you like outlook, after I save it it does not take the cookies anymore... I am using the droplet terminal. When I first install evilginx2 every phishlet is working fine!!!

THANK YOU FOR HELPING ME!!!