Monday, April 23, 2012

Social Engineer Toolkit (SET)

I love the SET. It is fun to see it work. However, it does have its glitches! I also love it when the developers "readme" files leave out stuff you need to make things work!! Then tutorials on these applications follow the leader and perpetuate leaving out STUFF. One example is theHarvester. I have seen the "how-tos" How to execute the application: # python theharvester.py or ./theharvester.py or ./theHarvester.py Even in the downloads "readme" file enclosed and in tutorials it is both ways, i.e. theharvester or theHarvester; h lower case or H upper case. I guess this confusion is built in for the noobs. They cannot have it so easy, they have to learn the hard way. Now let me get to SET. SET I really like. However, a word of caution for serious pentesters who may try to use it. Note that a lot of the applications in SET require a pop up in a browser. Now Mozilla and Firefox developers are quite clever by having built it the newer versions a "pop-up blocker". If pop up blocker is checked in Firefox a lot of the SET apps will not work as intended. No where in any readme files nor in any tutorials is this pointed out. But, we all knew that didn't we??

No comments:

Post a Comment