Pentest Tools

Published on October 3rd, 2015 📆 | 6611 Views ⚑

0

Weeman – HTTP Server for Phishing


iSpeech

HTTP server for phishing in python. Weeman has support for most of the (bigest) websites.
Usually you will want run Weeman with DNS spoof attack. (see dsniff, ettercap).

[adsense size='1']

Weeman will do the following steps:
  1. Create fake html page.
  2. Wait for clients
  3. Grab the data (POST).
  4. Try to login the client to the original page
Requirements
  • Python <= 2.7.
  • Python BeautifulSoup 4
Install BeautifulSoup
  • Archlinux - sudo pacman -S python2-beautifulsoup4
  • Ubuntu/Linuxmint - sudo apt-get install python-bs4
  • For another OS: - sudo pip install beautifulsoup4
Platforms
  • Linux (any)
  • Mac (Not tested)
  • Windows (Not tested)
[!] If weeman runs on your platform (Mac/Windows), please let me know.

Usage
Just type help
[adsense size='1']
Run server:





  • For port 80 you need to run Weeman as root!
  • Host to clone (Ex: www.social-networks.local)
    set url https://localhost
  • "<"form action = "TAKE THIS URL">"(View the site source and take the URL)
    set action_url https://localhost/sendlogin 
  • The port Weeman server will listen
    set port 2020
  • Start the server
    run

The settings will be saved for the next time you run weeman.py.

Download Weeman



Comments are closed.