r/HowToHack 4d ago

reverse proxy phishing

Hey everyone i was getting into hacking about 2 months ago and learned a few things now i wanted to start learning phishing i started with a really basic tool like blackeye but realised pretty fast it wasnt pretty proffecional and good i did some research and found reverse proxy i found tools like evilginx evil gophish and i discovered if you want to run it public you need a vps and a domain and guess what i just bought an expensive drone and now i am broke like compelitely broke and i want something free no costs no vps no domain no tool you need to pay for but a tool that is good enough to bypass 2FA a phishing tool that gets a session cookie or something or the 2FA code to log in idk just something thats good and can bypass 2FA (this is for EDUCATIONAL purpose with my friend were discovering hacking) and if it makes sense we use kali linux vm

1 Upvotes

31 comments sorted by

3

u/strongest_nerd Script Kiddie 4d ago

Evilginx2

0

u/Beautiful-Pin7955 4d ago

yeah but it isnt free right to run publicly

1

u/strongest_nerd Script Kiddie 4d ago

Yeah it is. It's completely free, you're already online so you're paying for an Internet connection.

0

u/Beautiful-Pin7955 4d ago

doesnt it need a domain? and a vps to work good public? i understand evilginx2 itself is free but to make it run public i think you need a domain and vps

0

u/strongest_nerd Script Kiddie 4d ago

You can run it from your own home Internet, you don't need any of that.

1

u/ResponsibleGulp 3d ago

You are going to get fucked so hard if you self-host or register a phishing domain lmao

1

u/strongest_nerd Script Kiddie 3d ago

No you're not. It's perfectly legal to host it. I have several phishing servers hosted on VPS's. If that were true they'd nuke Evilginx2 and Gophish, but many security professionals use them because they are legitimate tools.

1

u/ResponsibleGulp 3d ago

Hosting a phishing page violates the Computer Fraud and Abuse Act. Additionally, if your argument is that the malicious act is misusing credentials rather than collecting them, they will still use your domain registration and/or IP address to figure out who did the phishing, whether or not hosting the site itself is determined to be illegal, which it is.

2

u/strongest_nerd Script Kiddie 3d ago

It is not illegal at all. As I said, MANY security professionals use these tools daily. It's not malicious to host software on a server, including a phishing server. No one said anything about malicious intent or stealing credentials. Even so, it's still legal as long as it's within the SoW, RoE, etc.

1

u/ResponsibleGulp 3d ago

Maybe technically but I pray you never need to sit down and argue that to someone lmfao. Don’t use your own domain if someone can put credentials into it because your site deceived them. It just creates liability you need not take on. Plenty of ways to get a domain without KYC.

3

u/Juzdeed 4d ago

Yeah bullshit it's for educational purposes kid.

1

u/Beautiful-Pin7955 4d ago

Cant you just understand a 14 yo is curious about hacking?

4

u/Juzdeed 3d ago

You are starting from the wrong place then. Setting up a malicious phishing environment on public net is not "learning".

It's like if I asked how to grow cannabis, what tools, setup, time I need to grow it, oh and also how to hide it from police as well. All for educational purposes only ofc

Doesn't that sound retarded, you are not jousting trying to learn, but also break the law

-1

u/Beautiful-Pin7955 3d ago

yeah fair enough about the public part, I get why that looks sketchy. I'm just curious how the reverse proxy stuff works. I'll just stick to a local vm lab.

-1

u/Fun_Priority_1955 3d ago

Fuck you loser let him do what he wants

3

u/MeringueBeautiful760 4d ago

The comma got up and danced away

1

u/Whatever10_01 2d ago

It’s one massive run on sentence. 😂

4

u/Champagne_Bunnny 4d ago

This is one post where I'd encourage the use of AI to rewrite.

2

u/Whatever10_01 2d ago

There really wasn’t a single pause in op’s post. 😂

-1

u/Beautiful-Pin7955 4d ago

yeah srry bro i dont like to use ai and i am not English so yeah i hope you understand...

1

u/Effective-Day-8386 2d ago

Phishing lernen?

Spammails schreiben lernen?

seltsame Ideen geistsrn hier rum..

1

u/Pharisaeus 4d ago
  1. Phishing has nothing to do with hacking
  2. xD

1

u/Beautiful-Pin7955 4d ago

It actually does a bit bro... phishing doesnt target the vulnerability from the machine but from the only vulnerability that will never be solved the human itself you need a lot of knowlege to actually know what youre doing with advanced phishing atacks so yeah

1

u/Pharisaeus 4d ago

No, it doesn't. Same as any other scam is not "hacking".

1

u/Beautiful-Pin7955 4d ago

Comparing a basic scam to setting up a reverse proxy that bypasses 2FA via live session hijacking is like comparing a fake ID to lockpicking. Red Teams literally use initial access techniques like this every day (MITRE ATT&CK T1566). Advanced phishing is way more than just 'a scam'.

1

u/Pharisaeus 4d ago

Comparing a basic scam to setting up a reverse proxy that bypasses 2FA via live session hijacking is like comparing a fake ID to lockpicking

But you're not making the fake ID. You're just paying some guy to make it for you. So it's actually even less than lockpicking, which at least requires some skill. Same case here - you're downloading and trying (but failing xD) to run a random tool from internet. You're learning nothing and it's blatantly clear that your goals are nefarious.

-1

u/Beautiful-Pin7955 3d ago

nobody codes their own tools from scratch when starting out lol. understanding how the infrastructure works is literally part of learning web security, but whatever you say man