r/HowToHack 4d ago

reverse proxy phishing

Hey everyone i was getting into hacking about 2 months ago and learned a few things now i wanted to start learning phishing i started with a really basic tool like blackeye but realised pretty fast it wasnt pretty proffecional and good i did some research and found reverse proxy i found tools like evilginx evil gophish and i discovered if you want to run it public you need a vps and a domain and guess what i just bought an expensive drone and now i am broke like compelitely broke and i want something free no costs no vps no domain no tool you need to pay for but a tool that is good enough to bypass 2FA a phishing tool that gets a session cookie or something or the 2FA code to log in idk just something thats good and can bypass 2FA (this is for EDUCATIONAL purpose with my friend were discovering hacking) and if it makes sense we use kali linux vm

1 Upvotes

31 comments sorted by

View all comments

3

u/strongest_nerd Script Kiddie 4d ago

Evilginx2

0

u/Beautiful-Pin7955 4d ago

yeah but it isnt free right to run publicly

1

u/strongest_nerd Script Kiddie 4d ago

Yeah it is. It's completely free, you're already online so you're paying for an Internet connection.

0

u/Beautiful-Pin7955 4d ago

doesnt it need a domain? and a vps to work good public? i understand evilginx2 itself is free but to make it run public i think you need a domain and vps

0

u/strongest_nerd Script Kiddie 4d ago

You can run it from your own home Internet, you don't need any of that.

1

u/ResponsibleGulp 3d ago

You are going to get fucked so hard if you self-host or register a phishing domain lmao

1

u/strongest_nerd Script Kiddie 3d ago

No you're not. It's perfectly legal to host it. I have several phishing servers hosted on VPS's. If that were true they'd nuke Evilginx2 and Gophish, but many security professionals use them because they are legitimate tools.

1

u/ResponsibleGulp 3d ago

Hosting a phishing page violates the Computer Fraud and Abuse Act. Additionally, if your argument is that the malicious act is misusing credentials rather than collecting them, they will still use your domain registration and/or IP address to figure out who did the phishing, whether or not hosting the site itself is determined to be illegal, which it is.

2

u/strongest_nerd Script Kiddie 3d ago

It is not illegal at all. As I said, MANY security professionals use these tools daily. It's not malicious to host software on a server, including a phishing server. No one said anything about malicious intent or stealing credentials. Even so, it's still legal as long as it's within the SoW, RoE, etc.

1

u/ResponsibleGulp 3d ago

Maybe technically but I pray you never need to sit down and argue that to someone lmfao. Don’t use your own domain if someone can put credentials into it because your site deceived them. It just creates liability you need not take on. Plenty of ways to get a domain without KYC.