Never ever use an easily guessable password. Be sure that your password is at least eight characters long and contains letters, numbers and symbols. The stronger, the better.
Chances are you didn't succeed with the first step. Well, that pretty much all you can do... Just kidding. Continue reading!!!
Steal someone's password using phishing
What is phishing?
Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money), often for malicious reasons, by masquerading as a trustworthy entity in an electronic communication.
Simply put, if the user wants to access facebook, he/she has to type in his username/password. If you make him think your page is facebook or needs the passcode for some features to appear, then the user might be tricked into revealing his credentials to a third party.
So, all you have to do is create a phishing page that asks the user for his username/password while your website doesn't seem suspicious. If the user is convinced, he/she will offer his credentials in your hands.
To setup a website like that you'll need a web costing account (you can find plenty, free of charge), upload your documents used to create it(ex. a facebook logo and a neat user/pass field). Now, every time someone enters information to the fields above, a file will be created storing this info for you to see. Simple as that.
Just hand your url to your friends and hope there are plenty of phishes in the sea. You saw what i did there?
!!!Our safety tip!!!Never hand out your credentials to sites you don't trust. Even, if a page asks you for your password be sure to check that it redirects you to the official facebook page.
Read also: Best Facebook Tips, Tricks and HacksSidejacking with Hamster and Ferret
No, this is not a family movie's name.
What is sidejacking?
Sidejacking is the process of stealing someone's access to a website, typically done on wireless public networks. To access to a website, the bad actor uses a packet sniffer to obtain an unencrypted cookie(session cookie) that grants access to a website, such as webmail.
For this to work, you need to be in the same network the user you are trying to steal from is. If you are in a public network,oh boy, start hunting.
We will use
Linux(Backtrack-Linux will definitely do the trick)
for this one. Some tools are available in Windows too.
Follow the steps below:
i)Download Hamster and Ferret if they aren't already in your machine.
ii)Extract and build using the terminal.
iii)Open terminal in Hamster's folder and start Hamster with command "./hamster".
iv)Open your browser and go to http://127.0.0.1:1234
v) Select adapters and type eth0 for ethernet or wlan0 for wireless network.
vi)Now, you must see some targets(their ip address) if someone else is using the network too. You can sidejack his/her session just by clicking the links on the left panel.
Remember, with this technique you don't acquire usernames/passwords but you gain instant and full access to other people's accounts(at least till they log out). This must be what you wanted in the first place, right?
!!!Our safety tip!!!Never trust public networks. Always log in to your accounts from trusted networks(ex. your home) that are properly protected. Also, remember to log out of your accounts after you have finished your work.
Read also: How to secretly accept a friend request on FacebookIf all of the above fail, the next trick will certainly do it.
Defeat SSL with sslstrip
What is SSL?SSL(
Secure Sockets Layer) is a standard security technology for establishing an encrypted link between a server and a client—typically a web server (website) and a browser; or a mail server and a mail client (e.g., Outlook).
Facebook uses SSL. Twitter uses SSL. LinkedIn uses SSL. Everybody uses SSL(I'm quoting Oprah here). If this wasn't the case, oxid's Cain and Abel would be the go to solution.
Here comes sslstrip though.
Sslstrip is a python program created by Moxie Marlinspike that has the capability to "hijack HTTP traffic on a network, watch for HTTPS links and redirects, then map those links into either look-alike HTTP links or homograph-similar HTTPS links".
Let it to the experts. Just follow his tutorial on his official website (
http://www.thoughtcrime.org/software/sslstrip/).
!!!Our safety tip!!!Same goes for this one. Always log into safe networks. You never know where the intruder will be. Take care.
That was the guide on how to : Hack into a Facebook account and steal someone's password. Hope you found it useful. Comment in the section below.