@_mpta09_:

🐥
🐥
Open In TikTok:
Region: VN
Saturday 01 August 2026 20:30:07 GMT
207
37
0
2

Music

Download

Comments

There are no more comments for this video.
To see more videos from user @_mpta09_, please go to the Tikwm homepage.

Other Videos

Explanation of AdvPhishing with OTP Simulation (Educational Focus) AdvPhishing is an open-source Bash script tool for simulating OTP (One-Time Password) phishing attacks in ethical cybersecurity training, such as red team exercises or awareness labs. It creates fake login pages mimicking popular sites (e.g., social media, banking) to capture credentials and OTPs, demonstrating vulnerabilities in two-factor authentication (2FA). For educational use only—misuse is illegal and unethical; always use with consent in controlled environments, complying with laws like the Computer Fraud and Abuse Act. Core Functionality * Purpose: Simulates phishing to teach how attackers bypass 2FA by intercepting OTPs. * Platform: Runs on Linux (Kali, Parrot OS, Ubuntu, Arch), Android (Termux), or iOS (via iSH emulation). * Features:     * Templates: Customizable phishing pages for popular sites.     * Data Capture: Logs credentials and OTPs to a file (usernames.dat) or email.     * Tunneling: Supports LOCALHOST or Ngrok for external links.     * Email Integration: Sends captured data via Gmail SMTP (requires less-secure app settings).     * Prerequisites: PHP, Apache2, sudo, Ngrok token. * OTP Bypass Technique:     1. Trainee clicks a fake link, enters credentials on a cloned page.     2. Instructor uses credentials on the real site to trigger an OTP.     3. Trainee enters OTP on the fake page; it’s captured, allowing the instructor to log in first.     4. Demo highlights defenses: app-based 2FA, hardware keys, URL checks. Setup (Kali or iSH) 1. Clone: git clone https://github.com/Ignitetch/AdvPhishing.git 2. Navigate: cd AdvPhishing 3. Permissions: chmod +x * 4. Run: ./AdvPhishing.sh (or ./Android-Setup.sh for Termux). 5. Configure: Edit config.php with sender/receiver email and app password. 6. Execute: Select template, tunneling option, and monitor captures via email or file. Educational Value * Demonstrates real-world phishing risks and 2FA weaknesses. * Teaches defenses: avoid unsolicited links, use secure authenticators, verify HTTPS/URLs. * Pair with tools like Burp Suite for traffic analysis in labs. Ethical Notes The GitHub README stresses: “TO BE USED FOR EDUCATIONAL PURPOSES ONLY.” Developers (contact: sg5479845@gmail.com) disclaim misuse liability. Safer alternatives like KnowBe4 or Gophish offer compliance-friendly options. Use in isolated setups with explicit consent. #CyberSec #PhishingAwareness #EthicalHacking #OTPBypass #AdvPhisher #iSHShell #CybersecurityTraining #2FASecurity #HackingEthics #PhishingSimulation #CyberDefense #SecurityTools #InfoSec #PenTesting #CyberEducation #OnlineSafety #TechSecurity #EthicalHacker #CyberSkills #SecurityAwareness #SocialEngineering #WebCloning #CyberTraining #HackerTools #PhishingPrevention #CybersecurityAwareness #PenTest #CyberEd #HackingTools #SecurityTraining #CyberThreats #EthicalHack #2FAProtection #PhishingDemo #CyberLearning #SecureCoding #iOSSecurity #LinuxShell #CyberSim #PhishingTools #SecurityLabs #EthicalPentest #CyberAwarenessMonth #OTPSecurity #WebSecurity #CyberTools #HackingAwareness #SecurityEducation #PhishingDefense #CyberEthics For a step-by-step lab guide or comparison with ZPhisher, let me know!
Explanation of AdvPhishing with OTP Simulation (Educational Focus) AdvPhishing is an open-source Bash script tool for simulating OTP (One-Time Password) phishing attacks in ethical cybersecurity training, such as red team exercises or awareness labs. It creates fake login pages mimicking popular sites (e.g., social media, banking) to capture credentials and OTPs, demonstrating vulnerabilities in two-factor authentication (2FA). For educational use only—misuse is illegal and unethical; always use with consent in controlled environments, complying with laws like the Computer Fraud and Abuse Act. Core Functionality * Purpose: Simulates phishing to teach how attackers bypass 2FA by intercepting OTPs. * Platform: Runs on Linux (Kali, Parrot OS, Ubuntu, Arch), Android (Termux), or iOS (via iSH emulation). * Features: * Templates: Customizable phishing pages for popular sites. * Data Capture: Logs credentials and OTPs to a file (usernames.dat) or email. * Tunneling: Supports LOCALHOST or Ngrok for external links. * Email Integration: Sends captured data via Gmail SMTP (requires less-secure app settings). * Prerequisites: PHP, Apache2, sudo, Ngrok token. * OTP Bypass Technique: 1. Trainee clicks a fake link, enters credentials on a cloned page. 2. Instructor uses credentials on the real site to trigger an OTP. 3. Trainee enters OTP on the fake page; it’s captured, allowing the instructor to log in first. 4. Demo highlights defenses: app-based 2FA, hardware keys, URL checks. Setup (Kali or iSH) 1. Clone: git clone https://github.com/Ignitetch/AdvPhishing.git 2. Navigate: cd AdvPhishing 3. Permissions: chmod +x * 4. Run: ./AdvPhishing.sh (or ./Android-Setup.sh for Termux). 5. Configure: Edit config.php with sender/receiver email and app password. 6. Execute: Select template, tunneling option, and monitor captures via email or file. Educational Value * Demonstrates real-world phishing risks and 2FA weaknesses. * Teaches defenses: avoid unsolicited links, use secure authenticators, verify HTTPS/URLs. * Pair with tools like Burp Suite for traffic analysis in labs. Ethical Notes The GitHub README stresses: “TO BE USED FOR EDUCATIONAL PURPOSES ONLY.” Developers (contact: [email protected]) disclaim misuse liability. Safer alternatives like KnowBe4 or Gophish offer compliance-friendly options. Use in isolated setups with explicit consent. #CyberSec #PhishingAwareness #EthicalHacking #OTPBypass #AdvPhisher #iSHShell #CybersecurityTraining #2FASecurity #HackingEthics #PhishingSimulation #CyberDefense #SecurityTools #InfoSec #PenTesting #CyberEducation #OnlineSafety #TechSecurity #EthicalHacker #CyberSkills #SecurityAwareness #SocialEngineering #WebCloning #CyberTraining #HackerTools #PhishingPrevention #CybersecurityAwareness #PenTest #CyberEd #HackingTools #SecurityTraining #CyberThreats #EthicalHack #2FAProtection #PhishingDemo #CyberLearning #SecureCoding #iOSSecurity #LinuxShell #CyberSim #PhishingTools #SecurityLabs #EthicalPentest #CyberAwarenessMonth #OTPSecurity #WebSecurity #CyberTools #HackingAwareness #SecurityEducation #PhishingDefense #CyberEthics For a step-by-step lab guide or comparison with ZPhisher, let me know!

About