In this hands-on lab, we will create and send a phishing email. The goal is to get the target to click on the link in the email, revealing information about themselves, such as their IP address, browser, and operating system. We will then use the IP address to geolocate the target.
Learning Objectives
Successfully complete this lab by achieving the following learning objectives:
- Install and Start the Apache Web Server
- Install the Apache web server.
yum install httpd
- Start the Apache web server.
systemctl start httpd
- Verify that the server is running.
systemctl status httpd
- Install the Apache web server.
- Find the Target’s IP Address
- Run the following command:
curl ifconfig.me
- Run the following command:
- Create a Resource in the Root Directory of the Server
- Change to the default root directory of the server.
cd /var/www/html/
- Create a new resource.
touch <RESOURCE_NAME>
- Edit the resource file.
echo "Thank you for the free information" > <RESOURCE_NAME>
- Verify that the file is not empty.
cat <RESOURCE_NAME>
- Change to the default root directory of the server.
- Create and Send a Phishing Email
- Use your email client to create and send a phishing email.
- Include an image attachment that links to the resource we created in the previous task.
- Monitor the Server for Incoming Client Connections
- Run the following command:
tail -f /var/log/httpd/access_log
- Run the following command:
- Perform a GeoIP Lookup
- Run the following command:
geoiplookup <IP_ADDRESS>
- Consult the manual pages for more information about the GeoIP lookup tool.
man geoiplookup
- Run the following command: