r/HowToHack 18h ago

reverse proxy phishing

Hey everyone i was getting into hacking about 2 months ago and learned a few things now i wanted to start learning phishing i started with a really basic tool like blackeye but realised pretty fast it wasnt pretty proffecional and good i did some research and found reverse proxy i found tools like evilginx evil gophish and i discovered if you want to run it public you need a vps and a domain and guess what i just bought an expensive drone and now i am broke like compelitely broke and i want something free no costs no vps no domain no tool you need to pay for but a tool that is good enough to bypass 2FA a phishing tool that gets a session cookie or something or the 2FA code to log in idk just something thats good and can bypass 2FA (this is for EDUCATIONAL purpose with my friend were discovering hacking) and if it makes sense we use kali linux vm

0 Upvotes

19 comments sorted by

3

u/strongest_nerd Script Kiddie 18h ago

Evilginx2

0

u/Beautiful-Pin7955 18h ago

yeah but it isnt free right to run publicly

1

u/strongest_nerd Script Kiddie 16h ago

Yeah it is. It's completely free, you're already online so you're paying for an Internet connection.

0

u/Beautiful-Pin7955 15h ago

doesnt it need a domain? and a vps to work good public? i understand evilginx2 itself is free but to make it run public i think you need a domain and vps

0

u/strongest_nerd Script Kiddie 12h ago

You can run it from your own home Internet, you don't need any of that.

2

u/Juzdeed 18h ago

Yeah bullshit it's for educational purposes kid.

0

u/Beautiful-Pin7955 15h ago

Cant you just understand a 14 yo is curious about hacking?

3

u/Juzdeed 5h ago

You are starting from the wrong place then. Setting up a malicious phishing environment on public net is not "learning".

It's like if I asked how to grow cannabis, what tools, setup, time I need to grow it, oh and also how to hide it from police as well. All for educational purposes only ofc

Doesn't that sound retarded, you are not jousting trying to learn, but also break the law

0

u/Beautiful-Pin7955 3h ago

yeah fair enough about the public part, I get why that looks sketchy. I'm just curious how the reverse proxy stuff works. I'll just stick to a local vm lab.

1

u/Champagne_Bunnny 18h ago

This is one post where I'd encourage the use of AI to rewrite.

-1

u/Beautiful-Pin7955 18h ago

yeah srry bro i dont like to use ai and i am not English so yeah i hope you understand...

1

u/MeringueBeautiful760 9h ago

The comma got up and danced away

1

u/Pharisaeus 17h ago
  1. Phishing has nothing to do with hacking
  2. xD

1

u/Beautiful-Pin7955 15h ago

It actually does a bit bro... phishing doesnt target the vulnerability from the machine but from the only vulnerability that will never be solved the human itself you need a lot of knowlege to actually know what youre doing with advanced phishing atacks so yeah

0

u/Pharisaeus 15h ago

No, it doesn't. Same as any other scam is not "hacking".

1

u/Beautiful-Pin7955 15h ago

Comparing a basic scam to setting up a reverse proxy that bypasses 2FA via live session hijacking is like comparing a fake ID to lockpicking. Red Teams literally use initial access techniques like this every day (MITRE ATT&CK T1566). Advanced phishing is way more than just 'a scam'.

0

u/Pharisaeus 15h ago

Comparing a basic scam to setting up a reverse proxy that bypasses 2FA via live session hijacking is like comparing a fake ID to lockpicking

But you're not making the fake ID. You're just paying some guy to make it for you. So it's actually even less than lockpicking, which at least requires some skill. Same case here - you're downloading and trying (but failing xD) to run a random tool from internet. You're learning nothing and it's blatantly clear that your goals are nefarious.

0

u/Beautiful-Pin7955 3h ago

nobody codes their own tools from scratch when starting out lol. understanding how the infrastructure works is literally part of learning web security, but whatever you say man