← Back to list

SOCIAL ENGINEERING

PHISHING

Trevor Gaturuku · 2026-05-21 09:03 · 0 claps · 2.0 min read
#social-engineering #phishing #credential-phishing
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

SOCIAL ENGINEERING

PHISHING

CREDENTIAL PHISING

-Phishing is where a malicious person tries to trick you into giving away sensitive information e.g; passwords and personal details by pretending to be a trusted source.

  • We will us ZPhisher in Kali linux. Install ZPhisher from github.com and it should look like this after typing the commands in the terminal.

  • In this case we will be using google, so we will type “03” then press enter

  • Click on “02” Gmail new login page then press enter

  • We will use “02” cloudflared then it will ask if we need a custom port then we say “N”. This is how it should look after

  • It will then ask us whether we want to mask the url and in this case we will mask the url in order for it to look more secure for the target.
  • I will mask my url as and send it to one of my family members as an example. This is how it should look after masking

  • I sent this to my target and here was the outcome

  • As you can see we were able to find the targets email and password. I later advised them to change their password and beware of similar links
  • We can see that the account is “trendsevents51@gmail.com” and password is “Mombasa202030” and it also showed us the IP address.
  • That is how you phish someone’s details using ZPhisher.

메타데이터
post_id
9b6b4404b349
slug
social-engineering-9b6b4404b349
url
https://medium.com/@trevorgaturuku3/social-engineering-9b6b4404b349
canonical_url
https://medium.com/@trevorgaturuku3/social-engineering-9b6b4404b349
author_url
https://medium.com/@trevorgaturuku3
status
ok
fetched_at
2026-06-09 15:37:30