CamPhish is a camera phishing toolkit inspired from saycheese, it is a upgraded version of saycheese. We can get camera clicks from victim’s mobile’s front cam or PC’s webcam. We can use this on our Kali Linux and we also can use it on our Android mobile phone using Termux.
CamPhish have two automatic generated webpage templates for engaging target on that webpage so the attacker can get more camera snaps.
CamPhish need some tools installed in our system, the tools are php, openssh, git, wget. All these tools comes pre-installed with our Kali Linux system, so we start installation process by entering following command:
For Termux==>
pkg install -y git php openssh wget
git clone https://github.com/techchipnet/CamPhish
It will be cloned on our current working directory, as we can see the process in the following screenshot:
Then we need to to the CamPhish directory by using following command:
cd CamPhish
Then we give the permission to the shell script by running following command:
chmod +x camphish.sh
After this we can run the tool by applying following command:
bash camphish.sh
Then it will open it’s menu as we can see in the following screenshot:
Here we need to select the port forwarding option we can choose between ngrok and Serveo.net as we know serveo server goes down sometimes so we choose ngrok.
Then it will prompt for choose phishing template as we can see in the following screenshot:
Here we got two options, option 1 is festival wishing and other is YouTube. We can choose whatever depending on our social engineering. For an example we choose option 2 for YouTube.
Here the YouTube watch ID means then end id of a YouTube video URL. The screenshot is following:
We copy a YouTube video’s watch ID as per our target’s interest and paste it on CamPhish.
If ngrok is not installed in our system then this tool now download and install ngrok in our system. Then it will configure the server and automatically give us a link. This is the link as we can see in the following screenshot.
Here we can see that we got the ngrok link (can be opened from anywhere via internet) and now we can send this to victim with some social engineering twists. Sending phishing links to target is an art, we have discussed it on this tutorial.
Now whenever target clicks on the link it will open YouTube video in target’s browser and prompt for camera permission. Peoples usually don’t read about the permissions and clicked “OK”. BINGO! We got connected and we can get snaps from victim’s webcam/Frontcam.
Here we can see that target got connected with our CamPhish server and we are getting camera shots. That is how we can take control of front cameras.
Checkout Youtube Video
This tutorial is for educational purpose and Proof of Concept only. Phishing is a crime. If anyone do any illegal activity then we are not responsible for that.
CamPhish: HACK FRONT CAMERA OF ANY SMARTPHONE USING TERMUX ANDROID (Hack By Link🔗 Sending Part2)
Reviewed by Surjeet Roy
on
May 15, 2020
Rating:
Bhai yah dekho lagta hai ki koi permission nahin padta bahar Koi smart hai bhai Koi aisi tric batao Jo automatic ki permission le automatic permission per pul batao yah payload mein ho yah wala link mein
ReplyDeleteBhai yah teku lagta hai ka koi permission nahin padta bhai har Koi smart hai bhai Koi aisi tric batao Jo automatic hi permission le automatic permission pe tool batao batao yah payload mein ho yah wala link mein
ReplyDeleteOnly link bhejoge to koi click na karega kuch socail mind v lago 😁😁
DeletePlayload auto permission hi hai installation time
DeleteI can't find nagrok link. please help me
ReplyDeleteKeep on hotspot on while using this tool
DeleteI had kept hotspot ON but still I didn't get the link
DeleteI had kept hotspot ON but still not get the link
DeletePlease reinstall all pkg
DeleteBro I got cam files but where are they
ReplyDeleteAt Camphish folder
DeleteHow to see video of victum
ReplyDeleteIts only for photos.
DeleteLink is not generating
ReplyDeleteHotspot trun on
DeleteKon kon sa PKG install krna padega camphish open krne ke liye
ReplyDeleteRead full post
Delete