27. Social Engineering Awareness
27.4 The SET Toolkit (Awareness Only)
Kali madhe Social-Engineer Toolkit (SET) naav cha tool aahe. To phishing pages, fake emails ani payloads banavu shakto. Aapan to attack sathi vaparnar nahi – fakt he samajnyasathi ki attacker kiti sahajtene ek khari-disnari fake login page banavu shakto, mhanun aapan alert rahave.
- SET can clone a real login page so it looks identical to the original.
- It can craft phishing emails and malicious files.
- Authorised companies use it (with written permission) for awareness training – sending a safe fake phishing mail to staff and measuring who clicks, then training them.
SET is for authorised training only
Cloning a real login page and sending it to people is illegal without written authorisation, even as a "joke" or "test". We name SET so you understand how convincing fakes are made – so you and your students never fall for one.
Ravindra Bagale's Tip
After seeing SET, students realise that a fake login page looks exactly like the real one – apart from the URL, there is no difference. So always check the URL in the address bar and the HTTPS lock – that is the only real way to tell. However real a page looks, the URL can be fake.
Ravindra Bagale's Tip – मराठी
SET बघितल्यावर students ना कळते की fake login page खऱ्यासारखेच दिसते – URL सोडून काही फरक नसतो. म्हणून नेहमी address bar मधला URL आणि HTTPS lock तपासा – तीच एकमेव खरी ओळख आहे. Page कितीही खरे दिसले तरी URL खोटा असू शकतो.
Ravindra Bagale's Tip – हिंदी
SET देखने के बाद students को समझ आता है कि fake login page बिलकुल असली जैसा दिखता है – URL के अलावा कोई फ़र्क नहीं होता. इसलिए हमेशा address bar का URL और HTTPS lock जाँचो – यही एकमात्र असली पहचान है. Page कितना भी असली दिखे, URL नकली हो सकता है.
Practice task
Without using SET, explain in your notes why you cannot trust how a login page looks, and what the only reliable check is (the exact URL and HTTPS). Give an example of a lookalike URL for a bank or wallet you use.