> For the complete documentation index, see [llms.txt](https://ceh-practical.cavementech.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ceh-practical.cavementech.com/module-9.-social-engineering/1.-perform-social-engineering-using-tools.md).

# 1. Perform Social Engineering using tools

## 1. Sniff credentials using SET (Social engineering toolkit)

launch SET

```
sudo su
setoolkit
```

Select social engineering toolkit > website attack vectors > credential harvestor > site cloner

<figure><img src="/files/lLvLCKymbAhKpzQuH7r9" alt=""><figcaption></figcaption></figure>

As soon as the victim types in his/her **Username** and **Password** and clicks **Login**, **SET** extracts the typed credentials. These can now be used by the attacker to gain unauthorized access to the victim’s account.

{% embed url="<https://www.udemy.com/course/ethical-hacker-practical/?referralCode=289CF01CF51246BCAD6C>" %}
