Social-Engineering Toolkit(SET) 是一个由 David Kennedy (ReL1K)设计的社会工程学工具,该工具集成了多个有用的社会工程学攻击工具在一个统一的简单界面上。SET的主要目的是对多个社会工程攻击工具实现自动化和改良。作为一个渗透测试人员,社会工具是一个有效的攻击手段,但实际上并没有多少人使用它。目前SET更新至1.3.5版,新版主要改变如下:

  • Fixed a bug where create payload and listener wouldn’t work for the new SET interactive shell or RATTE
  • Updated the SET User Manual for version 1.3.5
  • Fixed the core.log(error) core library to properly log potential errors within SET
  • Updated the SET interactive listener to hold over nearly unlimited connections versus the 30 it was initially limited to
  • Turned the Java Repeater off by default, still a bit buggy, feel free to turn on if you want it
  • Added an automatic selection for the Sun Java Applet2ClassLoader Remote Code Execution to select java meterpreter since it is specific to the java meterpreter as a payload selection
  • Fixed alignment issues in the Metasploit attack vectors

工具下载:http://www.secmaniac.com/download/