Inspiration for tutorial: Foxtrot's "How to Trap a Tracker"
If you have been following my past tutorials, (and it's fine if you haven't,) you would know how much social engineering and doxing I do. During these moments when we are convincing people that we are a different person, we need information that doesn't exist. This might lead our target to believe we are false, so we need a foolproof fake identity. This includes a name, credit card number, email, height, weight, date of birth, family, and more. In today's tutorial we will be exploring the world of identity and what makes it so important.
For a fake identity, not only do we need an email, but we need a bunch of them at our disposal. I introduce to you... (drum roll) the disposable email. These emails are free to use and easy to check at any time. My personal favorite disposable email to use is mailinator. Basically, I can make up any email I wish, as long as it is (anything)@mailinator.com, and then I can check that email's inbox at any time by going to http://www.mailinator.com and typing in the name of my email.
We can use these emails for signing up for things that we don't want forensic investigators to dig into, like Social media websites. Along with a disposable email we will also need a "legit" email, like gmail. This legit email, is for big corporations like Facebook, that will detect our fake emails. When you are signing up for this email, use your fake name (which we will get to in the next step) and other info from your fake bio as neccecary.
Along with our email we will need a fake bio. This includes your name and medical information about you. To do this we are going to be using a website called http://www.fakenamegenerator.com/. This website is insanely useful. It gives you a fake name, address, phone number, weight and height, occupation, geolocation, birthday, credit card, and more. To use this generator simply pick your gender and location of the identity and press the red generate button. The following should appear with your information.
We won't be using the email, but this is more than enough information to start with. It even gives us a valid credit card number if we need to trick some people furthur. Now in the next step we are going to make a Facebook page to make our identity more realistic. If you need a better understanding of making fake Facebook pages, Foxtrot made a great tutorial called "How to Trap a Tracker" which goes into detail on how to make a Facebook page that is fake.
So for our Facebook page we are going to need a picture of a person. However, the person we are tricking can reverse image lookup this picture so it would be best to go out and take one. For the sake of this tutorial, I am going to find a group picture on google images, and scroll down a @!$# ton.
I think I'll use this photo. This way our target will assume that we are one of the people in the photo. Now let's look at the Facebook form.
Okeydokey. Here we see we have to put in our full name, email (valid one), password, birthday, and gender. We can obtain most of this info from our fake identity. For me, I would put Wilfredo Kimball for the name, and the rest of the information as follows.
Moral of the story, don't trust anybody whatsoever. Well...just kidding, you can trust some people. However, make sure that they have more than an email to back up their identity, always do research on people, for their safety and for yours as well. Big thanks to Foxtrot for sparking the inspiration for this tutorial and as always any questions are welcome in the comment section! :D
It’s Black Friday week in the Null Byte shop! If you’ve been wanting to improve your skill set in hacker- and cybersecurity-geared topics such as Python, Raspberry Pi, and Linux, now’s the time. We’ve got huge sales on online courses, and we’ve outlined 13 favorites you won’t want to miss. Check them out!