Some tools are considered "controversial" for their potential for harm, but in the right hands they can be an abundant source of knowledge. In fact, anything related to computer security follows that pattern, and it's up to each person to set limits. One of the most striking cases is Trape, a package for "analysis and research" that lets us deploy social engineering attacks, with the goal of tracking users and obtaining credentials from their services, among other things.

Trape: How to Track People Online
Trape

Mid last year we shared a tutorial on WiFiSlax, a Linux distro full of tools to evaluate the security of WiFi networks, and if possible, obtain their passwords. Given the popularity of that article, it's clear that users' interest goes beyond stealing the neighbor's WiFi password. The lack of security discipline will make things very easy for any attacker, and that's not limited to local networks. The use of public and open networks to access sensitive services is very worrying. One of the best ways to learn why it represents such a big risk is to put yourself on the other side of the fence and study resources like Trape.

https://www.youtube.com/embed/I9CzSoB05Xo

How Trape Works

Trape presents itself as a tool package capable of executing social engineering attacks and tracking the users it "catches" in the process. The first step is to download Trape and install it on your favorite Linux distro (the example in the video uses Kali Linux). Running Trape requires setting up a "bait", something that leads the user to click on that link. In its initial configuration, it's clear that the link isn't quite right, but that's where user creativity comes in (say, a fake landing page on an open router). Once the "victim" clicks, Trape will present the available information through its control panel.

Trape: How to Track People Online
Location, public and private IP numbers, active services... Trape provides a lot of information

Powerful Session Recognition

One of the most powerful elements in Trape is the session recognition module, compatible with a total of 30 services. Facebook, Twitter, Instagram, Amazon, PayPal... if the user has them open, Trape can know it in real time and perform attacks to steal their credentials. Another option is to inject JavaScript code into the victim's terminal, or try to send a payload. We're barely scratching the surface here with Trape. The rest is a matter of reviewing its documentation and starting to practice with our own terminals. And as always, with responsibility.

Official site: Click here

https://old.neoteo.com/192-168-0-1-por-que-esta-es-la-direccion-por-defecto-de-tu-router/