Type : Tutorial, Tips and Trick
Level : Easy
Why my inbox mail is have a lot of email that I don't want? how they know my email address so they can sending me some ads to my email address?or even they can send me some fake email address? Actually this method below is usually used by spammers to get an email address and also other people will use Email gathering to create mailing lists and then sending the email address with some ads. Let's see how to get an email address using Google, Bing, and Yahoo via Metaploit step by step.
2. Search E-Mail Collector (extension : rb; filesize : 1.57KB)
Download Link :
3. Internet Connection
1. Open your metasploit console windows /pentest/exploits/framework3/msfconsole
2. If you still dont have search_email_collector.rb in your MSF(Metasploit Framework)3, you can download from the link above and copy to the /pentest/exploits/framework3/modules/auxiliary/gather/. If you don't know how to copy the file in metasploit, you can refer to my previous posts about internet explorer 6 exploit using ie_aurora and see section number 1.
3. type this command below to use the email collector we've been added before.
4. The next step you need to set up the domain you want to locate the email addres.
set DOMAIN microsoft.com
When we finished setup the domain, the default searching engine who will be use for this searching are Google, Bing, and Yahoo.
5. The next step is run the script by typing the run command like the picture below :
There it is the email address for the specified domain.
1. You need to perform email security such as :
- do not posting your email at the public area(forum, website, guestbook, etc), or
- disable "display email address" on your public profile