Social engineering is the psychological manipulation of users into performing actions or divulging confidential information. Instead of exploiting technical system flaws, cybercriminals exploit human traits like trust, urgency, fear, and curiosity to gain unauthorized access to accounts like Facebook.
Practical Demonstration
Step1: Open the terminal and type the following command to open setoolkit.
setoolkit
Step2: Select Social Engineering Attacks
1
Step3: Select Web Attack Vectors
2
Step4: Select Credential Harvester Attack
3
Step5: Select Site Cloner
2
Step6: Type your IP address. To perform this attack over WAN you'll need to enter your public/external IP address. To perform over LAN type your internal IP address provided by your router. To find your IP address type ifconfig in new terminal windows and copy your IP address.
ifconfig
Step7: Now input the URL you want to clone and perform a phishing attack over (in this case Facebook)
https://www.facebook.com/
The process will complete in a couple of seconds and then the phishing website will be hosted on the specified IP address on port 80 (mostly).

Now open the website on other device with the IP. Make sure you are connected to same network in case of LAN.

A Facebook Login page is displayed which seems to be legit.

As the user enters the email ID and password it is fetched by setoolkit

The password and email id entered by the victim is successfully fetched by the Hacker (highlighted in red).

The credentials are stored in an XML file to check over them later, to access it open this file location
/root/.set/reportsNow open the only XML file and findthe email and password parameter.

To make the link more convincing, hackers mask the URL with appealing words and phrases with tools like Maskphish (check out: Maskphish)