Now let's have a look at a Social Engineering plugin that will allow us to steal usernames and passwords from accounts. Basically, it will dim the screen and will tell the person that they got logged out of the session so they need to log in again to get authenticated. This will allow us to bypass HTTPS, HSTS, and all the security that's used by the target account page. For example, if we are trying to get usernames and passwords for Facebook, we will be able to bypass all the security that Facebook uses, because we are just showing a fake Facebook page, so the user will never actually make contact with Facebook. Let's click on Pretty Theft, which will open the tab:
In the preceding screenshot, we can click which account we want to hijack. Let's say we're going with Facebook. We can select what the Backlight will be, so we&apos...