ãã®ããã°ã¯ãæè¿AWSã¨æ ¼éãã¦ããã¢ã«ãã¤ãã®seigo2016ãæ¸ãã¦ãã¾ãã ãããããã¶ããã®å 容ã¯å人ã®æè¦ã§ãã
ã¯ããã«
æ¤è¨¼ã«ã¯èªèº«ã§ç®¡çããç°å¢ã使ç¨ããèªå·±è²¬ä»»ã§ãé¡ããã¾ããã¾ãããã®æ
å ±ãæªç¨ãããã¨ã¯çµ¶å¯¾ã«è¡ããªãã§ãã ããã
ä»åã¯ããã£ãã·ã³ã°ã¡ã¼ã«ããæ¨çåæ»æã¡ã¼ã«ã®è¨ç·´ã«æç¨ãªã½ããã¦ã§ã¢ã§ãããEvilgophishã®æ¤è¨¼ãè¡ãã¾ããã
æ¦è¦
Evilgophishã¯ãä¸éè
æ»æãã¬ã¼ã ã¯ã¼ã¯ã®Evilginx3ã¨ããã£ãã·ã³ã°ãã¼ã«ãããã®Gophishãçµã¿åãããã½ããã¦ã§ã¢ã§ãã
Evilgophishã使ããã¨ã§ãã½ã¼ã·ã£ã«ã¨ã³ã¸ãã¢ãªã³ã°ãæ¨çåæ»æã¡ã¼ã«ã®è¨ç·´ããã¹ããè¡ããã¨ãã§ãã¾ãã
Evilginxã«ã¤ãã¦
Evilginxã¯ãã»ãã·ã§ã³Cookieã¨å ±ã«ãã°ã¤ã³èªè¨¼æ å ±ããã£ãã·ã³ã°ããä¸éè æ»æãã¬ã¼ã ã¯ã¼ã¯ã§ãã Goè¨èªã§ç¬èªã®HTTPåã³DNSãµã¼ãã¼ãå®è£ ããã¦ãã¾ãã
Gophishã«ã¤ãã¦
Gophishã¯ããããã¬ã¼ã·ã§ã³ãã¹ãçåãã«è¨è¨ãããããªã¼ãã³ã½ã¼ã¹(MIT License)ã®ãã£ãã·ã³ã°ãã¼ã«ãããã§ãã ãã¡ããGoè¨èªã§å®è£ ããã¦ãã¾ãã
Evilgophishã«ã¤ãã¦
Evilginx3ãã½ã¼ã·ã£ã«ã¨ã³ã¸ãã¢ãªã³ã°ã®æ¤è¨¼ã調æ»ã«ç¨ããããã«ã¯ãå¥éåå¥ã®è¿½è·¡æ å ±ãåå¾ã»ç¢ºèªããæ©è½ããå®éã«ã¡ã¼ã«ãSMSãªã©ã«éä¿¡ããæ¹æ³ãç¨æããå¿ è¦ãããã¾ãã
ãã®Evilgophishã§ã¯ãEvilginx3ã¨Gophishãçµã¿åããããã¨ã§ããã£ã³ãã¼ã³ã®çµ±è¨æ å ±ã®åå¾ã»ç¢ºèªãã¡ã¼ã«ã»SMSã®éä¿¡ãªã©ãå¯è½ã§ãããæ´ã«ãããã®æ å ±ãWebãã©ã¦ã¶ãã確èªãããã¨ãã§ãã¾ãã
æ¤è¨¼
æ¤è¨¼ç°å¢æ§æ
ãã¹ã¦ã®ç°å¢ã¯Vagrantä¸ã«æ§ç¯ããããããã«ãã¼ã«ã«ã®IPã¢ãã¬ã¹ãä»ä¸ãã¦ãã¾ãã
- Evilgophishå®è¡ç°å¢
- Ubuntu 22.04 (generic/ubuntu2204)
- ãã¹ãå : example.test
- ã¡ã¼ã«ãµã¼ãã¼å®è¡ç°å¢
- CentOS 7.2 (centos/7)
- Dovecot(2.2.36) / Postifx (3.7.2, ã½ã¼ã¹ã³ã¼ãããã¤ã³ã¹ãã¼ã«)
- ãã¹ãå : mail.test
- WordPressãµã¼ãã¼å®è¡ç°å¢
Evilgophishç°å¢æ§ç¯æé
cloneã¨ã»ããã¢ãã
git clone https://github.com/fin3ss3g0d/evilgophish.git sudo ./setup.sh example.test example.test true google.com true user_id false
Evilgophishã®æ¤è¨¼
Evilginxã®èµ·åã»è¨å®
cd evilginx3 ./evilginx3 -g ../gophish/gophish.db -p legacy_phishlets/ --developer
-developer
ãã¤ãããã¨ã§ãdeveloper modeãæå¹ã«ãªããèªå·±ç½²å証ææ¸ãçºè¡ããã¾ãã
-p
ãªãã·ã§ã³ã§legacy_phishlets/
ãã£ã¬ã¯ããªãæå®ãããã¨ã§ãlegacy_phishlets
ãã£ã¬ã¯ããªä»¥ä¸ã®phishletsãèªã¿è¾¼ã¾ãã¾ãã
-g
ãªãã·ã§ã³ã§é£æºããgophishã®ãã¼ã¿ãã¼ã¹ãæå®ãã¾ãã
æ¤è¨¼ã®ããã«ç¨æããWordpressç¨ã®phishletã使ç¨ããlegacy_phishlets
ãã£ã¬ã¯ããªä»¥ä¸ã«é
ç½®ãã¾ããã
ãã®phishletã¯åããæ ªå¼ä¼ç¤¾Armorisã¢ã«ãã¤ãã®Shaderoã以åã®æ¤è¨¼ã§å©ç¨ãããã®ã使ããã¦ããã£ã¦ãã¾ãã
author: '@armoris' min_ver: '2.3.0' proxy_hosts: - {phish_sub: '', orig_sub: '', domain: 'wp.test', session: true, is_landing: true} sub_filters: - {triggers_on: 'wp.test', orig_sub: '', domain: 'wp.test', search: '{hostname}', replace: '{hostname}', mimes: ['text/html']} auth_tokens: - domain: 'wp.test' keys: ['wordpress_logged_in_12913fd91550a6158ad37f2c7911fba9'] credentials: username: key: 'log' search: '(.*)' type: 'post' password: key: 'pwd' search: '(.*)' type: 'post' login: domain: 'wp.test' path: '/wp-login.php'
config domain example.test config ipv4 172.16.0.99 phishlets hostname wordpress example.test phishlets enable wordpress lures create wordpress lures get-url 0
ããã§è¡¨ç¤ºããããã£ãã·ã³ã°URLãgophishå´ã§å©ç¨ãããããä¿åãã¦ããã¾ãã
gophishã®èµ·åã»è¨å®
ä»åã¯ãgophishã®ããã·ã¥ãã¼ãã«LANå ã®å¥ã®ãã·ã³ããæ¥ç¶ãããããconfigã®listen_urlãæ¸ãæãã¦ãã¾ãã
{ "admin_server": { "listen_url": "0.0.0.0:3333", "use_tls": true, "cert_path": "gophish_admin.crt", "key_path": "gophish_admin.key" }, "phish_server": { "listen_url": "0.0.0.0:8080", "use_tls": true, "cert_path": "gophish_template.crt", "key_path": "gophish_template.key" }, "feed_enabled": true, "db_name": "sqlite3", "db_path": "gophish.db", "migrations_prefix": "db/db_", "contact_address": "", "logging": { "filename": "", "level": "" } }
sudo ./gophish
èµ·åã«æåããã¨ãååãã°ã¤ã³ç¨ã®ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã表示ããã¾ãã ãããç¨ãã¦ããã©ã¦ã¶ããããã·ã¥ãã¼ãã«ãã°ã¤ã³ãã¾ãã
Email Templatesã®ä½æ
å·¦å´ã®ã¡ãã¥ã¼ããEmail/SMS Templates
ãé¸æããNew Template
ãã¿ã³ãã¯ãªãã¯ãã¦ããã£ãã·ã³ã°ã¡ã¼ã«ã®ãã³ãã¬ã¼ããä½æãã¾ãã
æ¬æå
ã«{{.URL}}
ãè¨å®ãããã¨ã§ãå¾ã§è¨å®ããEvilginxã®ãã£ãã·ã³ã°URLãæ¿å
¥ããã¾ãã
Email Sending Profilesã®ä½æ
å·¦å´ã®ã¡ãã¥ã¼ããEmail/ Sending Profiles
ãé¸æãããã£ãã·ã³ã°ã¡ã¼ã«ã®éä¿¡ã«å©ç¨ããSMTPãµã¼ãã¼ã®è¨å®ãè¡ãã¾ãã
Users & Groups ã®ä½æ
å·¦å´ã®ã¡ãã¥ã¼ããUsers & Groups
ãé¸æããNew Group
ããããã£ãã·ã³ã°ã¡ã¼ã«ãéä¿¡ããã¦ã¼ã¶ã¼ã®ã°ã«ã¼ããè¨å®ãã¾ãã対象ã®ã¦ã¼ã¶ã¼ã®ååãã¡ã¼ã«ã¢ãã¬ã¹ãæå®ããã¦ã¼ã¶ã¼ã追å ãããã¨ãã§ãã¾ãã
Campaignsã®ä½æ
å·¦å´ã®ã¡ãã¥ã¼ã®Launch Email Campaign
ãããã£ã³ãã¼ã³ãä½æãã¾ãã
ããã§ãå
ç¨è¨å®ããEmail Templateåã³Sending Profileãã¦ã¼ã¶ã¼ã°ã«ã¼ããè¨å®ãã¾ãã
ã¾ããevilginx URL
ã®æ¬ã«ãEvilginxã§çºè¡ããPhishing URLãå
¥åãããã¨ã§ãå
è¿°ã®Email Templatesã®{{.URL}}
ã®ç®æã«URLãæ¿å
¥ããã¾ãã
ä¸é¨ã®Profitãã¿ã³ãã¯ãªãã¯ããã¨ãã¡ã¼ã«ãéä¿¡ããã¾ãã
ä»åã¯ãã®ãããªã¡ã¼ã«ãéä¿¡ãã¾ããã
ãã£ã³ãã¼ã³ç¶æ ã®ç¢ºèª
éä¿¡å¾ãããã·ã¥ãã¼ãã«æ»ã£ã¦ããã¨ãEmail/SMS Sentãæ´æ°ããã¦ãã¾ãã ãã®ããã«ãã°ã©ãã£ã«ã«ã«ã¢ã¯ãã£ããªãã£ã³ãã¼ã³ã®ç¶æ ã確èªã§ãã¾ãã
ã¾ããç»é¢ä¸é¨ã®Detailsæ¬ã«åå¥ã®ã¡ã¼ã«éä¿¡å
ã®Statusã¨åå¾ããæ
å ±ã表示ããã¾ãã
åä¿¡ããã¡ã¼ã«ãã¦ã¼ã¶ã¼ãã¯ãªãã¯ããã¨ãStatusãClicked Link
ã«æ´æ°ãããã¯ãªãã¯ããOSåã³ãã©ã¦ã¶ã®æ
å ±ã¨æ¥æã表示ããã¾ãã
ãã®å¾ãã¦ã¼ã¶ã¼ãEvilginxã§ç¨æãããã£ãã·ã³ã°ãµã¤ãã«ãã°ã¤ã³ããã¨ãSubmitted Data
ã¨Captured Session
ã®ã¹ãã¼ã¿ã¹ãæ´æ°ããã¾ãã
Detailsæ¬ã®è©²å½ã¦ã¼ã¶ã¼ã®ã¿ã¤ã ã©ã¤ã³ãè¦ãã¨ãç¨æããEvilginxã®Phishletsã§ãã£ããã£ããããã«æå®ããæ å ±ãåå¾ã§ãã¦ãããã¨ã確èªã§ãã¾ãã
Evilginx2ã¨3ã®å·®ç°
ã»ãã·ã§ã³ãã¼ã¯ã³é¢é£
HTTP å¿çãã±ããã®æ¬æããAuthorizationãããã¼ãªã©ãããã»ãã·ã§ã³ãã¼ã¯ã³ãåå¾ã§ããããã«ãªãã¾ããã
ããã¾ã§ãã»ãã·ã§ã³ãã¼ã¯ã³ã¯HTTP Cookieã¨ãã¦éä¿¡ãããåæã§ããããæè¿ã§ã¯JSONã¨ãã¦åå¾å¾ããã¼ã«ã«ã¹ãã¬ã¼ã¸ã«ä¿åããæµããä¸è¬çã§ããããã¨èª¬æããã¦ãã¾ãã
config
configã®ãã¡ã¤ã«ãã©ã¼ããããyamlããJSONã«å¤æ´ããã¾ãããä¸æ¹ã§ãphishletsã¯yamlã®ã¾ã¾ã§ãã
phishing sessions
æå¹ãªURLãéãããã¨ã常ã«ãã£ãã·ã³ã°ã»ãã·ã§ã³ãä½æãããããã«ãªãã¾ããã ããã«ãããã¿ã¼ã²ãããURLãéã度ã«ãªãã¼ã¹ãããã·ã»ãã·ã§ã³ãæ°ããä½æããã¾ãã
JavaScriptã§ã®URLãªãã¤ã¬ã¯ã
ããã¾ã§ã¯ãHTTP Locationãããã¼ãéãã¦redirect_urlã«ãªãã¤ã¬ã¯ããã¦ãã¾ããããããããã®æ¹æ³ã§ã¯ãrefererãããã¼ãéãã¦ãã£ãã·ã³ã°URLãå®å ã«å ¬éããã¦ãã¾ã£ã¦ãã¾ãããä»å¾ã¯JavaScriptãç¨ãã¦ãªãã¤ã¬ã¯ãããã¾ãã
Evilgophishã§æ»æãããå ´åã®æ¤ç¥æ¹æ³
Gophishã§éä¿¡ããã¡ã¼ã«ã®X-Mailerãããã¼ã«ã¯IGNORE
ãè¨å®ããã¦ãã¾ãã
X-Mailerãããã¼ã¨ã¯ãéä¿¡è
ã®ä½¿ç¨ããã¡ã¼ã«ã¯ã©ã¤ã¢ã³ãããã®ãã¼ã¸ã§ã³ãªã©ãè¨è¼ããããã®ã§ãã
ä»ã®ã¨ããããã®ãããã¼ã®å¤æ´ã¯Optionããã¯è¡ããªãããã§ãã
ä»åéä¿¡ããã¡ã¼ã«ã®ãããã¼æ å ±
æå¾ã«
ä»åã¯Evilginx2ã¨3ã®æ¯è¼ã¨ãEvilgophishã®æ¤è¨¼ãè¡ãã¾ããã
Evilginx3ã§ã¯ãphishing sessionsä½æã¿ã¤ãã³ã°ã®å¤æ´ãsession tokenãåå¾ã§ããç®æã®å¢å ã«ãããããæè»ã«å©ç¨ãããã¨ãã§ãããã«ãªã£ãã¨æãã¾ããã
ã¾ããEvilgophishãç¨ãããã¨ã§ãã¡ã¼ã«ãã³ãã¬ã¼ãã®ä½æãéä¿¡ã»çµ±è¨æ
å ±ã®åå¾ã¾ã§ããã©ã¦ã¶ä¸ã§å®¹æã«è¡ããã¨ãã§ããé常ã«æç¨ã§ããã¨æãã¾ãã
ãæ¨çåæ»æã«ããæ©å¯æ å ±ã®çªåãã¯ãIPAãå ¬éãã¦ããæ å ±ã»ãã¥ãªãã£10大è å¨ 2023ã§ãé·å¹´ä¸ä½ã«ã©ã³ã¯ã¤ã³ãã¦ãã¾ããEvilgophishãæ´»ç¨ãããã¨ã§ãæ¨çåæ»æã¡ã¼ã«è¨ç·´ã®å®æ½ãç°¡åã«è¡ããã¨ãã§ãã¾ãã