Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow Toolsarrow Need to build a Phishing platform/framework
EH-Net
May 22, 2013, 08:44:00 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Need to build a Phishing platform/framework  (Read 15106 times)
0 Members and 1 Guest are viewing this topic.
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« on: July 28, 2011, 11:55:57 AM »

I'm on a roll today...

Just before leaving for SANS last week, I was hit up and told that we need to implement our own home-grown phishing tests.  My first thought was "crap, gotta build a box, write code, run tests, maintain code, etc"...

Well, I went to a phishing lunch and learn at the conference, and found out about the PhishMe company/service.  I like the idea of it, and I'm try to get approval to move forward with a demo, HOWEVER, cost is always an object.  We got an initial quote, and it's probably going to be difficult to get funding.

Which, puts me back at building my own solution.  As I was looking up reviews on PhishMe, there were mentions in articles about scripts and programs in the open source community that assist in phishing tests, but my google-foo is not up to snuff this morning and I'm coming up blank.

So, I'm putting out a call to anyone with information on building a platform for this.  What scripts/programs/frameworks do you utilize to perform phishing exercises?

As always, thanks for any input!
Logged

Poking at security since 1986.  +++ATH
dbest
Jr. Member
**
Offline Offline

Posts: 79


View Profile
« Reply #1 on: July 28, 2011, 12:09:52 PM »

Have you had a look at The Social Engineer Toolkit (http://www.social-engineer.org/) Am certain it contains a module for Phishing attacks.
Logged

CISM, CEH, CISA, ISO 27001 LA
cochese86
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #2 on: July 28, 2011, 12:26:09 PM »

+1 to SET and sendmail on a backtrack box.  You should be ok then.
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #3 on: July 28, 2011, 12:49:10 PM »

I've been playing around with a BT5 VPS instance from hackingmachines.com (in beta) and that is really all I needed. SET using Sendmail is an amazing tool and I've been having lots of fun lately. In fact I just demonstrated to a client last week that I could spoof messages to him that looked like they were coming from his boss and he could not tell the difference (had to harvest an example with boss's signature line first) I sent him an email telling him he was being transferred to their office in Bogota. They don't have an office in Bogota ;P Imagine the fun you could have just issuing instructions to staff. No need to hack anything, just go all HBGary on them and ask for the SSH credentials  Grin
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #4 on: July 28, 2011, 01:41:52 PM »

I've been playing around with a BT5 VPS instance from hackingmachines.com (in beta) and that is really all I needed. SET using Sendmail is an amazing tool and I've been having lots of fun lately. In fact I just demonstrated to a client last week that I could spoof messages to him that looked like they were coming from his boss and he could not tell the difference (had to harvest an example with boss's signature line first) I sent him an email telling him he was being transferred to their office in Bogota. They don't have an office in Bogota ;P

I've been considering a VPS for awhile now and I think I was just persuaded!

No need to hack anything, just go all HBGary on them and ask for the SSH credentials  Grin

LOL
Logged

GSEC, eCPPT, Sec+
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #5 on: September 04, 2011, 02:47:32 PM »

We normally just run SET for these types of engagements.  If you can base your template off of one of their existing internal emails that is your best option.  Back-up plan, make it more of a generic announcement ("Please update your employee benefit options."), and when you construct the email and phishing web page go to the targets home webpage and mimic their font, color schemes, logos, etc. 
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
dbest
Jr. Member
**
Offline Offline

Posts: 79


View Profile
« Reply #6 on: September 05, 2011, 12:45:36 AM »

We normally just run SET for these types of engagements.  If you can base your template off of one of their existing internal emails that is your best option.  Back-up plan, make it more of a generic announcement ("Please update your employee benefit options."), and when you construct the email and phishing web page go to the targets home webpage and mimic their font, color schemes, logos, etc. 

A colleague of mine recently did something similar. However, he created an URL similar to famous social networking site. The organization had a URL filtering software in place and the spoofed site could not be accessed by the users.
Something to keep in mind. Smiley
Logged

CISM, CEH, CISA, ISO 27001 LA
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« Reply #7 on: September 05, 2011, 10:20:19 AM »

If they already have controls in place to block traffic from going to web sites of different types, and you make a page that is similar to them, you're probably going to get blocked.  That's why I recommended copying their own corporate home page.  I'd be slightly surprised to see someone blacklisting their own site.
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #8 on: September 06, 2011, 12:14:43 PM »

If you need to phish users from common services that many people use, there's SET by the Social Engineer project, but also many other free and open source projects you could look into.

Many of these may be unfinished, perhaps even buggy, but there is one in particular that should catch your interest.

I'm glad my memory is with me today, as it has been a few years since people talked about this:
http://forum.intern0t.net/offensive-guides-information/2262-phishing-google-wave-hacking-google-buzz.html
http://blog.nparashuram.com/2008/06/tackle-javascript-based-phishing-kit.html

A friend of mine also wrote a blog entry which you may be interested in checking out:
http://www.e-x-e.dk/2010/07/03/how-to-phish-the-effective-and-smart-way-using-xss-3/


Enjoy and use it for ethical purposes only!  Wink
Logged

I'm an InterN0T'er
rance
Full Member
***
Offline Offline

Posts: 212


<censored>


View Profile
« Reply #9 on: September 07, 2011, 11:52:43 AM »

Looks like SET is the way to go, going to have to find some time to take a peek at it.

Thanks to everyone for all the info!
Logged

Poking at security since 1986.  +++ATH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.098 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.