Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Evilginx-Phishing-Infra-Setup — دليل إعداد البنية التحتية للتصيد الاحتيالي Evilginx - تأمين البنية التحتية لـ Evilginx وGophish، إزالة مؤشرات الاختراق، تكتيكات وتقنيات وإجراءات التصيد الاحتيالي | Kitploit
أدوات/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
أدوات التصيدالتهرب من IDS/IPSالتصيد الاحتياليالقيادة والسيطرةالهندسة الاجتماعيةالتعلم والتعليمالفريق الأحمرموارد منسقةأمان البريد الإلكتروني

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

دليل إعداد البنية التحتية للتصيد الاحتيالي Evilginx - تأمين البنية التحتية لـ Evilginx وGophish، إزالة مؤشرات الاختراق، تكتيكات وتقنيات وإجراءات التصيد الاحتيالي

عرض المستودع
598115منذ سنة واحدةتمت المراجعة من قبل Kitploit

دليل إعداد البنية التحتية لعمليات التصيد

ملاحظة: هذه نسخة من ملاحظاتي الشخصية. يرجى عدم الاعتماد عليها بشكل كامل.

جدول المحتويات

  • المدونات/المحاضرات
  • أتمتة البنية التحتية للفريق الأحمر/التصيد
  • تقنيات شراء النطاقات وتصنيفها
  • تحسين كتابة رسائل التصيد باستخدام الأدوات
  • اختبار مدى احتمالية تصنيف البريد كسبام
  • محاكاة رسائل التصيد / تصيد الفريق الأرجواني
  • مصادر رائعة لأمان البريد الإلكتروني للمؤسسات
  • توصيل رسائل البريد إلى صندوق الوارد
  • عمليات التصيد باستخدام Evilginx
    • بناء Phishlets لـ Evilginx
    • سكربتات تثبيت Evilginx
    • نصائح لتأمين البنية التحتية لـ Evilginx
    • مدونات/محاضرات أبحاث Evilginx
    • أساليب الدفاع ضد Evilginx
  • تأمين البنية التحتية لـ GoPhish
    • مدونات/محاضرات أبحاث GoPhish
    • بدائل GoPhish
  • ما بعد الاستغلال عبر AiTM / مدونات/محاضرات أبحاث التصيد
  • تقنيات/مدونات/أبحاث أخرى
  • محاضرات أبحاث التصيد

المدونات/المحاضرات

  • BHIS | كيفية بناء حملة تصيد - برمجة TTPs : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

أتمتة البنية التحتية للفريق الأحمر/التصيد

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - نصائح الفريق الأحمر في 2024 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • انشر بنية تحتية للتصيد بشكل فوري : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

تقنيات شراء النطاقات وتصنيفها

  • تحقق من النطاقات المنتهية واشترِ الجيد منها إن أمكن

    • https://expireddomains.net/
  • تصنيف النطاقات

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (يتطلب التسجيل)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (يتطلب التسجيل)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (إرسال فقط؛ لا يوفر فحصًا) (انقر على Submit a Sample -> Web Address)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • أتمتة فحص/إرسال سمعة النطاق

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon
  • مدونات

تحسين كتابة رسائل التصيد باستخدام الأدوات

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (تجنب كلمات رسائل التصيد الشائعة) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

اختبار مدى احتمالية تصنيف البريد كسبام

  • https://www.mail-tester.com/

محاكاة رسائل التصيد / تصيد الفريق الأرجواني

  • https://delivr.to/

مصادر رائعة لأمان البريد الإلكتروني للمؤسسات

  • https://github.com/0xAnalyst/awesome-email-security
  • ماجيك كوادرانت من Gartner لمنصات أمان البريد الإلكتروني email-security-providers

توصيل رسائل البريد إلى صندوق الوارد

  • الطريقة 1: استخدام مزودي خدمة البريد الإلكتروني

    • استخدم SendGrid - http://sendgrid.com/
      • خدمة مفيدة لكن بصراحة، ستحتاج إلى خطة Pro المدفوعة كي تكون محظوظًا بعدم الوقوع في قائمة السبام
    • MailGun - https://app.mailgun.com/
      • لم أواجه أي مشكلة معها
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • أنشئ مستأجر Azure للحصول على نطاق onmicrosoft.com مثل attackdomain.onmicrosoft.com يمكن استخدامه كنطاق لإرسال البريد الإلكتروني والتصيد معًا
    • LarkSuite (يسمح بنطاق مخصص) : https://www.larksuite.com/
    • Zoho (استخدم خيار البريد "مجاني مدى الحياة" من Zoho) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • الطريقة 2: تقنيات متفرقة

    • التقنية 1: بواسطة Andre Rosario - من BreakDev Red على ديسكورد

      • إذا كنت تواجه مشكلات في توصيل رسائل البريد بسبب تصفية البريد الإلكتروني، ففكر في استخدام Microsoft 365 وAzure IPP لإرسال رسائل بريد مشفرة إلى أهدافك!
        • تصدر الرسائل من خوادم SMTP شرعية تابعة لـ Microsoft لذا لا يمكن حظرها.
        • الأهداف الذين يستلمون البريد المشفر هم الوحيدون القادرون على فتحه؛ إذا أعادوا توجيهه إلى فريق DFIR لديهم، فسيتعين عليهم تسجيل الدخول بصفة ذلك المستخدم لمجرد رؤية رسالتك.
        • سهولة الإدارة في بوابة Microsoft Admin للنطاقات المخصصة، وإنشاء الكثير من الحسابات الوهمية.
        • يتيح M365 تعيين أسماء عرض عشوائية. لذا في Outlook الخاص بالهدف قد يبدو البريد وكأنه من [email protected] لكنه في الحقيقة من [email protected] (يمكن للأشخاص التقنيين اكتشاف ذلك بسهولة بالرغم من ذلك)

عمليات التصيد باستخدام Evilginx

  • بناء Phishlets لـ Evilginx

    • دورة إتقان Evilginx : https://academy.breakdev.org/evilginx-mastery
    • توثيق Evilginx : https://help.evilginx.com/
    • مجموعات Phishlets لـ Evilginx : https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • تقنيات Evilginx الأقل شهرة : https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • سكربتات تثبيت Evilginx

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • نصائح لتأمين البنية التحتية لـ Evilginx -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - Rewrite URLs on Phishing Pages to avoid detection through URL Path pattern matching (by Kuba).
      - Remove IOCs (X-Evilginx header and Default Cert Details)
      - Modify Unauth redirect static contents
      - Modify code to request wildcard certificates for root domain from Let'sEncrypt other than requesting for each subdomains (As mentioned in Kuba's blog) - Check this repo for reference https://github.com/ss23/evilginx2
      - Put evilginx behind a proxy to help against TLS fingerprinting (JA3 and JA3S)
      - Use cloudflare in between if possible/feasible (You have to configure the SSL Settings correctly, change it to Full in cloudflare settings)
      - Use some known ASN blacklist to avoid getting detected like here (https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - Reduce the Number of proxyhosts in phishlet if possible to reduce content loading time.
      - Host Evilginx at Azure and use their domain (limit proxy host in phishlet to 1 or find a way , may be create multiple azure sub domains and try with that)
      - Add some sub_filters to modify the content of the pages to avoid content based detections, like (Favicon, form title font or style, or anything which seems relevant)
      - Block the feedback/telemetry/logs/analytics subdomains using the phishlet sub_filters which can log the domain or may help later on analysis.
      - See if js-injected is static or dynamic , if static modify the evilginx js-inject code to create dynamic/obfuscated version of your js for each user/target.
      - Make sure to not leak your Evilginx infra IP, Check the DNS history to make sure its not stored anywhere (Analysts may look for older DNS Records of the domain)
      - Be aware of this research : https://catching-transparent-phish.github.io/catching_transparent_phish.pdf , repo - https://catching-transparent-phish.github.io/
      

مدونات ومحاضرات أبحاث Evilginx :

  • البحر الهادئ لا يصنع صياد تصيّد ماهرًا - Kuba Gretzky (x33fc0n 2024) :
    • المحاضرة : https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • الشرائح : https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • ثالوث الوصول الأولي : https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber : https://github.com/Flangvik/Bobber
  • تجاوز كشف Canary AiTM : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • حماية Evilginx باستخدام cloudflare وتعتيم HTML : https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (تحسين موثوقية تسليم البريد الإلكتروني لـ Evilginx) إضافة سجلات SPF وDMARC وDKIM وMX : https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • تكتيكات التصيّد وOPSEC : https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + تكتيكات المراوغة : https://youtu.be/p1opa2wnRvg
  • الخطاف والخيط وPhishlet - التغلب على AD FS باستخدام Evilginx : https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • البنية التحتية للتصيّد عبر O365 - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • لا يمكنك رؤيتي – حماية البنية التحتية للتصيّد لديك : https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/

تكتيكات الدفاع ضد Evilginx

  • كشف ومواجهة التصيّد عبر الخصم في المنتصف - X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • استخدام HoneyTokens لكشف AiTM : https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • الحماية من التصيّد الحديث : https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • كشف evilginx باستخدام بصمات JA3 وJA3S وJA4
    • قاعدة بيانات JA4 : https://ja4db.com/

تأمين البنية التحتية لـ GoPhish

ستعمل هذه التعديلات أيضًا في أحدث إصدار من evilginx + gophish أي evilginx3.3

  • نصائح : استخدم معامل {{.URL}} في قالب التصيّد عند استخدامه مع evilginx ( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • تعديلات في الكود المصدري وهيكل الملفات لـ gophish لتأمين البنية التحتية لـ GoPhish

    • إزالة مثيلات X-Gophish ( X-Gophish-Contact , X-Gophish-Signature)

    • إزالة const ServerName= "gophish" وتغييرها إلى const ServerName= "IGNORE" في الملف config/config.go

    • تغيير منفذ خادم الإدارة الافتراضي في ملف config.json.

    • تعديل توقيعات رسائل البريد الاختبارية، لتجنب الاكتشاف أثناء اختبار SMTP. Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      

مدونات ومحاضرات أبحاث ما بعد الاستغلال / التصيّد عبر AiTM

  • AiTm (ما بعد الاستغلال) : https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## تقنيات/مدونات/أبحاث أخرى
  • لإساءة استخدام المواقع الشرعية للتصيد : https://lots-project.com/
  • Muraena : https://github.com/muraenateam/muraena
  • NecroBrowser : https://github.com/muraenateam/necrobrowser
  • BITB : https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb : https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish : https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • Okta مرتبط مع Azure مع اشتراك MFA تلقائي لـ Okta وتجاوز Frame Buster لتنفيذ BITB : https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • التصيد عبر تطبيقات الويب التقدمية (PWA) : https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • التصيد عبر noVNC : https://adepts.of0x.cc/novnc-phishing/

محاضرات أبحاث التصيد

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
تنزيل الأداة
  • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7
  • تأتي الرسائل من عناوين IP ونطاقات Microsoft شرعية، لذا لا داعي للقلق بشأن تصنيف النطاق أو عمره طالما أنها من Microsoft.
  • التقنية 2: استخدام وظيفة الدعوة الخارجية في Azure - من BreakDev Red على ديسكورد

    • يمكن استخدام الدعوة الخارجية في Azure لإرسال بريد إلكتروني يحتوي على رابط إعادة توجيه إلى رابط التصيد
    • يمكن أيضًا إرسال رسائل بريد بكميات كبيرة، للمرجع تحقق من: https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite
  • نصائح متفرقة للمساعدة في إيصال رسائل البريد إلى صندوق الوارد.

    • امتلك نطاقًا بسمعة جيدة، وتحقق من تصنيف النطاق
    • امتلك نطاقًا عمره أكثر من عام أو استخدم النطاقات المنتهية
    • امتلك إعدادات DKIM وDMARC وSPF صالحة.
      • Mailgoose (تحقق مما إذا كانت إعدادات SPF وDMARC وDKIM مضبوطة بشكل صحيح) : https://github.com/CERT-Polska/mailgoose
    • أضف رابط إلغاء الاشتراك في البريد الإلكتروني
    • أرسل رسائل بريد غير ضارة أولًا (قد يساعد ذلك في تحسين السمعة)
    • اجعل الرابط في البريد من نفس النطاق المستخدم لإرسال البريد.
  • مدونات/محاضرات/مراجع

    • Outlook_Email_Auth_Bypass : https://gitlab.com/hxxpxxp/outlook_email_auth_bypass (في تطبيق Outlook لسطح المكتب والويب، يمكن لـ"اسم العرض" في ترويسة "From" الخاصة بالبريد التلاعب بالبريد الإلكتروني للمرسل المعروض للمستخدم، وقد يؤدي ذلك إلى رسائل تصيد أكثر إقناعًا)
    • Spy Pixel - بكسل صورة لتتبع رسائل البريد : https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - أنماط هجمات انتحال البريد الإلكتروني الجديدة : https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • أزل ترويسة X-Evilginx (تحقق من جميع أسطر الكود التي تحتوي على req.Header.Set وقم بتعليق الوظائف ذات الصلة في ملف core/http_proxy.go)

    root@kitploit:~
      // comment line 469
      req.Header.Set(p.getHomeDir(), o_host)
      
      //comment line 659
      req.Header.Set(p.getHomeDir(), o_host)
      
      // comment function at line 1791-1793
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // comment line 52-54
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • لتعديل المحتوى الثابت لإعادة التوجيه غير المصرح بها، ابحث عن <html> في ملف core/http_proxy.go وعدّل كود HTML لإزالة أي توقيعات ثابتة.

  • أيضًا لتجنب اكتشاف توقيع كود js المحقون الثابت، يمكنك تعديل الكود كما يلي:

    • تأكد من إضافة "github.com/tdewolff/minify/js" في imports

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// Handle error - Obfuscation failed
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • عدّل ملف core/cert.db أيضًا

  • غيّر “rid” لـ gophish.

  • استخدم nginx أو caddy أو بروكسيات أخرى أمام evilginx.

  • استخدم أدوات إعادة التوجيه (Redirectors)

    • استخدم Cloudflare Turnstile كأداة إعادة توجيه لـ evilginx واحظر الروبوتات.
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • شفّر أدوات إعادة التوجيه المبنية على html/js
      • قائمة عوامل مستخدم HTTP المشبوهة : https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • طرق اكتشاف الروبوتات المستخدمة في عدة التصيد gabagool : https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • وسم Meta بلغة html لإعادة التوجيه
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • غيّر النمط الافتراضي لرابط الطُعم وهو سلسلة عشوائية من 8 أحرف.

    root@kitploit:~
       // Line 728 in core/terminal.go file
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • أعد كتابة الروابط في صفحات التصيد لتجنب الاكتشاف عبر مطابقة نمط مسار الرابط (بواسطة Kuba). [هذه الميزة غير متوفرة في النسخة العامة من evilginx، سيتعين عليك تنفيذها بنفسك.]

    root@kitploit:~
    # Only Work in Evilginx Pro Version
    # Similar functionality can be implemented in public version as well.
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • عدّل النمط والقيمة الموقَّعين لملفات تعريف الارتباط الخاصة بمعرف الطُعم/الجلسة (بواسطة @rad9800 )

    • القاعدة 1: اسم Cookie=XXXX-XXXX وقيمة=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • وظيفة كود evilginx المسؤولة (لاسم ملف تعريف الارتباط) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • وظيفة كود evilginx المسؤولة (لقيمة ملف تعريف الارتباط) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • القاعدة 2: مسار السكربت=/s/64_hex_chars.js مع content-length=0
    • القاعدة 3: وجود كل من القاعدة 1 والقاعدة 2 معًا
      • المنطق الكامل لمقتطف js موجود هنا https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • احجب ترويسات Referrer لمنع تسريب اسم نطاق التصيد الخاص بك - راجع هذه المدونة البحثية كمرجع:

    • أضف السطر التالي في ملف http_proxy.go هنا (لا يحترم Chrome هذا الأمر عندما يتم بدء الطلب عبر دالة url() في CSS - تحقق من المدونة للمزيد)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • لأتمتة ذلك من phishlet تحقق من هذا الـ PR : https://github.com/kgretzky/evilginx2/pull/1006
  • حدد سياسة أمان المحتوى CSP الخاصة بك لتجنب القياس عن بُعد/الكناري/الاكتشاف عبر تسريب نطاق التصيد.

    • اقرأ هذا للمزيد : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • تحقق مما إذا كان الموقع المستهدف يستخدم نوعًا من رموز الكناري (CSS, JS) وتجنبها

    • تجاوز اكتشاف AiTM عبر كناري (CSS, JS) : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • تجنب بصمة JA4

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + تجاوز كسر الإطارات (Frame Busting)

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx : https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • مثال Subfilter لتجاوز كسر الإطارات من : https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 و https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • تقنيات كسر الإطارات المستخدمة بشكل عام
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • التقنيات الشائعة لكشف وجود iframe
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • قد تستخدم المواقع الطريقة التالية بمجرد اكتشاف iframe لتنفيذ إعادة التوجيه
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • الخطاف والخيط والغاطس: التصيّد عبر Windows Hello for Business باستخدام Evilginx : https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • التصيّد للمقاومين - التصيّد للحصول على رمز التحديث الأساسي في Microsoft Entra بقلم Dirk Jan : https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • مثل إطلاق النار على أسماك التصيّد في برميل - تجاوز زاحفات الروابط : ****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • اشرب مثل أسماك التصيّد - كيف تجعل مواقع التصيّد لديك تندمج ****: https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • تغذية أسماك التصيّد : ****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • كشف أدوات التصيّد من Push Security : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • إضافة كروم من Push Security تكتشف evilginx بقواعد هشّة إلى حد ما
      • القاعدة 1: اسم الكوكي=XXXX-XXXX وقيمته=64_hex_chars
      • القاعدة 2: مسار السكربت=/s/64_hex_chars.js مع content-length=0
      • القاعدة 3: وجود كل من القاعدة 1 والقاعدة 2 معًا
      • المنطق الكامل لمقتطف js موجود هنا https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • تغيير استجابة 404

    • أضف الدالة المخصصة التالية في ملف controllers/phish.go

      root@kitploit:~
      func customNotFound(w http.ResponseWriter, r *http.Request) {
      	http.Error(w, "Try again!", http.StatusNotFound)
      }
      
    • الآن استبدل جميع حالات http.NotFound(w, r) بـ customNotFound(w, r)

  • إزالة الاستجابة المثبتة يدويًا لـ robots.txt وتعديلها في الملف controllers/phish.go

    • عدّل الكود المعني في ملف phish.go إلى الكود التالي.

      root@kitploit:~
      //Modified Response
      // RobotsHandler prevents search engines, etc. from indexing phishing materials
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • تعديل معامل GET “rid” في الطلبات

    • تأكد من تعديل جميع حالات "rid" إلى شيء آخر.
    • هذه الحالات موجودة أيضًا في الكود المصدري لـ evilginx3.3، لذا تأكد من تعديلها هناك أيضًا.
  • للوقاية المتقدمة، يمكنك أيضًا تعديل مجلد static وإعادة تسميته إلى اسم آخر، وكذلك إعادة تسمية الملفات بداخله لتجنب الاكتشاف القائم على المسار. فقط لا تنسَ تعديل الكود المصدري ذي الصلة أيضًا.

    • مثل أسماء الصور، مثال: pixel.png، عدّلها إلى شيء آخر.
  • تغيير خصائص الشهادة في ملف util/util.go

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • استخدم Nginx لتمرير الحركة المرورية عبره كوسيط لتجنب أي بصمة لخادم Golang

    • service nginx start

    • تحتاج إلى تغيير config.json الخاص بـ gophish لتغيير منافذ http من 80 إلى 8080 وhttps من الافتراضي إلى 60002، كما هو موضح أدناه

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • الإعداد التالي سيحظر جميع الطلبات التي يحتوي وكيل المستخدم فيها على “Bot” أو “bot”

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTP server
          server {
              listen 80 default_server;
              
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • للسماح بوكيل مستخدم محدد فقط، استخدم الإعداد التالي. سيحظر هذا جميع الطلبات ولن يسمح إلا بالطلبات التي يكون وكيل المستخدم فيها “iamdevil”.

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTP server
          server {
              listen 80 default_server;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • تعديل توقيع بكسل التتبع في Gophish لتجنب الاكتشاف القائم على بكسل التتبع الموقّع.

  • تغيير نمط تسلسل ترويسات البريد الإلكتروني في gophish. قد يُستخدم هذا النمط للكشف عن gophish (من مجتمع BreakDev Red).

  • قم بإعداد PostFix أمام gophish لإزالة مؤشرات الاختراق (IOCs) ووسائل الاكتشاف الأخرى ومنع الرسائل من الظهور كبريد عشوائي، وكذلك إزالة الترويسات وإصلاحها.

  • مدونات ومحاضرات أبحاث GoPhish :

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • بدائل Gophish :

    • SniperPhish : https://github.com/GemGeorge/SniperPhish
    • Mailcow : https://github.com/mailcow/mailcow-dockerized
    • EvilnoVNC : https://github.com/JoelGMSec/EvilnoVNC
    • MultiEvilnoVNC : https://blog.wanetty.com/blog/tools/multievilnovnc
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • Delusion (أداة مبنية على NoVNC) : https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
    • كشف NoVNC : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNC و Docker : https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - التصيد عبر رموز QR
    • توليد رمز QR : https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii : https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish (docker و noVNC) : https://github.com/powerseb/NoPhish و https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish : https://github.com/fin3ss3g0d/evilgophish
  • Smishing : https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • التصيد باستخدام CloudFlare Workers
    • TryCloudflare : https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • التصيد باستخدام Cloudflare Public Buckets : https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • إعادة التوجيه المفتوحة من Google للتصيد
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • إعادة توجيه مفتوحة على (لا يعمل) : https://googleweblight.com/i?u=m4lici0u5.com
    • إعادة توجيه مفتوحة : https://www.google.com/url?q=https://m4lici0u5.com
    • إعادة توجيه مفتوحة : https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • يمكن العثور على المزيد في : https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • التصيد متجاوزًا عناصر حماية البريد باستخدام Azure Information Protection
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • التصيد لسرقة بيانات الاعتماد عبر إساءة استخدام Docusign : https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • التصيد الخفي لسرقة بيانات الاعتماد عبر مرفقات EML : https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • استخدام Microsoft Customer Voice في التصيد : https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking : https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • مقارنة بين مختلف التقنيات : https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • إساءة استخدام webhooks الواردة من Microsoft Teams في التصيد : https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • Rogue RDP أو RDP (.rdp) للتصيد : https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • SVG للتصيد : https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • استخدام ClickOnce مع التصيد للوصول الأولي : https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • [يجب الاطلاع عليه] Evilworker : https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249