Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Evilginx-Phishing-Infra-Setup — Evilginx フィッシングインフラストラクチャ設定ガイド - Evilginx と Gophish インフラストラクチャのセキュリティ強化、IOC の除去、フィッシング TTP | Kitploit
ツール/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
フィッシングツールIDS/IPS回避フィッシングコマンド&コントロールソーシャルエンジニアリング学習と教育レッドチーミング厳選リソースメールセキュリティ

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Evilginx フィッシングインフラストラクチャ設定ガイド - Evilginx と Gophish インフラストラクチャのセキュリティ強化、IOC の除去、フィッシング TTP

リポジトリを見る
5981151年前Kitploit レビュー済み

フィッシングエンゲージメントインフラ構築ガイド

注記: これらは私の個人ノートのコピーです。完全にこれらに依存しないでください。

目次

  • ブログ/トーク
  • レッドチーム/フィッシングインフラ自動化
  • ドメイン購入とカテゴリ分類手法
  • ツールを活用したフィッシングメール作成の改善
  • メールのスパム度テスト
  • フィッシングメールのエミュレート / パープルチームフィッシング
  • エンタープライズメールセキュリティのすごいまとめ
  • メールを受信箱に配信する
  • Evilginxを使ったフィッシングエンゲージメント
    • Evilginxフィッシュレットの構築
    • Evilginxインストールスクリプト
    • Evilginxインフラ保護のヒント
    • Evilginxに関する研究ブログ/トーク
    • Evilginxに対する防御戦術
  • GoPhishインフラの保護
    • GoPhishに関する研究ブログ/トーク
    • Gophishの代替
  • AiTMポストエクスプロイテーション / フィッシング研究ブログ/トーク
  • その他の手法/ブログ/研究
  • フィッシング研究に関するトーク

ブログ/トーク

  • BHIS | How to Build a Phishing Engagement - Coding TTP's : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

レッドチーム/フィッシングインフラ自動化

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - Red Team Tips in 2024 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • フィッシングインフラをその場で展開 : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

ドメイン購入とカテゴリ分類手法

  • 期限切れドメインを確認し、良さそうなものを購入する

    • https://expireddomains.net/
  • ドメインカテゴリ分類

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (要登録)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (要登録)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (報告のみ、確認は不可) (「サンプルを送信」→「Webアドレス」をクリック)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • ドメインレピュテーションの確認/報告の自動化

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon
  • ブログ

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7

ツールを活用したフィッシングメール作成の改善

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (一般的なフィッシングメールの単語を避ける) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

メールのスパム度テスト

  • https://www.mail-tester.com/

フィッシングメールのエミュレート / パープルチームフィッシング

  • https://delivr.to/

エンタープライズメールセキュリティのすごいまとめ

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner メールセキュリティプラットフォームのマジッククアドラント email-security-providers

メールを受信箱に配信する

  • 方法1 : メールサービスプロバイダの利用

    • SendGridを使う - http://sendgrid.com/
      • 便利なサービスだが、正直なところスパムリストに載らないためには有料プランが必要
    • MailGun - https://app.mailgun.com/
      • これまで問題はなかった
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • Azureテナントをセットアップして、attackdomain.onmicrosoft.com のような onmicrosoft.com ドメインを取得する。これはメール送信とフィッシングドメインの両方に使用できる
    • LarkSuite (カスタムドメイン可) : https://www.larksuite.com/
    • Zoho (Zohoの「永久無料」メールオプションを利用) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • 方法2 : その他のテクニック

    • Technique 1 : Andre Rosario氏 - BreakDev Red Discordより

      • メールフィルタリングによる配信問題がある場合、Microsoft 365とAzure IPPを使ってターゲットに暗号化メールを送信することを検討しよう!
        • メールは正規のMicrosoft SMTPサーバーから送信されるため、ブロックできない。
        • 暗号化メールを受け取ったターゲットだけが開封でき、もしDFIRチームに転送しても、そのユーザーとしてログインしなければメッセージを見ることができない。
        • Microsoft管理ポータルでカスタムドメインを簡単に操作でき、偽のアカウントを大量に作成できる。
        • M365では任意の表示名を設定できる。そのため、ターゲットのOutlook上では [email protected] からのメールに見えるが、実際には [email protected] からのものである(技術者なら簡単に見抜けるが)。
        • メールは正規のMicrosoft IPとドメインから送信されるため、ドメインのカテゴリ分類や寿命を心配する必要はない(Microsoftであるため)。
    • Technique 2 : Azureの外部招待機能の利用 - BreakDev Red Discordより

      • Azureの外部招待機能は、フィッシングURLへのリダイレクトリンクを含むメールを送信するために使用できる

Evilginxを使ったフィッシングエンゲージメント

  • Evilginxフィッシュレットの構築

    • Evilginxマスターコース : https://academy.breakdev.org/evilginx-mastery
    • Evilginxドキュメント : https://help.evilginx.com/
    • Evilginxフィッシュレットコレクション : https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • Evilginxのあまり知られていないテクニック : https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • Evilginxインストールスクリプト

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • Evilginxインフラ保護のヒント -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - フィッシングページ上のURLを書き換え、URLパスパターンマッチングによる検出を回避する(Kuba氏による)。
      - IOC(X-Evilginxヘッダーとデフォルトの証明書詳細)を削除する
      - 認証されていないリダイレクトの静的コンテンツを修正する
      - Let'sEncryptから各サブドメインごとにリクエストするのではなく、ルートドメインのワイルドカード証明書をリクエストするようにコードを修正する(Kuba氏のブログ参照) - 参考リポジトリ: https://github.com/ss23/evilginx2
      - evilginxをプロキシの背後に配置し、TLSフィンガープリンティング(JA3およびJA3S)を防ぐ
      - 可能であれば、間にCloudflareを使用する(SSL設定を正しく構成し、Cloudflare設定で「Full」に変更する必要がある)
      - 既知のASNブラックリストを使用して検出を回避する(例: https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - 可能であればフィッシュレット内のproxyhostの数を減らし、コンテンツ読み込み時間を短縮する
      - AzureでEvilginxをホストし、そのドメインを使用する(フィッシュレット内のプロキシホストを1つに制限するか、方法を見つける。複数のAzureサブドメインを作成して試すのも良い)
      - sub_filtersを追加してページのコンテンツを変更し、コンテンツベースの検出を回避する(ファビコン、フォームタイトルのフォントやスタイル、関連するものなど)
      - フィッシュレットのsub_filtersを使用して、フィードバック/テレメトリ/ログ/アナリティクスのサブドメインをブロックする。これらはドメインを記録したり、後の分析に役立つ可能性がある。
      - js-injectedが静的か動的かを確認し、静的な場合はevilginxのjs-injectコードを変更して、ユーザー/ターゲットごとに動的/難読化されたバージョンのjsを作成する。
      - EvilginxインフラのIPが漏洩しないようにする。DNS履歴を確認し、どこにも保存されていないことを確認する(アナリストはドメインの古いDNSレコードを調べる可能性がある)
      - この研究に注意: https://catching-transparent-phish.github.io/catching_transparent_phish.pdf 、リポジトリ - https://catching-transparent-phish.github.io/
      

Evilginx 研究ブログ・講演 :

  • 穏やかな海は熟練のフィッシャーマンを作らない - Kuba Gretzky (x33fc0n 2024) :
    • 講演 : https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • スライド : https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • 初期アクセスの三要素 : https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber : https://github.com/Flangvik/Bobber
  • Canary AiTM検出のバイパス : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • CloudflareとHTML難読化を使用してEvilginxを保護 : https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (Evilginxのメール配信信頼性向上) SPF、DMARC、DKIM、MXレコードの追加 : https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • フィッシング戦術とOPSEC : https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + 回避戦術 : https://youtu.be/p1opa2wnRvg
  • Hook, Line and Phishlet - EvilginxでAD FSを攻略する : https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • O365フィッシングインフラ - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • You Can’t See Me – フィッシングインフラの保護 : https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/

Evilginxに対する防御戦略

  • 中間者フィッシングの解明と対策 - X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • HoneyTokensを使用したAiTMの検出 : https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • 最新のフィッシングから保護する : https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • JA3、JA3S、JA4フィンガープリンティングを使用したevilginxの検出
    • JA4データベース : https://ja4db.com/

GoPhishインフラの保護

これらの修正は、最新のevilginx + gophishバージョン(evilginx3.3)でも動作します。

  • ヒント : evilginxと一緒に使用する場合、フィッシングテンプレートで{{.URL}}パラメーターを使用します( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • GoPhishインフラを保護するためのGoPhishソースコードとファイル構造の修正

    • X-Gophishインスタンスの削除( X-Gophish-Contact 、 X-Gophish-Signature)

    • const ServerName= "gophish"を削除し、ファイルconfig/config.goでconst ServerName= "IGNORE"に変更します。

    • config.jsonファイルのデフォルトの管理サーバーポートを変更します。

    • SMTPテスト中の検出を避けるために、テストメールメッセージの署名を変更します。Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      
    • 404応答の変更

AiTM ポストエクスプロイテーション / フィッシング研究ブログ・講演

  • AiTM(ポストエクスプロイテーション) : https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## その他のテクニック/ブログ/研究
  • 正規サイトを悪用したフィッシングについて : https://lots-project.com/
  • Muraena : https://github.com/muraenateam/muraena
  • NecroBrowser : https://github.com/muraenateam/necrobrowser
  • BITB : https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb : https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish : https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • OktaとAzureを連携し、Oktaの自動MFAサブスクリプションとFrame Busterバイパスを使用してBITBを実行 : https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • プログレッシブウェブアプリ(PWA)フィッシング : https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • noVNCフィッシング : https://adepts.of0x.cc/novnc-phishing/

フィッシング研究トークス

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
ツールをダウンロード
  • 一括メールも送信可能。参考: https://learn.microsoft.com/ja-jp/entra/external-id/tutorial-bulk-invite
  • メールを受信箱に届けるためのランダムなヒント

    • 評判の良いドメインを持つこと。ドメインのカテゴリ分類を確認する。
    • 1年以上経過したドメインを使用するか、expireddomain を利用する。
    • 有効なDKIM、DMARC、SPFを持つこと。
      • Mailgoose (SPF、DMARC、DKIMの設定が正しいか確認) : https://github.com/CERT-Polska/mailgoose
    • メールに購読解除リンクを追加する。
    • まず無害なメールを送信する(評判向上に役立つ可能性あり)。
    • メール内のリンクに、メール送信に使用しているものと同じドメインを使用する。
  • ブログ/トーク/参考資料

    • Outlook_Email_Auth_Bypass : https://gitlab.com/hxxpxxp/outlook_email_auth_bypass (OutlookデスクトップアプリとWebアプリでは、メールの「差出人」ヘッダーの「表示名」がユーザーに表示される送信元アドレスを操作できるため、より説得力のあるフィッシングメールになる可能性がある)
    • Spy Pixel - メール追跡用画像ピクセル : https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - 新しいメールなりすまし攻撃パターン : https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • X-Evilginxヘッダーを削除する(req.Header.Setのコード行をすべて確認し、core/http_proxy.goファイルの関連関数をコメントアウトする)

    root@kitploit:~
      // 469行目をコメントアウト
      req.Header.Set(p.getHomeDir(), o_host)
      
      // 659行目をコメントアウト
      req.Header.Set(p.getHomeDir(), o_host)
      
      // 1791-1793行目の関数をコメントアウト
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // 52-54行目をコメントアウト
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • 認証されていないリダイレクトの静的コンテンツを修正するには、core/http_proxy.goファイル内の <html> を検索し、HTMLコードを修正して静的シグネチャを削除する。

  • また、静的に注入されたjsコードのシグネチャ検出を回避するには、以下のようにコードを修正する。

    • インポートに "github.com/tdewolff/minify/js" を追加することを忘れずに

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// エラー処理 - 難読化に失敗
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • core/cert.db ファイルも修正する

  • gophish用の “rid” を変更する。

  • evilginxの前段にnginx、caddyなどのプロキシを配置する。

  • リダイレクタを使用する

    • Cloudflare Turnstileをevilginxのリダイレクタとして使用し、ボットをブロックする。
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • HTML/JSベースのリダイレクタを難読化する
      • 不審なHTTPユーザーエージェントリスト : https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • gabagoolフィッシングキットで使用されているボット検出方法 : https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • リダイレクト用のmeta HTMLタグ
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • デフォルトのルアーURLパターン(長さ8のランダム文字列)を変更する。

    root@kitploit:~
       // core/terminal.go ファイルの728行目
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • フィッシングページのURLを書き換え、URLパスパターンマッチングによる検出を回避する(Kuba氏による)。[この機能はevilginxの公開バージョンでは利用できません。自分で実装する必要があります。]

    root@kitploit:~
    # Evilginx Pro版のみで動作
    # 同様の機能は公開バージョンでも実装可能。
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • ルアー/セッション識別子クッキーの署名パターンと値を変更する(@rad9800 氏による)

    • ルール1: クッキー名=XXXX-XXXX & 値=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • evilginxの該当コード機能(クッキー名用) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • evilginxの該当コード機能(クッキー値用) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • ルール2: スクリプトパス=/s/64_hex_chars.js 、content-length=0
    • ルール3: ルール1とルール2の両方が存在する場合
      • 完全なスニペットのjsブロブロジックはこちら: https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • Referrerヘッダーがフィッシングドメイン名を漏洩するのをブロックする - この研究ブログを参照:

    • http_proxy.goファイルのここに以下の行を追加する(Chromeはこれを尊重せず、リクエストがurl() CSS関数によって開始された場合 - 詳細はブログ参照)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • フィッシュレットから自動化するには、このPRを確認: https://github.com/kgretzky/evilginx2/pull/1006
  • 独自のCSP(コンテンツセキュリティポリシー)を定義し、テレメトリ/カナリア/フィッシングドメインの漏洩による検出を回避する。

    • 詳細はこちら: https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • ターゲットサイトがカナリアトークン(CSS、JS)を使用しているか確認し、それらを回避する

    • (CSS、JS)カナリアAiTM検出のバイパス : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • JA4フィンガープリント回避

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + フレーム破壊バイパス

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx : https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • フレーム破壊バイパスのサブフィルター例: https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 および https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']
      ```- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • フレーム破壊技術の一般的な使用法
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • iframeの存在を検出する一般的な手法
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • iframe検出後、リダイレクトを実行するためにウェブサイトが使用する可能性のある方法
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • Hook, Line and Sinker: Evilginxを使用したWindows Hello for Businessのフィッシング : https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • 耐性のあるフィッシング - Dirk JanによるMicrosoft Entraでのプライマリリフレッシュトークンのフィッシング : https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • Like Shooting Phish in a Barrel - リンククローラーのバイパス : ****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • Drink Like a Phish - フィッシングサイトを目立たなくする方法 ****: https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • Feeding the Phishes : ****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • Push Securityフィッシングツール検出 : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • Push SecurityのChrome拡張機能は、かなり脆弱なルールでevilginxを検出します
      • ルール1: Cookie名=XXXX-XXXX & 値=64_hex_chars
      • ルール2: スクリプトパス=/s/64_hex_chars.js かつ content-length=0
      • ルール3: ルール1とルール2の両方が存在する
      • 完全なスニペットjsブロッブロジックはこちら https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • controllers/phish.goファイルに以下のカスタム関数を追加します。

    root@kitploit:~
    func customNotFound(w http.ResponseWriter, r *http.Request) {
    	http.Error(w, "Try again!", http.StatusNotFound)
    }
    
  • 次に、http.NotFound(w, r)のインスタンスをすべてcustomNotFound(w, r)に置き換えます。

  • robots.txtのハードコードされた応答を削除し、ファイルcontrollers/phish.goで修正します。

    • phish.goファイルの該当コードを以下のように修正します。

      root@kitploit:~
      //修正された応答
      // RobotsHandlerは検索エンジンなどがフィッシング素材をインデックスするのを防ぎます
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • リクエストの"rid"GETパラメーターを変更します。

    • "rid"のインスタンスをすべて他のものに変更してください。
    • これらはevilginx3.3のソースコードにも存在するため、そちらでも修正してください。
  • 高度な防止策として、静的フォルダーを変更して別の名前にリネームし、内部のファイル名も変更してパスベースの検出を回避できます。関連するソースコードも変更することを忘れないでください。

    • 画像名など、例:pixel.pngを他のものに変更します。
  • util/util.goファイルの証明書プロパティを変更します。

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • Nginxを使用してトラフィックをプロキシし、Golangサーバーのフィンガープリントを回避します。

    • service nginx start

    • gophishのconfig.jsonを変更して、HTTPのポートを80から8080に、HTTPSのデフォルトを60002に変更します。以下の通りです。

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • 以下の設定は、User-Agentに"Bot"または"bot"を含むすべてのリクエストをブロックします。

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # イベント処理パラメーターをここで定義
          worker_connections 1024; # 要件に応じて調整
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTPサーバー
          server {
              listen 80 default_server;
              
      
              # User-Agentに"bot"または"Bot"を含むリクエストを拒否
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPSサーバー
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # User-Agentに"bot"または"Bot"を含むリクエストを拒否
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • 特定のUser-Agentのみを許可するには、以下の設定を使用します。これにより、User-Agentが"iamdevil"のリクエストのみを許可し、それ以外はすべてブロックします。

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # イベント処理パラメーターをここで定義
          worker_connections 1024; # 要件に応じて調整
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTPサーバー
          server {
              listen 80 default_server;
      
              # "iamdevil"以外のUser-Agentを持つリクエストを拒否
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPSサーバー
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # "iamdevil"以外のUser-Agentを持つリクエストを拒否
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • 署名されたトラッキングピクセルに基づく検出を回避するために、Gophishトラッキングピクセルの署名を変更します。

  • gophishのメールヘッダーのシーケンスパターンを変更します。これはgophishの検出に使用される可能性があります(BreakDev Red Communityより)。

  • gophishの前にPostFixをセットアップして、IOCやその他の検出、メールのスパム性を除去し、ヘッダーを修正・削除します。

  • GoPhish研究ブログ・講演 :

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • GoPhishの代替 :

    • SniperPhish : https://github.com/GemGeorge/SniperPhish
    • Mailcow : https://github.com/mailcow/mailcow-dockerized
    • EvilnoVNC : https://github.com/JoelGMSec/EvilnoVNC
    • MultiEvilnoVNC : https://blog.wanetty.com/blog/tools/multievilnovnc
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • Delusion(NoVNCベースのツールキット) : https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
    • NoVNCの検出 : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNCとDocker : https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - QRフィッシング
    • QR生成 : https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii : https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish(DockerとnoVNC) : https://github.com/powerseb/NoPhish and https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish : https://github.com/fin3ss3g0d/evilgophish
  • スミッシング : https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • Cloudflare Workersを使ったフィッシング
    • TryCloudflare : https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • Cloudflare Public Bucketsを使ったフィッシング : https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • フィッシングのためのGoogleのオープンリダイレクト
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • オープンリダイレクト(動作しない) : https://googleweblight.com/i?u=m4lici0u5.com
    • オープンリダイレクト : https://www.google.com/url?q=https://m4lici0u5.com
    • オープンリダイレクト : https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • 詳細はこちら : https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • Azure Information Protectionを使用したメール保護制御を回避するフィッシング
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • Docusignの悪用による認証情報フィッシング : https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • EML添付ファイルを使用した隠れた認証情報フィッシング : https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • Microsoft Customer Voiceをフィッシングに使用 : https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking : https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • 各種テクニックの比較 : https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • 受信Microsoft Teams webhookを悪用したフィッシング : https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • フィッシングのためのRogue RDPまたはRDP(.rdp) : https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • フィッシングのためのSVG : https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • ClickOnceをフィッシングに使用して初期アクセスを獲得 : https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • 【必見】Evilworker : https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249