
フィッシングキャンペーンを送信するための、非常に整理された柔軟なスクリプト
フィッシングキャンペーンを送信するための、超整理された柔軟なスクリプト。
goPhishも素晴らしい選択肢です。しかし、私は同時に柔軟性とシンプルさを重視します。goPhishを何度か使いましたが、ある時点で、圧倒されるか柔軟性に欠けると感じることがありました。
ほとんどの場合、私はそれらの統計情報は必要なく、フィッシングキャンペーンを準備して送信するための柔軟な方法だけが必要です。goPhishを使うたびに、ウェブサイトの追加方法や特定のリクエストの転送方法などをドキュメントで確認しなければなりません。そこで、goCabrito と getCabrito を作成しました。
getCabritoはオプションでメール追跡用のユニークなURLを生成します。
各メールにハッシュを生成し、URLまたは画像URLの末尾に追加し、これらの情報をgetCabritoがインポートして提供するのに役立つ他の情報とともに保存します。この機能がgoCabritoとgetCabritoスクリプトを結びつける唯一のものですので、ご安心ください!
それは私のお気に入りのレストランの名前で、チームメンバーによって選ばれました。
gemsの依存関係をインストール
sudo apt-get install build-essential libsqlite3-dev
gemsをインストール
gem install mail sqlite3
goCabrito.rb — A simple yet flexible email sender.
Help menu:
-s, --server HOST:PORT SMTP server and its port.
e.g. smtp.office365.com:587
-u, --user USER Username to authenticate.
e.g. [email protected]
-p, --pass PASS Password to authenticate
-f, --from EMAIL Sender's email (mostly the same as sender email)
e.g. [email protected]
-t, --to EMAIL|LIST|CSV The receiver's email or a file list of receivers.
e.g. [email protected] or targets.lst or targets.csv
The csv expected to be in fname,lname,email format without header.
-c, --copy EMAIL|LIST|CSV The CC'ed receiver's email or a file list of receivers.
-b, --bcopy EMAIL|LIST|CSV The BCC'ed receiver's email or a file list of receivers.
-B, --body MSG|FILE The mail's body string or a file contains the body (not attachements.)
For click and message opening and other trackings:
Add {{track-click}} tag to URL in the HTML message.
eg: http://phisher.com/file.exe/{{track-click}}
Add {{track-open}} tag into the HTML message.
eg: <html><body><p>Hi</p>{{track-open}}</body></html>
Add {{name}} tag into the HTML message to be replaced with name (used with --to CSV).
eg: <html><body><p>Dear {{name}},</p></body></html>
Add {{num}} tag to be replaced with a random phone number.
-a, --attachments FILE1,FILE2 One or more files to be attached seperated by comma.
-S, --subject TITLE The mail subject/title.
--no-ssl Do NOT use SSL connect when connect to the server (default: false).
-g, --groups NUM Number of receivers to send mail to at once. (default all in one group)
-d, --delay NUM The delay, in seconds, to wait after sending each group.
-P, --profile FILE A json file contains all the the above settings in a file
-D, --db FILE Create a sqlite database file (contains emails & its tracking hashes) to be imported by 'getCabrito' server.
--dry Dry test, no actual email sending.
-h, --help Show this message.
Usage:
goCabrito.rb <OPTIONS>
Examples:
$goCabrito.rb -s smtp.office365.com:587 -u [email protected] -p P@ssword1 \
-f [email protected] -t targets1.csv -c targets2.lst -b targets3.lst \
-B msg.html -S "This's title" -a file1.docx,file2.xlsx -g 3 -d 10
$goCabrito.rb --profile prf.json
dry 値を確認)ruby goCabrito.rb -P CUSTOMER/3/camp3.json --dry
--dry スイッチを削除し、設定ファイルの dry 値が false であることを確認最近では、多くのクラウドベースのメールベンダーがデフォルトでSMTP認証をブロックしています(例:Office365、GSuite)。これはもちろんエラーを引き起こします。これを解決するために、さまざまなベンダーでSMTP認証を有効にするための手順を以下に示します。
SMTP認証をグローバルに有効にするには、PowerShellを使用します。
$ sudo pwsh
Install-Module -Name PSWSMan -Scope AllUsers
Install-WSMan
Install-Module -Name ExchangeOnlineManagement
Import-Module ExchangeOnlineManagement
Connect-ExchangeOnline -InlineCredential
上記のコマンドを実行すると、Office365管理者の認証情報を入力するよう求められます。
PowerShell credential request
Enter your credentials.
User: [email protected]
Password for user [email protected]: **********
Connect-ExchangeOnline -UserPrincipalName [email protected]
Set-TransportConfig -SmtpClientAuthenticationDisabled $false
Set-CASMailbox -Identity [email protected] -SmtpClientAuthenticationDisabled $false
Get-CASMailbox -Identity [email protected] | Format-List SmtpClientAuthenticationDisabled
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
次に以下の手順に従います。