Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Evilginx-Phishing-Infra-Setup — Evilginx 网络钓鱼基础设施设置指南 - 保护 Evilginx 和 Gophish 基础设施、清除 IOC、网络钓鱼 TTP | Kitploit
工具/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
钓鱼工具IDS/IPS规避钓鱼攻击命令与控制社会工程学学习与教育红队精选资源电子邮件安全

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
an0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Evilginx 网络钓鱼基础设施设置指南 - 保护 Evilginx 和 Gophish 基础设施、清除 IOC、网络钓鱼 TTP

查看仓库
59811561年前Kitploit 审核通过

钓鱼演练基础设施搭建指南

注意: 这些内容是我个人笔记的副本。请不要完全依赖它们。

目录

  • 博客/演讲
  • 红队/钓鱼基础设施自动化
  • 域名购买与分类技术
  • 使用工具改进钓鱼邮件编写
  • 测试邮件的垃圾邮件程度
  • 模拟钓鱼邮件/紫队钓鱼演练
  • Awesome 企业邮件安全资源
  • 将邮件投递至收件箱
  • 使用 Evilginx 进行钓鱼演练
    • 构建 Evilginx Phishlets
    • Evilginx 安装脚本
    • 加固 Evilginx 基础设施的技巧
    • Evilginx 研究博客/演讲
    • 针对 Evilginx 的防御策略
  • 加固 GoPhish 基础设施
    • GoPhish 研究博客/演讲
    • Gophish 替代方案
  • AiTM 后渗透/钓鱼研究博客/演讲
  • 其他技术/博客/研究
  • 钓鱼研究演讲

博客/演讲

  • BHIS | 如何构建钓鱼演练 - 编写 TTP:https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

红队/钓鱼基础设施自动化

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - 2024 年红队技巧:https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • 即时部署钓鱼基础设施:https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

域名购买与分类技术

  • 检查过期域名,如有合适的可直接购买

    • https://expireddomains.net/
  • 域名分类

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx(需要注册)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm(需要注册)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx(仅支持提交,不支持查询)(点击 Submit a Sample -> Web Address)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • 自动化域名信誉检查/提交

    • Domainhunter:https://github.com/threatexpress/domainhunter
    • Chameleon:https://github.com/mdsecactivebreach/Chameleon

使用工具改进钓鱼邮件编写

  • mgeeky:https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter(避免常见的钓鱼邮件用词):https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers:https://github.com/mgeeky/decode-spam-headers

测试邮件的垃圾邮件程度

  • https://www.mail-tester.com/

模拟钓鱼邮件/紫队钓鱼演练

  • https://delivr.to/

Awesome 企业邮件安全资源

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner 邮件安全平台魔力象限 email-security-providers

将邮件投递至收件箱

  • 方法 1:使用邮件服务提供商

    • 使用 SendGrid - http://sendgrid.com/
      • 服务很有用,但说实话,你需要 Pro 付费套餐才有幸不被列入垃圾邮件列表
    • MailGun - https://app.mailgun.com/
      • 没有遇到过任何问题
    • Amazon AWS SES
    • Brevo:https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • 设置一个 Azure 租户,获取类似 attackdomain.onmicrosoft.com 的 onmicrosoft.com 域名,该域名既可用于发送邮件,也可用作钓鱼域名
    • LarkSuite(支持自定义域名):https://www.larksuite.com/
    • Zoho(使用 Zoho“终身免费”邮箱选项):https://www.zoho.com/mail/custom-domain-email.html
    • Yandex:https://360.yandex.com/business/domain-mail/
  • 方法 2:其他技巧

    • 技巧 1:作者 Andre Rosario - 来自 BreakDev Red Discord

      • 如果你因邮件过滤而难以投递邮件,可以考虑使用 Microsoft 365 和 Azure IPP 向目标发送加密邮件!
        • 邮件来自合法的 Microsoft SMTP 服务器,因此他们无法将其屏蔽。
        • 只有收到加密邮件的目标才能打开它;如果他们将其转发给 DFIR(数字取证与应急响应)团队,对方也必须以该用户身份登录才能看到你的消息。
        • 在 Microsoft 管理门户中可轻松编排自定义域名,并创建大量虚假账户。
        • M365 允许你设置任意的显示名称。因此,在目标的 Outlook 中,邮件可能看起来像来自 [email protected],但实际上来自 [email protected](不过技术人员很容易识破这一点)
        • 邮件来自合法的 Microsoft IP 和域名,因此你无需担心域名分类或域名寿命,因为这是微软的基础设施。
    • 技巧 2:使用 Azure 外部邀请功能 - 来自 BreakDev Red Discord

      • Azure 外部邀请可用于发送包含重定向到钓鱼 URL 链接的邮件
      • 也可以批量发送邮件,参考:https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite

使用 Evilginx 进行钓鱼演练

  • 构建 Evilginx Phishlets

    • Evilginx 精通课程:https://academy.breakdev.org/evilginx-mastery
    • Evilginx 文档:https://help.evilginx.com/
    • Evilginx Phishlets 合集:https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • Evilginx 鲜为人知的技巧:https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • Evilginx 安装脚本

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • 加固 Evilginx 基础设施的技巧 -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - Rewrite URLs on Phishing Pages to avoid detection through URL Path pattern matching (by Kuba).
      - Remove IOCs (X-Evilginx header and Default Cert Details)
      - Modify Unauth redirect static contents
      - Modify code to request wildcard certificates for root domain from Let'sEncrypt other than requesting for each subdomains (As mentioned in Kuba's blog) - Check this repo for reference https://github.com/ss23/evilginx2
      - Put evilginx behind a proxy to help against TLS fingerprinting (JA3 and JA3S)
      - Use cloudflare in between if possible/feasible (You have to configure the SSL Settings correctly, change it to Full in cloudflare settings)
      - Use some known ASN blacklist to avoid getting detected like here (https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - Reduce the Number of proxyhosts in phishlet if possible to reduce content loading time.
      - Host Evilginx at Azure and use their domain (limit proxy host in phishlet to 1 or find a way , may be create multiple azure sub domains and try with that)
      - Add some sub_filters to modify the content of the pages to avoid content based detections, like (Favicon, form title font or style, or anything which seems relevant)
      - Block the feedback/telemetry/logs/analytics subdomains using the phishlet sub_filters which can log the domain or may help later on analysis.
      - See if js-injected is static or dynamic , if static modify the evilginx js-inject code to create dynamic/obfuscated version of your js for each user/target.
      - Make sure to not leak your Evilginx infra IP, Check the DNS history to make sure its not stored anywhere (Analysts may look for older DNS Records of the domain)
      - Be aware of this research : https://catching-transparent-phish.github.io/catching_transparent_phish.pdf , repo - https://catching-transparent-phish.github.io/
      

Evilginx 研究博客/演讲:

  • 平静的海面练就不出熟练的钓鱼者 - Kuba Gretzky(x33fc0n 2024):
    • 演讲:https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • 幻灯片:https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • 初始访问的三位一体:https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber:https://github.com/Flangvik/Bobber
  • 绕过 Canary AiTM 检测:https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • 使用 Cloudflare 和 HTML 混淆保护 Evilginx:https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (提高 Evilginx 邮件送达信任)添加 SPF、DMARC、DKIM、MX 记录:https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • 钓鱼战术与 OPSEC:https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + 规避战术:https://youtu.be/p1opa2wnRvg
  • Hook, Line and Phishlet——用 Evilginx 攻克 AD FS:https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • O365 钓鱼基础设施 - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • 你看不见我——保护你的钓鱼基础设施:https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/

针对 Evilginx 的防御战术

  • 揭示并反制中间人钓鱼(Adversary in the Middle Phishing)- X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • 使用蜜令牌(HoneyTokens)检测 AiTM:https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • 防范现代钓鱼攻击:https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • 使用 JA3、JA3S、JA4 指纹识别检测 evilginx
    • JA4 数据库:https://ja4db.com/

保护 GoPhish 基础设施

这些修改也适用于最新的 evilginx + gophish 版本,即 evilginx3.3

  • 提示:在与 evilginx 配合使用时,请在钓鱼模板中使用 {{.URL}} 参数( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • 对 gophish 源码和文件结构进行修改,以保护 GoPhish 基础设施

    • 移除 X-Gophish 实例(X-Gophish-Contact、X-Gophish-Signature)

    • 在 config/config.go 文件中移除 const ServerName= "gophish",并将其改为 const ServerName= "IGNORE"

    • 更改 config.json 文件中的默认 Admin 服务器端口。

    • 修改测试邮件消息签名,以避免在 SMTP 测试期间被检测到。Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      
    • 更改 404 响应

      • 在 文件中添加以下自定义函数

AiTM 后渗透/钓鱼研究博客与演讲

  • AiTM(后渗透):https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## 其他技术/博客/研究
  • 用于钓鱼的滥用合法站点:https://lots-project.com/
  • Muraena:https://github.com/muraenateam/muraena
  • NecroBrowser:https://github.com/muraenateam/necrobrowser
  • BITB:https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb:https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish:https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • 将 Okta 与 Azure 链式结合,通过 Okta 的自动 MFA 订阅和 Frame Buster 绕过执行 BITB:https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • 渐进式 Web 应用(PWA)钓鱼:https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • noVNC 钓鱼:https://adepts.of0x.cc/novnc-phishing/
    • EvilnoVNC:

钓鱼研究演讲

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
下载工具
  • 博客

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7
  • 帮助邮件进入收件箱的零散小技巧

    • 使用信誉良好的域名,检查域名分类
    • 使用注册超过 1 年的域名,或使用过期域名
    • 配置有效的 DKIM、DMARC 和 SPF
      • Mailgoose(检查其 SPF、DMARC 和 DKIM 配置是否正确):https://github.com/CERT-Polska/mailgoose
    • 在邮件中添加退订链接
    • 先发送良性邮件(可能有助于建立信誉)
    • 邮件中的链接使用与发送邮件相同的域名
  • 博客/演讲/参考资料

    • Outlook_Email_Auth_Bypass:https://gitlab.com/hxxpxxp/outlook_email_auth_bypass(在 Outlook 桌面版和网页版中,邮件“From”标头的“显示名称”可以操纵展示给用户的发件邮箱,从而制作出更具迷惑性的钓鱼邮件)
    • Spy Pixel - 用于跟踪邮件的图片像素:https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - 新型邮件伪造攻击模式:https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • 移除 X-Evilginx 标头(检查所有包含 req.Header.Set 的代码行,并注释掉 core/http_proxy.go 文件中的相关函数)

    root@kitploit:~
      // comment line 469
      req.Header.Set(p.getHomeDir(), o_host)
      
      //comment line 659
      req.Header.Set(p.getHomeDir(), o_host)
      
      // comment function at line 1791-1793
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // comment line 52-54
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • 要修改未授权重定向的静态内容,请在 core/http_proxy.go 文件中搜索 <html>,并修改 HTML 代码以移除所有静态特征。

  • 另外,为了避免静态注入的 JS 代码特征被检测,你可以按如下方式修改代码

    • 确保在 imports 中添加“github.com/tdewolff/minify/js”

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// Handle error - Obfuscation failed
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • 同时修改 core/cert.db 文件

  • 为 gophish 更改 “rid”。

  • 在 evilginx 前面使用 nginx、caddy 或其他代理。

  • 使用重定向器

    • 使用 Cloudflare Turnstile 作为 evilginx 重定向器并阻止机器人。
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • 混淆基于 HTML/JS 的重定向器
      • 可疑 HTTP User-Agent 列表:https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • gabagool 钓鱼工具包使用的机器人检测方法:https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • 用于重定向的 Meta HTML 标签
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • 更改默认的 lure URL 模式,该模式为 8 位随机字符串。

    root@kitploit:~
       // Line 728 in core/terminal.go file
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • 重写钓鱼页面上的 URL,以避免通过 URL 路径模式匹配被检测(作者 Kuba)。[此功能在 evilginx 公开版中不可用,你必须自行实现。]

    root@kitploit:~
    # Only Work in Evilginx Pro Version
    # Similar functionality can be implemented in public version as well.
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • 修改 lure/会话标识 Cookie 的特征模式和值(作者 @rad9800 )

    • 规则 1:Cookie 名称=XXXX-XXXX & 值=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • 对应的 evilginx 代码功能(针对 Cookie 名称):https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • 对应的 evilginx 代码功能(针对 Cookie 值):https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • 规则 2:脚本路径=/s/64_hex_chars.js,且 content-length=0
    • 规则 3:规则 1 和规则 2 同时存在
      • 完整的 JS blob 逻辑片段在此处
  • 阻止 Referrer 标头泄露你的钓鱼域名 - 参考这篇研究博客:

    • 在 http_proxy.go 文件的此处添加以下行(Chrome 不遵守此设置,且当请求由 url() CSS 函数发起时 - 更多细节请查看博客)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • 要从 phishlet 中自动执行,请看这个 PR:https://github.com/kgretzky/evilginx2/pull/1006
  • 定义你自己的 CSP(内容安全策略),以避免因泄露钓鱼域名而被遥测/金丝雀/检测系统发现。

    • 更多信息请阅读:https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • 检查目标站点是否使用了某种金丝雀令牌(CSS、JS),并规避它们

    • 绕过(CSS、JS)金丝雀 AiTM 检测:https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • JA4 指纹规避

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + 框架破环绕过

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx:https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • 框架破环绕过 Subfilter 示例(来自):https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 和 https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • 通常使用的 Frame Busting 技术
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • 检测 iframe 存在的常用技术
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • 网站检测到 iframe 后可能会使用以下方法执行重定向
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • 完全上钩:使用 Evilginx 钓鱼 Windows Hello for Business:https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • 钓鱼有防备者——在 Microsoft Entra 中窃取主刷新令牌(Dirk Jan):https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • 桶中射鱼——绕过链接爬虫:****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • 像鱼一样豪饮——如何让你的钓鱼网站融入环境 ****:https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • 喂养钓鱼目标:****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • Push Security 钓鱼工具检测:https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • Push Security 的 Chrome 扩展使用一些相当脆弱的规则检测 evilginx
      • 规则1:Cookie name=XXXX-XXXX & value=64_hex_chars
      • 规则2:Script path=/s/64_hex_chars.js with content-length=0
      • 规则3:规则1 和规则2 同时存在
      • 完整的 JS blob 代码片段逻辑见 https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • controllers/phish.go
    root@kitploit:~
    func customNotFound(w http.ResponseWriter, r *http.Request) {
    	http.Error(w, "Try again!", http.StatusNotFound)
    }
    
  • 现在将所有 http.NotFound(w, r) 替换为 customNotFound(w, r)

  • 移除 robots.txt 硬编码响应,并在 controllers/phish.go 文件中进行修改

    • 将 phish.go 文件中的相应代码修改为以下内容。

      root@kitploit:~
      //Modified Response
      // RobotsHandler prevents search engines, etc. from indexing phishing materials
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • 修改请求中的 “rid” GET 参数

    • 确保将所有 "rid" 实例修改为其他内容。
    • 这些内容也存在于 evilginx3.3 源码中,因此请确保在那里也进行修改。
  • 为了更高级的防护,你也可以修改 static 文件夹并将其重命名为其他名称,同时重命名其中的文件,以避免基于路径的检测。不要忘记同步修改相关源代码。

    • 例如图片名称,如 pixel.png,将其修改为其他名称。
  • 更改 util/util.go 文件中的证书属性

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • 使用 Nginx 代理流量,以避免任何 Golang 服务器指纹

    • service nginx start

    • 你需要修改 gophish 的 config.json,将 http 端口从 80 改为 8080,并将 https 端口从默认值改为 60002,如下所示

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • 以下配置将阻止所有 User-Agent 中包含 “Bot” 或 “bot” 的请求

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTP server
          server {
              listen 80 default_server;
              
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • 若仅允许特定 User-Agent,请使用以下配置。这将阻止所有请求,仅允许 User-Agent 为 “iamdevil” 的请求。

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTP server
          server {
              listen 80 default_server;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • 修改 Gophish 追踪像素签名,以避免基于已知签名追踪像素的检测。

  • 更改 gophish 邮件头序列模式。该模式可能被用于检测 gophish(来自 BreakDev Red 社区)。

  • 在 gophish 前设置 PostFix,以清除 IOCs、其他检测特征以及邮件的垃圾邮件特征,同时移除并修复邮件头。

  • GoPhish 研究博客/演讲:

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • Gophish 替代方案:

    • SniperPhish:https://github.com/GemGeorge/SniperPhish
    • Mailcow:https://github.com/mailcow/mailcow-dockerized
  • https://github.com/JoelGMSec/EvilnoVNC
  • MultiEvilnoVNC:https://blog.wanetty.com/blog/tools/multievilnovnc
  • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
  • Delusion(基于 NoVNC 的工具包):https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • 检测 NoVNC:https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNC 与 Docker:https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - QR 码钓鱼
    • 生成 QR 码:https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii:https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish(Docker 和 noVNC):https://github.com/powerseb/NoPhish 和 https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish:https://github.com/fin3ss3g0d/evilgophish
  • Smishing:https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • 使用 CloudFlare Workers 进行钓鱼
    • TryCloudflare:https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • 使用 Cloudflare 公共存储桶进行钓鱼:https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • 用于钓鱼的 Google 开放重定向
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • 开放重定向(不可用):https://googleweblight.com/i?u=m4lici0u5.com
    • 开放重定向:https://www.google.com/url?q=https://m4lici0u5.com
    • 开放重定向:https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • 更多内容可在此找到:https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • 使用 Azure 信息保护绕过邮件防护控制的钓鱼
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • 通过滥用 DocuSign 进行凭据钓鱼:https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • 隐藏在 EML 附件中的凭据钓鱼:https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • 利用 Microsoft Customer Voice 进行钓鱼:https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking:https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • 各种技术的比较:https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • 滥用 Microsoft Teams 入站 Webhook 进行钓鱼:https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • 用于钓鱼的恶意 RDP 或 RDP(.rdp):https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • 利用 SVG 进行钓鱼:https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • 使用 ClickOnce 与钓鱼获取初始访问权限 :https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • [必看] Evilworker:https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249