Тёмный

Multi-Factor Authentication Phishing Setup Part 3: EvilGoPhish Setup 

Cyber Attack & Defense
Подписаться 4,7 тыс.
Просмотров 14 тыс.
50% 1

Наука

Опубликовано:

 

30 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 77   
@imposssibruuuu7003
@imposssibruuuu7003 Год назад
thank you for this. i am a red teamer and this has helped
@CyberAttackDefense
@CyberAttackDefense Год назад
Great! Thanks for watching!
@vaster1142
@vaster1142 Год назад
Can you do a class on how to create a YAML phishlet for Evilginx2?
@CyberAttackDefense
@CyberAttackDefense Год назад
I can add that to the list. Thanks for the idea!
@vaster1142
@vaster1142 Год назад
@@CyberAttackDefense Thanks. It'd be nice if it can be hours long and if we could write for an example site you prolly set-up on your localhost. Thanks.
@Kingdd1os
@Kingdd1os Год назад
Best content for pentester ❤
@cvport8155
@cvport8155 Год назад
Please make more vd for advanced techniques red team and phishing tool And evilginx 3 ... Good work
@CyberAttackDefense
@CyberAttackDefense Год назад
Noted
@SamKhan-iw6rl
@SamKhan-iw6rl 2 месяца назад
Can u make a video on how to create phishlists in a convenient way cuz i didn't understand from the main source.
@tektabanca3275
@tektabanca3275 4 месяца назад
Hi . I am using Kali. For me, only " | example | disabled | visible " appears. Why don't other phisleths appear? Thank you
@CyberAttackDefense
@CyberAttackDefense 4 месяца назад
Unfortunately this project is discontinued. I recommend using evilginx3 or 4
@tektabanca3275
@tektabanca3275 4 месяца назад
@@CyberAttackDefense I am using this version: version 3.3.0
@davidlynch5531
@davidlynch5531 3 месяца назад
So are the subdomains in the gophish setup supposed to match the subdomains in the evilginx phishlet?
@CyberAttackDefense
@CyberAttackDefense 3 месяца назад
Yes typically you want them to match.
@tonyweems271
@tonyweems271 Месяц назад
Could you make a video on the updated version
@CyberAttackDefense
@CyberAttackDefense Месяц назад
Yeah sure can.
@davidsmith-ot2hx
@davidsmith-ot2hx Год назад
Awesome tutorial thanks . Which terminal did you use?
@juanpalacio7604
@juanpalacio7604 Год назад
Hi bro good afternoon, do you have any detailed manual or video of how to configure evilgophish step by step, for example, the evilginx part and how to link the user actions with the statistics of the panel, for example: when he clicks or when he opened the email. Thanks
@CyberAttackDefense
@CyberAttackDefense 6 месяцев назад
evilgophish has been archived by the author. It's better to just learn how to setup evilginx3 breakdev.org/evilginx-3-0-evilginx-mastery/
@donaldschniers
@donaldschniers Год назад
Hello sir, sendgrid is not allowing to sign up again, and do you have offer service to help in the installation in the Evilgophish sir? i dont mind paying for it, because am issues in the installation process sir.. anywhere i can contact you sir?
@CyberAttackDefense
@CyberAttackDefense Год назад
No sorry I don’t offer phishing infrastructure setup services right now. Sendgrid can be finicky. You can try many of the other services. Here is another evilginx2 setup guide www.optiv.com/insights/source-zero/blog/spear-phishing-modern-platforms
@foliwe
@foliwe Год назад
Great tutorial. I just have one question. What are the subdomains in the setup for, are they for gophish or evilgnix2. in the setup, you used account and gophish for your example. where do they fit in the program?.
@CyberAttackDefense
@CyberAttackDefense Год назад
That’s for the Apache redirection for subdomains going to evilginx2 within evilgophish setup. That can be a list of different domains.
@bahidieudonne3746
@bahidieudonne3746 9 месяцев назад
good evening sir, your video helped me a lot but there is more for video 4. to see how to configure gophish with the API key.
@CyberAttackDefense
@CyberAttackDefense 8 месяцев назад
Not sure what you need an API key for.
@mynamejebb
@mynamejebb Год назад
What happens if you need to change the domain after setup? Do you redo the txt records and re-run the setup? Will the old gophish database also need to be removed?
@CyberAttackDefense
@CyberAttackDefense Год назад
Either rerun setup or do replace_rid.sh
@avioz3135
@avioz3135 Год назад
Evilginx can't find the db on that path. What should I do??
@CyberAttackDefense
@CyberAttackDefense Год назад
It’s in the gophish folder
@avioz3135
@avioz3135 Год назад
@Cyber Attack & Defense I'm trying to load it, but Evilnginx don't recognize it as valid db
@Boolap1337
@Boolap1337 Год назад
Clean tutorial! People are sleeping on this. The section on this video "Fixing Network Manager, starting 1:02 - Do you recommend doing this on a clean machine? Can these adjustments mess upp my kali box with all my other installations?
@CyberAttackDefense
@CyberAttackDefense Год назад
Yes I recommend this is a separate clean machine just for evilgophish. Use Amazon or digital ocean.
@Boolap1337
@Boolap1337 Год назад
@@CyberAttackDefense what do you mean by ocean or digital ocean? Not kali?
@CyberAttackDefense
@CyberAttackDefense Год назад
@@Boolap1337 nope not kali clean Ubuntu or other image.
@Boolap1337
@Boolap1337 Год назад
@@CyberAttackDefense alright, something new for me then. Will try tmr as its 01.45 AM atm :)… appreciate the answers
@fabianpena7370
@fabianpena7370 Год назад
When I use the Google Admin Toolbox Dig, it doesn't show me any results. In the TXT section I get: Record not found!
@CyberAttackDefense
@CyberAttackDefense Год назад
Then you haven’t put the correct records in.
@fabianpena7370
@fabianpena7370 Год назад
@@CyberAttackDefense I did put the acme records.
@CyberAttackDefense
@CyberAttackDefense Год назад
@@fabianpena7370 it must be public facing DNS. Otherwise I have no idea.
@avioz3135
@avioz3135 Год назад
@@fabianpena7370 Make sure to include the acme part only while adding the TXT record
@Clurd284
@Clurd284 Год назад
Great teaching. Just some few setbacks I'm experiencing and I would need your guidance. I'm done setting the lures and a link was generated for me . But i cant access the website cos the server cant be found. is there something I'm not doing write?
@CyberAttackDefense
@CyberAttackDefense Год назад
Hmm sounds like it could be DNS or name resolution. Try adding that name in your hosts file or DNS.
@Clurd284
@Clurd284 Год назад
​@@CyberAttackDefense Thank you for the reply. Pls how do i add the name in my hosts file or DNS. Been on it for more than 3 hours. I deleted the setup and started again. Still giving me the same error. I followed your tutorial from scratch.
@CyberAttackDefense
@CyberAttackDefense Год назад
@@Clurd284 www.hostinger.com/tutorials/how-to-edit-hosts-file#Change_the_File_Manually
@Boolap1337
@Boolap1337 Год назад
@@Clurd284 Did you solve this issue? Facing the same.
@vaster1142
@vaster1142 Год назад
Just found this channel and I'm in love with you already. It's easy to see you put in all you have into these videos. Thanks a bunch for this.
@CyberAttackDefense
@CyberAttackDefense Год назад
Welcome aboard!
@charlesmarseille123
@charlesmarseille123 Год назад
Yes.. so glad to have found it also. The prime time for youtubers is before people realize how good they are. Thanks for your work!
@vaster1142
@vaster1142 Год назад
@@charlesmarseille123 Really, right? They kind of lose that passion and focus on growth, which is also important, later on.
@DanielSchneider-lt7xm
@DanielSchneider-lt7xm Год назад
Hello Sir, please i need where to get a VPS that i can use for the installation..
@CyberAttackDefense
@CyberAttackDefense Год назад
Amazon EC2, digital ocean, etc
@Boolap1337
@Boolap1337 Год назад
@@CyberAttackDefense How come you didnt go thru the setup for a VPS in this tutorial? Is a VPS needed, like Digital Ocean, or can I use my VM machine as a VPS?
@CyberAttackDefense
@CyberAttackDefense Год назад
@@Boolap1337 I figured everyone could figure out their own choices on cloud vs local. A VPS isn’t required.
@joshhood9565
@joshhood9565 Год назад
Great video content, is there a way to prevent the lures link from turning red fast?
@CyberAttackDefense
@CyberAttackDefense Год назад
Not sure I understand the question.
@Redearslider239
@Redearslider239 Год назад
Great video sir. Sir my dns record get verified and CA certificate but atlast the binary file of evilgnix2 n gophish did not install. While installing binary it is giving me error please help me sir.
@CyberAttackDefense
@CyberAttackDefense Год назад
Check to make sure go installed. If it didn’t then you need to install it manually then go into each folder and run go build.
@waldep
@waldep Год назад
@@CyberAttackDefense the same issue sir, even when i run "go build" inside each folder, the binary file does not get created, please help, Thanks for your knowledge sharing
@CyberAttackDefense
@CyberAttackDefense Год назад
@@waldep Hmm. I really don't know what could be happening. Maybe check this article out. www.digitalocean.com/community/tutorials/how-to-build-and-install-go-programs
@waldep
@waldep Год назад
@@CyberAttackDefense The solution was to purge GoLang version "go1.20.1" (that comes by default with the server ) and re-install "go1.19.5"
@CyberAttackDefense
@CyberAttackDefense Год назад
@@waldep that’s not surprising. I ran into a bunch of issues with GO when I was building out this video setup.
@Boolap1337
@Boolap1337 Год назад
Im not finding any binaries when looking thru evilgophish. I didnt have problems downloading Go either. What could be the issue?
@CyberAttackDefense
@CyberAttackDefense Год назад
There are some issues with the version of go on default Ubuntu. You need to install the newest version then try again.
@Boolap1337
@Boolap1337 Год назад
@@CyberAttackDefense newest version of go? Appreciate it.
@CyberAttackDefense
@CyberAttackDefense Год назад
@@Boolap1337 yep newest version works.
@Boolap1337
@Boolap1337 Год назад
@@CyberAttackDefense Just reinstalled go. I got the binaries in evilfeed and gophish but not in evilginx2, any ideas? Appreciate the help.. :-)
@Boolap1337
@Boolap1337 Год назад
used go1.20.1.linux-amd64.tar.gz
@harryharry-gz9nv
@harryharry-gz9nv Год назад
It is necessary to build your own sMtp server
@CyberAttackDefense
@CyberAttackDefense Год назад
No sendgrid and other providers will send the mail for you.
@unoallin6389
@unoallin6389 Год назад
​@@CyberAttackDefense U cannot spoof emails with sendgrid. U need your own smtp server for that. Your tutorials don't make sense in regards to spoofing as you're sending emails from your own domain. So thats not spoofing
@CyberAttackDefense
@CyberAttackDefense Год назад
@@unoallin6389 I assure you the email sent comes from gophish through the sendgrid api. There isn’t an smtp server involved. I’m not spoofing anything just using a registered domain.
@avioz3135
@avioz3135 Год назад
@@unoallin6389 You will need to add SPF record to allow Sendgrid to send email behalf of your domin.
Далее
▼ КАПИТАН НАШЁЛ НЕФТЬ В 🍑
33:40
Просмотров 457 тыс.
MFA Can Be Easily Bypassed - Here's How
9:22
Просмотров 91 тыс.
Finding the Sliver Lining
22:47
Просмотров 4,1 тыс.
Cori sets up Gophish on LighSail
6:22
Просмотров 7 тыс.
bulletproof❌ Nokia✅
0:17
Просмотров 32 млн
Мэджик! Смартфон 2-в-1!
0:48
Просмотров 754 тыс.
Умный обзор умного iPhone 16 / 16 Pro
21:21