Penetration Testing: Gophish Tutorial (Phishing Framework)

Поділитися
Вставка
  • Опубліковано 18 вер 2024
  • Gophish is a powerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing. This is an important tool for penetration testers and ethical hackers. Learn to use Gophish in this tutorial.
    🎥Course from Sagar Bansal.
    🔗Sagar's UA-cam channel: / @sagarbansal
    🔗Sagar's website: sagarbansal.com/
    --
    Learn to code for free and get a developer job: www.freecodeca...
    Read hundreds of articles on programming: www.freecodeca...

КОМЕНТАРІ • 149

  • @anthonytuff8783
    @anthonytuff8783 5 років тому +27

    This is the only course in you tube that teaches how to do real social engineering campaigns on remote network using Gophish...thank Bro and may your knowldge be increased

  • @Flyers8810
    @Flyers8810 Рік тому +15

    I have recently been tasked with pentesting my coworkers and this tutorial has been a huge help. Thank you!

    • @ytg6663
      @ytg6663 Рік тому

      Is there option to send attachment in gophish

    • @filmrolls3165
      @filmrolls3165 9 місяців тому

      So is it legit to use gmail or outlook to send phishing email?

  • @minibit0103
    @minibit0103 5 років тому +51

    Wow free code camp is covering pentesting tools, awesomeness.

  • @SkreenGG
    @SkreenGG 2 роки тому +9

    This course is so good. I followed from beginning to end and you did such a great job explaining every detail! Thank you so much!

    • @NV-qe3px
      @NV-qe3px 2 роки тому

      Hey, how
      does the CD Command work for you on 18:24?

    • @SkreenGG
      @SkreenGG 2 роки тому +1

      @@NV-qe3px Hey NV, the CD (change directory ) command worked as expected for me. I downloaded the zip file from the the gophish website and placed it in my documents folder then I unzipped it. I used the GUI (just right click on the folder and selected 'extract here'. Then I pulled up the terminal and used the cd (change directory) command to move to the directory where my gophish application was.
      Linux is case sensitive so 'cd' is different from 'CD'.

  • @kyopan23
    @kyopan23 Рік тому +4

    Actual tutorial starts until minute 57:00

  • @asdasfdasdads6635
    @asdasfdasdads6635 2 роки тому +2

    Nice video man! I understood it from the third time but I finally get it :D
    cheers and keep up the good work

  • @stefano6632
    @stefano6632 3 роки тому +4

    Great video!
    Could you also make a video on how to avoid spam filters? Thank you

  • @Iknowpython
    @Iknowpython 5 років тому +5

    great tutorial being a python programmer I find penetration and such topic very interesting thank you so much for this tutorial ... in half way only i understood that its worth watching

  • @aryanupadhyay5107
    @aryanupadhyay5107 3 роки тому +2

    All your words were just flying above my head using a JetPack..... LOL...

  • @osokavictor3852
    @osokavictor3852 4 роки тому +4

    this is a nice tutorial, please can I get the windows version

  • @sasibkarat
    @sasibkarat 5 років тому +1

    Tysm sir for sharing your knowledge

  • @ameen.webdivers
    @ameen.webdivers 5 років тому +4

    This Is the real phishing 😍

  • @lunaticloomer7461
    @lunaticloomer7461 4 роки тому +1

    @Sagar Bansal, you recorded this course on 13th Jan 2018, and released it on 17th June 2019,
    why so?

  • @eminenceubah4083
    @eminenceubah4083 2 роки тому +1

    Kindly do a Video on how to do penetrating test with Gophish using Windows.

  • @askiomen2117
    @askiomen2117 4 роки тому

    Appreciate for the awareness.Thanks

  • @ishrashad
    @ishrashad 10 місяців тому

    I agree with others here, this is a very helpful and well-paced guide. And the only full one that I have found.
    I have a question though, regarding Digital Ocean now blocking the SMTP port by default: I have not contacted them yet, hoping to get some current comments about it before I do.
    I'm running on my usual motto of hope for the best, anticipate the worst. So if I get knocked back on my request, does anyone have a way of getting around the restriction? (and I'm open to any suggestions, like hosting it elsewhere, etc).
    I have the brief to do some penetration testing for a couple of small organisations that I support. THis was looking promising - till I hit this roadblock.
    Any suggestions would be greatly appreciated. Thanks.

  • @edwinng2532
    @edwinng2532 22 дні тому

    I'm not allowed to use my own SMTP as well for some reason not letting sendgrid to get registered. Anyone help? This is regards to using gophish.

  • @borntorule16
    @borntorule16 5 років тому

    Excellent 👌

  • @DabPanda710
    @DabPanda710 3 роки тому +1

    I'm not sure how to setup URL Correctly for Gophish Listening Server for Launch Campaign
    Can you elaborate on that??
    or is it somewhere specific in the Video

  • @AwaisChaudhry
    @AwaisChaudhry 3 роки тому

    Thankyou !

  • @zeeshanansari5812
    @zeeshanansari5812 3 роки тому

    That's great but what about call vicitum

  • @lucascristovam9273
    @lucascristovam9273 4 роки тому +3

    Hello, how are you? I really need your help.
    I can't get gophish to count "submitted data". I've done campaigns for imported sites and also for handmade HTML on login and password. But the gophish does not identify credentials at all. What do you need to do in the code for gophish to collect this information?

  • @TheMbudzeni
    @TheMbudzeni 3 роки тому +1

    Thanks for this bro. I am hosting my gophish server internally in my organization and using an internal IP address to access it and not a domain name. Could that be the reason why my campaigns do not redirect me to the landing page when I click the link on the phishing email just like on your video? Even after clcking the link, the dashboard only updates the number of emails sent and no click stats

  • @hamzasertbas58
    @hamzasertbas58 4 роки тому

    your content is very nice but it would be better if you add automatic translation subtitle.

  • @trevorelvis1355
    @trevorelvis1355 2 роки тому

    Maybe the test email failed cause of the port. When I use 465, it works fine. That's if u enabled access for less secure apps

  • @derock607
    @derock607 3 роки тому +2

    Hey bro, I am a bit confused.... I dont understand how 6:29 became 6:39 ... where did the new files come from during your break?
    I would appreciate an explanation. Thanks

  • @DabPanda710
    @DabPanda710 3 роки тому

    When you click on Quora, how does it go to the landing page? what part of the video is that? I am having issues with data capture

  • @NV-qe3px
    @NV-qe3px 2 роки тому

    On 18:24 in the video, whenever I use the CD command, it doesn't work for some reason.

  • @xoxo-sf1zg
    @xoxo-sf1zg 5 років тому +2

    Amazing as always! Sagar Sir 🔥 😎

  • @mnageh-bo1mm
    @mnageh-bo1mm 5 років тому +7

    all this to just install the it

  • @nourhijazi4347
    @nourhijazi4347 2 роки тому

    is there another alternative for digital ocean droplet

  • @rajdey486
    @rajdey486 4 роки тому +2

    I keep getting the same error "max connection exceeded - unencrypted connection" even after following step by step this video..I dont understand why

    • @r03ky25
      @r03ky25 3 роки тому

      there is a sittings in google account you need to downgrade the security of your account in order to receive mails.

  • @jmanga4723
    @jmanga4723 Рік тому

    Hi, did you have some icloud phishing panel for sale?

  • @randyrobertson-sh9xk
    @randyrobertson-sh9xk Рік тому

    i have problem after luching with ./gophish, my ip refused to load i use azure vps and i have the port 80 open on the portal

  • @TankCatIntoMordor
    @TankCatIntoMordor 3 роки тому +1

    The ZeroSSL generation is slightly different now - you can verify via email, and it gives you three files - does it still work?

    • @kuyadjvlogs
      @kuyadjvlogs 2 роки тому +2

      yes. it works too :) just ignore the another cert with bundler.

    • @TankCatIntoMordor
      @TankCatIntoMordor 2 роки тому

      @@kuyadjvlogs yeah I figured that out too, you can literally just copy and paste the text of each cert into the files within Gophish

  • @Didi-dj5xd
    @Didi-dj5xd 2 роки тому

    I have set up a VPS droplet in Digital Ocean with a domain name (I got a free domain and it has been published) to launch the phishing campaign and I'm trying to obtain an SSL certificate for the domain using ZeroSSL. The domain verification always fails (domain verification using DNS (CNAME)). It shows the error " We were unable to verify your CNAME entry. Please check for errors on your side and try again after 5-10 minutes. " The Name, Address to point to, and TTL values for the new CNAME record which ZeroSSL asks me to add have been entered correctly as a new CNAME record in DigtalOcean but the verification test keeps failing. I have sent an email to ZeroSSL support but some annoying bot responded. Please help!

    • @DailyFlashTate
      @DailyFlashTate Рік тому

      @khunthai6738 for hostname copy only what is behind the dot

  • @saintrophez
    @saintrophez 7 місяців тому

    Hey bro please how can I reach you, I’m having issues with the ssl certificate. What’s your telegram channel?

  • @hugoxu3
    @hugoxu3 Рік тому

    another thing, stop making questions on why u cant execute this and that, and how unzip the file, etc etc. first learn how to use a linux distro, learn how to use the file system, user permissions, google search and you will easily find the answers. you all want to run before knowing how to walk..

  • @egeengindeniz4738
    @egeengindeniz4738 2 роки тому

    Is paid VPS neccessary for external phishing attacks?

  • @himaibrahim2901
    @himaibrahim2901 3 роки тому

    hi , can you please tell me where is the referral link for digital ocean

  • @Scholz23
    @Scholz23 2 роки тому

    My landing page keeps coming up with the gophish login when clicking a link from a test email. Does anyhbody know how to fix this?

  • @lucifergaming9491
    @lucifergaming9491 2 роки тому

    im not able to connect to the phish page hosted on vps

  • @Panchal813
    @Panchal813 2 роки тому

    I have a hosted a site and it is perfectly working fine but i used the certificate and key of that site in the config.json file as "phish_server" and update the certificate and key path. The site is working fine. I am not able to track the details in gophish dashboard. Could you suggest something ?

  • @fer135
    @fer135 3 роки тому +6

    Thank you! Really good video, specially that you teach how configure domain and ssl (free) like in a real world test. I didn't do it in digitalocean but aws, but everything was almost the same. It will be great if you make a video of how to configure the server to send emails also (including the reverse dns)

    • @evercastillo4767
      @evercastillo4767 2 роки тому

      When I run the server everything is ok but I can't see the login page, Im using AWS too, can u help me? I don´t speak english so I hope you can understand me xD

    • @seyeibrahim3750
      @seyeibrahim3750 Рік тому

      Does aws open port 25?

    • @fer135
      @fer135 Рік тому

      @@evercastillo4767 check the firewall rules. You need to open port 80,443 to everyone and 22 to your ip.

  • @anthonybryan4895
    @anthonybryan4895 3 роки тому

    I have successfully created and sent my first campaign but it doesn’t seem to load the requested landing page. I don’t know what I’m doing wrong. It just shows Apache 2 running . Can you reply me back?

  • @playshort9053
    @playshort9053 4 роки тому +1

    Gophish laggy why?

  • @vijaybhaskar925
    @vijaybhaskar925 4 роки тому

    Hi digital ocean is not unblocking smtp 25 port, can you please help me in unblocking the port.

    • @raheembryan1863
      @raheembryan1863 2 роки тому

      Hey did you receive any help with that am having the same problem

  • @hammadamjad469
    @hammadamjad469 3 роки тому

    i am getting max connection attempts exceeded. Kindly let me know how to resolve this

  • @mo-mz9ys
    @mo-mz9ys 4 роки тому +1

    Thank you!
    STMP2GO doens't work thou

  • @HiddenTemplates
    @HiddenTemplates 5 років тому

    Am trying on how to install gophish on my digital ocean vps server but cannot .... Please can you show a video on this...

  • @BrunoSilva-dq2nn
    @BrunoSilva-dq2nn 5 років тому

    Congrats by your video

  • @blancablanquita5800
    @blancablanquita5800 5 років тому

    hi i was working with this tool for a while until stoped to work correctly i cant spoof anymore can i add you to talk about what i have bad in my sending profile?

  • @digidork01
    @digidork01 5 місяців тому

    Gophish default password is not working

  • @kanthraj5646
    @kanthraj5646 3 роки тому

    its showing password wrong at 7:58 for me.
    edit : password will provided by the system during the run time. default password is will not work !

  • @playshort9053
    @playshort9053 4 роки тому

    Why gophish very slow when sending email?

  • @brendawilburn3425
    @brendawilburn3425 2 роки тому

    who can put me through gophish because mine keeps saying wrong password.
    i am using wonders

  • @Didi-dj5xd
    @Didi-dj5xd 2 роки тому

    I'm unable to get DigitalOcean to unblock my smtp server. I need help with that please

    • @hugoxu3
      @hugoxu3 Рік тому

      all u need is a working smtp server, u can use microsoft server (using an outlook/hotmail adress and server config), gmail, whatever you want, keep in mind that some email providers prevent you from using unsecured applications, like gophish, limit the emails that you can send, and the most important in phishing, spoofing your email.

    • @hugoxu3
      @hugoxu3 Рік тому

      i'm currently fighting with that problem, i'm going to test sendgrid. look up for that..

  • @okonkwophilip8141
    @okonkwophilip8141 3 роки тому

    Sorry, please I need help
    My DNS is not going through but my IP address does

  • @f.x_g.m2456
    @f.x_g.m2456 2 роки тому

    Hello sir please how can I get the email raw source code thank you

  • @filmrolls3165
    @filmrolls3165 9 місяців тому

    🙋 Hello guys! But is it legit to use gmail or outlook to send phishing email using this gophish in a company?

  • @kozzek7287
    @kozzek7287 4 роки тому +1

    My emails are landing into the spam category :(

  • @webtoolkit6196
    @webtoolkit6196 Рік тому

    when i enter user name (admin) but the password (gophish) it tells me wrong password pls help me

    • @hugoxu3
      @hugoxu3 Рік тому

      gophish isnt the default password anymore, when you launch the server for the first time, the console outputs the username and password for that session, this is before you change the password. With the outputed password you can login then change it.

  • @Funnycombos
    @Funnycombos 2 роки тому

    I wish you are using windows

  • @rhmoult
    @rhmoult Рік тому

    Actual phishing tutorial starts at ua-cam.com/video/S6S5JF6Gou0/v-deo.html. Irma gerd.

  • @abdelkader8556
    @abdelkader8556 2 роки тому

    Timestamps?

  • @KeithMakank3
    @KeithMakank3 4 роки тому

    echo > [file you want to empty]. Next time.

  • @prashanthravichandhran5688
    @prashanthravichandhran5688 4 роки тому

    how to register free domain in 2020 june (freenom not working)

  • @nagrajullasgokarnkar6366
    @nagrajullasgokarnkar6366 5 років тому

    Sagar is always the best
    Please do course on automatic security by rest API tutorial it may be helpful for many people

    • @empty_7212
      @empty_7212 4 роки тому

      @@sagarbansal Hey! My VPS from Digital Ocean just got disconnected from the network. They say that it could have bem used for spam or DDOS. How can we prevent this from happening?

  • @jnsound2962
    @jnsound2962 2 роки тому

    সুন্দর

  • @karthibalaji3817
    @karthibalaji3817 5 років тому +1

    Great sagar

  • @icyguyxd7807
    @icyguyxd7807 5 років тому +9

    this is a clickbait title xD

    • @icyguyxd7807
      @icyguyxd7807 5 років тому +4

      @@sagarbansal oh sweet summer child xD

    • @mnageh-bo1mm
      @mnageh-bo1mm 5 років тому

      yes

    • @1ycx
      @1ycx 5 років тому

      @@icyguyxd7807 lol. He is the creator of this course - Sagar Bansal

  • @empty_7212
    @empty_7212 4 роки тому +1

    Hey! My VPS from Digital Ocean just got disconnected from the network. They say that it could have bem used for spam or DDOS. How can we prevent this from happening?

  • @weezycrew6039
    @weezycrew6039 3 роки тому

    Hi, thank's for your video it's very helpful to me ! I'm doing a phishing campaign with my job and I need to sent 400/500 mails someone have a solution ? cause outlook gmail ... are limited and I can't sent more than 10 mails there is a solution except buy a domain and configure an smtp server ?
    Thanks :)

  • @sunnychopra0812
    @sunnychopra0812 Рік тому

    50:00

  • @prashanthravichandhran5688
    @prashanthravichandhran5688 4 роки тому

    my mails are ending in spam help me out guys

  • @kumarabhinav1577
    @kumarabhinav1577 4 роки тому

    ./gophish -permission denied

  • @abelrosalez4573
    @abelrosalez4573 4 роки тому

    Hello, does anyone know why the folder wont show? After I unzipped the download on the server, and press ls I dont see the folder, but I do see the zipped file. I don't understand this. Please Help!!

    • @sahilsaalu2355
      @sahilsaalu2355 4 роки тому

      Abel Rosalez unzip /gophish

    • @sahilsaalu2355
      @sahilsaalu2355 4 роки тому

      Abel Rosalez or create a folder name gophish and move files to it

  • @Mohanaharishj
    @Mohanaharishj 4 роки тому +1

    WoW!! that is really helpful!! Thank you!!!!!!
    u rocked it!1

    • @Cosmicray782
      @Cosmicray782 4 роки тому

      hey do you think you can make me one

  • @k.jmotivation7452
    @k.jmotivation7452 5 років тому +1

    Make video on Android development please

    • @Tux0xFF
      @Tux0xFF 5 років тому

      Freecodecamp has dev tutorials just like this in their channel, they might have android tuts already, check out their channel

  • @brettmunro8870
    @brettmunro8870 4 роки тому

    Hi all, great video, i'm having issues with running the gophish server after loading the certificates getting the message " level=fatal msg="tls: failed to parse private key"
    Anyone got any ideas or can help?

    • @acorchia
      @acorchia 4 роки тому

      i suggest checking your file that you might have copied the key information with some empty spaces or not a full copy paste of all text from the private key you created

  • @salemsalem3968
    @salemsalem3968 5 місяців тому

    Waste of time. Speak coherently

  • @vasanthkumar3685
    @vasanthkumar3685 5 років тому

    No contact address has been configured

  • @sankalp_choudhary
    @sankalp_choudhary 5 років тому

    Not much g9od

    • @lunaticloomer7461
      @lunaticloomer7461 4 роки тому

      at-least appreciate his work he's giving out for free.
      DON'T CRITICISE THEM.

  • @mastikids7167
    @mastikids7167 9 місяців тому

    Go learn first you wasted time

  • @cyphercoda4575
    @cyphercoda4575 3 роки тому

    at 38:58, we're so impatient.

  • @LeonardoGA93
    @LeonardoGA93 3 роки тому

    I keep getting the "Cant execute binary file". Obviosly im new at this. Anything I can do?
    gophish: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, ... , not stripped
    Linux usrv 5.8.0-1034-oracle #35~20.04.2-Ubuntu SMP ... aarch64 aarch64 aarch64 GNU/Linux
    PS. I already executed "chmod u+x" on it. Gophish v0.11.0

  • @RaGhav363
    @RaGhav363 2 місяці тому

    whats wrong with your accent bro

  • @kurinjicomputers4361
    @kurinjicomputers4361 4 роки тому +2

    u r wasting most of the time

  • @ravisuj
    @ravisuj 4 роки тому +1

    very bad and unnecessary accent. seems there is no script, very unplanned or not properly executed

    • @b3twiise853
      @b3twiise853 4 роки тому

      Wow

    • @trix7860
      @trix7860 4 роки тому +1

      He cant do anything about his accent?????

    • @lunaticloomer7461
      @lunaticloomer7461 4 роки тому +2

      at-least appreciate his work he's giving out for free.
      DON'T CRITICISE THEM.

    • @hugoxu3
      @hugoxu3 Рік тому

      ​@@lunaticloomer7461 nothing is given out for free. I bet this course was made for some paid platform, when reached the minimal profit he uploaded it to youtube, still making profit from views and adds, not saying that we dont have to be grateful, i am grateful for its effort, but since it was made to be bought at least he should had organize better for recording, scripting the lessons and prepare them before recording, we can see how in many situations he's completely blind on what he is doing, that's not a good professor.. i'm sorry but its the truth.

  • @lawmo69
    @lawmo69 Рік тому

    ./2023>July

  • @nirdeshraya2006
    @nirdeshraya2006 Рік тому

    i got this after unzipping .. well i am using parrot os .. ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=ce2b024de4886db5f77a4b8a437385d17892a60a, for GNU/Linux 3.2.0, with debug_info, not stripped