Multi-Factor Authentication Phishing Setup Part 3: EvilGoPhish Setup

Поділитися
Вставка
  • Опубліковано 16 лис 2024

КОМЕНТАРІ • 80

  • @imposssibruuuu7003
    @imposssibruuuu7003 Рік тому

    thank you for this. i am a red teamer and this has helped

  • @Kingdd1os
    @Kingdd1os Рік тому +2

    Best content for pentester ❤

  • @cvport8155
    @cvport8155 Рік тому +2

    Please make more vd for advanced techniques red team and phishing tool
    And evilginx 3 ... Good work

  • @vaster1142
    @vaster1142 Рік тому

    Just found this channel and I'm in love with you already. It's easy to see you put in all you have into these videos. Thanks a bunch for this.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      Welcome aboard!

    • @charlesmarseille123
      @charlesmarseille123 Рік тому +1

      Yes.. so glad to have found it also. The prime time for youtubers is before people realize how good they are. Thanks for your work!

    • @vaster1142
      @vaster1142 Рік тому

      @@charlesmarseille123
      Really, right? They kind of lose that passion and focus on growth, which is also important, later on.

  • @davidsmith-ot2hx
    @davidsmith-ot2hx Рік тому

    Awesome tutorial thanks . Which terminal did you use?

  • @vaster1142
    @vaster1142 Рік тому +2

    Can you do a class on how to create a YAML phishlet for Evilginx2?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому +1

      I can add that to the list. Thanks for the idea!

    • @vaster1142
      @vaster1142 Рік тому

      @@CyberAttackDefense Thanks. It'd be nice if it can be hours long and if we could write for an example site you prolly set-up on your localhost. Thanks.

  • @NicoleAbraham-v9l
    @NicoleAbraham-v9l Місяць тому

    just watching this amazing video, what happens if i can't find the gophish binary in the directory. how do i resolve this

  • @Boolap1337
    @Boolap1337 Рік тому

    Clean tutorial! People are sleeping on this.
    The section on this video "Fixing Network Manager, starting 1:02 - Do you recommend doing this on a clean machine? Can these adjustments mess upp my kali box with all my other installations?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      Yes I recommend this is a separate clean machine just for evilgophish. Use Amazon or digital ocean.

    • @Boolap1337
      @Boolap1337 Рік тому

      @@CyberAttackDefense what do you mean by ocean or digital ocean? Not kali?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@Boolap1337 nope not kali clean Ubuntu or other image.

    • @Boolap1337
      @Boolap1337 Рік тому

      @@CyberAttackDefense alright, something new for me then. Will try tmr as its 01.45 AM atm :)… appreciate the answers

  • @SamKhan-iw6rl
    @SamKhan-iw6rl 4 місяці тому

    Can u make a video on how to create phishlists in a convenient way cuz i didn't understand from the main source.

  • @foliwe
    @foliwe Рік тому

    Great tutorial. I just have one question. What are the subdomains in the setup for, are they for gophish or evilgnix2. in the setup, you used account and gophish for your example. where do they fit in the program?.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      That’s for the Apache redirection for subdomains going to evilginx2 within evilgophish setup. That can be a list of different domains.

  • @bahidieudonne3746
    @bahidieudonne3746 10 місяців тому

    good evening sir, your video helped me a lot but there is more for video 4. to see how to configure gophish with the API key.

  • @tonyweems271
    @tonyweems271 3 місяці тому

    Could you make a video on the updated version

  • @juanpalacio7604
    @juanpalacio7604 Рік тому

    Hi bro good afternoon, do you have any detailed manual or video of how to configure evilgophish step by step, for example, the evilginx part and how to link the user actions with the statistics of the panel, for example: when he clicks or when he opened the email. Thanks

    • @CyberAttackDefense
      @CyberAttackDefense  8 місяців тому

      evilgophish has been archived by the author. It's better to just learn how to setup evilginx3 breakdev.org/evilginx-3-0-evilginx-mastery/

  • @tektabanca3275
    @tektabanca3275 6 місяців тому

    Hi . I am using Kali. For me, only " | example | disabled | visible " appears. Why don't other phisleths appear?
    Thank you

    • @CyberAttackDefense
      @CyberAttackDefense  6 місяців тому

      Unfortunately this project is discontinued. I recommend using evilginx3 or 4

    • @tektabanca3275
      @tektabanca3275 6 місяців тому

      @@CyberAttackDefense I am using this version: version 3.3.0

  • @davidlynch5531
    @davidlynch5531 4 місяці тому

    So are the subdomains in the gophish setup supposed to match the subdomains in the evilginx phishlet?

  • @mynamejebb
    @mynamejebb Рік тому

    What happens if you need to change the domain after setup? Do you redo the txt records and re-run the setup? Will the old gophish database also need to be removed?

  • @Clurd284
    @Clurd284 Рік тому

    Great teaching. Just some few setbacks I'm experiencing and I would need your guidance. I'm done setting the lures and a link was generated for me . But i cant access the website cos the server cant be found. is there something I'm not doing write?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      Hmm sounds like it could be DNS or name resolution. Try adding that name in your hosts file or DNS.

    • @Clurd284
      @Clurd284 Рік тому

      ​@@CyberAttackDefense Thank you for the reply. Pls how do i add the name in my hosts file or DNS. Been on it for more than 3 hours. I deleted the setup and started again. Still giving me the same error. I followed your tutorial from scratch.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому +1

      @@Clurd284 www.hostinger.com/tutorials/how-to-edit-hosts-file#Change_the_File_Manually

    • @Boolap1337
      @Boolap1337 Рік тому

      @@Clurd284 Did you solve this issue? Facing the same.

  • @joshhood9565
    @joshhood9565 Рік тому

    Great video content, is there a way to prevent the lures link from turning red fast?

  • @adeniranjamiu8417
    @adeniranjamiu8417 Місяць тому

    Have been looking for such this nice video, bro.. kudos to your talent and am having problems showing on evilginx2 after I run this command ./build/evilginx -p ./phishlets/ and it showing certdb: tls: private key does not match public key, could you help on this such case please.

  • @fabianpena7370
    @fabianpena7370 Рік тому

    When I use the Google Admin Toolbox Dig, it doesn't show me any results. In the TXT section I get: Record not found!

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      Then you haven’t put the correct records in.

    • @fabianpena7370
      @fabianpena7370 Рік тому

      @@CyberAttackDefense I did put the acme records.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@fabianpena7370 it must be public facing DNS. Otherwise I have no idea.

    • @avioz3135
      @avioz3135 Рік тому

      @@fabianpena7370 Make sure to include the acme part only while adding the TXT record

  • @avioz3135
    @avioz3135 Рік тому

    Evilginx can't find the db on that path. What should I do??

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      It’s in the gophish folder

    • @avioz3135
      @avioz3135 Рік тому

      @Cyber Attack & Defense I'm trying to load it, but Evilnginx don't recognize it as valid db

  • @Boolap1337
    @Boolap1337 Рік тому

    Im not finding any binaries when looking thru evilgophish. I didnt have problems downloading Go either. What could be the issue?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      There are some issues with the version of go on default Ubuntu. You need to install the newest version then try again.

    • @Boolap1337
      @Boolap1337 Рік тому

      @@CyberAttackDefense newest version of go? Appreciate it.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@Boolap1337 yep newest version works.

    • @Boolap1337
      @Boolap1337 Рік тому

      @@CyberAttackDefense Just reinstalled go. I got the binaries in evilfeed and gophish but not in evilginx2, any ideas?
      Appreciate the help.. :-)

    • @Boolap1337
      @Boolap1337 Рік тому

      used go1.20.1.linux-amd64.tar.gz

  • @DanielSchneider-lt7xm
    @DanielSchneider-lt7xm Рік тому

    Hello Sir, please i need where to get a VPS that i can use for the installation..

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      Amazon EC2, digital ocean, etc

    • @Boolap1337
      @Boolap1337 Рік тому

      @@CyberAttackDefense How come you didnt go thru the setup for a VPS in this tutorial? Is a VPS needed, like Digital Ocean, or can I use my VM machine as a VPS?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@Boolap1337 I figured everyone could figure out their own choices on cloud vs local. A VPS isn’t required.

  • @Redearslider239
    @Redearslider239 Рік тому

    Great video sir. Sir my dns record get verified and CA certificate but atlast the binary file of evilgnix2 n gophish did not install. While installing binary it is giving me error please help me sir.

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому +1

      Check to make sure go installed. If it didn’t then you need to install it manually then go into each folder and run go build.

    • @waldep
      @waldep Рік тому

      @@CyberAttackDefense the same issue sir, even when i run "go build" inside each folder, the binary file does not get created, please help, Thanks for your knowledge sharing

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@waldep Hmm. I really don't know what could be happening. Maybe check this article out. www.digitalocean.com/community/tutorials/how-to-build-and-install-go-programs

    • @waldep
      @waldep Рік тому

      @@CyberAttackDefense The solution was to purge GoLang version "go1.20.1" (that comes by default with the server ) and re-install "go1.19.5"

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@waldep that’s not surprising. I ran into a bunch of issues with GO when I was building out this video setup.

  • @donaldschniers
    @donaldschniers Рік тому

    Hello sir, sendgrid is not allowing to sign up again, and do you have offer service to help in the installation in the Evilgophish sir? i dont mind paying for it, because am issues in the installation process sir.. anywhere i can contact you sir?

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      No sorry I don’t offer phishing infrastructure setup services right now. Sendgrid can be finicky. You can try many of the other services. Here is another evilginx2 setup guide www.optiv.com/insights/source-zero/blog/spear-phishing-modern-platforms

  • @harryharry-gz9nv
    @harryharry-gz9nv Рік тому

    It is necessary to build your own sMtp server

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      No sendgrid and other providers will send the mail for you.

    • @unoallin6389
      @unoallin6389 Рік тому

      ​@@CyberAttackDefense U cannot spoof emails with sendgrid. U need your own smtp server for that. Your tutorials don't make sense in regards to spoofing as you're sending emails from your own domain. So thats not spoofing

    • @CyberAttackDefense
      @CyberAttackDefense  Рік тому

      @@unoallin6389 I assure you the email sent comes from gophish through the sendgrid api. There isn’t an smtp server involved. I’m not spoofing anything just using a registered domain.

    • @avioz3135
      @avioz3135 Рік тому

      @@unoallin6389 You will need to add SPF record to allow Sendgrid to send email behalf of your domin.