Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ SniperPhish - The Web-Email Spear Phishing Toolkit

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š SniperPhish - The Web-Email Spear Phishing Toolkit


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: feedproxy.google.com


SniperPhish is a phishing toolkit for pentester or security professionals to enhance user awareness by simulating real-world phishing attacks. SniperPhish helps to combine both phishing emails and phishing websites you created to centrally track user actions. The tool is designed in a view of performing professional phishing exercise and would be reminded to take prior permission from the targeted organization to avoid legal implications.


Installation
  1. Download the source code and put it in your web root folder
  2. Open http://localhost/install in your browser and follow the steps for installation
  3. After installation, open http://localhost/spear to login

Default login - Username: admin Password: sniperphish


Main Features
  • Web tracker code generation - track your website visits and form submissions independently
  • Create and schedule Phishing mail campaigns
  • Combine your phishing site with email campaign for centrally tracking
  • An independent "Simple Tracker" module for quick tracking an email or web page visit
  • Advance report generation - generate reports based on the tracking data you needed
  • Custom tracker images and dynamic QR codes in messages
  • Track phishing message replies

Screenshots




Creating Web-Email Campaign

We create web tracker -> Add the web tracker to the phishing website -> create mail campaign with a link pointing to the phishing website -> start mail campaign.


Creating a web tracker:
  1. Design your website in your favorite programming language. Make sure you provided unique "id" and "name" value for HTML fields such as text field, checkbox etc.
  2. Generate web-tracker code Web Tracker -> New Tracker. The "Web Pages" tab list the pages you want to track
    • To track form submission data, provide the "id" or "name" values of HTML fields present in your phishing site form.
    • Repeat above for each page in your phishing site.
  3. From the final output, copy the generated JavaScript link and add it under the section of each website page.
  4. Finally, save the tracker created. Now the tracker is activated and listening in the background. Opening your phishing site or data submission is tracked.

Creating an Email campaign:
  1. Go to Email Campaign -> User Group and add target users
  2. Go to Email Campaign -> Sender List and configure Mail server details
  3. Go to Email Campaign -> Email Template and create mail template. When you add your phishing website link, make sure to append ?cid={{CID}} at the end. This is to distinguish each users. For example, http://yourphishingsite.com/login?cid={{CID}}
  4. Now go to Email Campaign -> Campaign List -> New Mail Campaign and select/fill the fields to create campaign.
  5. Start Mail campaign

Viewing combined Web-Email Result

Open Web-MailCamp Dashboard -> Select Campaign and select Mail Campaign and Web Tracker you created.



More

SniperPhish honors contributions of

Joseph Nygil (@j_nygil) and Sreehari Haridas (@sr33h4ri)



...



๐Ÿ“Œ SniperPhish: An all-in-one open-source phishing toolkit


๐Ÿ“ˆ 52.34 Punkte

๐Ÿ“Œ Spear Phishing: A Highly Targeted Phishing Attempt


๐Ÿ“ˆ 27.89 Punkte

๐Ÿ“Œ Fishy Business: What Are Spear Phishing, Whaling and Barrel Phishing?


๐Ÿ“ˆ 27.89 Punkte

๐Ÿ“Œ Spear Phishing vs Phishing: What Are The Main Differences?


๐Ÿ“ˆ 27.89 Punkte

๐Ÿ“Œ Difference between Whale Phishing and Spear Phishing


๐Ÿ“ˆ 27.89 Punkte

๐Ÿ“Œ Spear-Phishing-Attacken kosten Unternehmen Millionen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Nuclear Regulatory Commission Employee Pleads Guilty to Spear Phishing (February 2, 3, and 4, 2016)


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Amazon Users Targets of Massive Locky Spear-Phishing Campaign


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Wie man Pseudo-Hacker austrickst: Spear-Phishing-Mails: Jetzt wird zurรผckgeschlagen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing: Angriffsziel Industrie und Ingenieurswesen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Simple eBay security flaw exposed millions of users to spear phishing campaigns


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing: Deutsche Politiker mit Malware-Mails angegriffen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing: Deutsche Politiker mit Malware-Mails angegriffen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing Incident Causes Havoc at San Francisco Exploratorium Museum


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Simple eBay security flaw exposed millions of users to spear phishing campaigns


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing-Attacken kosten Unternehmen Millionen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Nuclear Regulatory Commission Employee Pleads Guilty to Spear Phishing (February 2, 3, and 4, 2016)


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Amazon Users Targets of Massive Locky Spear-Phishing Campaign


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Wie man Pseudo-Hacker austrickst: Spear-Phishing-Mails: Jetzt wird zurรผckgeschlagen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing: Angriffsziel Industrie und Ingenieurswesen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing: Deutsche Politiker mit Malware-Mails angegriffen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing: Deutsche Politiker mit Malware-Mails angegriffen


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing Incident Causes Havoc at San Francisco Exploratorium Museum


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Beware the latest tax-season spear-phishing scam


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing Attack Installs Two PowerShell Backdoors on Victimsโ€™ Machines


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing Attacks Increasingly Focused: Report


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing Attacks


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear Phishing Campaign Targets Palestinian Law Enforcement


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing: BSI warnt vor gezielten Cyberangriffen auf Politik und Wirtschaft


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing: BSI warnt vor gezielten Cyberangriffen auf Politik und Wirtschaft


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ GreatHorn Secures $6.3 Million to Combat Spear-Phishing Attacks


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Konzepte gegen Spear-Phishing


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Berkeley boffins build better spear-phishing black-box brusier


๐Ÿ“ˆ 21.52 Punkte

๐Ÿ“Œ Spear-Phishing und CEO-Fraud: In der Praxis versagen die meisten Mail-Security-Systeme


๐Ÿ“ˆ 21.52 Punkte











matomo