Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…
Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.
Show HN: Phishing as a service
21–30 of 70 posts
Re: Show HN: Phishing as a service
#22I don't like the click link = you lose idea.
Re: Show HN: Phishing as a service
#23the FAQ page is 10/10 https://cuttlephish.com/faq
The documentation's FAQ page asks:
"How much phish could a cuttlephish phish if a cuttlephish could phish phish?"
This is not accurate based on my own testing. This should actually read:
" "How much phish could a cuttlephish phish if a cuttlephish could phish phish phish?"
If you can correct this error, I would love to start using your service
Re: Show HN: Phishing as a service
#24Consider changing pricing to $/click (pay per victim), so that companies are paying for the value you provide (detection security holes), and the CTO can "bet" the CEO that employees need better training/protection. Much more upside for you.
The problem there is that the person/group conducting the test (presumably security team of a 500 person org) doesn't know if it will cost 500 x PerClickRate, or 5 x PerClickRate.. They don't yet know the stupidity of their users. Variable pricing like that can be a deal breaker for a small company.
Re: Show HN: Phishing as a service
#25I often intentionally click links to phishing sites, and sometimes enter in fake usernames and passwords. (I even wrote several bots to auto enter thousands of random usernames and passwords.) I don't like the click link = you lose idea.
Re: Show HN: Phishing as a service
#26How do you do email authentication? What are the headers that you put on your email?
Re: Show HN: Phishing as a service
#27Re: Show HN: Phishing as a service
#28Neat! I really like the easy pricing model. Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason. Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming fr…
Thanks, and very cool project! > Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL. > Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagg…
Re: Show HN: Phishing as a service
#29Earlier quoted context omitted.
The problem there is that the person/group conducting the test (presumably security team of a 500 person org) doesn't know if it will cost 500 x PerClickRate, or 5 x PerClickRate.. They don't yet know the stupidity of their users. Variable pricing like that can be a deal breaker for a small company.
You could address that by creating a control on the price. "I want to run this campaign against 500 users. But my budget is $100." The service sends out e-mails up to the $100 cost if they all clicked through, then deducts the actual expenses from the budget. In a few days, it sends the next batch of e-mails targeting the rest of the budget. Continue until either the e-mails are all sent, or the budget is expired.
Even reading your explanation, I'm not clear on what it will cost me -- this sounds more like pre-paying? how long should it wait between batches? how effective will batching be? Rumors of phishing/testing could move quick in the organisation making the report outcome misleading.
Re: Show HN: Phishing as a service
#30Neat! I really like the easy pricing model. Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason. Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming fr…
Thanks, and very cool project! > Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL. > Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagg…
The root of trademark law is preventing consumers from being confused or deceived about brand affiliations. I believe using a trademark to refer to the product/service symbolized by the mark is a protected case, so long as you are clear that no endorsement exists. Looking at your language, this is abundantly (and amusingly) clear.
You might have something to worry about with your insinuations about Dropbox though. I'm quite sure they are strongly pro-cephalopod.