Live data from Hacker News

Show HN: Phishing as a service

cuttlephish.com

1–10 of 70 posts

Re: Show HN: Phishing as a service

#4
Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from your process.

Re: Show HN: Phishing as a service

#5
post #4

Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…

+1! This thing is awesome. And that would make it even more awesome.

Re: Show HN: Phishing as a service

#6
post #4

Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…

Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well.

One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.

Re: Show HN: Phishing as a service

#8
Neat! I really like the easy pricing model.

Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason.

Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming from "support@github.com". Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagged as spam.

[1] http://github.com/jordan-wright/gophish

Post reply on HN