Live data from Hacker News

Show HN: Phishing as a service

cuttlephish.com

11–20 of 70 posts

Re: Show HN: Phishing as a service

#11
How do you send your emails ?

If your customer is using google domains, microsoft 365 or what else, and the employees do not fall in your phishing attempt and report your mail as spam, you may be heading for some trouble with delivery afterward.

Re: Show HN: Phishing as a service

#12
post #8

Neat! I really like the easy pricing model. Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason. Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming fr…

Thanks, and very cool project!

> Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates?

I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL.

> Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagged as spam.

I don't know much about spf records, honestly--for every site I had to try multiple "From" and "Reply-To" addresses to get the emails past gmail's spam filter. Some of them didn't even arrive in my spam folder, (apparently they just got killed on some intermediate hop). support@github.com definitely works, at least for me--you should try it yourself and see how it goes.

Hope this helps!

Re: Show HN: Phishing as a service

#14

How do you send your emails ? If your customer is using google domains, microsoft 365 or what else, and the employees do not fall in your phishing attempt and report your mail as spam, you may be heading for some trouble with delivery afterward.

I'm sending the emails directly from my server with the unix "mail" utility.

Ending up in spam is actually what most concerns me about this idea, and in fact this concern was what led me to choose the "you don't pay unless someone clicks on a link" pricing--I was worried that some of the emails might eventually start ending up in spam after a few customers and wanted to make sure I wouldn't be charging people if that happened.

I'm planning to see what works once/if the phishing emails actually start ending up in spam.

Re: Show HN: Phishing as a service

#18
Consider changing pricing to $/click (pay per victim), so that companies are paying for the value you provide (detection security holes), and the CTO can "bet" the CEO that employees need better training/protection.

Much more upside for you.

Re: Show HN: Phishing as a service

#20

Consider changing pricing to $/click (pay per victim), so that companies are paying for the value you provide (detection security holes), and the CTO can "bet" the CEO that employees need better training/protection. Much more upside for you.

The problem there is that the person/group conducting the test (presumably security team of a 500 person org) doesn't know if it will cost 500 x PerClickRate, or 5 x PerClickRate.. They don't yet know the stupidity of their users. Variable pricing like that can be a deal breaker for a small company.
Post reply on HN