Live data from Hacker News

Show HN: Phishing as a service

cuttlephish.com

41–50 of 70 posts

Re: Show HN: Phishing as a service

#41
There are many sites like this and I love what they are doing for raising awareness. As one of the first people to ever fight phishing (I worked at eBay and PayPal fighting phishing before there was a word for it), I'm keenly aware that awareness is the only way to really stop it.

That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see what it does, so it would count me as a victim. Since the page you go to isn't a real looking login page, you can't differentiate between those who fall for it and those who just clicked to see what it was.

You need to actually set up the fake page and see who puts in valid credentials to get a true report.

Re: Show HN: Phishing as a service

#42

Earlier quoted context omitted.

One option that might do something to ensure trust would be to have the javascript on the page that accepts the credentials be unminified and readable.

Or provide a self-hosting option; JavaScript can be changed at any moment. Request A might look fine, but request B for the same file 5 minutes later could be malicious.

I think that'd be the best way to go. Or, half-way between hosted and self-hosted: in exchange for payment, provide a button that lets them launch a CuttlePhish instance on Heroku. (I'm not sure if this can be automated to the point that regular non-developers would understand it, though.)

Re: Show HN: Phishing as a service

#43
post #4

Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…

Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.

Do something like Google's new authentication process - rather than asking for the username and password on a single page, ask for the username only with a "continue logging in" button. There's no need to actually ask for a password.

Re: Show HN: Phishing as a service

#44
post #4

Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…

Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.

I think you are completely correct in your second sentence there - there's no way I'd use this if there was any chance of my colleagues actually disclosing real credentials to a third party.

(Suspicious me is wondering if you're evil - 'cause if evil-me was in your position, I'd be selectively showing your "you've been phished, ha ha!" landing page to most people, but mining LinkedIn/Rapportive/Google for key contacts at any domains that sign up, and displaying genuinely evil credential-collecting-login pages if I got a hit from senior sysadmins or a CTO/CIO/CSO...)

Re: Show HN: Phishing as a service

#45
post #41

There are many sites like this and I love what they are doing for raising awareness. As one of the first people to ever fight phishing (I worked at eBay and PayPal fighting phishing before there was a word for it), I'm keenly aware that awareness is the only way to really stop it. That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see wha…

But i guess that you are in the small, small minority of false positives

Re: Show HN: Phishing as a service

#46
post #41

There are many sites like this and I love what they are doing for raising awareness. As one of the first people to ever fight phishing (I worked at eBay and PayPal fighting phishing before there was a word for it), I'm keenly aware that awareness is the only way to really stop it. That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see wha…

But i guess that you are in the small, small minority of false positives

Most people won't think twice about the link in the email. They'll usually stop at the login screen because it doesn't look right, has a wrong URL, etc. Having done a lot of work in this area I can tell you that I'm definitely not in the minority.

Clicking the link from a secure VM sure puts me in the minority, but just clicking the link? Lots of people do that and then get suspicious.

That's why you need two steps to truly know how bad it is.

Re: Show HN: Phishing as a service

#47
post #44

Earlier quoted context omitted.

Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.

I think you are completely correct in your second sentence there - there's no way I'd use this if there was any chance of my colleagues actually disclosing real credentials to a third party. (Suspicious me is wondering if you're evil - 'cause if evil-me was in your position, I'd be selectively showing your "you've been phished, ha ha!" landing page to most people, but mining LinkedIn/Rapportive/Google for key contact…

The phishing page could be set up to have a fake form that sends no data, and says "you've been phished" when someone tries to submit information to it.

At that level, though, the pen-tester really ought to have control over the phishing landing page.

Re: Show HN: Phishing as a service

#48
post #41

There are many sites like this and I love what they are doing for raising awareness. As one of the first people to ever fight phishing (I worked at eBay and PayPal fighting phishing before there was a word for it), I'm keenly aware that awareness is the only way to really stop it. That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see wha…

Not to dismiss your experience (perhaps you had not heard the term yet) but the term 'phishing' has been around longer (mid 90s at least) than ebay and paypal have been big enough to be phishing targets.

Re: Show HN: Phishing as a service

#49
post #41

There are many sites like this and I love what they are doing for raising awareness. As one of the first people to ever fight phishing (I worked at eBay and PayPal fighting phishing before there was a word for it), I'm keenly aware that awareness is the only way to really stop it. That being said, I don't like these reports, because any time I get a phishing email I immediately load it up in a protected VM to see wha…

Not to dismiss your experience (perhaps you had not heard the term yet) but the term 'phishing' has been around longer (mid 90s at least) than ebay and paypal have been big enough to be phishing targets.

I was deeply involved in the fledgling anti-spam industry in the early 2000s, by way of the anti-virus industry, and it was not a common term then. Wikipedia gives the first recorded use as '95, and that refers to it as "fishing", and as being AOL-specific.

Re: Show HN: Phishing as a service

#50
post #34

Hm. I often click on obviously phishing links to see what's there. Would this tool classify me as a victim?

Me too. I often intentionally click on phishing links to see how well the page is done and where it's hosted.

OP should probably consider adding login pages etc (discarding the credentials) to actually find people who would fall for it, as someone here suggested. Many people click the links just out of curiosity.

Post reply on HN