Live data from Hacker News

Show HN: Phishing as a service

cuttlephish.com

21–30 of 70 posts

Re: Show HN: Phishing as a service

#21
post #4

Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…

Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.

One option that might do something to ensure trust would be to have the javascript on the page that accepts the credentials be unminified and readable.

Re: Show HN: Phishing as a service

#22
I often intentionally click links to phishing sites, and sometimes enter in fake usernames and passwords. (I even wrote several bots to auto enter thousands of random usernames and passwords.)

I don't like the click link = you lose idea.

Re: Show HN: Phishing as a service

#23

the FAQ page is 10/10 https://cuttlephish.com/faq

I noticed a serious issue with the documentation. I'm not able to go any farther until this is corrected...

The documentation's FAQ page asks:

"How much phish could a cuttlephish phish if a cuttlephish could phish phish?"

This is not accurate based on my own testing. This should actually read:

" "How much phish could a cuttlephish phish if a cuttlephish could phish phish phish?"

If you can correct this error, I would love to start using your service

Re: Show HN: Phishing as a service

#24
post #20

Consider changing pricing to $/click (pay per victim), so that companies are paying for the value you provide (detection security holes), and the CTO can "bet" the CEO that employees need better training/protection. Much more upside for you.

The problem there is that the person/group conducting the test (presumably security team of a 500 person org) doesn't know if it will cost 500 x PerClickRate, or 5 x PerClickRate.. They don't yet know the stupidity of their users. Variable pricing like that can be a deal breaker for a small company.

You could address that by creating a control on the price. "I want to run this campaign against 500 users. But my budget is $100." The service sends out e-mails up to the $100 cost if they all clicked through, then deducts the actual expenses from the budget. In a few days, it sends the next batch of e-mails targeting the rest of the budget. Continue until either the e-mails are all sent, or the budget is expired.

Re: Show HN: Phishing as a service

#25
post #22

I often intentionally click links to phishing sites, and sometimes enter in fake usernames and passwords. (I even wrote several bots to auto enter thousands of random usernames and passwords.) I don't like the click link = you lose idea.

Sometimes phishing links may be tracked, and if you click on one of them, you may be added into a list of "potentially highly vulnerable targets" and therefore receive more of such emails in the future.

Re: Show HN: Phishing as a service

#26
This is a useful service. But I imagine there will be some nontrivial issues regarding spam filtering, server reputation, legal, etc.

How do you do email authentication? What are the headers that you put on your email?

Re: Show HN: Phishing as a service

#28
post #8

Neat! I really like the easy pricing model. Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason. Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming fr…

Thanks, and very cool project! > Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL. > Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagg…

Might be worth reaching out to the relevant companies once you reach a certain size, as they presumably will patch any holes in their spf records that you bring to their attention.

Re: Show HN: Phishing as a service

#29
post #20

Earlier quoted context omitted.

The problem there is that the person/group conducting the test (presumably security team of a 500 person org) doesn't know if it will cost 500 x PerClickRate, or 5 x PerClickRate.. They don't yet know the stupidity of their users. Variable pricing like that can be a deal breaker for a small company.

You could address that by creating a control on the price. "I want to run this campaign against 500 users. But my budget is $100." The service sends out e-mails up to the $100 cost if they all clicked through, then deducts the actual expenses from the budget. In a few days, it sends the next batch of e-mails targeting the rest of the budget. Continue until either the e-mails are all sent, or the budget is expired.

I suspect explaining that pricing model is a sales risk. flat fee or price per contact is far more intuitive I suspect.

Even reading your explanation, I'm not clear on what it will cost me -- this sounds more like pre-paying? how long should it wait between batches? how effective will batching be? Rumors of phishing/testing could move quick in the organisation making the report outcome misleading.

Re: Show HN: Phishing as a service

#30
post #8

Neat! I really like the easy pricing model. Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason. Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming fr…

Thanks, and very cool project! > Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? I'm honestly not 100% sure, but I think in the context of a phishing site using trademarks like that falls under fair use. But IANAL. > Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagg…

IANAL. I took a seminar freshman year on IP law.

The root of trademark law is preventing consumers from being confused or deceived about brand affiliations. I believe using a trademark to refer to the product/service symbolized by the mark is a protected case, so long as you are clear that no endorsement exists. Looking at your language, this is abundantly (and amusingly) clear.

You might have something to worry about with your insinuations about Dropbox though. I'm quite sure they are strongly pro-cephalopod.

Post reply on HN