Launching a phishing attack

There are prerequisites that need to be set up in Gophish before launching the phishing campaign. These can be broadly divided into four important things to do before launching a successful campaign:

  • Profiles: A profile is the place where you will have all the SMTP details and sender details; Gophish allows attackers to have multiple profiles defined, along with custom email headers.
  • Users and groups: Upload single or bulk targeted victims email IDs with their first and last names. Gophish allows testers to create groups and import them in CSV format.

Once the templates, landing pages, users, and sending profiles are set, we are now set to launch the campaign, as shown in the following screenshot. Attackers can also set the date and time of phishing and set the group of target victims. Gophish also provides an option to test an email to see whether it was blocked or delivered straight to the target's inbox:

Once the campaign is successfully launched, pen testers can now monitor the entire campaign in full detail, as shown in the following screenshot:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.23.101.60