How to Spoof 97% of Email Accounts

แชร์
ฝัง
  • เผยแพร่เมื่อ 16 พ.ค. 2024
  • The video is a recording of a streaming session where I demonstrated some of the offensive/testing tools my team built at 6point6.
    The first is mail-spoofer, it "circumvents" legitimate SPF, DKIM and ARC records. Additionally, it can forge fake - signed - DMARC passes through ARC abuse.
    The hope is to force a much wider adoption of DMARC as a security technology. And to encourage better email security standards - in my opinion, they're awful.
    If you would like to:
    - Spoof email accounts - github.com/6point6/mail-spoofer
    - Find vulnerable domains/review our findings - github.com/6point6/dmarc_checker
    - Shout add me/discuss the research - / discord
    - Add me on LinkedIn - / chris-cyber-researcher
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 82

  • @jedbooth8239
    @jedbooth8239 ปีที่แล้ว

    I got this to work pretty quickly! Thank you so much! One issue that I ran into was that I need to also spoof the IP address that I'm sending from because the SPF record is set to a certain IP range. Gmail allows the mail to go through, but my organization catches the mail and it does not get delivered. I was thinking about using scapy to try and write a python program, but it isn't working. Do you have any solution for this?

  • @Cookiekeks
    @Cookiekeks 2 ปีที่แล้ว

    Really nice presentation, thank you

  • @matthewferguson6697
    @matthewferguson6697 2 ปีที่แล้ว +1

    Great work! Shared it on

  • @papajohnscookie
    @papajohnscookie ปีที่แล้ว +1

    This was great, really informative and interesting.

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      Did this work for you? I’m getting an error message when trying to send a test email

  • @user-xw9tn8zx1g
    @user-xw9tn8zx1g 2 ปีที่แล้ว +2

    Hey man thank you so much! This was super informative both in the explanation at the beginning and in the demo at the end. I learned a lot and can't thank you enough!! As I was following along with the demo when it finally came to sending the test email, all the connections timed out and nothing was sent. Everything up to then was setup perfectly, my cloudflare was automatically completed with the DNS entries, and I could access the gophish portal perfectly. Just wondering if you know of any fix to this problem or if you have any ideas? Once again thank you for the great work and great lecture!!

    • @s7davidj
      @s7davidj 2 ปีที่แล้ว

      41:43

    • @martinaddison4880
      @martinaddison4880 ปีที่แล้ว +1

      yes...all these cats say "it's EASY to spoof these emails" but like you said...it is NOT. And it does not matter how smart some cat is.

    • @BHax0r
      @BHax0r 5 หลายเดือนก่อน

      Fixed it yet ?

    • @BHax0r
      @BHax0r 5 หลายเดือนก่อน

      That is not he reason its keeps crashing @@s7davidj

  • @jak10987
    @jak10987 2 ปีที่แล้ว +6

    Thank you for the informational video, this was incredibly valuable!

  • @Tchatarero36
    @Tchatarero36 10 หลายเดือนก่อน

    Great Content Chris

  • @unoallin6389
    @unoallin6389 11 หลายเดือนก่อน

    How does mimecast & proofpoint handle spoof emails. Will the emails get through to the inbox?

  • @r188ops8
    @r188ops8 ปีที่แล้ว

    Hi, so basically to protect my domain, all I need to do is add p=reject into my DMARC? Shoul I add sp=reject too or is that not necessary? Thanks, gained a subscriber :-)

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      We’re you able to send an email?

  • @girl4632
    @girl4632 3 หลายเดือนก่อน +1

    Hey, which is better.
    Sending email using self written normal python script or using gophish.

  • @jeffdelancey9346
    @jeffdelancey9346 ปีที่แล้ว

    Digital ocean blocks port 25. Any solution for this

  • @harryhodgson7988
    @harryhodgson7988 2 ปีที่แล้ว

    Also using Mac OS how do I get mail spoofer to my server the scp code doesn’t seem to work

  • @raifaniath-thaariq7983
    @raifaniath-thaariq7983 10 หลายเดือนก่อน

    where can i get the mail-spoofer tmp?

  • @marqueemoon276
    @marqueemoon276 ปีที่แล้ว

    I’m trying to send a test email but after a while getting an error that says “Max connection attempts exceeded - EOF” anyone know why?

  • @T8USD
    @T8USD 2 ปีที่แล้ว

    If I get my domain and do everything what you did. Hypothetically speaking, if I am to forge from scratch or just copy x company's mail content to make it look like it's theirs, when it's not. Will it then immediately be recognized by gmail for example and sent to spam.
    I.e. Facebook's logo inside the mail

    • @chrispowell1224
      @chrispowell1224  2 ปีที่แล้ว

      No, we did some testing and found our emails always go through. Provided the IP reputation isn't terrible, even with malicious emails.

    • @T8USD
      @T8USD 2 ปีที่แล้ว

      @@chrispowell1224 Thank you for answer. And what happens when user marks the email as spam. Does that lower the reputation

  • @neilmcrae624
    @neilmcrae624 ปีที่แล้ว

    Does this still work? I think I have rebuild on digital ocean about 10 times now... Still no sent email

  • @cyphercoda4575
    @cyphercoda4575 2 ปีที่แล้ว

    sorry, just a noob here! when you pushed all your files to the digital ocean, it means you setup gophish in your machine in docker first then you pushed that or you just pushed the mail-spoofer file to the digital ocean?

    • @chrispowell1224
      @chrispowell1224  2 ปีที่แล้ว

      Everything was on digital ocean

    • @cyphercoda4575
      @cyphercoda4575 2 ปีที่แล้ว

      @@chrispowell1224 Dude did you just again delete the comment? lol please don't delete the comments i have download your mail-spoofer and i think after few enhancements it can do the job. its a pretty awesome tool without a doubt. but still we can improve this. and Sendgrid API wont work because of their new auth features. To bypass this thing we can use AWS SES or some bulletproof SMTP server. This may be fix the problem and emails will start landing in the inbox of O365 and bypass Gsuites, Please let me know if i am wrong.

    • @chrispowell1224
      @chrispowell1224  2 ปีที่แล้ว

      @@cyphercoda4575 I've never delete any comments. If you want to improve on mail spoofer, issue a PR.

  • @nyshone
    @nyshone 2 ปีที่แล้ว

    Do you know how could I possibly resolve postfix timing out? It shows email sent, but the ubuntu says postfix keeps timing out and no email is received.

    • @theodoredapaah712
      @theodoredapaah712 2 ปีที่แล้ว

      Your port 25 isp is been blocked my your provider

  • @user-gu7ft2st2w
    @user-gu7ft2st2w ปีที่แล้ว

    Hi
    thanks for sharing such an important information
    As you said your team worked on spoofed emails. I need help from you as I am doing project on spoofed email detection using ML. I cant find a data for spoofed emails to train my model . if you have spoofed email dataset can you share it with me, I can explain my project to you. thank you.

  • @muhammedmustaphaabdullahi1029
    @muhammedmustaphaabdullahi1029 2 ปีที่แล้ว

    You just left someone hanging if you know you wont help you shouldn’t have built this wonderful application you made me changed my project in school i choose the email marketing as my project defense , its just a waste of time when you can’t help

  • @iamturkishcoffee
    @iamturkishcoffee 14 วันที่ผ่านมา

    THANK YOU

  • @jamestrevor2149
    @jamestrevor2149 ปีที่แล้ว

    hello, i keep getting an error when trying to send a test mail "Max connection attempts exceeded - dial tcp: lookup postfix25: Temporary failure in name resolution"....any solution?

    • @Pranks101
      @Pranks101 ปีที่แล้ว

      Your port 25 isp is been blocked my your provider : Comment Copied From Theodore Dapaah

  • @axelnuno6673
    @axelnuno6673 ปีที่แล้ว

    Hello Powell, just a question, I made authentication with a password not with a ssh key, what is the command to install mail-spoofing on digital ocean becuase "scp -r .\Deskptop\mail-spoofer\ spoof:/tmp" doesn't work to me, I hope you can answer me :) (min 46:36 of the video)

  • @thomaslium5382
    @thomaslium5382 6 หลายเดือนก่อน

    This is nice, but can you reply to the emails after sending it? it seems it will only be sent once, but cant actually have a conversation in email

  • @sleekbr7666
    @sleekbr7666 2 ปีที่แล้ว

    Where did Chris post the tool that summarized the entire exercise?

  • @motazsa1
    @motazsa1 4 หลายเดือนก่อน

    Amazing 👏🏼

  • @axoz9116
    @axoz9116 2 ปีที่แล้ว +3

    how did you end up getting a domain from go daddy? and is there any free alternatives if possible?

    • @olmi7953
      @olmi7953 2 ปีที่แล้ว

      With a free domain there is a 100% chance your email will be blocked

    • @olmi7953
      @olmi7953 2 ปีที่แล้ว

      But yeah freenom offers free domains

    • @axoz9116
      @axoz9116 2 ปีที่แล้ว

      @@olmi7953 so there's none

  • @lifediggerdev318
    @lifediggerdev318 2 ปีที่แล้ว

    Lol I had a look at the Collage I am currently studying at and found they don't even have a DMARC record.

  • @dannyocean6579
    @dannyocean6579 ปีที่แล้ว

    My mails not inboxing non of them how is that possible?

  • @sufianiskandar3586
    @sufianiskandar3586 2 หลายเดือนก่อน

    I did all the steps above and managed to spoof the emails but all landed in junk folder flagged as spam.

  • @morningweb8538
    @morningweb8538 2 ปีที่แล้ว

    hi chris did gmail updated their filters i tried to forge dmark with your setup but i get A fail !

    • @whoiam7447
      @whoiam7447 2 ปีที่แล้ว

      yes gmail fixed that

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      So this doesn’t work anymore?

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      @@whoiam7447 so this doesn’t work anymore?

  • @adriankatong3962
    @adriankatong3962 ปีที่แล้ว

    This is a holy grail if my African friend found this video!! this is kinda out of the topic of the awareness its more to from small spammer become guru of the email spoofer BUT!! this is must people know about it so they know how degerous is the Phishing don't always belive what you seeing and don't ever click on what you see on your email its 95% security patch 5% human error this kinda of human error that never can be patched! SALUTE FOR THE VIDEO!

  • @notvalid4061
    @notvalid4061 ปีที่แล้ว +1

    still works took many hours of trail and error but is legit

    • @Tinetikon
      @Tinetikon ปีที่แล้ว

      hey i saw your recent post. i have difficulty with setting things up can you help me? i bought domain and try to create server with hmailserver but didnt work as expected. If you down to get in contact with me i will leave my email. pls respond

  • @jhanjones5695
    @jhanjones5695 ปีที่แล้ว

    What are your thoughts on dmarc?

  • @harryhodgson7988
    @harryhodgson7988 2 ปีที่แล้ว

    What does it mean when it shows fo=1 ?

  • @muhammedmustaphaabdullahi1029
    @muhammedmustaphaabdullahi1029 2 ปีที่แล้ว

    Can you please answer my question Chris, my landing page does not display even viewing page source doesn’t show

  • @dannyocean6579
    @dannyocean6579 ปีที่แล้ว +1

    How do i boost my reputation?

    • @OMGPainRipper
      @OMGPainRipper 6 หลายเดือนก่อน +1

      How did you solve this?

  • @harryhodgson7988
    @harryhodgson7988 2 ปีที่แล้ว

    Does this only work on Linux ?

  • @dandeeteeyem2170
    @dandeeteeyem2170 7 หลายเดือนก่อน

    You know this exact vulnerability has been available for mobile phone numbers as long as it has for email? 😂
    I love how sincere you sound when saying you don't know why this vulnerability exists 😂
    By the way, if you think number 10, or the cia leave this low hanging fruit misconfigured by mistake, you are very naive 😅

    • @chrispowell1224
      @chrispowell1224  7 หลายเดือนก่อน +1

      I was an intelligence officer most of my career. It 100% was misconfiguration.
      You think too highly of the CIA.

    • @dandeeteeyem2170
      @dandeeteeyem2170 7 หลายเดือนก่อน

      @@chrispowell1224 you can still spoof calls, there's no good reason for that vulnerability to still be there. 😉

  • @didyouknowamazingfacts2790
    @didyouknowamazingfacts2790 ปีที่แล้ว

    is this illegal!!!

  • @richardclifford9641
    @richardclifford9641 ปีที่แล้ว

    Video too long

  • @theodoredapaah712
    @theodoredapaah712 2 ปีที่แล้ว

    Why is it that when I put the sendgrid Api key in your tool it don’t work the mails are sent through the smtp port 25 ?

    • @sleekbr7666
      @sleekbr7666 2 ปีที่แล้ว

      Where's the link to the tool?

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      Did you get this to work?

  • @ellenorscheffers3185
    @ellenorscheffers3185 2 ปีที่แล้ว +1

    Please I’ll like to speak to you personally. Maybe you could find a way to contact me, thanks and I hope you consider my plea

  • @DelkorYT
    @DelkorYT ปีที่แล้ว +1

    cia.gov has a p=none and rua setup now 😂

  • @daviddaniel4844
    @daviddaniel4844 ปีที่แล้ว +1

    Digital ocean blocks port 25 🥲🥲🥲.
    Is there any way we can use any other port

    • @marqueemoon276
      @marqueemoon276 ปีที่แล้ว

      Did you figure out a fix?

    • @OMGPainRipper
      @OMGPainRipper 6 หลายเดือนก่อน

      @@marqueemoon276Did you figure out a fix?