FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more. The features will continue to be expanded and will include website spoofing, click tracking, and extensive notification options.
Note: As of 1/6/2017, FirePhish has been renamed FiercePhish. Screenshots may still show FirePhish logo
Click here to go to the Wiki Pages
This project is my own and is not a representation of my employer’s views. It is my own side project and released by me alone.
More screenshots are available in the “Features” wiki pages
For more information (like a manual installation method), see the wiki pages
This is the preferred method of installing FiercePhish + SMTP + IMAP services.
(Fresh installs are expected, but the installer should work on a used OS with no problems)
(Ubuntu 14.04 support has been removed. To install FiercePhish on 14.04, read these instructions)
If you would like a different OS distribution supported, create a Github issue
This isn’t required, but it is heavily suggested. Phishing campaigns where you spoof an active domain you don’t own are extremely susceptible to being spam filtered (unless the domain’s SPF record is improperly configured). The best way to perform a phishing campaign is by buying a generic domain that can fool someone (“yourfilehost.com”) or a domain that is very similar to a real domain (“microsoft-secure.com”).
This method is probably the easiest way to install/configure everything. It is a fully unattended installation (aside from the beginning).
sudo su
curl https://raw.githubusercontent.com/Raikia/FiercePhish/master/install.sh | bash
Click here for a detailed description of the configuration variables
curl https://raw.githubusercontent.com/Raikia/FiercePhish/master/install.sh | bash
Sit and wait. The installation could take anywhere from 5-15 minutes depending on your server’s download speed.
Once the installation completes, follow the instructions it prints out. It will tell you what DNS entries to set.
This method is just as easy as method #1, but the install will prompt you as it runs for the information it requires (as opposed to using a configuration file like method #1).
sudo su
wget https://raw.githubusercontent.com/Raikia/FiercePhish/master/install.sh
chmod +x install.sh
./install.sh
The installer will prompt you for the same information as is described in the configuration file for method #1. See that wiki page for information on what to provide.
Sit and wait. The installation could take anywhere from 5-15 minutes depending on your server’s download speed.
Once the installation completes, follow the instructions it prints out. It will tell you what DNS entries to set.
As of FiercePhish v1.2.0, an update script is included. Versions prior to 1.2.0 are not compatible with 1.2.0 and later, so you’ll have to do a fresh install (or read the wiki).
To update FiercePhish, simply run:
sudo ./update.sh
If you have errors with the installation script, you can safely rerun the script without messing anything up (even if you provide it different information). If you continue to have problems, set “VERBOSE=true” (for method #1) or run ./install.sh -v
(for method #2) to see the full log of everything running. If you still have problems, submit a bug report.