OSCP Phishing Guide
This is a guide for the OSCP & other CTF's that may include phishing as part of the exam.
Last updated
This is a guide for the OSCP & other CTF's that may include phishing as part of the exam.
Last updated
In this page we will conduct a phishing attack that goes as follows:
We open a WebDAV server on our Kali host, we create a malicious Microsoft Office Macro that we will send to the organization through a compromised Mail server. Once the victim clicks on the malicious macro it will open a reverse shell back to our Kali attack host.
Next we'll create a malicious Windows Library file that we'll use to hold our reverse shell.
Once we've created the Windows Library we transfer the Lirbary file and powercat.ps1 script to the WebDAV server.
In the beginning of this page we mentioned that we have access to a compromised mail server, there are various tools we can use to leverage SMTP. We will use swaks
After some time we can check back on our netcat listener and see that we successfully phished a victim.