Risk
8/19/2008
09:46 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Free Spear-Phishing Tool on Tap

Open source tool aimed at penetration testers lets them customize phishing attacks on their organizations

A researcher next month will unleash a new, free open-source tool for conducting targeted phishing attacks in-house.

Targeted phishing attacks, also known as spear-phishing, are increasingly becoming the hacker’s method of choice for infecting and/or infiltrating a specific organization. These attacks can be eerily convincing, often using identical message footers and IP addresses as those within an organization, and can easily dupe unsuspecting users into opening them and following their malicious links. Just last week, a spear-phishing attack on New Zealand-based University of Otago resulted in an estimated 1.55 million spams generated from the university’s server within 60 hours. (See Spear Phishing Attack Unleashes 1.5M Spam Messages.)

A recent report from iDefense Labs found that over 15,000 corporate victims in the past 15 months have been hit by spear phishing attacks.

The new Lunker phishing attack and audit tool is aimed at the penetration tester, so it comes with some advanced hacking features, and doesn’t use canned scenarios, but rather templates that can be customized. “Spear phishing is a huge risk. You’ve really got to start testing for this,” says Joshua Perrymon, who developed the Lunker tool. “You’ve got to start measuring the effectiveness of your [organization’s] security awareness and policies.”

Last month, boutique security firm Intrepidus Group rolled out a software-as-a-service offering called PhishMe that lets companies find the weakest links in their targeted phishing defense, as well as give their users a real-world taste of just what a spear-phishing attack looks and feels like. (See 'PhishMe' Tool Lets Businesses Spear-Phish Themselves.)

Lunker is aimed at the in-house hacker or outside researcher, Perrymon, CEO of PacketFocus, says. It includes an email reconnaissance feature that crawls the major search engines for corporate email accounts, but can also use lists provided by the would-be targeted organization. It also probes the target for weak links and suggests the most effective template for an attack, based on the emails and other analysis it has conducted on the target. And it comes with monitoring features that analyze the phished user’s actions in response to the phishing email.

“I decided to make this open source,” Perrymon says, so organizations can get see how easy these attacks can be done and to find ways to secure themselves. “There’s no reason for the bad guys” to only have that knowledge and ability, he says.

Perrymon will release the new spear-phishing tool next month at the OWASP Conference, where it will be bundled with the OWASP LiveCD, an application security testing set of tools. He’ll also provide a stand-alone version of Lunker sometime after that.

Another feature he hopes to add to Lunker is some user training features. “But the biggest need is for organizations to understand these attacks first, so the big push has been getting it to work for pen-testers,” Perrymon says. Lunker runs on PHP-based Web servers.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?