Skip to content

Latest commit

 

History

8 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

gophish-auto v0.1

Automated deployment for GoPhish - Ansible playbook + one-shot install script.

gophish-auto installs dependencies, sanitizes/neutralizes identifiable headers for evasion, builds GoPhish in-place on the target host, and deploys it as a persistent systemd service.

Intended for lab, research and authorized red-team use only. Do not use against targets without permission.


What it does

  • Installs required packages
  • Removes/sanitizes HTTP headers and metadata to reduce fingerprinting.
  • Clones GoPhish and builds the binary on the target host.
  • Creates and enables a systemd service so GoPhish runs persistently and restarts on failure.

Requirements

  • Control node (for Ansible): Linux, Ansible >= 2.9 (optional if you use local installer).
  • Target host: Linux x86_64 (Ubuntu/Debian/CentOS tested).
  • SSH + sudo/root access for remote deploys OR run gophish-deploy.sh as root locally.
  • Internet access to download Go and GoPhish repo (unless you vendor the source).

Quick start

Local bootstrap

Make the script executable and run it as root:

chmod +x gophish-deploy.sh
sudo ./gophish-deploy.sh

After the installation completes, the installer prints a summary similar to this:

==========================================
=== Installation Complete ===
==========================================

✓ Evasive Gophish installed to: /opt/39b3090a516f/
✓ Service name: sys-39b3090a516f
✓ Binary name: service_monitor
✓ Service status: active
✓ Credentials saved to: /root/gophish_credentials.txt

=== Admin Credentials ===
Username: admin
Password: 900c7cddd119adfc

Admin Panel: https://127.0.0.1:3333
Phishing Server: http://0.0.0.0:80

=== Modified Headers ===
  ✓ X-Gophish-Contact -> X-Contact-Address
  ✓ X-Gophish-Signature -> X-Sender-Signature
  ✓ ServerName -> IGNORE

Quick commands:
  cat /root/gophish_credentials.txt    # View credentials
  systemctl status sys-39b3090a516f    # Check status
  journalctl -u sys-39b3090a516f -f    # View logs

⚠️  CHANGE DEFAULT PASSWORD after first login!

Important: Change the autogenerated admin password after the first login.

Remote deploy via Ansible

ansible-playbook -i ansible/example.hosts ansible/deploy-gophish.yml

Edit ansible/example.hosts with your inventory first.

After the playbook runs, per-host output will be available on the control node in:

/tmp/ansible_results/<hostname>.out

Default service & access

  • Default admin listen address: 127.0.0.1:3333 (adjustable)
  • Phishing server default: 0.0.0.0:80

Check service:

sudo systemctl status gophish
sudo journalctl -u gophish -f

TODO

  • Generate config.json from templates (admin user, ports, TLS settings)
  • Optional TLS: Let's Encrypt (Certbot) or self-signed cert creation
  • Custom 404 Page
  • Secure local port forwarding to Internet (easy access)

References

About

GoPhish autodeployment

Resources

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages