Automated deployment for GoPhish - Ansible playbook + one-shot install script.
gophish-auto installs dependencies, sanitizes/neutralizes identifiable headers for evasion, builds GoPhish in-place on the target host, and deploys it as a persistent systemd service.
Intended for lab, research and authorized red-team use only. Do not use against targets without permission.
- Installs required packages
- Removes/sanitizes HTTP headers and metadata to reduce fingerprinting.
- Clones GoPhish and builds the binary on the target host.
- Creates and enables a
systemdservice so GoPhish runs persistently and restarts on failure.
- Control node (for Ansible): Linux, Ansible >= 2.9 (optional if you use local installer).
- Target host: Linux x86_64 (Ubuntu/Debian/CentOS tested).
- SSH + sudo/root access for remote deploys OR run
gophish-deploy.shas root locally. - Internet access to download Go and GoPhish repo (unless you vendor the source).
Make the script executable and run it as root:
chmod +x gophish-deploy.sh
sudo ./gophish-deploy.shAfter the installation completes, the installer prints a summary similar to this:
==========================================
=== Installation Complete ===
==========================================
✓ Evasive Gophish installed to: /opt/39b3090a516f/
✓ Service name: sys-39b3090a516f
✓ Binary name: service_monitor
✓ Service status: active
✓ Credentials saved to: /root/gophish_credentials.txt
=== Admin Credentials ===
Username: admin
Password: 900c7cddd119adfc
Admin Panel: https://127.0.0.1:3333
Phishing Server: http://0.0.0.0:80
=== Modified Headers ===
✓ X-Gophish-Contact -> X-Contact-Address
✓ X-Gophish-Signature -> X-Sender-Signature
✓ ServerName -> IGNORE
Quick commands:
cat /root/gophish_credentials.txt # View credentials
systemctl status sys-39b3090a516f # Check status
journalctl -u sys-39b3090a516f -f # View logs
⚠️ CHANGE DEFAULT PASSWORD after first login!
Important: Change the autogenerated admin password after the first login.
ansible-playbook -i ansible/example.hosts ansible/deploy-gophish.yml
Edit ansible/example.hosts with your inventory first.
After the playbook runs, per-host output will be available on the control node in:
/tmp/ansible_results/<hostname>.out
- Default admin listen address: 127.0.0.1:3333 (adjustable)
- Phishing server default: 0.0.0.0:80
Check service:
sudo systemctl status gophish
sudo journalctl -u gophish -f
- Generate
config.jsonfrom templates (admin user, ports, TLS settings) - Optional TLS: Let's Encrypt (Certbot) or self-signed cert creation
- Custom 404 Page
- Secure local port forwarding to Internet (easy access)