Skip to content

Gophish v0.7.0

Compare
Choose a tag to compare
@jordan-wright jordan-wright released this 04 Sep 15:01
· 197 commits to master since this release

Gophish Just Got Better.

tl;dr - New version of Gophish. Lots of improvements. Binaries can be found above. πŸ˜„

We're excited to announce v0.7.0. This release is packed with improvements that make Gophish more powerful than ever.

Campaign Preview

When setting up a campaign, you want to know what the email and landing page looks like. Previously, to do this you would have to set up a separate campaign just for yourself, since there was no way of testing the full flow.

This isn't good.

In this Gophish release, we've fixed this! Now, when sending a test email from the campaign builder, clicking on the links will load up the landing page, showing you exactly what your recipients would see.

Timed Campaigns

Before this release, emails for a Gophish campaign were all sent at the same time. This is great in some cases, but sometimes you want to spread out the emails over a period of minutes, hours, or even days.

Now you can!

In this release, we've added a new field called "Send Emails By". If you set this field, then Gophish will spread out the emails evenly between the campaign launch and this date.

image

Device Details

No one likes looking through raw logs to see what kinds of devices are clicking on links. Now you don't have to!

In this release, we parse the user-agents for devices that click links or submit credentials, and we show that information in the campaign details:

image

Transparency

As mentioned in #1057, we can do a better job of running friendly phishing simulations. The only approved use of Gophish is to run authorized phishing simulations, so we've added some features to make these campaigns more transparent.

Specifically, we've added:

  • A contact_address field to the config.json. This field is inserted as an X-Gophish-Contact header in outgoing emails
  • An X-Mailer header is set to gophish for outgoing emails
  • We've added a transparency handler if you add a "+" to a valid rid. This returns a JSON response containing the contact address and indicates that the email was generated by Gophish

Those are the big features, but that's certainly not everything! You can find a full changelog here.

How to Upgrade

To upgrade, simply download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new gophish binary and you'll be good to go!

Thank You

I want to also take a quick moment to say thank you to everyone. The community is what makes Gophish great. I'm so thankful to everyone who leaves questions, suggests features, and goes the extra mile to help others out.

Thank you all for everything you do!

Now, one more thing:

We want to hear from you!

Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.

Enjoy!

SHA1 Hash Filename
63149165688d3ca989974e32b5716be7e87ed6b4 gophish-v0.7.0-linux-32bit.zip
f113435940626c3f13448ce8e12aafb3e347c504 gophish-v0.7.0-linux-64bit.zip
45736f416e475541ac214611f41c40fb967167dd gophish-v0.7.0-osx-32bit.zip
d9b3ac3a2cf11f53bd33196d0310167ffb43cd8a gophish-v0.7.0-osx-64bit.zip
98ad9756fa95d43af99b12f8d08423f71dc7fc14 gophish-v0.7.0-windows-32bit.zip
f069cc4f4c9c50e422923f205c34eb226a2ea550 gophish-v0.7.0-windows-64bit.zip

Old hashes (only valid if you downloaded the release immediately after it was published before I got a chance to bump the VERSION file):

SHA1 Hash Filename
dfddc8a8038fa612022bb22e823e2a51b343e261 gophish-v0.7.0-linux-32bit.zip
261efd81c727021dfa039fe081ff7941cd86f9ee gophish-v0.7.0-linux-64bit.zip
5ca9e90bc8c6ed0494ddb29deb907548859c5ab0 gophish-v0.7.0-osx-32bit.zip
c0ffcc5f06799c807b79c3b41cefa6785c853dd8 gophish-v0.7.0-osx-64bit.zip
fd12ebc44c964e8577f688405f6c01d470335d9f gophish-v0.7.0-windows-32bit.zip
8000eec9d77a3d6987aa57b7d61736717238c471 gophish-v0.7.0-windows-64bit.zip