User Tools

Site Tools


smishing

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Last revisionBoth sides next revision
smishing [2016/07/19 22:48] lucysmishing [2019/07/25 12:49] – external edit 127.0.0.1
Line 1: Line 1:
 +
 ====== Background Info ====== ====== Background Info ======
-Smishing (short for SMS Phishing) is a variant of phishing email scams that uses Short Message Service (SMS) systems to send out bogus text messages. Also written as SMiShing, SMS phishing made recent headlines when a vulnerability in the IPhone's SMS text messaging system was discovered that made smishing on the mobile device possible.+Smishing (short for SMS Phishing) is a variant of phishing email scams that uses Short Message Service (SMS) systems to send out bogus text messages. Also written as SMiShing, SMS phishing made recent headlines when a vulnerability in the iPhone's SMS text messaging system was discovered that made smishing on the mobile device possible.
  
 Smishing scams frequently seek to direct the text message recipient to visit a website or call a phone number. At which point, the person being scammed is enticed to provide sensitive information such as credit card details or passwords. Smishing websites are also known to attempt to infect the person's phone with Malware. Smishing scams frequently seek to direct the text message recipient to visit a website or call a phone number. At which point, the person being scammed is enticed to provide sensitive information such as credit card details or passwords. Smishing websites are also known to attempt to infect the person's phone with Malware.
 +
 +SMS phishing uses cell phone text messages to deliver the bait, persuading people to divulge their personal information. The "Hook" (method used to capture people's information) in the text message may be a website URL. LUCY offers the possibility to simulate such attacks. To create a smishing campaign is the same as creating a regular [[create_your_first_phishing_campaign|Phishing Campaign]]. The only difference is that within the message template (former e-mail template) you have to select SMS instead of email as a delivery method.
  
 ====== How is LUCY sending SMS? ====== ====== How is LUCY sending SMS? ======
  
 LUCY has a build in API which will connect to a centralized LUCY gateway when initializing SMS delivery. The gateway will first verify, if the LUCY client has sufficient credits and is allowed to send SMS. If all checks pass our gateway will connect to an international provider using a second API. This provider is able to send the messages with the settings defined in LUCY. LUCY has a build in API which will connect to a centralized LUCY gateway when initializing SMS delivery. The gateway will first verify, if the LUCY client has sufficient credits and is allowed to send SMS. If all checks pass our gateway will connect to an international provider using a second API. This provider is able to send the messages with the settings defined in LUCY.
 +
  
 ====== Requirements ====== ====== Requirements ======
Line 13: Line 17:
  
 a) commercial license and  a) commercial license and 
- 
 b) sufficient balance  b) sufficient balance 
  
  
-**Questions**+====== Q&As ======
  
   * Where can I see my current assets available for this feature?   * Where can I see my current assets available for this feature?
Line 23: Line 26:
 You can find your current credit under settings/licence: You can find your current credit under settings/licence:
  
-{{ lic.png?600 }}+{{:smishing_camp_1.png?600|}}
  
   * How do I add credits?   * How do I add credits?
  
-In LUCY < 2.9: You can simply send us a mail with the required balance. We will then update your balance. Payment can be done via credit card. 
  
-In LUCY > 2.9: You have a button next to the balance which enables you to buy more credits directly within the LUCY GUI.+ You have a button next to the balance which enables you to buy more credits directly within the LUCY GUI.
  
   * How many credits do I need?   * How many credits do I need?
  
-One sms usally costs between 3 and 9 cents. Here's the detailed pricing page (there is a selection for destination country): https://www.messagebird.com/en-us/pricing+One sms usually costs between 3 and 9 cents.
  
-  * How do I get a commercial licence?+  * How do I get a commercial license?
 After deciding which [[lucy_pricing|pricing model]] you need you can [[how_to_purchase_lucy|purchase]] and [[how_to_activate_lucy|activate]] lucy in order for this feature to work. After deciding which [[lucy_pricing|pricing model]] you need you can [[how_to_purchase_lucy|purchase]] and [[how_to_activate_lucy|activate]] lucy in order for this feature to work.
 +
 +
 ====== Setup ====== ====== Setup ======
-Within the scenario (Base Settings --> Scenario Settings --> Message Settings) you can use as a delivery method either "mail" or "sms". Choose "SMS". As a sender you can put a name or phone number (use always the phone number with the country code: example 49 xxx). The actual phone number should have no "00" and "+" in front, i.e. 41796959611 (41 - Switzerland country code) and not 0041796959611 or +41796959611. See https://en.wikipedia.org/wiki/List_of_country_calling_codes 
  
-{{ smishing_n.png?600 }}+A Smishing Campaign is not different from a [[create_your_first_phishing_campaign|regular phishing campaign]]. Most templates can be used in the same way. The difference is only the delivery method: within the scenario (Base Settings --> Scenario Settings --> Message Settings) you can use as a delivery method either "mail" or "sms". Choose "SMS". As a sender, you can put a name or phone number (use always the phone number with the country code: example 49 xxx). The actual phone number should have no "00" and "+" in front, i.e. 41796959611 (41 - Switzerland country code) and not 0041796959611 or +41796959611. See https://en.wikipedia.org/wiki/List_of_country_calling_codes 
 + 
 +{{:smishing_camp_2.png?600|}}
  
 If the phone number is saved in the recipient's contacts, it will show the corresponding contact information upon arrival of the SMS. If the phone number is saved in the recipient's contacts, it will show the corresponding contact information upon arrival of the SMS.
Line 49: Line 54:
  
 {{ smishing3.png?600 }} {{ smishing3.png?600 }}
 +
  
 ====== Automated URL Shortening ====== ====== Automated URL Shortening ======
  
 When you place the %link% variable within the message body and your scenario uses a public domain name, it will automatically be shortened. The link will look like "http://is.gd/9VjDKF” to fit into one text message. If you use an IP address for your landing page the link will be not shortened. When you place the %link% variable within the message body and your scenario uses a public domain name, it will automatically be shortened. The link will look like "http://is.gd/9VjDKF” to fit into one text message. If you use an IP address for your landing page the link will be not shortened.
 +
  
 ====== Known Issues ====== ====== Known Issues ======
-  * Issues when spoofing within same provider: Spoofing a message within same provider within the same country might not work. For example: if you want to send a spoofed message from a cell phone using “o2” to another cell phone using “o2” the message won't arrive. But if you send the same message from a phone using “telekom” to a cell phone using “o2” it will work 
-  * Issues with specific countries: in certain countries SMS spoofing will not work at all or SMS might only arrive if the sender is using a different country code. Example: in Belgium the SMS sender will get replaced by a general number like "8850" when using a different country code. 
  
 +  * Issues with specific countries: in certain countries, SMS spoofing will not work at all or SMS might only arrive if the sender is using a different country code. For example: in Belgium, the SMS sender will get replaced by a general number like "8850" when using a different country code.
 +  * **Issues with Delivery (sender):**This usually means, that your provider did not accept your senders ID. Try different variations to solve this. Example: if your sender number is 0041793531111 (where 0041 is the country code, 79 the prefix and 3531111 the phone number) you could try to send as +41793531111 or 0041793531111 or +41.793531111. If all variations do not work, please leave the sender field empty. Our message provider will then replace it with the default sender name. If the message gets successfully delivered with the default message, you can try to enter your own sender name (e.g. Jon Smith) instead of a phone number.
 +  * **Issues when spoofing with same provider**: Spoofing a message within same provider within the same country might not work. For example: if you want to send a spoofed message from a cell phone using “o2” to another cell phone using “o2” the message won't arrive. But if you send the same message from a phone using “telekom” to a cell phone using “o2” it will work
 +  * **No credit**: In order to use the Smishing feature you will need enough credits. To see your current balance go to the license page in LUCY.
 +  * **Issues with delivery (recipient number)**: sometimes the message is not delivered, because the phone number under the recipient is saved with the wrong format. Make sure recipients phone number always has the country code included.
 +  * **Issues with specific countries**: in certain countries SMS spoofing will not work at all or SMS might only arrive if the sender is using a different country code. Example: in Belgium the SMS sender will get replaced by a general number like “8850” when using a different country code.
 +  * **Delivery issues (content)**: Unfortunately some operators block links in SMS sometimes (for example, in Russia it's nearly impossible to send a link in SMS). You could try to remove http link or create a plain SMS without a link to test this feature.
  
 +For further info please check out the support section at: http://support.messagebird.com/hc/en-us
smishing.txt · Last modified: 2021/11/01 14:11 by lucysecurity