PackageTrack
Sign in Get early access

github.com/gophish/gophish

v0.12.1 #279 most downloaded on Go modules gophish/gophish

What this package is like to depend on

Last release 2 years ago

no release in 18 months

Ships unpredictably

gaps range from 9 days to 12 months

Most releases are documented

notes for 9 of 15 stable releases

Nothing withdrawn

no release was ever pulled

13 years old

814 releases · first in 2013

0 releases in the last 12 months

see the full history below

Release timeline

814 releases · Nov 2013 to Sep 2024
2014 2016 2018 2020 2022 2024 2026
Release Pre-release

Releases

latest 60 of 814
  1. v0.12.2-0.20240923042443-956184697992 23 Sep 2024 pre-release

    Nothing published for this version

  2. v0.12.2-0.20230915144530-8e7929441393 15 Sep 2023 pre-release

    Nothing published for this version

  3. v0.12.2-0.20221216170455-d2efb18ef1e3 16 Dec 2022 pre-release

    Nothing published for this version

  4. v0.12.2-0.20221013151637-cec2da512890 13 Oct 2022 pre-release

    Nothing published for this version

  5. v0.12.2-0.20220929122131-095a9ba20c41 29 Sep 2022 pre-release

    Nothing published for this version

  6. v0.12.1 14 Sep 2022
    Release notes

    Gophish just got better.

    We're excited to announce the release of Gophish v0.12.1. This is a minor release that includes a couple of bug fixes and one great new feature.

    Added Trusted Origins to CSRF Handler

    We've added the ability to set trusted_origins in the config.json file. This allows you to add addresses that you expect incoming connections to come from, which is helpful in cases where TLS termination is handled by a load balancer upstream, rather than the application itself. This has been a long discussed and requested feature so it's great to have! Thanks to @mcab and everyone else in this thread.

    Updated Workflows

    Our Continuous Integration workflow has been updated and is succeeding again. We've also updated the Release workflow, mitigating some security concerns and adapting it be able to build Windows releases again. These are (hopefully!) at the bottom of this post.

    Minor fixes

    Some JavaScript files hadn't been minified properly, causing problems with adding customer headers. A small bug was fixed where copying a campaign would not show [Deleted] in an edge case - see #2482. Thanks @29vivek.

    Changelog

    You can find the full changelog for this release here.

    How to Upgrade

    To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!

    Now, one more thing:

    We want to hear from you!

    Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.

    Enjoy

    SHA256 Hash Filename
    9ed2f88d6582b798a3448fb51080ff782b40cec8fb4855895720e9f782f68511 gophish-v0.12.1-linux-32bit.zip
    44f598c1eeb72c3b08fa73d57049022d96cea2872283b87a73d21af78a2c6d47 gophish-v0.12.1-linux-64bit.zip
    f80786dcb2c4037d7f9d6c9e8e8655c5eeaa8e46ef4032bda704b9ce18e23491 gophish-v0.12.1-osx-64bit.zip
    e6936b8a472c730dcb0da64024d82341806869af666fad10f8639e7f85b1b7e6 gophish-v0.12.1-windows-64bit.zip
    Open source →
    Release notes

    Gophish v0.12.1 Latest

    Latest

    Compare

    Choose a tag to compare

    Open source →
  7. v0.12.1-0.20220912210534-a53665b1b6e9 12 Sep 2022 pre-release

    Nothing published for this version

  8. v0.12.1-0.20220906142019-78e9a5116845 06 Sep 2022 pre-release

    Nothing published for this version

  9. v0.12.1-0.20220826210914-3863ad31b9e3 26 Aug 2022 pre-release

    Nothing published for this version

  10. v0.12.1-0.20220825132854-34f745729492 25 Aug 2022 pre-release

    Nothing published for this version

  11. v0.12.1-0.20220824160000-32c050299940 24 Aug 2022 pre-release

    Nothing published for this version

  12. v0.12.0 12 Aug 2022
    Release notes

    Gophish just got better.

    We're excited to announce the release of Gophish v0.12.0. This release includes important security fixes, adds some features, and fixes some bugs.

    Attachment Tracking

    This has been a long time requested feature, and we're super excited to release it! We've added the ability to add gophish variables to a number of file types which can be attached to emails. As a trivial example it is possible to include Hello {{.FirstName}}, please click here: {{.URL}} to a Word document, or with a little more effort add tracking pixels to documents. This will allow notification of when users have opened attached files, or enabled macros in Office documents. We currently support the following file extensions: docx, docm, pptx, xlsx, xlsm, txt, html, ics. Please see the documentation for more guidance and examples.

    Inline Image Attachments #1525

    Images in emails are now marked as embedded rather than attached, so email clients don't show them as attachments. This is a great addition to improve the quality of campaigns. Thanks @dzsibi

    Custom Sender Envelopes #2334

    We've added the ability to specify an envelope sender in templates. If left empty, it will fallback to the SMTP-From in the Sender-settings. This can be used to pass SPF-checks but still send a spoofing email. Thanks @ChessSpider and @ptitdoc

    Added functionality to lock accounts #2060

    Added minor functionality to display last login time for each user in the User Management page and the ability to lock user accounts.

    Open Redirect #2262

    Fixed a minor Open Redirect issue. Thanks @Kirill89

    Changelog

    You can find the full changelog for this release here.

    How to Upgrade

    To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!

    Now, one more thing:

    We want to hear from you!

    Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.

    Enjoy

    SHA256 Hash Filename
    42f228158e91e2fce182fbd60a6669fcbed21f76186563f264a941efbc9c1159 gophish-v0.12.0-linux-64bit.zip
    d06945497f0f3467748c50e518aa4e526e8c71cd7fa58c23541cb65477539306 gophish-v0.12.0-osx-64bit.zip
    c0fdc4a980914893a9d19544bb6233586db8d81a139657e9773ca8e03c387a02 gophish-v0.12.0-windows-64bit.zip
    Open source →
    Release notes

    Gophish v0.12.0

    Compare

    Choose a tag to compare

    Open source →
  13. v0.11.1-0.20220812193143-6b61426aabc2 12 Aug 2022 pre-release

    Nothing published for this version

  14. v0.11.1-0.20220809142429-90cd444dcb04 09 Aug 2022 pre-release

    Nothing published for this version

  15. v0.11.1-0.20220611102556-5ef2d75e72a0 11 Jun 2022 pre-release

    Nothing published for this version

  16. v0.11.1-0.20220605201832-6fb77bf3ceee 05 Jun 2022 pre-release

    Nothing published for this version

  17. v0.11.1-0.20220601160155-d0ff3829e588 01 Jun 2022 pre-release

    Nothing published for this version

  18. v0.11.1-0.20220601154004-0c255bbe92fd 01 Jun 2022 pre-release

    Nothing published for this version

  19. v0.11.1-0.20220601151422-b7c69662ced6 01 Jun 2022 pre-release

    Nothing published for this version

  20. v0.11.1-0.20220415142819-704e6d56b328 15 Apr 2022 pre-release

    Nothing published for this version

  21. v0.11.1-0.20220325152449-bb516ef7aba4 25 Mar 2022 pre-release

    Nothing published for this version

  22. v0.11.1-0.20220225121019-e0acb99734b2 25 Feb 2022 pre-release

    Nothing published for this version

  23. v0.11.1-0.20220217140351-eb016a437cf6 17 Feb 2022 pre-release

    Nothing published for this version

  24. v0.11.1-0.20220216162651-67e304f3724e 16 Feb 2022 pre-release

    Nothing published for this version

  25. v0.11.1-0.20220216154630-e215132bdfc4 16 Feb 2022 pre-release

    Nothing published for this version

  26. v0.11.1-0.20220216153038-741201b7f09a 16 Feb 2022 pre-release

    Nothing published for this version

  27. v0.11.1-0.20220207161255-1f95efcb7b0b 07 Feb 2022 pre-release

    Nothing published for this version

  28. v0.11.1-0.20220202144127-a6627dfc6b1d 02 Feb 2022 pre-release

    Nothing published for this version

  29. v0.11.1-0.20211223181343-0646f14c9904 23 Dec 2021 pre-release

    Nothing published for this version

  30. v0.11.1-0.20211218084934-ceab0509eba7 18 Dec 2021 pre-release

    Nothing published for this version

  31. v0.11.1-0.20211218084920-202ecd339741 18 Dec 2021 pre-release

    Nothing published for this version

  32. v0.11.1-0.20211218084911-4b106b3fe209 18 Dec 2021 pre-release

    Nothing published for this version

  33. v0.11.1-0.20211218084850-1d18ea7e013d 18 Dec 2021 pre-release

    Nothing published for this version

  34. v0.11.1-0.20211218084841-b3f0bad5cef0 18 Dec 2021 pre-release

    Nothing published for this version

  35. v0.11.1-0.20211218084833-12ecfd84cc0c 18 Dec 2021 pre-release

    Nothing published for this version

  36. v0.11.1-0.20211218084800-4814620cdce2 18 Dec 2021 pre-release

    Nothing published for this version

  37. v0.11.1-0.20210901040010-003d1436418c 01 Sep 2021 pre-release

    Nothing published for this version

  38. v0.11.1-0.20210810234211-f89c85f5585d 10 Aug 2021 pre-release

    Nothing published for this version

  39. v0.11.1-0.20210525073327-5aa3a858cb63 25 May 2021 pre-release

    Nothing published for this version

  40. v0.11.1-0.20210510070801-82fd6adf68b8 10 May 2021 pre-release

    Nothing published for this version

  41. v0.11.1-0.20210508150326-5fc6ba6beff4 08 May 2021 pre-release

    Nothing published for this version

  42. v0.11.1-0.20210429185225-a5b3b134bacc 29 Apr 2021 pre-release

    Nothing published for this version

  43. v0.11.1-0.20210330153951-f72206501801 30 Mar 2021 pre-release

    Nothing published for this version

  44. v0.11.1-0.20210328204031-db63ee978dcd 28 Mar 2021 pre-release

    Nothing published for this version

  45. v0.11.1-0.20210328203841-96d1a5555861 28 Mar 2021 pre-release

    Nothing published for this version

  46. v0.11.1-0.20210306174042-54d9eb28ff3c 06 Mar 2021 pre-release

    Nothing published for this version

  47. v0.11.1-0.20210224233438-15303e32cfc9 24 Feb 2021 pre-release

    Nothing published for this version

  48. v0.11.1-0.20210124200140-166ff8a05039 24 Jan 2021 pre-release

    Nothing published for this version

  49. v0.11.1-0.20210124194410-e6533e9993e4 24 Jan 2021 pre-release

    Nothing published for this version

  50. v0.11.1-0.20201211132428-9f5368aa13f4 11 Dec 2020 pre-release

    Nothing published for this version

  51. v0.11.1-0.20201207145605-ced52616787f 07 Dec 2020 pre-release

    Nothing published for this version

  52. v0.11.1-0.20201015013532-8b8e88b07739 15 Oct 2020 pre-release

    Nothing published for this version

  53. v0.11.1-0.20201011224937-120e232cfed6 11 Oct 2020 pre-release

    Nothing published for this version

  54. v0.11.1-0.20201011221833-23154126de98 11 Oct 2020 pre-release

    Nothing published for this version

  55. v0.11.1-0.20201011185942-af3122f93bad 11 Oct 2020 pre-release

    Nothing published for this version

  56. v0.11.1-0.20201001030015-3c490dbadbe6 01 Oct 2020 pre-release

    Nothing published for this version

  57. v0.11.1-0.20201001020608-b53cff0c9822 01 Oct 2020 pre-release

    Nothing published for this version

  58. v0.11.1-0.20200924021519-c1d3c7cd7583 24 Sep 2020 pre-release

    Nothing published for this version

  59. v0.11.1-0.20200924014021-0b2ab68f8db4 24 Sep 2020 pre-release

    Nothing published for this version

  60. v0.11.0 28 Aug 2020
    Release notes

    Gophish just got better.

    We're excited to announce the release of Gophish v0.11.0. This release includes important security fixes, adds some minor features, and fixes some bugs.

    Security Fixes

    This release addresses multiple security issues that were identified and reported by the community. As always, we encourage sending in security reports via our security policy, and are appreciative of all the work that went in to finding and reporting these vulnerabilities.

    The following vulnerabilities were fixed in this latest release:

    Server-side Request Forgery (SSRF)

    Reported by: Marcus Nilsson of usd AG
    Reported by: @dunderhay in #1908

    An authenticated user could use certain features of Gophish to make inbound connections to the local network. The most critical of these is via the Landing Page import feature, which could be used to make arbitrary upstream web requests.

    Since importing local webpages, or otherwise making local network connections (e.g. for SMTP/IMAP servers, webhook URLs, etc.) is an expected use case for Gophish we've decided to implement an opt-in allowlist. By default, we block access only to known IP addresses commonly associated with cloud metadata services, but it is now possible to explicitly set the allowed_internal_hosts configuration variable in the admin_server section of config.json to a list of allowed internal addresses.

    More information can be found here.

    Cross-Site Scripting (XSS)

    Reported By: Marcus Nilsson of usd AG
    Reported By: @dunderhay in #1901

    Various cross-site scripting issues were identified and fixed. All issues required authenticated access and only affected either the user that created the objects, or an administrator using our "Impersonate" issue to impersonate the user that created the objects.

    More information can be found in 4e9b94b and 19ef924.

    CSV Injection

    Reported By: Marcus Nilsson of usd AG

    Malicious data could be submitted during a campaign that, when exported as a CSV and opened in a spreadsheet viewer, is interpreted as a formula leading to command execution.

    More information on CSV Injection can be found here. More information about the fix can be found in b25f5ac.

    Clickjacking

    Reported By: Marcus Nilsson of usd AG

    An attacker could create an iframe which tricks an authenticated administrator into unexpectedly clicking the "Reset" button in the settings page, causing their API key to be reset, potentially causing a denial of service condition.

    More information about the fix can be found in 6df62e8.

    Adding a Password Policy

    This release adds a basic password policy for administrators, and removes the default password "gophish". Instead, an initial password is randomly generated and printed in the terminal when Gophish is launched for the first time.

    It is possible to override the initial password and API key with environment variables if needed.

    More Robust IMAP Support

    This release adds the ability to mark emails as reported that were sent as an attachment. Additionally, it changes the underlying IMAP library to be more robust, eliminating some possible bugs.

    Credit to @glennzw for the changes!

    Changelog

    You can find the full changelog for this release here.

    How to Upgrade

    To upgrade, download the release for your platform, extract into a folder, and copy (remember to copy, not move so that you have a backup) your existing gophish.db file into the new directory. Then, run the new Gophish binary and you'll be good to go!

    Now, one more thing:

    We want to hear from you!

    Have questions, comments, or feature ideas about Gophish? Let us know by filing an issue.

    Enjoy

    SHA256 Hash Filename
    beb32e243e888f21849d3ee09a979a33cd1da7a7cd79438c8f56fce1a2d9d44c gophish-v0.11.0-linux-32bit.zip
    f33ac7695850132c04d190f83ef54732421a8d4578be1475d3a819fe6173c462 gophish-v0.11.0-linux-64bit.zip
    f1af96033c946ed2fe757b9b3a7aefc63ec3548f0ab21f01c44d70a58410ffbe gophish-v0.11.0-osx-64bit.zip
    f5083bc084715319a4e671bc58dc28f66828fec78a43bd41456373fcc024703c gophish-v0.11.0-windows-64bit.zip
    Open source →
    Release notes

    Gophish v0.11.0

    Compare

    Choose a tag to compare

    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive