LUCY might initiate certain communication channels to servers on the internet:
Important: Lucy version >= 5.0 will require access to update1.phishing-server.com The IP address is dynamic, please create an allow rule for the Domain name.
IP | Function | Port | Protocol |
---|---|---|---|
162.55.130.83 (update.phishing-server.com) update1.phishing-server.com (Dynamic IP) | Lucy Update/License Server/HTTP proxy | 80/443 (HTTP/HTTPS) | TCP |
162.55.130.83 (update.phishing-server.com) 18.185.209.112, 3.120.90.173 (update1.phishing-server.com) | Linux repository | 80 (HTTP) | TCP |
8.8.8.8 (or any other DNS Server) | Your DNS Server | 53 (DNS) | UDP |
nvd.nist.gov | NIST CVE database (Optional) | 443 (HTTPS) | TCP |
0.0.0.0 (Any) | Mail Communication (Optional) | 25 (SMTP) | TCP |
116.203.185.12 (changelog.lucysecurity.com) | Fetch LUCY Update News (Optional) | 80 (HTTP) | TCP |
is.gd | URL Shortening service (Optional) | 443 (HTTPS) | TCP |
api-ssl.bitly.com | URL Shortening service (Optional) | 443 (HTTPS) | TCP |
api.authy.com | Two-factor authentication service (Optional) | 443 (HTTPS) | TCP |
In order to reach LUCY from the internet port 80 and 443 (if you use SSL in a campaign) needs to be open. No other ports are required. If LUCY should forward mails from users that respond to a phishing simulation port 25 (SMTP) needs to be opened as well.
Source IP | Destination | Port | Prot | Comment |
---|---|---|---|---|
ANY | Your LUCY Server IP | 80/443 (HTTP/HTTPS) | TCP | Needed for accessing the landing pages & for certificate verification (http) |
ANY | Your LUCY Server IP | 25 (SMTP) | TCP | Only needed, if you want to catch email replies |
ANY | Your LUCY Server IP | 5001 (HTTPS) | TCP | Only needed, if you use Adapt authoring tool. Should be turned off if Adapt is not used (taking additional resources) |
Upon execution, the malware simulation tool will open the built in Internet Explorer or other default browser (in hidden mode) and send out the collected data to LUCY via HTTP or HTTPS (it will automatically choose HTTPS if you run your campaign via SSL). This tool will also work in environments where the Internet is accessed with Proxy servers - only allowing access for authorized Windows users.