{"repo":"ColumPaget/pam_honeycreds","free":true,"listed":false,"github":"https://github.com/ColumPaget/pam_honeycreds","clone":"git clone https://github.com/ColumPaget/pam_honeycreds.git","description":"A pam module to send warnings when certain 'fake' passwords are used to login","language":"C","stars":15,"topics":["c","pam","authentication"],"license":"GPL-3.0","category":"auth-billing-email","readme_excerpt":"PAM HONEYCREDS This is a simple PAM (Pluggable Authentication Modules) that watches for certain passwords being used. A list of passwords can be stored either in cleartext or as a list of salted sha256 hashes. It can also log passwords that do not match any list, but will not log passwords that are in a list, instead reporting them by file and line. In addition to logging events, a script can be run. Uses of this PAM module are: 1) 'Honey credentials'. Fake passwords are made available where they might be found by intruders. If they are ever used it may indicate a network compromise, and in this event pam honeycreds can be set up to notify the network administrator. Given that people frequently forget/mistype their passwords, a simple 'failed login' alert will cause a lot of noise, and will eventually be ignored by the sysadmin. An actual match against a list of prohibited passwords should be a clearer signal. Alternatively one can simply watch for passwords from any of the 'common passwords' lists that are available on the internet, in order to detect bruteforce attempts happening within your network. 2) Watching for passwords appearing in brute-force attempts against web-facing servers. Anyone with internet-facing ssh, web or SMTP servers has seen bruteforce password-guessing attempts that run through a dictionary of stolen passwords. pam honeycreds can be used to watch for your own passwords appearing in this list, either indicating that your password databases have been s","default_branch":null,"files":null,"tree":[],"storefront":"/r/ColumPaget","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ColumPaget/pam_honeycreds/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}