{"repo":"dvershinin/nginx-honeypot","free":true,"listed":false,"github":"https://github.com/dvershinin/nginx-honeypot","clone":"git clone https://github.com/dvershinin/nginx-honeypot.git","description":"NGINX honeypot with lots of honey","language":"Shell","stars":12,"topics":["nginx","bots","firewall","honeypot","ipset","rhel","security"],"license":"MIT","category":"security-tools","readme_excerpt":"nginx-honeypot NGINX honeypot with lots of honey for \"flies\". [!IMPORTANT] This repository builds upon the popular article NGINX honeypot – the easiest and fastest way to block bots! and is compatible with the RHEL-based distributions. What is honey? The unwanted requests which are no good for a well-maintained LEMP stack website. You don't host phpMyAdmin or other junk on your server. All these requests come from bots, not from you, and allow early detection and very proactive blocking in order to reduce server load and logs noise. Honey is at honeypot/honey.conf . Install From the GetPageSpeed repository (RPM) On RHEL / CentOS / AlmaLinux / Rocky / Amazon Linux: The package is config-only - it depends on nothing but nginx . It drops the honey list and NGINX snippets into /etc/nginx/honeypot/ and also ships the optional ban tooling, which stays dormant unless you opt into the free fcgiwrap path below. Manual Copy the honeypot directory to /etc/nginx/honeypot . For the free ban path, also install libexec/block-ip.cgi and sbin/block-ip.sh (mode 0755). Wiring (detection only) Out of the box the honeypot just detects bot-bait requests and returns 410 Gone - pure NGINX config, no firewall, no extra packages. Auto-load the honey map: In each server {} block: That's it. Bots probing /wp-includes/... , /.env , phpMyAdmin and friends get a 410, and your logs and app stay quiet. Optional: ban the offending IP To go beyond detection and ban the source IP, include ONE of the ban variant","default_branch":null,"files":null,"tree":[],"storefront":"/r/dvershinin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dvershinin/nginx-honeypot/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}