django-admin-honeypot

A fake Django admin login screen to notify admins of attempted unauthorized access.


Keywords
django, admin, honeypot, trap, python
License
MIT
Install
pip install django-admin-honeypot==1.1.0

Documentation

django-admin-honeypot

Travis-CI Coverage Code Climate

django-admin-honeypot is a fake Django admin login screen to log and notify admins of attempted unauthorized access. This app was inspired by discussion in and around Paul McMillan's security talk at DjangoCon 2011.

Documentation

http://django-admin-honeypot.readthedocs.io

tl;dr

  • Install django-admin-honeypot from PyPI:

    pip install django-admin-honeypot
    
  • Add admin_honeypot to INSTALLED_APPS

  • Update your urls.py:

    urlpatterns = patterns(''
        ...
        url(r'^admin/', include('admin_honeypot.urls', namespace='admin_honeypot')),
        url(r'^secret/', include(admin.site.urls)),
    )
    
  • Run python manage.py migrate

NOTE: replace secret in the url above with your own secret url prefix