求在Django中创建伪管理员登录蜜罐页面的可行方案
Hey there, let's get your Django admin honeypot set up properly for Django 2+. I've got two solutions lined up exactly as you asked—one quick and minimal, another using an adapted version of django-admin-honeypot.
Solution 1: Quick Fake Admin Page (No IP Logging)
This is a lightweight approach if you just need to mimic the admin login page without tracking attempts. It's perfect for quickly securing your real admin behind a non-standard URL.
Step 1: Create a Fake Login View
In one of your Django apps (e.g., core/views.py), add this simple view to render a fake admin login form:
from django.shortcuts import render from django.contrib.admin.forms import AuthenticationForm def fake_admin_login(request): # Use Django's built-in admin auth form to match the real look form = AuthenticationForm(request, data=request.POST or None) if request.method == 'POST': # Pretend validation failed to keep the ruse going form.add_error(None, "Please enter the correct username and password") return render(request, 'fake_admin/login.html', {'form': form})
Step 2: Copy the Admin Login Template
Grab Django's default admin login template (you can find it in django/contrib/admin/templates/admin/login.html) and paste it into your project's templates/fake_admin/login.html. You can leave it as-is, or tweak minor details if you want (though keeping it identical works best for deception).
Step 3: Configure URLs
Update your project's urls.py to route the default /admin/ to your fake view, and hide the real admin behind a custom, non-obvious URL:
from django.contrib import admin from core.views import fake_admin_login # Adjust the import path to your view urlpatterns = [ # Honeypot: Fake admin page at the standard /admin/ path path('admin/', fake_admin_login, name='fake_admin'), # Real admin: Use a unique, hard-to-guess URL path('secure-admin-9876/', admin.site.urls, name='real_admin'), ]
That's it—attackers hitting /admin/ will see a familiar login form, but no valid credentials will work, and your real admin is safely hidden.
Solution 2: Adapted django-admin-honeypot for Django 2+
If you want the full honeypot functionality (including optional logging of login attempts), we can use a maintained fork of django-admin-honeypot that supports Django 2+.
Step 1: Install the Compatible Version
Use pip to install the Django 2.x-compatible branch:
pip install git+https://github.com/dmpayton/django-admin-honeypot.git@django-2.x
Step 2: Update Settings.py
Add admin_honeypot to your installed apps (make sure it comes before django.contrib.admin so URL routing works correctly):
INSTALLED_APPS = [ 'admin_honeypot', # Place this above django.contrib.admin 'django.contrib.admin', # Your other apps... ] # Optional: Disable logging if you don't need it # By default, the app logs attempts to the 'admin_honeypot' logger. If you don't want logs, skip the logging config below. LOGGING = { 'version': 1, 'disable_existing_loggers': False, 'handlers': { 'honeypot_log': { 'level': 'INFO', 'class': 'logging.FileHandler', 'filename': '/var/log/django/admin_honeypot.log', # Choose your log path }, }, 'loggers': { 'admin_honeypot': { 'handlers': ['honeypot_log'], 'level': 'INFO', 'propagate': True, }, }, }
Step 3: Configure URLs
Set up your URLs to route /admin/ to the honeypot, and the real admin to your secret URL:
from django.contrib import admin from admin_honeypot import views as honeypot_views urlpatterns = [ # Honeypot at standard /admin/ path('admin/', honeypot_views.admin_honeypot, name='admin_honeypot'), # Real admin at your custom URL path('my-super-secret-admin-123/', admin.site.urls, name='real_admin'), ]
This setup will log all login attempts (IP, username, password used) if you enabled logging, while keeping your real admin page hidden from automated scanners.
内容的提问来源于stack exchange,提问作者keybald

