You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求在Django中创建伪管理员登录蜜罐页面的可行方案

Solutions for Django 2+ Admin Honeypot & Secure Admin URL

Hey there, let's get your Django admin honeypot set up properly for Django 2+. I've got two solutions lined up exactly as you asked—one quick and minimal, another using an adapted version of django-admin-honeypot.


Solution 1: Quick Fake Admin Page (No IP Logging)

This is a lightweight approach if you just need to mimic the admin login page without tracking attempts. It's perfect for quickly securing your real admin behind a non-standard URL.

Step 1: Create a Fake Login View

In one of your Django apps (e.g., core/views.py), add this simple view to render a fake admin login form:

from django.shortcuts import render
from django.contrib.admin.forms import AuthenticationForm

def fake_admin_login(request):
    # Use Django's built-in admin auth form to match the real look
    form = AuthenticationForm(request, data=request.POST or None)
    
    if request.method == 'POST':
        # Pretend validation failed to keep the ruse going
        form.add_error(None, "Please enter the correct username and password")
    
    return render(request, 'fake_admin/login.html', {'form': form})

Step 2: Copy the Admin Login Template

Grab Django's default admin login template (you can find it in django/contrib/admin/templates/admin/login.html) and paste it into your project's templates/fake_admin/login.html. You can leave it as-is, or tweak minor details if you want (though keeping it identical works best for deception).

Step 3: Configure URLs

Update your project's urls.py to route the default /admin/ to your fake view, and hide the real admin behind a custom, non-obvious URL:

from django.contrib import admin
from core.views import fake_admin_login  # Adjust the import path to your view

urlpatterns = [
    # Honeypot: Fake admin page at the standard /admin/ path
    path('admin/', fake_admin_login, name='fake_admin'),
    # Real admin: Use a unique, hard-to-guess URL
    path('secure-admin-9876/', admin.site.urls, name='real_admin'),
]

That's it—attackers hitting /admin/ will see a familiar login form, but no valid credentials will work, and your real admin is safely hidden.


Solution 2: Adapted django-admin-honeypot for Django 2+

If you want the full honeypot functionality (including optional logging of login attempts), we can use a maintained fork of django-admin-honeypot that supports Django 2+.

Step 1: Install the Compatible Version

Use pip to install the Django 2.x-compatible branch:

pip install git+https://github.com/dmpayton/django-admin-honeypot.git@django-2.x

Step 2: Update Settings.py

Add admin_honeypot to your installed apps (make sure it comes before django.contrib.admin so URL routing works correctly):

INSTALLED_APPS = [
    'admin_honeypot',  # Place this above django.contrib.admin
    'django.contrib.admin',
    # Your other apps...
]

# Optional: Disable logging if you don't need it
# By default, the app logs attempts to the 'admin_honeypot' logger. If you don't want logs, skip the logging config below.
LOGGING = {
    'version': 1,
    'disable_existing_loggers': False,
    'handlers': {
        'honeypot_log': {
            'level': 'INFO',
            'class': 'logging.FileHandler',
            'filename': '/var/log/django/admin_honeypot.log',  # Choose your log path
        },
    },
    'loggers': {
        'admin_honeypot': {
            'handlers': ['honeypot_log'],
            'level': 'INFO',
            'propagate': True,
        },
    },
}

Step 3: Configure URLs

Set up your URLs to route /admin/ to the honeypot, and the real admin to your secret URL:

from django.contrib import admin
from admin_honeypot import views as honeypot_views

urlpatterns = [
    # Honeypot at standard /admin/
    path('admin/', honeypot_views.admin_honeypot, name='admin_honeypot'),
    # Real admin at your custom URL
    path('my-super-secret-admin-123/', admin.site.urls, name='real_admin'),
]

This setup will log all login attempts (IP, username, password used) if you enabled logging, while keeping your real admin page hidden from automated scanners.


内容的提问来源于stack exchange,提问作者keybald

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:26:36