I've used other apps where, after installing them, you can move or rename the ACP (Admin Control Panel - I'm using this term generically) then install a dummy/honeypot in the directory where the ACP would normally be found. I think this is a splendid idea - let hackers hammer away at a bogus entrance while the real entrance is safely hidden away. I have already copied my MODX manager to another location (and enabled 2FA but now I'd like to edit the code in the /MODX/manager directory so that no matter what, it comes back with the standard "incorrect password" message. Ideally, I'd like it to lock hackers out for an hour after 5 "incorrect" attempts. I'm betting there's a simple edit in one of the files in /manager that will get this done. Can someone please point me toward it?
That's a fun idea, though I might be inclined to automatically block them by IP in .htaccess after a certain number of visits. Letting them hack away could waste server resources and bandwidth.
You could also argue that having them get a 404 on all requests would make them give up and move on to another site.
Still, it's fun to think that you could have a whole MODX install in and under the Manager directory by modifying the config.core.php file to point to a custom config.inc.php file that used a separate MODX database. You could have a whole Manager and core there designed to drive hackers completely crazy.
You might take a look at the BotBlockx extra and the LogFileNotFound extra, the first for the interesting code, the second to get a report on what hackers are looking for.
Yikes! Is that what it would take? Seems like that's swatting a fly with a sledgehammer.
No, No. There are much simpler ways to handle it depending on what you want. You could just modify the Login processor to do whatever you want, or replace the code in the manager/index.php file, with a login form and a bit of PHP code to process submissions.
I was just amused by the idea of creating a MODX Manager that did things like randomly renaming your resources, swapping the content of two chunks, or saying "I'm sorry Dave, I can't do that."
Well, I've done it! Using the method I suggested above, If you append "/wp-admin" to my domain, you get a very realistic looking WordPress login page that will not log you in. The form posts to /wp-login.php (which exists, but returns a 500 error.) I'm actually pretty pleased with it!