We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 53113
    • 13 Posts
    I've used other apps where, after installing them, you can move or rename the ACP (Admin Control Panel - I'm using this term generically) then install a dummy/honeypot in the directory where the ACP would normally be found. I think this is a splendid idea - let hackers hammer away at a bogus entrance while the real entrance is safely hidden away. I have already copied my MODX manager to another location (and enabled 2FA but now I'd like to edit the code in the /MODX/manager directory so that no matter what, it comes back with the standard "incorrect password" message. Ideally, I'd like it to lock hackers out for an hour after 5 "incorrect" attempts. I'm betting there's a simple edit in one of the files in /manager that will get this done. Can someone please point me toward it?
      • 3749
      • 24,544 Posts
      That's a fun idea, though I might be inclined to automatically block them by IP in .htaccess after a certain number of visits. Letting them hack away could waste server resources and bandwidth.

      You could also argue that having them get a 404 on all requests would make them give up and move on to another site.

      Still, it's fun to think that you could have a whole MODX install in and under the Manager directory by modifying the config.core.php file to point to a custom config.inc.php file that used a separate MODX database. You could have a whole Manager and core there designed to drive hackers completely crazy.

      You might take a look at the BotBlockx extra and the LogFileNotFound extra, the first for the interesting code, the second to get a report on what hackers are looking for.

        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 53113
        • 13 Posts
        Quote from: BobRay at Jan 10, 2017, 01:59 PM
        That's a fun idea, though I might be inclined to automatically block them by IP in .htaccess after a certain number of visits. Letting them hack away could waste server resources and bandwidth.
        Seems to me that hackers are going to come after my site no matter what. That wasted bandwidth/resources is probably inevitable.
        You could also argue that having them get a 404 on all requests would make them give up and move on to another site.
        I dunno... to me that just tells them that I was smart enough to rename the manager directory - which makes it a obvious that security was a priority for me and therefore the site is an even bigger prize if it can be hacked...
        Still, it's fun to think that you could have a whole MODX install in and under the Manager directory by modifying the config.core.php file to point to a custom config.inc.php file that used a separate MODX database. You could have a whole Manager and core there designed to drive hackers completely crazy.
        Yikes! Is that what it would take? Seems like that's swatting a fly with a sledgehammer. I'd be more inclined to view the source on a WordPress admin login page and do a php file like:
        <?php
             echo "<html that displays a WordPress admin login page>";
        ?>
        Now they'll spin their wheels trying all the wrong exploits! On the flipside, having an entire honeypot installation and database would certainly have some advantages.
        You might take a look at the BotBlockx extra and the LogFileNotFound extra, the first for the interesting code, the second to get a report on what hackers are looking for.
        Will do. Thanks, Bob!
          • 3749
          • 24,544 Posts
          Yikes! Is that what it would take? Seems like that's swatting a fly with a sledgehammer.

          No, No. There are much simpler ways to handle it depending on what you want. You could just modify the Login processor to do whatever you want, or replace the code in the manager/index.php file, with a login form and a bit of PHP code to process submissions.

          I was just amused by the idea of creating a MODX Manager that did things like randomly renaming your resources, swapping the content of two chunks, or saying "I'm sorry Dave, I can't do that."

            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 53113
            • 13 Posts
            Well, I've done it! Using the method I suggested above, If you append "/wp-admin" to my domain, you get a very realistic looking WordPress login page that will not log you in. The form posts to /wp-login.php (which exists, but returns a 500 error.) I'm actually pretty pleased with it!
              • 36816
              • 109 Posts
              Quote from: quantiumtech at Jan 10, 2017, 01:19 PM
              (and enabled 2FA

              Curious -- what method of 2FA are you using with MODX?
                • 53113
                • 13 Posts
                Quote from: clareoconsulting at Jan 10, 2017, 06:13 PM
                Quote from: quantiumtech at Jan 10, 2017, 01:19 PM
                (and enabled 2FA

                Curious -- what method of 2FA are you using with MODX?
                I misspoke(typed) - I'm using 2FA on my cpanel. Planning to use it on MODX; haven't got to it yet, but I plan to.