[code] [blog] [Repos] [GPS Tracker] [Music] [VNC] [Restart VNC] [E-Mail me]

Error page that traps vulnerability scanners, e-mail harvesters and botnets

git clone https://coredump.ws/repos/cunty-error.git
# push (client certificate):
git remote set-url --push origin https://coredump.ws:8443/repos/cunty-error.git

Branches and tags

masterbranch18 h agozip

Files at HEAD (4a1686af94) · download zip

build_fpmap.py1.7 KB
build_markov.py2.2 KB
dictionary69.5 KB
error.php257.3 KB
honeypot-selftest.sh7.0 KB
README.md7.0 KB

Recent commits · all

4a1686afUpdate honeypot: front-controller, fingerprint matching, dropper capture, webshell/CVE coverageno-body-in-particular18 h ago
592f38c2cunty-error: the coredump.ws error page that traps scanners and botsno-body-in-particular19 h ago

README.md

cunty-error

A deceptive error/404 handler for the Hiawatha web server. Instead of a plain error page, it serves convincing but entirely fabricated content to automated vulnerability scanners and exploit bots: realistic Markov-generated prose, fake SQL/PHP/framework errors, fake product logins, fake config/secret files, and more — wasting the bots' time and generating abuse-report intelligence, while never exposing anything real.

Everything it returns is fake. It touches no database and no real file beyond its own dictionary and markov.db. Every value reflected from a request is HTML-escaped, so it cannot become an XSS vector against a human.

What it traps

Requirements

Setup

  1. Place the page and its data in your web root (e.g. /var/www/hiawatha):
  1. Build markov.db from public-domain text (Project Gutenberg works well):
   mkdir corpus && cd corpus
   curl -L https://www.gutenberg.org/files/1342/1342-0.txt -o pride.txt
   curl -L https://www.gutenberg.org/files/2701/2701-0.txt -o moby.txt
   cat *.txt > ../corpus_all.txt && cd ..
   python3 build_markov.py .        # writes markov.db next to corpus_all.txt
   cp markov.db /var/www/hiawatha/
  1. Wire it into Hiawatha. Minimal (returns HTTP 500 — realistic for a SQL/PHP error, and enough to keep sqlmap engaged):
   # hiawatha.conf
   ErrorHandler = 401:/error.php
   ErrorHandler = 403:/error.php
   ErrorHandler = 404:/error.php
   ErrorHandler = 405:/error.php
   ErrorHandler = 500:/error.php
   ErrorHandler = 501:/error.php
   ErrorHandler = 503:/error.php

Recommended (front-controller): route every unknown path through the handler so it can return realistic status codes (200 for a fake page, 500 only for a SQL error, 401/403/429 where appropriate) instead of the pinned error code. Add to your UseToolkit chain, after your deny rules:

   UrlToolkit {
       ToolkitID = secure
       # ... your existing deny rules (dotfiles, sensitive extensions) ...
       RequestURI exists Return
       # keep your real apps/proxies serving:
       Match ^/(app1|app2|assets)(/|$) Return
       Match ^/?$ Return
       Match .* Rewrite /error.php
   }

With the front-controller, error.php returns 200 by default and 500 only on an error-based SQL page. Validate any config change with hiawatha -k before restarting.

  1. Optional static bait (served as real 200 files; their URLs all 404 back into the honeypot):
  1. Logging. The page appends one tab-separated line per trapped request to /var/log/honeypot.log (create it writable by the CGI user). Since it is a dedicated file, point your log rotation at it. honeypot-abuse-report.py turns the log into per-source-IP abuse-report drafts (via RDAP; it never sends anything on its own).

Change these before you rely on it

error.php contains two public-by-definition values you must change for your own deployment:

Testing

honeypot-selftest.sh exercises every trap type and the boolean-blind SQLi invariants against a running instance and prints PASS/FAIL. Run it after any edit:

sh honeypot-selftest.sh http://127.0.0.1

Files

filepurpose
error.phpthe handler (place in web root)
build_markov.pybuilds markov.db from a text corpus
honeypot-selftest.shregression test for every trap + invariants
honeypot-abuse-report.pyturns honeypot.log into abuse-report drafts

Caveats