Express Honeypot Logo

Express Honeypot

0
Free
Updated 11 March 2025
Visit Website

Express honeypot is a honeypot for remote file inclusion (RFI) and local file inclusion (LFI). The aim of this project is to catch bots and malwares that are scanning websites and try to upload remote files. Those RFI / LFI bots use a list of google dorks in order to search the web for vulnerable websites. Express honeypot uses 310 fake URLs based on RFI LFI dorks and serves them dynamically. Every request to any of the honeypot URLs is logged, and the remote file is downloaded and safely stored. This honeypot is written in JavaScript and uses Express as a web server. A light logs viewer page is available at /beekeeper, but it needs to have more commands. Development is still in progress, but the core architecture won't change, so you are safe to start using it. To use, clone the project and install the dependencies: git clone https://github.com/christophe77/express-honeypot cd express-honeypot yarn install Edit /express/config.js file. Port is the port for the web server. BeekeeperCredentials are the username and password to access /beekeeper URL. RemoteFileSave allows you to choose to save the remote file on your local drive, on dpaste, or on both of them. GoogleVerification is th

FEATURES

SIMILAR TOOLS

A comprehensive dashboard for managing and monitoring honeypots with detailed information on attack attempts and connections.

A tool for testing subdomain takeover possibilities at a mass scale.

An automation framework for subdomain bruteforcing

Python telnet honeypot for catching botnet binaries

A low-interaction SSH authentication logging honeypot that logs all authentication attempts in JSON format.

Ansible role for deploying and managing Bifrozt honeypots

A tool to bypass Content Security Policy (CSP) restrictions

Django App for the SSH Honeypot called 'kippo'

A highly interactive honeypot for observing access from attackers by building easily targeted and compromised web applications, forwarding logs to Google BigQuery for accumulation and visualization.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved