Previously a POST to a fake login hit a Laravel 419 (CSRF) or 405, unmasking the framework, and the phpMyAdmin/generic forms even posted to real paths (/index.php, /login). Now: the decoy paths are CSRF-exempt (bootstrap/app.php) and drop BlockBannedIp (an already-banned prober stays inside the deception, always fed a fake — never a revealing 403 — while the ban still blocks them from the REAL login). Every fake form posts back to its own decoy, so a submit re-serves the fake page (looks like a failed login) and trap() records the guessed username + password as threat intel (meta.tried_user / tried_pass). DetectHoneytoken stays on the group, so a submitted canary is still caught. |
||
|---|---|---|
| .. | ||
| Console/Commands | ||
| Enums | ||
| Events | ||
| Http | ||
| Jobs | ||
| Livewire | ||
| Models | ||
| Notifications | ||
| Providers | ||
| Rules | ||
| Services | ||
| Support | ||