Honeypot on the boykisser forum(blog.boykisser.nl)
The author of a blog set up a honeypot to combat a botnet that was targeting their forum, after receiving a recommendation from the phpBB community forums. The honeypot, which is a simple trap that bans IP addresses that access a hidden link, revealed that the botnet appears to be originating from third-world countries, as well as some unexpected locations like Germany. The author noticed that the bots were targeting specific URLs on their forum, and that some IP addresses were sharing the same session ID, indicating suspicious activity. The honeypot adds banned IP addresses to the forum's htaccess file and throws a fake 500 error, but the author notes that this may not be effective against infected machines, and that server configurations may prevent the error from being displayed.