Case Study: Honeypot Deflection & Tarpit Scanning Sink
This case study demonstrates how to use RouteWarden to deflect reconnaissance bots and malicious vulnerability scanners into honeypots or silent TCP drops.
The Threat Model
Public IPv4 and IPv6 addresses receive continuous automated requests looking for .env, /phpinfo.php, /.git, and common vulnerable endpoints.
While returning an HTTP 403 Forbidden or 404 Not Found works, scanners will often continue iterating through hundreds of file paths, consuming reverse proxy bandwidth and generating thousands of log lines.
Strategy A: Silent Connection Drops (mode: silentDrop / silent_drop)
Rather than allocating memory buffers and sending an HTTP status response, RouteWarden's silentDrop mode closes the underlying TCP connection immediately (or returns an empty payload).
# dynamic_conf.ymlhttp: middlewares: scanner-drop: plugin: routewarden: enabled: true enableDefaultPatterns: true # Close connection immediately on probe attempts response: mode: silentDropResult:
- Port scanners receive a connection reset (
TCP RSTor EOF). - Automated vulnerability tools flag the endpoint as dead or unresponsive, prompting them to abandon the host.
- Zero server bandwidth spent delivering HTML error bodies.
Strategy B: External Honeypot Deflection (mode: redirect)
When an attacker accesses any sensitive file pattern, RouteWarden can issue an HTTP 302/307 Redirect to an external honeypot, a public loopback (http://127.0.0.1), or an FBI/IC3 reporting endpoint:
# dynamic_conf.ymlhttp: middlewares: honeypot-deflect: plugin: routewarden: enabled: true enableDefaultPatterns: true response: mode: redirect statusCode: 307 redirectUrl: "https://honeypot.internal.corp/capture" headers: X-RouteWarden-Deflected: "true"Strategy C: Staging & Preview Environment Cloaking
For pull-request preview environments (e.g., pr-142.staging.example.com), competitors or automated crawlers shouldn't index unreleased code:
# dynamic_conf.ymlhttp: middlewares: staging-guard: plugin: routewarden: enabled: true # Block everything by default pathPatterns: - '^/.*$' # Disable standard public exemptions (robots.txt, sitemap.xml) enableDefaultAllowPatterns: false # Allow exclusively developer and office subnets allowedIps: - "10.0.0.0/8" - "100.64.0.0/10" # Tailscale - "203.0.113.50/32" # Corporate NAT IP response: mode: json statusCode: 404 body: '{"error":"Not Found"}'Strategy D: Active Defense with Gzip Bomb (mode: gzipBomb / gzip_bomb)
When automated reconnaissance scanners (nikto, gobuster, dirsearch, or credential stuffers) probe for sensitive configuration files (.env, wp-config.php, /actuator/env), returning a 403/404 allows them to swiftly move to the next URL on their wordlist.
With RouteWarden's gzipBomb mode (alias: bomb), the middleware serves a valid HTTP 200 response with Content-Encoding: gzip consisting of a stream of compressed zero bytes.
# dynamic_conf.ymlhttp: middlewares: honeypot-bomber: plugin: routewarden: enabled: true pathPatterns: # Lure crawlers scanning for high-value targets - '(?i)(^|/)(\.env.*|\.git.*|wp-login\.php|phpmyadmin.*)$' response: mode: gzipBomb # Alias: "bomb" statusCode: 200 # Looks like a jackpot 200 OK to the crawler gzipBombMB: 10 # 10MB uncompressed expands ~1000x to ~10GB in client memoryHow the Gzip Bomb Neutralizes Scanners:
- Negligible Server Cost: The server streams compressed zeroes. Transmitting a 10 MB payload over the wire requires only a few kilobytes of bandwidth and tiny CPU cycles.
- Client Memory Exhaustion (OOM): Most automated crawler libraries (
requests,urllib3, Go/Python scrapers) auto-decompress gzip responses in RAM. When the stream expands to 10+ GB, the attacker's crawler crashes from out-of-memory errors. - Scan Halting: The attacker's scanning process terminates, preventing further probing across your infrastructure.
CAUTION: Impact on Legitimate Crawlers & Browsers
Legitimate web browsers and search engine indexers (such as Googlebot, Bingbot, or Applebot) automatically decompress gzip content encoding.
- Do NOT bind
gzipBombas a global entrypoint catch-all across all application routes. - Always keep
enableDefaultAllowPatterns: true(or explicitly whitelist/robots.txtand/sitemap.xml) so search engine indexers are never trapped. - Only target explicit, high-confidence exploit paths that standard human users and valid search spiders will never request (e.g.,
^/\.env,^/\.git,^/wp-login\.php,^/phpmyadmin).
Strategy E: Tarpit Scanning Sink (mode: tarpit)
Rather than dropping or bombing the connection, RouteWarden's Reverse Slowloris Tarpit stalls scanner concurrency pools by accepting requests to probe endpoints with a 200 OK header and trickling individual bytes at slow, deliberate intervals.
Because automated vulnerability tools (sqlmap, nikto, nuclei) operate with finite worker thread pools (typically 10–50 concurrent workers), tying up sockets on honeypot routes paralyzes their scanning capacity.
http: middlewares: tarpit-sink: plugin: routewarden: enabled: true pathPatterns: - '(?i)^/(phpmyadmin|pma|wp-login\.php|\.env|\.git.*)$' response: mode: tarpit statusCode: 200 tarpitDelayMs: 1000 # Trickle 1 byte every 1000ms tarpitMaxDurationSeconds: 120 # Release socket after 2 minutesResult:
- The crawler's active thread pool is occupied for up to 120 seconds per probing thread.
- Scanning velocity against your legitimate applications drops to near-zero.
- The connection cleanly closes after
tarpitMaxDurationSecondsto protect reverse proxy file descriptor limits.