7 ms·
It's much more fun to run an exit node and inspect the traffic using tools like the dsniff suite and Suricata. Back in the day, 90% of the traffic I would see
by DominoTree 10y ago
It's much more fun to run an exit node and inspect the traffic using tools like the dsniff suite and Suricata.
Back in the day, 90% of the traffic I would see was just people trying to brute force Hotmail accounts via POP3, but occasionally I'd sniff the credentials for an IRC-based C2 for a botnet, and I'd log in and wreck the thing.
- DaKnOb 10y agoWell, it's fun to do this and learn from that, however in an exit node it's not something I'd want to do. People use Tor to surf the web anonymously (mostly) and have some privacy. There are certainly exit nodes that do this, and it has been proven by blog posts in the past, however the more nodes that don't engage in such activities, the better for the network overall.
- nxzero 10y agoWould it be possible for Tor to detect sniffing by seeding the traffic with poison pills that ratted out anyone doing this in bulk?
- dogma1138 10y agoNot really you can always mirror the wan/uplink port and do the capture on another box so even some time based / performance analysis won't show anything.
- dkopi 10y agoPort mirroring means you can only be a passive eavesdropper. Attacks like SSL mitm wouldn't work because you actually have to intercept and modify the traffic
- dogma1138 10y agoSSL MITM still won't work unless you want it to be very noticeable or you have very substantial resources. Port mirroring is enough to capture SSL traffic and to break weak SSL keys or if you have compromised the key of the destination services (w/ some caveats like no forward secrecy etc.) And it doesn't prevents you from executing MITM attacks from upstream or just doing specific MITM attacks from within the TOR exit node later on. But overall there is nothing you can do to ensure that your TOR exit node, your VPN gateway or even your ISP isn't reading your traffic other than to use encrypted tunnels everywhere and even then you are for the most part only moving the problem upstream.
- unethical_ban 10y agoYou can't silently mitm SSL unless you are trusted by the client.
- DaKnOb 10y agoThis has been done in the past: researchers visited a uniquely generated URL from Tor and then recorded which Exit Nodes visited it again. You can find their work if you google it..
- brownbat 10y agohttps://chloe.re/2015/06/20/a-month-with-badonions/ https://chloe.re/2015/06/20/a-month-with-badonions/ "Chloe" visited unique web pages for a month last year, and also used unique credentials to log into a custom honeypot. Of the over 137,000 exit nodes tested, 15 attempted to use the credentials, 650 visited the unique websites. Less than half of a percent, but definitely happening regularly enough to be an issue.
- j3097736 10y agoYes, see http://www.cs.kau.se/philwint/spoiled_onions/ http://www.cs.kau.se/philwint/spoiled_onions/ and http://www.leviathansecurity.com/blog/the-case-of-the-modified-binaries http://www.leviathansecurity.com/blog/the-case-of-the-modifi...
- nxzero 10y agoMakes you wonder why Tor doesn't replicate this and send the nodes ghost traffic, poison pills, block the IPs, etc.
- paavokoya 10y agoSounds strenuous on an already slow network..
- makomk 10y agoLast I heard, there was basically one guy handling all reports of malicious exit nodes, and I couldn't even get him to do anything about the ones very obviously intercepting traffic to Bitcoin wallets and injecting code that stole people's money
- pjc50 10y agoPeople are communicating with bitcoin wallets without end-to-end encryption?
- nbraud 10y agoThere is automated tooling out there that is used to detect misbehaving exits, like ExitMap: https://gitweb.torproject.org/user/phw/exitmap.git/ https://gitweb.torproject.org/user/phw/exitmap.git/
- deleted 10y ago[deleted]
- vog 10y ago> however the more nodes that don't engage in such activities, the better for the network overall. I'd argue that it is quite the opposite. The more people are aware that plaintext over Tor is a really, really bad idea [1], the more people will use end-to-end encryption. In particular, they will insist that more websites switch to HTTPS. Which is actually better for the network overall, and would render most of these attacks useless. I wonder whether the Tor browser bundle should disable plain HTTP completely, only to be enabled through some obscure config setting for the seldom use cases where this is actually needed. [1] Tor is by definition a system of man-in-the-middle through man-in-the-middle. Why would anybody want to use that without end-to-end encryption?
- nbraud 10y ago> The more people are aware that plaintext over Tor is a really, really bad idea [1], the more people will use end-to-end encryption. Yes, but how does your collecting logs impact overall awareness? Even if it did (say, you make the logs available through some snazzy web interface, it gets mass media attention), how does that balance out with the users who traffic you exposed?
- vog 10y agoI didn't mean that more exit nodes should collect and share their logs. That would indeed weaken the Tor network, by facilitating traffic correlation. I meant inspecting/manipulating the traffic if it is unencrypted. As a political statement, this should of course never actually attack the client, but instead try to raise attention by e.g. injecting a message along the lines: Hi, I'm a stranger and it was trivial for me to inject this message. Please use HTTPS to prevent me from doing this. Thinking more about that, however, this may be a bad idea. People could perceive this to be a security hole in the Tor network itself, rather than HTTP itself, which could damage the reputation of Tor.
- beardog 10y agoIsn't this technically wiretapping and illegal in some countries?
- erikpukinskis 10y agoI don't think it's wiretapping if people just give you their requests.
- codesterling 10y agoFortunately you're wrong. Otherwise, post would never have gotten off the ground.
- ashitlerferad 10y agoMonitoring Tor exit node traffic would be exceptionally unethical.
- 0x0 10y agoIt's also probably something you should assume is happening on all the exit nodes.
- dcposch 10y agoExactly. Ethics is just the wrong way to think about it. It's like the people emptying weak brainwallets. Is it unethical to empty the brainwallet for "password123"? Is it unethical to pick up a quarter lying on the sidewalk? No and no. Saying that strangers on the internet are bound by ethics is unrealistic. Instead, we should build systems that are resilient. For example: * A brainwallet generator should estimate passphrase complexity and warn if it's too low * Tor Browser should show a red lock icon for plain HTTP and warn users clearly that their traffic may be read Blame the program, not the person. Calling the inevitable attacker "unethical" just isn't useful. Saying the user is dumb or Doing It Wrong isn't useful either. Good crypto software should be resistant to both misuse (by Adam) and abuse (by Eve)
- not_anit_woman 10y agoI'm just giddy that Bitcoin is coming into common parlance here :)
- brianleb 10y agoYou seem to be completely misunderstanding ethics. Just because you 'can' do something does not mean it should be done or is ethical to do so. You 'can' break into your neighbor's house and steal <whatever>. Just because you have that capacity does not make it suddenly ethical to do so, even if they leave their doors unlocked. GP didn't say that strangers on the internet are bound by ethics. Ethics are not a thing we are 'bound' by. They are a value judgment we make based on whatever social contract we think we have with those around us. If passphrase complexity is "too low", that's also a judgment. There are no universal truths about what is adequate complexity. What you think is adequate today will not be adequate tomorrow. If someone's passphrase was inadequate and was cracked, was it ethical for the cracker to take advantage of it? If the passphrase passed a certain complexity, did it suddenly become unethical?
- marcoperaza 10y agoI'm pretty sure you just confessed to several felonies.
- codesterling 10y agoNot sure why you're being down voted, what he did is indeed a felony.
- rndgermandude 10y agoTell that to all those ISPs doing DPI and injecting crap and ads in unencrypted http. Or hotels running captive portals. Or your employer doing org-wise TLS MITM and logging. Unethical? Most certainly! A crime? Could be depending on what was done and in what jurisdiction, but far from certain.
- marcoperaza 10y agoIn all of those examples you cite, the user has agreed to allow the monitoring or injection.
- rndgermandude 10y agoHonestly, it is arguable that the user actually agreed to monitoring and in-flow data modification knowingly, and therefore it might constitute an Unconscionable Contract due to an Unfair Surprise (again, depending on jurisdiction). That is assuming the user did actually agree to anything. Now what if the exit operator put up a ToS themselves stating users of their exit node will be monitored and/or data flowing through their services might be modified on route even? Because, after all, it is the TOR users using their services, not the other way round. "You hereby grant Tor Exit Operator Ltd, A Nigerian Prince/Russian Business Network joint venture, the right to monitor, log, modify all data you transmit to our service and an irrevocable, unlimited license to use any data you transmit for any purpose".
- 10y ago
- x0 10y agoNice one :) I do the same to IRC botnets, but mainly phishers, I must admit. The botnets I see always seem to use that one Perl script, the "servidor" one, written in Portugese.
- simplemath 10y agoOh greyhats, never change
- qwertyuiop0987 10y agoThis of course is stupidly simple to do. Tor is doing a disservice to their community by acting like this isn't the case. Also, why on earth should Tor be some kind of sacred platform that should not be poked if it's insecure? This looks fun: http://packetstorm.foofus.com/papers/attack/jackin-tor.txt http://packetstorm.foofus.com/papers/attack/jackin-tor.txt On a more innocent note, and far more difficult to detect (if not impossible) would be running passiveDNS + relay/exit will turn up interesting data. For example (roughly 2 weeks of data): https://gist.github.com/anonymous/831ab3fa8c07654479c61e615c85b4a8 https://gist.github.com/anonymous/831ab3fa8c07654479c61e615c...