8 ms·
De-anonymizing ransomware domains on the dark web
- Handytinge 4y agoDid that last one remind anyone of Uplink[0]? 20 year old memories of proxying my ssh traffic through InterNIC just came flooding back! 0. https://en.wikipedia.org/wiki/Uplink_(video_game) https://en.wikipedia.org/wiki/Uplink_(video_game)
- dpapai 4y ago
- orthoxerox 4y agoThis should come in handy if I ever have to run a website on the dark web
- jmprspret 4y agoAvoiding all of this is incredibly basic and borderline common sense. When running a darknet site you don't want associated with the clearnet, step one should be only having the http server listen on the Tor onion domain!
- aaron695 4y ago
- flatiron 4y agoI know absolutely nothing about the subject but I would at least run nginx and tor in a docker container. Make sure no traffic comes out of the container on my public ip. Wouldn’t solve every problem but seems like it would solve…a lot of them? That and I could move it around a lot. Not sure if that’s good opsec or bad though lol.
- hnlmorg 4y agoYou’d probably want some traffic going out on your public IP because everything going via Tor is itself a suspicious activity and likely to draw attention. They key is to ensure only legal stuff goes out on your IP and the illegal stuff is anonymised. Which is easier said than done.
- sterlind 4y agotunnel all the Tor traffic out through a VPN? I feel like there's probably a bunch of servers operating like that for legit reasons. they'd probably assume you're just seeding torrents or something. you can do the same trick to connect to it from home - VPN use is common. you'd want a burner laptop, of course, and some physical box preventing the laptop from hitting anything other than the VPN. I've thought about setting this kind of thing up for fun. you could get really fancy - talking to some hopbox through Tor where you script up actions to take asynchronously, to defeat timing attacks.
- hnlmorg 4y ago> tunnel all the Tor traffic out through a VPN? Same problem. Tunnelling all of your traffic will look suspicious and thus stand out from the thousands of other people who don't tunnel all of their traffic. If I recall correctly, one of the documents Snowden released even specified that people who tunnel all of their traffic via VPC land themselves on government lists for closer monitoring. Regardless of whether this is true or not, creating a lot of legitimate traffic on your same gateway should still make it harder to fingerprint you as someone who exercises in activities that warrant closer inspection.
- naniwaduni 4y agoOkay, tunnel all your Tor traffic through a VPN and also seed Linux ISOs, then, both through the VPN and publicly?
- hnlmorg 4y agoThe best approach really is just to use VPN for specific purposes. Everyday traffic, checking the news, personal email, etc shouldn't be via VPN. You should buy yourself a dedicated laptop for "work" with all that traffic going via VPN+Tor. Don't use your "work" laptop for anything personal and visa versa with your personal devices. This keeps things simple (conceptually) while also effortlessly creates genuinely normal looking traffic. However eventually you'll still get caught. It doesn't matter how careful you are, you only need to slip up once.
- neurostimulant 4y agoThere are plenty of noob mistakes to make when using docker such as accidentally exposing their database port. A lot of mongodb "hacks" in the past was due to this.
- deleted 4y ago[deleted]
- ipaddr 4y agoSo certificates do not enable privacy they take it away. SSL may stop your roommate or isp but they provide another vector for linking to other entities. I wonder how many are using this technique to link web properties together.
- no_time 4y agoThis is not a big deal really. Getting an SSL cert only requires you provide proof of ownership of your domain and has no KYC. You can get as many certs as you want, or sign it yourself. Right now, SSL(or PKI to be precise) is a very privacy respecting technology. For both the server and the client.
- deleted 4y ago[deleted]
- miloignis 4y agoCertificates enable privacy for the user - fundamentally, they are about proving the identity of the server, which is at least somewhat at odds with privacy of the server. Anyway, these all seem like pretty obvious opsec fails where the darknet website is also served over the regular internet, which is just atrocious.
- nick__m 4y agoIf you follow the best practices and do not bind your onion service on 0.0.0.0 and use selfsign and don't reuse key, they do provide privacy against snooping exit node.
- bragr 4y ago>do not bind your onion service on 0.0.0.0 Good advice >they do provide privacy against snooping exit node onion services don't use exit nodes. Your client and the service build circuits to nominated middle relays so https only offers very marginal increases in privacy. However, you are right to assume than any exit node may (or probably is) monitored.
- ziddoap 4y ago#1 and #2 really should just be a part of #3: catastropic opsec. I don't know what it is about people who run these criminal enterprises on the darknet, but they constantly seem to be failing even the most basic of opsec. Re-using identities across multiple services, using e-mail addresses with real names, posting photos with identifiable information (and before websites stripped metadata for them, often posted with metadata), etc. I mean it's nice that they are making it easier to catch themselves, but at the same time I can only wonder how some genius can invent some novel and complex ransomware operation just to turn around and use the email they've had since they were 13 to register the services that operate it.
- number6 4y agoYou only catch those who make those mistakes
- ziddoap 4y agoYes, thanks for that. My point is that those mistakes are made by plenty of ransomware gangs, some of the largest dark markets to ever exist (AlphaBay, Silk Road, etc.), Freedom Hosting, and more. All of which were, at some point, major entities on the darknet making absolutely rudimentary opsec mistakes.
- Closi 4y agoYou only have to slip up once to get caught. Some of the people caught on those listed examples had great Opsec... until that one time where they messed up and then suddenly ended up in jail.
- ziddoap 4y agoWhich ones of my list had great opsec? I'm not denying what you said, it only takes one slip up, but in the cases I mentioned by name: AlphaBay used their regular hotmail account to send password reset emails, and that email was tied to their LinkedIn. Freedom Hosting was taken down because the operators used outdated FF with javascript enabled. Silk Road's Ross Ulbricht posted his personal Gmail address, linking the identities. All of these are profound opsec failures, not just an oopsie that led to getting caught by talented LEOs.
- auiya 4y agoNot sure why there's a mystique over the "dark web", they're all still just websites, and suffer the same types of vulnerabilities.
- mirntyfirty 4y agoYea, it would be rather unfortunate terminology to call websites outside the realms of Google and bing as “dark web” as if somehow these services legitimize the internet itself.
- smegsicle 4y agothe term 'deep web' refers to the subset of internet-connected information that is not widely published eg on search engines, where as the 'dark web' is specifically sites that hide their hosting information behind tor i2p etc as unfair as it may be, a huge part of the usefulness of information is its accessibility, and these search engines currently hold a near-monopoly on which sites can generally be considered readily accessible, ie the 'surface web' above the deep web
- nuccy 4y agoI would personally call telegram/viber/whatsapp/et al. groups/chats/channels "dark web", since information is not indexed there and is basically decaying over time. In about a decade or decade and a half ago, forums flourished, it was really easy to find and share relevant information with relevant group of interested people. I particularly was interested in car's DIY service & retrofit topics. Unfortunately everything is mostly in messengers these days, which won users by offering real-time responses, but providing no real way of topic sorting or proper history. Duplicates of questions and answers of different topics and threads mixed together into an information garbage bin.
- tete 4y ago> I would personally call telegram/viber/whatsapp/et al. groups/chats/channels "dark web", since information is not indexed That's a really odd way of naming thing. They are not web, and "not indexed" usually is referred to as "deep web", not "dark web".
- spacemanmatt 4y agoLooks like every server they busted broke at least one rule from the opsec info posted here just a month or two ago. Classic.
- paulpauper 4y agoOnion domains will never be good for anonymity. too big of a surface area, too much potential leakage somewhere
- 48cfu 4y ago[dead]
- rkagerer 4y agoBasically they found some darknet onion sites whose operators reused the same unique favicon, self-signed TLS certificate, etc. on other sites hosted from public IP's. And in one case left a secret key in a publicly-accessible configuration file.
- neh_89 4y agoThere is no silver bullet when it comes to protecting against ransomware. A ransomware attack A prime example of this was the WannaCry virus attack in May 2017, where 200,000+ computers worldwide were infected due to a weakness in Windows SMB EnternalBlue, which allowed hackers to hijack computers running on an unpatched Microsoft Windows operating system. Users were asked to pay anywhere from 300-700 bitcoins to decrypt the data in 3 days. https://www.spiceworks.com/it-security/cyber-risk-management/articles/ransomware-payment-to-pay-not-to-pay/ https://www.spiceworks.com/it-security/cyber-risk-management...