4 ms·
Novel technique can unmask up to 70% of crooks hiding behind VPNs, proxies, Tor
- k310 2y ago> The technique leverages honey pots and Canarytokens used to bait attackers to interact with token-embedded files (Excel, Word, PDF, ZIP) and URLs (QR codes, DNS tokens, HTTP requests). If an attacker falls for the trap the method generates an HTTP request containing metadata such as IP addresses, user-agent strings, timestamps and geographic data. > “When the attacker tries to access or load the honey file, this will cause the payload to start looking for information such as the real IP address and user agent (data tied to the hacker’s browser, operating system, and device),” the authors wrote. > This, in turn, triggers a process in which the incriminating attacker’s data is sent back to a cyber-defender’s server. Paper (pdf) Unmasking the True Identity: Unveiling the Secrets of Virtual Private Networks and Proxies [0] [0] https://www.mdpi.com/2078-2489/16/2/126 https://www.mdpi.com/2078-2489/16/2/126