2 ms·
The FBI is claiming that the CAPTCHA on the login page was misconfigured and was leaking the IP. Here's the relevant testimony[1]: In or about early June 2013
by csandreasen 12y ago
The FBI is claiming that the CAPTCHA on the login page was misconfigured and was leaking the IP. Here's the relevant testimony[1]:
In or about early June 2013, another member of CY-2 and I closely examined the traffic data being sent from the Silk Road website when we entered responses to the prompts contained in the Silk Road login interface. This did not involve accessing any administrative
area or “back door” of the site. We simply were
interacting with
the website’s user login
interface, which was fully accessible to the public, by typing in miscellaneous entries into the username, password, and CAPTCHA fields contained in the interface. When we did so, the website sent back data to the computer we were using
– specifically, the Silk Road homepage, when we used valid login credentials for undercover accounts we had on the site, or an error message, when we used any username, password, or CAPTCHA entry that was invalid.
Upon examining the individual packets of data being sent back from the website, we noticed that the headers of some of the packets reflected a certain IP address not associated with any known Tor node as the source of the packets. This
IP address (the “Subject IP Address”) was the only non-Tor source IP address reflected in the traffic we examined. The Subject IP Address caught our attention because, if a hidden service is properly configured to work on Tor, the source IP address of traffic sent from the hidden service should appear as the IP address of a Tor node, as opposed to the true IP address of the hidden service, which Tor is designed to conceal. When I typed the Subject IP Address into an ordinary (non-Tor) web browser, a part of the Silk Road login screen (the CAPTCHA prompt) appeared. Based on my training and experience, this indicated that the Subject IP Address was the IP address of the SR
Server, and that it was “leaking” from the SR Server because the computer code underlying the login interface was not properly configured at the time to work on Tor.
[1] http://www.scribd.com/doc/238844570/FBI-Explanation-of-Silk-Road-vulnerability http://www.scribd.com/doc/238844570/FBI-Explanation-of-Silk-... (pages 3-4)