10 ms·
Logs of compromised Tor site released
- deleted 12y ago[deleted]
- jlgaddis 12y agoTo grab everything: $ mkdir foo $ cd foo $ wget --mirror --convert-links --adjust-extension --page-requisites --no-parent http://doxbin.strangled.net/ Or you can grab a tarball here: http://evilrouters.net/mirror/doxbin.strangled.net.tar http://evilrouters.net/mirror/doxbin.strangled.net.tar (~37 MB)
- raquo 12y agoAm I understanding this correctly? * Attacker has control of X number of tor nodes * Attacker DDoS-es a hidden service, sending millions of requests to it * Attacker hopes that at least one of these requests will be routed exclusively through their own tor nodes, thus revealing the IP address of the hidden service That sounds neat. Is it a viable way to de-anonimize a hidden service?
- verroq 12y agoIn other words, a Sybil attack.
- aosmith 12y agoehh a Sybil attack involves breaking identification systems (eg, cracking private keys). In this case it seems like they've broken the underlying protocol (tor) to get the ip address.
- jaekwon 12y agoA Sybil attack is any attack that involves attacking by brute forcing the number of identities. The identity need not be based on cryptographic systems -- it could simply be the number of IP addresses.
- aosmith 12y agoSure but Sybil generally refers to obscuring identity as opposed to actually actively breaking into systems... This seems like a much more active attack if it involves forged packets.
- jokoon 12y agowhat do you mean by "hidden service" ?
- deleted 12y ago[deleted]
- greenyoda 12y agoA web site only available using Tor. See: https://www.torproject.org/docs/hidden-services.html.en https://www.torproject.org/docs/hidden-services.html.en
- aosmith 12y agoI think you're right. This describes a graph attack that uses a secondary vector of malformed packets to limit other connections.
- jokoon 12y agoWhat are the odds of that request being routed exclusively through those specific nodes ? I mean he either tried for a long time or had a very long list of nodes... I don't even know what's the average number of middle node for one route.
- aosmith 12y agoI think there's a chance of using malformed packets to disrupt all other nodes.
- nickysielicki 12y agoWhat I don't fully understand is why it's necessary for an adversary to have access to all nodes on the complete path from his DDoS machine to the target IP he's trying to unmask. Wouldn't it only be necessary that I have shared knowledge of what packet I'm sending between the machine that I'm sending my DDoS from and my relay which I'm hoping is the last one that my target is connecting to? Or perhaps I don't understand Tor well enough.
- aosmith 12y agoTor works by obfuscating traffic, jumping through 3 or more nodes before exiting the tor network. If an attacker controls those three nodes it is possible for them to determine the source.
- redthrowaway 12y agoYou're not going to know the contents of the packet unless you also control the machine in the previous hop.
- IshKebab 12y agoYou can use a timing attack.
- kryptiskt 12y agoYou might be able to use statistics instead. If you flood Tor with requests for a particular service, that service's address should become more common at the relays you control.
- deutronium 12y agoIs there actually anything you can do to prevent this kind of attack? I'm assuming once your network is compromised to such an extent there is not much you can do.
- s_q_b 12y agoCut the hardline. Well, but seriously, shut down the network temporarily.
- comboy 12y agoWouldn't that only make it easier to confirm that this network/ip is associated with given hidden service? This made me thinking btw about the latest hetzner hiccups which never happened before.
- s_q_b 12y agoYeah, assuming a global adversary, you'd just watch which servers went dark and the investigate them. We really need a "defensive mode" for TOR.
- userbinator 12y agoOne (rather wasteful) workaround to delay the discovery a little bit is to have each node generate an equivalent amount of traffic going somewhere else. The concept of a hidden service is itself interesting since it must still be "visible" to some extent, or else nothing could communicate with it; but at the same time, it's attempting to hide any indications of its presence. Attacks based on a large volume of traffic will always work if the service is centralised, since that's where all the traffic will (eventually) go. The only real solution I see is to make hidden services highly distributed so that the load is spread out and largely masked by other traffic. Somewhat related: http://en.wikipedia.org/wiki/Fast_flux http://en.wikipedia.org/wiki/Fast_flux
- AlyssaRowan 12y agoThat's broadly describing one possible class of attack. It looks more like a combination of attacks may have been used - traffic confirmation via timing of outages and packets is definitely a strong one, and that's what GCHQ's QUICKANT was gunning for; ONIONBREATH was targeted at hidden service enumeration and distinguishability, and Tor is seemingly not perfect at that. (I gather HSes were due for an overhaul anyway?) Remember, Tor cannot comprehensively protect against a global passive attacker - which is what GCHQ, DSD, NSA, et al are trying to be, as well as every other kind of attacker of course. (Generally speaking, they try every possible angle at once.) However, they have still not had much success to date identifying users, especially en masse. We're talking here about highly-targeted attacks, combined with a few OPSEC fails. (I still prefer garlic routing in general, but Tor has a huge advantage which has little to do with tech - a massive, diverse userbase to hide amongst.)
- s_q_b 12y agoI've studied Tor vulnerabilities for two years. I'm seeing signs of traffic confirmation (active), traffic confirmation (passive), stream watermarking, and a massive willingness to shape control of the network with DoS. Just about every attack on hidden services (active and passive), of which I am aware, was deployed, all at once. The malformed packet DoS was especially clever. And I'm sure a ton more were used that never made it to the academic research. It was almost comical, like the star ship captain saying "now on my mark, fire all photon torpedoes!" They just revealed a massive amount of capability to send a message: Tor is not safe. They want everyone to know that despite that sticker on Snowden's laptop, Tor remains vulnerable. But what remains interesting, and glaringly obviously absent, is user identification. The NSA does not appear to be able to deanonymize users at will. That is, given enough time and enough resources, they can ID hidden services and long-term users, but given an arbitrary Tor exit and and TCP stream, they can't simply follow it back to its origin. A for effort. But in organizaton it looks like a military campaign, not a cyber attack. Straight out of the "total dominance" playbook. But of course it won't work. Tor isn't a country. Its an idea. You can't force the Internet to "submit." All this did was make blindingly obvious holes that many researchers have been asking to be fixed for a while.
- 12y ago
- arthurcolle 12y agoI don't understand the context of this post on torproject.org Who is this guy? Nachash? Is he an operator of one of the illegal websites that were seized as a result of Onymous? He is talking as I would expect a sysadmin, so is that what you'd call him? He talks about inheriting PHP code, is he referring to the original SR source code? If so, how could he have acquired this source code?
- tux3 12y ago>Who is this guy? He was the guy running doxbin [0] before Onymous seized the servers. He's trying to provide any relevant information he can to the Tor devs so that they can better prevent attacks against hidden services in the future. >He talks about inheriting PHP code, is he referring to the original SR source code? He's referring to the doxbin source code [1], which he didn't write entirely but just improved upon. [0] doxbinzqkeoso6sl.onion [1] qhlkmirbijvet2dp.onion
- FurSec 12y ago>Who is this guy? To add on to what tux3 has posted, nachash has been involved in various other illegal happenings on the net over the past few years, usually with other ED hackertypes. You can just use google to find irc logs to get a general idea of who this guy is.
- libraryatnight 12y agoED?
- arthurcolle 12y agoencyclopedia dramatica?
- meowface 12y agoYes.
- aosmith 12y agoWhat if we just started using keys with tor and setting a few (trusted) default nodes... Update to clarify: I'm talking about every user setting a few distinct trusted nodes.
- owenmarshall 12y agoA few nodes makes it easier for a global adversary to attack, I'd think. The FBI could seize those nodes and replace them with rooted boxes. The NSA could use their little boxes in Sprint/ATT/L3's broom closets to forward packets to Ft. Meade. What Tor needs is lots more traffic going through lots more nodes.
- jokoon 12y agoIsn't freenet or I2P more resilient to such attacks ? I mean tor is great because it allows to browse webpages, but aren't there thicker means to be anonymous ?
- aosmith 12y agoEvery system is susceptible to a graph attack at some level...
- weinzierl 12y agoAnd even if its only the money flow graph...
- aosmith 12y agoRegardless of source graph attacks are one of the oldest LEO techniques, even if they don't fit the modern definition...
- doublec 12y agoFreenet doesn't have the concept of a server that hosts a site though. Data is distributed across the datastore in nodes in Freenet. When users request a site or data then it is gathered from the nodes that hold the information. This means sites can't have dynamic functionality but for those that host only static data then it would seem to be an alternative. They are possibly vulnerable to being discovered when inserting data if the attacker knows what they are inserting.
- runeks 12y ago> They are possibly vulnerable to being discovered when inserting data if the attacker knows what they are inserting. If we go by the theory that compromising a single Tor user is not feasible, then connecting to the Freenet network through a fresh Tor connection every time you want to insert new data should make it a lot more difficult to find the identity of the person who is inserting this data. I'm thinking here in the context of operating a black market, where new items are signed with the operator's key, and uploaded to Freenet, along with a list of all items on the market in question, also signed by the operator (with an increasing nonce).
- weinzierl 12y agoFrom the standpoint of someone with root access to a dedi with OpenVZ vms, finding hidden services that are hosted by customers is a matter of looking for files named private_key anywhere under the /vz folder. [...] 2. Cross your fingers and pray really, really hard that the money trail is correctly obscured. Hetzner is a popular German hoster and as far as I know payment requires either a valid credit card or a German bank account. How is it possible to obscure the money trail at all?
- aosmith 12y agoCan you use a prepaid credit card?
- monort 12y agoIt seems you can get them anonymously: https://www.reddit.com/r/Frugal/comments/1zjdob/you_can_get_an_anonymous_prepaid_debit_card_up_to/ https://www.reddit.com/r/Frugal/comments/1zjdob/you_can_get_...
- weinzierl 12y agoI think this is about debit cards, probably not accepted by Hetzner.
- weinzierl 12y agoFrom their payments page [1]: The following credit cards are accepted through this payment facility: Visa, Master, Diners and Amex. I don't know if any of those companies offers prepaid credit cards. [1] http://www.hetzner.co.za/helpcentre/index.php/articles/content/category/payments/what_methods_are_ava_87/ http://www.hetzner.co.za/helpcentre/index.php/articles/conte...
- aosmith 12y agoI know Visa and Amex do. Recent darkweb busts have displayed a level of arrogance that is somewhat disturbing.
- imaginenore 12y ago%5C%22 stands for \" Not sure if that's significant in any way, could be just a unique identifier.
- AlyssaRowan 12y agoIt looks like guard discovery was one component of the attack, and DoS could have been used to boot HSes into choosing a malicious guard, or at least, a raided (but no logs?) or somehow-rooted guard. So it's probably just a badly-coded script-kiddie-grade DoS script. It doesn't have to be an amazing, novel DoS to have an effect - it just has to be a DoS, and they don't have to show their hands by using anything particularly amazing. What I think is that they probably don't have anything that we don't know about already as being theoretically possible. They just tried every attack we do know about at once, and some of it proved fruitful given their reach. Tor stinks - but it still works, and we can improve it.
- justcommenting 12y agoalso of note: https://blog.torservers.net/20141109/three-servers-offline-likely-seized.html https://blog.torservers.net/20141109/three-servers-offline-l...
- aosmith 12y agoSo this is perhaps a little naive but could any of these boxes be shell shock vulnerable? If they were that would make this whole thing trivial...