“Warning: Do Not use my mirrors/services until I have reviewed the situation”
1–10 of 167 posts
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#2 Node fingerprints are as follows, please blacklist ASAP. Some servers are
accessible via their KVM again but not networked.
D78AB0013D95AFA60757333645BAA03A169DF722
6F545A39D4849C9FE5B08A6D68C8B3478E4B608B
5E87B10B430BA4D9ADF1E1F01E69D3A137FB63C9
0824CE7D452B892D12E081D36E7415F85EA9988F
35961469646A623F9EE03B7B45296527A624AAFD
1EA968C956FBC00617655A35DA872D319E87C597
E5A21C42B0FDB88E1A744D9A0388EFB2A7A598CF
5D1CB4B3025F4D2810CF12AB7A8DDDD6FC10F139
722B4DF4848EC8C15302C7CF75B52C65BAE3843A
93CD9231C260558D77331162A5DC5A4C692F5344
A3C3D2664F5E92171359F71931AA2C0C74E2E65C
575B40EF095A0F2B13C83F8485AFC56453817ABF
27780F5112DEB64EA65F987079999B9DC055F7C0
54AA16946DB0CF7A8FA45F3B48A7D686FD1A1CEF
1EB8BDA15D27B3F9D4A2EDDA58357EA656150075
17A522BC05A0D115FC939B0271B8626AAFB1DDFF
1324EC51FBFA5FD1A11B94563E8D2A7999CD8F57
[1] http://thread.gmane.org/gmane.network.tor.user/34619Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#3Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#4As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#5As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.
Also, IMO it's unlikely that these events are unrelated.
1. Tor says they might get compromised.
2. Guy's exit node gets compromised.Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#6Interesting to see this play out in realtime. This message just showed up in the thread[1]: Node fingerprints are as follows, please blacklist ASAP. Some servers are accessible via their KVM again but not networked. D78AB0013D95AFA60757333645BAA03A169DF722 6F545A39D4849C9FE5B08A6D68C8B3478E4B608B 5E87B10B430BA4D9ADF1E1F01E69D3A137FB63C9 0824CE7D452B892D12E081D36E7415F85EA9988F 35961469646A623F9EE03B7B45296527A624AAFD…
Not much further info at this point. Trying to do secure log dumps but most systems seem unavailable again. Bracing for possible local raid
Apologies no further info atm, I don't know what I am dealing with yet, ISP has made no comment Re: if warrant executed at servers
Interesting that the servers were briefly up and running, but down again.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#7As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.
Also, warning people not to use those mirror sites is a responsible reaction to possible compromise.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#8As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.
Um, it's useful for other Tor operators to know what to look for if they find their servers rebooting / going down for a while without good reason. Also, warning people not to use those mirror sites is a responsible reaction to possible compromise.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#9Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#10It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan government compromise). And of course the whole Free Syrian Army / ISIS / terrorist nom de jure attacks.
I can't shake the analogy to pictures from WW II where shop keepers were huddled in the back while soldiers fought from the front of the store. I see innocent servers being 'occupied' by enemy malware so that it can launch attacks on other servers further into a protected network.
Fortunately in this modern version of war you can "kick the soldiers out" of your server by bringing it down and re-imaging it. And they won't turn around and shoot you, but that is not all that comforting somehow.