Brief survey on methods for attacking Tor hidden service
translate.wooyun.io
Brief survey on methods for attacking Tor hidden service
1–8 of 8 posts
Re: Brief survey on methods for attacking Tor hidden service
#2Re: Brief survey on methods for attacking Tor hidden service
#3Re: Brief survey on methods for attacking Tor hidden service
#4Re: Brief survey on methods for attacking Tor hidden service
#5Is the illustration really accurate for hidden services? If so, for what reason isn't the last hop encrypted too?
Re: Brief survey on methods for attacking Tor hidden service
#6Is the illustration really accurate for hidden services? If so, for what reason isn't the last hop encrypted too?
The methods for attacking hidden services (DNM) are the same as any other site such as exploiting misconfiguration, exploiting unpatched software or finding new ones, and looking for pieces of opsec like the Czech guy who's darkmarket used some obscure Czech php framework which was identified by viewing the CSS. Every so often a research paper comes out too that identifies some new scheme of analysis of guard nodes/pattern matching/fingerprinting ect to identify hidden service IPs as noted in this Wooyun article. https://news.mit.edu/2015/tor-vulnerability-0729
Snowden docs also talked about QUANTUM which was some NSA/GCHQ scheme to try race conditions against relays to lure Tor users to their own relay farm for analysis detailed here https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a...
Re: Brief survey on methods for attacking Tor hidden service
#7Is the illustration really accurate for hidden services? If so, for what reason isn't the last hop encrypted too?
The title for this is confusing, they are talking about detecting and attacking regular Tor connections not internal hidden services (like a DarkMarket). That illustration showing not encrypted is the exit node to a regular clearnet site. The methods for attacking hidden services (DNM) are the same as any other site such as exploiting misconfiguration, exploiting unpatched software or finding new ones, and looking fo…
Re: Brief survey on methods for attacking Tor hidden service
#8Is the illustration really accurate for hidden services? If so, for what reason isn't the last hop encrypted too?
The title for this is confusing, they are talking about detecting and attacking regular Tor connections not internal hidden services (like a DarkMarket). That illustration showing not encrypted is the exit node to a regular clearnet site. The methods for attacking hidden services (DNM) are the same as any other site such as exploiting misconfiguration, exploiting unpatched software or finding new ones, and looking fo…