Jump to content

Practical Onion Hacking


System Error

Recommended Posts

this method could easily be beaten by disabling javascript and flash in your browser whenever you are using the tor network (which you shouldnt need if you are using the tor network for something specific). also routing all dns lookups through tor adds another layer of security.

Link to comment
Share on other sites

Pretty interesting article.

I get the gist of waht they are doing. But a question arises. They are atacking the anominity of the User right>? But why is the paper called unwrapping the onion>?

I ask this becasue, it appears that they arent actually figureing out the ip address of all Tor clients but rather only those who directly connect to their tor server initially and then out onto the web and not to another tor server.

"First Queue Interesting Data"

1: All outbound packets destined to port 80 which are not going to another tor node.

2: All inbound traffic originating from port 80, and not form another Tor node.

so this model suggests to me that it only can find the ip of:

client(target) -> tor server(IP_getter) ->web

and not:

client(target) -> tor(server) ->tor server(IP_Getter)->tor->web

or

client(target) ->server(IP_Getter)->tor->web

or

client(target) -> tor(server) ->tor server(IP_Getter)->web

I could be misunderstanding the paper so if you can clrify please do so. but it seems that if it isnt keeping track of any data comming in from another tor node or going to a tor node....the it misses those anonmous browsers....its not really unwraping the onion but rather sliceing off a peice of it.

again if i jsut missed the concept please clarify.

thanks

Link to comment
Share on other sites

They are atacking the anominity of the User right>? But why is the paper called unwrapping the onion?
Well, the goal of TOR is to make sure you can't be identified. If someone is able to identify you, what exactly is TOR doing for you?
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...