<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Hacking Tor - A Flaw Appears?</title>
	<atom:link href="http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 21 Aug 2008 23:59:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: ethernode</title>
		<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35465</link>
		<dc:creator>ethernode</dc:creator>
		<pubDate>Tue, 05 Dec 2006 16:50:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35465</guid>
		<description>I was talking about the packetstormsecurity.org implications, not about the flaw itself. Following what i understood from the article, that would mean that tor's anonymity features are fake (because of the "sent back via DNS tunnel to an external host to confirm the real identity of the host") ? I'm beginning to guess i'm saying shit, but doesn't this back-tunnel outpass the 1-hop only feature?</description>
		<content:encoded><![CDATA[<p>I was talking about the packetstormsecurity.org implications, not about the flaw itself. Following what i understood from the article, that would mean that tor&#8217;s anonymity features are fake (because of the &#8220;sent back via DNS tunnel to an external host to confirm the real identity of the host&#8221;) ? I&#8217;m beginning to guess i&#8217;m saying shit, but doesn&#8217;t this back-tunnel outpass the 1-hop only feature?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35463</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Tue, 05 Dec 2006 16:41:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35463</guid>
		<description>&lt;strong&gt;Brian:&lt;/strong&gt; Yah I guess it would, anything as such can circumvent the anonymity of a proxy, that's why using something like AnonymOS is preferable.

&lt;strong&gt;gerg:&lt;/strong&gt; Thanks I'll check that out.

&lt;strong&gt;ethernode:&lt;/strong&gt; I don't think so this a flaw in any proxy based system, it's just showing how its relevant to Tor aswell. It's still the best system there is ATM.</description>
		<content:encoded><![CDATA[<p><strong>Brian:</strong> Yah I guess it would, anything as such can circumvent the anonymity of a proxy, that&#8217;s why using something like AnonymOS is preferable.</p>
<p><strong>gerg:</strong> Thanks I&#8217;ll check that out.</p>
<p><strong>ethernode:</strong> I don&#8217;t think so this a flaw in any proxy based system, it&#8217;s just showing how its relevant to Tor aswell. It&#8217;s still the best system there is ATM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ethernode</title>
		<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35423</link>
		<dc:creator>ethernode</dc:creator>
		<pubDate>Tue, 05 Dec 2006 12:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-35423</guid>
		<description>So, if the SANS is serious about this, is tor a giant honeypot? Corporate or occult?</description>
		<content:encoded><![CDATA[<p>So, if the SANS is serious about this, is tor a giant honeypot? Corporate or occult?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gerg</title>
		<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-34852</link>
		<dc:creator>gerg</dc:creator>
		<pubDate>Fri, 01 Dec 2006 00:17:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-34852</guid>
		<description>This so called paper only describe methods that are known for more than 10 years and that work with every proxy...
There's no Tor specific flaws in this document.

The paper title is just a way to make lamers talk and provide "instant celebrity" to his author... nothing new here

If you want some real technical paper on Tor search a pdf document on how to discover the location of an hidden service using statistics based on rendez-vous nodes.</description>
		<content:encoded><![CDATA[<p>This so called paper only describe methods that are known for more than 10 years and that work with every proxy&#8230;<br />
There&#8217;s no Tor specific flaws in this document.</p>
<p>The paper title is just a way to make lamers talk and provide &#8220;instant celebrity&#8221; to his author&#8230; nothing new here</p>
<p>If you want some real technical paper on Tor search a pdf document on how to discover the location of an hidden service using statistics based on rendez-vous nodes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-34823</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Thu, 30 Nov 2006 19:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hacking-tor-a-flaw-appears/#comment-34823</guid>
		<description>Thanks for this post, I use tor pretty extensively myself and I have to say this is troubleing. The only thing is wouldn't this "vulnerability" fall into the same category as the already known ActiveX and Flash vulnerabilities for these plugin's requiring a direct connection with the client and thus circumventing the proxy network?</description>
		<content:encoded><![CDATA[<p>Thanks for this post, I use tor pretty extensively myself and I have to say this is troubleing. The only thing is wouldn&#8217;t this &#8220;vulnerability&#8221; fall into the same category as the already known ActiveX and Flash vulnerabilities for these plugin&#8217;s requiring a direct connection with the client and thus circumventing the proxy network?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
