TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Snooping on Tor from Your Load Balancer

2018-07-03 · Read original ↗

ATT&CK techniques detected

15 predictions
T1090.003Multi-hop Proxy
97%
"e. g., the fbi ), which can ’ t track hackers, thieves, and drug dealers who use it. today, the tor network is mostly run by true ( privacy ) believers at the tor project. 1 these volunteers are constantly trying to improve the network, releasing tor browser updates and closing t…"
T1090.002External Proxy
91%
"on the other hand, are anything but simple and safe. a tor exit node will appear to the internet as if it were the actual user on the other side of tor. the user could be a researcher. or a journalist. or a spy. or a child pornographer. or a digital pirate. or a hacker. the only …"
T1090.003Multi-hop Proxy
89%
"fortunately, the tor project gives instructions on how to configure your tor exit node to filter out torrent and other troublesome traffic. 5 i also didn ’ t want tor hogging all my bandwidth, so i configured it with what i thought were sane defaults for maximum input and output …"
T1090.003Multi-hop Proxy
88%
"home had been globally marked as a tor exit node, and sites were ( correctly ) blocking my traffic. i usually recommend to customers i talk to that they do the same. while, yes, newspapers should accept tor traffic because they are dealing in a trade where the free flow of news i…"
T1090.003Multi-hop Proxy
83%
"load balancer to specifically deliver http. traffic destined for port 80 started flowing through it — it was actually about half the traffic exiting the tor node. so, the system was all set up to fully snoop on http connections exiting my tor node. things i could have done to tha…"
T1090.003Multi-hop Proxy
80%
"snooping on tor from your load balancer a couple of years ago i was assigned a simulation project for a new technology that mapped and categorized outbound end - user traffic. i thought, “ hmmm, where can i get live user traffic? ” the idea of simulating end - user traffic via sc…"
T1090.002External Proxy
79%
"into the proxy to count the number of unprotected login pages passing through it. i did not record, or even look for, user credentials. on a typical day, i saw about 2, 000 unprotected login pages passing through my tor exit node. i found that number extremely high, and worrisome…"
T1090.003Multi-hop Proxy
72%
"local pawnshop, wiped the hard drive, and installed my favorite linux distribution, ubuntu server. i followed the tor project ’ s instructions on installing and configuring a tor exit node. ( i was about to link to those instructions, but here ’ s a much, much better guide to run…"
T1090.003Multi-hop Proxy
65%
"and renewed my isp lease to get a new ip address. was it worth it? ultimately, there was a decent amount of satisfaction to be gained from running the tor exit node. the project i ’ d been assigned that ultimately required the user traffic got postponed, which deprioritized the n…"
T1090.002External Proxy
64%
"forwarded back out to the internet and couldn ’ t probe my internal network. i defined a single virtual server on the inbound side of the load balancer to forward incoming tor traffic ( in - tor2 ) directly to the exit node on port 9001, and then another virtual server to forward…"
T1090.003Multi-hop Proxy
59%
"forwarded back out to the internet and couldn ’ t probe my internal network. i defined a single virtual server on the inbound side of the load balancer to forward incoming tor traffic ( in - tor2 ) directly to the exit node on port 9001, and then another virtual server to forward…"
T1090.002External Proxy
57%
"local pawnshop, wiped the hard drive, and installed my favorite linux distribution, ubuntu server. i followed the tor project ’ s instructions on installing and configuring a tor exit node. ( i was about to link to those instructions, but here ’ s a much, much better guide to run…"
T1090.003Multi-hop Proxy
56%
"into the proxy to count the number of unprotected login pages passing through it. i did not record, or even look for, user credentials. on a typical day, i saw about 2, 000 unprotected login pages passing through my tor exit node. i found that number extremely high, and worrisome…"
T1090.002External Proxy
48%
"load balancer to specifically deliver http. traffic destined for port 80 started flowing through it — it was actually about half the traffic exiting the tor node. so, the system was all set up to fully snoop on http connections exiting my tor node. things i could have done to tha…"
T1090.002External Proxy
33%
"snooping on tor from your load balancer a couple of years ago i was assigned a simulation project for a new technology that mapped and categorized outbound end - user traffic. i thought, “ hmmm, where can i get live user traffic? ” the idea of simulating end - user traffic via sc…"

Summary

An F5 Labs researcher snoops on Tor exit node traffic from a load balancer. What he finds will shock you. SHOCK YOU.