Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

[Full-disclosure] Active Web->Tor CGI proxies.

Subject: [Full-disclosure] Active Web->Tor CGI proxies.
Date: Tue, 22 Apr 2008 09:12:02 -0400
Not my doing, but good news never the less.
www.torproxy.net
Now with 100% more hidden service url support!
Time to lighthttpd+tor your servers for hosting delicious contents for
wgetting fun. Kids: don't forget to encrypt those sweet unreleased,
unreported, unknown, private, exploits.
Time to put up black markets and spam the links about.
Backends for your phishing pages, botnet control, 'js zombie' control.
I bet you could even whip up a sweet google maps GIS (oh I know I
have). Simple SQL botnet control anyone?

Diffie Hellman in Javascript that delivers encapsulated HTTP to
browsers please, could make an interesting BBS interface with real
member to member encrypted and private chat (high latency granted.)
You could even do some simple digital signature support to protect
against rogue TOR nodes. I had envisioned a system that would enforce
you after signup to connect through 3 distinct endpoints to collect
the key and make sure it was consistent, and providing simple loader
source that can be easily verified that loads the prompt to verify the
signature. Login would be hash the source from 3 locations to make
sure it's all the same, include all grabbed javascript. Then verify
that the presented signature is valid. It's not perfect but better
than nothing and obviously more anonymous than SSL.
Too bad math in JS is massively slow.

In the words of Andrew Weeblsoi: There's no point in hiding any more.

IRL,

Travis

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>
  • [Full-disclosure] Active Web->Tor CGI proxies., T Biehn <=