Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Active Web->Tor CGI proxies. |
|---|---|
| Date: | Tue, 22 Apr 2008 09:12:02 -0400 |
Not my doing, but good news never the less. www.torproxy.net Now with 100% more hidden service url support! Time to lighthttpd+tor your servers for hosting delicious contents for wgetting fun. Kids: don't forget to encrypt those sweet unreleased, unreported, unknown, private, exploits. Time to put up black markets and spam the links about. Backends for your phishing pages, botnet control, 'js zombie' control. I bet you could even whip up a sweet google maps GIS (oh I know I have). Simple SQL botnet control anyone? Diffie Hellman in Javascript that delivers encapsulated HTTP to browsers please, could make an interesting BBS interface with real member to member encrypted and private chat (high latency granted.) You could even do some simple digital signature support to protect against rogue TOR nodes. I had envisioned a system that would enforce you after signup to connect through 3 distinct endpoints to collect the key and make sure it was consistent, and providing simple loader source that can be easily verified that loads the prompt to verify the signature. Login would be hash the source from 3 locations to make sure it's all the same, include all grabbed javascript. Then verify that the presented signature is valid. It's not perfect but better than nothing and obviously more anonymous than SSL. Too bad math in JS is massively slow. In the words of Andrew Weeblsoi: There's no point in hiding any more. IRL, Travis _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Security issue in Filezilla 3.0.9.2:passwordsare stored in plain text (sitemanager.xml), Joey Mengele |
|---|---|
| Next by Date: | [Full-disclosure] Boners for boffins, auto188821 |
| Previous by Thread: | [Full-disclosure] IMF 2008 - 2nd Call for Papers, Oliver Goebel |
| Next by Thread: | [Full-disclosure] Boners for boffins, auto188821 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |