Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: Anonymize internet access

Subject: RE: Anonymize internet access
Date: Thu, 29 Sep 2005 16:04:33 -0500
-----Original Message-----
From: Alexander Klimov [mailto:alserkli@inbox.ru] 
Sent: Wednesday, September 28, 2005 7:11 AM
To: security-basics@securityfocus.com
Subject: Re: Anonymize internet access

<snip>

* Should I snoop on the plaintext that exits through my Tor server?

No. You are technically capable of monitoring or logging plaintext
that exits your node if you modify the Tor source code or install
additional software to enable such snooping. However, Tor server
operators in the U.S. can create legal and possibly even criminal
liability for themselves under state or federal wiretap laws if they
affirmatively monitor, log, or disclose Tor users' communications,
while non-U.S. operators may be subject to similar laws. Do not
examine the contents of anyone's communications without first talking
to a lawyer.

 --
Regards,
ASK

</snip>

Hello,

Well this whole post got me interested in TOR so I went ahead and set it
up on my machine. Overall, I'm pretty impressed... the setup was simple,
and I was browsing "anonymously" in about 10 minutes. Too bad this last
statement is a little unnerving. For something that is created to help
with anonymity and privacy - having to worry about someone snooping on
my actions while using TOR is a little scary. Can someone please
elaborate on what exactly could be monitored or logged?

While we are at it Jeffrey mentioned a couple sites that helped check
your anonymity. One of those sites was:
http://www.stilllistener.com/checkpoint1/. One of the tests that they
had was a Java based test at:
http://www.stilllistener.com/checkpoint1/Java/. While running through
TOR in Firefox the page was still able to get my real IP address. I was
wondering if anyone could explain what happened and if there was anyway
around that. Thanks in advance.

Best Regards,
Josh

<Prev in Thread] Current Thread [Next in Thread>