RSS

(ab)using Tor to spy on connections

Wed, Feb 13, 2008

Security

I saw a reference to this article recently. I knew how Tor worked but never really go under the hood of the exit servers. Well apparently some others have and are setting up their own exit servers for nefarious purposes. It seems as though if you setup an exit server you can specify what ports you want to allow through it. By default I believe it will allow any. If I were to setup an exit server and only allow ports 23, 110 and 143, what do you think I would be able to see?  Passwords. To top it off it looks like anyone can setup their own exit server.

Brilliant.

The moral of the story…unencrypted logins will get you into trouble.

–Chris

Technorati Tags: , ,

Print Friendly

This post was written by:

- who has written 173 posts on InfoSecPodcast.com.


Contact the author

Leave a Reply

Bad Behavior has blocked 1013 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.