Category: General|Aug 5, 2020 | Author: Admin

Disgruntled Researcher Drops Two Tor (0Days?) Vulnerabilities – Promises More Soon!

Share on

An angry researcher has dropped two Tor vulnerabilities (he calls them 0day) for similar reasons. He also pledges to drop more such bugs in the days to come.

Unpatched Tor Vulnerabilities Dropped Online Security researcher Dr. Neal Krawetz has dropped two unpatched Tor vulnerabilities online. He calls both the bugs 0days since they aren’t known or fixed. These public disclosures result from his bad experience in the past while disclosing vulnerabilities to The Tor Project. While he has detailed his experience along with some past bugs he reported, in his blog post, here we quickly review the recently disclosed vulnerabilities. The first of the two revolves around blocking users from connecting to the Tor network. As described in his blog post, Tor relies on randomly-generated TLS certificates that bear a distinct pattern. These TLS certificates are small enough to fit in a packet. Hence, a packet scanner can let the organizations track anyone attempting to connect to Tor. As stated,

When the packet sniffer sees a TLS server-side certificate, it generates a signature. If the signature matches the pattern for a Tor server, the scanner flags the connection as a Tor connection.

The second 0day explained in another blog post, also relates to blocking Tor network. This one specifically aims at detecting indirect connections to Tor. Tor offers bridges as a workaround for the users to evade blocking and connect to the Tor network. Bridges are Tor nodes not known to authorities censoring the Tor network.

However, TCP packet sniffing can once again help in blocking these indirect connections. Tor Projects Disagrees To Call The Bugs ‘Zero-day’ While Dr. Krawetz clearly calls both the bugs ‘zero-day’, The Tor Project disagrees. Briefly, they don’t consider these issues zero-day because the bugs are known and their researchers are working on them. Secondly, they do not agree with the threat severity as they believe the bugs can’t be enforced at scale.

They have shared a detailed response to ZDNet regarding Dr. Krawetz’s findings. Whenever security researchers get annoyed because a vendor did not listen to their report, the revenge comes in the form of disclosure of unpatched bugs online. It then depends on whether the bugs should be called zero-day or not.

Nonetheless, what remains crucial is to avoid any exploitation by patching the bugs at the earliest. Given the critical nature of Tor, let’s hope that the conflict resolves soon. And that the bugs remain unexploited to not result in a real-time disaster. Let us know your thoughts in the comments.

 

Sponsored Ads:

Comments:


There are already problems with them

Category: Apple|Sep 26, 2022 | Author: Admin

GTA VI-HACKER (17) should be arrested

Category: General|Sep 25, 2022 | Author: Admin

25 percent consider quitting up

Category: General|Sep 24, 2022 | Author: Admin

This is Logitech's Sky-Handened with up to 12 hours of gaming

Category: General|Sep 23, 2022 | Author: Admin

The Taliban think PUBG is too violent

Category: General|Sep 22, 2022 | Author: Admin

If YouTube crashes on the iPhone, this is the solution

Category: General|Sep 21, 2022 | Author: Admin

See the graphics RTX 40 is capable of - here are the prices - DLSS 3 only to RTX 40

Category: General|Sep 20, 2022 | Author: Admin

Now the Rockstar Monster leak comments on the GTA VI

Category: General|Sep 19, 2022 | Author: Admin

Snapchat, Tiktok and Instagram can destroy the iPhone 14 Pro

Category: Apple|Sep 18, 2022 | Author: Admin

Updated: Uber's employees did not believe what they saw: Must have become the pig-hack by 18-year-old

Category: General|Sep 17, 2022 | Author: Admin

Only one mobile lasts longer than the iPhone 14 Pro Max in a surf test

Category: Apple|Sep 16, 2022 | Author: Admin

This is the date The Sims 4 goes free

Category: General|Sep 15, 2022 | Author: Admin

Google gives up

Category: Google|Sep 14, 2022 | Author: Admin

DOWNLOAD NOW: iOS 16 has been released

Category: Apple|Sep 13, 2022 | Author: Admin

Here it is: OnePlus 11 Pro

Category: General|Sep 12, 2022 | Author: Admin
more