Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Nick Mathewson
On Sat, Oct 27, 2007 at 05:46:33PM -0400, Roger Dingledine wrote:
> On Sat, Oct 27, 2007 at 08:12:58PM +0200, Fabian Keil wrote:
> > > Oct 27 18:32:00.180 [err] Bug: container.c:828: strmap_get: Assertion map 
> > > failed; aborting.
> > 
> > Not using MyFamily works around the problem
> > (and in my case it's not necessary anyway).
> > 
> > Maybe specifying the MyFamily nodes by fingerprint
> > would have worked as well, but I didn't figure out
> > an acceptable fingerprint format yet ...
> 
> Hi Fabian,
> 
> Thanks for the bug report. I may have fixed it here:
> http://archives.seul.org/or/cvs/Oct-2007/msg00511.html
> 
> If you could tweak your local copy of the code and see if that fixes
> the crash for you, that would be great.
> 
> (This might also be totally the wrong fix. I'll let Nick take a look at
> it too before 0.2.0.10-alpha comes out. :)

There's a deeper problem at work, too; I've added this as Bug 538:
 https://bugs.torproject.org/flyspray/index.php?id=538&do=details

yrs,
-- 
Nick Mathewson


pgp3ksugWnFZm.pgp
Description: PGP signature


Re: An other tor-proxy

2007-10-27 Thread TOR Admin (gpfTOR1)

Ringo Kamens schrieb:

It might help to make links to certain sites in this list topic so
that google will index them. For instance:
awxcnx dotde/tor-i2p-proxy-en.htm?JASDJHSDF.ONION


Nice idea, we have done the job and hope, google will like our links.


That way, google gets to them and can do all of the hard indexing leg
work. The wikis would be a good place to link to.
Comrade Ringo Kamens


More wikis we will be linked to, but not this night.
Greetings


Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Roger Dingledine
On Sat, Oct 27, 2007 at 08:12:58PM +0200, Fabian Keil wrote:
> > Oct 27 18:32:00.180 [err] Bug: container.c:828: strmap_get: Assertion map 
> > failed; aborting.
> 
> Not using MyFamily works around the problem
> (and in my case it's not necessary anyway).
> 
> Maybe specifying the MyFamily nodes by fingerprint
> would have worked as well, but I didn't figure out
> an acceptable fingerprint format yet ...

Hi Fabian,

Thanks for the bug report. I may have fixed it here:
http://archives.seul.org/or/cvs/Oct-2007/msg00511.html

If you could tweak your local copy of the code and see if that fixes
the crash for you, that would be great.

(This might also be totally the wrong fix. I'll let Nick take a look at
it too before 0.2.0.10-alpha comes out. :)

Thanks!
--Roger



Re: An other tor-proxy

2007-10-27 Thread Ringo Kamens
It might help to make links to certain sites in this list topic so
that google will index them. For instance:
awxcnx dotde/tor-i2p-proxy-en.htm?JASDJHSDF.ONION
That way, google gets to them and can do all of the hard indexing leg
work. The wikis would be a good place to link to.
Comrade Ringo Kamens

On 10/27/07, TOR Admin (gpfTOR1) <[EMAIL PROTECTED]> wrote:
> Hi,
>
> we like the idea of https://tor-proxy.net and we setup an other
> TOR-proxy and an I2P-proxy, see:
>
> https://www.awxcnx.de/tor-i2p-proxy-en.htm
>
> or for german people:
>
> https://www.awxcnx.de/tor-i2p-proxy.htm
>
> The main goal of our proxy is, to make hidden services (TOR) and
> eepsites (I2P) accessible by more people. Anonymous surfing is possible
> too, but not highly recommended.
>
> Ads, referer, user-agent ... are removed/modified by privoxy, cookies
> may be removed by activating a checkbox (some sites like hidden
> messaging need cookies). Java and Javascript has to be disabled in your
> browser, because we can not do this job.
>
> May be, it will help someone.
>


An other tor-proxy

2007-10-27 Thread TOR Admin (gpfTOR1)

Hi,

we like the idea of https://tor-proxy.net and we setup an other 
TOR-proxy and an I2P-proxy, see:


   https://www.awxcnx.de/tor-i2p-proxy-en.htm

or for german people:

   https://www.awxcnx.de/tor-i2p-proxy.htm

The main goal of our proxy is, to make hidden services (TOR) and 
eepsites (I2P) accessible by more people. Anonymous surfing is possible 
too, but not highly recommended.


Ads, referer, user-agent ... are removed/modified by privoxy, cookies 
may be removed by activating a checkbox (some sites like hidden 
messaging need cookies). Java and Javascript has to be disabled in your 
browser, because we can not do this job.


May be, it will help someone.


Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Fabian Keil
Fabian Keil <[EMAIL PROTECTED]> wrote:

> Roger Dingledine <[EMAIL PROTECTED]> wrote:
> 
> > This ninth development snapshot switches clients to the new v3 directory
> > system; allows servers to be listed in the network status even when they
> > have the same nickname as a registered server; and fixes many other bugs
> > including a big one that was causing some servers to disappear from the
> > network status lists for a few hours each day.
> 
> My client seems to work, but both of my servers abort with:
> 
> Oct 27 18:31:57.221 [notice] Tor 0.2.0.9-alpha (r12180) opening log file.
> Oct 27 18:31:57.222 [warn] Can't log to stdout with RunAsDaemon set; skipping 
> stdout
> Oct 27 18:31:57.250 [warn] Unable to open "/var/run/tor/tor.pid" for writing: 
> No such file or directory
> Oct 27 18:31:57.683 [warn] I have no descriptor for the router named 
> "Zwiebelsuppe" in my declared family; I'll use the nickname as is, but this 
> may confuse clients.
> Oct 27 18:31:57.698 [notice] Your Tor server's identity key fingerprint is 
> 'Zwiebelkuchen 8666 742C 9AD2 D3B3 028E 1FB7 C7E6 12F7 4340 BD05'
> Oct 27 18:31:57.699 [notice] Configured hibernation.  This interval began at 
> 2007-10-27 17:25:00; the scheduled wake-up time was 2007-10-27 17:25:00; we 
> expect to exhaust our quota for this interval around 2007-10-28 17:25:00; the 
> next interval begins at 2007-10-28 17:25:00 (all times local)
> Oct 27 18:32:00.180 [err] Bug: container.c:828: strmap_get: Assertion map 
> failed; aborting.

Not using MyFamily works around the problem
(and in my case it's not necessary anyway).

Maybe specifying the MyFamily nodes by fingerprint
would have worked as well, but I didn't figure out
an acceptable fingerprint format yet ...

Fabian


signature.asc
Description: PGP signature


Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Marco Bonetti
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

[EMAIL PROTECTED] wrote:
> Sure.  We set the following variables to 0:
thanks!

- --
Marco Bonetti
Slackintosh Linux Project Developer: http://www.slackintosh.org
Linux-live for powerpc: http://www.slackintosh.org/pub/rsync/mb/linux-live
My webstuff: http://sidbox.homelinux.org

My GnuPG key id: 0x86A91047
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHI3GtE3eWALCzdGwRAgajAJ4vRziaj7cAWbcHFykzuqDCSx54vwCfUMmO
V6fCudCFTGZHK1lRzGpId+I=
=fLfc
-END PGP SIGNATURE-


Re: Firefox IPv6 Anonymity bypass NOT A BUG

2007-10-27 Thread Ringo Kamens
Thanks for the clarification. It's much easier to understand now.
Comrade Ringo Kamens

On 10/26/07, Nick 'Zaf' Clifford <[EMAIL PROTECTED]> wrote:
> Nick 'Zaf' Clifford wrote:
> > Hey ya,
> >
> > Just noticed one small problem with Tor + Firefox + IPv6.
> > I'm aware that Tor doesn't yet support IPv6, but I found an interesting
> > development with respect to a system that has IPv6 configured and working.
> >
> >
> Embarrassing confession time:
> When I first noticed this "bug", I didn't realize I'd set a proxy bypass
> for .nrc.co.nz (my local domain) a long time ago when doing other proxy
> testing. This meant when I went to a .nrc.co.nz address, it did so
> directly, bypassing any proxy.
>
> When I eventually started playing with Tor, I had forgotten about that
> setting (and use TorButton so never even looked at the proxy settings of
> Firefox).
> The end result was that I went to a local system, it bypassed Tor (as
> I'd asked it to do).
>
> All of my systems here have IPv6 (and some of them don't have IPv4), so
> when I saw that I was able to connect to my internal network systems,
> supposedly via tor (having forgotten that I'd set that proxy bypass ages
> ago), I became suspicious, and looked at the system logs, saw my own
> IPv6 address, and went "Ah ha!". That lead to the above bug report.
>
> The questions you have all raised in response to my report (with
> reference to it being network.dns.IPv6, and asking if it still disabled
> numerical addresses), prompted me to do further testing, where I found
> conflicting results, that lead me to notice the .nrc.co.nz proxy bypass.
>
> So, after doing more testing, the results are:
> If you set up Firefox to use Privoxy and Tor, All requests go to Privoxy
> (this is obvious if you think about it, because otherwise Firefox would
> have to do DNS lookups on hostnames to notice they are IPv6, which would
> be a big huge leak).
> Privoxy takes the hostname, and does an IPv4 lookup (eg it doesn't
> support v6), so feeds the request through Tor as expected and desired.
> To round out the testing, and provide answers to all:
> If you give privoxy an IPv6 numerical address, eg:
> http://[2002:x:1]/, privoxy fails to recognise the address at all as
> being an IPv6 address, and therefore fails gracefully:
> Your request for http://[2002::1]/ could not be fulfilled, because
> the domain name *[2002* could not be resolved.
>
> This is fine, and therefore I respectfully withdraw by bug report, and
> apologize to the Firefox developers, as I commented that it was probably
> a bug in Firefox.
>
> I'd also like to thank all of you on the mailing list who immediately
> recognized what this may have been (had it been accurate) and
> acknowledged my find and started fixing your own systems.
>
> So to everyone, stand down, not a bug, the problem was a PEBKAC (Problem
> Exists Between Keyboard And Chair)
> Thanks,
> Nick Clifford
>
>


Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Fabian Keil
Roger Dingledine <[EMAIL PROTECTED]> wrote:

> This ninth development snapshot switches clients to the new v3 directory
> system; allows servers to be listed in the network status even when they
> have the same nickname as a registered server; and fixes many other bugs
> including a big one that was causing some servers to disappear from the
> network status lists for a few hours each day.

My client seems to work, but both of my servers abort with:

Oct 27 18:31:57.221 [notice] Tor 0.2.0.9-alpha (r12180) opening log file.
Oct 27 18:31:57.222 [warn] Can't log to stdout with RunAsDaemon set; skipping 
stdout
Oct 27 18:31:57.250 [warn] Unable to open "/var/run/tor/tor.pid" for writing: 
No such file or directory
Oct 27 18:31:57.683 [warn] I have no descriptor for the router named 
"Zwiebelsuppe" in my declared family; I'll use the nickname as is, but this may 
confuse clients.
Oct 27 18:31:57.698 [notice] Your Tor server's identity key fingerprint is 
'Zwiebelkuchen 8666 742C 9AD2 D3B3 028E 1FB7 C7E6 12F7 4340 BD05'
Oct 27 18:31:57.699 [notice] Configured hibernation.  This interval began at 
2007-10-27 17:25:00; the scheduled wake-up time was 2007-10-27 17:25:00; we 
expect to exhaust our quota for this interval around 2007-10-28 17:25:00; the 
next interval begins at 2007-10-28 17:25:00 (all times local)
Oct 27 18:32:00.180 [err] Bug: container.c:828: strmap_get: Assertion map 
failed; aborting.

#0  0x28416ad7 in kill () from /lib/libc.so.7
#1  0x28336e66 in raise () from /lib/libthr.so.3
#2  0x2841576a in abort () from /lib/libc.so.7
#3  0x080f937a in strmap_get (map=0x0, key=0x28c46a80 "zwiebelkuchen") at 
container.c:828
#4  0x080f9ab1 in strmap_get_lc (map=0x0, key=0x28c46b20 "Zwiebelkuchen") at 
container.c:923
#5  0x080b465b in networkstatus_nickname_is_unnamed (nickname=0x28c46b20 
"Zwiebelkuchen") at networkstatus.c:885
#6  0x080d34a1 in router_get_by_nickname (nickname=0x28c46b20 "Zwiebelkuchen", 
warn_if_unnamed=1) at routerlist.c:1703
#7  0x080cd16c in router_rebuild_descriptor (force=0) at router.c:1235
#8  0x080cc97c in router_get_my_routerinfo () at router.c:1099
#9  0x080d4bfb in routerlist_insert (rl=0x2852a9e0, ri=0x285395e0) at 
routerlist.c:2157
#10 0x080d6b7b in router_add_to_routerlist (router=0x285395e0, msg=0xbfbfeae8, 
from_cache=1, from_fetch=0) at routerlist.c:2675
#11 0x080d7db4 in router_load_routers_from_string (s=0x289af436 "", 
eos=0x289af436 "", saved_location=SAVED_IN_CACHE, 
requested_fingerprints=0x0, descriptor_digests=0, prepend_annotations=0x0) 
at routerlist.c:3066
#12 0x080d0452 in router_reload_router_list_impl (store=0x2852a9f8) at 
routerlist.c:635
#13 0x080d067c in router_reload_router_list () at routerlist.c:685
#14 0x080b0dc0 in do_main_loop () at main.c:1356
#15 0x080b2339 in tor_main (argc=15, argv=0xbfbfecec) at main.c:1932
#16 0x080ebd12 in main (argc=Cannot access memory at address 0x3
) at tor_main.c:28

Fabian


signature.asc
Description: PGP signature


Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread Roger Dingledine
On Sat, Oct 27, 2007 at 12:37:33AM +0200, Marco Bonetti wrote:
> Roger Dingledine wrote:
> > We also modified the default Privoxy config files in the bundles to
> > avoid some security problems, so make sure to leave "install Privoxy"
> > checked when you upgrade.
> could you be more verbose about privoxy tweaking?
> just for the rest of us which do not use the bundle ;-)

Give us a few days to put out 0.1.2.18, and then I'll go into more
details beyond what phobos sent. :) They aren't earth-shattering issues,
unless you're trusting your privoxy to keep your anonymity for you --
which probably isn't a good idea in the first place. Use a modern Firefox
plus the dev version of Torbutton and you should be fine.

More news soon I hope,
--Roger



Re: Tor 0.2.0.9-alpha is out

2007-10-27 Thread phobos
On Sat, Oct 27, 2007 at 12:37:33AM +0200, [EMAIL PROTECTED] wrote 0.8K bytes in 
28 lines about:
: > We also modified the default Privoxy config files in the bundles to
: > avoid some security problems, so make sure to leave "install Privoxy"
: > checked when you upgrade.
: could you be more verbose about privoxy tweaking?
: just for the rest of us which do not use the bundle ;-)

Sure.  We set the following variables to 0:

enable-remote-toggle
enable-remote-http-toggle
enable-edit-actions

cheers.

-- 
Andrew


Re: Firefox IPv6 Anonymity bypass

2007-10-27 Thread Juliusz Chroboczek
> If you are using Tor (and have Firefox configured to use the HTTP
> proxy), Firefox will not use the proxy for IPv6 traffic.

Nonsense.  At the time at which Firefox decides whether to make
a request through a proxy, it doesn't yet know whether the target
server has an IPv6 address.

What you're seeing is probably some other issue, which it would be
good to clarify.

Juliusz