[tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Fabio Pietrosanti (naif)
I made a big portscan+app fingerprinting of all Tor exit and Relay: wget -q -O /tmp/Tor_ip_list_ALL.csv \ http://torstatus.blutmagie.de/ip_list_all.php/Tor_ip_list_ALL.csv nmap -iL /tmp/Tor_ip_list_ALL.csv -F -sS -sV -PI -T Insane \ -oM Tor-Scan-20-12-2011_00_30.out You can find the result

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Andrew Lewman
On Tue, 20 Dec 2011 09:11:29 +0100 Fabio Pietrosanti (naif) li...@infosecurity.ch wrote: Or a process like that to always know that the System/Network security of computers running Tor it's ok, and if not ok do something. Perhaps you are interested in the exit authority code,

[tor-talk] Exit enclaves

2011-12-20 Thread tor
Hi, I have some questions regarding enclaved servers and hope you can help me finding the answer to these questions. I have tried to find those answers on this mailing list and also in the TOR documentation and the wiki, but to no avail. If my questions have been answered over and over again

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Lee
On 12/20/11, Fabio Pietrosanti (naif) li...@infosecurity.ch wrote: I made a big portscan+app fingerprinting of all Tor exit and Relay: [.. snip ..] Which is why I stopped running a relay - wy too many people poking at my machine. In retrospect I was probably just incredibly naive, but

Re: [tor-talk] Tor 0.2.3.9-alpha is out

2011-12-20 Thread Nick Mathewson
On Tue, Dec 20, 2011 at 3:37 PM, Nick Mathewson ni...@alum.mit.edu wrote: I've added this as #4572 at https://trac.torproject.org/projects/tor/ticket/4752 ; more thinking is needed about the best solution. Oops; both of those numbers should be 4752. sorry there, -- Nick

Re: [tor-talk] Suggest a new name for the Torouter, win an Excito B3

2011-12-20 Thread Runa A. Sandvik
Hi everyone, We have received a lot of good naming suggestions for the Excito B3 Torouter, thank you to everyone who emailed us! We have decided that the new name for the Excito B3 Torouter is onionbox. An email has gone out to the lucky winner of a B3, a t-shirt and some stickers, as well as

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Lee
On 12/20/11, Nick Mathewson ni...@alum.mit.edu wrote: On Tue, Dec 20, 2011 at 1:35 PM, Fabio Pietrosanti (naif) li...@infosecurity.ch wrote: Absolutely brilliant. Someone donates to your cause and, if they don't come up to your standards, you do your best to ensure they get pwned instead of

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Chris
Security trough obscurity doesn't scale, so what' the problem? The problem is that I don't know you, I don't know your intentions, and I haven't given you permission to do a security audit, free or otherwise, on my machine. You need to GET PERMISSION FIRST or you're behaving exactly like

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Fabio Pietrosanti (naif)
On 12/20/11 8:06 PM, Nick Mathewson wrote: On Tue, Dec 20, 2011 at 1:35 PM, Fabio Pietrosanti (naif) li...@infosecurity.ch wrote: Absolutely brilliant. Someone donates to your cause and, if they don't come up to your standards, you do your best to ensure they get pwned instead of just

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Klaus Layer
Lee ler...@gmail.com wrote on 20.12.2011: Which is why I stopped running a relay - wy too many people poking at my machine. In retrospect I was probably just incredibly naive, but when I put up a tor relay I was expecting to just relay tor traffic. I did not sign up to be the target of

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread Mike Damm
On Dec 20, 2011, at 2:54 PM, Chris tmail...@errtech.com wrote: Security trough obscurity doesn't scale, so what' the problem? The problem is that I don't know you, I don't know your intentions, and I haven't given you permission to do a security audit, free or otherwise, on my machine. You

Re: [tor-talk] Automatic vulnerability scanning of Tor Network?

2011-12-20 Thread grarpamp
Which is why I stopped running a relay - wy too many people poking at my machine.  In retrospect I was probably just incredibly naive, but when I put up a tor relay I was expecting to just relay tor traffic.  I did not sign up to be the target of any wannabe pen tester. For me it is