Tor Project To Fix Bug Used For DDoS Attacks On Onion Sites For Years

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+Sdg8=gd9-kQs4tZo2mt53MsvKXU11+pao8+_fsic41Q@mail.gmail.com>
'"The Tor Project is preparing a fix for a bug that has been abused
for the past years to launch DDoS attacks against dark web (.onion)
websites," reports ZDNet. "Barring any unforeseen problems, the fix is
scheduled for the upcoming Tor protocol 0.4.2 release." The bug has
been known to Tor developers for years, and has been used to launch
Slow Loris-like attacks on the web servers that run the Tor service
supporting an .onion site. It works by opening many connections to the
server and maxing out the CPU. Since Tor connections are CPU intensive
because of the cryptography involved to support the privacy and
anonymity of the network, even a a few hundreds connections are enough
to bring down dark web portals. A tool to exploit the bug and to
automate DDoS attacks has been around for four years, and has been
used by hackers to extort dark web marketplaces all spring. At least
two markets selling illegal products have shut down after refusing to
pay attackers. To get the bug fixed, members of a dark web forum
banded together and donated to the Tor Project to sponsor the bug's
patch.'

-- source: https://it.slashdot.org/story/19/07/05/208230

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.