SSH IP Spoofing Attack on Tor

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 พ.ย. 2024

ความคิดเห็น • 57

  • @Sam_Bent
    @Sam_Bent  3 วันที่ผ่านมา +4

    One Weird trick article: delroth.net/posts/spoofed-mass-scan-abuse/ [thanks john for reminding me]
    OONI Probe/test for Relay Ops: ooni.org/install/
    Template for abuse complaints: gitlab.torproject.org/tpo/network-health/analysis/-/issues/85#note_3126618Dir Autorities getting abuse complaints: gitlab.torproject.org/tpo/network-health/analysis/-/issues/85
    Tor Project sysadmin team: gitlab.torproject.org/tpo/tpa/team/-/issues/41840 (technical details)
    Tor Relay Ops: community.torproject.org/relay/
    Tor Dir. Authorities: community.torproject.org/relay/governance/policies-and-proposals/directory-authority/
    GreyNoise: www.greynoise.io/
    InterSecLab: www.opentech.fund/projects-we-support/supported-projects/interseclab/
    Ignore abuse reports from "watchdogcyberdefense.com": seclists.org/nanog/2024/Nov/24

  • @Acid741981
    @Acid741981 2 วันที่ผ่านมา +2

    Thanks a lot for the info on that. I was on vacation when my provider sent the abuse complaint and could not immediately react to it. There are finally some answers... Would appreciate an update if there's more knowledge about the actual attacker.
    Great vid as always.

  • @ProfessorLinux
    @ProfessorLinux 2 วันที่ผ่านมา +1

    Great setup. I love your background and lighting❤

  • @BangBangBang.
    @BangBangBang. 2 วันที่ผ่านมา +3

    I used to work for a a large IaaS/hosting provider. There's so much garbage usually automated sent to the abuse desk that thats why providers don't really do much on it. Don't use automated tools to flood abuse contacts over the smallest things.
    It's usually copyright complaints, network stuff (pings/scans/connects) and spam with law enforcement/data retention requests sent in.
    Hey FYI that $4 VPS you're paying for, we're handing over any and all info to anybody with a law enforcement letterhead they're faxing/emailing to the record request contact. That's widespread in the industry. That's why VPN ads on TH-cam make me laugh so hard

    • @Sam-rr4ek
      @Sam-rr4ek 2 วันที่ผ่านมา

      @@BangBangBang. so the only good VPN is mullvad?

  • @fd20231
    @fd20231 วันที่ผ่านมา +1

    Thanks for the info big homie!!!
    Appreciate the video once again. Also,
    looking yoked bro! NO DIDDY
    Been working out or is it the winter 15 where thanksgiving just keeps on giving cuz im suffering from the latter myself 😂😂

  • @oOEmberOo
    @oOEmberOo 3 วันที่ผ่านมา +3

    I appreciate your angle

  • @nezu_cc
    @nezu_cc 3 วันที่ผ่านมา +7

    Oh so that's why my ISP is mad, damn

  • @effsixteenblock50
    @effsixteenblock50 2 วันที่ผ่านมา +1

    Here's how I'm thinking the guy got caught:
    The traffic that would eventually tell the tale to investigators would be the TCP SYN packets that timed out, of which, in such a high volume there would be many.
    If there were enough of them, they could sort of "work backwards" to find his basic location, assuming he didn't fiddle with the TTLs. They could see where a packet was when it timed out and since some ASs are only reachable from a single path, they could get one piece of the puzzle at a time. Again, there would have to be a ton of traffic to do this but thankfully there obviously was.
    If the guy would have randomized the TTLs, he probably wouldn't have been caught.
    Another thing that could contribute to him revealling his whereabouts would be if there was something unique or non-standard in any of the TCP f(or even lower layers) fields. Some TCP stacks are by default slightly different - TCP window, TCP options etc..
    Either way, I'm sure it involved a sh!t-ton of work. Hats off to the folks that did it!

  • @rakly3473
    @rakly3473 2 วันที่ผ่านมา +4

    Your diagram is wrong. You connect Exit to onion service. That's never how a tor connection to a onion service works.
    I run a node, there were some issues triggering my DDoS protection. Other than that, I didn't really experience much trouble.
    My node remained operative, But I had to temporarily separate the node from the rest of my network (just a simple virtual lan) to stop the flooding from the node to my other devices. - I don't know the intricacies of the whole thing, just that my firewall had blocked all my wired connected devices from being reachable. (meaning, no inbound connections were accepted)

  • @joshuatimothy2966
    @joshuatimothy2966 2 วันที่ผ่านมา

    Thanks for the update, keep doing your thing

  • @noprivacyverner
    @noprivacyverner 3 วันที่ผ่านมา +14

    sound more like some was mapping the network or trying to i bet it was first round

    • @MikeJones-mf2rt
      @MikeJones-mf2rt 2 วันที่ผ่านมา +1

      Unit 8200

    • @NYC__101
      @NYC__101 2 วันที่ผ่านมา

      @@MikeJones-mf2rt 🙊🐵🙈

    • @naesone2653
      @naesone2653 วันที่ผ่านมา

      Interesting can u go more in-depth

    • @GOOGLE-IS-EVIL-EMPIRE
      @GOOGLE-IS-EVIL-EMPIRE วันที่ผ่านมา

      ​@@MikeJones-mf2rtwhat is unit 8200?

  • @chams7960
    @chams7960 2 วันที่ผ่านมา +3

    Hey sam ! Can you make a step by step guide on how to be safe? From buying a laptop to being safe in the net? That would be crazy content!

    • @joshuatimothy2966
      @joshuatimothy2966 2 วันที่ผ่านมา +3

      I think the opsec bible has something similar to it

    • @chams7960
      @chams7960 2 วันที่ผ่านมา +1

      @ okay I’ll check that, I thought it would be really interesting to see how he set up his computer

    • @ashahahaha
      @ashahahaha 2 วันที่ผ่านมา

      See his Defcon talks :)

    • @TevynSmith
      @TevynSmith 2 วันที่ผ่านมา

      This isn’t direct advice but hypothetically in theory, make sure you run tails with Ethernet only and to have 16GB of ram to be most optimal

    • @joshuatimothy2966
      @joshuatimothy2966 2 วันที่ผ่านมา

      @@TevynSmith as well as flashing the BIOS/UEFI to CoreBoot/LibreBoot and other open source boot loaders

  • @stevez5134
    @stevez5134 3 วันที่ผ่านมา +6

    would it be better to just use i2p?

    • @elguero933
      @elguero933 2 วันที่ผ่านมา +1

      It has no exit to clearnet

    • @zeus1141
      @zeus1141 2 วันที่ผ่านมา

      @@stevez5134 and is significantly smaller network and older tech.

    • @ashahahaha
      @ashahahaha 2 วันที่ผ่านมา

      ​@elguero933 tbh good, dummy proof :P

  • @serenditymuse
    @serenditymuse 2 วันที่ผ่านมา +1

    Why do we need centralized control nodes? It could be done more on event decoupled basis where nothing knows about all the relays. Instead the relays respond to and put information about state on an event bus. If done right the IP addresses of relays may not be known with any dependably so difficult to spoof traffic from them.

  • @JoeBrown-b7w
    @JoeBrown-b7w 46 นาทีที่ผ่านมา

    Can you do a video explaining how to pgp encrypt a message?

  • @dennisestenson7820
    @dennisestenson7820 2 วันที่ผ่านมา +1

    I'm 46 and if I had never shaved my beard in my life, it wouldn't be half that long.

  • @Iris_and_or_George
    @Iris_and_or_George 2 วันที่ผ่านมา +1

    Ooofff dat leet runtime!

  • @henrik2117
    @henrik2117 3 วันที่ผ่านมา +1

    Your humour is the best! 😅

  • @wildweasel3001
    @wildweasel3001 2 วันที่ผ่านมา +1

    If you don't need to see the response you can spoof TCP messages.

  • @deannawolfe3900
    @deannawolfe3900 วันที่ผ่านมา

    Bro you should cover whatever is up with abacus market

  • @davegebbings7632
    @davegebbings7632 2 วันที่ผ่านมา

    Thanks Sam

  • @djksfhakhaks
    @djksfhakhaks 2 วันที่ผ่านมา +3

    Omfg. Your beard is Sun Microsystems "Im so valuable im alloud to live in the mountans and just think things up" worthy.

  • @The0men710
    @The0men710 2 วันที่ผ่านมา

    grate VHS video /me bows down ^_^ dank -bg lol

  • @TevynSmith
    @TevynSmith 2 วันที่ผ่านมา +1

    You seem like your personality is never up or down always stable, what do you attribute that to?

    • @Sam_Bent
      @Sam_Bent  วันที่ผ่านมา

      Lack of emotion. I'm an INTP-A and a Sigma. If I had to guess.

    • @TevynSmith
      @TevynSmith วันที่ผ่านมา

      @@Sam_Bent you remind me of a Patrick Bateman type , but with no smiling

  • @SALTINBANK
    @SALTINBANK 2 วันที่ผ่านมา

    Great video and iam thinking that the level of complexity involved give us a clear picture who is doing that and this a not a skidz job ...

    • @The0men710
      @The0men710 2 วันที่ผ่านมา

      ya be surprised in 2024 =) maybe not a script kiddy, but as young as a teen could to boot in his mothers basement =) =)
      if ya know ya know lol and ssh every hacker knows =)
      from what i know when the kids connect their terminals to tor thast when they get cray cray lol
      hahahahha look at nightmare market lol
      yeah it was just a kid lol SMRK lol
      look at vendors pretty faces one that coems to mind over here is NSWgrate

  • @AndreeaCe
    @AndreeaCe 3 วันที่ผ่านมา

    Ever read what not to send via classic mail network?
    Don't send cash, jewellery or other high value goods...will be stolen. This being one side of the coin.

  • @awesomesauce804
    @awesomesauce804 2 วันที่ผ่านมา

    Personal opinion -- the original use case for tor is no longer necessary because the ships can use starlink ( dod paid for low earth orbit gps replacement satellites and elon took advantage with starlink ). So, tor is a problem now and there are other opsec friendly covert networks for government communication. Get ready for tor as you know it to be relentlessly assaulted and perhaps eventually gone. This is all a personal opinion and i am a no one from nowhere.

    • @etziowingeler3173
      @etziowingeler3173 วันที่ผ่านมา

      Starlink has replaced Tor? lul ok

    • @awesomesauce804
      @awesomesauce804 วันที่ผ่านมา

      @etziowingeler3173 no? Go read how tor came to be. The US Navy invented it.

  • @ZambeziSentinel
    @ZambeziSentinel วันที่ผ่านมา

    What's crazy is it's not hard 😂

  • @whenindoubtgotowikipedia.8292
    @whenindoubtgotowikipedia.8292 2 วันที่ผ่านมา

    Skid

  • @mikemaldanado6015
    @mikemaldanado6015 2 วันที่ผ่านมา

    If you want to maintain any sort of integrity you need to put out a correction video regarding the silk road. You're entire video was false. Dread Pirate Roberts was never even charged for running silk road, he got two life sentences for conspiracy to murder 8 people. It's sad that you won't like all other youtubers that get shit wrong, Then u wonder why nobody can agree on anything anymore.... it's mostly to do with youtube/redddit, etc.. how do u expect people to believe any of your videos now? whatevs. unsub.

    • @Sam_Bent
      @Sam_Bent  วันที่ผ่านมา

      reason.com/2018/07/25/ross-ulbrichts-murder-for-hire-charges-d/
      Amplified through inaccurate and sensationalized reporting, these false murder-for-hire allegations were used to deny Ross Ulbricht’s bail, smear him in the media, and justify the life sentence he ultimately received.
      Ross was never tried for these allegations, which means the allegations were never ruled on by a jury and Ross was never found guilty of paying to have anyone killed. These unproven and unprosecuted accusations were eventually dismissed “with prejudice” in 2018, and therefore can never be re-filed or used against Ross again.
      The allegations were never proven in court and relied on anonymous chats and text files never proven to have been authored by Ross. Hard evidence and testimony-including from the lead Silk Road investigator-show that, over time, multiple people were behind the site admin’s handle (who was called Dread Pirate Roberts or “DPR” for short). Two corrupt federal investigators (sent to prison) also had unfettered access to Silk Road and were admittedly involved in numerous plots.
      Ross has always denied being involved with these allegations. And even Curtis Green, the only alleged victim ever identified in these allegations, has spoken out against these allegations and is a longtime, fervent supporter of Ross’s release.
      freeross.org/false-allegations/