Security Thread

If you're using Tor for illegal activities, how safe are you and how to improve that ?

Is possible to get information, because they have EXIT Relays and that is where you can be caugh. Is not impossible, FBI and Europol or Interpol does that to catch high profile criminals.
Isn't impossible, if is little harder? Yes, but from them they are high skilled. They will try to track, and you will left traces like Login in personal Social Media with TOR, same passwords you use, they will try to match to any Social media.

And they got it, easily. With a simple password they can discover who you are. Let's talk you use "mypassowordishard2" you are the one in the world who uses that or in your country, they know your password by takedown any website in TOR, they use that password and they ask for information in Social Media, Websites they will discover you easily.

By using a password, don't you believe? Better start thinking that's possible and they do it. Most of people doesn't know that, or doesn't care about that, but that is a TRACE.
 
No the website is called any.run :)
This is actually really cool! This sounds like a great service. Seems like they run dynamic analysis for malware.
For other people that want to have a Dynamic Analysis Malware Lab at home just like this, here are some resources.
hxxps://cuckoosandbox.org/
hxxps://www.youtube.com/watch?v=p7VMV8R7pyo

To catch malware to test with:
hxxps://www.honeynet.org/projects/active/dionaea/

You can search github for some malware databases.
People collect samples and upload them.
I'm not gonna share because I'm not sure if it's against the rules so I don't want to break them.
But you can find some online, setup your lab, put them in, and see what they do.
Most are pretty dumb.

If you're using Tor for illegal activities, how safe are you and how to improve that ?
If you're buying drugs or something on it, you should be fine. If you're hosting a website on tor from home, that can be way more difficult.

Your ISP knows every time you connect to Tor, which means the feds also know. One way they know who's who online, is to see who signs on and off on Forums on Tor. They match the time with the logs they get from ISPs and they can deanonymize people this way. Having a VPN provider helps this, especially if they're outside your country, and the fourteen eyes. Takes a lot longer to work with other governments and companies outside a country.

Definitions:
clearnet = hxxp://website[.]com
on the Tor Network would be like aklshenruiofgnjknaoisdf[.]onion

Also, depending if you stay on the Tor Network vs. go to clearnet, is another way to be deanonymized.
Example) I visit EvilClearnetFourm[.]com, but I"m Tor. Now let's say the feds are monitoring all traffic being sent to EvilClearnetFourm because the internet provider of this website is giving them all the logs. When I travel to the website, MY ISP knows how much traffic in bytes are being sent out. EvilClearnetFourm's ISP RECEIVES the EXACT same number of bytes, close to the same time. Feds use this to deanonymize people that use Tor on the clearnet. It's called a correlation attack.

hxxps://www.eff.org/deeplinks/2014/06/why-you-should-use-tor
hxxps://blog.torproject.org/traffic-correlation-using-netflows?page=1

Is possible to get information, because they have EXIT Relays and that is where you can be caugh. Is not impossible, FBI and Europol or Interpol does that to catch high profile criminals.
Isn't impossible, if is little harder? Yes, but from them they are high skilled. They will try to track, and you will left traces like Login in personal Social Media with TOR, same passwords you use, they will try to match to any Social media.

And they got it, easily. With a simple password they can discover who you are. Let's talk you use "mypassowordishard2" you are the one in the world who uses that or in your country, they know your password by takedown any website in TOR, they use that password and they ask for information in Social Media, Websites they will discover you easily.

By using a password, don't you believe? Better start thinking that's possible and they do it. Most of people doesn't know that, or doesn't care about that, but that is a TRACE.
This is correct. The Exit Relay attack is what I listed above. As for the social media, this is why Qubes is pretty nifty. You can create a VM, put all your personal stuff in one, and have it go out through your ISP, while having all your sketchy stuff in another VM, that sends traffic to your VPN, and then TOR. You'd segment your personal life with your other life, and you setup the traffic so they also look like they're coming from different locations.

And yes, never use the same password across the internet. Some websites don't encrypt people's password, and when they get hacked, hackers and anyone with the database can see your password and email. If you didn't change it, they'll login to your email or any other website they can find you at.

Why aren't hackers targeting internet marketers? It would certainly be the most profitable ones to target?
Also to address this further. Some hackers do malvertising. I'm not quite familiar with the process entirely, but what I believe happens, is someone will signup with advertisers that allow it (or do it sneakily), create an Ad and put malicious code in it. Could be a script that executes code from another website or location), and then put their Ad on as many websites as possible. In this way, as soon as someone visits the site, they're hacked. It's usually a network of people that do this. One guy will own a shitload of compromised websites, and another person handles the ads/pulling out the money, and another person will create the exploit kit. They all get paid well.
 
Last edited:
the real hacker handcraft everything there is nothing can save you, by just updating everything and windows 10 not going to save you , for a real pro hacker breaking AMSI isnt tough , and bypassing AV's system tokens/privileges etc arent tough either... tbh security and privacy is myth if u care really say GTFO to windows move to linux whonix or tails
 
the real hacker handcraft everything there is nothing can save you, by just updating everything and windows 10 not going to save you , for a real pro hacker breaking AMSI isnt tough , and bypassing AV's system tokens/privileges etc arent tough either... tbh security and privacy is myth if u care really say GTFO to windows move to linux whonix or tails
To note, malware authors also write malware for linux-based OS. But @kelvin.thechamp does make a great point. As there is malware for linux, unless you're hosting a server on it, there's less malware for it. (There's a lot of linux-based web servers so naturally, there is a good amount of malware targeting these systems as well). There's way less malware for desktop linux-based OS'. If you're not running nginx, apache, VNC, or other services on your linux box, you're pretty safe. Safer to surf the internet on a linux-based machine than Windows forsure. This is because there are way more Windows computers online. It's, again, a numbers game. If someone is to write malware, would it be better to try to infect 100k systems, or 1k?

No system is safe. Just don't be the lowest-hanging fruit.

very interesting discussion here :)

Guys if you wanna protect your privacy with VPN, you should buy Perfect Privacy.

They are the leaders in this industry and have also a warrant canary
https://www.perfect-privacy.com/en/warrant-canary
Just checked out this provider. One thing that's really good about this provider is that it says it provides a feature called "Kill Switch".
This is a very good feature. In the event your VPN cuts out, so does all your network traffic on your device, until you reconnect to the same location, connect to another location, or close your VPN app. The reason this is important, is because there have been some legal cases where hackers were doing something sketchy, and their VPN connection dropped, and their network traffic just hopped back to using their ISP. So they reconnected to their IRC servers that were apart of anonymous, and their real IP was leaked to that server, and everyone on the server could see it.
 
Last edited:
This is actually really cool! This sounds like a great service. Seems like they run dynamic analysis for malware.
For other people that want to have a Dynamic Analysis Malware Lab at home just like this, here are some resources.
hxxps://cuckoosandbox.org/
hxxps://www.youtube.com/watch?v=p7VMV8R7pyo

To catch malware to test with:
hxxps://www.honeynet.org/projects/active/dionaea/

You can search github for some malware databases.
People collect samples and upload them.
I'm not gonna share because I'm not sure if it's against the rules so I don't want to break them.
But you can find some online, setup your lab, put them in, and see what they do.
Most are pretty dumb.


If you're buying drugs or something on it, you should be fine. If you're hosting a website on tor from home, that can be way more difficult.

Your ISP knows every time you connect to Tor, which means the feds also know. One way they know who's who online, is to see who signs on and off on Forums on Tor. They match the time with the logs they get from ISPs and they can deanonymize people this way. Having a VPN provider helps this, especially if they're outside your country, and the fourteen eyes. Takes a lot longer to work with other governments and companies outside a country.

Definitions:
clearnet = hxxp://website[.]com
on the Tor Network would be like aklshenruiofgnjknaoisdf[.]onion

Also, depending if you stay on the Tor Network vs. go to clearnet, is another way to be deanonymized.
Example) I visit EvilClearnetFourm[.]com, but I"m Tor. Now let's say the feds are monitoring all traffic being sent to EvilClearnetFourm because the internet provider of this website is giving them all the logs. When I travel to the website, MY ISP knows how much traffic in bytes are being sent out. EvilClearnetFourm's ISP RECEIVES the EXACT same number of bytes, close to the same time. Feds use this to deanonymize people that use Tor on the clearnet. It's called a correlation attack.

hxxps://www.eff.org/deeplinks/2014/06/why-you-should-use-tor
hxxps://blog.torproject.org/traffic-correlation-using-netflows?page=1


This is correct. The Exit Relay attack is what I listed above. As for the social media, this is why Qubes is pretty nifty. You can create a VM, put all your personal stuff in one, and have it go out through your ISP, while having all your sketchy stuff in another VM, that sends traffic to your VPN, and then TOR. You'd segment your personal life with your other life, and you setup the traffic so they also look like they're coming from different locations.

And yes, never use the same password across the internet. Some websites don't encrypt people's password, and when they get hacked, hackers and anyone with the database can see your password and email. If you didn't change it, they'll login to your email or any other website they can find you at.


Also to address this further. Some hackers do malvertising. I'm not quite familiar with the process entirely, but what I believe happens, is someone will signup with advertisers that allow it (or do it sneakily), create an Ad and put malicious code in it. Could be a script that executes code from another website or location), and then put their Ad on as many websites as possible. In this way, as soon as someone visits the site, they're hacked. It's usually a network of people that do this. One guy will own a shitload of compromised websites, and another person handles the ads/pulling out the money, and another person will create the exploit kit. They all get paid well.
Hi,
U said that i can be tracked if i use tor because the ISP nows the amount of bytes send or so :-). But if i use this Setup: Perfect privacy VPN + TOR VM + Vip72.asia "vic"socks would i then be safe?
 
Hi,
U said that i can be tracked if i use tor because the ISP nows the amount of bytes send or so :). But if i use this Setup: Perfect privacy VPN + TOR VM + Vip72.asia "vic"socks would i then be safe?
Yes, so long as the traffic from the VM is going out through your VPN and is not a bridge connection, you should be good.
To test this:
1. Connect to your VPN provider.
2. In your VM, check the IP address. Make sure it's the same as the host with the VPN connected to it.
If it is, then you can go on Tor on your VM, and you'll be good.

To note, you ISP will know you on connected to a VPN. They won't know you're on Tor, nor what you're looking and searching. =)
 
Yes, so long as the traffic from the VM is going out through your VPN and is not a bridge connection, you should be good.
To test this:
1. Connect to your VPN provider.
2. In your VM, check the IP address. Make sure it's the same as the host with the VPN connected to it.
If it is, then you can go on Tor on your VM, and you'll be good.

To note, you ISP will know you on connected to a VPN. They won't know you're on Tor, nor what you're looking and searching. =)
Ok. Will i be safe too if i use a vpn which is logging? Because it dosent matters if i connect only to tor right :-) ?
 
Ok. Will i be safe too if i use a vpn which is logging? Because it dosent matters if i connect only to tor right :) ?
It depends on your threat model. If the government is going after you, you should find a VPN provider that doesn't log. If they're not, you should be fine. :)
 
1. Some VPN services aren't too expensive, like $6/month. But if you can't, yeah Tor is your best bet. You can configure which relays your connections does as well. This can help if you want the exit relay to be outside your country. Warning though, your ISP will know you're on Tor. They won't know what you're looking at, but they'll know. It usually matters more if you're high profile.
2. I would say Qubes is one of the best, yes.
3. They could scan it, see if you have any ports open, and exploit any vulnerable services you have. Having someone's home IP, there's not TOO many things. It's easier and quicker to get them to click a link and exploit their computer that. I couldn't do much with a home IP, but others can. Most hackers can't.
4. ALL of them. Any website online gets hit with a bunch of attacks constantly. Let's say I figured out how to use an exploit for IIS 10.0. I could scan the entire internet for websites running IIS 10.0, and then exploit them all. It's not that I target one system, but all systems. So long as you keep your software up-to-date, and protect against the OWASP 10, you'll be alright. Persistent hackers can get into any webapp. It just takes practice and once you do enough engagements, you know what to look for. There's always a door somewhere.
Those VPNs got burnt ass IPs with high risk scores
 
I forgot to mention. Another great add-on/extension? to use when surfing sketchy things, is NoScript.
Blocks scripts from executing once you hit a website. It can be annoying if it's on and you're just trying to live your life,
but if you're going to a sketchy site, you should enable it.
Please send me your TG or somehow to reach you, I want to talk to you about something. Thanks!
 
Back
Top