Tor Users Busted

I once tried to use tor for making fb accounts. But everytime the fb account said phone verification needed. Does tor switch proxies every couple of seconds? I am a bit of noob when it comes to tor and proxies. Gonna google about its use in detail today.

The problem with Tor is that most of the exit node's IP Address are documented and blocked. So the end-point destination may not know who you are, where you are from, etc..., but they know that you are coming in on Tor. And while I'm a full supporter of web anonymity, Tor, etc... (I've even hosted a Tor node for a while), let's be honest here. Most uses of Tor are nefarious.

I keep having this recurring idea that someone creates a collective "cloud" network. One that people get paid to join, but they pay to use, where all the computers are interlinked and centrally controlled so that (for example) people can join for free, and their browsing traffic gets bounced around randomly before it exits randomly, but (another example), sending email or other types of network traffic is paid, and those participants in the network allow their computers to be used for various, other purposes (such as email spamming), etc...

Seems to me that if the network is large enough, it would be impossible for law enforcement, or the spam blocking services to identify every single exit node and block it, and even if they did, the network simply changes gears and the spam exits somewhere else.

So, to get people to join, you incentivize it by two means: 1) Free, anonymous web browsing, where you "borrow" other people's computers in order to surf the internet and 2) A "pay per use" system where for every (example) craigslist ad that gets posted using your IP address, you make 5 cents (and the network keeps the rest).

Users could choose to participate in the paid-spam or not, or there could be a minimum requirement (must allow 1 spam per day, or per week), and get paid for anything above that.

Overall, what this could is obscure the 1 to 1 correlation between an action on the internet (say, a credit card transaction) and an IP Address. Law Enforcement could no longer "prove" that because IP Address 123.xxx... made a fraudulent transaction, that IP Address MUST be the person that lives at 123 yourstreet, yourstate, USA. Bad for Law Enforcement, bad for credit card companies, good for privacy and individual rights & freedoms.
 
I used to have a tor node about 6 years ago, but stopped after I realized that it may be used by child molesters to send illegal pics. And if you want to setup the legal protection to not get legal issues you have to go through the trouble of starting a company, and buying everything in the companies name, and setting up a ramdisk so that it cannot keep logs.
 
Props to the investigators that took them down. I would just like to add though, this is an old trick, and is by no means a software "exploit" (though it was definitely effective). Anyone that relies on anonymity enough to require Tor, NEEDS to understand how browser requests work, or it's only a matter of time. This includes knowledge on headers, scripts, addons, cookies, and so on. Hell, get a plain-text browser if you think you can handle it! xD
 
I blame it on the Javascript. ;)

David Hasselhoff Move. :hijacked:
 
I would advise to use P.O.R.T.A.L. which is build on Tor, but handles ALL connections trough TOR, not depending on if JS is enabled or not.
In that way you should be safe unless someone does not install a trojan or keylogger on your PC.

And of course: Don't shit where you eat ;-).
 
I keep having this recurring idea that someone creates a collective "cloud" network. One that people get paid to join, but they pay to use, where all the computers are interlinked and centrally controlled so that (for example) people can join for free, and their browsing traffic gets bounced around randomly before it exits randomly, but (another example), sending email or other types of network traffic is paid, and those participants in the network allow their computers to be used for various, other purposes (such as email spamming), etc...

Another idea I've had is that, given the recent Tor bust, and the public awareness that MAC Addresses can be given out and are considered to be "unique identifiers", another functionality that would need to be built into the "central cloud server" is that the MAC addresses of all the various 'bot computers would need to be spoofed. Somehow, that MAC spoofing record would have to be stored and centrally managed.

Finally, I think about browser fingerprinting, and how that also would need to be managed in some way. I have this idea that someone should create a browser specifically dedicated for the purpose on anonymity; one that would morph it's browser fingerprint constantly. On one site it would be a Firefox browser ver. A1 from IP Address "X", running extension "Y", with MAC Address "G" and at the next website it is Internet Explorer 10, from IP Address "Y" with ActiveX disabled and MAC Address "F".

Never the same IP, MAC address, or browser fingerprint twice. And a handful of expert witnesses available to testify in any court (for a price) that there is no way that the State can prove that this person used that computer to go to this website in order to do x, y & z. No way the attorneys for the RIAA can prove that this copyright material was uploaded from this computer with this MAC Address via this webhosting service with this IP Address, etc...

You'd only need a few case law precedents set before they'd quit trying to convince juries that they actually knew something they could prove. Unless, of course, there's a racist retard on the jury like B29, but that's a different rant for a different thread. But it IS yet another reason why government is bad, and keeping as much information away from the government as possible is necessary for even law abiding, non-blackhat people to survive.

Which lead me to my next rant, which is this stupid bogey man "child porn", and all I'll say about this is, if someone TRULY hated you, all they would need to do is get some child porn on your computer and call the police. You'd NEVER be able to prove it wasn't yours, and the State doesn't have to prove that it is. The fact that it's on your computer is enough to put you in prison for years & years & years. And, worse, there will be some knuckle-dragging retard like juror B29, sitting in judgement of you, with a dishonest and manipulative prosecution, and a mentally unbalanced judge with a political agenda willing to distort the judicial process in order to send your ass to prison. Unless you've got a damn good attorney, like Z did. But you won't, and you'll be screwed.

Now that it occurs to me. I LIKE this idea. It's new. I just got it. Something constructive for Anonymous to do. Start putting child porn on Government Employees computers, and then informing on them to the authorities, lol. Let's test our government's integrity, and see if they are willing to prosecute one of their own by the letter (and not the spirit) of the law.
 
Props to the investigators that took them down. I would just like to add though, this is an old trick, and is by no means a software "exploit" (though it was definitely effective). Anyone that relies on anonymity enough to require Tor, NEEDS to understand how browser requests work, or it's only a matter of time. This includes knowledge on headers, scripts, addons, cookies, and so on. Hell, get a plain-text browser if you think you can handle it! xD

If they can use one exploit to break-down the anonymity of Tor, they can use another exploit to make the computer up & download child porn. Sycophants like yourself would always like to believe in being half-pregnant, and that a dishonest government is only dishonest for noble purposes, and never self-serving purposes. And you also believe that when the band plays "Hail to the Chief" they are pointing the cannon in another direction, and never at you. And the "bad guy" is always going to be "someone else", and not you.

And yet, here you are on a blackhat forum, lol, roflmao. Idiot.

Here's something you, and every other like-minded dummy should read. I expect a 3 page book report by next Monday. It's a story about a guy that got a hard-on when it came to torturing someone else, but discovered that God has a VERY sick sense of humor.

http://en.wikipedia.org/wiki/Brazen_bull

[video=youtube_share;fBN_3YJKZrY]http://youtu.be/fBN_3YJKZrY[/video]

You hear that noise, overhead? That's a Predator drone. And some day, it's going to drop a hellfire missle on your neighbor's house. Don't bring your children to a war. Anyone remember that one?
 
Last edited:
Props to the investigators that took them down. I would just like to add though, this is an old trick, and is by no means a software "exploit" (though it was definitely effective). Anyone that relies on anonymity enough to require Tor, NEEDS to understand how browser requests work, or it's only a matter of time. This includes knowledge on headers, scripts, addons, cookies, and so on. Hell, get a plain-text browser if you think you can handle it! xD

This had nothing to do with browser requests. Try RTFA before you start spreading disinformation.
 
Back
Top