AplusWebMaster
Topic Starter
FYI…
- http://blog.washingtonpost.com/securityfix…te_for_tor.html
August 8, 2007 - "One of the best-known and free services for helping Internet users maintain their anonymity online - a network known simply as "Tor" – suffered an attack this past week that may have exposed the identities of thousands of users. The good news, however, is that the vulnerability in Tor that permitted the attack is now plugged with a software patch. Tor president and co-founder Roger Dingledine received word of the attack as he was delivering a talk at the Black Hat security conference in Las Vegas this past week regarding security and privacy built into the Tor network… Someone was testing out an exploit that caused obvious Web browsing problems for at least several hundred people surfing the Internet with Tor… This specific vulnerability allowed a remote attacker on the network to overwrite any Tor users' configuration file. With that level of access, the attacker could easily force a Tor user's computer to identify its true numeric Internet address, the very information Tor is meant to protect. Tor is designed to run on most operating systems, including Linux, Mac OS X, and Windows. If you have a version of Tor installed on any of these systems and plan to continue using it, you'd be well-advised to update to the latest iteration, as this attack is now probably well-understood by a number of folks who may not have the network's best interests at heart. The latest version is available from this link here*."
* http://tor.eff.org/download.html.en
Last modified: Thu Aug 2 21:10:49 2007 - Last compiled: Tue Aug 7 23:44:27 2007
"…The latest stable release is 0.1.2.16…"
.
- http://blog.washingtonpost.com/securityfix…te_for_tor.html
August 8, 2007 - "One of the best-known and free services for helping Internet users maintain their anonymity online - a network known simply as "Tor" – suffered an attack this past week that may have exposed the identities of thousands of users. The good news, however, is that the vulnerability in Tor that permitted the attack is now plugged with a software patch. Tor president and co-founder Roger Dingledine received word of the attack as he was delivering a talk at the Black Hat security conference in Las Vegas this past week regarding security and privacy built into the Tor network… Someone was testing out an exploit that caused obvious Web browsing problems for at least several hundred people surfing the Internet with Tor… This specific vulnerability allowed a remote attacker on the network to overwrite any Tor users' configuration file. With that level of access, the attacker could easily force a Tor user's computer to identify its true numeric Internet address, the very information Tor is meant to protect. Tor is designed to run on most operating systems, including Linux, Mac OS X, and Windows. If you have a version of Tor installed on any of these systems and plan to continue using it, you'd be well-advised to update to the latest iteration, as this attack is now probably well-understood by a number of folks who may not have the network's best interests at heart. The latest version is available from this link here*."
* http://tor.eff.org/download.html.en
Last modified: Thu Aug 2 21:10:49 2007 - Last compiled: Tue Aug 7 23:44:27 2007
"…The latest stable release is 0.1.2.16…"
.