Flushing out MITM attacks in the TOR network

After a few news sites picked up the entries on the suspicious TOR nodes I’ve had a few queries on the issue.While it is very easy to detect TOR nodes that are blindly doing MITM attacks on every SSL encrypted connection, targeted attacks are a _lot_ harder to find. Basically to detect a TOR node that targets a special site for MITM attacks I’d need to know the exact IP address(es) of the target to be able to check the nodes.

I’ve got a few more ideas on how to improve the tool I have to make a few other checks on TOR nodes but it’ll take some time before I can implement them.

Comments are closed.

If you want to comment on this article please send e-mail
to authors(_at_)teamfurry.com or go to the forums.


InspectorWordpress has prevented 2 attacks.