This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

The Bad Guys are Running Out of Places to Hide

The Hacker News reported today that it has been confirmed the FBI has access to the entire Tor Mail database. This is great news for the Cyber Security community, as it makes things even harder for online criminals to prey on easy victims.

Access to this database will allow the FBI to find all sorts of juicy incriminating data, such as drug deals, coordinated hacking, and even murders.

So for anyone out there who had incriminating evidence on Tor Mail, consider yourself on notice - the "Party Van" will be visiting your house soon.

Remember kiddies, the Internet is forever.

What the FBI probably knows about Tor Users

Vlad Tsyrklevich has posted an excellent analysis of the payload delivered by the Tor Browser Bundle exploit.

This payload was delivered to every Tor Browser Bundle user who visited a Freedom Hosting hosted Tor Hidden Service, including Tormail.

According to Vlad, the exploit sends the hostname and MAC address of the local system to 65.222.202.54 over HTTP, then crashes.

So, what can the FBI do with this information?

Well, they now have a record of what systems were visiting all sites on Freedom Hosting.
It is also safe to assume that the FBI now has all emails and logs stored by Tormail.

The Tormail emails can be an excellent datamine without any additional info. Many Tormail users could have possibly revealed sensitive information over Tormail, including their name and home address, especially if using Tor to order illicit goods or services.

However, the hostname and MAC address can also be useful.
For example, the FBI can use the MAC address to subpoena a computer manufacturer to find out who purchased the computer. They can then use the hostname to verify they have the right person.

For example, let's say the FBI got a hostname of "DOE-PC" and a MAC address matching a Dell laptop.

The FBI contacts Dell with a subpoena "Did you sell a computer to someone named Doe with MAC address XX:XX:XX:XX", Dell can send them the transaction information, including home address.

This is a big win for law enforcement worldwide, and should help to end some of the illegal activities occurring on Tor.


Just remember kiddies, there is no such thing as "private" on the Internet. Not even on Tor.


NOTE: You can review the deobfuscated JavaScript at my Malware Analysis Google Code site: https://code.google.com/p/caffsec-malware-analysis/source/browse/trunk/TorFreedomHosting/

Massive TOR Hidden Service Compromise

It was announced today on Twitter that one of the major "hidden services" hosting companies, has been delivering malicious content and the hosted sites shutdown after a raid by law enforcement.

Supposed, among the compromised services include "TorMail", which provides anonymized email services.

If TorMail has been compromised, this could have broader reaching effects, including giving the FBI and Interpol the ability to directly access associated accounts outside of Tor hidden services. It would then be easy for the authorities to request from associated websites a log of associated IP addresses.

This spells bad news for anyone who uses Tor for illegal purposes, and a major win for the law enforcement community.

NOTE: You can view deobfuscated versions of the malicious code at my Malware Analysis Google Code site: https://code.google.com/p/caffsec-malware-analysis/source/browse/trunk/TorFreedomHosting/