[tor-bugs] #2148 [Torbutton]: RefSpoofer fails on 5 test cases out of 12.
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Wed Nov 3 23:49:54 UTC 2010
#2148: RefSpoofer fails on 5 test cases out of 12.
--------------------------------+-------------------------------------------
Reporter: T(A)ILS developers | Owner: mikeperry
Type: defect | Status: new
Priority: normal | Milestone: Torbutton: 1.3
Component: Torbutton | Version: Torbutton: 1.3
Keywords: refspoofer | Parent:
--------------------------------+-------------------------------------------
Comment(by bee):
HI TAILS!!!!!!!!!!!!
Try BeeFREE!!!!!!!! my addon!!!!!!!!!
Bee FREE is able also to forge referrers ("softly" keeping the subdomains,
or "strictly", keeping only the top domains!!!!), but in its default
configuration it works removing the referrers!!!!!!!!!!! You've got to use
this key to change the way it works!!!!!!!!!!!!!!
http://honeybeenet.altervista.org/beefree/?id=114000#extensions.beefree.websites.default.header.referer.action
You can change it from the GUI too!!!!!!!!!!!!!!!!!!!!
Ha!!!! A forged referrer being send is always the hostname of the target
host you're sending the HTTP request to, so even this way of working won't
let leak information!!!!!!!!!!!!!! Filters of beefree can be configured to
remove the referrers even when you're surfing between the pages of the
same filtered website!!!!!! you've to look at the keys named
"*.header.referer.action.boost" to change this!!! this is also a per-
filter based configuration and there is no GUI for it!!!!!!! for example
you've to create this integer key
"extensions.beefree.website.generic.header.referer.action.boost" and set
it to "1" if you want to enable this feature everywhere!!!!!!! so all
referrers will be removed (or "FORGED" if you want!!!!!!!) every time on
all pages even if hosted under the same "domain.name"!!!!!!!!!!!
YEAH!!!!!!!!!!
bye!!!!!!!!!!!!
~bee!!!!!!
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2148#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list