[tor-bugs] #17303 [DirAuth]: Bad exits inject port 8123 into HTTP redirects

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Nov 11 01:55:46 UTC 2015


#17303: Bad exits inject port 8123 into HTTP redirects
----------------------+----------------------------------
 Reporter:  ikurua22  |          Owner:
     Type:  defect    |         Status:  new
 Priority:  High      |      Milestone:  Tor: unspecified
Component:  DirAuth   |        Version:  Tor: unspecified
 Severity:  Critical  |     Resolution:
 Keywords:            |  Actual Points:
Parent ID:            |         Points:
  Sponsor:            |
----------------------+----------------------------------

Comment (by teor):

 Replying to [comment:10 dcf]:
 > Replying to [comment:9 teor]:
 > > Replying to [comment:8 dcf]:
 > > > I ran attachment:http-redirect.py three times in the past weeks.
 > > >  2015-10-04:: 54 bad exits
 > > >  2015-10-17:: 39 bad exits
 > > >  2015-11-10:: 8 bad exits
 > >
 > > I'm assuming that the exit numbers are decreasing because they're
 listed by the DirAuths as bad exits, in response to your emails (or
 running exitmap themselves).
 > >
 > > It seems we're solving the problem, albeit incrementally.
 > >
 > > Are the remaining exits new instances, or existing instances that
 haven't been blocked yet?
 >
 > Thanks, I didn't realize that they were already BadExits. The 8 exits
 from today are all new and were not in the previous scans.

 I am assuming that they are disappearing because they were being tagged as
 BadExits in response to this issue - I don't know for sure.

 I'm not sure if the bad exit list is public.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17303#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list