[tor-bugs] #29607 [Core Tor/Tor]: 2019 Q1: Denial of service on v2 and v3 onion service

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Apr 29 16:53:21 UTC 2019


#29607: 2019 Q1: Denial of service on v2 and v3 onion service
-------------------------------------------------+-------------------------
 Reporter:  pidgin                               |          Owner:  pidgin
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  Immediate                            |      Milestone:  Tor:
                                                 |  0.4.1.x-final
Component:  Core Tor/Tor                         |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tor-hs, tor-dos, network-team-       |  Actual Points:
  roadmap-2019-Q1Q2                              |
Parent ID:  #29999                               |         Points:  10
 Reviewer:                                       |        Sponsor:
                                                 |  Sponsor27-must
-------------------------------------------------+-------------------------

Comment (by dgoulet):

 Status update:

 asn and I have setup an environment to reproduce this `INTRODUCE2` DDoS
 for which we were successful at reproducing the max CPU utilization on the
 service. However, we haven't figured out just yet how can the service
 still receives `INTRODUCE2` cells 30+ minutes after the circuit has been
 closed (found from the logs given in private).

 Ticket #30291 has been opened regarding a reason of the high CPU usage.
 And nickm already worked on improvements so we expect these upstream soon.

 We'll be working on the DoS master ticket #29999, especially #15516 and
 #26294 in the coming weeks. Improvements will be coming to master
 incrementally thus expect more updates about the situation as we progress
 in this work.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29607#comment:52>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list