[tor-bugs] #18101 [Applications/Tor Browser]: IP leak from Windows UI dialog with URI

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 11 13:44:08 UTC 2019


#18101: IP leak from Windows UI dialog with URI
-------------------------------------------------+-------------------------
 Reporter:  uileak                               |          Owner:
                                                 |  arthuredelstein
     Type:  defect                               |         Status:
                                                 |  needs_revision
 Priority:  Medium                               |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Major                                |     Resolution:
 Keywords:  tbb-disk-leak, tbb-proxy-bypass,     |  Actual Points:
  TorBrowserTeam201805                           |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by ericlaw):

 This bug still leaks the user's IP to the remote server and full HTTP urls
 (including .onion urls) to any network intermediaries.

 Unsetting FOS_FORCEFILESYSTEM and setting FOS_SUPPORTSTREAMABLEITEMS
 appears to resolve the worst of this problem by returning unretrieved URLs
 to the browser instead of instructing the Windows Shell to download them.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18101#comment:82>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list