[tor-relays] Traffic in port 9050 in a relay (denial of service attack?)

Luther Blissett lblissett at paranoici.org
Tue Nov 5 14:46:05 UTC 2013

On Tue, 2013-11-05 at 09:36 +0100, jj tor wrote:
> Sorry for the confusión, the exact line in my torrc is "Socksport 0", so,
> SOCKS port is closed. Moreover, I haven't got any exit rule towards port
> 9050
> Even if I block this traffic using iptables, I am very curious about  why
> the server is receiving that huge amount
> Maybe, because my relay's exit policy? (exit policy-->
> doc/ReducedExitPolicy – Tor Bug Tracker & Wiki :
> https://trac.torproject.org/projects/tor/wiki/doc/ReducedExitPolicy)

Sorry but I could not understand, which way are you seeing this traffic
pass by? The port is open, closed or filtered?

If it's from outside and you don't want it to be open, just close the
door and filter it with iptables. You can also use iptables to log the
traffic and maybe study it?

