[tor-relays] Abuse messages from IPs marked as rejected in the exit policy

Tim Wilson-Brown - teor teor2345 at gmail.com
Wed Nov 18 23:28:59 UTC 2015


> On 19 Nov 2015, at 07:32, tor-admin at torland.me wrote:
> 
> Hi all,
> 
> I am receiving abuse messages for the Torland1 relay for IPs that are
> blacklisted in the exit policy. For example as
> https://atlas.torproject.org/#details/E1E922A20AF608728824A620BADC6EFC8CB8C2B8
> shows,  62.67.194.0/24 is blocked. But I am getting abuse messages out of this
> IP range. Can someone explain me how this can happen?

False positives?
Incorrect source addresses?
Multihomed destinations? (For example, they're reporting an IPv4 address, but the Exit used another IPv4 address, or an IPv6 address to contact them.)
A non-tor process on the relay?

Can you post the ExitPolicy from your torrc?
I can only see the one on globe, and I'd like to make sure they match.
(But it's well structured: reject …; accept …; reject *:*; so I don't force any issues.)

Tim

Tim Wilson-Brown (teor)

teor2345 at gmail dot com
PGP 968F094B

teor at blah dot im
OTR CAD08081 9755866D 89E2A06F E3558B7F B5A9D14F

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20151119/4d85f3a2/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 842 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20151119/4d85f3a2/attachment.sig>


More information about the tor-relays mailing list