Firefox,Torbutton leaks real IP Address.

dr._no at cool.ms dr._no at cool.ms
Wed Dec 3 23:26:54 UTC 2008


Hi,

i think the main problem is that via java/javacript the browser can do direct
connections, bypassing your proxy and only using your default gateway!
You can see this bypassing with test sites like https://www.jondos.de/de/anontest .

That's why i am not using a default gateway on the PC i am using and usually you
only need proxy and no default gateway (behind the Router with the firewall and proxy).
For some situations like updating my homepage via ssh/rsync i'm using 
a default gateway but only for a short time (approx. 1 minute) and at
that time i'm using no browser.

Regards,

Rolf


> The combination Firefox-3.0.3(in fact,Iceweasel-3.0.3),Torbutton-1.2.
> 0 leaks my real IP
> address.This happens BETWEEN when I initiate Tor-0.2.0.31 with the 
> bash command 
> /usr/local/tor/bin/tor and the moment when Tor effectively establishes 
> a connection-circuit.
> This can be 60 seconds or more,and if in between we connect to the 
> Internet with
> Firefox-Torbutton the real IP address is used(even with torbutton 
> running-green)
> I tested with www.showmyip.com and others.My fear is if the same 
> could happen when Tor changes circuit by ten-ten minutes or so,when 
> leaves the previous circuit to the next one.(what happens in the 
> transition moments).I did not test that situation.
> 
>  Thanks. 
> 
> 




More information about the tor-talk mailing list