[tor-talk] Hidden server path

Alexandre Guillioud guillioud.alexandre at gmail.com
Fri Jan 11 14:43:24 UTC 2013


>From my experiments, it depends of the client. Referrer is a strange var,
and as it's client defined you can't rely on it.
I've done my experiments without tor. And as far as i know, tor isn't
changing data in any way, my experiments are relevent.

2013/1/11 Outlaw <outlaw at omail.pro>

> > BUT. If your .onion server links to an outside page, includes an image,
> > script-file, whatever, externally - the HTTP Referer will give away the
> URL
> > to the other server if not properly sanitized by the client...
> >
> > There is always room for misconfiguration ;-)
> >
> >  - Lasse
>
> Hi! Did I understand right: if a page has a link (or image), then with
> clicking on that link I give the _whole_
> http://somelonghashstring.onion/path/to/somewhere.html as referer? Or
> just part of it - domain? Thanks!
>
> --
> Outlaw
>
> _______________________________________________
> tor-talk mailing list
> tor-talk at lists.torproject.org
> https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk
>


More information about the tor-talk mailing list