[tor-talk] Security issue. Firefox in Tor Browser Bundle allows access to LAN resources. To fix: ABE of NoScript must be turn on by default

Olivier Cornu o.cornu at riseup.net
Tue Jan 21 09:20:34 UTC 2014


Le mar. 21 janv. 2014 10:01:24 CET, Olivier Cornu a écrit :
> TBB connecting to loopback netcat socket from tortestprivacy.url.ph
> javascript:

Sorry, previous log showed an attempt with a regular Firefox.
Here is the TBB log:

$ nc -l -p 1234
GET / HTTP/1.1
Host: 127.0.0.1:1234
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 
Firefox/24.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://tortestprivacy.url.ph/
Origin: http://tortestprivacy.url.ph
Connection: keep-alive

--
Olivier Cornu


More information about the tor-talk mailing list