[tor-talk] Blocking STUN Requests at Firewall?

Bill Berry bill at techwang.com
Sun Feb 8 11:00:28 UTC 2015


Hi all,

I've setup a Tor transparent proxy, as per the instructions here 
https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy (I'm 
aware of the security risks of not using the Tor Browser)

It's working well except it is vulnerable to STUN requests (as per 
http://ipleak.net/). Does anyone have experience of blocking these 
requests? Based on the spec they can be TCP or UDP, so just blocking non 
DNS UDP doesn't seem to help. Maybe it could be achieved using DPI? Not 
much info on the net.

Thanks,

Bill




More information about the tor-talk mailing list