LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-12-2007, 11:49 AM   #1
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Looking For Comments (Tor Nodes)


I was thinking about turning on my TOR to allow people to connect out from it. Then I found this article...

Click Here For Article

Here is an excerpt:

Code:
Earlier this week, a hacker infiltrated the website of a company in
France, defacing the site and using it to send vulgar emails. The
hacker was not a Rose-Hulman student. But through a router maintained
by a Rose-Hulman student, the hacker was able to do this anonymously.

The student, senior computer science major David Yip, was maintaining
a router on his computer called a Tor onion router. What Tor basically
does is enable anonymous communications over the internet. Yip
downloaded and installed Tor on his computer about two months ago. His
machine became a Tor exit node on September 4, 2005.
I know the purpose of TOR and I personally love it. Is there no way to offer a TOR exit node while protecting yourself? I would like to participate in the program, however I'm not going to put myself at risk to do so.

Thanks for all of your comments.

nomb
 
Old 10-12-2007, 12:16 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Are you refering to system/network protection or legal protection? Many applications which are used to regulate a LAN's access to a WAN can be re-implemented to regulate outgoing Tor exit node traffic. That said, running an exit node is by definition a risky endeavour (since you don't know the intentions of people using your exit node), and no amount of precautions will change that.
 
Old 10-13-2007, 03:51 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
TOR configuration allows exit nodes to control what IP ranges and ports they connect with with ExitPolicy directives. So you can for instance block some ISP range and SMTP, telnet, SSH, IRC (if they reside on these std ports). Traffic inside the "TOR cloud" is encrypted but exit nodes have to decrypt that (do not confuse with SSL) to allow it to reach its destination, so after the TOR ExitPolicy directives you're free to use routing / netfilter to block .fr, .cn, .tw or whatever else. If you don't feel comfortable running an exit node you could help TOR by running it as a middleman. (Not to chide you in any way but all of this you could have read in the TOR docs.)
 
Old 10-16-2007, 10:11 PM   #4
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Original Poster
Rep: Reputation: 58
Quote:
Originally Posted by unSpawn View Post
TOR configuration allows exit nodes to control what IP ranges and ports they connect with with ExitPolicy directives. So you can for instance block some ISP range and SMTP, telnet, SSH, IRC (if they reside on these std ports). Traffic inside the "TOR cloud" is encrypted but exit nodes have to decrypt that (do not confuse with SSL) to allow it to reach its destination, so after the TOR ExitPolicy directives you're free to use routing / netfilter to block .fr, .cn, .tw or whatever else. If you don't feel comfortable running an exit node you could help TOR by running it as a middleman. (Not to chide you in any way but all of this you could have read in the TOR docs.)
Thanks guys for your responses. Oh, btw, I read the TOR docs, however I seem to have gotten the docs without your opinions/comments included in them which is why I was asking for them. If you know where the docs are that include everyone's opinions/comments by all means let me know.

Usually when I buy something I read the reviews on it first, likewise when I am thinking about implementing on my computer/network I read the 'reviews' for that as well. M$ says they are the best OS in the world but if you speak with the 'consumer' you find differently.

nomb
 
Old 10-17-2007, 02:25 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by nomb View Post
Oh, btw, I read the TOR docs, however I seem to have gotten the docs without your opinions/comments included in them which is why I was asking for them. If you know where the docs are that include everyone's opinions/comments by all means let me know.
I should have said the TOR Wiki. Those docs are pretty good. Then there's the TOR users mailing list, pretty good discussions there too.
 
Old 10-19-2007, 05:01 PM   #6
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Original Poster
Rep: Reputation: 58
Now that's something I could sink my teeth into.
I haven't looked at the wiki yet.

nomb
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Tor select fastest nodes chup Linux - Software 6 06-09-2007 01:05 PM
how to see if tor is working. dr_zayus69 Linux - Networking 2 12-08-2005 02:05 PM
Privoxy and tor z3nith Linux - Software 2 10-01-2005 09:31 PM
Help with Tor Please botman Linux - Software 3 08-18-2005 01:17 PM
Help with Tor? botman SUSE / openSUSE 3 08-12-2005 01:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration