Brief survey on methods for attacking Tor hidden service
translate.wooyun.io
translate.wooyun.io
The methods for attacking hidden services (DNM) are the same as any other site such as exploiting misconfiguration, exploiting unpatched software or finding new ones, and looking for pieces of opsec like the Czech guy who's darkmarket used some obscure Czech php framework which was identified by viewing the CSS. Every so often a research paper comes out too that identifies some new scheme of analysis of guard nodes/pattern matching/fingerprinting ect to identify hidden service IPs as noted in this Wooyun article. https://news.mit.edu/2015/tor-vulnerability-0729
Snowden docs also talked about QUANTUM which was some NSA/GCHQ scheme to try race conditions against relays to lure Tor users to their own relay farm for analysis detailed here https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a...