If the alleged pedophile is savvy enough to use Tor, won't he be running his web traffic over SSL, rendering this sort of attack useless?
For example: http://www.teamfurry.com/wordpress/2007/11/20/tor-exit-node-...
A google search returns lots of results, although I'm unsure if any are 'in the wild' exploits.