I was on Tor the other day, when I tried to access a Blogger blog. I got an infinite chain of redirections, because Google geolocates the IP and then issues a redirect to that country's blogger site.
For instance, with an IP geolocated to the Netherlands, *.blogspot.com and *.blogspot.de will redirect to *.blogspot.nl. Tor Browser sees that as a new site and runs a new circuit with a different exit node, likely in a different country, causing another redirection.
Generally, the domain and exit node mapping remains fixed. So, blogspot.com might redirect to blogspot.de, which would redirect to blogspot.nl, which might redirect to blogspot.com. But the later accesses retain the original exit nodes, and all cause the redirections again. Most sites work because they don't try to change domains per country.
A few attempts at "New Tor circuit for this site" finally broke the loops by changing the exit node for that single domain, but it's clear Google still puts too much faith in geolocation.
Any blogs that end up being accessed from EU exit nodes also get the cookie warning… generally in a language I can't read, because it's chosen by geolocation. Even though my headers have "Accept-Language: en-US;q=0.5" and I'm visiting a page whose primary language is English. IK SNAP HET!
(Speaking of Tor, though. If you want to know whether a site uses CloudFlare, just load it in Tor Browser. You'll generally see a CloudFlare CAPTCHA on their sites. They're so aggressive about putting out high-difficulty puzzles, I generally don't bother to solve anymore.)
Showing posts with label tor. Show all posts
Showing posts with label tor. Show all posts
Wednesday, March 23, 2016
Saturday, April 13, 2013
Tor for VirtualBox Guests (idea only; no code)
To give a guest only one network card with host-only networking, yet still let it access the Internet, we can let it connect to an HTTP proxy running on the host. If this proxy is polipo, we can configure it to connect to tor’s SOCKS server as its upstream:
Then what happens? Any and all Internet traffic from the guest VM is delivered via Tor. Since the guest doesn't have Internet access of its own, any software which doesn't cooperate with the proxy cannot communicate. Although malware on a compromised guest could still exfiltrate data, it hides the host's true external IP address from the malware. (Assuming, dangerously, no security bugs in polipo nor VirtualBox that would allow a compromise of the host.)
I said that first, but maybe not very clearly, on twitter.
But… given an appropriate proxy, traffic can be forwarded over any transport. A proxy could accept data from the guest and transmit it via VPN. On the other hand, building a VPN client into VirtualBox to offer a VPN network type would let a client connect to a VPN without necessarily allowing other host processes access to it, nor requiring the VPN to be mediated by an additional (dual-homed) guest.
Polipo doesn't have to use tor as a backend, either; it's also perfectly capable of forwarding using ssh's SOCKS proxy. (This is known as "dynamic tunnel mode" in some clients.) Compared to the amount of software and configuration needed to set up the average VPN, ssh is just as secure and much easier to get running.
Sending traffic via proxy is an effective way to apply further modifications to the destination stream, without needing the cooperation of software connecting to the proxy.
Then what happens? Any and all Internet traffic from the guest VM is delivered via Tor. Since the guest doesn't have Internet access of its own, any software which doesn't cooperate with the proxy cannot communicate. Although malware on a compromised guest could still exfiltrate data, it hides the host's true external IP address from the malware. (Assuming, dangerously, no security bugs in polipo nor VirtualBox that would allow a compromise of the host.)
I said that first, but maybe not very clearly, on twitter.
But… given an appropriate proxy, traffic can be forwarded over any transport. A proxy could accept data from the guest and transmit it via VPN. On the other hand, building a VPN client into VirtualBox to offer a VPN network type would let a client connect to a VPN without necessarily allowing other host processes access to it, nor requiring the VPN to be mediated by an additional (dual-homed) guest.
Polipo doesn't have to use tor as a backend, either; it's also perfectly capable of forwarding using ssh's SOCKS proxy. (This is known as "dynamic tunnel mode" in some clients.) Compared to the amount of software and configuration needed to set up the average VPN, ssh is just as secure and much easier to get running.
Sending traffic via proxy is an effective way to apply further modifications to the destination stream, without needing the cooperation of software connecting to the proxy.
Subscribe to:
Posts (Atom)
