Results of the second security audit of Tor Project developments

The developers of the anonymous Tor network published the results of the second audit conducted by Radically Open Security from April to August 2023 (the first audit was carried out by Cure53 from November 2022 to April 2023). The review focused on the code that ensures the operation of exit nodes, the Tor Browser, infrastructure components (metric collection, SWBS, Onionoo API), and testing utilities. The primary goal of the re-evaluation was to assess the changes made to increase the speed and reliability of the Tor network, such as the traffic-splitting protocol Conflux added in the Tor 0.4.8 release and methods to protect Onion services from DoS attacks based on proof of work.

The audit identified 17 vulnerabilities, only one of which was classified as critical. Four vulnerabilities were rated as medium severity, while 12 were categorized as minor issues. The most critical vulnerability was found in the onbasca application (Onion Bandwidth Scanner), used for scanning the bandwidth of network nodes.

The vulnerability arises from the ability to send requests via the HTTP GET method, allowing Cross-Site Request Forgery (CSRF), enabling an attacker to add their own bridge nodes to the database by manipulating the "bridge_lines" parameter. For instance, an attacker could host a web page with JavaScript code fetch("http://127.0.0.1:8000/bridge-state/?bridge_lines=obfs4+0.0.0.000000+AAA+cert0+iat-mode0", and if a user with an active session to the Onion Bandwidth Scanner opens this page, the IP "0.0.0.0" will be added to the database on their behalf.

Medium severity issues:

  • Denial of service in metrics-lib through the transfer of a large compressed file — as the file is unpacked into memory, a zip-bomb-like file can be sent (for example, 600 MB of zeros can be packed into 0.0006 MB) which could lead to exhaustion of available memory.
  • Use in tor-android-service (used in the Tor browser for Android) of the discontinued third-party module tun2socks.
  • Writing a null byte beyond the allocated buffer in the Tor client due to the use of the read_file_to_str_until_eof function, which returns the size without counting the null character.
  • A vulnerability in sbws (Simple Bandwidth Scanner) allows rolling back an HTTPS connection to HTTP using a redirect to HTTP. A Tor exit node controlled by an attacker could potentially exploit this vulnerability to leak API tokens.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster