{"id":113257,"date":"2024-01-31T01:41:06","date_gmt":"2024-01-30T23:41:06","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor"},"modified":"2024-01-31T01:41:06","modified_gmt":"2024-01-30T23:41:06","slug":"rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor","title":{"rendered":"Results of the second security audit of Tor Project developments","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The developers of the anonymous Tor network published the results of the second audit conducted by Radically Open Security from April to August 2023 (the first audit was carried out by Cure53 from November 2022 to April 2023). The review focused on the code that ensures the operation of exit nodes, the Tor Browser, infrastructure components (metric collection, SWBS, Onionoo API), and testing utilities. The primary goal of the re-evaluation was to assess the changes made to increase the speed and reliability of the Tor network, such as the traffic-splitting protocol Conflux added in the Tor 0.4.8 release and methods to protect Onion services from DoS attacks based on proof of work.    <\/p>\n<p>The audit identified 17 vulnerabilities, only one of which was classified as critical. Four vulnerabilities were rated as medium severity, while 12 were categorized as minor issues. The most critical vulnerability was found in the onbasca application (Onion Bandwidth Scanner), used for scanning the bandwidth of network nodes.     <\/p>\n<p>The vulnerability is caused by the ability to send requests via the HTTP GET method, which allows for the substitution of cross-site requests on behalf of another user (CSRF, Cross-Site Request Forgery). This gives an attacker the opportunity to add their bridge nodes to the database by manipulating the parameter 'bridge_lines'. For example, an attacker could host a web page with JavaScript code fetch('http:\/\/127.0.0.1:8000\/bridge-state\/?bridge_lines=obfs4+0.0.0.000000+AAA+cert0+iat-mode0', and if a user with an active session to the Onion Bandwidth Scanner opens this page, the IP '0.0.0.0' will be added to the database on their behalf.    <\/p>\n<p>Medium severity issues:  <\/p>\n<ul>\n<li class=\"l\"> Denial of service in metrics-lib through the transmission of a large compressed file \u2014 since the file is unpacked into memory, one could send a zip bomb (for example, packing 600 MB of zeros into 0.0006 MB) and cause exhaustion of available memory.\n<li class=\"l\"> Use in tor-android-service (used in the Tor browser for Android) of the discontinued third-party module tun2socks.\n<li class=\"l\"> Writing a null byte beyond the allocated buffer in the Tor client due to the use of the read_file_to_str_until_eof function, which returns the size without counting the null character.\n<li class=\"l\"> A vulnerability in sbws (Simple Bandwidth Scanner) allows rolling back an HTTPS connection to HTTP using a redirect to HTTP. A Tor exit node controlled by an attacker could potentially exploit this vulnerability to leak API tokens.          <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60522\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0430\u043d\u043e\u043d\u0438\u043c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 Tor \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Radically Open Security \u0441 \u0430\u043f\u0440\u0435\u043b\u044f \u043f\u043e \u0430\u0432\u0433\u0443\u0441\u0442 2023 \u0433\u043e\u0434\u0430 (\u0434\u043e \u044d\u0442\u043e\u0433\u043e \u0441 \u043d\u043e\u044f\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430 \u043f\u043e \u0430\u043f\u0440\u0435\u043b\u044c 2023 \u0433\u043e\u0434\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Cure53 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043b\u0441\u044f \u043f\u0435\u0440\u0432\u044b\u0439 \u0430\u0443\u0434\u0438\u0442). \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u0437\u0430\u0442\u0440\u043e\u043d\u0443\u043b\u0430 \u043a\u043e\u0434 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u0432\u044b\u0445\u043e\u0434\u043d\u044b\u0445 \u0443\u0437\u043b\u043e\u0432, \u0431\u0440\u0430\u0443\u0437\u0435\u0440 Tor Browser, \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u044b \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b (\u0441\u0431\u043e\u0440 \u043c\u0435\u0442\u0440\u0438\u043a, SWBS, API Onionoo) \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-113257","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0430\u043d\u043e\u043d\u0438\u043c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 Tor \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Radically Open Security \u0441 \u0430\u043f\u0440\u0435\u043b\u044f \u043f\u043e \u0430\u0432\u0433\u0443\u0441\u0442 2023 \u0433\u043e\u0434\u0430 (\u0434\u043e \u044d\u0442\u043e\u0433\u043e \u0441 \u043d\u043e\u044f\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430 \u043f\u043e \u0430\u043f\u0440\u0435\u043b\u044c 2023 \u0433\u043e\u0434\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Tor | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0430\u043d\u043e\u043d\u0438\u043c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 Tor \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Radically Open Security \u0441 \u0430\u043f\u0440\u0435\u043b\u044f \u043f\u043e \u0430\u0432\u0433\u0443\u0441\u0442 2023 \u0433\u043e\u0434\u0430 (\u0434\u043e \u044d\u0442\u043e\u0433\u043e \u0441 \u043d\u043e\u044f\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430 \u043f\u043e \u0430\u043f\u0440\u0435\u043b\u044c 2023 \u0433\u043e\u0434\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-01-30T23:41:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-01-30T23:41:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Results of the second security audit of the Tor project developments | ProHoster","description":"The developers of the anonymous Tor network have published the results of the second audit conducted by Radically Open Security from April to August 2023 (this follows an earlier audit from November 2022 to April 2023 by the same company).","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Tor | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u0430\u043d\u043e\u043d\u0438\u043c\u043d\u043e\u0439 \u0441\u0435\u0442\u0438 Tor \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Radically Open Security \u0441 \u0430\u043f\u0440\u0435\u043b\u044f \u043f\u043e \u0430\u0432\u0433\u0443\u0441\u0442 2023 \u0433\u043e\u0434\u0430 (\u0434\u043e \u044d\u0442\u043e\u0433\u043e \u0441 \u043d\u043e\u044f\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430 \u043f\u043e \u0430\u043f\u0440\u0435\u043b\u044c 2023 \u0433\u043e\u0434\u0430 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/rezultaty-vtorogo-audita-bezopasnosti-razrabotok-proekta-tor","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-01-30T23:41:06+00:00","article:modified_time":"2024-01-30T23:41:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/113257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=113257"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/113257\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=113257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=113257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=113257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}