Tor: Beyond anonymous

Network August 2nd, 2006

Tor is well known as the anonymous Internet communication network, How Tor worksthe common practice is to bind tor with privoxy for the anonymous network surfing.

Beyond of this, tor also open a tunnel on the firewall. Suppose you live in irc.freenode.net but the port 6667 is blocked by the firewall. You can torify irssi to using the hidden service, and keep you IP private, — one stone kills two birds!

Add this line to /etc/tor/torrc

mapaddress 10.40.40.40 mejokbp2brhw4omd.onion

Run irssi in torified mode:

$ torify irssi

In irssi, /conn 10.40.40.40 to access irc.freenode.net

If you don’t have the privilege to access /etc/tor/torrc, you need socat to relay the tor network to your local socket proxy:

$ socat TCP4-LISTEN:6667,fork SOCKS4A:localhost:6ua4nhltph56henu.onion:6667,socksport=9050

Then you can run irssi and /conn localhost

There is a more detailed HOWTO about the onion router.

Social engineering rocks

Network December 7th, 2005

I just read this funny story about how to stop P2P user utilizing all the public bandwidth in the hotel. Just read the conversation between “Eric Smith” and “me”:

Me: Eric Smith?

Eric: Uhh, yeah?

Me: My name is Jim Grant, and I’m an investigator with the RIAA. Have you heard of us?

Eric: Uhhhhh… What does that stand for?

Me: Recording Industry Association of America. We represent several large record companies. In monitoring several p2p file-sharing networks, we have found that you Eric, are currently downloading copyrighted material. Are you aware that this is illegal?

Eric: Ummm. my laptop is off. (At this point, I no longer see him on the network)

Me: We are in the process of filing 18182 lawsuits against people who steal copyrighted music on the internet. We will continue monitoring these networks, and if we see you on them again, you will hear back from us.

Eric: Ok, thanks. Bye.

The author take another approach, social engineering to solve this problem. We would discuss more about the geek’s traditional approaches like ntop, arp poisoning, raw packet injection etc. later.