Heads up on Tor.

What do you have and what do you want?

Moderators: b1o, jkerr82508

User avatar
dedanna1029
Sound-Berserk
Posts: 8784
Joined: 14 Mar 2010, 20:29
Contact:

Heads up on Tor.

Postby dedanna1029 » 28 Jul 2011, 15:29

Please do not turn this into a political thread. It's specifically to do with Tor. Last night, I was censored by my ISP on a link (see Political forum for that). Went to bed after that, then woke up this morning to this in my browser:

Image Image

I'm finding that what Tor does, in particular if you run a relay, is stick you on these malicious networks. I've been warned on it before, via my browser, just not by my ISP. I have no clue how to stop it from doing so. If anyone can think of anything, to make it stick me on something different, like a non-malicious network, I'd appreciate it.

In other news, I have told my ISP where to blow; that I run Linux, am using Tor, and that I don't intend to stop for their M$ Windbloze crap. This is why I run Tor, is to keep nimrods like them from listening to their own customer's computers (and told them that, too). Their AUP, I am doing nothing wrong.
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Re: Heads up on Tor.

Postby viking60 » 29 Jul 2011, 17:53

An explanation on how Tor works and a link to their sight should do it. There might be heavy duty forces that want to maintain control but mostly it is just ignorance.
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
dedanna1029
Sound-Berserk
Posts: 8784
Joined: 14 Mar 2010, 20:29
Contact:

Re: Heads up on Tor.

Postby dedanna1029 » 29 Jul 2011, 21:44

No, it is tor, I've come to find out since. In particular when one's running a relay. I have found others with the same issue with it.
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html

User avatar
dedanna1029
Sound-Berserk
Posts: 8784
Joined: 14 Mar 2010, 20:29
Contact:

Re: Heads up on Tor.

Postby dedanna1029 » 30 Jul 2011, 04:37

Dear (me);


Customer ID: xxxxxxxxx


Qwest Security Services has received notification about malicious traffic
originating from this account. This means that this computer or another
computer on your network is trying to infect, attack, or gain unauthorized
access to other computers on the Internet.

This malicious traffic has been determined to be an instance of the "Conficker"
worm.

Conficker, also known as "Downadup", is a worm that disables access to web
sites related to computer security and antivirus programs, in order to prevent
removal.

Details about this worm are available at:
http://www.f-secure.com/v-descs/worm_w3 ... p_al.shtml

http://www.sophos.com/security/analyses ... ckera.html

Please see the Acceptable Use Policy at:
http://www.qwest.com/legal/usagePolicy.html

Qwest may take further action, including the suspension or termination of
your Service. Please note that if you use the Internet for Voice over IP
services (VoIP) to support Internet based calling, you will not be able
to make any incoming or outgoing calls, including 9-1-1 calls, from your
service address unless you have Internet service. Also, disconnection
of a bundled service may result in loss of you bundle discount.


Qwest recommends that you patch all Windows operating systems, as described in
Microsoft Security Bulletin MS08-067.

Please make sure that the system software is up to date, that antivirus
software is installed with current antivirus signatures, and that your hard
disk(s) have been scanned to detect and remove all viruses, worms, trojans, or
other software which allow unauthorized remote control of your systems.

Because this worm blocks access to web sites related to computer security and
antivirus programs in order to prevent removal, attempts to update or obtain
antivirus programs may fail. For this reason, Qwest and Microsoft are providing
access to the Microsoft Malicious Software Removal Tool to assist our customers
in effectively removing this worm. This tool is available at:
http://www.qwest.net/MSRT

In the event that you are unable to update your antivirus program to remove the
worm, you may need to seek assistance from a computer professional to
effectively remove the worm and update your antivirus protection. Please note
that you may need to reinstall updated antivirus software after the worm is
removed to restore protection.

Additionally, having your firewall block inbound access to TCP port 445 may
prevent future access to vulnerable systems. Please consult your firewall or
server documentation for further instructions on how to block access to this
port.

Removal tools for this worm are available at:

* Microsoft Malicious Software Removal Tool:
http://www.microsoft.com/security/malwa ... fault.mspx
Or:
http://www.qwest.net/MSRT

* or, Symantec:
http://www.symantec.com/business/securi ... 16-0247-99

Other tools may be available through your antivirus provider.


The date, time (GMT) and IP addresses identified in our investigation
are as follows:

Date IP Additional Info
=================== =============== =======================================================
2011-07-26 15:58:49 75.173.30.2 infection => 'conficker', subtype => 'downadup', src_port => '45116', dst_port => '80', http_host => '149.20.56.34', url => 'GET /search?q=0 HTTP/1.1', http_agent => 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)', dst_ip => '149.20.56.34', sourceSummary => 'Sinkhole HTTP Drone Report'
2011-07-26 15:58:49 75.173.30.2 infection => 'conficker', subtype => 'downadup', src_port => '45116', dst_port => '80', http_host => '149.20.56.34', url => 'GET /search?q=0 HTTP/1.1', http_agent => 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)', dst_ip => '149.20.56.34', sourceSummary => 'Sinkhole HTTP Drone Report'



Regards,
--
Qwest Security Services [email protected], [email protected]

Acceptable Use Policy
http://www.qwest.com/legal/usagePolicy.html

High Speed Internet Subscriber Agreement
http://www.qwest.com/legal/highspeedint ... agreement/

HAHAHAHAHA riiiiiiiiiiiiggghht... I'm gonna do that, for sure! <sarcasm>
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Re: Heads up on Tor.

Postby viking60 » 31 Jul 2011, 19:15

I cannot understand how the Conficker worm comes into it though? (It is nasty: I have dealt with it at work years ago).
For the rest even ISP's cannot imagine that anything but windows is possible :lol:
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
dedanna1029
Sound-Berserk
Posts: 8784
Joined: 14 Mar 2010, 20:29
Contact:

Re: Heads up on Tor.

Postby dedanna1029 » 31 Jul 2011, 20:25

Yeah, I thought the same thing. I think it must be something off the relay, or something off the relay mimicking it.
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html


Return to “Software”