Anyone using TOR proxy server might want to read this

by The Copy Nazi Banned
4 replies
I had my Adwords a/c HACKED last night. Aholes got in and created a BOGUS campaign with a daily spend of €2000 at bids of up to €1.90. Luckily I couldn't sleep last night and was checking to see how my latest campaign was going and noticed the bogus one. But not before €220 had been rung up. Google are on it. They have shut down my account while they investigate it but they had already noticed the hack.

Here's the thing (and no this is not a sell) - I've been test-driving the open source free Proxy Server TOR for a week or so. I'm doing a campaign for a paid proxy server so this was part of my research. My programmer mate had this to say about TOR -
TOR is pretty safe but there are issues - probably the main one from a security point is that you have little control over where your data is routed. Onion routing systems are often targetted as you can get access to someone elses data by being an exit node. This guy demonstrated an exploit on SSL at the Black Hat conference last month - he got 254 passwords from TOR users in 24 hours.

To prove his point, he ran SSLstrip on a server hosting a Tor anonymous browsing network. During a 24-hour period, he harvested 254 passwords from users visiting sites including Yahoo, Gmail, Ticketmaster, PayPal, and LinkedIn. The users were fooled even though SSLstrip wasn't using the proxy feature that tricks them into believing they were at a secure site. Sadly, the Tor users entered passwords even though the addresses in their address bars didn't display the crucial "https." (Marlinspike said he later disposed of all personally identifiable information)"

*TOR is an amazing product but of course has no real funding and private servers which is why it uses the concept it does. It is much safer and more secure than loads of commercial products though. When I say Free anonymous proxies I don't mean TOR nodes though - many people search for anonymous proxies on the internet to use. They then just surf via these proxies - most are either hacked or accidently acting as proxies - hackers do it deliberately and log everything that goes through these servers - they pick up thousands of passwords, account etc by everyone using them.
#proxy #read #server #tor
  • Profile picture of the author asupport
    I have been using TOR myself for almost a year now with no problems. Any tips on how to prevent having your passwods stolen?
    Signature
    {{ DiscussionBoard.errors[700137].message }}
  • Profile picture of the author lacraiger
    wow thats scary. hopefully google catches them - they should be able to tell from the sites they are doing ppc for.
    {{ DiscussionBoard.errors[700167].message }}
  • Profile picture of the author The Copy Nazi
    Banned
    Originally Posted by ProductCreator View Post

    Running your traffic through several Russian and Chinese anonymous servers, it is no surprise that it is a great security risk.

    Why are you using TOR anyway? I would suggest buying a cheap VPN account e.g. VPN IP Tunneling - UK, USA and ca VPN tunneling services. Free UK TV
    Mate I already told you why I was using it. Der.
    {{ DiscussionBoard.errors[700256].message }}

Trending Topics