On Metacritic: Predict the Oscar winners!
BNET Business Network:
BNET
TechRepublic
ZDNet

March 6th, 2007

Hacker builds tracking system to nab Tor pedophiles

Posted by Ryan Naraine @ 7:10 pm

Categories: Browsers, Exploit code, Hackers, Metasploit, Open source, Patch Watch, Privacy, Punditocracy, Spyware and Adware, Vulnerability research

Tags: DNS, IP, Server, Pedophile, Applet, Hacker, Ryan Naraine

Amidst concerns that pedophiles are using public Tor (the Onion Router) servers to trade in child pornography, über-hacker HD Moore is building a tracking system capable of pinpointing specific workstations that searched for and downloaded sexual images and videos of kids.

Moore, the brains behind the Metasploit Project, has come up with a series of countermeasures that include using patched Tor servers and a decloaking engine to detect the exact location of a pedophile within an organization or residence.

HD MooreMoore first discussed his "countermeasures" at a meeting of the Austin Hackers Association (AHA) last summer when it became clear that the EFF-backed anonymity/privacy network was being used for the most nefarious purposes. Further confirmation came last September when German authorities cracked down on Tor node operators because of the proliferation of child porn.

In an e-mail interview, Moore said the plan is to release the source code, which will allow anyone to run a patched Tor server to help pinpoint pedophiles online.

Moore's description of the countermeasures:

1. Run a patched TOR server. The patches embed a Ruby interpreter into the TOR connection engine and allow arbitrary Ruby scripts to process data before sending it back to the client.

2. When child porn-related keywords are seen (either the Web request, or the response), inject a little extra HTML code into the response going back to the Web browser. This HTML code would connect to my decloaking engine.

3. The decloak engine is based on the following techniques:

a) A unique identifier is created to track this user.

b) The browser is asked to resolve a unique host name, containing the identifier, that is part of a special domain hosted on my server. I run a modified DNS server that updates a database with the address from which the DNS request is received. The goal of this step is to determine the ISP of the user.

c) The browser is asked to load a Java applet. This applet uses two different techniques to obtain information about the user.

d) The first method uses the Java API to determine the local IP address of the user. This value is then passed back to the JavaScript code in the Web HTML snippet hosting the applet. The goal of this step is to get the real *internal* IP address of the user.

e) The second method involves the applet sending a raw DNS packet, directly to my server. Since this is UDP, it does not pass through TOR, and since it is sent by the Java code, it does not go through the ISP. This packet contains the unique identifier and if received, gives away the real *external* IP of the user. The goal of this step is to get the address of the user's NAT gateway.

f) At this point, my server is able to determine the internal address of the user, the external address from which they access the internet, and the ISP they use to provide DNS resolution, as well as the IP address they come from through the TOR network. This information, along with the unique tracking ID, allows me to identify a specific workstation within an organization or residence.

As to whether this is enough for law enforcement authorities to make an arrest and build a case, Moore's answer: "No idea."

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 23 Talkback(s)
but doesnt it breaks the whole point?
Kind of rules and kind of sucks.

What happens to all other legitimate uses of tor? While it is cool to kick some paedophiles butts, it pretty much renders Tor useless for a lot of it legitimate... (Read the rest)
Posted by: flpgdt Posted on: 01/26/10 You are currently: a Guest | | Terms of Use
An arrest should be imminent  sweklaweklfwe@... | 03/07/07
You even understand what's going on?  georgeou | 03/07/07
Do you understand?  No_Ax_to_Grind | 03/07/07
You are right on  Taz_z | 03/07/07
That's the tradeoff, anything can be abused  georgeou | 03/07/07
His method is flawed and doesn't work!!!  JanusVM | 03/07/07
Actually, the basic premise does work  Taz_z | 03/07/07
happy  JanusVM | 03/07/07
Re: Actually, the basic premise does work  Someguy2 | 03/09/07
Message has been deleted.  Reverend MacFellow | 03/07/07
Only if he is looking at ...  ShadeTree | 03/07/07
The whole point of anonymous software is so people can do whatever they ..  Been_Done_Before | 03/07/07
Thanks from Communist China, etc.  Rick_R | 03/07/07
Reality check.  sweklaweklfwe@... | 03/07/07
Inadissable Evidence?  mejohnsn | 03/08/07
Yes, this account...  sweklaweklfwe@... | 03/07/07
Different values  Dr_Zinj | 03/08/07
seriously...  ZDNET_guest666 | 07/31/07
RE: Hacker builds tracking system to nab Tor pedophiles  13thHouR | 11/10/07
RE: Hacker builds tracking system to nab Tor pedophiles  gregaustin | 06/18/08
RE: Hacker builds tracking system to nab Tor pedophiles  mejohnsn | 03/27/09
RE: Hacker builds tracking system to nab Tor pedophiles  mejohnsn | 03/27/09
but doesnt it breaks the whole point?  flpgdt | 01/26/10

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads