Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Leaky captcha deanonymised Silk Road

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Leaky captcha deanonymised Silk Road
Reply
 
Thread Tools
Old 07-09-2014, 18:11   #1
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Leaky captcha deanonymised Silk Road

Real IP of the server was leaked/transmitted in the http headers returned to a user when an incorrect captcha was entered on the login page.

Quote:
Ever since October 2013, when the FBI took down the online black market and drug bazaar known as the Silk Road, privacy activists and security experts have traded conspiracy theories about how the U.S. government managed to discover the geographic location of the Silk Road Web servers. Those systems were supposed to be obscured behind the anonymity service Tor, but as court documents released Friday explain, that wasn’t entirely true: Turns out, the login page for the Silk Road employed an anti-abuse CAPTCHA service that pulled content from the open Internet, thus leaking the site’s true location.
Krebs

US declaration of how they found it (PDF) http://ia700603.us.archive.org/21/it...22824.57.0.pdf
Qtx is offline   Reply With Quote
Advertisement
Old 08-09-2014, 17:30   #2
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: Leaky captcha deanonymised Silk Road

Doubts cast over FBI 'leaky CAPTCHA' Silk Road rapture - Security bod says affadavit makes no sense

There are a few who were doing a lot of penetration testing of Silk Road who reckon it wasn't leaking ip's in headers like the FBI are saying. While http headers as well as the data in http replies in various configurations can leak that kind of data, there is enough reputable peeps saying it wasn't the case here.

Be it a 0-day exploit or info gained from other security researchers, it's looking like the FBI's explanation as to how they found Silk road is a bit fishy.
Qtx is offline   Reply With Quote
Old 09-09-2014, 19:31   #3
richard s
Permanently Banned
 
Join Date: Jan 2012
Location: Near France
Services: Tivo XL 150mb broadband L phone
Posts: 1,817
richard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful onerichard s is the helpful one
Re: Leaky captcha deanonymised Silk Road

I like my Onions on my burger thanks, the horizon program made very interesting viewing though, I may make a grand Tor! later.
richard s is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 23:21.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum