Register Members List Search Today's Posts Mark Forums Read

Thread Tools
Old 23 Jun 2008, 11:14
Eunos Eunos is offline
Join Date: Sep 2003
Tor project enables anonymous hack attempts - how to combat it?

In the past 5 days, I've been getting swamped with email from registered forum users who are responding to the vB note that gets sent out when someone fails after 5 login attempts. Every one of them was telling me "it wasn't me".

Investigation of the IP addresses they're coming from reveals that they're bouncing off exit nodes from the Tor network. The Tor network is a distributed cryptographic anonymizing proxy service. It is not possible at this time to identify the actual source.

So in layman's terms - the hack attempts are coming from someone who is abusing the Tor network in order to anonymously attempt to log in to this forum as a legitimate user. If they succeed, they're most likely going to use it to spam the forum with ads.

I've been firewalling out IP addresses right and left, but this is proving to be useless since there are hundreds, or maybe thousands of Tor servers out there, and the hackers simply find another one to continue their barrage. And since Tor is totally anonymous, there's no way to identify the originator, and therefore no way to halt the break in attempts.

I found an abuse FAQ, and it has some hints on how to determine whether an IP is a Tor exit server.

What I'd like to do is have a hack that can identify a server as a Tor server, and simply block all registration and login attempts from those servers.

Has anyone does this? Any different suggestions?
Reply With Quote
Old 23 Jun 2008, 11:29
KURTZ KURTZ is offline
Join Date: Nov 2006
Real name: Christian
have you tried PM's hack 'proxy to real ip' add-on?
Reply With Quote
Old 23 Jun 2008, 11:57
Eunos Eunos is offline
Join Date: Sep 2003
How would that help?
Reply With Quote
Old 26 Jun 2008, 09:39
Angel-Wings's Avatar
Angel-Wings Angel-Wings is offline
Join Date: Sep 2007
That wouldn't help - no need to install it. About the problem - there's not much you can do
Reply With Quote
Old 26 Jun 2008, 10:45
fedorama fedorama is offline
Join Date: Jun 2008
I'm pretty sure there is something you can add server-side that will block all Tor IPs .. at least I remember reading that on the Tor project.
Reply With Quote
Old 26 Jun 2008, 10:51
Eunos Eunos is offline
Join Date: Sep 2003
Its really getting annoying, mostly because of the email that vB sends telling the account holder that someone tried to hack their account. So they get all worked up and scared, and they send me email telling me to delete their account - which I don't want to do because I hate having posts from someone named "Guest".
Reply With Quote
Old 26 Jun 2008, 12:45
Alfa1's Avatar
Alfa1 Alfa1 is offline
Join Date: Dec 2005
Proxy to IP is real helpful with identifying proxy users. Consider this hack:
Note that it excludes safari users.
Reply With Quote
Old 26 Jun 2008, 13:42
Dismounted's Avatar
Dismounted Dismounted is offline
Join Date: Jun 2005
Real name: Hanson
I don't think you understand the Tor network, Alfa1. Tor makes it pretty much impossible to locate where data originally came from, as it is passed from node to node before reaching its destination.
Former Staff Member

View My Modifications
29 Releases and Counting... Latest Modification: dmActivityStream - vBookie Integration (4.x)

Please do not PM me to ask for support - please use the relevant thread or forum.
Reply With Quote
Old 26 Jun 2008, 13:57
JoeBOBBillyTed JoeBOBBillyTed is offline
Join Date: Feb 2005
Why not disable the email. It won't fix the main problem, however it may stop the bleeding.
Reply With Quote
Old 26 Jun 2008, 14:50
blind-eddie's Avatar
blind-eddie blind-eddie is offline
Join Date: Apr 2006
Real name: Tim
wild card ban thier ip within your host, not only your site.
Reply With Quote

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

New To Site? Need Help?

All times are GMT. The time now is 07:01.

Layout Options | Width: Wide Color: