[Technical Discussion] So, any new info on how feds busted that hidden service?

Glad they busted pedos, but this article doesn't give much info on how they found the hidden service or what kind of exploit they used to deanon users. I think we'll all agree busting pedos is good, but it does raise questions on the status of Tor hidden services and what type of exploits are being used.

The article mentions something about tracing users once they logged on, so we must assume this site had a membership feature. Similar to SR2 busts where they were able to nab vendors logging into the vendor login page, maybe this type of exploit hooks into a php login function to exploit a user?

Any ideas or info?


Comments


[5 Points] sapiophile:

Isn't this the one where they left the forum's administrator password blank? If so, then I imagine the attack went like this:

  1. Feds seize control of the site's administrator account (just by logging in to it) and lock out other administrators,

  2. They invisibly modify the site's styling to serve malicious JavaScript to logged in visitors that de-anonymizes them - this lines up with "the FBI obtained a search warrant from a judge in Virginia that authorized it to use a technique that would cause a computer to send it data anytime a user logged on."

  3. Feds keep running the site for a couple of weeks to get lots of users' real IP addresses via their JavaScript implant.

  4. Profit!

Nothing really groundbreaking about any of this, although I'm pretty amazed that even pedos don't disable all scripts and embeds in their browser.

TL;DR: set the security slider to "High" and keep it there, and uh, don't leave the admin account of your onion site wide open.


[2 Points] None:

They used a well known JS exploit to deanon users, it only worked on Windows, but keep JS disabled. The hidden service was hacked.

EDIT: thought OP was talking about FH, no idea about this case, whoever voted me is an idiot


[0 Points] smokingdickhead:

Im not quite sure busting pedo websites is as good as people make it out to be . now that most child porn videos are gone what lengths will pedos now go to to get rid of the urge ?