Tor: Difference between revisions

From Leo's Notes
This page was last edited on 1 September 2019, at 00:39.
m formatting
Line 8: Line 8:


With Tor set up, add the following lines to the torrc configuration file:
With Tor set up, add the following lines to the torrc configuration file:
HiddenServiceDir /srv/tor/hidden_services/
 
HiddenServicePort 80 192.168.192.10:8881
{{highlight|lang=text|code=
HiddenServiceDir /srv/tor/hidden_services/
HiddenServicePort 80 192.168.192.10:8881
}}


The {{code|HiddenServiceDir}} will contain the hidden service hostname and private key. All subsequent {{code|HiddenServicePort}} directives after will define the ports available from that hostname and to which IP data should be forwarded to.
The {{code|HiddenServiceDir}} will contain the hidden service hostname and private key. All subsequent {{code|HiddenServicePort}} directives after will define the ports available from that hostname and to which IP data should be forwarded to.
Line 29: Line 32:
=== FreeBSD ===
=== FreeBSD ===


cd /usr/ports/security/tor
{{highlight|lang=text|code=
make config-recursive
cd /usr/ports/security/tor
make install clean
make config-recursive
make install clean
echo 'enable_tor="YES"' >> /etc/rc.conf
 
vi /usr/local/etc/tor/torrc
echo 'enable_tor="YES"' >> /etc/rc.conf
vi /usr/local/etc/tor/torrc
}}


Put the following in your torrc file:
Put the following in your torrc file:


#
{{highlight|lang=text|code=
# Refer to https://www.torproject.org/docs/tor-manual.html.en
#
#
# Refer to https://www.torproject.org/docs/tor-manual.html.en
#
# Listen on localhost, using the default port of 9051
 
SocksPort 9051
# Listen on localhost, using the default port of 9051
SocksListenAddress 127.0.0.1
SocksPort 9051
SocksListenAddress 127.0.0.1
ORPort 9001
 
ORPort 9001
# Do not be an exit node
 
ExitPolicy reject *:*  
# Do not be an exit node
ExitPolicy reject *:*  
BandwidthRate 10 MB
 
BandwidthBurst 100 MB
BandwidthRate 10 MB
BandwidthBurst 100 MB
RunAsDaemon 1
 
RunAsDaemon 1
ContactInfo tor@steamr.com


ContactInfo tor@steamr.com
}}


To start tor, run
To start tor, run
/usr/local/etc/rc.d/tor start
 
{{highlight|lang=terminal|code=
# /usr/local/etc/rc.d/tor start
}}


== Blocking Tor ==
== Blocking Tor ==

Revision as of 00:39, 1 September 2019

Tor is an anonymity network using onion routing.

Transparent Proxy

For detailed instructions on setting up a transparent proxy, see TOR_Transparent_Proxy.

Hidden Service

See: https://www.torproject.org/docs/tor-hidden-service.html.en

With Tor set up, add the following lines to the torrc configuration file:

HiddenServiceDir /srv/tor/hidden_services/
HiddenServicePort 80 192.168.192.10:8881

The HiddenServiceDir will contain the hidden service hostname and private key. All subsequent HiddenServicePort directives after will define the ports available from that hostname and to which IP data should be forwarded to.

Sites

  • Hidden Wiki - zqktlwi4fecvo6ri.onion
  • Not evil search engine - hss3uro2hsxfogfq.onion
  • Intel exchange - rrcc5xgpiuf3xe6p.onion
  • 0day.in - qzbkwswfv5k2oj5d.onion
  • abraxas (online store) - abraxasdegupusel.onion
  • Readers against DRM - c3jemx2ube5v5zpg.onion


Hosting

VPS Hosting - kowloon5aibdbege.onion Freedom Hosting 2 - http://fhostingesps6bly.onion/

Installation

FreeBSD

cd /usr/ports/security/tor
make config-recursive
make install clean

echo 'enable_tor="YES"' >> /etc/rc.conf
vi /usr/local/etc/tor/torrc

Put the following in your torrc file:

#
# Refer to https://www.torproject.org/docs/tor-manual.html.en
#

# Listen on localhost, using the default port of 9051
SocksPort 9051
SocksListenAddress 127.0.0.1

ORPort 9001

# Do not be an exit node
ExitPolicy reject *:* 

BandwidthRate 10 MB
BandwidthBurst 100 MB

RunAsDaemon 1

ContactInfo tor@steamr.com

To start tor, run

# /usr/local/etc/rc.d/tor start

Blocking Tor

To block all tor exit nodes that can reach your server, use the TorBulkExitList.py script at https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=xxx

#/bin/sh

# create a new set for individual IP addresses
ipset -N tor iphash

# get a list of Tor exit nodes that can access $YOUR_IP, skip the comments and read line by line
wget -q https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=$YOUR_IP -O - | sed '/^#/d' | while read IP
do
  # add each IP address to the new set, silencing the warnings for IPs that have already been added
  ipset -q -A tor $IP
done

# filter our new set in iptables
iptables -A INPUT -m set --match-set tor src -j DROP

Script above copied from: https://github.com/scriptzteam/BlockTor/blob/master/block.sh