{"id":6932,"date":"2018-09-11T00:33:56","date_gmt":"2018-09-10T22:33:56","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=6932"},"modified":"2022-07-21T18:36:44","modified_gmt":"2022-07-21T16:36:44","slug":"advisory-tor-7-x-bug-leading-to-bypass-anonymity","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/09\/11\/advisory-tor-7-x-bug-leading-to-bypass-anonymity\/","title":{"rendered":"Advisory: Tor 7.x bug leading to bypass anonymity"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" title=\"Tor\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" border=\"0\" alt=\"Sicherheit\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2014\/11\/Tor.jpg\" width=\"78\" align=\"left\" height=\"43\">A few days ago, in my German article Tor Browser 8.0 erschienen, I introduced the new version of the Tor browser. If you're still using older versions of Tor 7.x, you should switch as soon as possible..<\/p>\n<p><!--more--><\/p>\n<p>Zerodium, a vendor that buys and sells exploits for software, has announced on Twitter that Tor 7.x is insecure. A bug allows a user's choice of security level to be bypassed.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">Advisory: Tor Browser 7.x has a serious vuln\/bugdoor leading to full bypass of Tor \/ NoScript 'Safest' security level (supposed to block all JS). <br \/>PoC: Set the Content-Type of your html\/js page to \"text\/html;\/json\" and enjoy full JS pwnage. Newly released Tor 8.x is Not affected.<\/p>\n<p>\u2014 Zerodium (@Zerodium) <a href=\"https:\/\/twitter.com\/Zerodium\/status\/1039127214602641409?ref_src=twsrc%5Etfw\">10. September 2018<\/a><\/p><\/blockquote>\n<p><span id=\"preservec4c50a2a812b46e3a5e33e31756ee30a\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>All browsers are probably affected by the JavaScript exploits under Tor 7.x. Only the new Tor 8.x version is not affected. The developer of the NoScript add-on developed and released an update (<a href=\"https:\/\/noscript.net\/getit#classic\" target=\"_blank\" rel=\"noopener\">5.1.8.7<\/a>) after ZDNet.com pointed out the facts <a href=\"https:\/\/www.zdnet.com\/article\/exploit-vendor-drops-tor-browser-zero-day-on-twitter\/\" target=\"_blank\" rel=\"noopener\">in this article<\/a>. neowin.net <a href=\"https:\/\/www.neowin.net\/news\/zerodium-an-exploit-vendor-highlights-tor-7x-vulnerability-upgrade-now\" target=\"_blank\" rel=\"noopener\">writes here<\/a> that Zerodium sold the exploit months ago to another company that shares it with government organizations. So it means to update to Tor 8.x. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>A few days ago, in my German article Tor Browser 8.0 erschienen, I introduced the new version of the Tor browser. If you're still using older versions of Tor 7.x, you should switch as soon as possible..<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[872,580,22],"tags":[69,529],"class_list":["post-6932","post","type-post","status-publish","format-standard","hentry","category-browser","category-security","category-update","tag-security","tag-tor"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/6932","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=6932"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/6932\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=6932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=6932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=6932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}