Page 1 of 1

Heads up on Tor.

Posted: 28 Jul 2011, 15:29
by dedanna1029
Please do not turn this into a political thread. It's specifically to do with Tor. Last night, I was censored by my ISP on a link (see Political forum for that). Went to bed after that, then woke up this morning to this in my browser:

Image Image

I'm finding that what Tor does, in particular if you run a relay, is stick you on these malicious networks. I've been warned on it before, via my browser, just not by my ISP. I have no clue how to stop it from doing so. If anyone can think of anything, to make it stick me on something different, like a non-malicious network, I'd appreciate it.

In other news, I have told my ISP where to blow; that I run Linux, am using Tor, and that I don't intend to stop for their M$ Windbloze crap. This is why I run Tor, is to keep nimrods like them from listening to their own customer's computers (and told them that, too). Their AUP, I am doing nothing wrong.

Re: Heads up on Tor.

Posted: 29 Jul 2011, 17:53
by viking60
An explanation on how Tor works and a link to their sight should do it. There might be heavy duty forces that want to maintain control but mostly it is just ignorance.

Re: Heads up on Tor.

Posted: 29 Jul 2011, 21:44
by dedanna1029
No, it is tor, I've come to find out since. In particular when one's running a relay. I have found others with the same issue with it.

Re: Heads up on Tor.

Posted: 30 Jul 2011, 04:37
by dedanna1029
Dear (me);


Customer ID: xxxxxxxxx


Qwest Security Services has received notification about malicious traffic
originating from this account. This means that this computer or another
computer on your network is trying to infect, attack, or gain unauthorized
access to other computers on the Internet.

This malicious traffic has been determined to be an instance of the "Conficker"
worm.

Conficker, also known as "Downadup", is a worm that disables access to web
sites related to computer security and antivirus programs, in order to prevent
removal.

Details about this worm are available at:
http://www.f-secure.com/v-descs/worm_w3 ... p_al.shtml

http://www.sophos.com/security/analyses ... ckera.html

Please see the Acceptable Use Policy at:
http://www.qwest.com/legal/usagePolicy.html

Qwest may take further action, including the suspension or termination of
your Service. Please note that if you use the Internet for Voice over IP
services (VoIP) to support Internet based calling, you will not be able
to make any incoming or outgoing calls, including 9-1-1 calls, from your
service address unless you have Internet service. Also, disconnection
of a bundled service may result in loss of you bundle discount.


Qwest recommends that you patch all Windows operating systems, as described in
Microsoft Security Bulletin MS08-067.

Please make sure that the system software is up to date, that antivirus
software is installed with current antivirus signatures, and that your hard
disk(s) have been scanned to detect and remove all viruses, worms, trojans, or
other software which allow unauthorized remote control of your systems.

Because this worm blocks access to web sites related to computer security and
antivirus programs in order to prevent removal, attempts to update or obtain
antivirus programs may fail. For this reason, Qwest and Microsoft are providing
access to the Microsoft Malicious Software Removal Tool to assist our customers
in effectively removing this worm. This tool is available at:
http://www.qwest.net/MSRT

In the event that you are unable to update your antivirus program to remove the
worm, you may need to seek assistance from a computer professional to
effectively remove the worm and update your antivirus protection. Please note
that you may need to reinstall updated antivirus software after the worm is
removed to restore protection.

Additionally, having your firewall block inbound access to TCP port 445 may
prevent future access to vulnerable systems. Please consult your firewall or
server documentation for further instructions on how to block access to this
port.

Removal tools for this worm are available at:

* Microsoft Malicious Software Removal Tool:
http://www.microsoft.com/security/malwa ... fault.mspx
Or:
http://www.qwest.net/MSRT

* or, Symantec:
http://www.symantec.com/business/securi ... 16-0247-99

Other tools may be available through your antivirus provider.


The date, time (GMT) and IP addresses identified in our investigation
are as follows:

Date IP Additional Info
=================== =============== =======================================================
2011-07-26 15:58:49 75.173.30.2 infection => 'conficker', subtype => 'downadup', src_port => '45116', dst_port => '80', http_host => '149.20.56.34', url => 'GET /search?q=0 HTTP/1.1', http_agent => 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)', dst_ip => '149.20.56.34', sourceSummary => 'Sinkhole HTTP Drone Report'
2011-07-26 15:58:49 75.173.30.2 infection => 'conficker', subtype => 'downadup', src_port => '45116', dst_port => '80', http_host => '149.20.56.34', url => 'GET /search?q=0 HTTP/1.1', http_agent => 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)', dst_ip => '149.20.56.34', sourceSummary => 'Sinkhole HTTP Drone Report'



Regards,
--
Qwest Security Services sysop@qwest.net, abuse@qwest.net

Acceptable Use Policy
http://www.qwest.com/legal/usagePolicy.html

High Speed Internet Subscriber Agreement
http://www.qwest.com/legal/highspeedint ... agreement/

HAHAHAHAHA riiiiiiiiiiiiggghht... I'm gonna do that, for sure! <sarcasm>

Re: Heads up on Tor.

Posted: 31 Jul 2011, 19:15
by viking60
I cannot understand how the Conficker worm comes into it though? (It is nasty: I have dealt with it at work years ago).
For the rest even ISP's cannot imagine that anything but windows is possible :lol:

Re: Heads up on Tor.

Posted: 31 Jul 2011, 20:25
by dedanna1029
Yeah, I thought the same thing. I think it must be something off the relay, or something off the relay mimicking it.