Close Menu
USAHITMAN Conspiracy News
    Facebook X (Twitter) Instagram
    USAHITMAN Conspiracy NewsUSAHITMAN Conspiracy News
    • Home
    • Featured News
      Featured

      Prince Warned Of 9/11 Attacks In 1998

      9/11 May 7, 2016
      Recent

      Hunter Biden filmed himself smoking crack behind the wheel, driving at 172mph on way to Vegas: photos

      July 2, 2023

      King Charles, Bill Gates Foundation and The OceanGate Missing Submarine – How its connected

      June 22, 2023

      Why Is WEF & Bill Gates-Funded APEEL ON Organic Produce?

      June 18, 2023
    • Conspiracy News
      1. 911 Conspiracy
      2. Big Brother
      3. Police State
      4. NWO
      5. UFOs & ETs
      6. Conspiracy or Not
      7. Freemasonry
      8. Chemtrails
      9. HAARP News
      10. The Unknown
      11. Terrorism
      12. Lies & Hoaxes
      Featured

      Candidate Le Pen’s Political Ad Regarding France from the Year 2011

      Conspiracy or Not July 3, 2023
      Recent

      Candidate Le Pen’s Political Ad Regarding France from the Year 2011

      July 3, 2023

      Justice Department: Misconduct by federal jail guards led to Jeffrey Epstein’s suicide

      June 28, 2023

      The 4th Dimension and the Birth of the Jungle Gym

      June 27, 2023
    • Interesting News
      1. Covid
      2. Deaths
      3. Food & Health News
      4. Economy & Money
      5. Restrictions
      6. Bitcoin News
      7. Our Second Amendment
      8. Science & Space
      9. Much More News
      Featured

      U.S. Navy says it can convert seawater into fuel

      Interesting News April 8, 2014
      Recent

      George Soros’ foundation lays off 40% of workforce after billionaire investor’s son takes over

      July 1, 2023

      Supreme Court rejects affirmative action at colleges as unconstitutional

      June 30, 2023

      Prosecutor Reportedly Told Six Witnesses He Was Not Permitted To Charge Hunter Biden

      June 28, 2023
    • Archived Years
      • 2010 Articles
      • 2011 Articles
      • 2012 Articles
    USAHITMAN Conspiracy News
    Home»Featured News»Half of all TOR sites compromised, Freedom Hosting founder arrested

    Half of all TOR sites compromised, Freedom Hosting founder arrested

    August 5, 20134 Mins Read
    Facebook Twitter Reddit Telegram Email

    tor-logo

    The founder of Freedom Hosting has been arrested in Ireland and is awaiting extradition to USA.

    In a crackdown that FBI claims to be about hunting down pedophiles, half of the onion sites in the TOR network has been compromised, including the e-mail counterpart of TOR deep web, TORmail.

    http://www.independent.ie/irish-news/courts/fbi-bids-to-extradite-largest-childporn-dealer-on-planet-29469402.html

    This is undoubtedly a big blow to the TOR community, Crypto Anarchists, and more generally, to Internet anonymity. All of this happening during DEFCON.

    If you happen to use and account name and or password combinations that you have re used in the TOR deep web, change them NOW.

    Eric Eoin Marques who was arrested runs a company called Host Ultra Limited.

    http://www.solocheck.ie/Irish-Company/Host-Ultra-Limited-399806
    http://www.hostultra.com/

    He has an account at WebHosting Talk forums.

    http://www.webhostingtalk.com/showthread.php?t=157698

    A few days ago there were mass outages of Tor hidden services that predominantly effected Freedom Hosting websites.

    http://postimg.org/image/ltj1j1j6v/

    “Down for Maintenance
    Sorry, This server is currently offline for maintenance. Please try again in a few hours.”

    If you saw this while browsing Tor you went to an onion hosted by Freedom Hosting. The javascript exploit was injected into your browser if you had javascript enabled.

    What the exploit does:

    The JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn’t get deleted. Presumably it reports the victim’s IP back to the FBI.

    An iframe is injected into FH-hosted sites:

    TOR/FREEDOM HOST COMPORMISED
    By: a guest on Aug 3rd, 2013
    http://pastebin.com/pmGEj9bV

    Which leads to this obfuscated code:

    Javascript Mozilla Pastebin
    Posted by Anonymous on Sun 4th Aug 02:52
    http://pastebin.mozilla.org/2776374

    FH STILL COMPROMISED
    By: a guest on Aug 3rd, 2013
    http://pastebin.com/K61QZpzb

    FBI Hidden Service in connection with the JavaScript exploit:
    7ydnpplko5lbgfx5

    Who’s affected Time scales:

    Anyone who accessed an FH site in the past two days with JavaScript enabled. Eric Eoin Marques was arrested on Sunday so that’s the earliest possible date.

    “In this paper we expose flaws both in the design and implementation of Tor’s hidden services that allow an attacker to measure the popularity of arbitrary hidden services, take down hidden services and deanonymize hidden services
    Trawling for Tor Hidden Services: Detection, Measurement, Deanonymization”

    http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf

    The FBI Ran a Child Porn Site for Two Whole Weeks
    http://gizmodo.com/why-the-fbi-ran-a-child-porn-site-for-two-whole-weeks-510247728

    http://postimg.org/image/o4qaep8pz/

    On any other day one would say these sick perverts got what they deserved. Unfortunately the Feds are stepping far beyond just pedophiles in this latest issue.

    The js inserted at Freedom Hosting? Nothing really, just an iframe inject script with a UUID embedded server-side.

    The iframe then delivers an exploit kit that appears to be a JavaScript 0day leading to…something. It only attempts to exploit Firefox (17 and up) on Windows NT. There’s definitely some heap spraying and some possible shell code. The suspect shell code block contains some strings that look to formulate an HTTP request, but I haven’t been able to collect the final payload yet. The shell code also contains the UUID with which the exploit was delivered. Any UUID will work to get this part of the exploit.

    I’m still pulling this little bundle of malware apart. So far, I’ve got that the attack is split across three separate files, each loaded into an iframe. Calls are made between the frames to further obfuscate the control flow. The ‘content_2.html’ and ‘content_3.html’ files are only served up if the request “looks like” Firefox and has a correct Referer header. The ‘content_2.html’ is loaded from the main exploit iframe and in turn loads ‘content_3.html’.

    Short version. Preliminary analysis: This little thing probably CAN reach out without going through Tor. It appears to be exploiting the JavaScript runtime in Firefox to download something.

    UPDATE: The exploit only affects Firefox 17 and involves several JS heap-sprays. Note that the current Extended Support Release is Firefox 17, so this may also affect some large organizations using Firefox ESR.

    http://pastebin.mozilla.org/2777139

    The script will only attempt the exploit on Firefox 17, so I’m no longer worried about it being some new 0day. Enough of the “Critical” MFSAs are for various sorts of memory corruption that I don’t have the time to find out if this is actually a new exploit or something seen before.

    http://postimg.org/image/mb66vvjsh/

    Logical outcomes from this?

    1. FBI/NSA just shut down the #1 biggest hosting site and #1 most wanted person on Tor

    2. Silkroad is next on their list, being the #2 most wanted (#1 was Child Porn, #2 is drugs)

    3. Bitcoin and all crypto currenecies set to absolutely CRASH as a result since the feds can not completely control this currency as they please.

    I don’t always call the Feds agenda transparent, but when i do, I say they can be trying harder.

    Compromised FBI Freedom Hosting Onion Passwods Sites Tor
    Share. Facebook Twitter Pinterest Email Reddit

    Related Posts

    Hunter Biden filmed himself smoking crack behind the wheel, driving at 172mph on way to Vegas: photos

    July 2, 2023

    King Charles, Bill Gates Foundation and The OceanGate Missing Submarine – How its connected

    June 22, 2023

    Why Is WEF & Bill Gates-Funded APEEL ON Organic Produce?

    June 18, 2023

    Candidate Le Pen’s Political Ad Regarding France from the Year 2011

    July 3, 2023

    Vaccine billionaire’s 3000 per cent gain with surprise bet

    July 3, 2023

    Hunter Biden filmed himself smoking crack behind the wheel, driving at 172mph on way to Vegas: photos

    July 2, 2023

    Millions of Your Taxpayer Dollars Are Going to Fund Foreign Pride Parades and Drag Shows

    July 2, 2023
    Categories
    • 9/11 (108)
    • Big Brother (635)
    • Conspiracy or Not (567)
    • Covid (270)
    • Deaths (71)
    • Economy & Money (953)
    • Featured News (377)
    • Food & Health News (1,146)
    • Fukushima (82)
    • Interesting News (1,956)
    • Lies & Hoaxes (112)
    • More News (2,399)
    • NWO (385)
    • Police State (628)
    • Politics (333)
    • Predictions and Prophecies (43)
    • Random News (2,487)
    • Restrictions (152)
    • Science & Space (953)
    • Second Amendment (129)
    • Secret Societies (112)
    • Survival (67)
    • Terrorism (595)
    • The Unknown (666)
    • UFOs & ETs (388)
    • Vaccine News (237)
    • War News (878)
    • Weather Manipulation (34)
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.