[tor-bugs] #25354 [Webpages/Website]: torproject.org using insecure ciphers/protocols (SSLv3, 3DES and RC4)

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Feb 26 00:30:51 UTC 2018


#25354: torproject.org using insecure ciphers/protocols (SSLv3, 3DES and RC4)
------------------------------+---------------------
 Reporter:  pege              |          Owner:  tpa
     Type:  defect            |         Status:  new
 Priority:  Very High         |      Milestone:
Component:  Webpages/Website  |        Version:
 Severity:  Major             |     Resolution:
 Keywords:                    |  Actual Points:
Parent ID:                    |         Points:
 Reviewer:                    |        Sponsor:
------------------------------+---------------------
Changes (by pege):

 * component:  Internal Services/Tor Sysadmin Team => Webpages/Website


Comment:

 Something seems to be of with the DNS records too. Only www.torproject.org
 can be resolved, torproject.org can't.

 {{{
 $ dig torproject.org @8.8.8.8

 ; <<>> DiG 9.10.3-P4-Debian <<>> torproject.org @8.8.8.8
 ;; global options: +cmd
 ;; Got answer:
 ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45845
 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

 ;; OPT PSEUDOSECTION:
 ; EDNS: version: 0, flags:; udp: 512
 ;; QUESTION SECTION:
 ;torproject.org.                        IN      A

 ;; AUTHORITY SECTION:
 torproject.org.         1539    IN      SOA     nevii.torproject.org.
 hostmaster.torproject.org. 2018022538 10800 3600 1814400 3601

 ;; Query time: 16 msec
 ;; SERVER: 8.8.8.8#53(8.8.8.8)
 ;; WHEN: Mon Feb 26 01:27:42 CET 2018
 ;; MSG SIZE  rcvd: 96

 $ dig www.torproject.org @8.8.8.8

 ; <<>> DiG 9.10.3-P4-Debian <<>> www.torproject.org @8.8.8.8
 ;; global options: +cmd
 ;; Got answer:
 ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21531
 ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

 ;; OPT PSEUDOSECTION:
 ; EDNS: version: 0, flags:; udp: 512
 ;; QUESTION SECTION:
 ;www.torproject.org.            IN      A

 ;; ANSWER SECTION:
 www.torproject.org.     149     IN      A       154.35.175.245

 ;; Query time: 126 msec
 ;; SERVER: 8.8.8.8#53(8.8.8.8)
 ;; WHEN: Mon Feb 26 01:28:00 CET 2018
 ;; MSG SIZE  rcvd: 63
 }}}

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/25354#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list