Yahoo Mail and Tor
Lee
ler762 at gmail.com
Thu Jul 9 17:36:24 UTC 2009
On 7/9/09, Andrew Lewman <andrew at torproject.org> wrote:
> On 07/09/2009 11:25 AM, Scott Bennett wrote:
>
>> enable-remote-toggle 0
>> enable-remote-http-toggle 0
>> enable-edit-actions 0
>> allow-cgi-request-crunching 0
>
> I'm trying to find the email thread, but until then, even with these
> set, it was demonstrated someone can manipulate your privoxy config by
> making your tor client pass strings from localhost.
Please post the link when you do find that thread. The only things I
could find were related to an insecure configuration of Privoxy - eg.
http://archives.seul.org/or/talk/Oct-2007/msg00295.html
http://osvdb.org/show/osvdb/48694
http://osvdb.org/show/osvdb/25875
Thanks,
Lee
More information about the tor-talk
mailing list