• Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
  • Resources
  • Industry Voice
  • Data Strategy Spotlight
  • Newsletters
  • Resources
    • Inqlogo 120x194
      Five things you should look for in choosing a Testing provider

      Choosing a Testing Partner can be complex.  So what do you look for?  This guide offers insight into the qualities you must look for in choosing a Testing provider.  Download now to learn more.

      Download
      Inqlogo 120x194
      Your questions answered: How to protect your data in the cloud

      The number of successful cyberattacks per year per company has increased by 46% over the last four years. But what really needs to be considered when exploring a solution? What questions need to be asked? Download to find out...

      Download
      Find resources
      Search by title or subject area
      View all resources
  • Follow us
    • RSS
    • Twitter
    • LinkedIn
    • Newsletters
    • Facebook
    • Google+
    • YouTube
  • Newsletter
  • Industry Voice
  • Data Strategy Spotlight
The Inquirer
The Inquirer
  • Home
  • News
  • Artificial Intelligence
  • Internet of Things
  • Open Source
  • Hardware
  • Software
  • Security
  • Trending
  • ICO fines Facebook
  • Thomas Cook breach
  • Galaxy Note 9
  • iPhone 9
  • World Cup
The Inquirer
  • Security

TorMoil: Tor flaw exposed IP addresses of Linux and Mac users

A full fix is expected later today

Tor flaw exposed IP addresses of Linux and Mac users
Tor flaw exposed IP addresses of Linux and Mac users
  • Nicholas Fearn
  • 06 November 2017
  • Tweet  
  • Facebook  
  • Google plus  
  •  
  •  
  • Send to  
0 Comments

A FLAW in the Tor browser last week exposed the IP addresses of Mac and Linux users. 

Every time a user clicked onto links starting with file://, as opposed to https:// and http://, the vulnerability would kick into action. It's been named TorMoil by its finder.

In a blog post published by We Are Segment, the security firm explains that when macOS and Linux users open these addresses, the OS connects directly to the remote host.

"Recently, our CEO, Filippo Cavallarin, discovered a critical security vulnerability in Tor Browser affecting Mac and Linux users that can lead to the leakage of users real IP address," the company wrote.

"Due to a Firefox bug in handling file:// URLs it is possible on both systems that users leak their IP address. Once an affected user navigates to a specially crafted web page, the operating system may directly connect to the remote host, bypassing Tor Browser."

Members of the Tor Project released a temporary fix on Friday and said Windows users haven't been affected by the problem.

"Tor Browser 7.0.9 is a security bugfix release for macOS and Linux users only. Users on Windows are not affected and stay on Tor Browser 7.0.8," the Project said.

"Tor Browser 7.0.9 is now available for our macOS and Linux users from the Tor Browser Project page and also from our distribution directory.

Related: Tor updates infrastructure to help protect the identity of servers

"This release features an important security update to Tor Browser for macOS and Linux users. Due to a Firefox bug in handling file:// URLs it is possible on both systems that users leak their IP address (note: as of Nov. 4, 2017, this link is non-public while Mozilla works on a fix for Firefox).

"Once an affected user navigates to a specially crafted URL the operating system may directly connect to the remote host, bypassing Tor Browser. Tails users and users of our sandboxed-tor-browser are unaffected, though."

Tor developers teamed up with Mozilla to come up with a fix the next day, and the patch for all affected versions is set to go live on Monday. µ

  • Tweet  
  • Facebook  
  • Google plus  
  •  
  •  
  • Send to  
  • Topics
  • Security
  • Security
  • Linux
  • tor
  • macos

INQ Latest

India sets the bar for net neutrality with 'world's strictest' rules
India sets the bar for net neutrality with 'world's strictest' rules

Seems like a good place to buy a server innit

  • Infrastructure
  • 12 July 2018
Intel's Xeon E 2018 chips take aim at entry-level workstations
Intel's new Xeon E chips take aim at entry-level workstations

Ryzen-rivaling silicon packs up to six cores and twelve threads

  • Chips
  • 12 July 2018
 Chrome 67 Site Isolation keeps Spectre attacks at bay
Chrome 67 protects against Spectre hacks but gobbles more RAM

Render processes get split to avoid Spectre bug exploits

  • Security
  • 12 July 2018
ZTE's long-running saga with the US government is almost over
ZTE's long-running saga with the US government is almost over

Firm strikes a deal to end seven-year supply ban

  • Friction
  • 12 July 2018
Back to Top

Most read

Galaxy Note 9 release date, specs and price: 24 August release date tipped as Samsung looks to offset 'sluggish' S9 sales
Galaxy Note 9 release date, specs and price: 24 August release date tipped
iPhone 9: Apple's LCD iPhone will 'adopt new backlight chips' to reduce bezel size
iPhone 9: Apple's LCD iPhone will 'adopt new backlight chips' to reduce bezel size
Apple to kill off the iPhone X and iPhone SE due to 'pent-up demand' for 2018 models
Apple to kill off the iPhone X and iPhone SE due to 'pent-up demand' for 2018 models
OnePlus 6 price, specs and news: OnePlus 6 'Red' edition goes on sale
OnePlus 6 price, specs and news: OnePlus 6 'Red' edition goes on sale
IBM's Watson AI can predict how well you'll do at work
IBM's Watson AI can predict how well you'll do at work
  • Contact
  • Marketing solutions
  • Enterprise IT Events
  • About Incisive Media
  • Terms & conditions
  • Privacy policy
  • RSS
  • Twitter
  • LinkedIn
  • Newsletters
  • Facebook
  • Google+
  • YouTube

© Incisive Business Media (IP) Limited, Published by Incisive Business Media Limited, New London House, 172 Drury Lane, London WC2B 5QR, registered in England and Wales with company registration numbers 09177174 & 09178013

Digital publisher of the year
Digital publisher of the year 2010, 2013, 2016 & 2017