Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread Ivan Markin
pa011: > Could you give some explanation please on the difference between: > -lots of challenge ACKs received exactly the same number of chacks as number of sent RSTs (fixed kernel, sysctl workaround, ...) > -one challenge ACK received just one chack during this connection > -two challenge ACKs

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread pa011
Am 10.12.2016 um 21:12 schrieb Ivan Markin: > pa011: >> What about relays not on the list at all? > > You mean that are not subscribed for tor-relays@? No, forget that one - was my mistakable in the spreadsheet > > btw, it would be awesome to give away t-shirts or something for running >

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread Ivan Markin
pa011: > What about relays not on the list at all? You mean that are not subscribed for tor-relays@? btw, it would be awesome to give away t-shirts or something for running diverse relays. > I would assume that not everybody of that 23 percent does know what > exactly to do, apart from better

Re: [tor-relays] Network scan results for CVE-2016-5696 / RFC5961

2016-12-10 Thread pa011
> I would however be very interested to hear back from tor-relay operators > if any of them have found Challenge ACK counter values higher than > a million... which would indicate some kind of funny business. > Thanky you for your work. I know of 3 relays with ACK above 1 million:

Re: [tor-relays] Atlas - location of relay changed

2016-12-10 Thread Ivan Markin
Hi Duncan, Duncan Guthrie: > > On the IRC channel, I was reassured that this was not a bad thing, > that GeoIP is inaccurate, for example. > > However, I am interested in what might have caused the relay to > change location listing like this? Just to be clear, this 'location' is hardly an

Re: [tor-relays] Connections from UNKNOWN relays

2016-12-10 Thread Roger Dingledine
On Sat, Dec 10, 2016 at 03:39:20PM +0200, Rana wrote: > Assuming most of these are bridges, this could be a vulnerability as >this allows rogue middle relays to enumerate bridges. Plenty more open research problems where that one came from:

[tor-relays] Atlas - location of relay changed

2016-12-10 Thread Duncan Guthrie
Hi folks, My Tor exit, ecntor, recently changed from being listed in the UK to being listed in Canada, without any input on our part. On the IRC channel, I was reassured that this was not a bad thing, that GeoIP is inaccurate, for example. However, I am interested in what might have caused

Re: [tor-relays] torworld relays in entry and exit position

2016-12-10 Thread Sam Pizzey
Ansible is GPL'd and free of cost - are you possibly looking at Ansible Tower, or something similar? You can find Ansible here: https://github.com/ansible/ansible ___ tor-relays mailing list tor-relays@lists.torproject.org

Re: [tor-relays] torworld relays in entry and exit position

2016-12-10 Thread pa011
Very good Nusenu - I like your insistent dialogue and asking in this case :-) You are quite often referring to Ansible which is new to me. Is there a permanent free version around to let your https://github.com/nusenu/ansible-relayor run on it? Isn’t it somehow dangerous in the area we

Re: [tor-relays] Connections from UNKNOWN relays

2016-12-10 Thread Rana
-Original Message- From: tor-relays [mailto:tor-relays-boun...@lists.torproject.org] On Behalf Of teor Sent: Saturday, December 10, 2016 2:54 PM To: tor-relays@lists.torproject.org Subject: Re: [tor-relays] Connections from UNKNOWN relays >> On 10 Dec. 2016, at 23:05, Rana

Re: [tor-relays] Connections from UNKNOWN relays

2016-12-10 Thread teor
> On 10 Dec. 2016, at 23:05, Rana wrote: > > Arm shows that my middle relay has incoming connections from UNKNOWN relays > (no consensus data on them at all except locale). Are these bridges? Possibly, or they are relays that are not in the current consensus, but are

[tor-relays] Connections from UNKNOWN relays

2016-12-10 Thread Rana
Arm shows that my middle relay has incoming connections from UNKNOWN relays (no consensus data on them at all except locale). Are these bridges? There is also one outgoing connection to UNKNOWN but the address of that is 0.0.0.0:0 ___ tor-relays