Blog | G5 Cyber Security

Threat actors added thousands of Tor exit nodes to carry out SSL stripping attacks

Since January 2020, a threat actor has been adding thousands of malicious exit relays to the Tor network to intercept traffic and carry out SSL stripping attacks on users. SSL stripping (aka SSL Downgrade Attack) allows downgrading connection from secure HTTPS to HTTP which could expose the traffic to eavesdropping and data manipulation. Threat actors operated more than 26% of the tor networks exit relay capacity two times in the last year, reaching 27% in February 2021. The rapid increase was spotted by the maintainers at the Tor Project, but according to Nusenu their response was not effective because as of 20210508 he estimates the attackers are controlling between 4-6% of”]

Source: https://securityaffairs.co/wordpress/117749/deep-web/tor-exit-nodes-ssl-stripping.html

Exit mobile version