sys-whonix sends traffic outside Tor

127 views
Skip to first unread message

atlahua

unread,
May 9, 2017, 10:34:12 AM5/9/17
to qubes...@googlegroups.com
I have sys-whonix set up to use Tor bridges. However when I run the
shell command 'ss -a -r -t' I can see that some of the traffic is sent
to IP addresses other than the selected bridge.

Why is sys-whonix sending traffic outside Tor?

cooloutac

unread,
May 9, 2017, 3:49:41 PM5/9/17
to qubes-users, atl...@krutt.org

what is the traffic where is it going?

cooloutac

unread,
May 9, 2017, 4:06:55 PM5/9/17
to qubes-users, atl...@krutt.org
On Tuesday, May 9, 2017 at 10:34:12 AM UTC-4, atlahua wrote:

I did netstat they all say tor except these two

tcp 0 0 127.0.0.1:4101 0.0.0.0:* LISTEN 215/brltty

tcp 0 0 10.137.3.1:9052 0.0.0.0:* LISTEN 902/python

tcp 0 0 0.0.0.0:8082 0.0.0.0:* LISTEN 925/tinyproxy


all the rest are: with ports in 9100s which I assume is tor.
tcp 0 0 10.137.3.1:9181 0.0.0.0:* LISTEN 997/tor


You should also check from sysnet to see what is leaving your pc.

cooloutac

unread,
May 9, 2017, 9:34:39 PM5/9/17
to qubes-users, atl...@krutt.org

you can use wireshark, tcpdump, or etherape. but all are extremely vulnerable. lol

atlahua

unread,
May 10, 2017, 11:19:35 AM5/10/17
to cooloutac, qubes-users
____________________________________________________________________

Thanks to all of you for your feedback.
At the time I detected the issue I made the mistake not to note down the
IP address at which the traffic was send.
I cannot reproduce the problem right now and all I can see is that
sys-whonix is using one obfs bridge and a non-obfs bridge
simultaneously. Nothing else that may look suspicious.

As for checking sys-net traffic, I guess you mean sys-firewall. sys-net
should not be connected to the network. Nothing coming out though.

cooloutac

unread,
May 10, 2017, 12:02:15 PM5/10/17
to qubes-users, raah...@gmail.com, atl...@krutt.org

your network card is in sys-net. sys-firewall is the in between proxy. Its considered trusted so I wouldn't run any monitoring programs in it. better to run them in sys-net or make another proxy.

Reply all
Reply to author
Forward
0 new messages