Added more contents
BIN
opsec/darknet_surf/Address_generation.png
Normal file
After Width: | Height: | Size: 24 KiB |
BIN
opsec/darknet_surf/Descriptor.png
Normal file
After Width: | Height: | Size: 25 KiB |
49
opsec/darknet_surf/Get_descriptor.drawio
Normal file
|
@ -0,0 +1,49 @@
|
|||
<mxfile host="Electron" agent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) draw.io/25.0.2 Chrome/128.0.6613.186 Electron/32.2.5 Safari/537.36" version="25.0.2">
|
||||
<diagram name="Page-1" id="g8vQf7lOZ8XOqS9MBZ0G">
|
||||
<mxGraphModel dx="1964" dy="848" grid="1" gridSize="10" guides="1" tooltips="1" connect="1" arrows="1" fold="1" page="1" pageScale="1" pageWidth="850" pageHeight="1100" math="0" shadow="0">
|
||||
<root>
|
||||
<mxCell id="0" />
|
||||
<mxCell id="1" parent="0" />
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-55" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;" edge="1" parent="1" source="dtsqZrcHcvNpIVlUkKEP-54">
|
||||
<mxGeometry relative="1" as="geometry">
|
||||
<mxPoint x="450" y="440" as="targetPoint" />
|
||||
</mxGeometry>
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-60" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;entryX=0.5;entryY=1;entryDx=0;entryDy=0;" edge="1" parent="1" source="dtsqZrcHcvNpIVlUkKEP-54" target="dtsqZrcHcvNpIVlUkKEP-59">
|
||||
<mxGeometry relative="1" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-54" value="Browser" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="390" y="500" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-58" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;entryX=1;entryY=0.5;entryDx=0;entryDy=0;" edge="1" parent="1" source="dtsqZrcHcvNpIVlUkKEP-56" target="dtsqZrcHcvNpIVlUkKEP-59">
|
||||
<mxGeometry relative="1" as="geometry">
|
||||
<mxPoint x="300" y="410" as="targetPoint" />
|
||||
</mxGeometry>
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-56" value="Tor DHT" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="390" y="380" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-57" value="1.Send Onion address ....onion" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="450" y="458" width="190" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-65" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;" edge="1" parent="1" source="dtsqZrcHcvNpIVlUkKEP-59">
|
||||
<mxGeometry relative="1" as="geometry">
|
||||
<mxPoint x="70" y="410" as="targetPoint" />
|
||||
</mxGeometry>
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-59" value="Descriptor" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="130" y="380" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-61" value="2.Download descriptor" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="250" y="380" width="140" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-62" value="3.Verify descriptor" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="220" y="500" width="120" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="dtsqZrcHcvNpIVlUkKEP-66" value="4.Get the introduction<div>nodes</div>" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="-50" y="380" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
</root>
|
||||
</mxGraphModel>
|
||||
</diagram>
|
||||
</mxfile>
|
BIN
opsec/darknet_surf/Get_descriptor.png
Normal file
After Width: | Height: | Size: 21 KiB |
BIN
opsec/darknet_surf/Introduction_points.png
Normal file
After Width: | Height: | Size: 22 KiB |
47
opsec/darknet_surf/clearnet_model.drawio
Normal file
|
@ -0,0 +1,47 @@
|
|||
<mxfile host="Electron" agent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) draw.io/25.0.2 Chrome/128.0.6613.186 Electron/32.2.5 Safari/537.36" version="25.0.2">
|
||||
<diagram name="Page-1" id="s6loIDSRB5_9RXOfCXPu">
|
||||
<mxGraphModel dx="1114" dy="848" grid="1" gridSize="10" guides="1" tooltips="1" connect="1" arrows="1" fold="1" page="1" pageScale="1" pageWidth="850" pageHeight="1100" math="0" shadow="0">
|
||||
<root>
|
||||
<mxCell id="0" />
|
||||
<mxCell id="1" parent="0" />
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-13" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;entryX=0;entryY=0.5;entryDx=0;entryDy=0;" edge="1" parent="1" source="FulabzOXLJhT0SXKIutw-1" target="FulabzOXLJhT0SXKIutw-12">
|
||||
<mxGeometry relative="1" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-18" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;" edge="1" parent="1" source="FulabzOXLJhT0SXKIutw-1">
|
||||
<mxGeometry relative="1" as="geometry">
|
||||
<mxPoint x="200" y="520" as="targetPoint" />
|
||||
</mxGeometry>
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-1" value="Browser" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="140" y="370" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-15" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;exitX=0;exitY=0.5;exitDx=0;exitDy=0;entryX=1;entryY=0.5;entryDx=0;entryDy=0;" edge="1" parent="1" source="FulabzOXLJhT0SXKIutw-12" target="FulabzOXLJhT0SXKIutw-1">
|
||||
<mxGeometry relative="1" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-12" value="Cloudflare dns<div><br></div><div>1.1.1.1</div>" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="425" y="370" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-14" value="What is ip of google.com" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="270" y="370" width="150" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-17" value="It is x.x.x.x" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="300" y="410" width="80" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-20" style="edgeStyle=orthogonalEdgeStyle;rounded=0;orthogonalLoop=1;jettySize=auto;html=1;" edge="1" parent="1" source="FulabzOXLJhT0SXKIutw-19">
|
||||
<mxGeometry relative="1" as="geometry">
|
||||
<mxPoint x="420" y="550" as="targetPoint" />
|
||||
</mxGeometry>
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-19" value="Google CDN" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="140" y="520" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-21" value="Google backend<div>server</div>" style="rounded=0;whiteSpace=wrap;html=1;" vertex="1" parent="1">
|
||||
<mxGeometry x="425" y="520" width="120" height="60" as="geometry" />
|
||||
</mxCell>
|
||||
<mxCell id="FulabzOXLJhT0SXKIutw-22" value="Distribute access to servers" style="text;html=1;align=center;verticalAlign=middle;resizable=0;points=[];autosize=1;strokeColor=none;fillColor=none;" vertex="1" parent="1">
|
||||
<mxGeometry x="260" y="520" width="170" height="30" as="geometry" />
|
||||
</mxCell>
|
||||
</root>
|
||||
</mxGraphModel>
|
||||
</diagram>
|
||||
</mxfile>
|
BIN
opsec/darknet_surf/clearnet_model.png
Normal file
After Width: | Height: | Size: 19 KiB |
BIN
opsec/darknet_surf/dread.png
Normal file
After Width: | Height: | Size: 574 KiB |
BIN
opsec/darknet_surf/firewall_config.png
Normal file
After Width: | Height: | Size: 6.4 KiB |
BIN
opsec/darknet_surf/firewall_reload.png
Normal file
After Width: | Height: | Size: 41 KiB |
295
opsec/darknet_surf/index.html
Normal file
|
@ -0,0 +1,295 @@
|
|||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=edge">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<meta name="description" content="">
|
||||
<meta name="author" content="">
|
||||
<link rel="shortcut icon" href="../../../../../../assets/img/favicon.png">
|
||||
|
||||
<title>Navigate the darknet</title>
|
||||
|
||||
<!-- Bootstrap core CSS -->
|
||||
<link href="../../assets/css/bootstrap.css" rel="stylesheet">
|
||||
<link href="../../assets/css/xt256.css" rel="stylesheet">
|
||||
|
||||
|
||||
|
||||
<!-- Custom styles for this template -->
|
||||
<link href="../../assets/css/main.css" rel="stylesheet">
|
||||
|
||||
|
||||
|
||||
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
|
||||
<!--[if lt IE 9]>
|
||||
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
|
||||
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
|
||||
<![endif]-->
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<!-- Static navbar -->
|
||||
<div class="navbar navbar-inverse-anon navbar-static-top">
|
||||
<div class="container">
|
||||
<div class="navbar-header">
|
||||
<button type="button" class="navbar-toggle" data-toggle="collapse" data-target=".navbar-collapse">
|
||||
<span class="icon-bar"></span>
|
||||
<span class="icon-bar"></span>
|
||||
<span class="icon-bar"></span>
|
||||
</button>
|
||||
<a class="navbar-brand-anon" href="\index.html">The Nihilism Blog</a>
|
||||
</div>
|
||||
<div class="navbar-collapse collapse">
|
||||
<ul class="nav navbar-nav navbar-right">
|
||||
|
||||
<li><a href="/about.html">About</a></li>
|
||||
<li><a href="/blog.html">Categories</a></li>
|
||||
<li><a href="https://blog.nowhere.moe/donate.html">Donate</a></li>
|
||||
<li><a href="/contact.html">Contact</a></li>
|
||||
</ul>
|
||||
</div><!--/.nav-collapse -->
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- +++++ Posts Lists +++++ -->
|
||||
<!-- +++++ First Post +++++ -->
|
||||
<div id="anon2">
|
||||
<div class="container">
|
||||
<div class="row">
|
||||
<div class="col-lg-8 col-lg-offset-2">
|
||||
<a href="../index.html">Previous Page</a></br></br><p><img src="../../assets/img/user.png" width="50px" height="50px"> <ba>nihilist - 00 / 00 / 00</ba></p>
|
||||
<h1>How to navigate darknet and join the webring</h1>
|
||||
<p>If you are new to the tor network, you might find out it is difficult to find the content you are interested in. Since all you get is a cold and long onion address, you cannot google it and remember the domain name.</p>
|
||||
<p>In this tutorial I will explain the special routing mechanism of tor, then how to find the legit websites and avoid scams. At last, I will show how to set up your own directory website, you can even help others for better reaching the darknet</p>
|
||||
</div>
|
||||
|
||||
</div><!-- /row -->
|
||||
</div> <!-- /container -->
|
||||
</div><!-- /grey -->
|
||||
|
||||
<!-- +++++ Second Post +++++ -->
|
||||
<div id="anon3">
|
||||
<div class="container">
|
||||
<div class="row">
|
||||
<div class="col-lg-8 col-lg-offset-2">
|
||||
<h2><b>How does onion routing works </b></h2>
|
||||
<p>Clearnet websites are like <b>legit real businesses</b>, which have a big sign on their shops, you can easily find them and visit them.</p>
|
||||
<p>For visiting a clearnet site you simply type in the domain name, and your browser query its ip address and access it. Sometimes there might be a layer of CDN in the middle</p>
|
||||
<img src="clearnet_model.png" class="imgRz">
|
||||
<p>For onion addresses on tor network this is a totally different story. TCP/IP is not designed to protect privacy at all, in order to allow client and server talk to each other while both of them remain anonymous, tor invent a very sophisticated mechanism to achieve</p>
|
||||
<p>Compare to the metaphor of clearnet, onion address access is more like <b>dark market</b>. Vendors cannot be found easily, and you need some sort middle man to arrange a meeting for trading to happen. The most important part of tor network is both parties <b>never</b> directly talk to each other.</p>
|
||||
<p>Setting up and access a hidden service is a quite complicated process technically speaking, here I summarize the most important part of it:</p>
|
||||
<p><b>Service Publish</b></p>
|
||||
<p>1.Like HTTPS which is used to establish a secure connection on clearnet, the first step for setup a hidden service to operate is to generate a <b>public/private key pair</b>. The public key then is encoded and is embedded in the onion address.</p>
|
||||
<img src="Address_generation.png" class="imgRz">
|
||||
<p>That is why the onion address is so human unfriendly, because it contains a complete public key inside</p>
|
||||
<p>2.Next step is let the tor network to know the <b>presence</b> of hidden service, because you do not have a clearnet port opening, if you do not advocate yourself nobody will ever be able to find you.</p>
|
||||
<p>First you connect to a group of <b>introduction points</b>, these are the "middle man" that passes the information for you and clients to meet. Also you connect to these introduction points through tor relays, so you do not need to trust them. Pretty much like a spy agent where each node only knows absolute necessary information</p>
|
||||
<img src="Introduction_points.png" class="imgRz">
|
||||
<p>For stability of the service, you maintain a stable connection to introduction points</p>
|
||||
<p>3.Next you need to furthur advertise yourself, only set up some introduction points is not enough. Like in the spy movies people publish ads on the newspaper for contacting other spies, you also need to publish your presence on the tor network </p>
|
||||
<p>You will create a <b>Hidden service descriptor</b> which contains your onion address and your introduction points, and sign it with your private keys. Then publish it on the tor network DHT</p>
|
||||
<img src="Descriptor.png" class="imgRz">
|
||||
<p></p>
|
||||
<p><b>Client Access</b></p>
|
||||
<p>Next the client will need to find the onion address from other places, like from a forum on clearnet or onion search engine.</p>
|
||||
<p>This is the weak spot of tor network, since its addresses are very human unfriendly, it is impossible to memorize it and people need to <b>trust</b> some place for providing the correct onion address, for example taking notes locally or using some clear net directory website, which makes phishing very rampant on tor network.</p>
|
||||
<p>A popular directory site <a href="dark.fail">dark.fail</a> was taken over by a malicious actor, and all the onion addresses on it were changed to phishing sites setup by him. This highlights the importance of keeping your own local notes or set up your own directory site.</p>
|
||||
<p>Let's assume a user obtained the correct onion address, and what happens next?</p>
|
||||
<p>1.The tor browser will send the onion address to tor DHT, and will try to retrieve the <b>hidden service descriptor</b>, which contains all the information for contacting the hidden service. The public key embedded in the address will also be used to verify the authenticity of the descriptor</p>
|
||||
<img src="Get_descriptor.png" class="imgRz">
|
||||
<p>2.Next the browser(or client) will find a random relay, and make it a rendezvous point, basically it is a relay that both hidden service and client connects to, because tor network do not use IP protocol for transmitting data at all. So you have to set up a <b>relay</b> point for communication</p>
|
||||
<p>3.The browser will inform the server about the rendezvous point through the introduction point.</p>
|
||||
<p>4.The server and client both connected to the rendezvous point, after some verification, now the onion talk officially starts</p>
|
||||
|
||||
</div>
|
||||
</div><!-- /row -->
|
||||
</div> <!-- /container -->
|
||||
</div><!-- /white -->
|
||||
|
||||
<div id="anon2">
|
||||
<div class="container">
|
||||
<div class="row">
|
||||
<div class="col-lg-8 col-lg-offset-2">
|
||||
<h2><b>Build you tor website directory</b></h2> </br> </br>
|
||||
<p>Now we will try to build our own directory of the tor network, at first step you have to rely on some trusted points for getting the sites at the beginning.</p>
|
||||
<p>For clearnet directory site, I recommend <a href="https://tor.taxi">tor.taxi</a> and <a href="https://kycnot.me">kycnot.me</a> which contains a lot of useful sites. </p>
|
||||
<p>kycnot.me mostly points towards legit privacy protecting services that is also available in clearnet, and most services support monero</p>
|
||||
<img src="kycnot.png" class="imgRz">
|
||||
<p>tor.taxi mostly points towards real onion sites that is not available on the clearnet, and it is the best place to start if you want to explore the shady areas of the internet </p>
|
||||
<img src="tortaxi.png" class="imgRz">
|
||||
<p>Now you should already have some sites you are interested in, as a good habit you should always <b>taking notes</b> of these sites, since directory sites built by others might be taken down someday.</p>
|
||||
<p>If you want to dive further down the rabbit hole, <b>dread</b> <a href="dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion">dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion</a> is the best place to start with. Darknet websites are like 95% scams, if you just randomly find links from search engines you will most likely get scammed.</p>
|
||||
<p>So it is best to lurk around a forum, and see people's feedback to determine the legitimacy of a service, and avoid phishing, and dread is the biggest and most active discussing forum right now. It is also topic oriented like reddit, so you choose the topic you are interested and go to its sub</p>
|
||||
<img src="dread.png" class="imgRz">
|
||||
<p>The darknet market sub on dread</p>
|
||||
<p>One last place for exploration is the search engine, which is a tool I strongly do not recommend. It is very likely to get a scam link from it, and scammers are way more motivated to get their site listed than legit sites </p>
|
||||
<p>For example vormweb search engine <a href="http://volkancfgpi4c7ghph6id2t7vcntenuly66qjt6oedwtjmyj4tkk5oqd.onion">http://volkancfgpi4c7ghph6id2t7vcntenuly66qjt6oedwtjmyj4tkk5oqd.onion</a></p>
|
||||
<img src="vormweb.png" class="imgRz">
|
||||
<p></p>
|
||||
<p>Just use your common sense, and anything looks <b>too good to be</b> true is very likely a scam</p>
|
||||
</div>
|
||||
</div><!-- /row -->
|
||||
</div> <!-- /container -->
|
||||
</div><!-- /white -->
|
||||
|
||||
|
||||
<!-- +++++ Second Post +++++ -->
|
||||
<div id="anon1">
|
||||
<div class="container">
|
||||
<div class="row">
|
||||
<div class="col-lg-8 col-lg-offset-2">
|
||||
<h2><b>Build your own directory site</b></h2> </br> </br>
|
||||
<p>Finally, we come to the most interesting part, which is building your own directory site. By doing this you build a webring, and help others to reach their wanted services.</p>
|
||||
<p>The source code is kindly provided by nihilism, and you can visit his own webring <a href="http://uptime.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion/">http://uptime.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion/</a></p>
|
||||
<p>Now we will host the webring using under <b>whonix</b>. The reason to use whonix is its superior security, even your website get compromised and get RCE, the attacker can only take down your site, but cannot reveal your real identity. If he wants to reveal your real identity, he needs to further exploit the whonix gateway or perform a vm escape, which will be significantly harder.</p>
|
||||
<p>The OS I use is Qubes OS, if you do not know what is this please consult <a href="../qubesosnetwork/index.html">Navigating Qubes OS</a></p>
|
||||
<p>1.Create a standalone dedicated whonix workstation vm, run this command in dom0</p>
|
||||
<pre><code class="nim">
|
||||
$ qvm-create --class StandaloneVM --template whonix-workstation-17 --label yellow webring-hosting
|
||||
</code></pre>
|
||||
<p>2.Next assign the net vm of this qube to your whonix gateway, which is mentioned in above qubes tutorial</p>
|
||||
<p>3.Start to setup the network, you can also consult this official whonix document <a href="https://www.whonix.org/wiki/Onion_Services">Whonix onion service hosting</a></p>
|
||||
<p>First check the ip address of the whonix workstation, open a terminal in workstation</p>
|
||||
<pre><code class="nim">
|
||||
$ ip a
|
||||
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
|
||||
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
|
||||
inet 127.0.0.1/8 scope host lo
|
||||
valid_lft forever preferred_lft forever
|
||||
inet6 ::1/128 scope host noprefixroute
|
||||
valid_lft forever preferred_lft forever
|
||||
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group 1 qlen 1000
|
||||
link/ether 00:16:3e:5e:6c:00 brd ff:ff:ff:ff:ff:ff
|
||||
inet 10.137.0.46/32 scope global eth0
|
||||
valid_lft forever preferred_lft forever
|
||||
inet6 fe80::216:3eff:fe5e:6c00/64 scope link
|
||||
valid_lft forever preferred_lft forever
|
||||
</code></pre>
|
||||
<p>Record the address of <b>eth0</b></p>
|
||||
<p>4.Edit the <b>torrc</b> config file in whonix gateway. Start a terminal in whonix gateway, and edit /usr/local/etc/torrc.d/50_user.conf for running your onion service</p>
|
||||
<img src="torrc_config.png" class="imgRz">
|
||||
<p>Add the above content into the file</p>
|
||||
<p>You should replace the ip address 10.137.0.46 to your <b>own</b> workstation ip address</p>
|
||||
<p>5.Restart the tor client in whonix gateway using the control panel</p>
|
||||
<img src="restart_tor.png" class="imgRz">
|
||||
<p>6.Next check the onion address that is just generated in /var/lib/tor/webring/</p>
|
||||
<pre><code class="nim">
|
||||
# root@host:/var/lib/tor/webring# cat hostname
|
||||
4i4q5btqberkgwv7fmra3tatoqdn6slseiinkbe2jgqkyghxc5einjqd.onion
|
||||
</code></pre>
|
||||
<p>7.Install the nginx and webring source code into the workstation vm according to this repo <a href="http://git.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion/nihilist/darknet-onion-webring">webring project</a></p>
|
||||
<p>First clone the repo</p>
|
||||
<pre><code class="nim">
|
||||
$sudo git clone http://git.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion/nihilist/darknet-onion-webring /srv/darknet-onion-webring
|
||||
</code></pre>
|
||||
<p>8.Install nginx and php(lol php)</p>
|
||||
<pre><code class="nim">
|
||||
$sudo apt install php8.2-fpm nginx -y
|
||||
</code></pre>
|
||||
<p>9.Copy the nginx config</p>
|
||||
<pre><code class="nim">
|
||||
$ sudo cp /srv/darknet-onion-webring/nginx.conf /etc/nginx/sites-available/uptime.conf
|
||||
</code></pre>
|
||||
<p>10.Next enable nginx configs and python dependencies</p>
|
||||
<pre><code class="nim">
|
||||
$ ln -s /etc/nginx/sites-available/uptime.conf /etc/nginx/sites-enabled/
|
||||
|
||||
$ nginx -s reload
|
||||
|
||||
$ sudo apt install python3-pandas python3-requests python3-socks
|
||||
</code></pre>
|
||||
<p>11.Check if the webpage is running correctly by trying to access it locally</p>
|
||||
<pre><code class="nim">
|
||||
$ curl 127.0.0.1:4443
|
||||
</code></pre>
|
||||
<p>If you get the webpage then it is up and running</p>
|
||||
|
||||
<p>12.Check the python uptime checker script is running correctly</p>
|
||||
<pre><code class="nim">
|
||||
$ python3 scripts/uptimechecker.py
|
||||
[+] ONION UPTIME CHECKER
|
||||
[+] Reading the CSV File: /srv/darknet-onion-webring/www/links/webring.csv
|
||||
[+] Checking if each .onion link is reachable:
|
||||
[+] Editing the uptime score
|
||||
0
|
||||
[+] http://uptime.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion 200
|
||||
http://uptime.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion ✔️
|
||||
[+] Reading the CSV File: /srv/darknet-onion-webring/www/links/Exchanges.csv
|
||||
[+] Checking if each .onion link is reachable:
|
||||
[+] Editing the uptime score
|
||||
0
|
||||
http://exchanger.infinityjs5qob5euyao745kp5x2hh4xquh7qs5cze3kcxv63xdwxlad.onion/ ❌
|
||||
[+] Editing the uptime score
|
||||
1
|
||||
[+] http://robosats6tkf3eva7x2voqso3a5wcorsnw34jveyxfqi2fu7oyheasid.onion/ 200
|
||||
http://robosats6tkf3eva7x2voqso3a5wcorsnw34jveyxfqi2fu7oyheasid.onion/ ✔️
|
||||
[+] Editing the uptime score
|
||||
2
|
||||
</code></pre>
|
||||
<p>If you see something like this without any exception then you are all good</p>
|
||||
<p>Then make this python script a crontab job, so you routinely check the uptime of your webring sites.</p>
|
||||
<pre><code class="nim">
|
||||
# crontab -e
|
||||
|
||||
*/3 0 * * * python3 /srv/darknet-onion-webring/scripts/uptimechecker.py </code></pre>
|
||||
<p>13.Finally, edit the whonix workstation firewall so onion traffic from the gateway can reach it</p>
|
||||
<p>First create the firewall config directory</p>
|
||||
<pre><code class="nim">
|
||||
$ sudo mkdir -p /usr/local/etc/whonix_firewall.d
|
||||
</code></pre>
|
||||
<p>Then find the "User firewall setting" in the GUI menu, add the below content</p>
|
||||
<img src="firewall_config.png" class="imgRz">
|
||||
<p>Save it can find the "Reload firewall" in the GUI menu, and make sure it is reloaded sucessfully</p>
|
||||
<img src="firewall_reload.png" class="imgRz">
|
||||
<p></p>
|
||||
<p>14.Open a tor browser, and try to access your own site</p>
|
||||
<img src="site.png" class="imgRz">
|
||||
</div>
|
||||
</div><!-- /row -->
|
||||
</div> <!-- /container -->
|
||||
</div><!-- /white -->
|
||||
|
||||
<!-- +++++ Footer Section +++++ -->
|
||||
|
||||
<div id="anonb">
|
||||
<div class="container">
|
||||
<div class="row">
|
||||
<div class="col-lg-4">
|
||||
<h4>PrismBreaker</h4>
|
||||
<p>
|
||||
Shatter the big brother.</p></br></br><p>Creative Commons Zero: No Rights Reserved</br><img src="\CC0.png">
|
||||
|
||||
</p>
|
||||
</div><!-- /col-lg-4 -->
|
||||
|
||||
<div class="col-lg-4">
|
||||
<h4>My Links</h4>
|
||||
<p>
|
||||
|
||||
<a target="_blank" rel="noopener noreferrer" href="http://blog.nowhere.moe/rss/feed.xml">RSS Feed</a><br/><a target="_blank" rel="noopener noreferrer" href="https://simplex.chat/contact#/?v=2-7&smp=smp%3A%2F%2FL5jrGV2L_Bb20Oj0aE4Gn-m5AHet9XdpYDotiqpcpGc%3D%40nowhere.moe%2FH4g7zPbitSLV5tDQ51Yz-R6RgOkMEeCc%23%2F%3Fv%3D1-3%26dh%3DMCowBQYDK2VuAyEAkts5T5AMxHGrZCCg12aeKxWcpXaxbB_XqjrXmcFYlDQ%253D&data=%7B%22type%22%3A%22group%22%2C%22groupLinkId%22%3A%22c3Y-iDaoDCFm6RhptSDOaw%3D%3D%22%7D">SimpleX Chat</a><br/>
|
||||
|
||||
</p>
|
||||
</div><!-- /col-lg-4 -->
|
||||
|
||||
<div class="col-lg-4">
|
||||
<h4>About nihilist</h4>
|
||||
<p style="word-wrap: break-word;"><u>Donate XMR:</u> 87iB34vdFvNULrAjyfVAZ7jMXc8vbq9tLGMLjo6WC8N9Xo2JFaa8Vkp6dwXBt8rK12Xpz5z1rTa9jSfgyRbNNjswHKTzFVh</p></br><p><u>Contact:</u> prismbreaker@waifu.club (<a href="https://keys.openpgp.org/vks/v1/by-fingerprint/735816B2B9E6F4660ECE44D983E602C4B6EA6AEE">PGP</a>)</p>
|
||||
</div><!-- /col-lg-4 -->
|
||||
|
||||
</div>
|
||||
|
||||
</div>
|
||||
</div>
|
||||
|
||||
|
||||
|
||||
<!-- Bootstrap core JavaScript
|
||||
================================================== -->
|
||||
<!-- Placed at the end of the document so the pages load faster -->
|
||||
|
||||
</body>
|
||||
</html>
|
BIN
opsec/darknet_surf/kycnot.png
Normal file
After Width: | Height: | Size: 584 KiB |
BIN
opsec/darknet_surf/restart_tor.png
Normal file
After Width: | Height: | Size: 24 KiB |
BIN
opsec/darknet_surf/site.png
Normal file
After Width: | Height: | Size: 141 KiB |
BIN
opsec/darknet_surf/torrc_config.png
Normal file
After Width: | Height: | Size: 18 KiB |
BIN
opsec/darknet_surf/tortaxi.png
Normal file
After Width: | Height: | Size: 83 KiB |
BIN
opsec/darknet_surf/vormweb.png
Normal file
After Width: | Height: | Size: 83 KiB |