The TOR network is widely known nowadays but there's plenty of gold in there that is not. This talk is about everything TOR: Popping shells, tunneling tools and commanding your bots over the world's most popular darknet.
This presentation was given on October 19th at the 11th H2HC (Hackers 2 Hackers Conference) 2014 at Sao Paulo, Brazil.
18. EEnnhhaanncciinngg pprriivvaaccyy obfs3
TTOORR PPllaaiinn vvss oobbffss33
TOR Plain
Initial handshakes and connection to same resource
TOR TLS handshake
The darkness of pixels indicates byte values from 0 to
255
24. TOR Plain obfs3
EEnnhhaanncciinngg pprriivvaaccyy
PPllaaiinn &&
oobbffss33 &&
SSccrraammbblleeSSuuiitt
Download of webpage at https://check.torproject.org/
Even with ScrambleSuit being more hard to detect, the
increase in payload length makes obfs3 better in the
overall cost tradeoff. (YMMV)
ScrambleSuit