Two days ago, everyone encountered an attack by a man in the middle when using ssh connection to the server through the tor. I was logged in on the server, then I was thrown out and after a second message, the message:
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY appeared! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed.
Has anyone encountered such attacks in real life when using ssh in tor? Can such attacks be considered targeted or are they mainly automated attacks? B Are such random attacks even possible in the tor network?
Two days ago, everyone encountered an attack by a man in the middle when using ssh connection to the server through the tor. I was logged in on the server, then I was thrown out and after a second message, the message:
Thanks for the post. What do you mean by “everyone”? And, did I
understand this correctly, you where successfully logged into a server
via SSH but your connection got terminated and you got the message below
when you tried to log in again?
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY appeared! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed.
Has anyone encountered such attacks in real life when using ssh in tor? Can such attacks be considered targeted or are they mainly automated attacks? B Are such random attacks even possible in the tor network?
We have seen MitM attacks via SSH in the past, yes, so they are
definitely possible. As to whether they are targeted or not, that is
hard to say and it depends. We’ve seen both.
Now, the important thing is to report such perceived attacks (or similar
ones) to our network-health team so they can start investigating and get
the malicious relays removed from the network. See:
You mentioned that everyone got the message. Sounds more like the server is compromised. OR The path to the server could be hijacked and thus everyone gets the message.
If the exit node were compromised then only you would get the message. Everyone was stated.
I assumed "server’ was external to the Tor system from the guard to the exit node. I assumed “everyone” was not coming through the Tor system. I also assumed you are not compromised.
If it were then the whole Tor system is blown and we would have found out long before this.
Not correctly “everyone” meant only his own case. Yes, after the first connection, the connection dropped for a few seconds and I tried to connect again and received a warning
Unfortunately, I didn’t write down the exit node, but now I’ll know where to write to mark it as malicious And another question: if this is a targeted attack, how can I know in advance that I will use this particular output node, provided that the exit nodes are constantly changing