Decloak - harder and harder to hide behind a proxy now!

Hi malware fighters,

Internet users that try to hide their real IP-address behind a proxy, can still be identified thanks to a new tool. Through a combination of client-side technologies and self developed services the Metasploit Decloak Engine will get the real IP-address. The first version was launched in June of 2006 , but could not beat the Torbutton Firefox extension and adaptations of the Flash plugin. The newer version has a series of improvements, does not use Javascript and supports iTunes, QuickTime and Microsoft Office technologies. Whoever has one of these plug-ins installed, runs the risk of loosing his or her anonimity. The tool could send a parameter out to the QuickTime plugin to set up a direct connection, that ignores the browser settings.

Developer H.D. Moore had to admit that a well configured combination of Tor, Torbutton together with Privoxy will still quarantee user anonymity, but all others fail. “Decloack is unique while it establishes the DNS server address used by the browser, combined with the results of various application models.” Websites that want to know the real IP-address of their visitors can implement the Decloaking Engine via this page: http://decloak.net/

polonus

Some of us aren’t that concerned about ‘hiding’ ;D

Hi bob3160,

If only we could say the same about the observing side?

polonus

And for some people who don’t live in the US, their lives depend on the ability to browse anonymously. :frowning:

Yea getting that way in the UK ;D getting to be a real big brother state, though our lives don’t depend on it.

One of the reasons I’m glad my parents decided to immigrate to this country.
I’ve never looked or gone back. :slight_smile:

Some of us aren't that concerned about 'hiding'

Bob, does that mean that you are willingly and abjectly abandoning your hard won rights in that great document, the US Constitution, that the government should not investigate your private activities without the due process of the law?

Sorry Alan,
but I don’t intend to get into a political discussion on this forum. :slight_smile:

Polonus, what about JAP? ???
http://anon.inf.tu-dresden.de/index_en.html

Hi Minacross,

There gonna be a very nice hardware solution from Janus. Take a peak here:
http://www.janusvm.com/goldy/JanusPA/index.html

polonus