mod_status

Pierluigi Paganini February 02, 2016
Default conf on Apache Web servers can de-anonymize your hidden service

A default setting in Apache Web servers can de-anonymize the hidden service allowing an attacker to obtain details on the hosting. An unknown student has discovered a serious issue in Apache Web Server that could potentially de-anonymize .onion-domains and servers hidden behind the Tor-network. The student already reported the issue to the Tor Project development team […]