An incomplete history of attacks
- Watering hole attack against "Playpen" onion site
- Believed to exploit a vulnerability in Firefox
- FBI chose to drop case rather than reveal details of technique
- Traffic confirmation attack
- Operated relays which injected and observed
RELAY_EARLY
cells - Subject of a canceled Black Hat talk
- Watering hole attack against commandeered onion site hosting service
- Used CVE-2013-1690 which was already patched in Tor Browser (based on Firefox 17 ESR) at the time
- Watering hole attack against "PedoBoard", "PedoBook" and "TB2" onion sites
- Took advantage of browsers automatically running Flash embeds (not the default setting in Tor Browser)
- Based on the Metasploit Decloaking Engine