A security researcher discovered that many websites on Tor that use SSL could expose the public IP of the underlying servers.
Yonathan Klijnsma, a researcher at RiskIQ, says that many Tor sites that use SSL could expose the public IP addresses of the underlying servers. Properly configured servers hosting hidden services should only identify the localhost (127.0.0.1) instead of any other public IP address.
Klijnsma explained to BleepingComputer: "This kind of situation is especially common when no firewall is used. Servers should be configured to only recognize 127.0.0.1."

The expert pointed out that it is quite easy to find misconfigured servers that expose their public IP address. Whenever a hidden service administrator adds an SSL certificate to a website, they associate the .onion domain (TOR webpage) with the certificate. The Common Name (CN) field of the certificate lists the hidden service's .onion address.
Klijnsma discovered the misconfigured servers by scouring the internet and correlating SSL certificates with the IP address they were hosted on. In doing so, he discovered the misconfigured hidden services in Tor and the corresponding public IP.
Yonathan Klijnsma concluded that to avoid exposing the public IP address for a hidden Tor service, it should only recognize 127.0.0.1.
