A coordinated IP Spoofing attack attempted to disrupt the Tor anonymity network, according to the Tor Project and relay operators.
See also: Tor says it's still secure despite reports of deanonymize

The Tor Project said the IP Spoofing attack began on October 20, when Tor directory authorities, the critical entities responsible for managing and maintaining the list of Tor relays, began receiving complaints claiming that servers were conducting port scanning.
The unauthorized port scanning triggered automated abuse reports to ISPs ,which resulted in some relays being taken offline.
An analysis revealed that a threat actor had used forged SYN packets to make it appear that IPs associated with Tor relays were conducting port scans. Non-exit relays were the focus of the attack.
He also noted, "We want to reassure everyone that this incident had no impact on Tor users. While the IP Spoofing attack had a limited impact on the Tor network – temporarily taking a few relays offline – it caused unnecessary stress and inconvenience to many relay operators who had to deal with these complaints."
See also: Tor Browser 13.5.3 update improves privacy across devices
It's unclear who is behind the attack. Malicious actors working for a government whose citizens often use Tor to bypass censorship and protect their privacy are a likely culprit, but other types of groups — including hacktivists and cybercriminals — could also benefit from a Tor network outage.

Tor relay operator Pierre Bourdon has been analyzing IP Spoofing attacks after his server was targeted with an automated abuse report.
Some cybersecurity services automatically send abuse reports to ISPs when they detect potential malicious activity from an IP address.
In this case, many of the automated reports were sent by WatchDogCyberDefense, which says it has begun working on a way to detect fake IPs after Bourbon urged the community to ignore abuse reports originating from that service.
The Tor Project said the origin of the forged packets was shut down on November 7th as a result of collaboration between the Tor community, InterSecLab, and GreyNoise.
See also: Tor WebTunnel: Mimics HTTPS traffic to avoid censorship
The IP Spoofing attack targeting the Tor network is a malicious technique in which the attacker submits a fake connection request using a fake IP address. This technique can be used to bypass IP-based security controls, such as firewalls, thereby creating a secure channel for the transfer of unauthorized data. IP Spoofing can also be part of broader attacks, such as conducting a DDoS, where multiple fake addresses are used simultaneously to overload a server. Countering these attacks requires the adoption of advanced security measures, such as the use of filters that detect patterns of abnormal data traffic.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: securityweek
