This guide covers security considerations, best practices, and recommendations for the Tor VPN System.
The Tor VPN System provides tools for managing Tor connections, but like any software that handles network traffic and system configuration, it requires careful security considerations.
The system is designed for:
⚠️ Known Security Concerns in Current Version:
Several scripts contain hardcoded passwords:
tor_vpn_beta.py: DEFAULT_PASSWORD constanttor_auto_torrc_config.py: DEFAULT_CONTROL_PASSWORD constantRisk: If source code is exposed, passwords are compromised.
Mitigation:
Some scripts pass passwords via command-line or store in variables:
Risk: Passwords may be exposed in process lists or memory dumps.
Mitigation:
Many scripts require root/sudo privileges:
Risk: Privilege escalation if code is compromised.
Mitigation:
Limited input validation in some functions:
Risk: Command injection or path traversal attacks.
Mitigation:
Logs may contain sensitive information:
Risk: Sensitive data exposure in log files.
Mitigation:
Before using the system in production:
# Use environment variables
import os
password = os.environ.get("TOR_PASSWORD")
if not password:
raise ValueError("TOR_PASSWORD environment variable not set")
# Set proper permissions
chmod 600 ~/.tor_config/torrc
chmod 700 ~/.tor_config
# Verify permissions
ls -la ~/.tor_config/torrc
# Set log file permissions
chmod 640 /var/log/tor/*.log
# Restrict log directory
chmod 750 /var/log/tor
Generate strong, unique passwords for Tor control:
# Generate secure password
openssl rand -base64 32
# Hash the password
tor --hash-password "your_secure_password"
Keep Tor and dependencies updated:
# Update Tor
sudo apt update && sudo apt install tor
# Update Python dependencies
pip install --upgrade -r requirements.txt
Regularly review logs for suspicious activity:
# Monitor Tor logs
tail -f /var/log/tor/notices.log
# Monitor application logs
tail -f vpn_app_advanced.log
Configure firewall rules:
# Allow only necessary ports
sudo ufw allow 9050/tcp # SOCKS proxy
sudo ufw allow 9051/tcp # Control port
sudo ufw deny incoming
sudo ufw enable
The system uses hashed passwords in torrc:
HashedControlPassword 16:B76A6ED6F4E32AB16028702348A5E765C6A53BCE1F82E467C614392ECD
Generate Strong Hashes
:::bash
tor --hash-password "your_very_strong_password_here"
Rotate Passwords Regularly
:::bash
Use Environment Variables
:::python
import os
from stem.control import Controller
password = os.environ.get("TOR_PASSWORD")
with Controller.from_port(port=9051) as controller:
controller.authenticate(password=password)
Cookie authentication uses a shared secret file:
CookieAuthentication 1
Secure Cookie File
:::bash
chmod 600 /run/tor/control.authcookie
Use in Trusted Environments Only
Cookie authentication is suitable for:
Automated scripts
Regular Cookie Rotation
:::bash
rm /run/tor/control.authcookie
sudo systemctl restart tor
Currently not implemented. Future enhancement:
# Example: Add MFA support
import pyotp
def authenticate_with_mfa(controller, password, totp_code):
"""Authenticate with password and TOTP code."""
# Verify TOTP
totp = pyotp.TOTP("your_secret_key")
if not totp.verify(totp_code):
raise AuthenticationError("Invalid TOTP code")
# Authenticate with password
controller.authenticate(password=password)
# Create secure torrc
umask 077
cat > ~/.tor_config/torrc << EOF
ControlPort 9051
HashedControlPassword 16:YOUR_HASHED_PASSWORD
EOF
# Set permissions
chmod 600 ~/.tor_config/torrc
# Configuration directory
chmod 700 ~/.tor_config
# Data directory
chmod 700 /var/lib/tor
# Log directory
chmod 750 /var/log/tor
# Set appropriate ownership
sudo chown -R debian-tor:debian-tor /var/lib/tor
sudo chown -R $USER:$USER ~/.tor_config
import logging
from logging.handlers import RotatingFileHandler
# Secure log handler
handler = RotatingFileHandler(
"secure.log",
maxBytes=1_000_000,
backupCount=5
)
handler.setLevel(logging.INFO)
# Set permissions
import os
os.chmod("secure.log", 0o640)
def redact_sensitive_data(message):
"""Redact sensitive data from log messages."""
import re
# Redact passwords
message = re.sub(r'password["\s:]+["\s]+[\w]+', 'password="***"', message)
# Redact IPs (optional)
message = re.sub(r'\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b', '***.***.***.***', message)
return message
# Only allow localhost
sudo iptables -A INPUT -p tcp -s 127.0.0.1 --dport 9051 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 9051 -j DROP
# More secure than TCP
# Configure in torrc
ControlSocket /run/tor/control.sock
CookieAuthentication 1
# Only allow localhost
sudo iptables -A INPUT -p tcp -s 127.0.0.1 --dport 9050 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 9050 -j DROP
Only allow trusted applications to use the proxy:
# In application code
import os
os.environ["HTTP_PROXY"] = "socks5h://127.0.0.1:9050"
os.environ["HTTPS_PROXY"] = "socks5h://127.0.0.1:9050"
⚠️ Critical Warning: Transparent proxy routes ALL traffic through Tor.
# Review current rules
sudo iptables -L -n
sudo iptables -t nat -L -n
# Save rules for audit
sudo iptables-save > /tmp/iptables-backup
# Flush rules when not using transparent proxy
sudo iptables -F
sudo iptables -t nat -F
# Application logs
chmod 640 vpn_app_advanced.log
# Tor logs
chmod 640 /var/log/tor/*.log
# Diagnostic logs
chmod 600 diagnostics/*
from logging.handlers import RotatingFileHandler
# Rotate logs to prevent unlimited growth
handler = RotatingFileHandler(
"app.log",
maxBytes=10_000_000, # 10 MB
backupCount=5
)
Avoid logging:
import logging
import json
class SecureFormatter(logging.Formatter):
def format(self, record):
# Remove sensitive fields
if hasattr(record, 'password'):
record.password = "***REDACTED***"
return super().format(record)
def validate_country_code(code):
"""Validate and sanitize country code."""
if not isinstance(code, str):
raise TypeError("Country code must be a string")
if len(code) != 2:
raise ValueError("Country code must be 2 characters")
if not code.isalpha():
raise ValueError("Country code must contain only letters")
return code.lower()
import html
def safe_output(text):
"""Safely encode output."""
return html.escape(text)
# Use parameterized queries
cursor.execute(
"SELECT * FROM users WHERE username = %s",
(username,)
)
# Check for known vulnerabilities
pip install safety
safety check
# Check for outdated packages
pip install pip-audit
pip-audit
# Update all dependencies
pip install --upgrade -r requirements.txt
# Check for security updates
pip list --outdated
pip install bandit
bandit -r .
pip install safety
safety check -r requirements.txt
pip install trufflehog
trufflehog --regex --entropy=False /path/to/repo
Session management
Authorization
Resource limits
Data Protection
Data retention
Logging
Attempt privilege escalation
Configuration
Test path traversal
Network
# Check for unauthorized Tor processes
ps aux | grep tor
# Check for suspicious network connections
netstat -tulnp | grep 9051
# Check for file modifications
find ~/.tor_config -mtime -1
# Check authentication attempts
grep "Authentication" /var/log/tor/notices.log
# Disconnect from network if needed
```
# Copy configuration
cp ~/.tor_config/torrc ~/incident-evidence/
```
# Check for configuration changes
git diff ~/.tor_config/torrc
```
Remediate
bash
# Change all passwords
# Update configuration
# Apply security patches
# Restart services
Document
Last Updated: 2024-04-23
Wiki: Configuration
Wiki: FAQ
Wiki: Home
Wiki: Troubleshooting