From ae614e2ee2ef96b82938ee4f863325783261caa0 Mon Sep 17 00:00:00 2001 From: mutantmonkey Date: Tue, 11 Mar 2014 19:40:20 -0700 Subject: [PATCH] add readme, PKGBUILD, systemd unit --- PKGBUILD | 22 +++++++++++++++ README.md | 44 ++++++++++++++++++++++++++++++ proxy.py => tor-control-port-proxy | 1 + tor-control-port-proxy.service | 11 ++++++++ 4 files changed, 78 insertions(+) create mode 100644 PKGBUILD create mode 100644 README.md rename proxy.py => tor-control-port-proxy (99%) create mode 100644 tor-control-port-proxy.service diff --git a/PKGBUILD b/PKGBUILD new file mode 100644 index 0000000..426f64c --- /dev/null +++ b/PKGBUILD @@ -0,0 +1,22 @@ +# Maintainer: mutantmonkey +pkgname=tor-control-port-proxy +pkgver=0.1 +pkgrel=1 +pkgdesc="Whitelisting Tor control port proxy written in Python" +arch=('any') +url="https://github.com/mutantmonkey/tor-control-port-proxy" +license=('GPL') +depends=('python' 'stem') +options=(!emptydirs) +source=('tor-control-port-proxy' 'tor-control-port-proxy.service') +sha256sums=('7fbc8295f94d074437ecf0607d2da78624c9cd8b07b4a892b783010a573f0893' + 'eda5f0f43c9d2c8956743ba6485bb50fdb307af9941634902385214ecda14ce4') + +package() { + install -Dm755 tor-control-port-proxy \ + "${pkgdir}/usr/bin/tor-control-port-proxy" + install -Dm644 tor-control-port-proxy.service \ + "${pkgdir}/usr/lib/systemd/system/tor-control-port-proxy.service" +} + +# vim:set ts=2 sw=2 et: diff --git a/README.md b/README.md new file mode 100644 index 0000000..5d297af --- /dev/null +++ b/README.md @@ -0,0 +1,44 @@ +tor-control-port-proxy +====================== + +A whitelisting proxy for the Tor control port. + +Rationale +--------- +The Tor Browser, when not used in "Transparent Torification" mode, requires +access to the Tor control port so that it can test that the browser is +configured to use Tor correctly and send a NEWNYM signal when the "New +Identity" button is clicked. + +While these are nice features to have, exposing the control port to the browser +results in an increased attack surface, particularly when the Tor daemon and +Tor Browser are run on separate machines such as in Qubes. For example, an +attacker could tamper with the Tor configuration to only use relays that he or +she controls or get the IP address of the machine running Tor by using the +`GETINFO address` command. + +Inspired by a [similar project written as part of +Whonix](https://www.whonix.org/wiki/Dev/Control_Port_Filter_Proxy), I wrote a +simple proxy that only allows commands necessary for operation of the Tor +Browser and rejects all others. It's still in a fairly early state, but it +should work without issue. + +Prerequisites +------------- +* Python 3+ +* [stem](https://stem.torproject.org/) + +Usage +----- +1. Install the proxy. Arch users can use the included PKGBUILD; other users + should copy tor-control-port-proxy to /usr/bin, and + tor-control-port-proxy.service to /etc/systemd/system. (If you're not using + systemd, you'll need to write your own initscript.) + +2. Configure Tor: set `ControlPort 9051` and `CookieAuthentication 1`. Then + restart Tor. + +3. Start the proxy: `sudo systemctl start tor-control-port-proxy.service`. + +4. Use port 9052 to access the control port; for example, start the Tor Browser + like this: `env TOR_CONTROL_PORT=9052 /usr/bin/torbrowser`. diff --git a/proxy.py b/tor-control-port-proxy similarity index 99% rename from proxy.py rename to tor-control-port-proxy index 1a55179..c4dbdd9 100644 --- a/proxy.py +++ b/tor-control-port-proxy @@ -1,3 +1,4 @@ +#!/usr/bin/python3 import asyncore import asynchat import shlex diff --git a/tor-control-port-proxy.service b/tor-control-port-proxy.service new file mode 100644 index 0000000..8d6a209 --- /dev/null +++ b/tor-control-port-proxy.service @@ -0,0 +1,11 @@ +[Unit] +Description=Tor control port proxy +After=tor.service + +[Service] +User=tor +Type=simple +ExecStart=/usr/bin/tor-control-port-proxy + +[Install] +WantedBy=multi-user.target -- 2.51.2