Loading HuntDB...

Expose relay IP in the debug (The source is different from the rendering)

T
Tor
Submitted None
Reported by rbcafe

Vulnerability Details

Technical details and impact analysis

Greetings, -- I observed that it was possible to expose the ip of a relay by doing this : Poc : -- - Go to https://sorry.google.com/sorry/misc/ - You must observe this visual. {F279451} - Open Tor Browser debug - You must observe this visual {F279452} Note : -- You observe that between the debug and the main window there is no relation between the rendered text and the source code. The text discloses the IP of the client while the source discloses the IP of the relay. Best regards @Rbcafe ## Impact - Get the IP of the relay by changing the ip of the client.

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted