Expose relay IP in the debug (The source is different from the rendering)
T
Tor
Submitted None
Actions:
Reported by
rbcafe
Vulnerability Details
Technical details and impact analysis
Greetings,
--
I observed that it was possible to expose the ip of a relay by doing this :
Poc :
--
- Go to https://sorry.google.com/sorry/misc/
- You must observe this visual.
{F279451}
- Open Tor Browser debug
- You must observe this visual
{F279452}
Note :
--
You observe that between the debug and the main window there is no relation between the rendered text and the source code. The text discloses the IP of the client while the source discloses the IP of the relay.
Best regards
@Rbcafe
## Impact
- Get the IP of the relay by changing the ip of the client.
Report Details
Additional information and metadata
State
Closed
Substate
Informative