Hacker News new | ask | show | jobs
by SageRaven 4694 days ago
What does the code actually deliver in the HTTP request, and what path does the request travel?

Is the exploit that the request is made outside of the TOR proxy (thus revealing the true origin IP) or that it gathers information about the host and sends that via TOR to some machine?

1 comments

The code is described as grabbing the MAC and hostname and sending them via a raw HTTP request to Virginia.

Since it is a Windows executable, this is done outside of TOR.