Hacker News new | ask | show | jobs
by talmand 4573 days ago
How did they know the something was done by someone using TOR on their network?
3 comments

There's a list of IPs that TOR networks run on, so they could just cross reference that.
tor exit nodes are easy to identify, if they had the co-operation of site.com then they'd not see the location, but they'd see the exit node.
I can understand they can the attack was done through Tor, what I don't understand is how they understood the attack originated on their own network through Tor.
It came from a TOR ip.