The Tor Project
Penetration Test Report for The Tor Project
Pages
46
Time to read
51 mins
Publication
Language
English
Pages
46
Time to read
51 mins
Publication
Language
English
This document is a penetration test report conducted by Radically Open Security B.V. for The Tor Project, covering the period from April 17, 2023, to August 13, 2023. The report outlines the scope of work, which includes a code audit of various components such as the Tor Browser, exit relay, and exposed services. The primary objective was to identify vulnerabilities in the software changes made to enhance the Tor network's performance and reliability. The findings detail several vulnerabilities categorized by threat level, including high-severity issues like a Cross-Site Request Forgery (CSRF) vulnerability in the Onion Bandwidth Scanner. The report also presents a summary of recommendations aimed at mitigating the identified risks, emphasizing the need to address public-facing infrastructure vulnerabilities and protect critical components within the Tor network. Additionally, the document includes a methodology section that describes the planning and risk classification processes employed during the audit.