Tor Hidden Services Risk IP Leak via Misconfiguration

A misconfiguration in Tor hidden services can expose real IP addresses, per SOS Intelligence researcher Amir Hadzipasic.

Tor Hidden Services Risk IP Leak via Misconfiguration

Image: cyberinsider.com

A recent report from SOS Intelligence researcher Amir Hadzipasic highlights a critical misconfiguration in Tor hidden services that can leak the real IP addresses and server data of operators. The Tor network is designed to anonymize both users and website operators by routing traffic through multiple relays, but certain setup errors can undermine this protection.

According to the report, the issue arises when hidden services are not properly configured to use Tor exclusively, allowing direct connections from the server to the internet. This can expose the server's true IP address, defeating the anonymity that Tor provides. Hadzipasic's analysis indicates that such misconfigurations are not uncommon, particularly among less experienced operators.

The findings underscore the importance of following Tor's official guidelines for setting up hidden services. Operators are advised to ensure that their web servers only listen on localhost and that all traffic is routed through Tor. Failure to do so can lead to deanonymization, potentially exposing operators to legal or security risks.

As of June 2026, the Tor Project has not issued a specific security advisory for this misconfiguration, but the report serves as a reminder for operators to audit their setups. The full details of Hadzipasic's research are available from SOS Intelligence.

❓ Frequently Asked Questions

What is a Tor hidden service?

A Tor hidden service is a website that is only accessible through the Tor network, designed to conceal the server's real IP address and location.

How can a misconfiguration leak an IP address?

If a hidden service's web server is not configured to only listen on localhost, it may accept direct connections from the internet, revealing the server's true IP address.

Who reported this vulnerability?

The issue was reported by Amir Hadzipasic, a researcher at SOS Intelligence, in a recent analysis.

📰 Source:
cyberinsider.com →
Share: