Uncovering Tor Hidden Service with Etag

by kofejnikon 6/15/2023, 11:22 AMwith 1 comments

by brookston 6/15/2023, 12:50 PM

Serving the same unique etag over both public internet and Tor is a catastrophic fail.

Probably good opsec to never even have the same machine serving both worlds, let alone the same web server and site config.