You are on page 1of 7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
More NextBlog

CreateBlog SignIn

TheLifeofaPenetrationTester
SecurityJournal
Home

Publications

Aboutme

Sunday,April7,2013

UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymize
InternetSurfingorOpenBlockedWebsites

SubscribeTo

Posts
Comments

Writtenby:PranshuBajpai|FindPranshuonGoogle+AndLinkedIn
Follow@pranshubajpai89

Freedomofexpressionandspeechisyourfundamentalrightandiftheytrytotakethataway
fromyoubyblockingaccesstospecificwebsites,thenthetoolsmentionedinthispostwill
aidyouindefeatingcensorship.
TheyrecentlyblockedwebsiteslikeHackThisSiteonthenetworkthatIuse,categorizing
themas"Hacking".TheirintentionsaregoodI'msurebutIneedtovisitsuchwebsites.

MostPopular

UsingTorand
PrivoxyonKali/
Debian/
BacktrackLinux
ToAnonymize
InternetSurfingorOpen
BlockedWebsites
Writtenby:PranshuBajpai|
FindPranshuonGoogle+
AndLinkedInFreedomof
expressionandspeechis
yourfundamentalrightandif
the...
InstallingNessus
inKaliLinux
Installedthenew
KaliPenTesting
Linuxtoday.
HoweverIwasdisappointed
toseenoNessusVul.
Scanner.Triedtoinstallitby
'ap...
IndexPage'/'

Anyway,Idecidedtouseaproxywebsite(whichisnotalwaysreliablesincetheywillblock
accesstothoseaswell).AsIsuspected,itwasblockedunder'ProxyAvoidance'.

HowToHackA
WebsiteSimple
Demo|Kali
Linux/
BackTrack|
Pranshu
Writtenby:PranshuBajpai|
FindPranshuonGoogle+And
LinkedInIwastestingforSQL
vulnerabilitiesatrandomover
theInternetand...
Hacking
Neighbour'sWifi
(Password)|
Hacking
Neighbor's
Wireless(Internet)|Stepby
StepHowTo
WrittenbyPranshuBajpai|
JoinmeonGoogle+|
LinkedInDisclaimer:For
educationalpurposesonly:
Thisismeantmerelyto

http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

1/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
exhibit...

Setuptheonionroutertogetaroundthis.First,youneedtoinstallitonyourboxusingthe
followingcommand:
#aptgetinstalltorprivoxy
Thiswillinstall2separatepackages'Tor'and'Privoxy'.
Torwillhostaproxyserveronyourmachineonport9050oftype'Socks5'
Privoxywillhostaproxyserviceonyourmachineonport8118oftype'HTTP'
AlsoinstalltheGUIfortorcalled'vidalia'
#aptgetinstallvidaliapolipo
Now,editthePrivoxyconfigurationfile:
#vi/etc/privoxy/config
Addthislineatthebottomofthisfile:
forwardsocks4a/localhost:9050.
Saveandclosethefile.ThiswilltellprivoxytoforwardSockstraffictotheServicerunningon
port9050onyourlocalhost(thisserviceisTor)
TimetofireupTorandprivoxyservices:
#/etc/init.d/torstart
#/etc/init.d/privoxystart

Recent

MultipleScreensin(Kali)Linux|
HowTo
USDtoINRExchangeRate
Calculator(Xoom,PayPal)Scriptin
Python
PhDComicsDownloader|Python
ScripttoDownloadPiledHigherand
DeeperComics
HowtoUseTruecrypt|Truecrypt
Tutorial[Screenshots]|KaliLinux,
BackTrack,BackBox,Windows
FOCAMetadataAnalysisTool
Aboutme
PublicationsPranshuBajpai
AffineCipherEncryptionDecryption
SourcecodeinJava
VignereCipherEncryption
DecryptionSourcecodeinJava
OneTimePadEncryption
DecryptionSourcecodeinJava

#whoami

NowgotoApplication>Internet>Vidalia

PranshuBajpai
SecurityResearcher

Checkthatitsays'connectedtotornetwork'

Viewmycomplete
profile
Search

Search

Labels

Academic(1)
Android(1)
Backtrack(24)
Cryptography(8)
ExploitResearch(1)
GeneralProgramming(1)
Hacking(31)
Java(12)
KaliLinux(34)
Linux(10)
ListsOfBest..(3)
MalwareAnalysis(1)
metasploit(5)
misc(4)

Youcanclickon'viewthenetwork'toseealltherelaysthatyouarepassingthrough.

Mutillidae(4)
MyPythonScripts(4)

Nowgotoyourbrowserandsettheproxyto:

mysql(1)
screencast(1)

ProxyIP'127.0.0.1'
Proxyport9050
TypeSocks5
http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

SSH(1)
Tomcat(2)
WebApplicationsHacking(6)

2/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
Windows(2)

Note:IfyouareusingtheFireFoxorIceweaselbrowser,youcanuse'AutoProxy'addonto
setthisup.

WirelessHacking(3)
DoNotCopy

Pageviews

495,018

Reloadthewebsitethatwasblockedearlier,ifyou'vedoneitright,youshouldhaveaccess
toit.

Furthermore,allyourbrowsingisnowanonymoussinceyouareconnectedthroughthe
onionrouter.
PostedbyPranshuBajpai

+3 Recommend this on Google

Labels:Backtrack,Hacking,KaliLinux

35comments:
http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

3/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
Anonymous April14,2013at7:52AM
Thankyouverymuch!
Reply

Anonymous April23,2013at5:33PM
THANKS!!!!!
Reply

Avadhoot April27,2013at11:35PM
Thanksforthispost
Reply

Anonymous May1,2013at12:45PM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous May14,2013at8:23PM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous May20,2013at7:38PM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous May21,2013at9:02PM
Excellentpost!!!Workslikeachamp
Reply

JosNinguem May22,2013at2:03AM
workslikeacharm.thanks=)
Reply

Anonymous May23,2013at9:40PM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous May25,2013at3:01PM
Thanks
Everythingworksgood
EgoDust
Reply

Anonymous May31,2013at8:41AM
This is a great post however I am a little confused on why we need privoxy, as from what I
cantellthewebbrowserconnectsdirectlytotoronport9050ratherthan8118whichisused
byprivoxysowhydoesitneedtobeinstalledandrunningisitdoingsomethingextrainthe
background?
Reply

http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

4/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
Replies
Anonymous June24,2013at7:23AM
You'reright.It'sbypassingprivoxy.Themainreasontohaveprivoxyisbecausetor
will leak dns information if running as an http proxy. Privoxy is the fix for that, he
doneitwrong.
Reply

Anonymous June1,2013at2:20PM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous June4,2013at5:33AM
Thanksmate..verygoodpost!!
Reply

Anonymous June12,2013at3:58AM
Hi,excellentpost,ihaveaquestion.Inproxysettings,yousettorport9050directly.Thisway,
privoxyiscompletelyleftout.I'mworkingonasimilarsetuponKali,andi'mlookingatprivoxy
log. If i use tor port 9050, privoxy log is silent (on max debug), tor activity via arm shows
networkgraph,sitesareloading.Ifispecifyprivoxy,ondefault8118port,iseeconnections
open and timeout on privoxy log, no tor activity, and sites never load. I try with two configs,
privoxyforwardingtotor,andprivoxystandalone.
Myconclusionisthatyouhaveleftprivoxyoutofyourconfig.Meaning,youleakheaderdata
outside...
Reply

Anonymous June16,2013at12:32AM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous June17,2013at9:22AM
tor is my but real ip is not chagimg.i use auto proxy setting but ,when I tried to watch
www.whatismyipaddress.com.thenmyipaddisnotchanged
Reply

Anonymous June18,2013at2:37AM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

ketangsang July1,2013at3:04AM
Thiscommenthasbeenremovedbyablogadministrator.
Reply

Anonymous July18,2013at2:50AM
Is vidalia hide whole machine ip? If i use sqlmap then what to do to protect me not to be
traced
Reply

Anonymous August17,2013at9:55PM

http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

5/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
I see no reason to also install polipo in this szenario. Why would you want two proxies
installed?
Reply

Anonymous August17,2013at11:31PM
IsyoursettingsforTorisachainedproxysetup?Orelse,thetracemightstilltrackable.
Reply
Replies
Anonymous December25,2013at5:56AM
WTF?
Reply

Anonymous October10,2013at2:38PM
Forattackthisnotverygood.
Reply
Replies
PranshuBajpai

October10,2013at10:46PM

huh?
Reply

ZacManns November6,2013at9:12AM
Thiscommenthasbeenremovedbytheauthor.
Reply

Anonymous November10,2013at8:28PM
I cant save "forwardsocks4a/localhost:9050" on terminal. after edit i press ctrl+x its not
working,sothereisnosavingoption.Help...
Reply
Replies
Anonymous December6,2013at6:49PM
aftertypingthatpressesckeyandthentypewqandenter
Reply

Anonymous November15,2013at9:28PM
Browsershouldbeconfiguredthrough8118.Ifit'sconfiguredthrough9050,you'rebypassing
privoxyandjustgoingthroughTOR,whichcanleaktimezoneinformation.
Reply

Anonymous November28,2013at6:02AM
gettingerror...needhelp
Reply

Anonymous December4,2013at9:10AM

http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

6/7

04/03/2015

TheLifeofaPenetrationTester:UsingTorandPrivoxyonKali/Debian/BacktrackLinuxToAnonymizeInternetSurfingorOpenBlockedWebsites
heybroIhaveonedoubtwhatistheextensionofkalilinuxsoftwares
Reply

Anonymous December25,2013at5:59AM
Thankyou!itworks!!
Reply

sonimehar February15,2014at2:36PM
helpmeplzzz
Reply

MusaIrfan February16,2014at8:50AM
KaliLinuxProblem:(CanAnyonehelpme
Reply

abdul January19,2015at9:03AM
I have a question which is confusing me, i applied every step in this tutorial, but after this
whenicheckedmyIPon"WhatisMyIP"itwassameasbefore
Reply

Enteryourcomment...

Commentas:

Publish

GoogleAccount

Preview

NewerPost

Home

OlderPost

Subscribeto:PostComments(Atom)

PranshuBajpai2013AllRightsReserved.Simpletemplate.PoweredbyBlogger.

http://lifeofpentester.blogspot.in/2013/04/usingtorandprivoxyonkalidebian.html

7/7

You might also like