On Mon, 19 Dec 2011, grarpamp wrote:
Maybe they are running sniffers or just traffic statistics?Cute. However, it is certainly safe to assume that many nodes, many ISP's and many 'other' are running such things transparently for equally known and unknown reasons. So this is of no particular cause for alarm or action.
First of all, your test is for servers that are answering on TCP 3000, which could very well be anything. Perhaps ntop, perhaps nethack. Who knows.
Second, ntop provides a subset of the information that anyone can trivially collect with tcpdump.
Any Tor user should assume that a baseline of traffic analysis and logging is being done on all relays - exit or not - and adjust your behavior accordingly.
_______________________________________________ tor-talk mailing list tor-talk@xxxxxxxxxxxxxxxxxxxx https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk