Delivery-Date: Sun, 28 Sep 2014 14:08:21 -0400
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.9 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED,
	RP_MATCHES_RCVD autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id 20D501E08C9;
	Sun, 28 Sep 2014 14:08:20 -0400 (EDT)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id F3BE730E8B;
	Sun, 28 Sep 2014 18:08:13 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 25C4C309B0
 for <tor-talk@lists.torproject.org>; Sun, 28 Sep 2014 18:08:10 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at eugeni.torproject.org
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id YnFQVkJgk9QZ for <tor-talk@lists.torproject.org>;
 Sun, 28 Sep 2014 18:08:10 +0000 (UTC)
Received: from mail-la0-f48.google.com (mail-la0-f48.google.com
 [209.85.215.48])
 (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits))
 (Client CN "smtp.gmail.com",
 Issuer "Google Internet Authority G2" (not verified))
 by eugeni.torproject.org (Postfix) with ESMTPS id BC9F324327
 for <tor-talk@lists.torproject.org>; Sun, 28 Sep 2014 18:08:09 +0000 (UTC)
Received: by mail-la0-f48.google.com with SMTP id q1so5075754lam.7
 for <tor-talk@lists.torproject.org>; Sun, 28 Sep 2014 11:08:06 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:mime-version:in-reply-to:references:date
 :message-id:subject:from:to:content-type;
 bh=VFN0+wc65MPMoVU/sZ4KXM1AlCAtSTzlts3sc2zKAsE=;
 b=hnH6Zwpi2oKGPKcuhItCzapTPC+WSehbhs6r4E6VcKJZEzaERusRs97yA/leR62+mW
 Nua8fgJHOjv1YI2F0xdoVkKQztfAs+LMM0MVgSrxCCMwjb5VM+0tJHcRD2CrTkSBk+xu
 HYegWRd9C9+dO2jBtD/rY4x/TwnbZ32IQEXl3/oygQN64+EX5Pry1l7+wBOj10P3268u
 g+o80BUeMCneaSGuAGd2rn9ag2NaPk60kUcwl3qc6GYm1R5fLtmc8aDscufjAmynI/iy
 MAazBdCbWY/doiflWLNo3L1VYG7QvB6QhbYFo+gL5JqK+8Hyn0azS8l80TdnpL4l9IFc
 yM/w==
X-Gm-Message-State: ALoCoQnrbUsOx5sTX8uBbquNieTL1KcsZFlE+PW7Gxbh92uD3VofntfqkfO/PpPnzOwg2Ev8ive4
MIME-Version: 1.0
X-Received: by 10.112.158.170 with SMTP id wv10mr32322512lbb.66.1411927686260; 
 Sun, 28 Sep 2014 11:08:06 -0700 (PDT)
Received: by 10.112.201.200 with HTTP; Sun, 28 Sep 2014 11:08:06 -0700 (PDT)
X-Originating-IP: [98.248.57.252]
In-Reply-To: <CAHzaGdAvOccaGWzPNzDyGz__5+B9_eEgt8XXtVzd7mcXrkpW0w@mail.gmail.com>
References: <CAHzaGdAvOccaGWzPNzDyGz__5+B9_eEgt8XXtVzd7mcXrkpW0w@mail.gmail.com>
Date: Sun, 28 Sep 2014 11:08:06 -0700
Message-ID: <CAHzaGdAWk+JZRA9Y1FTeG96vOMGY2h3Q=EUy1iEzCYH1M_BJ3w@mail.gmail.com>
From: Todd Troxell <xtat@rapidpacket.com>
To: tor-talk@lists.torproject.org
X-Content-Filtered-By: Mailman/MimeDel 2.1.15
Subject: [tor-talk] Fwd: IP Banned for running a non-exit relay from home?
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

Hi Folks, I run several relays, including a non-exit relay from my home
rack.  Recently I noticed that I can't access several major websites from my
home IP.  The network is otherwise clean, it's a relatively new IP since I
moved recently, and the RBLs come up negative.

The only thing I can think might have triggered it is the tor relay.
Googling around I have seen things like this- firewall rules that block all
tor nodes.

https://forum.netfort.com/netfort/topics/ids_ruleset_tue_aug_12_11_59_00_ist_2014

The sites that seem to be doing this are all hosting with these guys
http://www.internetbrands.com/
http://www.corvetteforum.com/
http://www.rennlist.com/
http://www.bensbargains.net/
[... many more]

I then noticed this guy https://www.dan.me.uk/dnsbl  - when I hit this page
from my relay-only IP, I get

"I'm sorry, but I really don't see why anyone would need to use a TOR node
or Anonymous Proxy server to look at my site.
So i'm afraid you can't look. Stop running TOR / using an anonymous proxy
and you can view my site."

Even though I'm not accessing the site over tor, and even though the node
at my IP is a non-exit and there is no
possibility that my IP would ever access their properties over TOR.

Anyway, this surprised me.  In retrospect I suppose if people have access
to the list of nodes (exit or not) they'll use
it to set up firewall rules whether they understand what they are doing or
not.

If this is the way things are moving, I suppose I'll have to shut down or
VPN up my home node.
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

