Creating a Dark Web – Deep web website

 

Posted on

 

Darket-website
Darket-website

As we discussed before the difference between Surface web, Dark web and Deep web. In dark web Tor is used and it allows anyone to access websites with anonymity.

If you want to create your own anonymous website or convert an existing website into dark web website, you can do so by creating a hidden service Tor site. Your website will run within Tor. Only people using Tor can access it.

People create dark web websites for trading stuff or a website like wikileaks as political activists in repressive countries. As per digital forensics course experts most of trading done in dark web is done via bit coins or sites like PayPal.

This tutorial is purely for educational purposes and will focus on setting up a hidden Tor site on Debian Linux. Note, that the tutorial only tells you how to set up website on TOR network. If your content is very important, you will have to penetration testing of your server and secure it well. To get started, you’ll have to download and install Tor on your computer.

Let’s start by installing some required packages

 

apt-get install nano

 

apt-get install openssl

 

Add user to your server so that you are not running your website as root.

 

adduser user

 

Add user to sudoers

 

sudo adduser user sudo

 

SSH configuration. Open up your sshd configuration and set up following and reload SSH configuration once done:

nano /etc/ssh/sshd_config

Setup port for SSH

Port 23433

PermitRootLogin no

Follow the torproject.org docs to add the Debian repo as shown here .

Then make a new folder named “tor” and download + extract tor

cd /

mkdir tor

 

wget https://www.torproject.org/dist/tor-X.X.X.X.tar.gz

 

tar xzf tor-X.X.X.X.tar.gz; cd tor-X.X.X.X

Then use this to install TOR:

make install

Open the folder which has the sample of a configuration file, rename it to “torrc” (or make a new copy) and add/modify lines in nano file editor:

 

cd /usr/local/etc/tor

경축! 아무것도 안하여 에스천사게임즈가 새로운 모습으로 재오픈 하였습니다.
어린이용이며, 설치가 필요없는 브라우저 게임입니다.
https://s1004games.com

cp torrc.sample torrc

nano torrc

Add/modify:

 

HiddenServiceDir /tor/hidden_service/

HiddenServicePort 80 127.0.0.1:9444

You can get the host name from

sudo cat /var/lib/tor/hidden_service/hostname

This will help you in defining the directory where you have the .onion link to your website and that port 80 (the website port) gets redirected to port 9444 on your actual server. You can set any port you want for that, but you will also make the web server listen on that port. 

Installing the Lighttpd Webserver

 

apt-get install lighttpd php5-cgi

 

lighty-enable-mod fastcgi

lighty-enable-mod fastcgi-php

 

/etc/init.d/lighttpd restart

 

Open lighttpd configuration file and modify lines:

 

nano /etc/lighttpd/lighttpd.conf

 

Add/modify:

 

server.port = 9444

 

$HTTP[“remoteip”] !~ “127.0.0.1” {

     url.access-deny = ( “” )

}

 

server.dir-listing         = “disable”

 

Restart Tor after you do this. Now you can also run it as a daemon so that it keeps on running after you exit the console. Once you have done this, you should check the Message Log to see if there are any error messages. If the Message log is free of errors, you’re good to go. Check out the hidden service directory you created. Tor will have created two files in the directory – hostname and private_key. Don’t give anyone the private_key file or they’ll be able to impersonate your hidden service Tor site. Give the address to others so they can access your site. Remember, people must be using Tor to access your hidden service site.

As mentioned above, be careful of letting your web server reveal identifying information about you, your computer, or your location. You will have to do hardening of your server incase you want be completely anonymous says Arturo Rojas from Mexico who is a black hat researcher and digital forensics course professor.

Another good option to make the deep web website is sities similar to Deepify, it allows  users to create a Silk Road–style black market easily and anonymously with about two clicks. You can open deepify with deepifyvyixbgkts.onion, and it is a very easy to use for people who are non technical.

 

[출처] https://iicybersecurity.wordpress.com/2015/05/13/creating-a-dark-web-deep-web-website/

 

본 웹사이트는 광고를 포함하고 있습니다.
광고 클릭에서 발생하는 수익금은 모두 웹사이트 서버의 유지 및 관리, 그리고 기술 콘텐츠 향상을 위해 쓰여집니다.
번호 제목 글쓴이 날짜 조회 수
공지 침투테스트(취약점검점검, 모의해킹) 문의 / 답변 졸리운_곰 2017.12.10 28360
18 모의해킹 수행 표준(PTES) 소개 file 졸리운_곰 2017.11.20 194
17 웹취약점 분석 및 진단 [템플릿] file 졸리운_곰 2017.11.18 592
16 [웹 취약점 점검] Web Application Security Scanner List 졸리운_곰 2017.11.17 198
15 [취약점 점검툴] Vulnerability Scanning Tools 졸리운_곰 2017.11.17 296
14 Kali 2.0 (VMware Tools 설치) 한글 깨짐현상 해결과 한글 타자 쓰기 file 졸리운_곰 2016.08.09 546
13 NMAP 사용법 졸리운_곰 2016.05.18 340
12 Nmap을 이용한 네트워크 스캐닝과 방어하기 졸리운_곰 2016.05.18 258
11 네트워크 허점을 구석구석! 무료 취약점 스캐너 6종 file 졸리운_곰 2016.05.12 324
10 [스크랩] nmap 명령어 및 사용법 file 졸리운_곰 2016.04.21 473
9 [침투 테스트] 모의해킹[Pentest]의 두번째 단계 스캐닝 file 졸리운_곰 2016.04.20 269
8 해킹방어의 최고수, HDCON에서 가린다 file 졸리운_곰 2015.11.06 200
7 [Kali LInux] WLAN 점검 툴을 개발할때 필요한 Lib libiw.a file 졸리운_곰 2015.05.07 448
6 윤리적·합법적 소셜 엔지니어링 침투 테스트 위한 6가지 고려 사항 졸리운_곰 2014.12.31 348
5 모의해킹결과보고서_hYd3.pdf file 졸리운_곰 2014.11.12 4541
4 취약점 보고서 .doc file 졸리운_곰 2014.11.12 623
3 취약점 점검결과 보고서 testasp_vuln_com_bitscanner_report.pdf file 졸리운_곰 2014.11.12 1569
2 08 - 모의해킹에 대한 소개.pdf file 졸리운_곰 2014.11.12 302
1 역쉘공격 - Reverse Shell Cheat Sheet 졸리운_곰 2014.11.10 271
대표 김성준 주소 : 경기 용인 분당수지 U타워 등록번호 : 142-07-27414
통신판매업 신고 : 제2012-용인수지-0185호 출판업 신고 : 수지구청 제 123호 개인정보보호최고책임자 : 김성준 sjkim70@stechstar.com
대표전화 : 010-4589-2193 [fax] 02-6280-1294 COPYRIGHT(C) stechstar.com ALL RIGHTS RESERVED