A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site’s .onion address using only public information, and then take that address over.

Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site’s visitors to a copy of the site they control. Taking over the address does not grant the attacker access to the site’s servers, database, or stored user data.

How the Flaw Works

An .onion address is really a public key, so whoever holds the matching private key controls the address. To stay reachable, a site publishes a signed record, called a descriptor, that anyone on the Tor network can fetch, and GoBalance signs that record.

The flaw is in the signing step. A Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest. The dropped half is the part that keeps each signature’s secret value hidden.

Without that half, the secret value becomes a fixed number anyone can compute. A single published descriptor then carries enough to recover the site’s private key, with no access to its servers.

Because the exposed key is the site’s long-term master key, not a short-lived one, a recovered key can sign valid records for the address far into the future.

Which Sites Are at Risk

GoBalance is a version of Tor’s Onionbalance load balancer rewritten in Go, and it ships with EndGame, a widely used toolkit that keeps dark web sites online during denial-of-service attacks. The flaw is in the rewrite.

Searchlight says the original Onionbalance and Tor itself are not affected.

It also affects only sites whose master key is stored in Tor’s own key format. GoBalance’s setup tool writes keys in a safer format that is not at risk, so not every site running GoBalance is exposed.

The Dread Takeover

The flaw came to light through Dread, one of the dark web’s biggest forums, run by administrators who go by HugBunter and Paris. Between October 5 and 7, both of Dread’s .onion addresses were taken over and pointed at a rival site, Conclave.

Dread’s operators first blamed their own mistake. On October 5, Paris said he had “stupidly uploaded dread’s main onion private key into a gobalance update.”

Two days later the second address, a backup kept for premium members, was taken over as well. A backup is harder to explain as a slip, and HugBunter then said the attacker had used a GoBalance flaw against several dark-web services. Searchlight takes the same view, calling the second takeover the stronger sign the flaw was used, while still treating the first address as a separate key leak.

Dread has since moved to a new address and told users to change their passwords. In a signed message on October 7, the operators said the forum had “migrated, permanently, following onion private key exposure due to a vulnerability in third-party software,” and that “other hidden services may be affected.” They say Dread’s servers were not broken into.

Who Else Is Affected

How many other sites are affected is not clear. HugBunter said several dark-web markets had their addresses taken over, including some that had already shut down, but did not name them or give a number.

At least one other site has confirmed it publicly. Omega, a dark-web market, said in a signed note on October 8 that it took its old address offline “due to an issue caused by the GoBalance bug” and moved to a new one.

No Official Fix Yet

There is no official fix. On October 9, The Hacker News found no CVE identifier for the flaw in the US National Vulnerability Database and no public advisory from the Tor Project or GoBalance’s maintainer. Dread has said it plans to release a patched version of GoBalance and help affected sites move across.

An independent researcher has published a patch and a working proof-of-concept that recovers a master key from a single public descriptor. The researcher says the demonstration used only keys made for the test and that no real service was targeted. The Hacker News has not run the code, and it is not an official release.

What Operators and Users Should Do

For site operators, a patch alone does not undo the exposure. Once a descriptor has been published, the key it leaks cannot be pulled back, so a site that ran a vulnerable version has to create a new .onion address and move to it, as Dread and Omega have done.

For users of a site that may be affected, Dread’s advice was to change your password on it and on other sites that may be affected, and to treat the old address as unsafe. Confirm any new address through a signed announcement before trusting it.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.