Iptables, privoxy, polipo & tor.. major headache.

Hello all
I've made another post about this, but it got me nowhere. So I thought I'd repost with a better description of my problem.
I'm trying to set up a method whereby I can connect to privoxy from firefox, which is in turn connected to polipo, which in turn is connected through tor, and then have all the rest of my traffic routed through port 9040 (tor's TransPort). So:
browser {pointed at privoxy} > privoxy > polipo > tor
{all traffic not passed through privoxy} > 127.0.0.1:9040
here is my iptables config:
# Generated by iptables-save v2.4.15 on Fri Oct 12 16:33:33 2012
*nat
:PREROUTING ACCEPT [12:3420]
:INPUT ACCEPT [1:261]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A OUTPUT -p tcp -m tcp -m owner ! --uid-owner polipo -m owner ! --uid-owner privoxy -j ACCEPT
-A OUTPUT -p tcp -m tcp -m owner ! --uid-owner tor -m owner ! --uid-owner polipo -m owner !-j REDIRECT --to-ports 9040
#-A OUTPUT -p tcp -m tcp -m owner ! --uid-owner tor -j REDIRECT --to-ports 9040
COMMIT
# Completed on Fri Oct 12 16:33:33 2012
# Generated by iptables-save v1.4.15 on Fri Oct 12 16:33:33 2012
*filter
:INPUT DROP [9:1175]
:FORWARD ACCEPT [0:0]
:OUTPUT DROP [8:488]
# general
-A OUTPUT -p tcp -m owner --uid-owner tor -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
# allow loopback
-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A INPUT -p all -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
# allow NTPD time syncs
-A OUTPUT -p udp --dport 123 -j ACCEPT
# allow tor
-A OUTPUT -p tcp --dport 9040 -j ACCEPT
-A OUTPUT -p udp --dport 53 -j ACCEPT
-A OUTPUT -p tcp --dport 8123 -j ACCEPT
-A OUTPUT -p tcp --dport 8118 -j ACCEPT
# allow pings
-A OUTPUT -p icmp --icmp-type 8 -j ACCEPT
COMMIT
# Completed on Fri Oct 12 16:33:33 2012
With this configuration, my traffic is blocked by iptables when connected to privoxy and when not connected to privoxy.
here is the output of iptables -nvL:
Chain INPUT (policy DROP 58 packets, 13301 bytes)
pkts bytes target prot opt in out source destination
1153 590K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
55 3617 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * * 127.0.0.1 127.0.0.1
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 523 packets, 31380 bytes)
pkts bytes target prot opt in out source destination
525 146K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 owner UID match 43
528 103K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
55 3617 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:123
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9040
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8123
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8118
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
does anyone see something I don't?
Last edited by ParanoidAndroid (2013-03-12 06:08:08)

duly noted. I appreciate your feedback, but most unfortunately, your constructive criticism does not answer my initial question.
[EDIT]
for the sake of simplicity, I grouped privoxy and polipo under gid "proxy" and tried to use iptables to redirect all but that traffic to port 9040. It still won't work. Here's my iptables config:
# Generated by iptables-save v2.4.15 on Fri Oct 12 16:33:33 2012
*nat
:PREROUTING ACCEPT [12:3420]
:INPUT ACCEPT [1:261]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A OUTPUT -p tcp -m tcp -m owner ! --gid-owner proxy -j ACCEPT
-A OUTPUT -p tcp -m tcp -m owner ! --uid-owner tor -m owner ! --gid-owner proxy -j REDIRECT --to-ports 9040
COMMIT
# Completed on Fri Oct 12 16:33:33 2012
# Generated by iptables-save v1.4.15 on Fri Oct 12 16:33:33 2012
*filter
:INPUT DROP [9:1175]
:FORWARD ACCEPT [0:0]
:OUTPUT DROP [8:488]
# general
-A OUTPUT -p tcp -m owner --uid-owner tor -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
#-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
# allow loopback
-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A INPUT -p all -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
# allow NTPD time syncs
-A OUTPUT -p udp --dport 123 -j ACCEPT
# allow tor
-A OUTPUT -p tcp --dport 9040 -j ACCEPT
-A OUTPUT -p tcp --dport 9050 -j ACCEPT
-A OUTPUT -p tcp --dport 8118 -j ACCEPT
-A OUTPUT -p tcp --dport 8123 -j ACCEPT
-A OUTPUT -p udp --dport 53 -j ACCEPT
# allow pings
-A OUTPUT -p icmp --icmp-type 8 -j ACCEPT
COMMIT
# Completed on Fri Oct 12 16:33:33 2012
I've tried every combination of rules I can imagine, and nothing I do seems to redirect traffic properly. At the moment, traffic can get through my proxies but it also gets redirected to 9040, which causes tor to deny it.
Last edited by ParanoidAndroid (2013-03-14 07:20:07)

Similar Messages

  • CS3 Upgrade & Camera Raw 4.5 = MAJOR HEADACHE!

    I bought a D300. Then found out that the only way to use Photoshop with it was to upgrade the Camera Raw plug-in to 4.5, which could ONLY be used with CS3. So NOW I have THOUSANDS of dollars in camera gear and software that has caused me more headaches than putting 4 kids through high school.
    P4, 4 GB RAM a gazzilion bytes of hard drive space and I'm getting the dreaded blue screen of death after going through 3 or 4 photos in CS3's Bridge.
    PFN_LIST_CORRUPT or something like that. I've emailed support and nothing. Very disappointing to say the least.
    I've got it down to faulting after going through about 10 pics now but NOW, on SOME of the Nikon (.NEF) files, it's telling me that "Photoshop CS2 cannot be found!"
    I'm sorry, but I'm very close to dousing this thing with lighter fluid and sending the ashes back to Adobe. I have over 1000 photos to process from the weekend it's it's IMPOSSIBLE to do it with these errors.
    YES, I did the Camera Raw update per the instructions.

    Elginet - your error message points to RAM problems. Perhaps your PS uses more RAM than other software and therefore the error only shows up when using PS. You could try to remove part of the memory just to locate the problem if it is within one or two memory banks. With 2 GByte the computer should run PS even though a bit slow. Once you located the problem you could either replace the defective memory or replace the whole set depending on your configuration.
    It is not necessarily a hardware fault it could be a setting for memory access in the BIOS.
    Basically CS3 and ACR4.5 work fine on many computers and it is very stable on my machine under Win XP-pro. Be certain it is not a general problem.
    Best of luck that you can resolve your problem.
    Cheers
    Walter

  • I am having major headaches updating to itunes 10.7 I am running windows xp and keep getting error message on instal  update \itunes.msi' cannot be found  i have searched and i cannot find it either not sue what i need to do?  please help

    I am trying to update itune and am geting canot find Update'itunes.msi  I have tried to locate the file and cannot  wit th phone upgraded to ios6 i canno cnnec it to itunes   How can i solve this issue?
    Help

    (1) Download the Windows Installer CleanUp utility installer file (msicuu2.exe) from the following Major Geeks page (use one of the links under the "DOWNLOAD LOCATIONS" thingy on the Major Geeks page):
    http://majorgeeks.com/download.php?det=4459
    (2) Doubleclick the msicuu2.exe file and follow the prompts to install the Windows Installer CleanUp utility. (If you're on a Windows Vista or Windows 7 system and you get a Code 800A0046 error message when doubleclicking the msicuu2.exe file, try instead right-clicking on the msicuu2.exe file and selecting "Run as administrator".)
    (3) In your Start menu click All Programs and then click Windows Install Clean Up. The Windows Installer CleanUp utility window appears, listing software that is currently installed on your computer.
    (4) In the list of programs that appears in CleanUp, select any iTunes entries and click "Remove", as per the following screenshot:
    (5) Quit out of CleanUp, restart the PC and try another iTunes install. Does it go through properly this time?

  • I pause my video and the audio continues...if I play again it causes a major headache. Help?

    This might be an easy to answer question, but I am making my second video, so I'm not too knowledgeable. Anyway, I imported audio into my video and it plays back fine. So I play the video, and pause it to try and synchronize the audio. The video stops, but the audio keeps playing, and it will not stop until the whole thing has played. If I try to start from the beginning again and play the audio to sort of override it, it just overlaps with the original audio, and the resulting noise gives me a headache. I don't know if somehow I can stop the audio a portion of the way through, but if I can, that would be great. It would make syncing a whole lot easier. Thanks!

    Ok, so I had a .m4a file on my computer, which I then turned into an mp3 using the adobe media encoder. I imported the mp3 using File-Import-Import to Library, and then I created a separate layer for the file and dragged the audio from the library onto the stage while I was on that layer. The layer now had a sound file on it, and I put a keyframe a ways ahead on the timeline so I could see the audio layer. I then played it back using the play button underneath the timeline to begin syncing my animation with the audio that I had imported. I stopped it, a little late as it turned out, but the music continued to play. It would not stop until it had gone through the whole song. While the song was playing I tried starting it from the beginning again, but the new sequence overlapped with the old one so they played together out of time, creating a very unpleasant noise. They both had to finish before I could play it back again to try and sync my animations more precisely. If I could pause the video (again, I'm using that little button at the bottom left of the timeline) and stop the audio, syncing would be so much easier, and I assumed there was a way to fix this. I am working with Flash Professional CS5.5. Thanks for your consideration!

  • 10.4.9 is causing me major headaches!

    Last night, I again, tried installing the 10.4.9 Combo Update. It hung at the "100% completed" mark as it had the night before. I went to bed and let it sit there for 8 hours. This morning, the installer was still hung at the same point! And I continue to have three very significant problems.
    1) when I download applications (using Speed Download 4.1.10 as my default downloader), and the .dmg tries to mount, I get an error window saying that the disk image failed to mount because of a "Broken Pipe." There doesn't seem to be anyway that I can get these files to mount thereafter. (I also tried coing back to Speed Download 4.1.9 and the same problem appeared.)
    2) Safari will, frequently, hang when loading a web page. The "address" window will be totally blue (as if it is just finishing loading the page) then I will get a spinning beach ball that stays there forever. I need to do a force quit to get out of it. If I go into Safari again, a page will load, and then I may not get a hang until I go to a 2nd, 3rd, 7th page. It is unpredictable. If I use FireFox 2.0.0.2 I don't seem to have this problem.
    3) When I try to do anything that requires an admin password (e.g., run Onyx, Tiger Cache Cleaner, System Preferences and work with accounts, etc.) the system will deny my admin password saying that it is invalid. Once I reboot, it will accept my password, for maybe one or two uses in programs that require it (including OS 10.4.9), but then it will stop recognizing my admin password and I will have to re-boot..
    The one mistake I may have made on the initial install attempt on Friday night was that I did not disconnect my FW and USB stuff before attempting the install.
    Can soneone please give me some suggestions on how I can get OS 10.4.9 to install properly and (I hope) clear up these problems! I have already wasted enough time trying running TechTool Pro, disk utility (before and after each install attempt, Disk Warrior, and even doing a "Repair Disk" from the original Tiger install CD!! Nothing helps, and I dread having to do an archive and install to go back to 10.4.8.
    Thank you for your help.
    James Collymore
    PowerMac G4 (MDD)   Mac OS X (10.4.9)   1.25 GHz, 1.5 Gb RAM

    Hi James,
    I had a similar problem downloaing 10.4.9 but in my case the icon showd a full download but it wouldn't open saying that it was not a complete download. Tried about a dozen time without success. Finally, in frustration, I went to my regular Apple store where I buy all my Mac stuff and they burned a DVD for me which worked perfectly.
    Are you able to do the same?
    Cheers
    Roger
    Intel Dual Core MacMini 1.86 mHz/20" Cinema Display/1GB RAM and 17" G4 PowerBook   Mac OS X (10.4.8)   Have PB 5300CE, PBG3WS1, G3 PB 500/Pismo and PowerMac 233 gHz desktop.
    Intel Dual Core MacMini 1.86 mHz/20" Cinema Display/1GB RAM and 17" G4 PowerBook   Mac OS X (10.4.9)   Have PB 5300CE, PBG3WS1, G3 PB 500/Pismo and PowerMac 233 gHz desktop.
    Intel Dual Core MacMini 1.86 mHz/20" Cinema Display/1GB RAM and 17" G4 PowerBook   Mac OS X (10.4.9)   Have PB 5300CE, PBG3WS1, G3 PB 500/Pismo and PowerMac 233 gHz desktop.

  • IMovie and Cinema mode = MAJOR headaches!

    Hi there. I've been having this issue for some time now and while I've read similar topics on multiple forums (including this one) I have yet to find a viable fix.
    My problem is importing video from my Panasonic mini DV cam after shooting in Cinema mode (widescreen) iMovie doesn't seem to handle it well. Even when I set iMovie to 16:9 (widescreen) before importing, the video becomes squashed or stretched EVERY time I do. It happened in HD06 as well. I have heard that by importing to Quicktime Pro and saving at a certain resolution it will format it correctly, then importing back to iMovie for editing. I'm not sure on the proper steps though. If anyone knows about this or has another solution PLEASE help! I have wedding footage that I need to edit and with the my current imports it's looking horrible!
    Message was edited by: Michael Carney

    That's an oldish model, and I think that its 16:9 mode is emulated 16:9 ..which means that either - as I mentioned above - it chops off the top and bottom of the picture to give a result which looks wider than normal, or it just spreads each pixel wider to look like 16:9.
    It will send a signal to a TV to tell it to display the video as 16:9 ..though it's actually been shot on a 4x3-shaped CCD.
    This widescreen display signal, though, doesn't do anything in iMovie, because iMovie detects the actual format in which the video was recorded (4:3 ..masquerading as 16:9). So iMovie displays it in the wrong shape.
    By importing your video, then opening each clip in QuickTime Pro and resizing it and Saving it (..as described above..) you should then be able to open it in the correct shape in iMovie ..HOWEVER, I've tried doing exactly that on several occasions, and the new 16:9 dimensions which I've given to clips have NOT been recognised by iMovie when the clips have been re-imported into iMovie! ..It's an annoying characteristic which I've referred to the iMovie Developers.
    Sometimes the newly changed dimensions DO work with iMovie, but often not. It's a shame.
    You can edit within QuickTime Pro, but it's not so simple as editing in iMovie.
    (..I'm just trying to think how I got round this business of QT adjustments not being recognised in iMovie ..I think maybe I exported the resized videos to some other device, like an Archos pocket video recorder..
    ..then re-imported from that ..but I can't quite remember..)
    You can assemble a long movie in QT Pro by adding video sequences to a movie, but there isn't the range of "tweaks" (..transitions, titling, etc..) available in QT Pro which are there in iMovie.
    I don't know if you can send to iDVD ..or rather, import into iDVD.. a QT-Pro-assembled movie: you should be able to with no problem, but I've never tried.
    But you could easily try that yourself! ..Open a video clip in QTP and resize it. Then open another clip in QTP and resize it. Add the 2nd clip to the 1st clip (..there are QTP tutorials online here..) and Save your work, then open iDVD and import the movie you've just created in QTP.
    I don't know if iDVD will recognise the -s-t-r-e-t-c-h-e-d- 16:9 format which you've resized in QTP, or if it will ignore it.
    Why not give it a try and report back..? ..the worst outcome might be that you'd waste a few cents worth of blank DVD..

  • CC LR5 problems, becoming a major headache.

    I have been looking at this needing a serial number for the last month, I spent two hours just today alone in a chat session with an adobe customer support respresentitive. I have un-installed and re-installed LR 5.4 four times today and working on the 5th install. I was told by this representitive that it was taking to long and I would be receiving an email with a open case number so I could continue to fix this problem, I have yet to receive an email and it has been almost three hours since I chatted with them. As a photographer the software we use is very vital to our jobs, it would be nice if it worked correctly half the time. I am about to be done with Adobe products if I can't get some actual solutions to the problems I am having. I need answers, I don't need links I have been to everyone of them and talked with people sending me to this person and that person within the last month and still no solution or response back. Thank you.

    I keep getting the serial number request for the license agreement. All of my other apps work, I have had no problem with them. LR is the only one. I have been on the phone and chat for I don't know how many hours tyring to get back into my LR. Today alone I have installed and reinstalled so much (5x), and the rep is not telling me or doing anything different. This has been very time consuming process and still do not have a solution, what pissed me off is that he told me it was taking to long to try and get this problem fixed, he lied and said an email would come shortly with a reference number to the open case, I have yet to receive a number which the end of the conversation was at 12p.m. central time four hours ago. To me that is another two hours that I spent on here trying to get this resolved; a complete waist of time. I have been through all the links and several representitives. I am having to pay a  monthly fee but it has not worked for me since I un-installed my "hardcopy" and installed from the cloud,  You can see where my frustration is coming from.

  • Premiere Elements 8.0 Trial Version - Major Headache HELP NEEDED!!!!

    I successfully downloaded the trial version of this product with a view to purchasing at a later stage.
    The installation was going well until right at the last minute, when the installation decided to uninstall itself.
    Has anybody else had this problem?
    I am running Windows Vista Home Edition and have recently installed the latest SP2......just wondering whether this has caused the problem

    mike4smq
    What browser are you using for the Premiere Elements 8 download from Adobe? Mozilla Firefox, Internet Explorer (what version?), other.
    Mozilla Firefox will not give me a successful download of this software, whereas Internet Explorer (version 6) will. You could try the download from another browser.
    Even when I was using Internet Explorer, I had a rough time downloading Photoshop Elements 8. The download kept coming with the name Premiere Elements, instead of Photoshop Elements. I believe that problem was on Adobe's end, since I kept retrying the download every so often, and the problems cleared in the early hours of the morning.
    Since I have successfully downloaded Premiere Elements 8, I have had a few odd things going on with my computer, Windows XP Professional SP3. Premiere Elements 8 still does not import .flv. There is a plugin for accomplishing this that works for Premiere Elements 3 and 4, but not 7. I have downloaded and used it and subsequently uninstalled it, no problem. So now I decide to download it to try it on Premiere Elements 8. It will obsolutely not install. It keeps telling me that I do not have any version of Premiere or Premiere Elements installed on my computer. I do have, Premiere Elements 2, 4, 7, as well as 8. Of course, not all opened at the same time. So now I have to figure out why the plugin could be installed with 2, 4, and 7, but not 2, 4, 7, and 8....need to pin down cause and effect.
    ATR
    Windows XP SP3

  • Podcast app in iOS 6 is a major headache. Need help.

    I just downloaded iOS 6 as well as the Podcast App, and my podcasts from "Music" do not all transfer to the Podcast App. Has anyone experienced a similar problem?

    Odd also is that the synch problem I have with the Podcast app is onky on my iPod Touch where I've downloaded both the app and iOS 6.  On my iPhone 4s and iPad 2 where I am still on iOS 5, the Podcast app seems to work, albeit I still receive the "We are sorry, but we are unable to authorize your account. Please contact customer service" for certain Podcast subscriptions.

  • New password policy causing major headaches

    So I was watching a Tedx youtube video the other day that was all about memory.To sum it up, if you create a policy for password (in this case) send out a email to the company about how to make passwords fun. Include a collage of random pictures to help users create new passwords.Collage list from GoogleFun items are much much much easier to remember.So if I had to make a new password as a user, I'd create something fun with the collage and generate a password from that.

    We recently put in a password policy that makes everyone change it every 90 days. This last week was the first time everyone's had to update their password, and we ran into a few issues.We've got over 150 users so I don't know if it's user error or what, but I've had half a dozen people over the last couple days say that they changed their password, and now they can't log into the computer. I end up resetting it for them, and then they're good to go again. I feel like maybe they aren't remembering what they set their password to.Also, another half dozen people so far have complained that their phones aren't syncing mail after changing their password. They said they put the new password into their phone, so it should just keep going... but nothing. Some are fixed by removing the profile and re-adding, others I have to go and delete...
    This topic first appeared in the Spiceworks Community

  • Major headaches with MSI FX5500 TD256 card...

            
    Hello all,
    I recently purchased an MSI FX5500 TD256..now my system keeps rebooting and often suffers from screen freeze.  I can access the internet and stay connected all day with no problems....but as soon as I try to play an online game such as City Of Heroes...reboot.
    I have already installed the newest bios/mobo drivers and any other updates recommended by the program:  Everest. 
    I have tried numerous drivers from both MSI site and Nvidia site.  (Cleaning after each re-install of these with Driver Cleaner Pro as to avoid any possible conflicts.)
    I even re-installed OS (WinXP/Home) twice.  (after formatting HD of course).
    I have used DocMem to check the ram...ram checked out ok.
    I am at my wits end....if anyone has any ideas...solutions..plz help....not much hair left  (grabs handfull and begins to pull)...
    I have a rar file (mini dump file of the error and Everest report on my system)...is it possible to post these?
    The system is roughly 2---2 1/2 yrs old.  (Self built and havent had any serious probs with it until this card.)  oddly enough...the card doesnt appear faulty...
    Also...Everest reports CPU temp is 120F.   But there are 6 fans installed and mobo/CPU  cooler are (mostly) clean.
    Any help would be appreciated. 
    Thnxs.
    Azreil.
     

    Azreil,
    Moan Guide
    Richard

  • Iptables and tor, reroute all traffic for security... Help?

    I'm attempting to route all TCP traffic that does not go through polipo through port 9040, tor's default TransPort. My web browser uses polipo to cache stuff, so I'd like to keep it in place if possible. However, all non-http traffic needs to be sent through the transPort. My current config, which does not take into account rerouting, is below:
    # Generated by iptables-save v1.4.15 on Fri Oct 12 16:33:33 2012
    #*nat
    #:PREROUTING ACCEPT [12:3420]
    #:INPUT ACCEPT [1:261]
    #:OUTPUT ACCEPT [0:0]
    #:POSTROUTING ACCEPT [0:0]
    #-A OUTPUT ! -p tcp -m owner --owner-uid tor -j REDIRECT --to-ports 9040
    #-A OUTPUT -p udp --dport 53 -j REDIRECT --to-ports 9053
    #COMMIT
    # Completed on Fri Oct 12 16:33:33 2012
    # Generated by iptables-save v1.4.15 on Fri Oct 12 16:33:33 2012
    *filter
    :INPUT DROP [9:1175]
    :FORWARD ACCEPT [0:0]
    :OUTPUT DROP [8:488]
    # allow loopback
    -A INPUT -i lo -j ACCEPT
    -A OUTPUT -o lo -j ACCEPT
    # allow NTPD time syncs
    -A OUTPUT -p udp --dport 123 -j ACCEPT
    # allow tor
    -A OUTPUT -j ACCEPT -m owner --uid-owner tor
    -A OUTPUT -p tcp --dport 9040 -j ACCEPT
    -A OUTPUT -p udp --dport 53 -j ACCEPT
    # allow BitTorrent
    -A OUTPUT -p tcp --dport 6969 -j ACCEPT
    -A OUTPUT -p tcp --dport 51413 -j ACCEPT
    -A OUTPUT -p udp --dport 51413 -j ACCEPT
    # allow pings (still not working. fix?)
    -A OUTPUT -p icmp --icmp-type 8 -j ACCEPT
    -A INPUT -p icmp --icmp-type 8 -m conntrack --ctstate NEW -j ACCEPT
    # allow traffic on established connections
    -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    -A INPUT -m conntrack --ctstate INVALID -j DROP
    COMMIT
    # Completed on Fri Oct 12 16:33:33 2012
    as you can see, I've already tried to redirect traffic using the --uid-owner polipo rule. So far, it's just caused iptables to spit out errors. I'm stumped, so I thought I'd come to you wonderful people at the Archlinux forums for help.

    Using the command you gave me, I found that the polipo user is indeed executing /usr/bin/polipo. Other than that, polipo is executing no processes.
    I tried adding the following to my iptables rules nat section:
    -A OUTPUT -p tcp -m tcp -m owner ! --uid-owner polipo -j ACCEPT
    -A OUTPUT -p tcp -m tcp -m owner ! --uid-owner polipo -j REDIRECT --to-ports 9040
    polipo now works, but the rest of my traffic that should go to the TransPort gets blocked.
    [EDIT]
    I'm now trying the same thing, except that I've chained privoxy with polipo like so:
    browser > privoxy > polipo > tor > internet
    my iptables rules look like this:
    # Generated by iptables-save v2.4.15 on Fri Oct 12 16:33:33 2012
    *nat
    :PREROUTING ACCEPT [12:3420]
    :INPUT ACCEPT [1:261]
    :OUTPUT ACCEPT [0:0]
    :POSTROUTING ACCEPT [0:0]
    #-A OUTPUT -p tcp -m tcp -m owner ! --uid-owner tor -j REDIRECT --to-ports 9040
    -A OUTPUT -p tcp -m tcp -m owner ! --uid-owner tor -m owner ! --uid-owner polipo -m owner ! --uid-owner privoxy -j REDIRECT --to-ports 9040
    COMMIT
    # Completed on Fri Oct 12 16:33:33 2012
    # Generated by iptables-save v1.4.15 on Fri Oct 12 16:33:33 2012
    *filter
    :INPUT DROP [9:1175]
    :FORWARD ACCEPT [0:0]
    :OUTPUT DROP [8:488]
    # general
    -A OUTPUT -p tcp -m owner --uid-owner tor -j ACCEPT
    -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    # allow loopback
    -A INPUT -i lo -j ACCEPT
    -A OUTPUT -o lo -j ACCEPT
    -A INPUT -p all -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
    # allow NTPD time syncs
    -A OUTPUT -p udp --dport 123 -j ACCEPT
    # allow tor
    -A OUTPUT -p tcp --dport 9040 -j ACCEPT
    -A OUTPUT -p udp --dport 53 -j ACCEPT
    -A OUTPUT -p tcp --dport 8123 -j ACCEPT
    -A OUTPUT -p tcp --dport 8118 -j ACCEPT
    # allow pings
    -A OUTPUT -p icmp --icmp-type 8 -j ACCEPT
    COMMIT
    # Completed on Fri Oct 12 16:33:33 2012
    and it STILL won't route traffic right. iptables redirects to the TransPort, but any traffic passed through polipo or privoxy reveals "connection reset" error message. Help?
    Last edited by ParanoidAndroid (2013-03-12 01:50:51)

  • Kde4's ktorrent and privoxy/tor

    Has anyone else had trouble getting the new kde4 ktorrent to work with privoxy and tor? I have the same settings as the kde3 version and it won't work for some odd reason. I have it set to send tracker communications through localhost:8118. Privoxy and Tor are both running and working in Firefox.
    ktorrent says "Unknown Host: Unknown Error" in the tracker status box. If I disable the proxy settings in ktorrent, it does work.
    I'm sure that I can't be the only person with this problem. By the way, the test torrent is the i686 iso for Arch 2008.6.

    I use opera, not firefox, but to get Tor working with opera i basically configure opera to use a proxy which is: 127.0.0.1 : 8118
    Maybe you could try setting up something similar, also I don't run "torify opera." I just run "opera."

  • Tor+privoxy+chrome Issue

    Im trying to get tor working with google chrome through privoxy
    Tor installed and runs. Installed vidalia as well
    Privoxy was installed succesfully
    Installed google chrome dev through AUR
    tried setting it up with this command :
    chromium --proxy-server="localhost:8118"      Only I replaced "chromium" with "google-chrome"
    Error is this:
    [1337:1350:3063716153:ERROR:object_proxy.cc(239)] Failed to call method: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.NetworkManager was not provided by any .service files
    Created new window in existing browser session.

    I read up on /etc/hosts.allow but the man page and whatever I could find on the wiki or through google weren't very helpful. I found some references for other things that need to be added to /etc/hosts.allow so I've been copying those but none of them are working.
    So I've added the following things (one of them at a time) to /etc/hosts.allow, then restarted Tor and Privoxy and gotten the exact same error.
    ALL: LOCAL
    privoxy: 127.0.0.1: ALLOW
    tor: 127.0.0.1: ALLOW
    ALL: LOCAL
    privoxy: 127.0.0.1
    tor: 127.0.0.1
    privoxy: 192.168.1.100
    tor: 192.168.1.100
    privoxy: 192.168.1.100: ALLOW
    tor: 192.168.1.100: ALLOW
    privoxy: LOCAL
    tor: LOCAL
    I've mostly been winging it for those entries based on what I read on how to get other daemons working so I've probably been doing it horribly wrong.  Again, all answers appreciated.

  • Privoxy - tor

    Hi!
    Today I installed Privoxy and Tor. I follow instructions from Tor site (I had privoxy - tor on Arch one month ago ) and doesn't work. I also try to turn firewall off and it same. When I check the site Tor detector:
    http://serifos.eecs.harvard.edu/cgi-bin/ipaddr.pl?tor=1
    it says: You are NOT using Tor and show my IP. One month ago work very well but now I don;t know why doesn't work.
    Thanks,

    lumiwa wrote:
    juergen wrote:
    lumiwa wrote:
    Hi!
    Today I installed Privoxy and Tor. I follow instructions from Tor site (I had privoxy - tor on Arch one month ago ) and doesn't work. I also try to turn firewall off and it same. When I check the site Tor detector:
    http://serifos.eecs.harvard.edu/cgi-bin/ipaddr.pl?tor=1
    it says: You are NOT using Tor and show my IP. One month ago work very well but now I don;t know why doesn't work.
    Thanks,
    You added forward-socks4a / localhost:9050 to your privoxy config file /etc/privoxy/config?
    privoxy was updated a few days ago. Your working config file was possible renamed to /etc/privoxy/config.pacsave.
    Jürgen
    Yes, I did.
    I did run tor runasdaemon 1 as user. Now I could run just as root.
    Don't you use the startup script /etc/rc.d/tor?
    tor should setuid tor if you use the default config.

Maybe you are looking for