FBI allegedly used browser vulnerability to target child abuse ring
American intelligence agency operation reportedly leads to Irish extradition.


The FBI has allegedly used a security vulnerability in Mozilla's Firefox browser to bring down a child pornography ring operating on the dark net.
According to reports, the FBI used a JavaScript injection to compromise the most popular hosting service on the Tor network, Freedom Hosting, which - as well as hosting legitimate services such as TorMail - was allegedly a hub for what has been described as the largest child pornography ring in the world.
The Tor project has not worked with the FBI on this case
So far the only arrest associated with the reported sting has been that of alleged Freedom Hosting founder, 28-year-old Eric Eoin Marques, who holds dual Irish and US citizenship.
Marques appeared before the Irish High Court on an extradition warrant issued by the FBI in Maryland. According to the Irish Independent, the FBI claims Marques is the "largest facilitator of child porn on the planet" and has accused him of distributing graphic images "depicting the rape and torture of pre-pubescent children".
The extradition hearing is ongoing and Marques is expected to appear in court again on Thursday 8 August.
According to reports from grey hat hacker SHG_Nackt and a pastebin posting, dark net sites hosted on Freedom Hosting were compromised using a JavaScript exploit. This allegedly caused a mass outage of hidden services those that can only be accessed using specific proxy services on the Tor network, primarily affecting those hosted on Freedom Hosting.
Those who tried to access sites using Freedom Hosting would, according to numerous reports, see the message "Down for Maintenance. Sorry, this server is currently offline for maintenance. Please try again in a few hours."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
According to SHG_Nackt, anyone who saw this message had arrived at a Tor site hosted by Freedom Hosting. If that person had JavaScript enabled and were using Firefox 17, a JavaScript exploit was injected into their browser.
According to SHG_Nackt,"the JavaScript zero-day exploit that creates a unique cookie and sends a request to a random server that basically fingerprints your browser in some way, which is probably then correlated somewhere else since the cookie doesn't get deleted. Presumably it reports the victim's IP back to the FBI."
The extradition hearing is ongoing and Marques is expected to appear in court again on Thursday 8 August.
Andrew Lewman, executive director of the Tor project told IT Pro "The Tor project has not worked with the FBI on this case. We know nothing about FBI involvement, nor who runs Freedom Hosting.
"The Tor project does not run the Tor Network. We do not run these hidden services. Our blog post clearly states we have no role in this situation."
An FBI spokesperson said: "An individual has been arrested as part of an ongoing criminal investigation in the United States.
"Because this matter is ongoing, longstanding Department of Justice Policy prohibits us from discussing the matter further."

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
By ITPro Published
-
Supply chain as kill chain
Whitepaper Security in the era Zero Trust
By ITPro Published
-
Microsoft under fire for “negligent” security practices in scathing critique by industry exec
News Microsoft took more than 90 days to issue a partial fix for a critical Azure vulnerability, researchers found
By Ross Kelly Published
-
SEC data breach rules branded “worryingly vague” by industry body
News The new rules announced last week leave many questions unanswered, according to security industry experts
By Ross Kelly Published
-
Crackdown on crypto needed to curb cyber crime, says expert
News Threat actors would struggle to generate money without the anonymity provided by unregulated digital tokens, but such a move would require worldwide buy-in
By Rory Bathgate Published
-
Apple patches zero day linked to spyware campaign
News Kaspersky researchers were the first to report a zero day used in a sophisticated attack chain
By Rory Bathgate Published