The first thing I found wasn't a drug market. It wasn't a carding forum. It was a Jenkins instance.
I was three days into a four-week enumeration project, running a Python scraper against a list of .onion addresses pulled from Ahmia, when a response came back that shouldn't have existed on Tor: a Jenkins login page, running version 2.289.1, exposed via a hidden service with no authentication on the /script endpoint. The hostname in the page title belonged to a Fortune 500 subsidiary. Someone in their dev org had spun up a Tor hidden service "for remote access" during a 2020 lockdown and never told security. That CI pipeline had production AWS credentials in its environment variables.
If you're a defender, that's the dark web. Not the monster under the bed — the mirror showing you what you already leaked.
This guide is for sysadmins, security engineers, and threat intel analysts who want to understand what's actually out there, how to enumerate it without getting owned, and — most importantly — how to find your own shadow assets before someone else does. I'm not going to teach you to buy drugs. I'm going to teach you to do OSINT on Tor like an adult with a change-management process.
:::note[TL;DR]
- The "dark web" is 90% dead links, scams, and mirrors of clearnet services. The interesting 10% is mostly accidental exposure and leak sites.
- Never browse Tor from your daily driver. Whonix or Tails, full stop.
- Blocking Tor at the firewall is theater. Detect and log it instead.
- The real risk to your org isn't hackers on Tor — it's the sysadmin who spun up a hidden service and forgot.
- Treat leak sites as a data source, not a destination. Automate, don't interact. :::
Prerequisites
Before you touch any of this, you need:
- A dedicated research VM or physical host (not your work laptop — I'll explain why in the opsec section)
- Whonix Gateway + Workstation, or Tails on a USB stick
- Python 3.9+ with
stem,requests[socks], andbeautifulsoup4 - Basic familiarity with
iptables/nftablesand Linux namespaces - A legal review from your org's counsel if you're doing this on company time (seriously)
What "The Dark Web" Actually Is (And What It Isn't)
Words matter here, because people conflate three different things constantly. The deep web is anything not indexed by search engines — your intranet, your bank portal, your O365 tenant. The dark web is content hosted on overlay networks like Tor, I2P, and Freenet that requires specific software to reach. Tor is the transport; the dark web is an application layer on top of it.
Tor uses onion routing — traffic is wrapped in three layers of encryption and bounced through three relays (guard, middle, exit). I2P uses garlic routing, which bundles multiple messages together and is optimized for internal services (eepsites) rather than exit traffic. Freenet is a distributed datastore, mostly academic at this point. ZeroNet is effectively dead. If someone tells you they're "on the dark web" and they mean ZeroNet, they're either confused or lying.
Why "Just Block Tor at the Firewall" Is a Losing Strategy
⚠️ TRUNCATED VERSION
This is an abbreviated cross-post. Full article (all config files, architecture diagrams, images): valtersit.com
🛠️ Partner Tools for Developers
ValtersIT curates partner deals for developers and sysadmins — VPS hosting, security tools, monitoring platforms and dev productivity gear. No filler, no affiliate spam.
Top comments (0)