Capture a service reachable only over Tor, documenting the path taken and declaring what stayed outside the anonymous network.
A module that fell back to the ordinary network “so as not to fail the acquisition” would be worse than one that stops: the operator would get a bundle, without knowing that the examined service had seen their address.
The Tor connection must be established before the window opens. If it is not, the acquisition does not start at all.
The checks that in other modules travel in the clear — DNS lookups, WHOIS, route tracing, direct certificate reading — have been removed, not routed elsewhere. What does not exist cannot leak.
Each acquisition starts from an empty session that never touches the disk, and the proxy is verified before every load rather than assumed to be set.
If anything could not go through Tor, the bundle contains the record of omitted checks and of any services contacted outside the network. An explicit statement is worth more than silence.
Further reading: the Web pages module, for the ordinary web · the chain of custody of digital evidence · how the opposing party verifies the bundle.
It is a choice, not a technical limitation: material from .onion services can be of any nature, and keeping it for years would mean holding it.
Hashes, times, timestamp, operator, service address and circuit. Any package is discarded by the server before it is even written to disk.
On the computer of whoever acquired it. There is no download button in the client area, and that is not a defect: in its place there are the fingerprints, which are what is needed to verify a bundle produced by someone else. The reports remain available, because they are generated from the recorded data.
A real error had reached the server with the full .onion address inside. Now every onion label is replaced by a short, stable fingerprint: two errors on the same service remain recognisable as such, but nobody can tell which service it is.
On top of everything a web page acquisition produces, minus the checks that make no sense over Tor.
The server recomputes the .onion address checksum itself rather than trusting the program, and derives the service's public key from it. An address that does not check out is flagged as unverified.
The path actually taken inside the network, with the relays traversed. ⚠️ For an .onion service the last node is not an exit node: it is a rendezvous point, and the report says so instead of using the wrong term.
DNS, WHOIS and route tracing do not exist for an .onion service. The bundle declares this as such, rather than leaving empty sections that would look like a half-successful acquisition.
Network exit, bundle retention, address verification and cost: the most common questions about the Deep Web module.
.onion services can be of any nature, and keeping it for years would mean holding it. The bundle exists in a single copy, on your computer; the reports remain available because they are generated from the recorded data.A real case where this module is needed: read the story.
Register for free and download C.E.R.T.O. Desktop for Windows and macOS from your client area.