>If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about the equivalent of pwning 1 sole proxy.
Can you go into more detail about what you are saying? I'm sure you could drop a- ADOBE, Active-X, Java, ect- 0-day on a page and pwn said box. You can also send payloads to/from TOR; although there are limited transfer protocols you can use.
The whole point of TOR is to try to anonymize you. It's not going to save you from getting owned.
I also made a Text Statistics javascript class based off of Mr. Child's! Any plans on putting your version on GitHub - I'd love to star it and use it to improve the version below.
edit: I even think you are using a similar method.