Quantcast

Jump to content


Photo

Cookie Grabbers.. Again >_<


  • Please log in to reply
78 replies to this topic

#26 iomega

iomega
  • 1070 posts


Users Awards

Posted 05 July 2010 - 04:45 PM

With any luck maybe they'll finally disable html in usershops and we won't have to deal with all those mall banners and Geocities style layouts


NOOOOOOOOOOOOOOOOOOOOOOOO!


:sarcasm:

#27 Xwee

Xwee
  • 994 posts

Posted 05 July 2010 - 05:09 PM

Yessss I did. Cross site scripting wont work. It needs to be executed on the neopets.com domain.


I will interpret this answer to say
"Yes xwee, don't leave your neopets account logged in 24/7 and log out of it so as to prevent the CG from doing its work."

Thanks iArgue for clarifying this for me. ^,^

Cross site scripting wont work <--- I knew this

#28 iargue

iargue
  • 10048 posts


Users Awards

Posted 05 July 2010 - 05:16 PM

I will interpret this answer to say
"Yes xwee, don't leave your neopets account logged in 24/7 and log out of it so as to prevent the CG from doing its work."

Thanks iArgue for clarifying this for me. ^,^

Cross site scripting wont work <--- I knew this


/sigh

#29 Xwee

Xwee
  • 994 posts

Posted 05 July 2010 - 05:33 PM

Concern was brought up by Noit telling us to log out and back in to reset our session.
I interpreted it to mean that logging out would prevent the cookies from stealing account information.
I wanted to know if being logged in at all times would make it so that my account was vulnerable or since I hadn't typed a pass then I shouldn't be worried.

Do you now see why I kept insisting my question went unanswered or am I just not being clear enough about my confusion/question for anyone to make any sense of. If so let me explain it the simplest way possible.

I asked if not ever logging out of neopets put my account at risk.

If that's not simple enough, then I'll just have to hope for the best.

#30 Noitidart

Noitidart
  • Neocodex Co-Founder

  • 23214 posts


Users Awards

Posted 05 July 2010 - 05:33 PM

Gosh kids. Lol.

#31 Xwee

Xwee
  • 994 posts

Posted 05 July 2010 - 05:41 PM

Sorry Noit, I don't mean any disrespect or insult to anyone, but I would like to know if I am at a greater risk since I almost never log out of my account or if I am fairly safe as having never logged out there isn't availability to my pass and such. I don't know how well or what CGs do, but will logging out at least once a day make my account safer is really all I want to know.

#32 Noitidart

Noitidart
  • Neocodex Co-Founder

  • 23214 posts


Users Awards

Posted 05 July 2010 - 05:56 PM

No sweat. I understand everyones paranoia, and I got a good laugh out of your discussion with argue. I love you both so much.

Anyways to reitterate and maybe explain a little more: Yes logging out will help as every time you log out your session expires. If you were CG'ed it doesn't matter as they have an old session which will no longer work. Be sure to add that pin in case they get into your account before you log out.

#33 iargue

iargue
  • 10048 posts


Users Awards

Posted 05 July 2010 - 06:15 PM

Concern was brought up by Noit telling us to log out and back in to reset our session.
I interpreted it to mean that logging out would prevent the cookies from stealing account information.
I wanted to know if being logged in at all times would make it so that my account was vulnerable or since I hadn't typed a pass then I shouldn't be worried.

Do you now see why I kept insisting my question went unanswered or am I just not being clear enough about my confusion/question for anyone to make any sense of. If so let me explain it the simplest way possible.

I asked if not ever logging out of neopets put my account at risk.

If that's not simple enough, then I'll just have to hope for the best.



Your account is only at risk when you visit a usershop thats infected with a Cookie Stealer. Thats it. So if your logged into neopets while browsing neocodex, your safe. If your logger in while visiting a user shop, you are not safe.

#34 Noitidart

Noitidart
  • Neocodex Co-Founder

  • 23214 posts


Users Awards

Posted 05 July 2010 - 06:17 PM

Most likely a usershop but can't it also be userlookups and pet page. Pet pages especially because you have so so much freedom there right? I don't know I've never made a pet page.

#35 iargue

iargue
  • 10048 posts


Users Awards

Posted 05 July 2010 - 06:41 PM

Most likely a usershop but can't it also be userlookups and pet page. Pet pages especially because you have so so much freedom there right? I don't know I've never made a pet page.

Yeah, it can be anything

Usershops are just the most common.

#36 coqs

coqs
  • 200 posts

Posted 05 July 2010 - 06:53 PM

oh fuck I was using my sister's acct to snipe because she has SSW, now I'm paranoid... thanks for the warning *goes to change her PW and add a pin on everything*

Edited by coqs, 05 July 2010 - 06:54 PM.


#37 Xwee

Xwee
  • 994 posts

Posted 05 July 2010 - 07:03 PM

alright then I'll log out before I begin a FQ since that's usually when I DO enter shops and as for petpages I rarely view them unless I know the person well. The only other time I view shops is if they have something I want.

I do wish that TNT will disable editing privelages and make shop styles available like they do sidebars so that the person can select a layout available without all the nonsense of extra images. Though after I worked so hard on my look up its sort of a shame if they do it.

Surely they won't remove petpages, since so many people use them for RP characters, but if they remove all then that one goes too. (Another I worked hard on.. and there are so many guides that can be linked directly to a petpage.. Maybe they'll make it so that we can only do text edits or something, and block tags except for br and p...

#38 artificial

artificial
  • 186 posts


Users Awards

Posted 06 July 2010 - 02:32 AM

The vulnerability -is- in the user shops.


Yeah, it can be anythingp


Derp.

#39 devil669988

devil669988
  • 355 posts

Posted 06 July 2010 - 06:09 AM

Just wondering if i am using auto trainer and it buys a codestone from a shop with a cookie grabber will it be able to grab the cookie? Since if thats so what can i do to prevent it other than putting pin on everything

#40 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 06 July 2010 - 06:11 AM

Just wondering if i am using auto trainer and it buys a codestone from a shop with a cookie grabber will it be able to grab the cookie? Since if thats so what can i do to prevent it other than putting pin on everything


Try reading the thread.

#41 devil669988

devil669988
  • 355 posts

Posted 06 July 2010 - 06:18 AM

Waser i've read the thread and i don't actually know how the auto trainer works so i don't know if it runs the javascript on the picture when buying items from the shop wizard. So can you please tell me if it can cookie grab and i know they take it from the web browser but Auto trainer can be used to browser sync plus it can be used to save user password so i was wondering if they can steal that information with the cookie grabber?

#42 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 06 July 2010 - 06:23 AM

Waser i've read the thread and i don't actually know how the auto trainer works so i don't know if it runs the javascript on the picture when buying items from the shop wizard. So can you please tell me if it can cookie grab and i know they take it from the web browser but Auto trainer can be used to browser sync plus it can be used to save user password so i was wondering if they can steal that information with the cookie grabber?


Also. Do not worry about our programs that use User Shops.

Our http wrapper does not execute Javascript(Or any other language), and thus is safe from any form of exploit again it.



#43 Nonygirl

Nonygirl
  • 99 posts

Posted 06 July 2010 - 06:33 AM

Argh, wtf. Noscript is driving me nuts.

I have no idea how to configure this. Can anyone tell me what the bare minimum settings are that I need to prevent cgers in neopets shops =/ Noscript is going crazy blocking all sorts of stuff. Is it just java I need to block?

Edited by Nonygirl, 06 July 2010 - 06:29 AM.


#44 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 06 July 2010 - 06:36 AM

Argh, wtf. Noscript is driving me nuts.

I have no idea how to configure this. Can anyone tell me what the bare minimum settings are that I need to prevent cgers in neopets shops =/ Noscript is going crazy blocking all sorts of stuff. Is it just java I need to block?


If you're having trouble with NoScript usually just pinning everything on your account will be good enough to prevent anything being taken. If everything is pinned then even if you are CGed they won't be able to do anything like stealing your items or taking NP out of the bank.

#45 Nonygirl

Nonygirl
  • 99 posts

Posted 06 July 2010 - 06:38 AM

If you're having trouble with NoScript usually just pinning everything on your account will be good enough to prevent anything being taken. If everything is pinned then even if you are CGed they won't be able to do anything like stealing your items or taking NP out of the bank.


Well see here's the thing, my emails to find my pin (I have a pin?) are bouncing and I can't figure out how to unblock the stupid emails so I have to wait until tomorrow to send yet another one, so I don't have a pin right now =/

Meh. I guess I just won't buy anything for a while.

#46 Waser Lave

Waser Lave

  • 25516 posts


Users Awards

Posted 06 July 2010 - 06:39 AM

Well see here's the thing, my emails to find my pin (I have a pin?) are bouncing and I can't figure out how to unblock the stupid emails so I have to wait until tomorrow to send yet another one, so I don't have a pin right now =/

Meh. I guess I just won't buy anything for a while.


If you're using Abrosia it'll be fine anyway because none of the programs run javascript. ;)

#47 Nonygirl

Nonygirl
  • 99 posts

Posted 06 July 2010 - 06:43 AM

If you're using Abrosia it'll be fine anyway because none of the programs run javascript. ;)


Yea I've noticed that seeing as you guys have had to repeat it like 5 times in this thread haha.

#48 devil669988

devil669988
  • 355 posts

Posted 06 July 2010 - 07:05 AM

I see thanks waser i didn't notice those posts

#49 kittycat

kittycat
  • 633 posts

Posted 06 July 2010 - 06:31 PM

I've never used a user shop before so I don't think this will effect me.

#50 pabs123

pabs123
  • 498 posts

Posted 06 July 2010 - 08:50 PM

I've never used a user shop before so I don't think this will effect me.


wow how is that possible :S no quests, pet training, BD items, faeries, gallery, collections, packrats, or anything? :S


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users