Jump to content


Neomail Cookie Grabbers


  • Please log in to reply
60 replies to this topic

#1 Waser Lave

Waser Lave

Posted 04 November 2010 - 03:52 AM

Apparently there's some cookie grabbers going around in Neomails recently so if you're concerned you might want to consider changing your Neopets site preferences to Plain Text Neomails or making it so only your Neofriends can send you mails for a while. As always, it's also best to use a PIN on the most valuable parts of your account if you really don't want to risk losing them.

http://www.jellyneo.net/

Posted Image


Advertisement

    #2 Powerrrr

    Powerrrr

    Posted 04 November 2010 - 04:19 AM

    Is Neopets ever going to fix this cookie grabber epidemic :angry:

    #3 DragonEx

    DragonEx

    Posted 04 November 2010 - 04:19 AM

    Thanks for the heads up, good to know. *Starts inserting pin all over*

    #4 KrawkLover

    KrawkLover
    • Trader Score:68.82

    Posted 04 November 2010 - 04:40 AM

    View PostPowerrrr, on 04 November 2010 - 04:19 AM, said:

    Is Neopets ever going to fix this cookie grabber epidemic :angry:

    people say that its quite impossible, because cookie function enables you to login; disabling the use of cookie function will make you log out every refresh... (not sure if its true)


    I just wonder how ppl can enter a set of script into the mail and is able to pass the filter...

    #5 Lineage

    Lineage
    • Trader Score:3

    Posted 04 November 2010 - 05:09 AM

    Thanks for the heads up.
    I stopped frequenting the Neoboards so I probably wouldn't have known otherwise.

    *goes to change neomails to neofriend-only*

    #6 soul__stealer

    soul__stealer
    • Trader Score:28

    Posted 04 November 2010 - 05:11 AM

    View PostKrawkLover, on 04 November 2010 - 04:40 AM, said:

    people say that its quite impossible, because cookie function enables you to login; disabling the use of cookie function will make you log out every refresh... (not sure if its true)


    I just wonder how ppl can enter a set of script into the mail and is able to pass the filter...
    It is possible. It just requires them to do some better coding and prevent people from being able to use the type of code they can in order to CG (which means a bit of revamping is in order ooh-rah.

    Supposedly this script is more than a simple CG script, and 'can retrieve your password' if you use your browser 'form saver' function and have your username/password stored.

    Posted Image

    Quote

    dorino: you look bad ass from the neck down and above that you're a god damn nerd, soul


    #7 EzioAuditore

    EzioAuditore

    Posted 04 November 2010 - 05:15 AM

    View PostPowerrrr, on 04 November 2010 - 04:19 AM, said:

    Is Neopets ever going to fix this cookie grabber epidemic :angry:


    If they spent their time fixing coding errors how would they ever have time to make new NC?!?!?!

    #8 Faval

    Faval

    Posted 04 November 2010 - 05:46 AM

    View Postsoul__stealer, on 04 November 2010 - 05:11 AM, said:

    It is possible. It just requires them to do some better coding and prevent people from being able to use the type of code they can in order to CG (which means a bit of revamping is in order ooh-rah.

    Supposedly this script is more than a simple CG script, and 'can retrieve your password' if you use your browser 'form saver' function and have your username/password stored.

    Well...isn't that just great. I have to say the guys who make the script are clearly better coders than the guys neopets hire :p

    #9 bloomer

    bloomer
    • Trader Score:3

    Posted 04 November 2010 - 05:54 AM

    thanks for warning now i`ll be careful to who isend mail

    are there any steps to know if someone is spamming

    #10 Abigail

    Abigail
    • Trader Score:49

    Posted 04 November 2010 - 06:02 AM

    I don't understand how it can be done throuh neomail, unless they give you a link through neomail and you click on it...
    is it even possible?

    #11 soul__stealer

    soul__stealer
    • Trader Score:28

    Posted 04 November 2010 - 06:17 AM

    View PostAbigail, on 04 November 2010 - 06:02 AM, said:

    I don't understand how it can be done throuh neomail, unless they give you a link through neomail and you click on it...
    is it even possible?
    No.

    When a page is loaded on the internets, scripts are executed to perform functions... in most cases they are good (example this pages scripts allow you to have the dropdown bars for you UserCP etc)...

    Most websites allow users to input information. Such as the neomail system (or codex post box). The problem is that due to the neohtml abilities, neopets has the flow in which users can take advantage of certain flaws in order to execute malicious scripts/codes. It's an oversite that Neopets seems to greatly ignore until it's too late.

    Posted Image

    Quote

    dorino: you look bad ass from the neck down and above that you're a god damn nerd, soul


    #12 EzioAuditore

    EzioAuditore

    Posted 04 November 2010 - 06:22 AM

    View Postsoul__stealer, on 04 November 2010 - 06:17 AM, said:

    No.

    When a page is loaded on the internets, scripts are executed to perform functions... in most cases they are good (example this pages scripts allow you to have the dropdown bars for you UserCP etc)...

    Most websites allow users to input information. Such as the neomail system (or codex post box). The problem is that due to the neohtml abilities, neopets has the flow in which users can take advantage of certain flaws in order to execute malicious scripts/codes. It's an oversite that Neopets seems to greatly ignore until it's too late.

    Isn't it possible to put a link into a neomail and hide it with script though? I thought that's how it was actually happening to people.

    #13 Noitidart

    Noitidart

    Posted 04 November 2010 - 12:32 PM

    Wow i heard this too. I didnt think it was true. Moved to news.
    Posted Image
    "PKKKHHHHHEWWWWWW....Safety" Posted Image
    Spoiler

    #14 Kraftwerk

    Kraftwerk
    • Trader Score:4

    Posted 04 November 2010 - 01:10 PM

    Thanks for the warning... I was a victim before and I don't want it to happen again -_-

    #15 iargue

    iargue
    • Trader Score:2

    Posted 04 November 2010 - 01:54 PM

    View PostFaval, on 04 November 2010 - 05:46 AM, said:

    Well...isn't that just great. I have to say the guys who make the script are clearly better coders than the guys neopets hire :p

    Usually just one person makes the script, and thousands of people known as "script kiddies" take the script and use it.

    View PostEzioAuditore, on 04 November 2010 - 06:22 AM, said:

    Isn't it possible to put a link into a neomail and hide it with script though? I thought that's how it was actually happening to people.


    What would the good of hiding a link be?

    They just make a script so whenever you visit a Neomail, it automatically emails your cookie to them, so they just load up the cookie in the browser and have fun. Logging out and back in is greater then this method, because only one cookie is valid at a time.


    Posted Image
    Credits to Joanna for the Sig!
    Old sigs

    Spoiler
    Programs Progress
    Spoiler

    Click here and ask me anything.


    #16 myob12345

    myob12345

    Posted 04 November 2010 - 04:52 PM

    i'm not sure i understand how this works. so they write a script into the neomail and it executes when you open the mail? is it just a blank mail then? or do they write some nonsense?

    would adblock (that blocks javascript) or noscript stop this at all?

    #17 iargue

    iargue
    • Trader Score:2

    Posted 04 November 2010 - 05:28 PM

    View Postmyob12345, on 04 November 2010 - 04:52 PM, said:

    i'm not sure i understand how this works. so they write a script into the neomail and it executes when you open the mail? is it just a blank mail then? or do they write some nonsense?

    would adblock (that blocks javascript) or noscript stop this at all?


    It can be either one. Usually some none sense to get you to open it.

    And Noscript would stop it. Adblock would need to block the specific script.


    Posted Image
    Credits to Joanna for the Sig!
    Old sigs

    Spoiler
    Programs Progress
    Spoiler

    Click here and ask me anything.


    #18 frostsnow

    frostsnow

    Posted 04 November 2010 - 10:16 PM

    Oh wow. This whole CG-ing business is really starting to do my head in. D:

    Thanks for the warning.

    *goes to change neomail settings*

    #19 Philly

    Philly
    • Trader Score:65

    Posted 04 November 2010 - 11:07 PM

    Thanks for the heads-up *changes settings on plain text neomail*
    When trading with me please remember:

    I live in GMT+1, go to bed early and have a life next to the internet. I might not always reply a second after you messaged me. MSN is quicker.


    #20 DragonX

    DragonX

    Posted 04 November 2010 - 11:14 PM

    Thanks man :)

    I gotta change my settings.



    #21 Scot

    Scot
    • Trader Score:4

    Posted 04 November 2010 - 11:18 PM

    Next thing you know there will be neobeard cgs and tnt will disable all html. Please let this happen.
    nymh (1:46:09 PM): I want a penis.
    nymh (1:48:20 PM): Can I make it look like a snail shell
    nymh (1:48:45 PM): I would hang stuff from it


    Spoiler

    #22 Noitidart

    Noitidart

    Posted 05 November 2010 - 01:09 AM

    I think everything plain text would be just awesome. There's nothing wrong with it.
    Posted Image
    "PKKKHHHHHEWWWWWW....Safety" Posted Image
    Spoiler

    #23 Fayt

    Fayt
    • Trader Score:9

    Posted 05 November 2010 - 05:29 AM

    There already have been a few Neoboard CG'ers apparently a month or so ago. They were in the trading boards and I saw one apparently on the pet trading board. :/
    Posted Image

    #24 Abigail

    Abigail
    • Trader Score:49

    Posted 05 November 2010 - 07:51 AM

    Plain text will fix it?

    #25 Faval

    Faval

    Posted 05 November 2010 - 07:57 AM

    View PostAbigail, on 05 November 2010 - 07:51 AM, said:

    Plain text will fix it?

    Yes, setting your neomails to plain text will prevent the scripts from going off in your neomail. Unless you meant something else?


    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users