Tue May 16, 2006 2:02 pm
Tue May 16, 2006 7:06 pm
Wed May 17, 2006 3:04 am
well,apperently after i found out that someone was taking items out of my SDB and putting in trades,i implemented the PIN.it stopped them for a few hours but when i woke up in the morning,my acct had been frozen due to "someone hacking".when i got my acct back,i still lost all my items and nps despite the implementation of the PIN.stampsyne wrote:I HIGHLY recommend implementing the PIN number system to protect all areas of your account.
Wed May 17, 2006 3:15 am
Wed May 17, 2006 4:25 am
patjade wrote:Did you change your password? Did you check and see if your email was changed? Perhaps the hacker managed to hack your email account? if so, they could then use it to get your password AND your PIN number.
Wed May 17, 2006 5:04 am
Wed May 17, 2006 5:11 am
well the moment i saw something suspicious,i went to change everything,password,email etc.all done within half an hour when i found out.patjade wrote:Did you change your password? Did you check and see if your email was changed? Perhaps the hacker managed to hack your email account? if so, they could then use it to get your password AND your PIN number.
well,i changed everything upon finding out.implemented the pin as well.and if i remembered correctly,that hacker even exhausted all 5 tries of the pin.cos when i tried to change the pin again it says i have exhausted my 5 tries.apparently the hacker is trying his luck with the pin.nevertheless the next morning he still got in....and took everything tat is valuable aka codestones,paintbrushes,morphling potions,neggs and my 8MILLION NEOPOINTS!everconfused wrote:patjade wrote:Did you change your password? Did you check and see if your email was changed? Perhaps the hacker managed to hack your email account? if so, they could then use it to get your password AND your PIN number.
If they were already in the account, and the PINs apparently weren't in place at the time, then the cg'er would easily have been able to change the email. So setting PIN after the fact would not help. And you can only change your email once every 24 hours (I think?).
I clear everything, it's set auto on FF which is what we mainly use here. However, if you've been (or think you've been) cg'ed, clearing cookies, etc. won't do anything - the person already has your info.
The only thing that *might* help is if you think anything's suspicious is to immediately go to your user info page and change your password, then if you like log out, clear and log in again. Usually, changing the password will kick anyone else out of your account -- but I have heard from a few people that that wasn't the case.
Wed May 17, 2006 7:44 pm
Wed May 17, 2006 10:37 pm
Thu May 18, 2006 12:52 am
Raza wrote:A cookie grabber is a bit of code in a webpage that uploads your neopets cookie (a cookie is the small file that websites send you to remember personal info, like settings and saved login info) to their server, ie 'grabs' it. The best way to stop it happening is to not visit neopets related sites that aren't either on neopets or some well known fansite like PPT. Or alternatively, you could browse neopets with a seperate browser entirely and not log in with the browser you do everything else with, so the cookie for neopets simply wouldn't exist when your browser is ordered to grab it.
I'm mostly speculating though. Never seen one in code and I couldn't tell you what they do exactly.
Thu May 18, 2006 3:04 am
this is bad...does it mean i will get cged again?everconfused wrote:Raza wrote:A cookie grabber is a bit of code in a webpage that uploads your neopets cookie (a cookie is the small file that websites send you to remember personal info, like settings and saved login info) to their server, ie 'grabs' it. The best way to stop it happening is to not visit neopets related sites that aren't either on neopets or some well known fansite like PPT. Or alternatively, you could browse neopets with a seperate browser entirely and not log in with the browser you do everything else with, so the cookie for neopets simply wouldn't exist when your browser is ordered to grab it.
I'm mostly speculating though. Never seen one in code and I couldn't tell you what they do exactly.
It doesn't matter what browser you're using, people have been cg'ed with javascript disabled, and every other security thing they can think of (much smarter about this stuff than I'll ever be!).
The thing is, the cg'ing that is happening on the site is just that -- it's ON the site. In other words, Neo could be the only place you go using x browser, and you're good about keeping everything cleared when you log out, don't store passwords, run your a/v and spyware scans, have a firewall.
All it takes is going to a lookup or shop (usually, though there were apparently some on pet lookups and petpages) that has the cg'er on it. You're done. At that point, the only thing I think you can do is change your password quickly, log out, clear everything, log in again and what some have done is change their password again, as well as their PIN.
I don't know about what migh currently be going on (if anything) but some of the cg'ers were redirecting people to a blank page, then back to Neo in a few seconds. So, again, it's not a matter of you voluntarily leaving the site and going to another, unsafe site. This is done to you, not by you.
Yes, you can get grabbed by going to unsafe sites and anyone who does this sort of thing is beyond pathetic IMHO. Neo instituted the HTML filter check to help stop this stuff. Now, a question is does/can the filter work if someone hasn't tried to change or update a page? Current consensus of some users is No, obviously the filter can't do anything if information is already on a page.
I do understand from a staff member posting on a board that alot of legwork was done to try to find any cg'ers on the site. And I think they did a great job! Does that mean they found them all? No. Does that mean, even with the new filter that cg can't be put on a page? Probably not, given that some people seem to have nothing better to do with their time than think up ways to steal from others.
Thu May 18, 2006 4:09 pm
moreau360 wrote:this is bad...does it mean i will get cged again?
Thu May 18, 2006 11:27 pm
Raza wrote:A cookie grabber is a bit of code in a webpage that uploads your neopets cookie (a cookie is the small file that websites send you to remember personal info, like settings and saved login info) to their server, ie 'grabs' it. The best way to stop it happening is to not visit neopets related sites that aren't either on neopets or some well known fansite like PPT. Or alternatively, you could browse neopets with a seperate browser entirely and not log in with the browser you do everything else with, so the cookie for neopets simply wouldn't exist when your browser is ordered to grab it.
everconfused"It doesn't matter what browser you're using, people have been cg'ed with javascript disabled, and every other security thing they can think of (much smarter about this stuff than I'll ever be!).[/quote]
No, you cannot be cookie grabbed with javascript disabled. There are only two ways for someone to look at your cookies:
1) Your browser sends them to the web server. For someone to look at them this way, they'd have to have access to Neopets' logs, which they don't.
2) A page on the same site can look at them through javascript. This means someone has to figure out a way to get javascript on a page somewhere. If you have javascript disabled. though, it won't work.
[quote="everconfused wrote:... some of the cg'ers were redirecting people to a blank page, then back to Neo in a few seconds. So, again, it's not a matter of you voluntarily leaving the site and going to another, unsafe site. This is done to you, not by you.
everconfused wrote:Yes, you can get grabbed by going to unsafe sites
everconfused wrote:Neo instituted the HTML filter check to help stop this stuff. Now, a question is does/can the filter work if someone hasn't tried to change or update a page? Current consensus of some users is No, obviously the filter can't do anything if information is already on a page.
everconfused wrote:Does that mean, even with the new filter that cg can't be put on a page? Probably not, given that some people seem to have nothing better to do with their time than think up ways to steal from others.