Wed Dec 13, 2006 11:46 pm
kcharles wrote:I'd say wait till Tuesday.I'm not going to any shops,lookups or new Petpages today.marccaty wrote:I'm taking all the precautions. But how do we know when it's safe again? Neopets has not, in the past, been helpful in either acknowledging problems like this or giving an all clear.
Thu Dec 14, 2006 3:11 pm
Thu Dec 14, 2006 4:44 pm
Thu Dec 14, 2006 9:25 pm
shapu wrote:I would think that the easiest way to go about fixing this would be to tie cookies to IP addresses.
Thu Dec 14, 2006 11:02 pm
Thu Dec 14, 2006 11:16 pm
Kenjiro wrote:shapu wrote:I would think that the easiest way to go about fixing this would be to tie cookies to IP addresses.
What if you use different computers?
Carnberry wrote:Yeah, or are on an ISP like AOL that changes your IP drastically every time you log on? I'm not, but I used to be a supermod at a large forum, and we'd often run into that problem when trying to place an IP ban on bad posters.
Fri Dec 15, 2006 1:28 am
Fri Dec 15, 2006 2:46 am
Hunter Lupe wrote:Probably the easiest way to go securing the sessions is to set relatively short experiation for session keys (keep swapping them while the user is logged in) - requires stolen cookies to be taken advantage of immediately rather than giving a large window of opportunity; then lock session to a particular IP wildcard and a hash of User-Agent: header (makes it somewhat less trivial to hijack a session - especially since a UA check is invisible to the client). Autologin keys could be stored as cookies on for separate subdomain (ie. http://secure.neopets.com) - that way, it's relatively easy to arrange a clickthrough (or simply a double Location: redirect) to re-authorize a timed-out user, and prevent the autologin key from being stolen anywhere on the site. I'd be surprised if they don't do some of that already.
Fri Dec 15, 2006 5:37 am
NeoFaN_mc2 wrote:CGS are EVERYWHERE! Theres anti CG tools and tips on my neo fan site(check my other topic ^_^)
Edit:
I got an update from my hacker friend that any page where an image could be placed, there could be a CG, so be SUPER CAREFULL EVERYBODY!!
Inrun Edit: Please edit your posts before you double post. We are not the neoboards. There is a handy little edit button in the top right of your post screen. Please use it in the future before you double post.
Fri Dec 15, 2006 6:06 am
everconfused wrote:anjuna, a few people who posted on the boards said they got some sort of weird pop-up that was only there for a few seconds -- that was in user shops. I don't know if anything showed up on bad lookups.
...
As to disabling java. I've heard that people have been frozen for doing that. So, on the one hand, disabling it is supposed to help prevent cg from happening. But I'm no tech-type person, so I don't know that that would actually do any good. And on the other hand, even if it somehow does protect you from cgers, TNT might take exception to your doing that and freeze you. Sounds like a lose/lose situation to me.
Fri Dec 15, 2006 7:16 am
anjuna wrote:
I default disable Java applets and am pretty sure you can't get frozen over anything like that.
Fri Dec 15, 2006 8:27 am
everconfused wrote:As to disabling java. I've heard that people have been frozen for doing that. So, on the one hand, disabling it is supposed to help prevent cg from happening. But I'm no tech-type person, so I don't know that that would actually do any good. And on the other hand, even if it somehow does protect you from cgers, TNT might take exception to your doing that and freeze you. Sounds like a lose/lose situation to me.
Fri Dec 15, 2006 1:21 pm
Fri Dec 15, 2006 6:03 pm
Fri Dec 15, 2006 6:52 pm