Pink Poogle Toy Forum

The official community of Pink Poogle Toy
Main Site
NeoDex
It is currently Wed Mar 19, 2025 12:37 am

All times are UTC




Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 82 posts ]  Go to page 1, 2, 3, 4, 5, 6  Next
Author Message
 Post subject: A Strange New Scam?
PostPosted: Thu Dec 29, 2005 2:09 am 
PPT Warrior
PPT Warrior
User avatar

Posts: 758
Joined: Sun Jun 13, 2004 12:51 pm
Location: Farther Away
COPIED FROM THE AVATAR BOARD:

Quote:
There have been hackers lately who discovered how to get around the -nojs- code on lookups and petpages and stuff, and they're putting CGs on them so even going on site now is dangerous.


Does anyone know if this is true?

If it is, they also posted some tips to stay safe, the most important one:

Quote:
Stay away from lookups, shops and petpages other than those of people you know and trust. From the word of the hackers (this guy called Kaos), who is pretty much the main hacker now - his username is drink_brawls, I think, (but don't look him up!) they are coming up with a CG that doesn't have a popup so you won't even know when it happens.


Just a thought.


Image


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 2:41 am 
PPT God
PPT God
User avatar

Posts: 1417
Joined: Tue Jun 01, 2004 12:03 am
Location: In a place called vertigo! :D
This was brought up on my guild's forums as well... It's making me nervous, I've decided to stay off of neo for the rest of the week, or until the all clear signal is given. :oops:


Image
Click here, click here! Don't be a c-c-c-combo breaker! :D
THANK YOU ZILARY. <3


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:01 am 
PPT God
PPT God
User avatar

Posts: 1114
Joined: Mon Oct 18, 2004 4:15 pm
Location: USA
Wow, that's freaky. Seeing as I only play games and stay away from things like Neoboards, I don't run into too many people I've never talked to. So I think I'll be safe.. hopefully. Hah. Thanks for the warning. :D


Image
Set by WIS


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:05 am 
Beyond Godly
Beyond Godly

Posts: 4819
Joined: Thu Jan 06, 2005 6:22 am
Location: Somewhere outside of reality
This has been a problem for many months - the username Kaos (and his many hacked accounts) has been on the Battledome Chat telling everyone who will listen what he is doing, apparently he has done severe damage to many accounts and TNT has tried to stop him but can't.

What he does is very real - 2 people I know have been affected by his cg's. Luckily both accounts were saved.

Main things to look out for - very cheap UB's. If you see an offer that is too good to be true than it is. This guy (group of guys) encourages people into there shops with really cheap items and set up CG's to steal your account.

There is a group of these "hackers" who have a website and encourage other people to join and learn how to set up these programs.

The Battledome Chat will often have posts about this person and what he is capable of.


As a sidenote: I know "hacking" is really the wrong phrase here, but as I am not into all the tech talk, I have no idea what else to call it. Some refer to it as "scripting" due to the scripts they write.


Last edited by Daze on Thu Dec 29, 2005 3:07 am, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:05 am 
Beyond Godly
Beyond Godly
User avatar

Posts: 2541
Joined: Mon Mar 07, 2005 10:50 am
Location: *bamf*
There are rumours that premium users in particular are being targetted. And if they've bypassed the nojs code then they can get your password without much effort at all :|

I didn't realise shops were no go areas too (though I should have) - thanks for the heads up.


Petpet Central


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:13 am 
PPT God
PPT God
User avatar

Posts: 1417
Joined: Tue Jun 01, 2004 12:03 am
Location: In a place called vertigo! :D
I heard about it on the Premium board that the guy put a grabber on a petpage, then tried to get people to view his "screenies."

How can someone be so low?! :roll:


Image
Click here, click here! Don't be a c-c-c-combo breaker! :D
THANK YOU ZILARY. <3


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:30 am 
PPT God
PPT God

Posts: 1247
Joined: Thu Sep 29, 2005 9:34 pm
Thats very scary. So basically theres code out there that will be able to grab your cookies just from you visiting the site? Is this a java thing, or you viewing a picture? And basically, any userlookup, petpage, and shop has the potential to have these cgs on them?


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:39 am 
Beyond Godly
Beyond Godly
User avatar

Posts: 2541
Joined: Mon Mar 07, 2005 10:50 am
Location: *bamf*
They've found a way to get around the no java script code that neo uses, so they can put their own java script on petpages, user lookups, pet lookups, shops etc. Basically, if they have bypassed the nojs code they can do whatever the hell they like - visit a page they've fixed up and wave goodbye to your account :S It's on the neo site so your browser, even firefox, has no problems handing over cookie info when requested - after all it's the originating site that is doing the requesting. Nasty.

Disabling javascript in your browser would protect you but it will make the game pretty unplayable... mind you it's pretty unplayable as it is anyway.


Petpet Central


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 3:53 am 
Newbie
Newbie
User avatar

Posts: 15
Joined: Wed Dec 28, 2005 9:28 am
Location: Sammamish, WA, USA, North America, Earth
Um, what's a CG? I've heard it stands for cookie grabber, but what is it, exactly?


-----
Image


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 4:04 am 
PPT Student
PPT Student
User avatar

Posts: 496
Joined: Sun May 15, 2005 12:30 am
Location: Australia
Internet sites place files in your browsers/computer called cookies. These hold all the info you've put into the site, in these cookies. Eg: Passwords.

Cookie Grabbers are a Trojan that can grab these cookies. So in short, they steal your passwords. The end.


Image
Set by stampsyne!


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 5:09 am 
PPT God
PPT God
User avatar

Posts: 1093
Joined: Tue Jul 27, 2004 8:47 pm
Yeah, this has been going on for quite awhile. I heard that this guy (or group of people, or whatever) is exploiting the -no js- bypass to screw up the site because TNT ignored him when he tried to tell them about it. I have no doubt that it's real, I was there on a thread when one girl put her account at risk to test it. The main hacker got into her account, moved some of her stuff around (points, sdb items), posted on the thread FROM her account, and then logged out of it. He didn't actually steal from her, which was good.

But yeah, be cautious everyone. I dunno, would virus protection block that sort of thing?


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 5:10 am 
PPT Warrior
PPT Warrior
User avatar

Posts: 758
Joined: Sun Jun 13, 2004 12:51 pm
Location: Farther Away
Ah, so it's been going on for a while now? I suppose most kinds of personal pages should be a no-go zone... we just all better watch out now. I doubt Neopets could fix this without shutting down the entire server for days and fixing the codes.

Unless this has been going on for a while and Neopets just simply doesn't care. But if it does, then how will we be able to do our shopping? Buy overpriced items each time so that we won't fall for some kind of a scam?


Image


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 5:40 am 
Beyond Godly
Beyond Godly
User avatar

Posts: 3041
Joined: Thu Jun 03, 2004 5:27 am
Location: at the late night science fiction picture show
I was on the site earlier and as usual went to lurk on the BD chat (you can find alot out on that board, plus many times have a good giggle when the 'regs' are being silly).

Apparently, it's this kaos person and someone else, name starts with an I and ends in numbers and is supposedly a girl. What they were saying on the BD chat (whether this is true or not) is that the I person (can't remember the name right now) is the one who actually made this thing, kaos is doing the collecting.

If you're asked to go to a lookup, petpage or someone posts that they have great things cheap in their shop, I'd be skeptical. Some people have gotten a pop-up and when they try to close it/backspace they got an error message. And that is that - your info is in their hands. However and whatever has been done ends with .cgi, so it seems to me that what needs doing is to simply stop that file extension from being able to be used.

I don't claim to understand this stuff, I'm totally non-technical. I have no idea how they created a pop-up and this cg.

Someone posted that they contacted TNT after last night's debacle and were told that they were allegedly d/l an autobuyer when they got cookie grabbed. Whether this is part of this whole thing or not, I don't know.

I wouldn't have known anything, seeing as I was briefly on the site last night and didn't go to any chat besides charter

And yes, apparently Premiums are being targeted along with BD'ers ... which is even more troubling since if they get that info, there's nothing to stop them from getting into your premium info meaning your personal/credit info.

All in all it's a mess. kaos posted on an account a little while back boasting that TNT had gone beyond IP ban to something even higher and stricter and that it took him about an hour to "crack" it. This needs to be stopped. I worry about our neo accounts, yes. I also worry about what else this person or persons are up to. Nothing would make me happier that to see on the news that such and such group of people were arrested for computer hacking/identity theft.

BTW, just so you all know, disabling javascript is against the rules on Neo. It's, for some reason, considered an unfair advantage.


Image Image


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 7:08 am 
PPT Student
PPT Student
User avatar

Posts: 404
Joined: Sun Sep 11, 2005 8:56 am
Location: in paintball gear on a DDR Pad
Wow I never knew about this scam till now. :o Seems like you can't do anything on Neopets these days for fear of getting scammed somehow. What defense do we have against this if any, since disabling javascript is out of the question?


Image
Awesome Set by DM!! :D

:) Neo44392 on Neopets^_^ Neomail me for neopets premium invites :)


Top
 Profile  
 
 Post subject:
PostPosted: Thu Dec 29, 2005 7:48 am 
PPT Trainee
PPT Trainee
User avatar

Posts: 507
Joined: Sat Oct 23, 2004 11:10 am
Well, for people still using IE, there's a recent exploit that lets anyone take over your computer completely just by having you view a page... They could be using that, or they could be not using it. In any case, Firefox isn't affected (but if you get a download box you didn't request yourself, don't download it, because then you will be vunerable).

If anyone can link me to an unfrozen account that supposedly has this, I can (safely, since I know what I'm doing :)) deconstruct it and give a better idea of what's going on to everyone. I can't seem to find any real information on the neoboards (figures).


Nabile pwns you...

            ...At Lenny Connundrum.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 82 posts ]  Go to page 1, 2, 3, 4, 5, 6  Next

All times are UTC


Who is online

Users browsing this forum: No registered users and 51 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group