AySz88 wrote:
Matt wrote:
What I don't understand is... How the hell can things like this even affect the Neopets site. The cookie grabber comes along, and surely (if Neopets has any sense) it will grab a hashed password; not a password. And surely (again, if Neopets has any sense), their hash will be unbreakable, and therefore, you should just have to brute force it for any collisions, hich will take as long as just brute forcing the entire password anyway...
You can probably still masquerade as the user by planting the cookie on your own computer. I'm sure the Neopets server doesn't remember users based on IP......there's no way to query MAC address right?
Also, I think I heard that it's possible to store all hash possibilities of a 7-letter password into a hard drive and break it. A quick calculation with (26^7*8 / 2^30) produces searching through something like 60 GB - certainly not impossible to do.
I doubt the cookie contains a hash of just the password though - they probaby hash something like username-date-time-randomintegers and store that into the cookie and a their own local database.
Apparently, for whatever reasons, the Neo cookies may or may not be "hashed", as someone claiming to be this kaos character said that a very famous neopian's "hash" was too long to try to break. That said, I don't know if that's something on Neo's end or the user (somehow).
BTW, if you just go to the site, don't log in even, then go look at the cookie, your IP addy IS there in the first line and again later in amongst all the other I don't know what they mean numbers. And it's been proven that Neo can and does track IP addresses. And the username is in the cookie if you log in. Now I did log in briefly on a side account - I cleared cookies after but not temporary internet. There's ALOT of xml and jscript stuff that I'm going to guess someone with the knowledge "might" be able to manipulate. I can't tell what's ads and what could be malicious - which most users wouldn't except for the obvious adcom, servedby, etc. I don't know what jsl.revsci.net is, but it's a JScript and crossdomain is an xml file. I'm soooo non-technical.
I don't know, there were boards earlier saying something about people somehow using "quick links" to peoples' SDB. If you go to your SDB on your own, you're fine. But (I don't get this at all) if you followed a link from a lookup, board, etc. saying it was a shortcut it somehow ended up being a CG via an iframe. Something like that. I was totally lost on the whole thing.
People are saying that Neo should just clear everything that can be personalized - lookups, petpages, pet descriptions, shops, galleries. That seems extreme, IMHO. I thought in order to plant a cg, the extension had to be .cgi and that would be easily banned. And according to a staff member, the cgs last week were disabled.
But as I was lurking on a couple of boards earlier I saw some really bizarre posts from older accounts and the person posting claiming that they'd hacked the accounts. Something needs doing. Accounts are being compromised, apparently without ever leaving the site. Premium members have been hacked and their personal info taken and compromised. It's quite sad that many of us are now afraid to go to a lookup, a petpage or even a user shop and some are madly changing passwords at least once a day.
All I know is IE and FF are affected, going by the posts I've read. The Microsoft fix apparently had nothing to do with whatever's going on on the site.
Bottom line ... as with all other glitches and problems, don't expect TNT to put anything in the news or anywhere else. Maybe a reminder to change your password regularly like after the weekend of 4/4 - which took them how long to post? Otherwise, they'll stand by their claim that the site's never been hacked and if anything happens to your account it's your problem, not theirs.