Pink Poogle Toy Forum

The official community of Pink Poogle Toy
Main Site
NeoDex
It is currently Thu Mar 13, 2025 4:01 pm

All times are UTC




Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 37 posts ]  Go to page Previous  1, 2, 3
Author Message
 Post subject:
PostPosted: Fri Jan 20, 2006 1:50 pm 
Administrator
Administrator
User avatar

Posts: 1140
Joined: Mon May 31, 2004 1:36 pm
the_dog_god wrote:
Cookies are your password. They're the stored version of that password which is logged onto your computer. By taking your cookies, they're taking your password.

ArwenEarendil wrote:
Cookies store your password... yes.

But in MD5. You'll need a decoder to actually get your password.


The technicality here is that cookies are not linked to your password. Cookies, more often than not, store a random token that authentifies that you are who you say you are. If you lose/duplicate the token, you only comprise the current session (which should be revokable or locked to your IP / Browser anyway), rather than the ability to create new sessions (hence it's useful to have a password-prompt on important pages of the website -- for example, account details).

Simple analogy: Suppose your password is "password". You then log-in to the server using the password (checked against the stored version in their database) -- if you pass the check, the server generates a random token to give you in a cookie: "apples", for example. Now, each time you talk to the server, you include your session key: "apples", and not your password ("password").
Now, suppose got a copy of your cookie -- only the currently active session is compromised, not your password. In other words, should the session be terminated (or verified using the user-agent tag of the browser you're using, or the IP you're accessing the site from), whoever stole the cookie can not access your account or get a new session, since your password ("password") is not compromised.



Speaking of MD5: reversal databases do exist -- and chances are you can get the MD5 hash of common words reversed pretty easily. And since no hashing algorythm is collision-free, you don't even have to get the right password -- as long as it fits the hash, you've won.


Image
Will you stop with the honour stuff?


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jan 20, 2006 4:31 pm 
PPT Trainee
PPT Trainee
User avatar

Posts: 507
Joined: Sat Oct 23, 2004 11:10 am
ArwenEarendil wrote:
Cookies store your password... yes.

But in MD5. You'll need a decoder to actually get your password.


No.

Neopets' passwords are based on you password, and yes encoded with MD5*. But the entire point of MD5 is that it's IMPOSSIBLE to go in the reverse direction. You CANNOT figure out a password from the cookie. End of story.

If you want more information, here. If the cookie were only an MD5 hash of the password, then you could do what's called a brute force attack: you could make a list of all the possible passwords, and find all their MD5 hashes, and try to find one that matched. But that won't work with neopets cookies, since what's being stored there is more than just your password. I'd hazard a guess it involves some timing data based on when you last changed it, and also some random data. To brute force this would be physically impossible. Computers are not fast enough.

* Or possibly some other similar algorithm.


Hunter Lupe wrote:
The technicality here is that cookies are not linked to your password. Cookies, more often than not, store a random token that authentifies that you are who you say you are.


It can be done that way, but that's not how it is here.


(edited twice to clarify things)


Nabile pwns you...

            ...At Lenny Connundrum.


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jan 20, 2006 9:10 pm 
Beyond Godly
Beyond Godly
User avatar

Posts: 2743
Joined: Mon May 31, 2004 3:55 pm
Location: PEI, Canada
Gender: Female
I think these last few posts show why a lot of people who were spreading info about this "hacker" on the neoboards and petpages were warned: they may be sure they know what they're talking about, but be mistaken. It makes sense that TNT wouldn't want any non-team member "educating" the masses on Neopets messageboards when they don't have the full story.


Image


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jan 20, 2006 10:27 pm 
PPT Toddler
PPT Toddler

Posts: 146
Joined: Wed Dec 22, 2004 2:36 pm
Location: Neopia
Cranberry wrote:
I think these last few posts show why a lot of people who were spreading info about this "hacker" on the neoboards and petpages were warned: they may be sure they know what they're talking about, but be mistaken. It makes sense that TNT wouldn't want any non-team member "educating" the masses on Neopets messageboards when they don't have the full story.



That's a great point, Cranberry. Still, I think it'd be best if they just addressed it in the news features, with an explanation and advice...


My Little Corner of Neopia


Top
 Profile  
 
 Post subject:
PostPosted: Fri Jan 20, 2006 11:23 pm 
Beyond Godly
Beyond Godly
User avatar

Posts: 2743
Joined: Mon May 31, 2004 3:55 pm
Location: PEI, Canada
Gender: Female
I never disputed that. It's not an either/or situation here -- it's not "either they let uninformed people spread incomplete info on the neoboards, or they post something in the news." Yes, they should definitely let us know something was wrong and has now been fixed, but that's a separate issue from the topic of this thread, which is them warning people and clearing petpages. All I said in my posts was that this behavior is understandable, from a business and safety perspective.


Image


Top
 Profile  
 
 Post subject:
PostPosted: Sat Jan 21, 2006 1:29 am 
PPT Warrior
PPT Warrior
User avatar

Posts: 765
Joined: Thu Jun 17, 2004 1:28 pm
Location: Among the crayons on my desk..
DOH. Why'd I put that?! Sorry. =P

Hunter Lupe and dolphinling.. greatest apologies.

I blame it for the post at 4:16 AM, but that's no excuse.

So everyone.. disregard previous post.

(Of course, this goes hand in hand when I originally thought it was encoded in SHA1)


Image
. Set by Medusa ♥


Top
 Profile  
 
 Post subject:
PostPosted: Sat Jan 21, 2006 5:01 am 
PPT Toddler
PPT Toddler
User avatar

Posts: 129
Joined: Thu Aug 04, 2005 9:44 pm
So is the whole cookie grabber fiasco thingover yet. I need to rs.


Image Always believe in hope Image


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 37 posts ]  Go to page Previous  1, 2, 3

All times are UTC


Who is online

Users browsing this forum: No registered users and 118 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group