Raza wrote:
A cookie grabber is a bit of code in a webpage that uploads your neopets cookie (a cookie is the small file that websites send you to remember personal info, like settings and saved login info) to their server, ie 'grabs' it. The best way to stop it happening is to not visit neopets related sites that aren't either on neopets or some well known fansite like PPT. Or alternatively, you could browse neopets with a seperate browser entirely and not log in with the browser you do everything else with, so the cookie for neopets simply wouldn't exist when your browser is ordered to grab it.
No. Wrong. A cookie grabber can
only work
from neopets.com. Someone has to find a way to put their own code on the neopets website, because other sites
cannot look at your neopets cookies. *
everconfused"It doesn't matter what browser you're using, people have been cg'ed with javascript disabled, and every other security thing they can think of (much smarter about this stuff than I'll ever be!).[/quote]
No, you cannot be cookie grabbed with javascript disabled. There are only two ways for someone to look at your cookies:
1) Your browser sends them to the web server. For someone to look at them this way, they'd have to have access to Neopets' logs, which they don't.
2) A page on the same site can look at them through javascript. This means someone has to figure out a way to get javascript on a page somewhere. If you have javascript disabled. though, it won't work.
[quote="everconfused wrote:
... some of the cg'ers were redirecting people to a blank page, then back to Neo in a few seconds. So, again, it's not a matter of you voluntarily leaving the site and going to another, unsafe site. This is done to you, not by you.
Right. And in fact, they were only making you leave the site in the first place because they were stupid. It's perfectly easy to make it so there's no indication at all that you've been cged.
everconfused wrote:
Yes, you can get grabbed by going to unsafe sites
I've said it already but I want to really make it sink in: No, you CAN'T.
everconfused wrote:
Neo instituted the HTML filter check to help stop this stuff. Now, a question is does/can the filter work if someone hasn't tried to change or update a page? Current consensus of some users is No, obviously the filter can't do anything if information is already on a page.
It could, but it doesn't. It would be perfectly easy for them to run the filter on all pages that already exist, but that would break old pages even if they weren't evil. (One of my petpages was that way, in fact.) They did, however, do other stuff to make sure there was no evil stuff that was already there, so any pages made before the new filter will be safe.
everconfused wrote:
Does that mean, even with the new filter that cg can't be put on a page? Probably not, given that some people seem to have nothing better to do with their time than think up ways to steal from others.
Actually, the current filter should be able to protect against any new attempts very well. In the old filter, something they didn't even know about could be a problem. In the new filter, anything they don't know about is automatically blocked, and they have to have actually made a mistake with something they
did know about for there to be a problem. So if there are any, there will be much fewer, and they will be much much harder to find.
The places where something might be found now are places that
don't have the new filter system. Think of the original CG place: the SDB search form. Those still
might have problems (none that are known now, though). The good thing about those, though, is that you can't be CGed by just going there, you have to click on a specific link. So to be careful, just look at a link before you click it, and if it looks suspicious, don't click it.
* The exception here is if you have a security hole in your web browser. That's why you should
always keep your browser up to date. The current version of Firefox is 1.5.0.3. If you don't have it already,
get it.
Nabile pwns you...
...At Lenny Connundrum.