Results 1 to 8 of 8

Thread: Cookie Grabbed?

  1. #1
    ribossoma's Avatar
    Joined
    Apr 2013
    Posts
    332
    Userbars
    22
    Thanks
    177
    Thanked
    259/115
    DL/UL
    115/0
    Mentioned
    68 times
    Time Online
    58d 5h 51m
    Avg. Time Online
    20m

    Cookie Grabbed?

    So I was browsing neopets with around 500k neopoints on hand. I change tabs and start reading an article a friend sent me, which took me a couple minutes to finish.

    When I moved back into the neopets tab, I tried to go to the boards but couldn't because I was logged out. I logged in just to find out my 500k were missing and my trades cancelled (items were still in the inventory, just not on the trading post).

    I'm not sure this was some bug/glitch/whatever or if someone broke into my account. If it was indeed someone I guess I interrupted their business because the neopoints in the bank, my weapons and the sdb seem to be untouched.

    Oddly enough, my cK account also got logged out. I was writting a PM (I tend to write them and only send them after a while, I'm weird like that) and when I tried to send it, it failed because I wasn't logged in. This was what made me think of cookie grabbing.

    Changed my password, set PIN on all areas neopets let us and logged out and logged in again.

    UPDATE: After writing this and before hitting "Submit New Thread" I tried to go on neopets again and was logged out again. Failed to log in so logged in on a side to check if my account was frozen - it is. Probably just for protection but I'm still curious about what just happened.

  2. #2

    Joined
    Jan 2012
    Posts
    1,286
    Thanks
    1,292
    Thanked
    302/209
    DL/UL
    1096/0
    Mentioned
    213 times
    Time Online
    59d 13h 45m
    Avg. Time Online
    20m
    change your password... just to be safe. and clear your cookies.

  3. #3
    TRENDSETTERASSBAG Maison's Avatar
    Joined
    Oct 2012
    Posts
    1,678
    Userbars
    7
    Thanks
    1,918
    Thanked
    1,140/611
    DL/UL
    12/1
    Mentioned
    320 times
    Time Online
    95d 4h 15m
    Avg. Time Online
    32m
    omg that is so sad D: People are still doing these things!!!

    Clear your cache!

    ---------- Post added at 11:38 PM ---------- Previous post was at 11:37 PM ----------

    I MEAN COOKIES

  4. #4

    Joined
    Mar 2014
    Posts
    1,387
    Thanks
    1,217
    Thanked
    3,913/1,165
    DL/UL
    84/1
    Mentioned
    533 times
    Time Online
    134d 9h 16m
    Avg. Time Online
    52m
    That's really odd.

    I'd assume someone got in and started the raiding process, got kicked out when you got back in, they logged back in before you could change the PW, and then self iced the account before the PW change registered in the DB?

    That's definitely odd as hell.

  5. #5
    Bowsette's Avatar
    Joined
    Oct 2013
    Posts
    3,479
    Userbars
    28
    Thanks
    1,225
    Thanked
    1,640/969
    DL/UL
    109/0
    Mentioned
    465 times
    Time Online
    312d 17h 55m
    Avg. Time Online
    1h 57m
    That's really weird :/

  6. #6
    Bettser's Avatar
    Joined
    Feb 2012
    Posts
    6,027
    Userbars
    30
    Thanks
    1,791
    Thanked
    3,790/1,690
    DL/UL
    41/0
    Mentioned
    1,446 times
    Time Online
    368d 17h 50m
    Avg. Time Online
    2h 6m
    Do you post on the boards by any chance or were the items in your trades intense?

    Someone attempt to steal my account a couple days ago but were unable to due to my monthly pin change tendacies ;D

  7. The Following User Says Thank You to Bettser For This Useful Post:

    cloudxcrash (01-04-2016)

  8. #7

    Joined
    Dec 2011
    Posts
    95
    Userbars
    4
    Thanks
    161
    Thanked
    172/63
    DL/UL
    32/3
    Mentioned
    87 times
    Time Online
    17d 12h 5m
    Avg. Time Online
    5m
    How do you usually log in to clraik? did you tick the 'remember me' when you logged in to cK? because if you didn't you might probably got automatically logged out after a certain period of time.

  9. #8
    ribossoma's Avatar
    Joined
    Apr 2013
    Posts
    332
    Userbars
    22
    Thanks
    177
    Thanked
    259/115
    DL/UL
    115/0
    Mentioned
    68 times
    Time Online
    58d 5h 51m
    Avg. Time Online
    20m
    Quote Originally Posted by Mophead View Post
    That's really odd.

    I'd assume someone got in and started the raiding process, got kicked out when you got back in, they logged back in before you could change the PW, and then self iced the account before the PW change registered in the DB?

    That's definitely odd as hell.
    I think I read somewhere that logging out and logging in again renders the stolen cookies session useless, so they couldn't go back in again after I changed my password, right? Because I logged out and in right after that. Only if they somehow managed to extract the password from the cookie (I don't even know if that's possible, just brainstorming xD).

    I'm excluding that they guessed my password because it wasn't an easy one. I mean, it was the producer code of a random grocery store bought egg 12 random numbers and letters, some capped, some not. Probably should have added a symbol, but I don't think brute force works on neopets so didn't bother.

    Quote Originally Posted by Bettser View Post
    Do you post on the boards by any chance or were the items in your trades intense?

    Someone attempt to steal my account a couple days ago but were unable to due to my monthly pin change tendacies ;D
    I do, but rarely. Only on a couple lending boards and that "avatars pet in the pound" board. And no, not really. The most expensive one was a ~2 mil stamp.

    I also change the pin pretty often, only had this one for like 2/3 weeks :/


    Quote Originally Posted by damian002 View Post
    How do you usually log in to clraik? did you tick the 'remember me' when you logged in to cK? because if you didn't you might probably got automatically logged out after a certain period of time.
    I usually tick it. Could've forgot this time though, yeah

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •