Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: About Cookie Grabbers

  1. #1
    tiramisu's Avatar
    Joined
    Jan 2014
    Posts
    88
    Userbars
    1
    Thanks
    49
    Thanked
    70/24
    DL/UL
    2/0
    Mentioned
    2 times
    Time Online
    3d 11h 19m
    Avg. Time Online
    1m

    About Cookie Grabbers

    In my many years of playing Neo I've never found any of my accounts hacked, even though I frequently visit user shops/petpages/etc. Still, if people say there's a real security issue, I'd like to take it into account.

    What bugs me is that usually when CGs are mentioned it's in the form of mass hysteria, with people having no idea what's happening. I was hoping that some people on here would be able to shed some light on the issue Here are some questions I have:

    1. How likely is CGing to happen on Neo at the moment (shops, lokups, petpages, boards)? I've seen a ton of cleared shop descriptions and "-blocked-" elements in the source, and it seems to me that with the current sensitive filtering it would be hard to pull off.

    2. Would CGing on Neo require clicking a link, or is automatic CGing currently possible?

    3. What are the most common indicators of a modern CG in a source code?

    I'm sorry if there's an up-to-date guide to this somewhere, I was unable to find one, and thank you for any input you may have

  2. The Following 2 Users Say Thank You to tiramisu For This Useful Post:

    Corliss (08-22-2019),Sakuras (06-23-2019)

  3. #2
    Meepit's Avatar
    Joined
    Mar 2014
    Posts
    1,937
    Userbars
    18
    Thanks
    8,173
    Thanked
    4,562/980
    DL/UL
    31/0
    Mentioned
    69 times
    Time Online
    58d 19h 39m
    Avg. Time Online
    22m
    Seems very unlikely,
    Most of what i've ever read here says that kinda stuff is patched out. A lot of the "hacks" are from an old ass website breach that people never updated their info after, but its easier to blame cgers instead of their own stupidity.
    Taking actives is frowned upon here so not likely anyone would share if there was one actively being used.
    A lot of cleared shop descriptions had old crap the website would block now. I have run into shops with peoples usernames from messengers and stuff too so they could have been cleared for a lot of random stuff that isn't harmful at all. Dunno about the automatic thing, but there are people who know way more than I ever will.

  4. #3

    Joined
    Jul 2012
    Posts
    1,888
    Thanks
    1,619
    Thanked
    3,297/1,003
    DL/UL
    223/0
    Mentioned
    469 times
    Time Online
    132d 23h 52m
    Avg. Time Online
    45m
    Quote Originally Posted by tiramisu View Post
    In my many years of playing Neo I've never found any of my accounts hacked, even though I frequently visit user shops/petpages/etc. Still, if people say there's a real security issue, I'd like to take it into account.

    What bugs me is that usually when CGs are mentioned it's in the form of mass hysteria, with people having no idea what's happening. I was hoping that some people on here would be able to shed some light on the issue Here are some questions I have:

    1. How likely is CGing to happen on Neo at the moment (shops, lokups, petpages, boards)? I've seen a ton of cleared shop descriptions and "-blocked-" elements in the source, and it seems to me that with the current sensitive filtering it would be hard to pull off.

    2. Would CGing on Neo require clicking a link, or is automatic CGing currently possible?

    3. What are the most common indicators of a modern CG in a source code?

    I'm sorry if there's an up-to-date guide to this somewhere, I was unable to find one, and thank you for any input you may have
    1 unlikely
    2 automatically
    3 javascript getting document.cookie

  5. #4
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,685/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    1. It's not likely to happen from within the site itself, on any page. The cleared shop descriptions nowadays are often just the word filter catching up with the latest slang for derogatory words, or the result of somebody having their shop reported for whatever reason. The Neopets server subjects all board, lookup, pet page and shop input type="text", select and textarea fields to a filtering routine which removes JavaScript. This prevents users from executing scripts which could hijack your cookies.

    Unless someone has copied your cookies from your browser's local database, captured your traffic as you browse, or installed an extension or script-injector, then your cookies are safe.
    2. (you need an account to see links) by clicking a link would only be possible if that link could be manipulated to execute code through a JavaScript event. (you need an account to see links) for a user's personal information by tricking them into manually entering their username and password is often associated with clicking a link, which will cause you to navigate to a site that is often disguised to look like the login page of the site you came from. A user may mistake that page as genuine and provide their credentials, resulting in their username and password being stolen.
    3. You'd want to look out for any code which is accessing the document.cookie object, then attempting to send that string off-site via an iframe request or postback, WebRTC, WebSocket or XMLHttpRequest. UserScripts can also use GM.xmlHttpRequest or GM_xmlhttpRequest to send data as well.

    The trouble with detecting when code is stealing cookies is that a smart developer will (you need an account to see links) their code, which makes it difficult to decipher what it's doing. Furthermore, almost all of the methods mentioned above are used on the Neopets site in some capacity, either by the site itself, or the advertiser content you see as you browse. Attempting to manually identify the good from the bad will be a tedious task.

  6. The Following 14 Users Say Thank You to Bat For This Useful Post:

    Achyfi (08-21-2019),Autobot (06-24-2019),Botan (06-24-2019),Cinnamoroll (06-23-2019),Delibird (06-23-2019),Meepit (06-23-2019),mugi (06-23-2019),Pearl (08-22-2019),Pinecone (06-24-2019),Sakuras (06-23-2019),Sugar Rush (06-23-2019),tiramisu (06-24-2019),vocaloid (06-23-2019),Witch (06-23-2019)

  7. #5

    Joined
    Dec 2016
    Posts
    2,275
    Thanks
    3,850
    Thanked
    9,573/1,609
    DL/UL
    17/0
    Mentioned
    306 times
    Time Online
    134d 4h 41m
    Avg. Time Online
    1h 11m
    People like to blame �CG� when they don�t understand what�s going on or fear losing something.

    The PC yells our CGer like Trump yells out �fake news�.

    I don�t think CGing has been a thing on neopets for years, but people still like to call it out.

  8. The Following 7 Users Say Thank You to motherfucker For This Useful Post:

    Brickhaus (06-24-2019),Cinnamoroll (06-23-2019),Delibird (06-23-2019),♥ PrettySarcastic ♥ (06-23-2019),Sakuras (06-23-2019),Sugar Rush (06-23-2019),Woodpecker (08-21-2019)

  9. #6
    Guil's Avatar
    Joined
    Sep 2013
    Posts
    1,144
    Pronouns
    she/her
    Userbars
    54
    Thanks
    2,722
    Thanked
    5,175/1,092
    Mentioned
    174 times
    Time Online
    41d 11h 34m
    Avg. Time Online
    15m
    During the last CG i was aware of the telltale sign was on pet lookups, the pet flash image box appreared on the lookups twice. thats all i really know about them lol


    custom userbars by @lyrichord (argyle) and @charmander (guilmon ryu)! thank you so much!


    "My name isn't Rob, but I'm Robbing"
    -Thieves 2020



    @guil and @delibird


    userbar by @charmander and art by @dankruse !

  10. #7
    GeorgieLiquor's Avatar
    Joined
    Jun 2019
    Posts
    52
    Userbars
    1
    Thanks
    17
    Thanked
    51/21
    DL/UL
    6/0
    Mentioned
    Never
    Time Online
    1d 6h 30m
    Avg. Time Online
    1m
    I got both of my old accounts grabbed, but oddly enough, doesn't seem like they took anything. They fucked with my emails a bit though. It wasn't any thing super malicious or active, I just hadn't played in years and didn't change passwords after the breach.

  11. #8
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,685/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    Quote Originally Posted by GeorgieLiquor View Post
    I got both of my old accounts grabbed
    Having your cookies "grabbed" isn't a generalized term for having an account stolen. It's a specific technique used wherein the target's Neopets cookies are copied from their browser in order to be used by someone else. It allows the person who "grabbed" the cookies to use the victim's account without having to log in for a time. The breach was simply a mass harvesting of Neopets user credentials. Nothing as nefarious as target cookie grabbing.

  12. The Following 3 Users Say Thank You to Bat For This Useful Post:

    Botan (06-24-2019),Delibird (06-23-2019),Pinecone (06-24-2019)

  13. #9
    GeorgieLiquor's Avatar
    Joined
    Jun 2019
    Posts
    52
    Userbars
    1
    Thanks
    17
    Thanked
    51/21
    DL/UL
    6/0
    Mentioned
    Never
    Time Online
    1d 6h 30m
    Avg. Time Online
    1m
    Quote Originally Posted by Odd View Post
    Having your cookies "grabbed" isn't a generalized term for having an account stolen. It's a specific technique used wherein the target's Neopets cookies are copied from their browser in order to be used by someone else. It allows the person who "grabbed" the cookies to use the victim's account without having to log in for a time. The breach was simply a mass harvesting of Neopets user credentials. Nothing as nefarious as target cookie grabbing.
    Got it. Sometimes the terminology here is a bit hard for me to grasp, since some of it is NP related and then some of it is programming or coding related.

    How do people even manage to grab cookies from others?

  14. #10
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,685/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    Quote Originally Posted by GeorgieLiquor View Post
    How do people even manage to grab cookies from others?
    I described how cookies can are grabbed (you need an account to see links), in answer 1 to the thread owner's question.

  15. The Following User Says Thank You to Bat For This Useful Post:

    Delibird (06-23-2019)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •