Cookie grabbers again?

For Neopets ONLY discussion.

Moderator: Moderators

Locked
Message
Author
Cranberry
Beyond Godly
Beyond Godly
Posts: 2743
Joined: Mon May 31, 2004 3:55 pm
Location: PEI, Canada

Cookie grabbers again?

#1 Post by Cranberry »

The battledome chat board at Neo and people at the IDB forums are saying there's a bad security problem right now and people are able to use cookie grabbers in neomail. I'm not positive this is true (haven't heard much yet, as night-time at Neo is rather slow), but I'd recommend changing your preferences so only neofriends can contact you, just to be safe. Apparently just reading the neomail is enough to get grabbed. And anyone who has more details, post here!

Edit: I found a post from someone who got frozen:

My account was iced because the security of it had been compromised. It appears to have been because of a CG through neomail. I'm not terribly sure.

I was warned that someone had been in my account via a messenger program. When the script ran and found that a suspicious IP had been in my account they froze it for my protection. That is what happened for sure. How they got in is still sketchy, but the most probable explanation is a cg'er.


And apparently others are receiving neomails with lines of code in them, but no one would post the code, so I dunno.

So... not sure whether this is all hysteria due to that one guy getting frozen + the code neomails, or a legitimate threat.
Image
danelkayam
PPT Baby
PPT Baby
Posts: 80
Joined: Wed Aug 24, 2005 2:47 am

#2 Post by danelkayam »

Well, it would be interesting to see how they would get javascript running in a neomail and actually getting the cookie past all of Neopet's firewalls to the sender.
Cranberry
Beyond Godly
Beyond Godly
Posts: 2743
Joined: Mon May 31, 2004 3:55 pm
Location: PEI, Canada

#3 Post by Cranberry »

Yeah, I'm thinking it's probably typical neoboard hysteria. One guy gets frozen, he happened to have received a neomail with some gibberish in it, and that equals OMGCOOKIEGRABBER! We'll see.
Image
mogster500
PPT Trainee
PPT Trainee
Posts: 653
Joined: Wed Mar 30, 2005 5:51 pm

#4 Post by mogster500 »

Just choose to recieve only Plain Text Neomail, you won't have any problems if it is true.
Image
es.dee
PPT Toddler
PPT Toddler
Posts: 220
Joined: Thu Jun 08, 2006 4:07 pm

#5 Post by es.dee »

I doubt it's true.

But if it was, it's no big deal.. I don't bother with neomails much anyway.
Image
User avatar
Siniri
Way Beyond Godly
Way Beyond Godly
Posts: 9769
Joined: Sat Apr 22, 2006 2:32 pm
Location: Georgia

#6 Post by Siniri »

mogster500 wrote:Just choose to recieve only Plain Text Neomail, you won't have any problems if it is true.


Err... I just tried to do this, but I couldn't seem to figure out where it was. However, aren't all neomails plain text? At least the ones I've gotten are (even the scam website one I got yesterday)... Unless my settings are already on plain text... o_O
stampsyne
Beyond Godly
Beyond Godly
Posts: 4593
Joined: Wed Aug 25, 2004 8:55 pm
Location: Oregon Outback

#7 Post by stampsyne »

Hcnage to plain text under

Help => Site Preferences

Check the 8th box down ;)
Image Image Image
User avatar
Siniri
Way Beyond Godly
Way Beyond Godly
Posts: 9769
Joined: Sat Apr 22, 2006 2:32 pm
Location: Georgia

#8 Post by Siniri »

stampsyne wrote:Hcnage to plain text under

Help => Site Preferences

Check the 8th box down ;)


Thanks! I was looking under neomail and user preferences on the neoboards main page...
SierraRaven
PPT Trainee
PPT Trainee
Posts: 511
Joined: Wed Jun 16, 2004 9:55 pm
Location: Deep in the Forest

#9 Post by SierraRaven »

If the account was accessed thru a messenger program, it sounds like somebody picked up a malicious payload while using an IM. All the IM programs are experiencing attacks lately, including AIM, MSN Messenger, and Yahoo...
Looking to buy Snowbunny Stamp and Sticky Snowflake Stamp. If you're selling, please PM me!
Katherine
PPT God
PPT God
Posts: 1649
Joined: Thu Jan 05, 2006 4:11 pm
Location: At a Rascal Flatts Concert
Contact:

#10 Post by Katherine »

SierraRaven wrote:If the account was accessed thru a messenger program, it sounds like somebody picked up a malicious payload while using an IM. All the IM programs are experiencing attacks lately, including AIM, MSN Messenger, and Yahoo...
I think that seems more likely.
Image
Set by the amazing Kitten Medli.
Wanna see some of my writing? Click here!
BeDeviled
PPT God
PPT God
Posts: 1723
Joined: Tue Jun 01, 2004 5:30 pm

#11 Post by BeDeviled »

kcharles wrote:
SierraRaven wrote:If the account was accessed thru a messenger program, it sounds like somebody picked up a malicious payload while using an IM. All the IM programs are experiencing attacks lately, including AIM, MSN Messenger, and Yahoo...
I think that seems more likely.


That or other sites that you might think should be safe, I was image searching for a friend 4 days ago and yep, got cookie grabbed. Miraculously I didn't lose anything permanent. They did get most of my email programs that are associated with 3 of my websites, got into my gmail and hotmail accounts. Also got into my yahoo account. Who ever it was is very persisitant since I keep getting reset your password links in my hotmail.
Teelie
PPT Student
PPT Student
Posts: 384
Joined: Sun Jun 04, 2006 5:16 pm

#12 Post by Teelie »

Sounds like paranoia to me. I was messing with my user look up last night and a bit of the code was off (a missing } bracket) and the error page told me about the security features to prevent that very kind of thing.

Still, if you're worried, disable neomails from non-friends. I rarely ever get them so I don't even worry about it.
The_Real_Demi
Newbie
Newbie
Posts: 11
Joined: Sat Jun 10, 2006 8:01 am
Contact:

#13 Post by The_Real_Demi »

I wouldn't really believe this considering neopets has a large ammount of firewalls and protection but you would also need to use special codes and as far as I know they won't even work on neopets.
Keylia
PPT Student
PPT Student
Posts: 302
Joined: Fri May 12, 2006 4:44 pm

#14 Post by Keylia »

Better safe than sorry, right?

I'd rather have plain text and avoid opening mail from strangers than lose my account.
Last edited by Keylia on Sat Jun 10, 2006 6:16 am, edited 1 time in total.
Image
Cranberry
Beyond Godly
Beyond Godly
Posts: 2743
Joined: Mon May 31, 2004 3:55 pm
Location: PEI, Canada

#15 Post by Cranberry »

The_Real_Demi wrote:I wouldn't really believe this considering neopets has a large ammount of firewalls and protection but you would also need to use special codes and as far as I know they won't even work on neopets.


Hehe, clearly you weren't here for the last cookie-grabber fiasco where people were putting them on userlookups and in shops and getting into all kinds of people's accounts. ;)

I agree that this time it sounds like paranoia, however. I haven't heard anything new since my original post.
Image
Locked