[SECURITY] Minimizing Neopets Cookie Grabbers (CGers)


210 replies [Last post]
[Report this topic]
User stealth. Stealth!
Joined: 10/06/2007
Posts: 4543
Rank: Admin

It appears that alot of people are getting Cookie grabbed recently so I figured this thread might help reduce it.
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other crap (like CGs) See attachment for more info

BLOCKSITE - this prevents certain websites from loading completely so if you were unfortunate to click on a CG site by accident, it wont load. Not supported for firefox 3.5 Subscription service for this add-on will be added on neomallers as soon as support is added.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

As for neomallers, everything is auto blocked which is why you guys can only use boring black text (no fancy colors, etc) and it also explains why some online parts of this site are so strict in terms of what you can type in :P If you're worried, you can also block scripts and flash on neomallers but keep in mind that the other_counters page may not work properly since it uses javascript to confirm whether or not you plan to delete the counter, etc If anyone has any other tips (or corrections to this post) , feel free to post

P.S. For those of you wondering, this post is an exception. I temporarily disabled filters for this particular post only.

NeoMallers Anti-CG Adblock Service
NeoMallers now runs its own adblock subscription service. To enable this, follow the steps:
1. Click Tools. Then add-ons. Select Options on Adblock.
2. Click Filters Menu. Select Add Subscription. Click the button Add a different subscription at the bottom.
3. Type in NeoMallers in the firstbox and http://cookiejar.neomallers.com/newbs.txt in the second box
4. Click subscribe. Whenever you need to update (it should do it automatically as well), right click NeoMallers and choose update.

 

AttachmentSize
whitelist-neopets.gif74.73 KB
ablock-instructions.gif43.8 KB
User stealth. Stealth!
Joined: 10/06/2007
Posts: 4543
Rank: Admin

To block neopets ads, follow the instructions here:
http://www.neopets.com/~saudor#adblock

Pip
User offline. Last seen 7 hours 38 min ago. Offline
Joined: 19/02/2009
Posts: 843
Rank: NT Archivist

Thanks for the heads up Dmitri! Very good advice because

I have some kind of awful virus/worm/trojan thing on my computer. The day I got infected I had only been to neopets, a few neohelp sites, and Cnn.com.
I don't to make any assumptions but I think it came from a help website, avoid ones unless they're known to be safe o-o

User offline. Last seen 3 days 18 hours ago. Offline
Joined: 13/11/2007
Posts: 479
Rank: Master

Ugh I still have nightmares about when I was CG'd

User offline. Last seen 13 weeks 6 days ago. Offline
Joined: 01/10/2007
Posts: 148
Rank: Moderator

Ditto Nicole. Thanks for posting Dmitri.

User offline. Last seen 3 hours 22 min ago. Offline
Joined: 20/03/2009
Posts: 153
Rank: Dedicator

what in the world are TNT doing not fixing this??? its beyond my comprehension sad

thanks for the tips, Dmitri!

User stealth. Stealth!
Joined: 28/12/2007
Posts: 165
Rank: Dedicator

Thanks for the tips. happy

User stealth. Stealth!
Joined: 21/09/2007
Posts: 940

I think its truely horrible that this has been going on for about 9 months now? (maybe longer, who knows, but about 9 months since its been a huge problem)
When it first started happening, I thought for sure it'd be fixed in a week or two, maybe a month cause TNT are slow. I wasnt buying from shops or anything cause I was so worried... but now its like you just have to hope you wont get CG'd cause as mallers, we all use the SSW daily! We cant avoid it. And its just totally ridiculous that TNT havent fixed such a major secuirty issue like this =(

User offline. Last seen 40 weeks 1 day ago. Offline
Joined: 18/01/2009
Posts: 410
Rank: Master

I was oddly logged out once last week and I signed back on and immediately changed my password and made sure the email hadn't changed. I chance my word at least once a week and anytime I snipe something or any time I get that feeling in my gut. I tried NoScript is annoyed the tar out of me.

User offline. Last seen 7 weeks 1 day ago. Offline
Joined: 28/02/2009
Posts: 893

Thx for the tips Dmitri. I didn't know you could get CG'd just by being on neopets o.0 *is more paranoid then ever*. Does anyone know any tips on how to stay safe on IE8?

User offline. Last seen 13 weeks 6 days ago. Offline
Joined: 01/10/2007
Posts: 148
Rank: Moderator

Quote:
Does anyone know any tips on how to stay safe on IE8?

Umm. Switch to firefox? Sorry, I just really hate IE. =/