UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, The GoNix Initiative, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
December
Su M Tu W Th F Sa
1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31
Sponsored Links
Latest Postings
Latest Reviews
Topic Options
Rate This Topic
#9563 - 09/08/06 07:36 AM stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
I have reason to believe that someone has stolen my cookies and now i have some questions.

Is it possible that someone could place a cookie grabber on say the main menu of a forum and then get all my cookies?

Could those cookies then be used to show that person what web sites i visit, and be used to track my activity online?

Could the person who stole cookies then gain access using my username and password and cookies to other web sites?

If they can get access is deleting cookies and changing my password enough to stop them from accessing it again or will the old cookie still work?

Is there some other way they could access anothe rsite i use and get information about who is there and ip addresses?

Some web sites won't work if cookies are not allowed. How to i protect myself from cookie grabbers when cookies are essential and convenient?

I use adaware, anti virus software and a firewall, is there anything else i should be using to prevent security breaches?

Top
Sponsored Links
      
#9564 - 09/08/06 04:32 PM Re: stolen cookies
Ghost Offline


Registered: 06/16/03
Posts: 807
Loc: Wisconsin
Cookies are basically a text file stored on your computer. The data they contain is sent to webservers that the cookie says it should be sent to. The way browsers and cookies work, only the cookies for a certain website will be sent to that website. If someone used some sort of cookie stealer to steal cookies, those cookies would be for the domain in question. So, in short, just visiting a page, unless the browser itself is vulnerable (like Internet Explorer), will not reveal cookie data and browsing history. For a site where your cookies were stolen, yes, changing the password for the account will usually prevent the cookies from being used to acess your account.

It's not your resonsibility to protect yourself from cookie stealers as long as you use up-to-date browsers, such as Firefox. If your cookies are stolen, it's because the site or server itself is insecure.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9565 - 09/08/06 06:50 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
thank you

but if it wasnt cookies i have more questions im afraid.

say someone (an admin) from one forum claims to be able to tell who is logged in when on another forum ,completly unrealted to her server and not the dame type of bb, and completely private forum that she has no acccess to, and claims to have ip logs proving you were logged into both sites at the same time, and has tracked your movement between both sites. is that possible somehow? how would i stop her from doing the same thing again?

Top
#9566 - 09/08/06 07:18 PM Re: stolen cookies
Ghost Offline


Registered: 06/16/03
Posts: 807
Loc: Wisconsin
Well, the only way they would be able to do that is if you were infected with some sort of malware, which might be possible, though unlikely. The other possibility is that this person has some sort of access to the server though subversive means. And, it's (almost) always possible to tell where you were right before coming to another site by way of the "referer" header, which has many legitimate and useful purposes.

Though, from what I can gather, it sounds like this person is just trying to scare you, in some sort of attempt to extort you or otherwise gain something. Considering your reaction, it seems to be working. You might try stepping back and thinking about the possibility of being socially engineered.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9567 - 09/08/06 07:51 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
i am sure she is just trying to scare me. and i am playing right into her hands by being worried. althougb unless she happens to read here she has no idea just how concerned her claims made me.

would the referrer header show if her site was opened in a new tab from a bookmark? what about if in a new window or would it have to be a new browser?

sorry i know im probably being really annoying but it is driving me crazy trying to figure it out lol

Top
#9568 - 09/08/06 08:29 PM Re: stolen cookies
Ghost Offline


Registered: 06/16/03
Posts: 807
Loc: Wisconsin
I don't know whether or not you could tell the refering site if it was opened in a new tab, though I doubt it. You might try disabling the referer information sent to that site, which you can learn how to do in your browser documentation.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9569 - 09/08/06 08:38 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
i found a firefox extension to do that, so have that set up now.

thanks for all your help ghost.

Top
#41067 - 10/08/06 02:41 PM Re: stolen cookies [Re: cat]
Artic Warrior Offline
UGN Member

Registered: 11/12/03
Posts: 478
Loc: My room
Ghost is cool like that, I wonder if he remembers helping me with the router login.
_________________________

Top

Moderator:  Infinite 
Featured Member
Registered: 02/28/02
Posts: 7193
Forum Stats
2152 Members
46 Forums
36290 Topics
71460 Posts

Max Online: 1567 @ 04/25/10 05:20 AM
Top Posters
UGN Security 29451
Gremelin 7193
§intå× 3255
SilentRage 1273
Ice 1146
pergesu 1136
Infinite 1041
jonconley 955
Girlie 908
unreal 860
Newest Members
cdefgh368568, HushHush, golqm, Tim050, Gecko666
2151 Registered Users
Who's Online
0 registered (), 261 Guests and 308 Spiders online.
Key: Admin, Global Mod, Mod
Latest News


Donate
  Get Firefox!
Get FireFox!