UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store
 

Network Sites UGN Security, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
September
Su M Tu W Th F Sa
1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30
Our Sponsors

Latest Postings
any way I can get mac os x leopard?
by Gizmo
09/03/08 01:45 PM
WGA - removing windows genuine authentication notice
by Gizmo
09/02/08 04:14 AM
Owning Servers
by Gizmo
08/30/08 07:20 AM
my old account still exists!
by Gizmo
08/19/08 02:27 PM
Burger King gone Wild!
by Gizmo
08/08/08 11:42 PM
PDX 2600
by rbcp
08/07/08 12:46 AM
Topic Options
#9563 - 09/08/06 07:36 AM stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
I have reason to believe that someone has stolen my cookies and now i have some questions.

Is it possible that someone could place a cookie grabber on say the main menu of a forum and then get all my cookies?

Could those cookies then be used to show that person what web sites i visit, and be used to track my activity online?

Could the person who stole cookies then gain access using my username and password and cookies to other web sites?

If they can get access is deleting cookies and changing my password enough to stop them from accessing it again or will the old cookie still work?

Is there some other way they could access anothe rsite i use and get information about who is there and ip addresses?

Some web sites won't work if cookies are not allowed. How to i protect myself from cookie grabbers when cookies are essential and convenient?

I use adaware, anti virus software and a firewall, is there anything else i should be using to prevent security breaches?

Top
Our Sponsors
Sponsor Our Sponsors

Top  
#9564 - 09/08/06 04:32 PM Re: stolen cookies
Ghost Administrator Offline
UGN Super Poster

Registered: 06/16/03
Posts: 807
Loc: Wisconsin
Cookies are basically a text file stored on your computer. The data they contain is sent to webservers that the cookie says it should be sent to. The way browsers and cookies work, only the cookies for a certain website will be sent to that website. If someone used some sort of cookie stealer to steal cookies, those cookies would be for the domain in question. So, in short, just visiting a page, unless the browser itself is vulnerable (like Internet Explorer), will not reveal cookie data and browsing history. For a site where your cookies were stolen, yes, changing the password for the account will usually prevent the cookies from being used to acess your account.

It's not your resonsibility to protect yourself from cookie stealers as long as you use up-to-date browsers, such as Firefox. If your cookies are stolen, it's because the site or server itself is insecure.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9565 - 09/08/06 06:50 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
thank you

but if it wasnt cookies i have more questions im afraid.

say someone (an admin) from one forum claims to be able to tell who is logged in when on another forum ,completly unrealted to her server and not the dame type of bb, and completely private forum that she has no acccess to, and claims to have ip logs proving you were logged into both sites at the same time, and has tracked your movement between both sites. is that possible somehow? how would i stop her from doing the same thing again?

Top
#9566 - 09/08/06 07:18 PM Re: stolen cookies
Ghost Administrator Offline
UGN Super Poster

Registered: 06/16/03
Posts: 807
Loc: Wisconsin
Well, the only way they would be able to do that is if you were infected with some sort of malware, which might be possible, though unlikely. The other possibility is that this person has some sort of access to the server though subversive means. And, it's (almost) always possible to tell where you were right before coming to another site by way of the "referer" header, which has many legitimate and useful purposes.

Though, from what I can gather, it sounds like this person is just trying to scare you, in some sort of attempt to extort you or otherwise gain something. Considering your reaction, it seems to be working. You might try stepping back and thinking about the possibility of being socially engineered.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9567 - 09/08/06 07:51 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
i am sure she is just trying to scare me. and i am playing right into her hands by being worried. althougb unless she happens to read here she has no idea just how concerned her claims made me.

would the referrer header show if her site was opened in a new tab from a bookmark? what about if in a new window or would it have to be a new browser?

sorry i know im probably being really annoying but it is driving me crazy trying to figure it out lol

Top
#9568 - 09/08/06 08:29 PM Re: stolen cookies
Ghost Administrator Offline
UGN Super Poster

Registered: 06/16/03
Posts: 807
Loc: Wisconsin
I don't know whether or not you could tell the refering site if it was opened in a new tab, though I doubt it. You might try disabling the referer information sent to that site, which you can learn how to do in your browser documentation.
_________________________
[[ GamerSupport ] [ UGN Security ] [ Evil Hosting ] [ Comic Relief ]
~[Ghost]

Top
#9569 - 09/08/06 08:38 PM Re: stolen cookies
cat Offline
Junior Member

Registered: 09/08/06
Posts: 4
Loc: uk
i found a firefox extension to do that, so have that set up now.

thanks for all your help ghost.

Top
#41067 - 10/08/06 02:41 PM Re: stolen cookies [Re: cat]
Artic Warrior Offline
UGN Member

Registered: 11/12/03
Posts: 408
Loc: My room
Ghost is cool like that, I wonder if he remembers helping me with the router login.
_________________________
follow the white rabbit

Top



Moderator:  Infinite 
Forum Stats
6868 Members
44 Forums
10498 Topics
45243 Posts

Max Online: 677 @ 06/30/07 10:06 PM
Top Posters
Gizmo 6933
UGN Security 3472
§intå× 3250
IceMyst 1449
SilentRage 1273
Ice 1146
pergesu 1134
Infinite 1039
jonconley 954
Girlie 903
Newest Members
heeheehaahaa, ssploo7, red queen, byopc, cybermox
6868 Registered Users
Who's Online
0 Registered (), 9 Guests and 16 Spiders online.
Key: Admin, Global Mod, Mod
Latest News
Update Humpday - Sept 03, 2008
by Gizmo
Yesterday at 09:37 AM
Update Humpday - Aug 27, 2008
by Gizmo
08/28/08 12:58 AM
Update Humpday - Aug 20, 2008
by Gizmo
08/21/08 01:48 AM
Update Humpday - Aug 14, 2008
by Gizmo
08/14/08 08:33 AM
Update Humpday - Aug 06, 2008
by Gizmo
08/06/08 08:05 AM


Donate

Get the Google FireFox Toolbar
Get Firefox!
Get FireFox!