Home › Forums › Archives › Instant Messaging › Yahoo! Messenger Support › Yahoo cookie capture exploit
- This topic has 11 replies, 6 voices, and was last updated 20 years, 10 months ago by
markking68.
-
AuthorPosts
-
October 3, 2005 at 6:38 am #20180
Dirty Red
MemberSomeone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/gals
October 3, 2005 at 7:13 am #131240miGs
MemberDirty Red wrote:Someone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/galsFor cookie related news, issues and articles, check this.
I think the exploit is more about decoding the cookie.As for solution, having a clean system, make sure there are no trojans hiding in your system and have decent firewall. Avoid clicking links too.
October 3, 2005 at 7:37 am #131234Dirty Red
MemberThat site was basically useless for answering my question, but thanks anyway. Im just at a loss because if these guys are capturing my info from my cookie, changing my password isnt going to help.
October 3, 2005 at 7:48 am #131241miGs
MemberDirty Red wrote:That site was basically useless for answering my question, but thanks anyway. Im just at a loss because if these guys are capturing my info from my cookie, changing my password isnt going to help.Oh I am sorry if that didnt help.
October 3, 2005 at 9:32 pm #131232UnSaKreD
MemberDirty Red wrote:Someone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/galsInteresting, having dealt alot with cookies, especially in decoding them.
I am intregued as to how your name was *stolen* from the cookie.
Considering, the password is not stored in the cookie.
Your account can be info cracked by the information that is decoded.
But you would still have to get the secret question correct.Any more info?
October 4, 2005 at 12:11 am #131235Dirty Red
Memberit actually wasn’t my name, it was a friend of mine’s, but i’m concerned because the people responsible are very unpredictable, using basically any excuse they can to wreak havoc and cause trouble. obviously Yahoo abuse reporting is automated, so theyre not going to do anything about it, but all the information i have is that the guys who did this were bragging in the room about using the cookie to gain access to the person’s account. regarding the secret question(s), they also bragged that they had changed those as well. at any rate, I’m sure everything will eventually work out, but messenger services being predominantly used for advertising purposes, they may not be too quick to patch this exploit. thanks for the help, i think i have given the basic outline of the information i have.
October 4, 2005 at 10:17 pm #131242markking68
Memberit is possable that you have a keyloger on your computer like back orafice,the only way to get to your cookies is to have access to your system files, if you are useing windows xp it can’t be done with a trojen.look for a file that is installing back orafice. forgot what file it it but you can get the info on it by doing a search for back orafice..don’t confuse it with back office witch windows uses if you have office..
might not help but its in that area where your problem is at..btw it can be downloaded to your computer through a pcture..heres a link to check out
http://www.bo2k.com/news.shtmlOctober 5, 2005 at 11:12 am #131236Dirty Red
MemberFor The last time people, it isn’t my name, my computer, or my account, however i need to say it. I cant get in touch with the guy it happened to right now to share all this with him, the reason i posted the topic was to be able to secure my own computer. Thanks for all the info it is helpful having new sites and learning new info, even if it isnt what i was looking for.
October 5, 2005 at 12:28 pm #131238Nessa
ParticipantDirty Red wrote:For The last time people, it isn’t my name, my computer, or my account…
We get that, just that it’s a habit and people always think it’s the one asking the question that needs help.Dirty Red wrote:…i have is that the guys who did this were bragging in the room about using the cookie to gain access to the person’s account. regarding the secret question(s), they also bragged that they had changed those as well…You say it’s them and accuse them and know they are bad people, so why believe every word they type? They could be lying just to brag. They could have spent several days trying to steal your friends account through cracking or some other method. Yet when they go brag they aren’t going to say they tried so hard just to get one name. They will say “oh we know this magical way of using cookies and i can do this and i can do that, FEAR ME!”
Well that’s all i got to say, and i’m sorry you feel this site didn’t offer much help, but people honestly try their best to answer any questions posted.
October 5, 2005 at 5:21 pm #131237Dermot
ParticipantHow do you know a cookie exploit was used?
Word of mouth?
guess?
I highly doubt it was…
However if the person lost his/her account im sure he knows by now and should have tried the Forget password option on the yahoo login page.
If they do not know their own info or it has been fully changed then its tough luck on that front.
I’m sure he can make a new id to let his friends know it has happened to him.
October 5, 2005 at 8:39 pm #131233UnSaKreD
MemberHaving actually used 0 day cookie exploits in the past, this does not sound like one of them. It sounds to me more like your friend was phished via a fake geocities login or something along those lines.
Although there are a few info cracking/regular account crackers working at the moment.
Still highly doubt it was attacked that way. I am leaning towards the PEBKAC.(Problem Exists Between Keyboard and Chair) and not uber l33t h4x0rs with a new cookie exploit.
October 5, 2005 at 11:14 pm #131239Nessa
ParticipantDirty Red wrote:…the reason i posted the topic was to be able to secure my own computer…
Regarding the reason you posted, all we can really recommend is things you probably already know… Keeping your anti-virus up to date, running programs to protect you against malicious items. (Spybot – Search & Destroy, Ad-Aware SE Personal) And the most reasonable one’s, NEVER click on random links, NEVER download attachments you aren’t completely sure of what they contain, and NEVER log in your id and password into a site that isn’t a legit yahoo site. (http://www.yahoo.com) <legitWell that’s all the advice i think anyone can really give you… I doubt as i said it was a cookie exploit, so just try to keep your computer safe, which i’m pretty sure you know the basics of how to do. Hope that helps.
-
AuthorPosts
- You must be logged in to reply to this topic.