Mon Jan 09, 2006 12:27 am
Bumping this up because it seems the cookie grabbing is in full swing yet again...and my brother was careless enough to get cged :[
Be careful...
Mon Jan 09, 2006 3:48 am
Mon Jan 09, 2006 5:31 am
Officer 1BDI wrote:I just wish TNT would actually tell us what's going on. I don't care if they're trying to prevent a site-wide panic; a lot of unaware users are going to walk right into this problem if no one brings their attention to it. And as much as I trust the people here, I'd really feel more assured if TNT came out and told us when the problem's fixed, let alone that there's a problem at all.
Mon Jan 09, 2006 6:17 am
AySz88 wrote:Matt wrote:What I don't understand is... How the hell can things like this even affect the Neopets site. The cookie grabber comes along, and surely (if Neopets has any sense) it will grab a hashed password; not a password. And surely (again, if Neopets has any sense), their hash will be unbreakable, and therefore, you should just have to brute force it for any collisions, hich will take as long as just brute forcing the entire password anyway...
You can probably still masquerade as the user by planting the cookie on your own computer. I'm sure the Neopets server doesn't remember users based on IP......there's no way to query MAC address right?
Also, I think I heard that it's possible to store all hash possibilities of a 7-letter password into a hard drive and break it. A quick calculation with (26^7*8 / 2^30) produces searching through something like 60 GB - certainly not impossible to do.
I doubt the cookie contains a hash of just the password though - they probaby hash something like username-date-time-randomintegers and store that into the cookie and a their own local database.
Mon Jan 09, 2006 6:34 am
Mon Jan 09, 2006 6:42 am
Mon Jan 09, 2006 7:13 am
Mon Jan 09, 2006 7:14 am
Mon Jan 09, 2006 7:35 am
Mon Jan 09, 2006 7:43 am
everconfused wrote:I guess what I don't understand is why anyone would follow a link from someone else to their own SDB.
Mon Jan 09, 2006 7:51 am
Mon Jan 09, 2006 8:40 am
Mon Jan 09, 2006 8:59 am
everconfused wrote:dolphinling, have you sent this information to TNT? This is very disturbing.
everconfused wrote:I'm going to assume (please correct me if I'm wrong) that if you: don't leave the site while logged in; go to your SDB directly - not following any links except from the main Shops page; if you do want to go anywhere else you log out of Neo first, clear your internet info (cookies, etc.), then clear everything again after you visit any other site ... you should be safe?
Skynetmain wrote:Two questions:
1) Would someone have to have with Neopets knowledge to go after the SDB like described above, or could that just be grabbed in a random attack?
Skynetmain wrote:2) How long does it take for password requests to get sent out? I just got an e-mail saying I requested one and immediately changed it. I remember requesting one months ago and never getting a reply, but I'm still paranoid. I never go to any strange/non-corperate/not-recommended-by-a-trusted-source sites. I've only seen the inside of an unknown usershop/lookup/etc three times this year, none in the past week, and all had only basic, NP issue stuff inside. Should I still be paranoid since nothing else is out of the ordinary, or I am I right to freak out?
Mon Jan 09, 2006 9:00 am
Skynetmain wrote:2) How long does it take for password requests to get sent out? I just got an e-mail saying I requested one and immediately changed it. I remember requesting one months ago and never getting a reply, but I'm still paranoid.
Mon Jan 09, 2006 9:01 am
everconfused wrote:dolphinling, have you sent this information to TNT? This is very disturbing.
everconfused wrote:I'm going to assume (please correct me if I'm wrong) that if you: don't leave the site while logged in; go to your SDB directly - not following any links except from the main Shops page; if you do want to go anywhere else you log out of Neo first, clear your internet info (cookies, etc.), then clear everything again after you visit any other site ... you should be safe?
Skynetmain wrote:Two questions:
1) Would someone have to have with Neopets knowledge to go after the SDB like described above, or could that just be grabbed in a random attack?
Skynetmain wrote:2) How long does it take for password requests to get sent out? I just got an e-mail saying I requested one and immediately changed it. I remember requesting one months ago and never getting a reply, but I'm still paranoid. I never go to any strange/non-corperate/not-recommended-by-a-trusted-source sites. I've only seen the inside of an unknown usershop/lookup/etc three times this year, none in the past week, and all had only basic, NP issue stuff inside. Should I still be paranoid since nothing else is out of the ordinary, or I am I right to freak out?