What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Instant Messaging > Yahoo! Messenger Support

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 10-03-2005, 02:38 AM
Dirty Red Dirty Red is offline
Junior Member
 
Join Date: Sep 2004
Location: GA, USA.
Posts: 8
Dirty Red is on a distinguished road (10)
Send a message via Yahoo to Dirty Red
Yahoo cookie capture exploit

Someone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/gals
Reply With Quote
  #2 (permalink)  
Old 10-03-2005, 03:13 AM
miGs's Avatar
miGs miGs is offline
Senior Member
 
Join Date: Mar 2005
Posts: 343
miGs is on a distinguished road (10)
Quote:
Originally Posted by Dirty Red
Someone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/gals
For cookie related news, issues and articles, check this.
I think the exploit is more about decoding the cookie.

As for solution, having a clean system, make sure there are no trojans hiding in your system and have decent firewall. Avoid clicking links too.

Last edited by miGs : 10-04-2005 at 03:32 AM. Reason: put the link back coz others may find it useful.
Reply With Quote
  #3 (permalink)  
Old 10-03-2005, 03:37 AM
Dirty Red Dirty Red is offline
Junior Member
 
Join Date: Sep 2004
Location: GA, USA.
Posts: 8
Dirty Red is on a distinguished road (10)
Send a message via Yahoo to Dirty Red
That site was basically useless for answering my question, but thanks anyway. Im just at a loss because if these guys are capturing my info from my cookie, changing my password isnt going to help.
Reply With Quote
  #4 (permalink)  
Old 10-03-2005, 03:48 AM
miGs's Avatar
miGs miGs is offline
Senior Member
 
Join Date: Mar 2005
Posts: 343
miGs is on a distinguished road (10)
Quote:
Originally Posted by Dirty Red
That site was basically useless for answering my question, but thanks anyway. Im just at a loss because if these guys are capturing my info from my cookie, changing my password isnt going to help.
Oh I am sorry if that didnt help.

Last edited by miGs : 10-04-2005 at 03:32 AM.
Reply With Quote
  #5 (permalink)  
Old 10-03-2005, 05:32 PM
UnSaKreD's Avatar
UnSaKreD UnSaKreD is offline
The One The Only
 
Join Date: Dec 2003
Location: Farmington, New Hampshire, USA.
Posts: 738
UnSaKreD is on a distinguished road (10)
Send a message via AIM to UnSaKreD Send a message via MSN to UnSaKreD Send a message via Yahoo to UnSaKreD
Quote:
Originally Posted by Dirty Red
Someone recently stole the account of a friend of mine. These goons travel in packs and are regs in my room. What i have gotten so far is that a cookie exploit was used, where no cracking was necessary. ANyone got any ideas about this exploit and a possible solution? This guy poses as my friend a lot but he kind of came after me tonite. Any help would be great. thanks guys/gals
Interesting, having dealt alot with cookies, especially in decoding them.
I am intregued as to how your name was *stolen* from the cookie.
Considering, the password is not stored in the cookie.
Your account can be info cracked by the information that is decoded.
But you would still have to get the secret question correct.

Any more info?
Reply With Quote
  #6 (permalink)  
Old 10-03-2005, 08:11 PM
Dirty Red Dirty Red is offline
Junior Member
 
Join Date: Sep 2004
Location: GA, USA.
Posts: 8
Dirty Red is on a distinguished road (10)
Send a message via Yahoo to Dirty Red
it actually wasn't my name, it was a friend of mine's, but i'm concerned because the people responsible are very unpredictable, using basically any excuse they can to wreak havoc and cause trouble. obviously Yahoo abuse reporting is automated, so theyre not going to do anything about it, but all the information i have is that the guys who did this were bragging in the room about using the cookie to gain access to the person's account. regarding the secret question(s), they also bragged that they had changed those as well. at any rate, I'm sure everything will eventually work out, but messenger services being predominantly used for advertising purposes, they may not be too quick to patch this exploit. thanks for the help, i think i have given the basic outline of the information i have.
Reply With Quote
  #7 (permalink)  
Old 10-04-2005, 06:17 PM
markking68 markking68 is offline
Junior Member
 
Join Date: Apr 2005
Posts: 22
markking68 is on a distinguished road (10)
cookie exploit

it is possable that you have a keyloger on your computer like back orafice,the only way to get to your cookies is to have access to your system files, if you are useing windows xp it can't be done with a trojen.look for a file that is installing back orafice. forgot what file it it but you can get the info on it by doing a search for back orafice..don't confuse it with back office witch windows uses if you have office..
might not help but its in that area where your problem is at..btw it can be downloaded to your computer through a pcture..heres a link to check out
http://www.bo2k.com/news.shtml
Reply With Quote
  #8 (permalink)  
Old 10-05-2005, 07:12 AM
Dirty Red Dirty Red is offline
Junior Member
 
Join Date: Sep 2004
Location: GA, USA.
Posts: 8
Dirty Red is on a distinguished road (10)
Send a message via Yahoo to Dirty Red
For The last time people, it isn't my name, my computer, or my account, however i need to say it. I cant get in touch with the guy it happened to right now to share all this with him, the reason i posted the topic was to be able to secure my own computer. Thanks for all the info it is helpful having new sites and learning new info, even if it isnt what i was looking for.
Reply With Quote
  #9 (permalink)  
Old 10-05-2005, 08:28 AM
Nessa's Avatar
Nessa Nessa is offline
Hrm.
 
Join Date: Jan 2005
Location: San Antonio, Texas
Posts: 1,504
Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)Nessa has left a lasting impression (500)
Quote:
Originally Posted by Dirty Red
For The last time people, it isn't my name, my computer, or my account...
We get that, just that it's a habit and people always think it's the one asking the question that needs help.

Quote:
Originally Posted by Dirty Red
...i have is that the guys who did this were bragging in the room about using the cookie to gain access to the person's account. regarding the secret question(s), they also bragged that they had changed those as well...
You say it's them and accuse them and know they are bad people, so why believe every word they type? They could be lying just to brag. They could have spent several days trying to steal your friends account through cracking or some other method. Yet when they go brag they aren't going to say they tried so hard just to get one name. They will say "oh we know this magical way of using cookies and i can do this and i can do that, FEAR ME!"

Well that's all i got to say, and i'm sorry you feel this site didn't offer much help, but people honestly try their best to answer any questions posted.

I told my psychiatrist that everyone hates me. He said I was being ridiculous - everyone hasn't met me yet.
Reply With Quote
  #10 (permalink)  
Old 10-05-2005, 01:21 PM
Dermot's Avatar
Dermot Dermot is offline
Here to help!
 
Join Date: Dec 2004
Location: Louth, Ireland.
Posts: 1,229
Dermot is a celebrity (300)Dermot is a celebrity (300)Dermot is a celebrity (300)Dermot is a celebrity (300)
Send a message via ICQ to Dermot Send a message via AIM to Dermot Send a message via MSN to Dermot Send a message via Yahoo to Dermot
How do you know a cookie exploit was used?

Word of mouth?

guess?

I highly doubt it was...

However if the person lost his/her account im sure he knows by now and should have tried the Forget password option on the yahoo login page.

If they do not know their own info or it has been fully changed then its tough luck on that front.

I'm sure he can make a new id to let his friends know it has happened to him.

Shadow-corp.net - 1500+ Games and climbing!
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
My ideals to improve Yahoo! Account-Security n3td3v Yahoo! Messenger Support 10 02-25-2006 02:49 AM
Servicio gratuito de llamadas a través del nuevo Yahoo! Messenger Jeff Noticias en MI 0 08-13-2005 01:58 AM
Biggest exploit ever in Yahoo! Johnson Yahoo! Messenger Support 0 11-23-2003 04:06 AM
Yahoo! Messenger Launches ′IMVironments′ With Next Generation of Yahoo! Messenger Service BigBlueBall News Yahoo! Messenger News 0 10-22-2001 01:00 AM

All times are GMT -5. The time now is 04:34 PM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.