Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-09-2001, 02:50 PM   #1
justsexxx
Too lazy to set a custom title
 
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
Look what I've made,,,,protect yourself....

Hi,

Look what I've made:
http://www.justsexxx.com/cook.html

click then on the link. The windows will show the cookie stored on your computer from google. I used the domain google, becasuse I presume that you've all been there once. Did it also with a passwork protected site, and I received the username and password, they we're protected, but you can encrypt that....

Let me know if your computer has the same problem.....(must have visited for this example google at least once since your last internetfiles cleanup)


Andre
justsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:17 PM   #2
GiggleBerries
Confirmed User
 
Join Date: Oct 2001
Location: The pay phone outside the 7-11
Posts: 357
Sure it works, but what's that supposed to prove? You are viewing the cookie information locally. No need to cause mass hysteria over a simple javascript. That cookie information can not be passed to a third party. Only the domain that set the cookie or you sitting at your machine can get the contents of that cookie.

------------------
Dot Matrix TGP System
GiggleBerries is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:19 PM   #3
m0rph3us
Confirmed User
 
Join Date: Mar 2001
Location: Principality of Sealand
Posts: 2,033
Quote:
Originally posted by GiggleBerries:
Sure it works, but what's that supposed to prove? You are viewing the cookie information locally. No need to cause mass hysteria over a simple javascript. That cookie information can not be passed to a third party. Only the domain that set the cookie or you sitting at your machine can get the contents of that cookie.


umm actually it can... and very simple to do so....
m0rph3us is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:27 PM   #4
GiggleBerries
Confirmed User
 
Join Date: Oct 2001
Location: The pay phone outside the 7-11
Posts: 357
Quote:
Originally posted by m0rph3us:

umm actually it can... and very simple to do so....
ummm, actually you're wrong. I have lots of cookies here set by lots of different sites. Show me the contents of any of those cookies. Give me a URL to visit and pull info from one of those cookies. In fact, I have a cookie set by giggleberries.com. Tell me what the contents of that cookie are.



------------------
Dot Matrix TGP System
GiggleBerries is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:36 PM   #5
justsexxx
Too lazy to set a custom title
 
Join Date: Aug 2001
Location: The Netherlands
Posts: 13,723
Hi,

Actually you can read those cookies. You can let it send to an emailaddress and try to encrypt it,.So I can read your cookies....

Andre
justsexxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:46 PM   #6
GiggleBerries
Confirmed User
 
Join Date: Oct 2001
Location: The pay phone outside the 7-11
Posts: 357
Quote:
Originally posted by justsexxx:
Hi,

Actually you can read those cookies. You can let it send to an emailaddress and try to encrypt it,.So I can read your cookies....

Andre
huh? Why in the hell would I send you my cookies?



------------------
Dot Matrix TGP System
GiggleBerries is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:55 PM   #7
Mango
Confirmed User
 
Join Date: Aug 2001
Posts: 474
Quote:
Originally posted by justsexxx:
Hi,

Actually you can read those cookies. You can let it send to an emailaddress and try to encrypt it,.So I can read your cookies....

Andre
Why should you encrypt this ??
Cookies are safe (on the discussed level at least).
Mango is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:55 PM   #8
funkmaster
So Fucking Banned
 
Join Date: Sep 2001
Location: shell beach
Posts: 7,938
... you won´t even notice when sending that email ... nasty things can be done with activeX exploits ...

------------------
Don't innovate - imitate!
... giving away mass traffic for free !!
funkmaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 03:58 PM   #9
SleazyDream
I'm here for SPORT
 
SleazyDream's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Phone # (401) 285-0696
Posts: 41,470
I like cookies with milk
SleazyDream is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 04:04 PM   #10
RockDaddy
Confirmed User
 
Join Date: Jul 2001
Posts: 750
This is a bit of the latest Microsoft Security Bulletin. Received this yesterday.


From Microsoft

Web sites use cookies as a way to store information on a user's
local system. Most often, this information is used for customizing
and retaining a site's setting for a user across multiple sessions.
By design each site should maintain its own cookies on a user's
machine and be able to access only those cookies.

A vulnerability exists because it is possible to craft a URL that
can allow sites to gain unauthorized access to user's cookies and
potentially modify the values contained in them. Because some web
sites store sensitive information in a user's cookies, it is also
possible that personal information could be exposed.

Risk Rating:
============
- Internet systems: High
- Intranet systems: High
- Client systems: High

RD
RockDaddy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 04:21 PM   #11
GiggleBerries
Confirmed User
 
Join Date: Oct 2001
Location: The pay phone outside the 7-11
Posts: 357
Sorry, I disagree. If it can be done....SHOW ME! This is the same kind of paranoia that has been fueling the nightmares of AOL users for years.

I get the same bulletins too, but as long as you leave your default security settings alone and stay away from the script kiddies sites, you are pretty safe.

In case anyone cares, the bulletin that we are speaking of is at
http://www.microsoft.com/technet/tre...n/MS01-055.asp

There are no known cases of anyone exploiting this issue, but it is possible (Linux anyone?).

------------------
Dot Matrix TGP System
GiggleBerries is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-09-2001, 04:31 PM   #12
RockDaddy
Confirmed User
 
Join Date: Jul 2001
Posts: 750
I'm not all that worried about it myself personally, but it should be a concern. If it hasn't been done then I don't think MS would even know about it or hot it works exactly and be calling it a high risk.

Nothing surprises me anymore after seeing what all has been exploited through active x controls. Autobookmarking, adding things to your desktop and start menu. Not to mention all of these programs that can replace your text/links/banners with someone elses. If anyone would have said any of those things are something to be worried about before they became a major reality, most people would not have believed that either.

I'm not a progammer, if it wasn't for Frontpage I would have to get a real job, but if there is a way to do it you can bet your last dollar that someone already knows how to do it or will soon enough.

RD
RockDaddy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.