Protecting against Neopets Cookie Grabber (CGer) Guide

347 posts / 0 new
Last post
habit_of_mine
habit_of_mine's picture
Offline
Last seen: 1 year 8 months ago
Joined: 30/07/2009 - 4:58pm
Thanks for the response.
abrar13
abrar13's picture
Offline
Last seen: 6 years 3 months ago
Joined: 30/07/2009 - 11:42am
zixianna luckily for us, TNT reviews trophy scores, so they see if you're cheating using a score sender to earn a trophy is pretty much asking for a ban >.> thank goddd for that xD ~Abrar http://www.neopets.com/browseshop.phtml?owner=abrar1646&misc
Gavin63
Gavin63's picture
Offline
Last seen: 1 year 4 months ago
Joined: 23/07/2009 - 11:09pm
Not sure if anyone can shed some light on this but what I have been wondering since I became frozen is... If Iframe coding does not pass neo filters it could not have been directly added through my shop description which probably indicates that no one directly accessed my account. Does it mean that the page was edited above my level of editing access like straight on the server files or how did it actually get there.. Pets paradise Mall 3 Branches Info http://www.neopets.com/~Shizukeo
zixianna
zixianna's picture
Offline
Last seen: 4 months 6 days ago
Joined: 26/03/2010 - 7:44pm
First, how long have iFrames been caught by the filters? Second, I believe what people were doing was adding in links and tags that the filters normally would not allow by breaking the tags up through special characters and other methods I won't understand until I see them and look up how they work *lol* This thread is way too long to read through it all, I bet everything I want to know is buried in there somewhere!
Gavin63
Gavin63's picture
Offline
Last seen: 1 year 4 months ago
Joined: 23/07/2009 - 11:09pm
The code that I found is on a text file on this thread http://www.neomallers.com/node/3023 Pets paradise Mall 3 Branches Info http://www.neopets.com/~Shizukeo
zixianna
zixianna's picture
Offline
Last seen: 4 months 6 days ago
Joined: 26/03/2010 - 7:44pm
Yea, if you notice, there is no actual 'iframe' tag in there. They tricked both the filters and browsers into rendering an iframe. Enforcing proper HTML tags shoud precludes this particular trick now. Which means they'll just find a new trick shortly, and probably faster than TNT is taking to fix this one (which is just standard operating procedure in the Black Hat community *lol* ). p.s. - One thing I've never learned to do is how to search on google with special characters, code, tags, etc. I'll have to do that, it's always very annoying...
Gavin63
Gavin63's picture
Offline
Last seen: 1 year 4 months ago
Joined: 23/07/2009 - 11:09pm
With the code in the shop in the form it was it did not pass the filters. Other users found the same code when they tried to update their shops.. even just having the word Iframe in any descriptions is picked up straight away.. Pets paradise Mall 3 Branches Info http://www.neopets.com/~Shizukeo
zixianna
zixianna's picture
Offline
Last seen: 4 months 6 days ago
Joined: 26/03/2010 - 7:44pm
[quote=Gavin63]With the code in the shop in the form it was it did not pass the filters. Other users found the same code when they tried to update their shops.. even just having the word Iframe in any descriptions is picked up straight away.. [/quote] There is another possibility too - using escape sequences and the like to enter the characters into the shop. For example, I can type <iframe> here by using & lt ; and & gt ;, but if you try to copy and paste that in, it isn't going to work.
_jaspeh_
_jaspeh_'s picture
Offline
Last seen: 10 years 8 months ago
Joined: 21/09/2007 - 8:27pm
FYI, for Chrome users, theres a new extension call NotScrips, which is like NoScript for FF. Its new, so probably not as good, but its better than nothing! :D [hr][size=11]Wearable Clothing for your pets! www.neopets.com/browseshop.phtml?owner=_jaspeh_&misc 4mil Independent Ads http://www.neopets.com/~SicalliaRomeo [/size]
[hr][size=11]Training, Luck & Medicine! ^_^ www.neopets.com/browseshop.phtml?owner=_jaspeh_&misc#c [/size]
slintia
slintia's picture
Offline
Last seen: 10 years 1 month ago
Joined: 01/06/2009 - 7:51pm
When I get suspicious, I just inspect the element via firebug. : D
I need to stop playing neopets. I'll never have a social life ><

Pages