Protecting against Neopets Cookie Grabber (CGer) Guide

Welcome to the in-depth guide to avoiding cookie grabbers. This page has been generated from background information of how it works, reverse engineering of various neo CGs and 1st hand research. (plus losing 800k + trades along the way, but hey, it's priceless!!)

[SHORT VERSION]

For the in-depth version, please see http://www.neopets.com/~punchback_bob
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other things (like CGs) See attachment for more info

REQUESTPOLICY. RequestPolicy is an extension that improves the privacy and security of your browsing by giving you control over when cross-site requests are allowed by webpages you visit.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

AttachmentSize
Image icon whitelist-neopets.gif74.73 KB
Image icon ablock-instructions.gif43.8 KB
Forums: 

That makes sense to me. =/

[quote=_jaspeh_]So typically we've seen CGers putting code on their userlookups and shops. Someone just said there is a gallery with CGing code in it as well. But I was thinking.. Wouldnt it make sense that any place you can enter code is at risk for CGers? That means they can put the code on userlookups, shops, gallery , pet lookups and petpages?[/quote] yes but they'd have to reference to an external .js file and noscript prevents that
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

I have several comments and questions. First, do you know if there are any add-ons for Chrome? I had numerous frustrating problems with FireFox till I finally wiped it completely off my computer. I had terrible problems with it! Since then, I've used Chrome and I love it, but it doesn't seem to offer any add-ons or let me block URL's. I do know that I clicked on a shop link once (from SSW) and it blocked the page with an error message saying, "Warning: Visiting this page could harm your computer. Do you want to continue?" I closed the page. I assume that was a CG or similar. What I don't know is if that means Chrome can block all of those things? Wouldn't that be nice! :) Does anyone know why/how Chrome blocked that one shop and if that means Chrome is a bit safer than the others? (Including FF). Maybe Chrome has some of those script blocking things built in so it doesn't need the add-ons? Neopets does seem to be working on this problem because a friend of mine got iced today the moment she clicked onto a CG page. They froze her immediately, to protect her account I assume, so that must mean they now have an auto-freezing program of some kind that is detecting when these things hit. I guess that's a good sign. ;) Heads up: She got the CG when she clicked a link to the pound. It was in a board post that said "Fire Draik is in the pound" with a link that looked like the pound, but when she clicked it, it went to a fake Tarla page. Also, several of you mentioned that the site was recently down for 2 days? Huh? I've been on Neopets for many hours each day, and I haven't seen it down recently. Did this only affect certain areas of the country or something? Mine hasn't been down for months! how weird! :o Another weird - my shop sales are actually up rather than down. I assumed it was because it is summer now. I did also recently change malls, so I don't know the traffic patterns yet, but my last 3 days have been higher traffic than ever before and I switched malls about 2 weeks ago...I think... :P I do price low SSW, so my traffic is almost all from wiz. Oh, wait...it was recently half price day. Come to think of it, I have heard that means more traffic. Right? 0:-) Please forgive my ramblings. My brain is fried from work! *hides under desk* :P ~ Love books? Please visit my bookshop. :) http://www.neopets.com/browseshop.phtml?owner=lolooma
~ Love books? Please visit my bookshop. :) http://www.neopets.com/browseshop.phtml?owner=lolooma

I installed the Key scrambler for FF and since then my space bar has been quirky, not always working in flash games, I thought I had broke it playing in the AC, but I guess not. Is it just me?

So that is why my spacebar does not work in games usually...lol I thought I broke it =}

I just got a neomail "There is a CG that is redirecting people to your shop after they steal cookies. " o_O What should I make of that? I dont even wanna reply... lol
[hr][size=11]Training, Luck & Medicine! ^_^ www.neopets.com/browseshop.phtml?owner=_jaspeh_&misc#c [/size]

http://www.neopets.com/neoboards/topic.phtml?topic=134431344 now this is interesting. *disables signatures too*
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

Thanks for posting that. Very scary topic indeed...

This is crazy! This is getting to where people are so paranoid that they don't even want to play anymore. How many more people are going to have to be CGed until TNT does something? .:| Paint Brushes |:. http://www.neopets.com/browseshop.phtml?owner=heartlessness_&banner

This is too scary!!!! I have had the best day ever in my shop. I have all addons in place - do you think I have been attacked. I am so paranoid.

Pages