Protecting against Neopets Cookie Grabber (CGer) Guide

Welcome to the in-depth guide to avoiding cookie grabbers. This page has been generated from background information of how it works, reverse engineering of various neo CGs and 1st hand research. (plus losing 800k + trades along the way, but hey, it's priceless!!)

[SHORT VERSION]

For the in-depth version, please see http://www.neopets.com/~punchback_bob
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other things (like CGs) See attachment for more info

REQUESTPOLICY. RequestPolicy is an extension that improves the privacy and security of your browsing by giving you control over when cross-site requests are allowed by webpages you visit.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

AttachmentSize
Image icon whitelist-neopets.gif74.73 KB
Image icon ablock-instructions.gif43.8 KB
Forums: 

Norton 360 (as well as Trend Micro) is a scam. DOnt think spybot is that great either. All you need is superantispyware/malware antibytes or something like that, AVG Free. Hope you got norton 360 for free lol. You should get both removed and get superantispyware So many people are getting scammed by these so called "security software", I'm almost tempted to start a live support called "GeekMallers" via teamviewer remote assistance
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

ok , thanks for your advice . ziggy

i googled superantispyware an checked out there site an its more or less the same as spybot - search & destroy . so i,m not sure what to do . i,m downloading the free version now an i will check it out before i spend out more money on another useless program . an i did pay more or less for the norton 360 it was a free upgrade from my norton internet securities when i renewed my subscription last year . it was like $168. for 2 years . it did save me from a trojon about 6 months ago . you definatly gave me aloth to thing about . thank you for all your help . this site an post has been so helpful . ziggy

Get MalwareBytes
525,600 Minutes http://www.neopets.com/browseshop.phtml?owner=desperately_yours&misc

Since Ziggy, thankfully somebody did, posted about different kinds of security software, I have a question myself. Does anybody know about McAfee and whether it is reliable? I have IE as well. And I know that's bad, so you don't have to remind me. (: I'm switching over soon (hopefully, the husband is a pain in the rear and doesn't feel the need to). Anyways, back to the real topic. I've had McAfee for a couple months now, and it's great. It lets me know which sites I can go to, which sites I shouldn't go to, and actually when I was on imageshack something unsafe was trying to redirect me to another site and McAfee wouldn't let it. So I'm really wondering if it is enough, at least for a little while, to keep me protected. Thanks ahead of time to anyone who may help me out. (:

i downloaded the superantispyware free version an ran the scan an found 46 problems but 22 of them were my neopets tool bar an i,m not removing that from my account . the other 24 i deleted . but befor i did i ran my spybot - search & destroy just to see as i already have my neopets allowed on it . it found 34 problems , of which included the 24 that superantispyware found an 10 others . between all the programs i have on my comp i have 2 firewalls , 3 ad/spy blockers an a norton , spybot an now the superantispyware . so hopefully with all that i at least stand a bit of a chance i hope i do anyway . i have PW an PINED all my accounts to death so it the best i can do . i run my scans an update everything monthly thats not a time table as well as defrag , i clean sweep multi times a day an clear my cookies an such every night befor i log off . in the end if i get hacked , i get hacked . its a sad day when users have to rip off free game accounts on a free pet site . that not even real an is a GAME !

Does it sound like I was CG'd? I logged in to read my e-mail and clicked to open a SHH event which sent me to a log-in page for Neopets (normal). I logged-in and got the SHH events. Then I checked my shop history and noticed I had sold two blue evil fuzzles. I used the super shop wizard to find a Blue Evil Fuzzle and went to zenanasx's shop to buy since it was the cheapest. I noticed the card Niten Hiroru for 17K and then SSW'd that item. These were the three shops I went to to buy the cards: kougakajoe; andimum; zenanasx. After purchasing the cards I bought zenanasx's Enchanted Maraquan Necklace too since it was so cheap. I then tried to SSW that item. I was asked to log-in again before I could super shop wizard it. I logged in, then out of my account immediately and logged back in. I don't know that I was CG'd but thought I should tell you since I knew the user's names. _____________________________________________________ ~ Mimi's Ménagerie Avatars ~ http://www.neopets.com/browseshop.phtml?owner=temps_bons&misc
~ Mimi ~ http://www.neopets.com/~Amyrilli

No cgs are in that shop. probably some cookies exploded or something
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

I often get logged out after opening a webmail so that might have happened to you too. It's not always right away, but sometimes within 3-4 clicks. It's very annoying :K I always change my pw when it happens anyway.

I like McAfee cranked down tight with intrusion alert, personal information protection, and password vault. I also use firefox in stealth mode, No Script, and key scrambler. Should I be getting more security?

Pages