Protecting against Neopets Cookie Grabber (CGer) Guide

Welcome to the in-depth guide to avoiding cookie grabbers. This page has been generated from background information of how it works, reverse engineering of various neo CGs and 1st hand research. (plus losing 800k + trades along the way, but hey, it's priceless!!)

[SHORT VERSION]

For the in-depth version, please see http://www.neopets.com/~punchback_bob
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other things (like CGs) See attachment for more info

REQUESTPOLICY. RequestPolicy is an extension that improves the privacy and security of your browsing by giving you control over when cross-site requests are allowed by webpages you visit.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

AttachmentSize
Image icon whitelist-neopets.gif74.73 KB
Image icon ablock-instructions.gif43.8 KB
Forums: 

[quote=littrell23]HELP! Is anyone on right now that can tell me what to download for Safari/Mac? I think I have just been CG'd![/quote] I sent you some dung because your mailbox is full! Log out, log back in and change your password and if you haven't already added pin numbers to EVERYTHING, do it now. _____________________________________________________ ~ Mimi's Ménagerie Avatars ~ http://www.neopets.com/browseshop.phtml?owner=temps_bons&misc
~ Mimi ~ http://www.neopets.com/~Amyrilli

thank you all so much! I think I am just going to just download Opera or stick w/ Firefox from now on. Basically what happened was a sniping a codestone & when I went into the shop, I clicked it, but it redirected me to another page in a pop-up, then quick flashed to something weird (a Neopets warning of somesort - I couldn't read it since it was so quick), then it flashed me to some other user's shop that said their account was frozen. I quick then logged out, logged back in & changed my p-word. I was so nervous though that I logged out, then ran over to another comp in the house & changed my p-word again on there! haha Since then I've downloaded an anti-virus & spyware locator (I have a Mac so I always though I didn't need one!), and found a virus on my computer. Luckily, no spyware though. I can't seem to find a keyscrambler though for Safari. So I will prob just use Opera instead, or Firefox. Thank you again all so much for your concern! And my nm is cleared now so I should be ok to chat! PS. So, if I did those steps am I def ok, or is there now something on my comp that the hacker can now see anything I type? Even if I just logged out, changed my p-word, and logged back in - is that enough?

Heya all, I just wanted to report that I found 2 more CG attempts tonight while restocking and sniping. Both were cheap codestones that led offsite, and noscript caught both of the scripts that were attached. I did actually make it to the obnoxious scammer offsite image in one case, although I *think* all of the scripty evils were blocked because the little cross-script-attempt bar popped up, and the new site showed as blocked. Despite the catch I still logged off, logged back on, and changed words, PINs, etc. (Just to be sure... I don't know if I'm being paranoid or sensible.) :K Please continue to be careful when wiz sniping, and make sure to turn noscript back on if you had it off!

OK I don't understand one thing in No-Script. How do you know IF there was a hacking attempt? On every page of Neopets there are TONS of blocked scripts simply because of the ads. So do you just allow all of the ad sites? In order to recognize a user page that uses an offsite .js file you would need to allow all of the ads. So should I? Come check it out: http://www.neopets.com/browseshop.phtml?owner=abrar1646&misc

Does this address look right? http://home.neopets.com/templates/homepage.phtml?pet_name=ChEeKeEpOo60 It is a page with backgrounds that looks like a petpet page. I don't know how my daughter found it but it is in my bookmarks as a neopets graphic page. EDIT: Okay, it is a pet page on neopets (I searched the name) http://www.neopets.com/~ChEeKeEpOo60 Is the first site address how a person who is not logged into neopets would get to the page? _____________________________________________________ ~ Mimi's Ménagerie Avatars ~ http://www.neopets.com/browseshop.phtml?owner=temps_bons&misc
~ Mimi ~ http://www.neopets.com/~Amyrilli

i think that the first link was how they used to link to petpages, ages ago, but then they changed it :) People outside can see the ~petname one :)
[hr][size=11]Training, Luck & Medicine! ^_^ www.neopets.com/browseshop.phtml?owner=_jaspeh_&misc#c [/size]

Just reading the mall openings and could not see a banner so I put the address into my browser and it blocked the site as an attack site in FireFox: http://www.cpi4u.com/neopets/nbad.gif Anyone know what's wrong with cpi4u? It is hosting images for The Market Place which is a pretty reputable mall: http://www.neopets.com/~UniquePenguin _____________________________________________________ ~ Mimi's Ménagerie Avatars ~ http://www.neopets.com/browseshop.phtml?owner=temps_bons&misc
~ Mimi ~ http://www.neopets.com/~Amyrilli

I dont know. i googled it and even google says the site is harmful. It's some east indian website
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

[quote=Dmitri]I dont know. i googled it and even google says the site is harmful. It's some east indian website[/quote] Interesting! I have a friend in that mall that I will let know about it. I haven't tried clicking on the mall banner for fear of .... well I dunno but I reeeely don't want to click on it, LOL! Thanks D!! _____________________________________________________ ~ Mimi's Ménagerie Avatars ~ http://www.neopets.com/browseshop.phtml?owner=temps_bons&misc
~ Mimi ~ http://www.neopets.com/~Amyrilli

It could be a free host but google doesnt really say it's bad though. Just some site advisors warn against free hosts since free hosts are often used to host viruses and other crap stuff. This is a WHOIS lookup on the domain: [quote]registrant-firstname: Surinder Singh registrant-lastname: Pama registrant-organization: canadian punjabi international inc registrant-street1: 165 Morton WAY registrant-pcode: L6Y 2P7 registrant-state: ON registrant-city: Brampton registrant-ccode: CA registrant-phone: +1.4168766007 registrant-email: [email protected] admin-c-firstname: Surinder Singh admin-c-lastname: Pama admin-c-organization: canadian punjabi international inc admin-c-street1: 165 Morton WAY admin-c-pcode: L6Y 2P7 admin-c-state: ON admin-c-city: Brampton admin-c-ccode: CA admin-c-phone: +1.4168766007 admin-c-email: [email protected][/quote]
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

Pages