Protecting against Neopets Cookie Grabber (CGer) Guide

Welcome to the in-depth guide to avoiding cookie grabbers. This page has been generated from background information of how it works, reverse engineering of various neo CGs and 1st hand research. (plus losing 800k + trades along the way, but hey, it's priceless!!)

[SHORT VERSION]

For the in-depth version, please see http://www.neopets.com/~punchback_bob
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other things (like CGs) See attachment for more info

REQUESTPOLICY. RequestPolicy is an extension that improves the privacy and security of your browsing by giving you control over when cross-site requests are allowed by webpages you visit.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

AttachmentSize
Image icon whitelist-neopets.gif74.73 KB
Image icon ablock-instructions.gif43.8 KB
Forums: 

http://www.neopets.com/browseshop.phtml?owner=lovehome_6&buy_obj_info_id=8537&buy_cost_neopoints=3500& I went to this shop to buy an icy negg and above it in the shop description there's a picture of another negg, with the price etc, but it links to a petpage. Would this be a CG I came across? I didnt click the link on the item though!

[quote=angel_shortcake]http://www.neopets.com/browseshop.phtml?owner=lovehome_6&buy_obj_info_id=8537&buy_cost_neopoints=3500& I went to this shop to buy an icy negg and above it in the shop description there's a picture of another negg, with the price etc, but it links to a petpage. Would this be a CG I came across? I didnt click the link on the item though![/quote] I don't think so... I used to see a lot of things like that around. They're usually just for fun (but are actually kinda stupid). I might be wrong though; don't click it just in case. XD The Preschool Mall: Petpet Paradise http://www.neopets.com/browseshop.phtml?owner=mizleah

No it's one of those dumb "Kindness Unlimited in stock. Price: Priceless" fake item things.. except this one is in another language. The petpage lists the codes to get these dumb things :P --------------------------------------------- Celebrate [color=red]Xmas[/color] at [color=green]Xmart[/color]. Buy a tent for your pet today! http://www.neopets.com/browseshop.phtml?owner=dmitri_stanislaus
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

I heard somewhere that there is a Firefox addon that emulates IE, I can't remember if I read it here or somewhere else. I love FF but I need IE at work for the custom program I use and FF will not let the program work properly

[center] Yeah, there is. Its called IE tabs, or something like that. Its very handy. https://addons.mozilla.org/en-US/firefox/addon/1419 Thats the version I'm using, I think. I see there is a new one listed too: https://addons.mozilla.org/en-US/firefox/addon/10909 Looks like it might be a better version, but I've not used it, so I can't vouch for it. ------------------------------------------------------------------- [url=http://www.neopets.com/browseshop.phtml?owner=raine_storme&misc]~~ Come visit my map shop ~~[/url] [/center]
[center] ------------------------------------------------------------------- [url=http://www.neopets.com/browseshop.phtml?owner=raine_storme&misc]~~ Come visit my map shop ~~[/url] [/center]

awesome, that is just what I need! Thank you!

[quote=Dmitri]It appears that alot of people are getting Cookie grabbed recently so I figured this thread might help reduce it. Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)Opera users should use the userjs file called BlockScript. It's sorta complicated but it's hereGet firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox Recommended Firefox Add-ons"NOSCRIPT" This helps block malicious scripts from running.  Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies. KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"ADBLOCK. It allows you to block ads... and other crap (like CGs) See attachment for more infoBLOCKSITE - this prevents certain websites from loading completely so if you were unfortunate to click on a CG site by accident, it wont load. Not supported for firefox 3.5 Subscription service for this add-on will be added on neomallers as soon as support is added.  Think you got CG'd?If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on, and then log back in and THEN change your password As for neomallers, everything is auto blocked which is why you guys can only use boring black text (no fancy colors, etc) and it also explains why some online parts of this site are so strict in terms of what you can type in :P If you're worried, you can also block scripts and flash on neomallers but keep in mind that the other_counters page may not work properly since it uses javascript to confirm whether or not you plan to delete the counter, etc If anyone has any other tips (or corrections to this post) , feel free to post P.S. For those of you wondering, this post is an exception. I temporarily disabled filters for this particular post only. NeoMallers Anti-CG Adblock ServiceNeoMallers now runs its own adblock subscription service. To enable this, follow the steps:1. Click Tools. Then add-ons. Select Options on Adblock.2. Click Filters Menu. Select Add Subscription. Click the button Add a different subscription at the bottom. 3. Type in NeoMallers in the firstbox and http://cookiejar.neomallers.com/newbs.txt in the second box4. Click subscribe. Whenever you need to update (it should do it automatically as well), right click NeoMallers and choose update.  [/quote] Some times when you post things like this I think my computer is going to explode or something. *lol*
http://www.neopets.com/browseshop.phtml?owner=fearce_dragon_hunter Sorry about not having a mall banner in. I lost it. :( So I'm making a new one.

Thank you so much for this information. I am grateful to know what to do when twice now this week the lowest price on the super shop wiz took me to a store that does not exist. Something *really* fishy about that.

bumping this up again -------------------------------------------------------------- [url=http://www.neopets.com/pirates/smugglerscove.phtml?thanks=24698]Get a SuAP[/url]
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

[quote=saudor]It appears that alot of people are getting Cookie grabbed recently so I figured this thread might help reduce it. Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)Opera users should use the userjs file called BlockScript. It's sorta complicated but it's hereGet firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox Recommended Firefox Add-ons"NOSCRIPT" This helps block malicious scripts from running.  Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies. KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"ADBLOCK. It allows you to block ads... and other crap (like CGs) See attachment for more infoBLOCKSITE - this prevents certain websites from loading completely so if you were unfortunate to click on a CG site by accident, it wont load. Not supported for firefox 3.5 Subscription service for this add-on will be added on neomallers as soon as support is added.  Think you got CG'd?If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password As for neomallers, everything is auto blocked which is why you guys can only use boring black text (no fancy colors, etc) and it also explains why some online parts of this site are so strict in terms of what you can type in :P If you're worried, you can also block scripts and flash on neomallers but keep in mind that the other_counters page may not work properly since it uses javascript to confirm whether or not you plan to delete the counter, etc If anyone has any other tips (or corrections to this post) , feel free to post P.S. For those of you wondering, this post is an exception. I temporarily disabled filters for this particular post only. NeoMallers Anti-CG Adblock ServiceNeoMallers now runs its own adblock subscription service. To enable this, follow the steps:1. Click Tools. Then add-ons. Select Options on Adblock.2. Click Filters Menu. Select Add Subscription. Click the button Add a different subscription at the bottom. 3. Type in NeoMallers in the firstbox and http://cookiejar.neomallers.com/newbs.txt in the second box4. Click subscribe. Whenever you need to update (it should do it automatically as well), right click NeoMallers and choose update.  [/quote] you forgot to say report them. And this is a very serious problem, not just for your np accounts, but for your real life. Once someone has access to your np account they have your name, birthday, e-mail, and any other personal info you have which they can use to steal your real identity. Losing neopoints, sad, losing real money, choas.

Pages