Protecting against Neopets Cookie Grabber (CGer) Guide

Welcome to the in-depth guide to avoiding cookie grabbers. This page has been generated from background information of how it works, reverse engineering of various neo CGs and 1st hand research. (plus losing 800k + trades along the way, but hey, it's priceless!!)

[SHORT VERSION]

For the in-depth version, please see http://www.neopets.com/~punchback_bob
Remember that Internet Explorer is vulnerable to on-site cookie grabbers (on neopets)
Opera users should use the userjs file called BlockScript. It's sorta complicated but it's here

Get firefox here: http://www.mozilla.com/en-US/firefox/firefox.html?from=getfirefox

Recommended Firefox Add-ons
"NOSCRIPT" This helps block malicious scripts from running. 
Don't forget to whitelist neopets.com and any other sites that you trust (like hotmail.com) (see attachment)

FLASHBLOCK This allows you to selectively load adobe flash player objects. If you need flash to play games, simply click the arrow to enable that object. This is allowed since most browsers don't even come with flash. Do not whitelist neopets as one type of CG uses a redirection of http://images.neopets.com/flash_version_check_v1.swf? to steal cookies.

KEYSCRAMBLER ADD-ON. For protection against key loggers (programs that record everything you type) It's no use changing your password if every key you press is being sent to the "hacker"

ADBLOCK. It allows you to block ads... and other things (like CGs) See attachment for more info

REQUESTPOLICY. RequestPolicy is an extension that improves the privacy and security of your browsing by giving you control over when cross-site requests are allowed by webpages you visit.

 

Think you got CG'd?

If you THINK you were CG'd, the first you should do is LOG OUT. Why? Because this invalidates the cookie that the "idiot" took. Try it yourself. Log into neo in another browser. You will see that you can browse neopets for a bit on both web browsers. Now click the log out button of one browser and see what happens. Contrary to popular belief, clearing cookies will do nothing for you. Just log out, get the keyscrambler add-on (if you can get it), and then log back in and THEN change your password

 

AttachmentSize
Image icon whitelist-neopets.gif74.73 KB
Image icon ablock-instructions.gif43.8 KB
Forums: 

[quote=misslegzz]yes I had everything pinned and they still got my pets and nps. I have no script as well. Apprently gmail may be the source, I really can't tell you what happened. I know I didn't go to any sites that are malicious. only sites I went to was JN and sunny. if anyone has gmail assosiated with their acc I would suggest changing it.[/quote] Your problem is higlighted in bold. Sunnyneo is a joke, they wont even update their shop layout codes. Chad's Bakery http://www.neopets.com/browseshop.phtml?owner=desperately_yours
525,600 Minutes http://www.neopets.com/browseshop.phtml?owner=desperately_yours&misc

Has anyone ever had all of their add-ons like no script and flashblock disappear? Should I be worried? =/ We weren't born to follow ♥
Spare a CC vote please? :* http://www.neopets.com/games/caption_browse.phtml

My ad block erased itself of all the ads I had blocked about a week ago. I've mostly got them all back, I just need the code to get rid of the nickelodeon bar.

): My Neopets account was hacked

If TNT made an Item "The Littlest Violin" and gave it to every account that got CGed as a "Help Rebuilding" (Which they'll never do, just play along) How long do you think till it'd deflate XD Enough accounts get hacked I'd bet it would be worth a couple K within a month of release. --- Step outside, take a breath of fresh air, then look down to see if you have a new text message.
[color=Gray]Good Idea: Feeding stray kittens in the park. Bad Idea: Feeding stray kittens in the park... to a bear.[/color]

I'm using a MAC so I can't use the keyscrambler. Does anyone know of any others that would be compatible? http://www.neopets.com/browseshop.phtml?owner=evilbluemunkeyz
http://www.neopets.com/browseshop.phtml?owner=evilbluemunkeyz

You're pretty much safe. key loggers are often PC based
----------------------------- [color=purple]Protect your account[/color] http://www.neopets.com/~punchback_bob CG information & more

I'm seriously wondering if I got CG'ed. My main account had the pw changed on it when I went to log in, got locked out, then reported it to neo to get my account back. In the meantime, I lost about 8 million NPs, (bank, till, stocks) and MANY morphing potions, expensive stuff etc. I only had about 100K left, which I consider fortunate, and my shop was not touched, neither was my gallery. My sister said the "stalker bar" (bar on the L side that tells your NFs that are on) said I was on when she knew I wasn't (but sometimes it malfunctions). I didn't fall for any fake logon pages, or use a stupid p/w, or send my p/w/PIN to anyone. I did get randomly logged out the previous day, which I thought was wierd. I know that if someone logs on to the same account on a different PC, it logs the original user off. I wonder if that is when the CG'er user tried to log on? I also (stupidly) had the same p/w on my sides and lost bith of those, working on getting one back, but the other I haven't heard about yet... and that one has my cybunny on it :(. That was really the only important thing I have one it. I got a interesting NM after it happened: i was just coming to mail you to ask what happened to me, but i saw this "Apologies all, my account was accessed/hacked May 13th, most of my NPs are gone (over 8 million), Many expensive items were stolen as well. Thank you 2 my 2 Wonderful Neofriends for your gifts. You know who you are In the course of restoring my account, TNT deleted my neofriends, so if you were my friend before, send me a new request please, and send me a note requesting to be my NF, so I know you actually visited my lookup" [Note I have posted on my user lookup] on friday, this/your account gave me about 4million nps, not to this account to my main. My account was frozen about a week ago for profanity and a few friends on the boards were giving/lending me a few nps, i couldnt and still cant remember all my nfs on there and you/your account offered me some nps to start off with, told me they would put some cheap items in your shop too, then poof my account was gone and i kept logging in but it wouldnt allow me, i mailed tnt, but i didnt get a mail back, then i logged in yesterday + my account was frozen for attempting to scam, :/ so i was just mailing to say i think i may have your nps on my account.. but until i get it back theres no way of giving you back :/ --------------- Interesting they possibly owned up to recieving the NPs. Anyhow, I guess I'd better go better go get firefox and the add-ons *sigh* Any comments on my rather long winded post?

I hate GCs. it's giving me nightmares, WHILE IM AWAKE!!!!!!!!!!!!! i didnt get hact on neopets but i got hacked on xbox live! oh the horror, THE HORROR! o no im having another nightmare! so if u want to help me acualy be able to do somthin in life (cause i get told i suck alot) just send me a neomail at http://www.neopets.com/neomessages.phtml?type=send&recipient=coolway1999

im gonna switch to ff. anyways who thinks this is a good idea: lets hack the hackers!

Pages