HELP: Cookie stealing support(me as a victim)

<<

distroyer

Newbie
Newbie

Posts: 1

Joined: Fri Dec 28, 2007 11:16 am

Post Fri Dec 28, 2007 11:29 am

HELP: Cookie stealing support(me as a victim)

Hi,

I was going through a hacked community on orkut which was originaly my frnd's community, in one of the links i found a javascript which if i put in the address bar and press enter, it wld add me as a moderator of any community. Sounds interesting!! But when i suddenly thought cant that be a mis-chief made by someone????? So, i searched into google and found that type of cookie hacking does exist on orkut (pasting such javascript into address bar hacks account).

The js was like:

  Code:
[b]

javascript:a=document.forms[1];a.action="CommMembers.aspx?cmm=34431350&Action.addModerator&memberId=11520216688680582958";a.submit();void(0) [/b]


Now, my question is, if i clear my cookies, for how long will my cookies be sent to the attacker?? or is there any file that is stored in my computer that keeps sending my cookies to the attacker??? how do i get free from if my cookies are hacked?? OR does it send only once

Thnx!!
<<

venom77

User avatar

Hero Member
Hero Member

Posts: 1911

Joined: Mon Dec 11, 2006 3:23 pm

Post Fri Dec 28, 2007 11:36 am

Re: HELP: Cookie stealing support(me as a victim)

Just looking at the JS code you've supplied, it doesn't appear to be sending data to anyone (except maybe the 'CommMembers.aspx' file). It appears that it's adding a moderator of a specific account ID.

You can go delete your temporary files/cookies if you're that paranoid about it.

I could also be mis-understanding your question, please clarify if that's the case.
<<

KrisTeason

User avatar

Hero Member
Hero Member

Posts: 531

Joined: Sat Sep 08, 2007 7:48 pm

Post Sat Dec 29, 2007 3:15 am

Re: HELP: Cookie stealing support(me as a victim)

I'm as confused as you are man, my guess is he's asking about Session Hijacking?
<<

proudindian

Newbie
Newbie

Posts: 32

Joined: Mon Dec 10, 2007 3:24 am

Post Sat Dec 29, 2007 7:17 am

Re: HELP: Cookie stealing support(me as a victim)

actually if i am not wronge,the script is for managing members or appointing moderator to any community,this is not about any cookie stealing script if i am not wronge.

Return to Network Pen Testing

Who is online

Users browsing this forum: No registered users and 1 guest

cron
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software