1
Bezoops
how to install a cockie via signature.
  • 2005/10/11 9:19

  • Bezoops

  • Friend of XOOPS

  • Posts: 38

  • Since: 2004/12/9


Do you know how to install a cockie via signature?.
I don'nt exactly how its makes, but it is posible:

Make sure that your browser configuration ask for install a cockies.

Now go to the account of "https://xoops.org/userinfo.php?uid=10424". You can see that ask to install cockie. If you see the html code, in the signature you can read:
<img src="http://www. casinoguru. net/images/yourhelp.jpg" alt="" />

This jpg file (is it really image jpg?) install cockie with format:
your_pc_user_name @ your_server_email_account.txt.

If you put this url in your browser, after try install cockie, return to page of parked domain.

i am alarmed by this, because, can any user via links (jpg is a permited extension) insert malicius code?

2
m0nty
Re: how to install a cockie via signature.
  • 2005/10/11 12:41

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24


i see nothing wrong with that whatsoever.

the domains been parked. probably because the guy has moved servers or something. and yes it is an image, but because the domain isn't linked to a server anymore the image will not show.

you're being paranoid about nothing!

btw it's a cookie not a cockie.

3
Bezoops
Re: how to install a cockie via signature.
  • 2005/10/11 22:02

  • Bezoops

  • Friend of XOOPS

  • Posts: 38

  • Since: 2004/12/9


Sorry, now i understand. Who put the cookie (thanks for correction) is the server, ... and the image donĀ“t exist.

Exactly, this is a Resized Image paranoia.

Thanks and excuse

4
Bezoops
Re: how to install a cockie via signature.
  • 2005/10/12 8:40

  • Bezoops

  • Friend of XOOPS

  • Posts: 38

  • Since: 2004/12/9


I have done more tests. With a computer with win ME and other one with Win XP SP2. With the browsers Opera, Firefox, Netscape and IE.
Though the image does not exist, when one access to a page where it is this sigature, it tries to install the cookie of casinoguru.

If it does not ask for it, it is possible that already it is yet installed. In opera I can see it with its name, but in IE, this is the above mentioned name .

You can try with IE, with preferences->Internet option->Privacity->Advanced-> asking to install cookies, deleting all the cookies in its directory, and returning to access to the page. It asks one from XOOPS and the other one casinoguru.

It has been called me the attention, because when i am having acceded to some web sites, sometimes continuous popup windows are opened in my browser to inviting me to game in a "casino".

5
Bezoops
Re: how to install a cockie via signature.
  • 2006/1/7 9:35

  • Bezoops

  • Friend of XOOPS

  • Posts: 38

  • Since: 2004/12/9


Be careful, is not a paranioa, it is a possible security hole.

In xhnewbb forum exist a new administration option to mark:

Quote:

- Allow to display external images in the post
- If some attackers post an external image using [img], he can know IPs or User-Agents of users visited your site.



Login

Who's Online

226 user(s) are online (157 user(s) are browsing Support Forums)


Members: 0


Guests: 226


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits