Instagram: Running IG bots with Session Cookies

f1ndm3h

Regular Member
Joined
Apr 13, 2013
Messages
238
Reaction score
56
Hi guys,

I am back to IM for a while now and trying to boost myself to the world of IG marketing and botting. I've seen lots of people recommending the use of session cookies to avoid verification loops etc. I do not get the good benefit of it.

For me it's a really bad idea because:
  • Session cookies are usually tied to a device/system.
  • Using them with another device (a bot emulates a phone for example) or browser -> not a good idea.
    • It means that the session cookies of the account have been hijacked/stolen/sold etc.
    • A normal user would never place their cookies to the device (technically super difficult, needs to be rooted etc) or the browser.
    • I think it's a big red flag!

So, what is everyone's take on this?

PS: I want good technical or empirical answers please.
 
So, what is everyone's take on this?

Session Cookies are tied to System/Device/App Version, that's correct! Nearly everyone is backuping their phone data. Do you know how many people are switching their phones on a regular basis? Many! For example: display cracks. They will send their phones to repair and get an exchange device for some days. These exchange device has a different Device ID and maybe a complete different System environment. But what is the normal user doing? He's using his backup for the exchange device -> same Cookie Session.

Import Session Cookies are not directly a big red flag. You need to know how the game works!

Switching Sessions between mobile device ids is totaly normal and it's not suspicious.
Switching from mobile id to browser id doesn't make sense at all!

Even if most people would never import their session on a technical base, they are switching a lot between different phones (broken, new ones...).
 
Session Cookies are tied to System/Device/App Version, that's correct! Nearly everyone is backuping their phone data. Do you know how many people are switching their phones on a regular basis? Many! For example: display cracks. They will send their phones to repair and get an exchange device for some days. These exchange device has a different Device ID and maybe a complete different System environment. But what is the normal user doing? He's using his backup for the exchange device -> same Cookie Session.

Import Session Cookies are not directly a big red flag. You need to know how the game works!

Switching Sessions between mobile device ids is totaly normal and it's not suspicious.
Switching from mobile id to browser id doesn't make sense at all!

Even if most people would never import their session on a technical base, they are switching a lot between different phones (broken, new ones...).

Interesting view. I am not sure whether transferring your IG app to another new device would hold the cookie. I think nowadays, only the app itself will be transferred and you will have to relogin - I think so!.

In terms of switching from mobile to browser, I think it makes sense! Again people could be normally switching or using both, why not? You just need to login again asking for new session. What if your phone's battery is out of charge and you urgently login from browser? :)

Thanks for your response, interesting input!
 
So whats the benefit in botting? Since those accounts are way more expensive than regular ones.
 
My bad, im tired. Whats the benefit to buy IG accounts with cookies?

I don't know to be honest, I just saw many people are using cookies. I just bought some accounts from a provider and they give you cookies as well. I still login with credentials and try using IPv4 proxies.
 
I think nowadays, only the app itself will be transferred and you will have to relogin - I think so!.
Nope, for example: iOS is backuping the whole file system of the iPhone. Credentials and Sessions are within the backup. If you restore a backup your automatically logged in at FB, IG...

In terms of switching from mobile to browser, I think it makes sense! Again people could be normally switching or using both, why not?
My answer was based on importing cookie sessions. It doens't make sense to import mobile cookie session into a browser. If you're owning a PC/Laptop it's a normal behavior to log in at the browser with your credentials to create a new session just for the browser.

My bad, im tired. Whats the benefit to buy IG accounts with cookies?
If you bought accounts and you log in with the credentials, you may trigger EV/PV for security reasons. IG has some security triggers to prevent abusing, because they want to ensure that you're the real owner. To bypass these triggers you can import the cookies. Adding accounts with imported cookies get less security triggers. At the end of the day it saves a lot of time when you botting mass accounts.

I just bought some accounts from a provider and they give you cookies as well. I still login with credentials and try using IPv4 proxies.
If you're not hitting the security triggers receiving EV/PV then everything is fine :) You don't have to worry.

@ownz btw which bot do you use ?
My own, it's selfcoded.
 
Nope, for example: iOS is backuping the whole file system of the iPhone. Credentials and Sessions are within the backup. If you restore a backup your automatically logged in at FB, IG...


My answer was based on importing cookie sessions. It doens't make sense to import mobile cookie session into a browser. If you're owning a PC/Laptop it's a normal behavior to log in at the browser with your credentials to create a new session just for the browser.


If you bought accounts and you log in with the credentials, you may trigger EV/PV for security reasons. IG has some security triggers to prevent abusing, because they want to ensure that you're the real owner. To bypass these triggers you can import the cookies. Adding accounts with imported cookies get less security triggers. At the end of the day it saves a lot of time when you botting mass accounts.


If you're not hitting the security triggers receiving EV/PV then everything is fine :) You don't have to worry.


My own, it's selfcoded.
Thanks for all responses, very good information!

I didn't know this for iOS I am mainly Android user, interesting.
 
Session Cookies are tied to System/Device/App Version, that's correct! Nearly everyone is backuping their phone data. Do you know how many people are switching their phones on a regular basis? Many! For example: display cracks. They will send their phones to repair and get an exchange device for some days. These exchange device has a different Device ID and maybe a complete different System environment. But what is the normal user doing? He's using his backup for the exchange device -> same Cookie Session.

Import Session Cookies are not directly a big red flag. You need to know how the game works!

Switching Sessions between mobile device ids is totaly normal and it's not suspicious.
Switching from mobile id to browser id doesn't make sense at all!

Even if most people would never import their session on a technical base, they are switching a lot between different phones (broken, new ones...).

All most all proxies are using with those browsers as those are socks or http.

your qustion would be what proxy provider is good for X site

Your answer depend on the service not the browser.

You must mention whats the purpose / site and someone will give you an accurate answer



Where can I find IG accounts for sale with Cookie / Session ID?
 
@stevehol next time pick topic from year 2016. I havent seen token based account around here but you can try hstock marketplace, there you will find ones
 
Session Cookies are tied to System/Device/App Version, that's correct! Nearly everyone is backuping their phone data. Do you know how many people are switching their phones on a regular basis? Many! For example: display cracks. They will send their phones to repair and get an exchange device for some days. These exchange device has a different Device ID and maybe a complete different System environment. But what is the normal user doing? He's using his backup for the exchange device -> same Cookie Session.

Import Session Cookies are not directly a big red flag. You need to know how the game works!

Switching Sessions between mobile device ids is totaly normal and it's not suspicious.
Switching from mobile id to browser id doesn't make sense at all!

Even if most people would never import their session on a technical base, they are switching a lot between different phones (broken, new ones...).
Thank you for your take in this. This is interesting!
 
Hi guys,

I am back to IM for a while now and trying to boost myself to the world of IG marketing and botting. I've seen lots of people recommending the use of session cookies to avoid verification loops etc. I do not get the good benefit of it.

For me it's a really bad idea because:
  • Session cookies are usually tied to a device/system.
  • Using them with another device (a bot emulates a phone for example) or browser -> not a good idea.
    • It means that the session cookies of the account have been hijacked/stolen/sold etc.
    • A normal user would never place their cookies to the device (technically super difficult, needs to be rooted etc) or the browser.
    • I think it's a big red flag!

So, what is everyone's take on this?

PS: I want good technical or empirical answers please.

I moved from logging in every time to using and saving sessions and cookies and it makes a world of difference.

First there are not many users that log in daily to do some actions and then log out, second if you are using mobile useragents then it makes no sense at all to log in and out every time, also I have seen that I lose much less accounts per day.
 
Back
Top