Remember to delete (or eat) cookies regularly !!!

1667592194_425417_gif-url.gif
 
Microsoft365/outlook is generally primary targets. These are easier with phishing links.
 
curios, how does that work
Like a client of mine downloaded some game for free from some random website.

The next day his ecom store was hacked, all his emails reported suspicious login, his facebook account was suspended, his vps hosting account and server both were compromised, cloudflare account was compromised, bank accounts were safe due to their security algorithm that prevented suspicious login from a foreign country etc...

Turns out he stores all his login and passwords in chrome and the game he downloaded was compromised that gave the hacker access to his pc.
 
Are there any signs that indicate when a cookie has been compromised?
 

Cybercriminals Are Stealing Cookies to Bypass Multifactor Authentication​

https://www.fbi.gov/contact-us/fiel...-cookies-to-bypass-multifactor-authentication

I mean, if regular browsers would have such a feature, it would be quite a big vulnerability.

It was early 2008'-ish if I recall correctly when I did such attacks and was able to harvest cookies by getting people visit my domains

nowadays if you don't download anything, I'm not sure of how it would be possible to get access to cookies in such way, thats why I did ask, as I think this statement is wrong

it would make more sense for installing malicious browser extensions

other than that - yeah, keep your cookies safe, while its quite a challenge to not only obtain them but replicate the system params to be able to read them and load them up for use, its still doable, yeah
I read the article... Ahhh, I get it. It's like this built-in feature in RATs, right? You can steal the cookies, not only passwords, cc numbers, etc. The article doesn't say if the victims downloaded a file and got infected with a RAT or it's just from clicking - exploits like these exist too but these are paid (I mean full featured RATs too, more often than not, it's a whole economy). Nothing new in this article, idk.
 
It’s easy to overlook, but regularly clearing cookies is crucial for staying secure, especially with cybercriminals finding new ways to bypass MFA. I try to make it a habit to clear them every couple of weeks and always avoid using “Remember Me” on sensitive accounts. Better safe than sorry.
 
just use KeePassXC and brave web browser and set it to delete everything on exit
 
I read the article... Ahhh, I get it. It's like this built-in feature in RATs, right? You can steal the cookies, not only passwords, cc numbers, etc. The article doesn't say if the victims downloaded a file and got infected with a RAT or it's just from clicking - exploits like these exist too but these are paid (I mean full featured RATs too, more often than not, it's a whole economy). Nothing new in this article, idk.
Yup, nothing new but it's a nice reminder for peeps
 
curios, how does that work



Cookies are by far not the things to consider. I had to look 3x if the Date of this Article is 10 years old or not.

Cookies / Session Stealing / Downloading Stuff: If you are unaware of the Source, running it on a Local Machine is far worse.
An example that I reported today is SSL Pinning.
There are many ways to capture the 2FA - but at the end of the Day, it depends on the user most likely to get phished (in many cases): Download a good Browser, hide trackers, use a Local Machine not to run any weird Scripts, either in Virtual Box, Strong passwords (different) on different pages, use a password manager & don't safe them in your Browser, turn off auto download in your messengers, don't permit everything - even if it looks legit - give it when you are forced to & it makes sense, turn on Firewall & Malwarebytes (Premium), run files or links through virus total if they seem suspicious. Use 2FA wherever you can; E-Mail is better than nothing, Mobile is better, and Hardware Token is even better.
Use your Brain while being online - that's what I tell my mother sometimes, in case she clicks around again.
With this approach, you avoid at least half of the obvious. Scams.
If someone wants to hack you or get traffic, they can do so through Discord, Telegram, or whatever.

This post is not addressed to @lucky.sparks , or OP.
Just casual "How to prevent Script Kiddies 101"

Still; lucky.sparks comment was funny.


Best,
zotix
 
Wait you aren't supposed to "click here, you've won iPhone 16" ads?

Ah.
Unfortunately, I did not receive those kinds of ads. But once, a single hot mom in my area wanted to date me.
After starting to chat with her, she asked me for a phone call.
Since then, we get weird phone bills and a lot of physical newsletters (adult), which is a bit odd.
Maybe I will call her with another number again and ask her for a date because she was so busy and somehow her profile picture disappeared.
 
I see what you mean, most of the time people just let the website remember the account and password to save time, and hackers use this cookie to steal information
 
why tho? Can you explain how by simply visiting a malicious site you could get your Paypal cookies stolen?
Good morning. Do you take this question seriously? I mean you are a smart person - I think you understood the reaction to the emoji wrong.
If this is a serious question, there is one example in my post and I can give you 10 more - without any chatgpt chitchat,.

Best regards,
zotix
 
Good morning. Do you take this question seriously? I mean you are a smart person - I think you understood the reaction to the emoji wrong.
If this is a serious question, there is one example in my post and I can give you 10 more - without any chatgpt chitchat,.

Best regards,
zotix
My question? Yes, I mean it seriously. Yes, perhaps I misunderstood something here. Can you give only 1 example?
 
curios, how does that work
Not possible without downloading anything. Despite OP's good intention in sharing this advice, FBI is a poorly reliable agency, based on its history it's hard to believe in anything they say. It seems they are trying to spread lies with this idea of visiting a website and get instantly infected without downloading anything, imagine if it was real, just use ads and infect thousands of people per day just by getting traffic. Woudln't it be quite profitable for them? Just run some pop ads and boom, millions of cookies stolen by visiting a website without any interaction from the user.

But yes, be careful about what you download
 
Back
Top