How Ebay, Paypal & co can track your identity - local stored objects

justone

BANNED
Joined
Oct 12, 2008
Messages
1,520
Reaction score
1,054
Most blackhatters are marketing guys, people looking to make money online and not security gurus.
Here I cover a "newer" part of internet security that is used by many big companies to track your identity.
The best proxy will not help to hide your identity if you lack knowledge about modern tracking techniques.

I am sure most people here already know what a cookie is and how to remove a cookie, I'll not get deeper into that.
But I'm sure a lot of users have no clue that there is another more sneaky way to place files on your computer that can NOT be removed by using browser features.

These objects (LSO) are also called Flash cookies.
"Flash cookies" because they are stored by an addon found in almost all browsers, the Adobe Macromedia Flash player. Frequently used to create animations or play movies on your browser.

The Flash player has a privacy ignorant function, it allows to store up to 100kb per website in a local file. This file is OUTSIDE of your normal browser folders and your browser does not even know about it.
A normal cookie is limited to a few kb and can easily be removed, flash cookies are evil and hide on your computer.

I've prepared two plugins here: http://www.cloakfish.com/?tab=howto#howto_remove-flash-cookies

On the left side you see all your flash cookies, the right side offers you a checkbox to stop your flash player from storing cookies.

If you never heard about flash cookies before, or did not know details about them you might be shocked about the hundreds or thousands of files that are stored on your computer without your knowledge.

Wearing the black hat means you are one step ahead, I hope this information helps you to keep distance ;)
 
Thanks for sharing this mate, I did not know that. Just checked my "Flash Cookies" and there were shitloads of them on my computer.
 
Wow. Did not have to many on my computer, but they were there! Thanks for the heads up!
 
Addendum:

If you want to manage how they are processed and used you can go to Adobe to take care of it. Apparently, the only way you can manage flash cookie setting is through the adobe site (so other programs are just doing it by proxy). Sorry to burst the bubble on this post or program, but it got me interested and thinking...
Code:
http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager06.html
 
Thanks for the heads up, but you can accomplish the same thing without having to pay for a license if you install the FF plugin Objection. Just tried it and it took care of all of them.

Code:
http://objection.mozdev.org/

You don't have to pay to remove the flash cookies just if you want a license for cloakfish

at the bottom of th page you can delete and change settings
 
You don't have to pay to remove the flash cookies just if you want a license for cloakfish

at the bottom of th page you can delete and change settings


Sorry, I must have missed that. I thought you had to buy a license the line:

Need a license ? Get one here ! Cheap introduction prices. Starting at 1$

made me think you had to pay to get one, so I didn't click through. Didn't see that you could get a free account.
 
C:\Documents and Settings\YOURUSERNAME\Application Data\Macromedia\Flash Player
 
Good info anyway. Never knew that ebay and paypal is doing that.
 
What a great post! Two thumbs up to Midknightg for the firefox addon headsup. I downloaded it and Holeeeee Shit!!! I was loaded on both computers. This will become a regular part of my daily maintenance routine.
 
It looks like anonymizeit removes the link bookmark
The full url i posted is
Code:
http://www.cloakfish.com/?tab=howto#howto_remove-flash-cookies
When you click it as link from the forum, anonymizeit will remove the # part, because of that you landed on the TOP of the page instead of the BOTTOM.
 
one of sites where I create multiple accounts left flash coockies. I was wandering how they detect I'm back .... Most funny thing I know about this flash cookie stuff. I don't know why don't check it before. Any way it's speed up my cleaning :)
 
Where is the physical location for flash cookies? I am using different user profile to logging to egay seller account. Are flash cookies common for all user account is it is separate for each user profile?
 
I think it's common among all browsers because it uses a central place.
it's in your Documents and settings -> Application Data\Macromedia\Flash Player\ folder
 
So do I need to go to Macromedia's website to remove these or can I just nuke a folder on my hard drive?

I think it's common among all browsers because it uses a central place.
it's in your Documents and settings -> Application Data\Macromedia\Flash Player\ folder

I have 4 folders inside of my ..\FlashPlayer\ folder:

-#security
-#shared objects
-www.macromedia.com
-macromedia.com

Which "folder" do I nuke? Is it as simple as that or will that take out some vital data as well?
 
For windows you might want to try these folders:

C:\Documents and Settings\USER*******\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys

and

C:\Documents and Settings\USER*******\Application Data\Macromedia\Flash Player\#SharedObjects

That plugin didnt really work too well for me. When i try to save the settings it didnt work.
 
This freaks me out because it makes me wonder what else they're using for tracking that we don't even know about yet!
 
Physical deleting this two folder will remove the flash cookies
 
Back
Top