Like a client of mine downloaded some game for free from some random website.curios, how does that work
imagine thatTurns out he stores all his login and passwords in chrome
Cybercriminals Are Stealing Cookies to Bypass Multifactor Authentication
https://www.fbi.gov/contact-us/fiel...-cookies-to-bypass-multifactor-authentication
I read the article... Ahhh, I get it. It's like this built-in feature in RATs, right? You can steal the cookies, not only passwords, cc numbers, etc. The article doesn't say if the victims downloaded a file and got infected with a RAT or it's just from clicking - exploits like these exist too but these are paid (I mean full featured RATs too, more often than not, it's a whole economy). Nothing new in this article, idk.I mean, if regular browsers would have such a feature, it would be quite a big vulnerability.
It was early 2008'-ish if I recall correctly when I did such attacks and was able to harvest cookies by getting people visit my domains
nowadays if you don't download anything, I'm not sure of how it would be possible to get access to cookies in such way, thats why I did ask, as I think this statement is wrong
it would make more sense for installing malicious browser extensions
other than that - yeah, keep your cookies safe, while its quite a challenge to not only obtain them but replicate the system params to be able to read them and load them up for use, its still doable, yeah
Yup, nothing new but it's a nice reminder for peepsI read the article... Ahhh, I get it. It's like this built-in feature in RATs, right? You can steal the cookies, not only passwords, cc numbers, etc. The article doesn't say if the victims downloaded a file and got infected with a RAT or it's just from clicking - exploits like these exist too but these are paid (I mean full featured RATs too, more often than not, it's a whole economy). Nothing new in this article, idk.
curios, how does that work
Unfortunately, I did not receive those kinds of ads. But once, a single hot mom in my area wanted to date me.Wait you aren't supposed to "click here, you've won iPhone 16" ads?
Ah.
why tho? Can you explain how by simply visiting a malicious site you could get your Paypal cookies stolen?Still; lucky.sparks comment was funny.
Good morning. Do you take this question seriously? I mean you are a smart person - I think you understood the reaction to the emoji wrong.why tho? Can you explain how by simply visiting a malicious site you could get your Paypal cookies stolen?
My question? Yes, I mean it seriously. Yes, perhaps I misunderstood something here. Can you give only 1 example?Good morning. Do you take this question seriously? I mean you are a smart person - I think you understood the reaction to the emoji wrong.
If this is a serious question, there is one example in my post and I can give you 10 more - without any chatgpt chitchat,.
Best regards,
zotix
Not possible without downloading anything. Despite OP's good intention in sharing this advice, FBI is a poorly reliable agency, based on its history it's hard to believe in anything they say. It seems they are trying to spread lies with this idea of visiting a website and get instantly infected without downloading anything, imagine if it was real, just use ads and infect thousands of people per day just by getting traffic. Woudln't it be quite profitable for them? Just run some pop ads and boom, millions of cookies stolen by visiting a website without any interaction from the user.curios, how does that work