Remember to delete (or eat) cookies regularly !!!

Not possible without downloading anything. Despite OP's good intention in sharing this advice, FBI is a poorly reliable agency, based on its history it's hard to believe in anything they say. It seems they are trying to spread lies with this idea of visiting a website and get instantly infected without downloading anything, imagine if it was real, just use ads and infect thousands of people per day just by getting traffic. Woudln't it be quite profitable for them? Just run some pop ads and boom, millions of cookies stolen by visiting a website without any interaction from the user.
Exactly, yes. That FBI statement instantly made me raise my eyebrow. I can imagine it was written by non-technical person and meant for generic public as in idea of if they wont land on malicious sites then the next steps of downloading something bad wont happen. like "don't walk bad areas at night to not get mugged" even this isn't fully correct as there should be another user input on street to trigger the criminal activity to match the idea of visiting bad websites
 
Looks like I'm going to have to clean up the contents of my browser
 
My question? Yes, I mean it seriously. Yes, perhaps I misunderstood something here. Can you give only 1 example?
Sure, if you ask - ofc. i can give you one example:
Cross site scripting / xss exploit, could be one way: injected java script in any search bar or comment section.
This script could potentially access the cookies, without even pro-activly doing anything - just load the page.
And no download is needed for that & "HTTPS" or "HTTP" only is not the solution to prevent xss exploits.

I don't need to go further in detail, its a common method - can be googled easily and is well known.
Injection can also happen in Ads, without any download or something.
These Remember Me cookies are an example of how easy it is to grab the cookies since most of the users store their sessions to easily log in.
And the FBI is warning (again), because this is something that happens too often, its not something you recognize.

"No Script" is a nice Browser extension, can be configured for each website you visit.

I hope that answers your question, I will not go further into this topic, since this is the wrong place.

Despite OP's good intention in sharing this advice
Appreciated

Best regards,
zotix
 
Sure, if you ask - ofc. i can give you one example:
Cross site scripting / xss exploit, could be one way: injected java script in any search bar or comment section.
This script could potentially access the cookies, without even pro-activly doing anything - just load the page.
And no download is needed for that & "HTTPS" or "HTTP" only is not the solution to prevent xss exploits.
year 2008 just called and is asking your hacking methods back

I don't need to go further in detail, its a common method - can be googled easily and is well known.
you clearly don't and please stop sharing nonsense.

Injection can also happen in Ads, without any download or something.
No it cant.

I hope that answers your question, I will not go further into this topic, since this is the wrong place.
You wont not because its not the right place but simply because you cant.
 
465717858_967913408701000_4600051301270961290_n.jpg
 
Great info; I’ll definitely check it out. Do you have any more links where I can read about it?
 
Sure, if you ask - ofc. i can give you one example:
Cross site scripting / xss exploit, could be one way: injected java script in any search bar or comment section.
This script could potentially access the cookies, without even pro-activly doing anything - just load the page.
And no download is needed for that & "HTTPS" or "HTTP" only is not the solution to prevent xss exploits.

I don't need to go further in detail, its a common method - can be googled easily and is well known.
Injection can also happen in Ads, without any download or something.
These Remember Me cookies are an example of how easy it is to grab the cookies since most of the users store their sessions to easily log in.
And the FBI is warning (again), because this is something that happens too often, its not something you recognize.

"No Script" is a nice Browser extension, can be configured for each website you visit.

I hope that answers your question, I will not go further into this topic, since this is the wrong place.


Appreciated

Best regards,
zotix
httponly cookies cannot be grabbed even if you could inject some javascript code in some web page. This is why sensitive data should not be kept inside local storage or a js cookie.
 
year 2008 just called and is asking your hacking methods back


you clearly don't and please stop sharing nonsense.


No it cant.


You wont not because its not the right place but simply because you cant.
If you have your opinion, and have the knowledge - fair enough, but answer appropriately
 
the best part of the cookies is not typing the information over and over again : :weep: everything to stay safe and avoid getting hacked :anyway:
 
Back
Top