Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 06-03-2007, 09:13 PM   #1 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default Is this possible?


Today my sister's orkut account got hacked and some other person was replying with her account on other's scraps. When my sister logged on and asked her who he was and how did he do this? He replied that you recently clicked some javascript link in your browser and cookies from the browser got transferred to his pc. And now he does not need user id and passwords to login to my sis's account. Is it possible. My sis got the password changed and he again logged back in. He reconfirmed that password change won't stop him. Is this possible?

And how to prevent this. As a precautionary measure I have removed complete firefox profile folders of my sister. I am using latest Firefox 2.0.0.2.
navjotjsingh is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 06-03-2007, 09:21 PM   #2 (permalink)
Alpha Geek
 
shashank4u's Avatar
 
Join Date: Jan 2006
Location: Online
Posts: 686
Default Re: Is this possible?

i think u shud change the browser settings to default...
and i think after the password change he wud not be able to login in yr sis account.
also check for spyware,keyloggers.
__________________
Be like a postage stamp-stick to one thing until you get there.
shashank4u is offline  
Old 06-03-2007, 09:30 PM   #3 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default Re: Is this possible?

i think,

simply some how ur sis was manage to leak out her password or some one guessed it

well thats my view only
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 06-03-2007, 09:38 PM   #4 (permalink)
Security Exp
 
47shailesh's Avatar
 
Join Date: Apr 2006
Posts: 734
Default Re: Is this possible?

Hmm...

First a brief intro about GUID (Globally Unique Identifier)...

Whenever u click "remember me" on login based site a cookie is created with a GUID in it...this cookie stores password and username in it, so that user can be identified on the basis of GUID on his/her return....

GUID is a unique string..

Now getting back to question....

When ur sis clicked on an AD or on JS then those scripts executes and search for GUID in the cookie folder...

If they get one they stores it and return to there MASTER hehe in ur case to that prank....

Solution: clear all cookies... get the password change ur r safe then...

And too use Spybot search and destroy + AdAware to detect for any maleare present in ur system....

__________________
We Love Once, And When We do We do it Well
47shailesh is offline  
Old 06-03-2007, 09:42 PM   #5 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default Re: Is this possible?

More Interesting Info...my sis never uses remember be option. I suggested her using long before since time gets wasted in typing again and again but she never listened.
navjotjsingh is offline  
Old 06-03-2007, 09:48 PM   #6 (permalink)
Security Exp
 
47shailesh's Avatar
 
Join Date: Apr 2006
Posts: 734
Default Re: Is this possible?

That is the most probable attack by JS that i have mentioned...

If that not the case then there can be N guesse for the reason...
__________________
We Love Once, And When We do We do it Well
47shailesh is offline  
Old 07-03-2007, 12:24 PM   #7 (permalink)
Wise Old Owl
 
piyush gupta's Avatar
 
Join Date: Sep 2005
Location: never land
Posts: 1,284
Default Re: Is this possible?

If clearing cookies and changing password are not working check your system for malwares

i m sure this person is using some evil scripts for your account login
just a guess

Can he access your other account e.g gmail,yahoo etc.
piyush gupta is offline  
Old 07-03-2007, 05:55 PM   #8 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default Re: Is this possible?

Well he hasn't logined today...I guess its safe now. And no malwares on my PC. I am dead sure.
navjotjsingh is offline  
Old 07-03-2007, 06:13 PM   #9 (permalink)
Security Exp
 
47shailesh's Avatar
 
Join Date: Apr 2006
Posts: 734
Default Re: Is this possible?

^Congrats
__________________
We Love Once, And When We do We do it Well
47shailesh is offline  
Old 07-03-2007, 06:37 PM   #10 (permalink)
Wise Old Owl
 
piyush gupta's Avatar
 
Join Date: Sep 2005
Location: never land
Posts: 1,284
Default Re: Is this possible?

@navjotsingh

i think he just luckly enterd into your sis account

now u r safe

enjoyy

cheers
piyush gupta is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by clmlbx
- by abhidev
- by Sarath
- by ico
- by clinton

Advertisement




All times are GMT +5.5. The time now is 02:38 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2