Re: The Phish that isn't Going Away

"Mike Easter" <[email protected]> Thu, 11 May 2006 18:40:19 -0700
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
Porpoise wrote:
> "Mike Easter"
>> spamacyde wrote:
>>
>>> It offers up a cookie and I rejected  it.  How much damage could
>>> the cookie have done?
>>
>> Cookies cannot do damage.  http://en.wikipedia.org/wiki/HTTP_cookie
>> An HTTP cookie, or a Web cookie, is a parcel of text sent by a
>> server to a web browser and then sent back unchanged by the browser
>> each time it accesses that server.
>
> Err..... Mike, would you like to re-phrase that comment?  Cookies can
> and do cause damage:
>
> http://www.peacefire.org/security/iecookies
> http://www.cookiecentral.com/dsm.htm
> http://www.donkboy.com/html/priv1.htm

Those are all information about information leakage by cookie
mismanagement, not 'damage'.  The article I cited discusses that and
other cookie hazards.

6 Drawbacks of cookies
6.1 Inaccurate identification
6.2 Cookie theft
6.3 Cookie poisoning
6.4 Cross-site cooking

> Q.10. Do "cookies" pose any security risks?:
> http://www.w3.org/Security/Faq/wwwsf2.html
>
> DoubleClick immediately springs to mind........

The original question was "It offers up a cookie and I rejected  it.
How much damage could  the cookie have done?"


-- 
Mike Easter
kibitzer, not SC admin