Re: The Phish that isn't Going Away

"Porpoise" <[email protected]> Fri, 12 May 2006 16:58:20 +0100
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
"Mike Easter" <[email protected]> wrote in message 
news:[email protected]...
> Porpoise wrote:
>
> Those are all information about information leakage by cookie
> mismanagement, not 'damage'.  The article I cited discusses that and
> other cookie hazards.
>
> 6 Drawbacks of cookies
> 6.1 Inaccurate identification
> 6.2 Cookie theft
> 6.3 Cookie poisoning
> 6.4 Cross-site cooking
>
>> Q.10. Do "cookies" pose any security risks?:
>> http://www.w3.org/Security/Faq/wwwsf2.html
>>
>> DoubleClick immediately springs to mind........
>
> The original question was "It offers up a cookie and I rejected  it.
> How much damage could  the cookie have done?"

Yes, well, as you probably gathered, the main thrust of my input was the 
cookie theft/cross-site cookie situation. I wonder how many users that have 
never visted doubleclick have their cookies in the cookie folder......... 
The thing is, not that the cookies can run malicious code, but that the user 
doesn't know whose/what cookies are being downloaded onto their systems. 
Also that if a hacker managed to get access to a HDD s/he could then have 
access to any login data stored in any of those cookies.......... as the 
info is in plain text.....