Re: The Phish that isn't Going Away
"Porpoise" <[email protected]> Fri, 12 May 2006 16:58:20 +0100
| Newsgroups | gmane.mail.spam.spamcop.user |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
"Mike Easter" <[email protected]> wrote in message news:[email protected]... > Porpoise wrote: > > Those are all information about information leakage by cookie > mismanagement, not 'damage'. The article I cited discusses that and > other cookie hazards. > > 6 Drawbacks of cookies > 6.1 Inaccurate identification > 6.2 Cookie theft > 6.3 Cookie poisoning > 6.4 Cross-site cooking > >> Q.10. Do "cookies" pose any security risks?: >> http://www.w3.org/Security/Faq/wwwsf2.html >> >> DoubleClick immediately springs to mind........ > > The original question was "It offers up a cookie and I rejected it. > How much damage could the cookie have done?" Yes, well, as you probably gathered, the main thrust of my input was the cookie theft/cross-site cookie situation. I wonder how many users that have never visted doubleclick have their cookies in the cookie folder......... The thing is, not that the cookies can run malicious code, but that the user doesn't know whose/what cookies are being downloaded onto their systems. Also that if a hacker managed to get access to a HDD s/he could then have access to any login data stored in any of those cookies.......... as the info is in plain text.....