Archive for the ‘cookies’ Category

Final Post

October 2, 2009

No – I’m not dead yet!!

This is a final post at Tigerstail.wordpress.com because I am tired of seeking knowledge and bitching about that which is. It is time to use my skills to develope the solutions to all of the problems I have discovered.

Join Me at jimmicap.wordpress.com

IE8 Privacy is an Oxymoron

September 20, 2008

I could have said that the IE8 privacy function is a lie or a joke but I happen to like the word oxymoron. In my preliminary tests I was acting as if my life and future depended on my online privacy and didn’t bother doing a comparison. I found my surfing history in cache memory, that Ccleaner didn’t wipe the cache memory information and that there was a hidden system file called PrivacIE (pronounce that “Priv A C”) which contained a hashed index.dat file which was untouchable. Not a bad find for a quick survey. I did a preliminary test against Firefox 3 automatically wiping all privacy data on closing and found a few lingering cookies which Ccleaner seemed to wipe out but no cache memory of the sites I visited.

I sort of find a hashed index.dat file (in a folder called PrivacIE) and a record of my surfing history in cache memory an insulting and direct compromise of the promise of real internet privacy.

If anyone cares about the method, I’ll do a post on it.

Dissecting a Kiddie Porn Cookie

February 11, 2008

Cookies can be used to transfer information about you to a website. Now when I started to use a Live CD, I got a little bolder in tracking source code on nasty sites and not shutting down between site visits. After all no permanent images would be stored and there wasn’t all that much information which could be transferred from a machine with no permanent memory of where it had been and what it had seen.

Well I found out there is an awful lot of information in temporary storage. like a cookie from any personal site you have visited, ie gmail, hotmail, hi5, myspace, facebook etc. Since I really hadn’t thought about it and therefore wasn’t avoiding it, I was able to get a peak at what kiddie porn sites wanted to learn about me.

From over at Fatsavage.wordpress.com, the original analysis of the cookie from americanthumbs.com was:

‘ucjc=xucjcxnoref
xucjcxnoref
xucjcx1
xucjcx0
xucjcx0
xucjcx
xucjcx; path=/;’

Now after a session of Google hacking for kiddie porn, I ended up with the following cookie from billpics.com or amglover.com which both use the ucj cookie.

‘ucjc=xucjxnocookie
xucjxnocookie
xucjx1
xucjx2
xucjxnone
xucjx|teens-girls.net|mymasha.com
xucjx; path=/;’

It would seem that a couple of sites I had not suspected of kiddie porn were of interest to the people from UCJ as both of their names show up as a variables in the cookie and the variable that was a 0 has now moved up to a 2. I guess they are counting the nasty places I had been. Apparently, I was cautious in this surfing secession as the “noref” variable had shifted to “nocookie”.

When I got sloppy, the changes in the cookie got really interesting.

‘ucjc=xucjxgoogle.co.vi
xucjxhttp://http://www.google.co.vi/search?hl=en&client=firefox
&rls=org.mozilla%3Aen-US%3Aunofficial&q=hq-teens.com&btnG=Search
xucjx1
xucjx0
xucjx0
xucjx
xucjx;

Well, I sort of figured this would happen so I had turned the machine on and went nowhere else except the Google search bar. Now in addition to my IP, they have my Google cookie, the country version of Google, that I search in English, that I’m using Firefox and that I pressed the search button while looking for information on hq-teens.com.

If I had checked my Hotmail or Gmail prior to the search, they would probably have my user name and everything else.

Tag I’m it, wandering in a forest of honeypots with Federal bees swarming to sting.