ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Is there anything we can do to protect ourselves with these account breaches?


  • This topic is locked This topic is locked
Is there anything we can do to protect ourselves with these account breaches?

#11

Malex
Malex
    Offline
    45
    Rep
    205
    Likes

    Veteran

Posts: 405
Threads: 45
Joined: Feb 07, 2018
Credits: 0

Six years registered
#11

Can you help me understand how it work?

Do they steal your cookies while we are logged in and able to re-use that cookies on somewhere else to login? I thought once you logged in the cookies is created and they took it? even if u are in incognito mode or clear ur cookies once you done browsing?

When you log in and check the "remember me" box a cookie/cookies will be created and stored on your pc, whenever you visit nulled again the cookies will be read and you will be automatically logged in.

My guess is that people have used cookiegrabbers to grab your cookies including your nulled cookies and used those cookies to get nulled to autologin to that user, clearing your cookies OR not checking the "remember me" box will probably be enough.

Please Login or Register to see this Hidden Content


  • 1

#12

Pr1m3v1L
Pr1m3v1L
    Offline
    15
    Rep
    29
    Likes

    LIVEVIL

Posts: 175
Threads: 9
Joined: Dec 27, 2018
Credits: 0

Five years registered
#12

It'll be good if we can implement some form of device activity tracking to track the devices that are logged into our accounts. This way we can keep track of our logins :D

 

For an interim measures, I'll suggest that we use a separate browser for links?

Example:

Assuming you use Chrome for Nulled, when you see an external link and you wish to view it, use another browser (Firefox, Opera etc) to view the link. It's a hassle but it grants us more security. :)


  • 0

#13

TheresaMay
TheresaMay
    Offline
    13
    Rep
    61
    Likes

    Junkie

Posts: 276
Threads: 19
Joined: Feb 22, 2019
Credits: 0

Five years registered
#13

 Yes, The exploit is well known I even have contacts who say they can do such a thing. If wanted I could try to report the method to finn. I think its just an exe or link that copies them to a remote DB then from that they can edit it in.


Edited by TheresaMay, 22 February 2019 - 04:25 AM.

  • 0

#14

NewLurker
NewLurker
    Offline
    94
    Rep
    633
    Likes

    Veteran

Posts: 767
Threads: 211
Joined: Oct 27, 2018
Credits: 6

Five years registered
#14

It'll be good if we can implement some form of device activity tracking to track the devices that are logged into our accounts. This way we can keep track of our logins :D

 

For an interim measures, I'll suggest that we use a separate browser for links?

Example:

Assuming you use Chrome for Nulled, when you see an external link and you wish to view it, use another browser (Firefox, Opera etc) to view the link. It's a hassle but it grants us more security. :)

yeah this will work, at least help in some way,

 

Use tor browser for tumble your real ip too


  • 0

pm or totallypeppa#0123 (NO Special Character COPY-PASTE THEIR TAG TO Here to check)


IMPORTANT, BEWARE SCAMMER/IMPERSONATOR SERIOUSLY

  • ONLY SEND MONEY if I send you my BTC Address or PayPal Via NULLED PM
  • My only Discord "totallypeppa#0123" no Special-Character no badges READ: Lucas's thread
  • if one wouldn't nulled pm confirm identity, they are impersonator !!!

#15

worlockt
worlockt
    Offline
    912
    Rep
    408
    Likes

    Currency Exchanger

Posts: 428
Threads: 40
Joined: May 18, 2018
Credits: 307

Five years registered
#15

isn't another good solution, as nulled system detect change in IP, send an authorization email on user email id.

this can avoid account missuse even somebody got your login details or fu*king cookies ..


  • 0

I am here for currency exchange service.
PM me
Telegram: t.me/worlockt
( Click above link. )

 

Confirm me via PM before deal off-site.


#16

NewLurker
NewLurker
    Offline
    94
    Rep
    633
    Likes

    Veteran

Posts: 767
Threads: 211
Joined: Oct 27, 2018
Credits: 6

Five years registered
#16

isn't another good solution, as nulled system detect change in IP, send an authorization email on user email id.

this can avoid account missuse even somebody got your login details or fu*king cookies ..

Brother, I'm not exactly sure if nulled let 2 computer log in at the same time, the cookies might let them in regardless IP ? I faced one with the real owner logged while hacker logged in as well..... so I guess your solution might work if the hacker is using cookies and remotely login from a different spot but still able to spoof the ip close to the owner real ip geo so... 

https://www.nulled.t...ner-are-online/


  • 0

pm or totallypeppa#0123 (NO Special Character COPY-PASTE THEIR TAG TO Here to check)


IMPORTANT, BEWARE SCAMMER/IMPERSONATOR SERIOUSLY

  • ONLY SEND MONEY if I send you my BTC Address or PayPal Via NULLED PM
  • My only Discord "totallypeppa#0123" no Special-Character no badges READ: Lucas's thread
  • if one wouldn't nulled pm confirm identity, they are impersonator !!!

#17

worlockt
worlockt
    Offline
    912
    Rep
    408
    Likes

    Currency Exchanger

Posts: 428
Threads: 40
Joined: May 18, 2018
Credits: 307

Five years registered
#17

Many security agencies implement this function.

For eg. you must notices in gmail. You access from another machine even for same IP, you get notification ( atleast )

I think by implement simple detect ( IP and machine ) and send authorization email many user will be save missuse.

And once user get info that something is leaking, they can restore their machine for better security.


  • 0

I am here for currency exchange service.
PM me
Telegram: t.me/worlockt
( Click above link. )

 

Confirm me via PM before deal off-site.



 Users browsing this thread: