过期域名预定抢注

 找回密碼
 免费注册

cookie stuffing普及篇(二)

[複製鏈接]
發表於 2008-11-13 19:35:24 | 顯示全部樓層 |閱讀模式
How and Why cookie stuffing works
& g; P2 i0 s" n  L- a% v( p8 w, @& \7 ]/ [
Cookie stuffing,depending on the method used,works in different ways.The ultimate goal however is to get that darned affiliate cookie onto someones computer.2 X1 N( R# z# ~3 x: c6 F
3 M9 t; \; n: r5 A
Cookies are passed in whats called a header.A web page doesn't have to be rendered for a header to be passed.Because of this,methods like image stuffing exist.The browser of your victim thinks is getting an image,but instead it gets a header with instructions to place a cookie on the computer.
& V. l& l+ `7 C1 B8 F
& q0 Q. Q* W! c) u  |7 K+ IIn other methods of stuffing,you are actually opening up your affiliate url in a new window or in a frame.Because the url is actually opened,a cookie is placed.Not only is the header processed for cookie placement,the html is also rendered by the browser.In most cases,this is visually detectable by the user.Like in the case of javascript,a pop up window is used to display your affiliate url.Talk about annoying.4 V# ^1 _: L$ Z( n

2 U1 e2 B8 V1 ZThere are other methods you can use like a 1 pixel iframe.This is less detectable visually,but very easy to spot if someone went digging through the source for it.$ ~, s+ j9 B7 M; ^$ f9 z0 s4 F
4 P7 w9 x( a3 G3 k, l
Summary: a cookie is passed via a http header.A browser will not ignore a cookie header unless its security settings are instructed to do so.When the browser asks a server for an image and is returned with a webpage,a header is sent before the webpage.The browser aknowledges the header,and disregards the rest of the content.Thus a cookie is placed.
發表於 2008-11-13 20:06:44 | 顯示全部樓層
已經翻譯的不錯了
回復 给力 爆菊

使用道具 舉報

 樓主| 發表於 2008-11-13 20:13:08 | 顯示全部樓層
lol 翻譯的還可以看懂 不過看英文的還是要舒服一點。
: [3 U4 z# X9 c5 g- j+ Q+ @3 B以上只是講了cookie stuffing是如何工作已經為什麼會存在cookie stuffing。
; f1 P) h6 ]7 n; y2 s8 `/ L9 Z至於具體的方法很多人也可以寫出自己的程序出來。看了部分cookie stuffer代碼,感覺應該是cookie stuffing的高級用法了。
4 q# f3 ^5 L, z( D  l6 V, qmoder也說了正道即是王道,還有某前輩也說了搞正規,所以關於cookie stuffing以後不再提了
回復 给力 爆菊

使用道具 舉報

發表於 2008-11-13 20:13:42 | 顯示全部樓層
非常感謝,從小英文就不及格,看來要去進修一下了,
回復 给力 爆菊

使用道具 舉報

 樓主| 發表於 2008-11-13 22:56:18 | 顯示全部樓層
很blackhat的說,國外有人討論也是很隱蔽的討論
" p/ U+ h( Y. B+ x9 y一個簡單的例子:
  1. http://www.im286.com/thread-3030307-1-1.html
複製代碼
以後Cookie Stuffing話題不會再公開討論,有興趣的朋友可以私下和我討論。
回復 给力 爆菊

使用道具 舉報

發表於 2011-1-21 16:00:50 | 顯示全部樓層
我要瞭解cookie stuffing,哪裡可以看到
回復 给力 爆菊

使用道具 舉報

發表於 2011-1-21 16:26:46 | 顯示全部樓層
謝謝了,。先看看再說。
回復 给力 爆菊

使用道具 舉報

發表於 2011-1-21 16:32:46 | 顯示全部樓層
。。。。。。。。。。掘墓啊
回復 给力 爆菊

使用道具 舉報

您需要登錄後才可以回帖 登錄 | 免费注册

本版積分規則

过期高净值品牌域名预定抢注

4um點基跨境網編創業社區

GMT+8, 2024-11-24 03:53

By DZ X3.5

小黑屋

快速回復 返回頂部 返回列表