-
Samy Kamar’s zombie cookie factory
Posted on September 23rd, 2010 at 20:21 3 commentsSamy Kamar is an amazing programmer/sleuth.
I’ve been talking about zombie cookies for a couple of months now, with several articles in Windows Secrets Newsletter, and a couple of posts on Infoworld’s Tech Watch. The basic idea: there’s a way to stick a copy of any cookie in Flash’s local storage, so a site’s cookie can be restored even if you delete it.
Ergo, zombie cookie.
A couple of days ago, Samy published a program that stores and retrieves cookies in eight different locations. The “zombie” factor can retrieve and reconstitute a cookie from any of those eight locations – and he says he has four more locations coming.
Amazing. Check out the article in Infoworld Tech Watch.
3 responses to “Samy Kamar’s zombie cookie factory”
-
rc primak September 26th, 2010 at 07:58
So, Woody, does this scheme defeat the Flash Cookie deletion Extensions like Better Privacy and Click&Clean? I know some modified Flash Players are used by the TV network sites for their Streaming Videos. They store all kinds of data in User Application Data Folders, among other places. Cleaning out all of those Folders is impractical, and antispyware programs do not flag the data, but I thought CCleaner was cleaning out these Folders. Am I wrong?
Basically, it looks like it’s a losing battle trying to keep private, secure and clean on a PC these days. (Sigh!)
-
@Bob -
Once this technique becomes commonplace, it’s a losing battle. Cleaning out Flash’s cookie storage used to suffice. It doesn’t any more. And I’d be willing to bet that the privacy software companies are going to have a H of a time figuring out how to get rid of all of these new zombies without messing up something.
-
rc primak September 27th, 2010 at 09:47
Maybe losing a few lawsuits or having an embarrassing experience in front of the US House of Representatives or the EU Courts will change their tune. Then again, maybe not.
Leave a reply
-


