Author Topic: Flash Cookies (Useful info if you did not know)  (Read 1023 times)

Offline toxin

  • Level 21
  • *
  • Posts: 231
  • Reputation: +4/-2
    • View Profile
    • Encore Montreal
Flash Cookies (Useful info if you did not know)
« on: December 20, 2009, 04:59:24 AM »
Wow something I just learned about flash has its cookie type that is NOT cleared when you clear your cookies or cache. I may have been a bit slow to finding this out so thought to share the knowledge with other. Firefox has you covered with this add-on https://addons.mozilla.org/en-US/firefox/addon/6623

You can also find the files in the Application Data directory of Adobe Flash directory name is #SharedObjects
something like this
X:\Documents and Settings\Saint\Application Data\Macromedia

This is used for ads and other things so read up on it as something are needed

Offline Nox

  • Level 35
  • **
  • Posts: 768
  • Reputation: +12/-2
    • View Profile
Re: Flash Cookies (Useful info if you did not know)
« Reply #1 on: December 20, 2009, 05:13:44 AM »
I think flash cookies are not really known, at least I almost never hear about them, so you're probably not that slow :)
or maybe you are slow and I am slow :)

I'd add:

this cookies can have up to 100kB, no quantity limit - compare with 4kB max for common cookie

http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1446862

Something to access them:
http://sourceforge.net/projects/soleditor/
http://solve.sourceforge.net/

http://synopsi.com/sol.zip for win (console application)
you have to locate them first: http://en.wikipedia.org/wiki/Local_Shared_Object

Other program that can handle them:
https://addons.mozilla.org/en-US/firefox/addon/6623 (BetterPrivacy FF addon)
http://www.ccleaner.com/
http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html (Adobe's Flash manager)

-----------------------------
Flash is not the only one - SilverLight (while having also the common cookies) has a feature called Isolated Storage allowing to store up to 1MB of data (dunno if per application or per domain)


These two also bypass Privacy modes in browsers

http://www.ghostery.com/

---------------------------------------------------------

Source: http://blog.synopsi.com/2009-08-21/nie-su-cookies-ako-cookies [slovak]

it's a security and privacy related blog so what I wrote is a bit biased, but I think still useful

btw lol http://igigi.baywords.com/shoptet-cz-expose-passwords-in-plaintext/ :) that's sad... I guess our games are more secure than this eshop generator
« Last Edit: December 20, 2009, 05:55:46 AM by Nox »
Meet us at an IRC irc.freenode.net #bbg as well
https://vimeo.com/36579366 (a must-watch) | Join BOINC - no longer a hype, but you can help never the less

Offline toxin

  • Level 21
  • *
  • Posts: 231
  • Reputation: +4/-2
    • View Profile
    • Encore Montreal
Re: Flash Cookies (Useful info if you did not know)
« Reply #2 on: December 20, 2009, 08:32:19 AM »
Well this one may need its own spot but will post here. It is Google gears an add-on to that lets you know at least before it adds it.
This could have use in games. I think i seen a old post on here some time back about having the user store images and other things on the computer I will be looking in to it a bit more.
Gears is an open source project that enables more powerful web applications, by adding new features to your web browser:
Desktop    Let web applications interact naturally with your desktop
Database    Store data locally in a fully-searchable database
WorkerPool    Run JavaScript in the background to improve performance



http://gears.google.com/


Offline Harkins

  • Level 28
  • **
  • Posts: 424
  • Reputation: +11/-2
  • Coder, blogger, entrepreneur.
    • View Profile
    • Push CX - Blog
Re: Flash Cookies (Useful info if you did not know)
« Reply #3 on: December 20, 2009, 10:51:29 AM »
Flash LSOs are a great way to notice dupers.

Visit #bbg on irc.freenode.net to talk browser games anytime.

Offline JGadrow

  • Level 35
  • **
  • Posts: 1,133
  • Reputation: +23/-2
    • View Profile
Re: Flash Cookies (Useful info if you did not know)
« Reply #4 on: December 21, 2009, 08:06:15 AM »
Flash LSOs are a great way to notice dupers.
Agreed, though still not 100% perfect. ;) I don't think it's possible to have 100% protection from multi-accounting. It's like computer security: You're never 100% safe, but if you throw enough at it, you can make it really difficult.
Idiocy - Never underestimate the power of stupid people in large groups.


Offline Mufasa

  • Game Owner
  • Level 18
  • *
  • Posts: 189
  • Reputation: +3/-0
  • Maniac Developer
    • View Profile
Re: Flash Cookies (Useful info if you did not know)
« Reply #5 on: December 22, 2009, 09:59:47 AM »
Flash LSOs are a great way to notice dupers.

which is why I love that it's not well-known. Almost everyone knows to clear cookies/cache (maybe even start a different browser) then change IP or use proxy. Almost no one thinks to clear flash cookies :)

 


SimplePortal 2.3.3 © 2008-2010, SimplePortal