1998-02-08 - Cypherpunks share cookies

Header Data

From: dlv@bwalk.dm.com (Dr.Dimitri Vulis KOTM)
To: cypherpunks@toad.com
Message Hash: 72058798efd54b0c3cb9ef1b28c65b79423409ed00169ed99984f339ea1fe8f7
Message ID: <1mPLke4w165w@bwalk.dm.com>
Reply To: N/A
UTC Datetime: 1998-02-08 21:53:37 UTC
Raw Date: Mon, 9 Feb 1998 05:53:37 +0800

Raw message

From: dlv@bwalk.dm.com (Dr.Dimitri Vulis KOTM)
Date: Mon, 9 Feb 1998 05:53:37 +0800
To: cypherpunks@toad.com
Subject: Cypherpunks share cookies
Message-ID: <1mPLke4w165w@bwalk.dm.com>
MIME-Version: 1.0
Content-Type: text/plain



I've updated the cookie-sharing page at:

http://www.geocities.com/CapeCanaveral/Hangar/6354/cookies.html

Please share your cookies!


I'm having a bit of a problem with the cookie from Firefly.com and other
sites that use their passport software (parts of barnes&noble, quitnet.org,
mylaunch.com, filmfinder.com, etc).

After a log in (as cypherpunks:cypherpunks, naturally), the server sends a
FIREFLYTICKETV3 cookie which appears to contain the username and
a timestamp.  After about 24 hours the cookie expires and one has to log
in again.  If someone can set the expiration date far in the future,
I'll add the cookie to the shared cookie list; otherwise they're useless.

Here's a sequence of "firefly ticket" cookies over a few days:

FIREFLYTICKETV3=WWKKILVVLLXVbVHKOHSNMH_\SVIHHHEGIIWRWUFIJI
                WWKKILVVLLXVbVHKOHSNMH_\SVGHJHLGMISRUUNIGI
                WWKKILVVLLXVbVHKOHTNFHa\WVHHGHKGFISRYUOILI
                WWKKILVVLLXVbVHKOHTNFHa\WVHHHHEGOIVR[UKIII
                WWKKILVVLLXVbVHKOHTNFHa\WVHHHHFGIIXRZUKIOI
                WWKKILVVLLXVbVHKOHTNFHa\WVHHGHKGFISRYUOILI
                WWKKILVVLLXVbVHKOHTNFHa\WVHHHHEGOIVR[UKIII
                WWKKILVVLLXVbVHKOHTNFHa\WVHHHHFGIIXRZUKIOI
                WWKKILVVLLXVbVHKOHTNFHa\WVJHGHEGJITRUUNIMI
                WWKKILVVLLXVbVHKOHTNFHa\XVEHLHJGKIXRRUNIHI
                WWKKILVVLLXVbVHKOHTNFHa\XVEHLHKGJIVRUUKIMI
                                     ^^^^^^     **********

The expiration is triggered by the piece I marked ^^^.  Munging the end
of the cookie (marked ***) doesn't seem to invalidate the cookie.

---

Dr.Dimitri Vulis KOTM
Brighton Beach Boardwalk BBS, Forest Hills, N.Y.: +1-718-261-2013, 14.4Kbps






Thread