176
2 Computer Viruses, Malicious Logic, and Spyware
2.6.2 Cookies Storage Method
The method of storing cookies depends on the type of the browser. Internet Explorer
saves cookie data as separate text files in the folder Cookies in the user profile. The
only means of protection of this folder is the presence of the System attribute, which
makes it invisible for the file explorer. The files have TXT extension and can be
viewed using Notepad.
For example, Mozilla Firefox stores cookies in the user profile in the file Application Data\Mozilla\Firefox\Proflles\\cookies.txt. This file has a fairly
simple structure—comments start with the # symbol, cookies are listed one per line,
and the fields are separated by tab characters.
For a deeper understanding of the features of the work, the reader can refer to [1],
where four simple examples of CGI programs in the Delphi language (in the form of
source texts and compiled programs) are shown to illustrate the basic techniques for
working with cookies. Compiled programs need to be placed in the catalog of the
web server, for which execution of CGI programs is allowed. With Microsoft IIS,
in order to study examples, it is recommended to create separate folders and allow
running scripts and executables in its settings.
Example one (cookies1.exe) is an example of a simplest CGI application creating
and reading cookies. The second example is slightly more complex; it illustrates the
possibility of CGI-controlled creation, acquisition, and deletion of cookies. The third
example demonstrates the work with session cookies, simulating the mechanism of
elementary user identification and session maintenance. Finally, the fourth example
demonstrates creation of a visit counter with basic protection from illegal alteration
of numbers implemented with the help of cookies.
These examples are detailed in the work [1] and can be compiled in any Delphi
version, starting from 5.0.
2.6.3 Other Types of Cookies
Two types of cookies are widely known: SpyWare cookies and Tracking Cookies.
These two names, as a rule, are used to refer to approximately identical types of
cookies used by developers of various rating and banner systems to track visits of
pages containing elements of such systems by a user. In this case, cookies are used to
“tag” the user; such tags, as a rule, cannot be associated with a specific user and their
personal data and only serve as simple unique identifiers. The workflow is shown in
Fig. 2.28.
Let us suppose that a user visits two sites containing counters of the same rating
system on their pages. Now, let’s say that receipt and transmission of cookies are
allowed in the user’s browser.
Upon visitation of the site A, two operations will take place—loading the page
from site A (step 1) and calling the rating system site (step 2) to obtain an image with
2 Computer Viruses, Malicious Logic, and Spyware
2.6.2 Cookies Storage Method
The method of storing cookies depends on the type of the browser. Internet Explorer
saves cookie data as separate text files in the folder Cookies in the user profile. The
only means of protection of this folder is the presence of the System attribute, which
makes it invisible for the file explorer. The files have TXT extension and can be
viewed using Notepad.
For example, Mozilla Firefox stores cookies in the user profile in the file Application Data\Mozilla\Firefox\Proflles\
simple structure—comments start with the # symbol, cookies are listed one per line,
and the fields are separated by tab characters.
For a deeper understanding of the features of the work, the reader can refer to [1],
where four simple examples of CGI programs in the Delphi language (in the form of
source texts and compiled programs) are shown to illustrate the basic techniques for
working with cookies. Compiled programs need to be placed in the catalog of the
web server, for which execution of CGI programs is allowed. With Microsoft IIS,
in order to study examples, it is recommended to create separate folders and allow
running scripts and executables in its settings.
Example one (cookies1.exe) is an example of a simplest CGI application creating
and reading cookies. The second example is slightly more complex; it illustrates the
possibility of CGI-controlled creation, acquisition, and deletion of cookies. The third
example demonstrates the work with session cookies, simulating the mechanism of
elementary user identification and session maintenance. Finally, the fourth example
demonstrates creation of a visit counter with basic protection from illegal alteration
of numbers implemented with the help of cookies.
These examples are detailed in the work [1] and can be compiled in any Delphi
version, starting from 5.0.
2.6.3 Other Types of Cookies
Two types of cookies are widely known: SpyWare cookies and Tracking Cookies.
These two names, as a rule, are used to refer to approximately identical types of
cookies used by developers of various rating and banner systems to track visits of
pages containing elements of such systems by a user. In this case, cookies are used to
“tag” the user; such tags, as a rule, cannot be associated with a specific user and their
personal data and only serve as simple unique identifiers. The workflow is shown in
Fig. 2.28.
Let us suppose that a user visits two sites containing counters of the same rating
system on their pages. Now, let’s say that receipt and transmission of cookies are
allowed in the user’s browser.
Upon visitation of the site A, two operations will take place—loading the page
from site A (step 1) and calling the rating system site (step 2) to obtain an image with
