So… as often happens in our lives, we do not always get what we want. Difficulties are there to overcome and, note, not always in the most difficult way.
To get to the point – often we get incomplete data in the logs – holders log into their accounts without answering secret questions, without further verification. The reason can be many factors – IP, flash (*.sol), the system trace (a set of individual parameters of the PC, which together give a very rare “picture”) and cookies. I am sure that there are also other parameters for identification, but here I will try to analyze the last one – cookies.
I think 99% of those who read this article – understand why and how cookies are recorded. If you don’t – google it – it’s not a mystery.
To give you an example let’s look at the most popular bank cookies, bankofamerica.com. Let’s say we have a log on the computer where the Holder logs in with no answers, the username is hidden by asterisks… what to do? Some time ago this was for me an insoluble problem – now … all solved ;-).
We need any account of the same bank with full access, a browser FireFox and two plugins – Cookies Importer, Cookies Exporter. I think the essence of grasped – we will log in with full access and try to understand how to use cookies and whether they can be used at all for this bank.
1) Evaluating the possibility of using only cookies for verification
Let’s take a full-fledged account… Log in to it (check all the boxes like “remember me” where possible). Remember (write down) the addresses of pages where you entered username, password, responses, etc. Exit correctly – LogOut. Here again we check if the bank remembered us and if everything is ok we export cookies after LogOut (use plugin) to a text file.
Next, we clean cookies, change IP (within a reasonable range 😉 ), change the system parameters. In general we do everything to keep from old entry only cookies (they are in text file). It is desirable to wait (if you are patient) for some hours, to avoid practically simultaneous visits from different IPs. Open a clean browser, import cookies (use the plugin) and go log in. If we are talking about BOA – you will succeed – cookies will work like clockwork ;-).
If it did not work – then it’s a happy event when you can do with “little blood”. Continue to explore the bank’s site in other ways.
2) Analysis of cookies – which of them we need?
Honestly – in 90% of my attempts to figure this out it all came down to a stupid search of different cookies, their combinations. Fortunately, there aren’t too many of them 🙂 ) Cookies with names including words or fragments of words login, ID… You will be guided there by the situation. The only thing I can advise you is to filter out unnecessary cookies. When you go to the site BOA – you recorded a certain set of cookies. And it is clear that they have nothing to do with access to the account.
Let’s look at an example – cookies when you visit bankofamerica.com

