Is Fob safe?
Fob reads your full LinkedIn cookie set, including the li_at session cookie, and writes it into a form field on the vendor's own site.
When you click its "connect to LinkedIn" button, Fob's background script pulls every cookie for linkedin.com, including li_at (LinkedIn's long-lived session-authentication cookie), and hands the full set back to the page. The content script then writes that raw cookie JSON into an input field on fob.ai.cc/linkedinAccount, a page owned by the extension's own vendor, matching the extension's stated purpose of retrieving your LinkedIn session each time you use it.
Who publishes iteoseocn - 1 other listing from the same operator, 1 of them carrying a finding
eoseocn - 1 other listing from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 297 users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Fob copies your entire LinkedIn cookie set into a field on its own page
Code analysis shows Fob reads every LinkedIn cookie, including the li_at session cookie, when you click its button on fob.ai.cc, then writes the full set into a form field on that page.
You click Get LinkedIn Cookies on the fob.ai.cc account-linking page while logged into LinkedIn.
The button only appears on the vendor's own fob.ai.cc/linkedinAccount page.
The extension reads every LinkedIn cookie, including the li_at session cookie, and writes the full set into a field on that page.
The read happens in the background service worker; the write happens in the content script.
| Field | Value | Why it matters | |
|---|---|---|---|
LinkedIn session cookie (li_at) | AQEDATmF3q0-abcd1234EFGH5678ijklMNOPqrst== | Lets whoever holds it act as you on LinkedIn without your password, until you sign out everywhere. | |
Browser ID cookie (bcookie) | "2-9f3c1a2e-7b6d-4e11-8a2f-1d4c9b0a5e33" | A long-lived identifier LinkedIn uses to recognize your browser across visits. | |
Load-balancer routing cookie (lidc) | "b=OGST07:s=O:r=O:a=O" | Routes your requests to the same LinkedIn server; not tied to your identity on its own. | |
Language preference cookie (lang) | "v=2&lang=en-us" | Stores your LinkedIn display language. |
Cookie read (background.js) and page write (content-script.js); ships unminified
chrome.runtime.onMessage.addListener(function(request, sender, sendResponse) {
new Promise(async (resolve, reject) => {
let linkedin_url = 'https://www.linkedin.com/';
chrome.cookies.getAll({ url: linkedin_url }, function (cookies) {
let login = 0;
const resList = cookies.map(item => {
if (item.name == 'li_at') { login = 1; }
return item;
});
const cookieJsonStr = JSON.stringify(resList);
sendResponse({ is_login: login, cookie: cookieJsonStr });
});
});
return true;
});connect_to_linkedIn.onclick = async function(){
chrome.runtime.sendMessage(
{ cookies: 'update', data: "hagro_linkedIn" },
function(response) {
if(response.is_login == 1){
$('input[name="cookies"]').val(response.cookie);
$("#connect_to_linkedIn").text('已获取Cookies');
$("#connect_to_linkedIn").prop("disabled",true);
}
}
);
};Pastes into DevTools on fob.ai.cc/linkedinAccount to watch the extension write LinkedIn cookies into the page field.
// Paste into the DevTools Console on https://fob.ai.cc/linkedinAccount
// BEFORE clicking the "Get LinkedIn Cookies" button.
const field = document.querySelector('input[name="cookies"]');
if (!field) {
console.log('input[name="cookies"] not found on this page yet.');
} else {
const desc = Object.getOwnPropertyDescriptor(HTMLInputElement.prototype, 'value');
Object.defineProperty(field, 'value', {
set(v) {
console.log('[fob-cookie-write] field value set to:', v);
desc.set.call(this, v);
},
get() { return desc.get.call(this); }
});
console.log('Watching input[name="cookies"]. Now click the button.');
}- 1Install Fob and log into LinkedIn.
- 2Open fob.ai.cc/linkedinAccount and open DevTools Console.
- 3Paste this script and press Enter.
- 4Click Get LinkedIn Cookies and read the logged field value.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 1.0.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on fob.ai.cc
*://fob.ai.cc/*
Read and change your data on linkedin.com
*://*.linkedin.com/*
Show you desktop notifications
notifications
Read and change cookies, including the ones that keep you signed in
cookies
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed Fob contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- fob.ai.cc
Fob sends data to fob.ai.cc. No other extension we have analysed sends data here.