exploit.cc sets no cookies of its own. Two other parties can set one on this domain: Google Analytics, which we run and which is delivered first-party through Cloudflare, and Cloudflare's own security layer. Every one of them is named below, with what it does and how long it lasts.
Operated by EVECS, LLC. Nothing on this Site depends on a cookie, so you can block all of them and lose nothing.
exploit.cc sets no cookie of its own. There are no accounts to keep you signed in to, no preferences to remember, and no consent banner state to store. Nothing on this Site stops working if you block every cookie it can set.
Two other parties can set one on this domain:
Sections 4 and 5 name every one of them. Our Privacy Policy covers the wider picture of what we hold.
A cookie is a small text file a site asks your browser to store and send back on later requests. It lets a server recognise a returning browser. Related technologies do similar work by other means: localStorage and sessionStorage keep data in the browser without attaching it to requests, and pixels and scripts can record that a page was loaded without storing anything at all.
A cookie is first-party when it is set on the domain in your address bar and third-party when it is set on some other domain. It is a session cookie when it expires as your browser closes and persistent when it survives until an expiry date or you delete it. Section 4 explains why the first-party label on this Site does not mean what it usually means.
Nothing. The Site is server-rendered, holds no session, and carries no preference you could save. We do not use localStorage or sessionStorage for anything either.
If that changes, this page changes with it before the feature ships, and the last-modified date at the top moves.
We use Google Analytics to see which pages and searches are useful. It is delivered through Cloudflare's Google tag gateway: the measurement script is served from a path on https://exploit.cc rather than from a Google domain, and measurement events are sent to https://exploit.cc and forwarded from there to Google.
Three consequences follow, and all three matter to a reader deciding what to block:
_ga: assigns a randomly generated identifier so a returning browser is counted once rather than several times. It is not linked to a name, an account or any other identifier, because we hold none. Persistent, up to two years._ga_<property-id>: holds session state for our specific Google Analytics property, so a visit that spans several pages is counted as one session. Persistent, up to two years.Google may change the cookies its measurement products use. If the names above stop matching what you see, the categories still hold, and telling us at contact@exploit.cc is the fastest way to get this page corrected.
We have not enabled Google Analytics advertising, remarketing or audience features. No ad network receives anything from this Site.
The Site is served through Cloudflare, which sets its own cookies when its security and delivery features act on a request. We do not control their contents and cannot read them for our own purposes. Most visitors will see one or none of these, since several appear only when a specific feature engages.
__cf_bm: bot management. Distinguishes automated traffic from human traffic. Expires after 30 minutes of inactivity._cfuvid: rate limiting. Separates individual visitors who share one IP address, so a shared network is not throttled as a single client. Session.cf_clearance: records that a security challenge was passed, so you are not challenged repeatedly. Set only if you are shown a challenge.__cflb, __cfruid, __cfseq, __cfwaitingroom, cf_ob_info, cf_use_ob: set only when the corresponding Cloudflare feature is active for a request, for load balancing, request attribution, bot detection, queueing or cached failover.Cloudflare maintains the authoritative list of these and their current lifetimes.
These are security and delivery cookies. Blocking them is your choice, but it may mean being challenged more often or, in the case of a genuine attack, not reaching the Site at all.
Cookies strictly necessary to deliver and secure a site may generally be set without consent. Analytics cookies may not, in jurisdictions including the EEA and the UK.
Where the law requires consent before an analytics cookie is set, we will present a consent mechanism, will not set the cookie before a choice is made, and will honour a later change of mind through the same mechanism or by your clearing cookies for this domain.
Blocking Cloudflare's security cookies is possible by the same means and is more likely to cost you something, as described in section 5.
We update this page when the cookies on this Site change, and revise the last-modified date at the top when we do. This policy forms part of our Terms of Use, and our Privacy Policy covers everything beyond cookies.
Questions, or a cookie on this domain that is not listed above: