Their php script gets the page, inserts their banner (VERY crudely), and gives you the output.
1) All requests go through their server... which requests the document.... then displays to surfer (so x2 as sloooow minimum).
2) they can spoof the referer with this, (currently set to
http://)
3) they can't spoof the IP they request the page from.
4) If you have their IPs, you can block this.
http://www.xites.com/i?sssid=18&h=www.gibhar.com&url=/
:-)
ta da.