Can IBill's Cookies be used to CHEAT everyone???

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Trax
    [----------------------]
    • Aug 2001
    • 14486

    #101
    you know.. there is still a way to earn a lot of cash with cheating cookies.. i´m not going to say HOW and WHAT as this would make a few guys hate me but a smart guy knows how to earn a few bucks cheating cookies. there áre already guys doing so..

    ------------------
    Best Paying Sponsors:
    ARS - Best PayPerSignup + AVS Sponsor
    ICQ: 59101924

    Comment

    • Incognito
      Confirmed User
      • May 2001
      • 371

      #102
      Originally posted by kisslolita:
      As I am new to this business i might have a slightly objective perspective on the matter

      Amp : What roberto was saying sounds highly reasonable.
      If I advertise a sponsor and a fucker clicked on this sponsor's banner on my site, and singed up, then in my opinion I should get the credit, and not some site that this surfer visited three days ago and clicked on the same banner! That's ridiculous!!!
      As to deleting this thread. I guess that cheaters are easy to come by, especially in this business (or in any other for that matter) . The question would be not how to avoid cheaters, but how to catch them redhanded and how to fuck them afterwords in order to set the example to other cheaters! Since this is all about $$$ and hard work, then the sodomization of cheaters must be cruel and efficient.

      Just my opinion.

      I beleive You to be partially correct from my point of view.

      I mean running around and trying to catch EVERY toplist, TGP or CJ out there who suddenly starts loading a cookie from a ZERO frame or worse from a PHP script (which makes it almost undetectable, that's how it was used in our case by the way against us) is a bit of a hard task dont You think?

      Why not fix that crap so that signup page being faced with two ID's takes nornal source code ID first?
      Seems a good idea to me.
      -=almost fucking incognito=-

      Comment

      • Incognito
        Confirmed User
        • May 2001
        • 371

        #103
        Originally posted by Trax:
        you know.. there is still a way to earn a lot of cash with cheating cookies.. i´m not going to say HOW and WHAT as this would make a few guys hate me but a smart guy knows how to earn a few bucks cheating cookies. there áre already guys doing so..

        Hmm...Cheating is bad.
        Cheating Your fellow webmasters, same guys reselling someone is even worse I think.
        -=almost fucking incognito=-

        Comment

        • Incognito
          Confirmed User
          • May 2001
          • 371

          #104
          [double post]

          [This message has been edited by Incognito (edited 12-07-2001).]
          -=almost fucking incognito=-

          Comment

          • Trax
            [----------------------]
            • Aug 2001
            • 14486

            #105
            Originally posted by Incognito:
            Hmm...Cheating is bad.
            Cheating Your fellow webmasters, same guys reselling someone is even worse I think.
            wowowowow... i should have meationed that i´m not cheating using cookies... damn.. don´t understand me wrong dude. i thoughtof the poissiblities.. its the same with hitbots.. i tested hitbots on my own sites (faking few hits) to check how they work and how to detect em... this does not mean that i´m a hitbotter.. just to clear things up

            ------------------
            Best Paying Sponsors:
            ARS - Best PayPerSignup + AVS Sponsor
            ICQ: 59101924

            Comment

            • Incognito
              Confirmed User
              • May 2001
              • 371

              #106
              Originally posted by Trax:
              wowowowow... i should have meationed that i´m not cheating using cookies... damn.. don´t understand me wrong dude. i thoughtof the poissiblities.. its the same with hitbots.. i tested hitbots on my own sites (faking few hits) to check how they work and how to detect em... this does not mean that i´m a hitbotter.. just to clear things up

              Sorry, really sorry.
              Just got You wrong - must be my perfect english.

              Honestly I just take this all a bit too seriously probably...
              -=almost fucking incognito=-

              Comment

              • Incognito
                Confirmed User
                • May 2001
                • 371

                #107
                Well anyway.
                The bug is so minor that since they're aware of it - gonna be fixed soon.
                -=almost fucking incognito=-

                Comment

                • DragonAss
                  Confirmed User
                  • May 2001
                  • 206

                  #108
                  I agree that cookies being overwritten on every visit is the way for billing companies to go. Then there's no worry about possible cookie hacking or tricks by previous sites... and current sales are [basically] safe.

                  That said, I didn't see this mentioned elsewhere...

                  I know cookies are supposed to be off by default (according to RFC) and in the past Microsoft has had them turned on by default. No doubt because they just love following standards

                  However, I noticed that IE6 has cookies quietly turned off by default. It even drove me nuts for a little while when all my scripts stopped working. This was becasue it even disables session cookies unless you take the trouble to specify otherwise.

                  With a good portion of Joe-Sick-Packers, I'd be surprised if they even bother to check this out. In other words, as more people get new computers and/or upgrade to IE6, I think the majority of the public will probably have cookies disabled.

                  I would hope the answer to this is no, but: Are there any billing companies out there who rely on cookies to credit sales?

                  Comment

                  • Trax
                    [----------------------]
                    • Aug 2001
                    • 14486

                    #109
                    Originally posted by Incognito:
                    Sorry, really sorry.
                    Just got You wrong - must be my perfect english.

                    Honestly I just take this all a bit too seriously probably...
                    no no..it was my fault... i read what i wrote again and it sounded as if i didn´t want to inform everybody because i wanted to keep it for me and not getting into trouble.. what i meant is that lot of webmasters would blame me for posting ways to cheat their programs.. which i don´t want

                    ------------------
                    Best Paying Sponsors:
                    ARS - Best PayPerSignup + AVS Sponsor
                    ICQ: 59101924

                    Comment

                    • TheFLY
                      So Fucking Banned
                      • Jan 2001
                      • 11856

                      #110
                      Originally posted by DragonAss:
                      I know cookies are supposed to be off by default (according to RFC) and in the past Microsoft has had them turned on by default. No doubt because they just love following standards ;)

                      However, I noticed that IE6 has cookies quietly turned off by default. It even drove me nuts for a little while when all my scripts stopped working. This was becasue it even disables session cookies unless you take the trouble to specify otherwise.
                      I don't know what you're getting at. The percentage of surfers with cookies must be around 90% based on my own traffic estimates -- but it remains to be said that most non-adult websites on the net won't even load now without cookies (and demand the surfer to turn them on) so I think the momentum is for cookies to remain on at all times. Anyone with a few $$$ could probably get sorts of cookie stats info at http://www.statsmarket.com/ from WSS.

                      Can you explain this for me please? "I noticed that IE6 has cookies quietly turned off by default." Are you saying that MSIE6 has different switches for turning on and off session cookies and non-session cookies? Maybe this is the source of some headache that I have been having w/ one of my scripts. Thanks.

                      [This message has been edited by TheFLY (edited 12-07-2001).]

                      Comment

                      • TheFLY
                        So Fucking Banned
                        • Jan 2001
                        • 11856

                        #111
                        Originally posted by Incognito:
                        The FLY, it could have been so funny if it was not so sad.

                        < snip >

                        I dont see anything really funny about it.

                        All I see is that You guys are a bit slow. Like 3 monthes slow.
                        :D
                        No offense.
                        No offense taken. Sorry if I came off trying to sound funny -- but I was dead serious. After reading this entire thread -- my only conclusion is that if we aren't already spamming cookies -- then we are being left behind.

                        Fix this IBill!!!

                        Comment

                        • TheFLY
                          So Fucking Banned
                          • Jan 2001
                          • 11856

                          #112
                          Originally posted by awechen:
                          with few tricks
                          u can reset the cookie's

                          easy way is .. to fake some http header's
                          ..also is posible to read cookies from other domain's ( only IE ) ....

                          read the rfc2068 and rfc2109
                          ( http://www.ietf.org/rfc )
                          You are a dangerous man.

                          POSTED: showdown at sunset.

                          ;)

                          Comment

                          • SleazyDream
                            I'm here for SPORT
                            • Jul 2001
                            • 41470

                            #113
                            Actually the IE6 cookie question is one really worth mentioning here. Tracking programs like sextracker had problems with that browser when it first came out and had to modify their counter's code so as to properly credit hits from IE6 surfers. Take that a step further and any sponser account that hasn't updated their cookie tracking program for IE6 isn't crediting you for the sales......... A question to ask a sponser now would be when was the last time you updated your cookie tracking program? If it hasn't been touched in a year - RUN AWAY.
                            This dog, is dog, a dog, good dog, way dog, to dog, keep dog, an dog, idiot dog, busy dog, for dog, 20 dog, seconds dog!

                            Now read without the word dog.

                            Comment

                            • Kimmykim
                              bitchslapping zebras!!!!!
                              • Jun 2001
                              • 16015

                              #114
                              "However, I noticed that IE6 has cookies quietly turned off by default. It even drove me nuts for a little while when all my scripts stopped working. This was becasue it even disables session cookies unless you take the trouble to specify otherwise."
                              ------------------------

                              How many times are we going to go over this????

                              IE6 does NOT have cookies turned off by default.

                              IE6 refuses to recognize THIRD PARTY cookies without a privacy policy on the site attempting to set the third party cookie by default.

                              Third party processors do NOT set third party cookies, let me mention that again as well.

                              As for the rest of it, ANYTHING can be cheated if someone works hard enough at it, that's a given. Webmaster fraud, cc fraud, it's come to the point where it's hack, anti-hack, crack, anti-crack. We see it every day, as does every other major program on the web.

                              Seeing as how I don't work for IBill I cannot and will not comment on their setup, but let's suffice it to say that it would be extremely difficult to manipulate our system and I would figure IBill's as well, especially given Mike Burns' comments.

                              Comment

                              • Kimmykim
                                bitchslapping zebras!!!!!
                                • Jun 2001
                                • 16015

                                #115
                                And lest SleazyDumb stalk me back over here and start talking about my ignorance again, I will also mention that if anyone attempted to manipulate our system, the way they would have to do it would mean that we would catch them almost immediately, if not sooner.

                                Comment

                                • TheFLY
                                  So Fucking Banned
                                  • Jan 2001
                                  • 11856

                                  #116
                                  Originally posted by Kimmykim:
                                  How many times are we going to go over this????
                                  This is the first time! Ahaha...

                                  Comment

                                  • Kimmykim
                                    bitchslapping zebras!!!!!
                                    • Jun 2001
                                    • 16015

                                    #117
                                    If you look at the segment I quoted again and you still think this is the first time we have discussed it on here, that would explain a lot about you.

                                    Comment

                                    • TheFLY
                                      So Fucking Banned
                                      • Jan 2001
                                      • 11856

                                      #118
                                      Originally posted by Kimmykim:
                                      And lest SleazyDumb stalk me back over here and start talking about my ignorance again, I will also mention that if anyone attempted to manipulate our system, the way they would have to do it would mean that we would catch them almost immediately, if not sooner.
                                      So does CCBill reset a cookie before expiration? Nobody has answered this -- in this thread anyway.

                                      Also Mike's comments seemed to only point to Adult.com's solution to the "problem" -- it has been said here that IBill still can be manipulated by default.

                                      And what you said about "third-party" cookies makes no sense -- what is a "third-party" cookie?

                                      Also where is the crime in setting a cookie? If I use a sponsor's own cookie CGI through an "IMG SRC" tag to load a sponsor's banner -- this is manipulation -- but is this cheating? No. Instead this seems to be what should now be common practice by all webmasters that are "in-the-know"...

                                      ------------------
                                      <A HREF="http://www.thefly.net/topfly.html" TARGET=_blank>
                                      </A>Oh Baby! TheFLY.net

                                      [This message has been edited by TheFLY (edited 12-07-2001).]

                                      Comment

                                      • Kimmykim
                                        bitchslapping zebras!!!!!
                                        • Jun 2001
                                        • 16015

                                        #119
                                        Each site owner controls their own cookie setup, it's in their admin.

                                        MS definitions of first and third party cookies --

                                        "Constants

                                        PRIVACY_TYPE_FIRST_PARTY (0)
                                        Refers to privacy settings for first party cookies.

                                        PRIVACY_TYPE_THIRD_PARTY (1)
                                        Refers to privacy settings for third party cookies

                                        Remarks

                                        Cookies are categorized as first-party and third-party. A first-party cookie is one that originates from the host domain. If "http://www.blueyonderairlines.com" is found in the Internet Explorer address bar, "www.blueyonderairlines.com" is the host domain. While visiting this page, if a cookie is set from a domain other than "www.blueyonderairlines.com", such as "www.fourthcoffee.com", this cookie is considered a third-party cookie."

                                        And once again, I'll say that attempting to manipulate the cookies of a processing company is not anywhere near so easy as you would like to think.

                                        Comment

                                        • SleazyDream
                                          I'm here for SPORT
                                          • Jul 2001
                                          • 41470

                                          #120
                                          Isn't VP a fancy name for a customer service rep that likes milk with her cookies.....
                                          This dog, is dog, a dog, good dog, way dog, to dog, keep dog, an dog, idiot dog, busy dog, for dog, 20 dog, seconds dog!

                                          Now read without the word dog.

                                          Comment

                                          • Kimmykim
                                            bitchslapping zebras!!!!!
                                            • Jun 2001
                                            • 16015

                                            #121
                                            Sure it is, just like SleazyDream is a common name for mental midgets.

                                            Comment

                                            • SleazyDream
                                              I'm here for SPORT
                                              • Jul 2001
                                              • 41470

                                              #122
                                              The underlying theme here is that this is a problem for advertisers and not paysites.
                                              It's pretty clear that some think advertisers are not worth shit here and the only people to worry about are paysites..

                                              The worry is that cc companies and paysites won't really care all that much about it because it doesn't really effect them financially as much since it doesn't change their bottom line one bit, it only really financially effects the advertisers and those paysites that actually GIVE A SHIT about their advertisers. It's been pretty much shown that in this thread that those people who only care about their own bottom line sick out here like a soar thumb.
                                              This dog, is dog, a dog, good dog, way dog, to dog, keep dog, an dog, idiot dog, busy dog, for dog, 20 dog, seconds dog!

                                              Now read without the word dog.

                                              Comment

                                              • Kimmykim
                                                bitchslapping zebras!!!!!
                                                • Jun 2001
                                                • 16015

                                                #123
                                                Originally posted by SleazyDream:
                                                It's been pretty much shown that in this thread that those people who only care about their own bottom line sick out here like a soar thumb.
                                                Soar thumb? I rest my case.

                                                Comment

                                                • SleazyDream
                                                  I'm here for SPORT
                                                  • Jul 2001
                                                  • 41470

                                                  #124
                                                  who's stalking who?
                                                  This dog, is dog, a dog, good dog, way dog, to dog, keep dog, an dog, idiot dog, busy dog, for dog, 20 dog, seconds dog!

                                                  Now read without the word dog.

                                                  Comment

                                                  • Kimmykim
                                                    bitchslapping zebras!!!!!
                                                    • Jun 2001
                                                    • 16015

                                                    #125
                                                    Well, that's evident.

                                                    Comment

                                                    • Incognito
                                                      Confirmed User
                                                      • May 2001
                                                      • 371

                                                      #126
                                                      Originally posted by SleazyDream:
                                                      The underlying theme here is that this is a problem for advertisers and not paysites.
                                                      It's pretty clear that some think advertisers are not worth shit here and the only people to worry about are paysites..

                                                      The worry is that cc companies and paysites won't really care all that much about it because it doesn't really effect them financially as much since it doesn't change their bottom line one bit, it only really financially effects the advertisers and those paysites that actually GIVE A SHIT about their advertisers. It's been pretty much shown that in this thread that those people who only care about their own bottom line sick out here like a soar thumb.
                                                      Fortunately what You said is bullshit.
                                                      A partnership program, ESPECIALLY a mainstream one relies heavy on newbies.

                                                      If newbies are fucked - all is fucked.
                                                      -=almost fucking incognito=-

                                                      Comment

                                                      • SleazyDream
                                                        I'm here for SPORT
                                                        • Jul 2001
                                                        • 41470

                                                        #127
                                                        why do you think so many go under? duuuuu
                                                        This dog, is dog, a dog, good dog, way dog, to dog, keep dog, an dog, idiot dog, busy dog, for dog, 20 dog, seconds dog!

                                                        Now read without the word dog.

                                                        Comment

                                                        • qcmoney
                                                          Confirmed User
                                                          • Aug 2001
                                                          • 291

                                                          #128
                                                          It seems like a social engineering problem, not a 'defect' of the code but a feature. So you are exploiting a perceived benefit that is actually a weakness.

                                                          So the only way that any processor would know is if they were suspicious about a large amount of traffic from a specific affiliate, and decided to investigate. That would be like shooting themselves in the foot financially though.


                                                          Am I right? Damn, Fly, that's two I have to thank you for. I need to get back into programming.

                                                          Just kidding. Maybe.

                                                          Comment

                                                          • gkk
                                                            Confirmed User
                                                            • Jul 2001
                                                            • 169

                                                            #129
                                                            According to the ibill documentation snippet posted about 70 posts or so back, it looks like you could set up the following scenario:-

                                                            [On a gallery page]
                                                            Have a link to "Gallery 2" that goes to http://www.gallerysite.com/gallery2.html

                                                            gallery2.html is a 0 second meta-refresh redirect page that sends the surfer through an ibill-formatted link where the landing page is http://www.gallerysite.com/gallery2b.html

                                                            The surfer then sees the pictures at gallery2b.html and their browser contains a cookie for whatever sponsor program you just piped them via.

                                                            Make a visitor view 10 galleries, and you've just sent them on their way with 10 cookies that will live for the next 24 hours...

                                                            At least, the above is what I understood *could* be possible from ibill's own documentation!

                                                            But I could be wrong (I'm sure you'll tell me in a heartbeat!)
                                                            Flashcash : Converting 1:700 with *crap* traffic!

                                                            Comment

                                                            • Kimmykim
                                                              bitchslapping zebras!!!!!
                                                              • Jun 2001
                                                              • 16015

                                                              #130
                                                              Guys it's not so simplistic or so easy. Once again, I can't speak for IBill but I'd bet they have safeguards in place to cover just this type of situation

                                                              Comment

                                                              Working...