GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Spyware is Killing our industry. Proof inside! Long Thread and VIDEO (https://gfy.com/showthread.php?t=720781)

Big_Red 05-05-2007 10:25 AM

100.....,..

joy 05-07-2007 05:11 AM

Notice your sales on May 2, 3, 4, 5th? Now watch what happens as of 6th.

If we all dont unite and do something the sky WILL fall

timberlands 05-07-2007 05:18 AM

spyware doctor = best anti spyware program.

joy 05-07-2007 08:44 AM

Quote:

Originally Posted by timberlands (Post 12384611)
spyware doctor = best anti spyware program.

Nope, once infected with the stuff in this thread there is not much they can do except reinstall.

The best solution (besides taking these fuckheads down..thats in the works btw) is to make the surfers awear.

StickyGreen 05-07-2007 06:31 PM

Bump.../

Andreas 05-08-2007 03:58 AM

i lost about 80% of my sales mostly from payed spots from GTS :(

Humpy Leftnut 05-08-2007 04:06 AM

lol what? You bought GTS traffic and then suddenly your sales took a nosedive?

Corleone 05-08-2007 04:33 AM

very good thread

Andreas 05-08-2007 06:50 AM

Quote:

Originally Posted by Humpy Leftnut (Post 12390848)
lol what? You bought GTS traffic and then suddenly your sales took a nosedive?

I've been buying gallery spots from them for a long time not that i bought it now for the first time then the sales went down :) I am saying that sales are down 80% from those spots compared to a few weeks ago.

VforVendetta 05-08-2007 08:46 AM

today bump

RawAlex 05-08-2007 08:54 AM

The truly big issue here is that the program owners aren't feeling any pain because sales continue for them, just different affiliates are getting credited for the sales. Something will happen when the spyware guys start massively redirecting traffic away from program join pages and onto other program's join pages. Then suddenly the "Bros club" will wake up and smell the shit they are standing in.

Until then, it sucks to be an affiliate.

Jizar II 05-08-2007 02:41 PM

Quote:

Originally Posted by joy (Post 12369973)
May 4th. This is why sales are down to the point that they are the past 3-4 days

Sponsors need to open their eyes and look at the big picture. Look at your sales the past 3-4 days, compare your join page VS 1st bill page. You will see that your join page traffic has not changed, however your biller page traffic went to shit.

this sounds like that we're experiencing on our paysite, have you heard about other owners who are having these direct issues? :Oh crap

biskoppen 05-08-2007 02:59 PM

Don't ask where I know this from but...

These guys are stealing ALOT OF FUCKING sales (more than you can imagine) and for some unknown reason their script do not, in many cases at least, change the refering URL when they replace your affiliate ID with their affiliate ID when your surfer clicks his way to the sponsor..

So... these guys accounts has alot of sales with your domains (your galleries) as the refering URL..

So... the program owners who looks at their data on a regular basis is fully aware of this problem .. and knows it's HUGE

I'm not sure how many surfers who's infected with this CODEC trojan, but I think it's MANY .. the way it's installed is genious... "You need this codec to watch this movie" .. I almost clicked the fucking download the first time I saw it... and I'm just average stupid ;)

I'm afraid we're talking 1000s of stolen sales a day..

joy 05-08-2007 03:04 PM

Quote:

Originally Posted by Jizar II (Post 12393889)
this sounds like that we're experiencing on our paysite, have you heard about other owners who are having these direct issues? :Oh crap

99% of programs are seeing this. Rather than face the facts and attack the issue at hand they are busy changing billers, hosting and tweaking tours.

They/we will all get how serious this is soon.....I hope

Jizar II 05-08-2007 03:11 PM

Quote:

Originally Posted by joy (Post 12394065)
99% of programs are seeing this. Rather than face the facts and attack the issue at hand they are busy changing billers, hosting and tweaking tours.

They/we will all get how serious this is soon.....I hope

i would like to talk with you, can i have your icq/email?

StarkReality 05-08-2007 03:29 PM

Quote:

Originally Posted by RawAlex (Post 12392063)
The truly big issue here is that the program owners aren't feeling any pain because sales continue for them, just different affiliates are getting credited for the sales. Something will happen when the spyware guys start massively redirecting traffic away from program join pages and onto other program's join pages. Then suddenly the "Bros club" will wake up and smell the shit they are standing in.

Until then, it sucks to be an affiliate.

Since most programs depend on affiliates and don't have loads of inhouse traffic, they'll be fucked...as soon as really big affiliates look for other programs because ratios go shit.

It's only a matter of time and owners still have the choice if they'll be losers or winners in this ugly game.

RawAlex 05-08-2007 03:35 PM

Quote:

Originally Posted by StarkReality (Post 12394298)
Since most programs depend on affiliates and don't have loads of inhouse traffic, they'll be fucked...as soon as really big affiliates look for other programs because ratios go shit.

It's only a matter of time and owners still have the choice if they'll be losers or winners in this ugly game.

Yes, but it takes time - most people aren't going to go back and pull up long embedded links, they aren't going to kill off older galleries... so there is plenty of traffic that just doesn't go away. The program owners will feel it though if they lose major listings because they don't convert.

joy 05-08-2007 03:36 PM

Quote:

Originally Posted by Jizar II (Post 12394139)
i would like to talk with you, can i have your icq/email?

What's your email? I will hit you up asap

Aussie Rebel 05-08-2007 05:05 PM

Bump, For the program owners to read

Quickdraw 05-08-2007 05:32 PM

This is only the tip of things but it is a good example of how traffic is being diverted from many places.

The following comes from 1 click on an infected machine. Everything in the quote all took place in about a second.
Notice that after clicking an ad on the Google results, it takes the user through the Google ad to the intended advertiser. It is then redirected so fast that most people won't even realize they even went to the intended site.

So, the advertisers on Google(and the other engines) are getting hit by a PPC charge, for traffic that really doesn't even make it to their site, but for a millisecond.

The traffic that is redirected is sent to various smaller PPC engines, through multiple redirects. The user finally lands at a, non-affiliated, top paying advertiser for these various PPC engines and the terms used. In this case the term was 'tomato seeds'.

this is happening for all keywords and all niches, mainstream and adult.


Code:

GET http://www.google.com/search?hl=en&q=tomato+seeds&btnG=Google+Search
200 OK

GET http://85.255.119.189/frame.php
200 OK
##### Ad click started here #####
GET http://www.google.com/pagead/iclk?sa=l&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2
302 Found to http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB

GET http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB
302 Found to http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA

GET http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA
200 OK

GET http://85.255.119.189/click.php?PHPSESSID=B043EDE50C4D4AACA85F6083F8EFF1CF&qq=b01bb5eae6568bd2aa6bd8a775309ac1&id=1&qnaes={B043EDE5-0C4D-4AAC-A85F-6083F8EFF1CF}
302 Found to http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF

GET http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF
302 Found to /dclick.php?c=0855c9e17bd60d2c196b&r=1

GET http://64.111.208.122/dclick.php?c=0855c9e17bd60d2c196b&r=1
302 Found to http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1

GET http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1
302 Found to http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US

GET http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US
302 Found to http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM

GET http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM
200 OK

POST http://67.29.139.220/jump/?affiliate=ss22&subid=1936_1615&Terms=tomato%20seeds&e=
200 OK
#### This is the top position on abcsearch.com ####
GET http://samson-exotic-gardens.com/14.html
200 OK

In this redirect it appears they are using abcsearch.com.
They use spoofed referrers such as indaxis.info/search.php?q=term-used and many other similarly styled refs.

Huggles 05-08-2007 05:37 PM

Quote:

Originally Posted by Quickdraw (Post 12394914)
This is only the tip of things but it is a good example of how traffic is being diverted from many places.

The following comes from 1 click on an infected machine. Everything in the quote all took place in about a second.
Notice that after clicking an ad on the Google results, it takes the user through the Google ad to the intended advertiser. It is then redirected so fast that most people won't even realize they even went to the intended site.

So, the advertisers on Google(and the other engines) are getting hit by a PPC charge, for traffic that really doesn't even make it to their site, but for a millisecond.

The traffic that is redirected is sent to various smaller PPC engines, through multiple redirects. The user finally lands at a, non-affiliated, top paying advertiser for these various PPC engines and the terms used. In this case the term was 'tomato seeds'.

this is happening for all keywords and all niches, mainstream and adult.



Sickening.

StarkReality 05-08-2007 05:58 PM

Quote:

Originally Posted by Quickdraw (Post 12394914)
This is only the tip of things but it is a good example of how traffic is being diverted from many places.

The following comes from 1 click on an infected machine. Everything in the quote all took place in about a second.
Notice that after clicking an ad on the Google results, it takes the user through the Google ad to the intended advertiser. It is then redirected so fast that most people won't even realize they even went to the intended site.

So, the advertisers on Google(and the other engines) are getting hit by a PPC charge, for traffic that really doesn't even make it to their site, but for a millisecond.

The traffic that is redirected is sent to various smaller PPC engines, through multiple redirects. The user finally lands at a, non-affiliated, top paying advertiser for these various PPC engines and the terms used. In this case the term was 'tomato seeds'.

this is happening for all keywords and all niches, mainstream and adult.


Code:

GET http://www.google.com/search?hl=en&q=tomato+seeds&btnG=Google+Search
200 OK

GET http://85.255.119.189/frame.php
200 OK
##### Ad click started here #####
GET http://www.google.com/pagead/iclk?sa=l&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2
302 Found to http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB

GET http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB
302 Found to http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA

GET http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA
200 OK

GET http://85.255.119.189/click.php?PHPSESSID=B043EDE50C4D4AACA85F6083F8EFF1CF&qq=b01bb5eae6568bd2aa6bd8a775309ac1&id=1&qnaes={B043EDE5-0C4D-4AAC-A85F-6083F8EFF1CF}
302 Found to http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF

GET http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF
302 Found to /dclick.php?c=0855c9e17bd60d2c196b&r=1

GET http://64.111.208.122/dclick.php?c=0855c9e17bd60d2c196b&r=1
302 Found to http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1

GET http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1
302 Found to http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US

GET http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US
302 Found to http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM

GET http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM
200 OK

POST http://67.29.139.220/jump/?affiliate=ss22&subid=1936_1615&Terms=tomato%20seeds&e=
200 OK
#### This is the top position on abcsearch.com ####
GET http://samson-exotic-gardens.com/14.html
200 OK

In this redirect it appears they are using abcsearch.com.
They use spoofed referrers such as indaxis.info/search.php?q=term-used and many other similarly styled refs.

Looks like many chinese sweatshop clickers will have to look for a new job...

Imagine the sums we are talking about with hundreds of thousands of infections daily...this isn't a few script kiddies making some money, it's organized crime at a high level.

Jizar II 05-08-2007 06:12 PM

Quote:

Originally Posted by joy (Post 12394335)
What's your email? I will hit you up asap

hit me up: 3lettercom AT gmail DOT com

thanks!

Corleone 05-08-2007 09:07 PM

this thread needs a bump

Huggles 05-08-2007 10:02 PM

Does anyone really care?


Is anyone doing anything to stop this?


What can I do?

NTSS 05-09-2007 01:02 AM

early morning bump

biskoppen 05-09-2007 01:35 AM

bump..............

StarkReality 05-09-2007 02:16 AM

Quote:

Originally Posted by Huggles (Post 12395773)
Does anyone really care?

Is anyone doing anything to stop this?


What can I do?

The problem is that all affiliates can do it trying to educate surfers, make them aware that this spyware can be used for identity theft, theft of personal data, etc...although a guy with his cock in his hand is rather hard to educate.

The only really effective way of getting rid of these parasites is shutting down their affiliate accounts on sight. It's up to the program owners to watch for new affiliates suddenly generating huge sales volumes, especially if these affiliates aren't from the US, canada or western europe.

dav3 05-09-2007 04:25 AM

greedy bastards

biskoppen 05-09-2007 09:42 AM

bump...............

NTSS 05-09-2007 09:49 AM

Theres got to be a way to prevent ref code swapping and it has to be done on the sponsor end. I don't have have a clue how all that shit works but i find it hard to believe that there is no way to encode ids to stop this.

RawAlex 05-09-2007 10:37 AM

NTSS: There are some ways that this could be addressed, but most programs aren't into it because (a) it would require time, effort, and programming, and (b) they are still making sales, just different affiliates are getting creditted.

Until the programs themselves start to feel true pain, there will be nothing done.

NetHorse 05-09-2007 10:39 AM

This is news? This has been going on for awhile, and it's not just the online adult industry that's affected.

biskoppen 05-09-2007 11:45 AM

I think a possible way to stop affiliate code replacements would be for all affiliates to be allowed to make domain aliases for the sites they're promoting...

Example :

You are an affiliate promoting cumfiesta.com .. when you link to the site like this cumfiesta.com?affid=mrcool then these thieves script see that the infected computer is loading the cumfiesta.com domain and then maked the replacement of the affid...

The affiliate could then reg his own domain for this site.. like cumfiestatour.com (nastydollar then need to add this as an alias to cumfiesta.com) then the trojan script can't recognize the domain and can't make any affid replacement..

RawAlex 05-09-2007 12:42 PM

Quote:

Originally Posted by intehend (Post 12398199)
This is news? This has been going on for awhile, and it's not just the online adult industry that's affected.

it's not news. But like any annoyance, nobody really talks about it until it becomes a real major issue. At this point, affiliates on many programs are seeing major sales swings, and now it would appear that CCBill may have been targetted, at least for some sites using them for sales and stats. It is finally news because the affiliates are feeling the pain.

My own experience shows conversions getting worse and worse, yet most program owners not saying a peep or discussing problems, so I have to assume they aren't seeing the same issues their affiliates are seeing.

So yeah, it's news, only because the minor cut has turned into a ruptured artery, and the lifeblood of the industry is slowly dripping out.

milambur 05-09-2007 01:03 PM

Quote:

Originally Posted by biskoppen (Post 12398563)
I think a possible way to stop affiliate code replacements would be for all affiliates to be allowed to make domain aliases for the sites they're promoting...

Example :

You are an affiliate promoting cumfiesta.com .. when you link to the site like this cumfiesta.com?affid=mrcool then these thieves script see that the infected computer is loading the cumfiesta.com domain and then maked the replacement of the affid...

The affiliate could then reg his own domain for this site.. like cumfiestatour.com (nastydollar then need to add this as an alias to cumfiesta.com) then the trojan script can't recognize the domain and can't make any affid replacement..

Might work on some, but most will just grab the sale as it hits the processor. If you move signups to the same domain you are gonna need SSL certificates for each alias. Besides, they'll catch on after a while and start adding the domains to the redirect database.

The thing is that the program owners can't be so aggressive in this issue or they risk getting their traffic redirected insted of just sent to an malware affiliate, my bet is many of them are aware of the malware affiliates and some probably shave them pretty hard. It's pretty easy to track what affiliates get malware sales.

When this become as big a problem for mainstream as it is for adult, then we will see improvements, not until then. I'm afraid that the only solution in the end is that microsoft fixes the rootkit problem and puts a really good anti-malware program in windows update.

Tom_PM 05-09-2007 01:13 PM

I will just say that I have reported all threads and issues such as this and they are taken seriously. I will continue to do so.

FiReC 05-09-2007 03:13 PM

Quote:

Originally Posted by Quickdraw (Post 12394914)
This is only the tip of things but it is a good example of how traffic is being diverted from many places.

The following comes from 1 click on an infected machine. Everything in the quote all took place in about a second.
Notice that after clicking an ad on the Google results, it takes the user through the Google ad to the intended advertiser. It is then redirected so fast that most people won't even realize they even went to the intended site.

So, the advertisers on Google(and the other engines) are getting hit by a PPC charge, for traffic that really doesn't even make it to their site, but for a millisecond.

The traffic that is redirected is sent to various smaller PPC engines, through multiple redirects. The user finally lands at a, non-affiliated, top paying advertiser for these various PPC engines and the terms used. In this case the term was 'tomato seeds'.

this is happening for all keywords and all niches, mainstream and adult.


Code:

GET http://www.google.com/search?hl=en&q=tomato+seeds&btnG=Google+Search
200 OK

GET http://85.255.119.189/frame.php
200 OK
##### Ad click started here #####
GET http://www.google.com/pagead/iclk?sa=l&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2
302 Found to http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB

GET http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB
302 Found to http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA

GET http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA
200 OK

GET http://85.255.119.189/click.php?PHPSESSID=B043EDE50C4D4AACA85F6083F8EFF1CF&qq=b01bb5eae6568bd2aa6bd8a775309ac1&id=1&qnaes={B043EDE5-0C4D-4AAC-A85F-6083F8EFF1CF}
302 Found to http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF

GET http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF
302 Found to /dclick.php?c=0855c9e17bd60d2c196b&r=1

GET http://64.111.208.122/dclick.php?c=0855c9e17bd60d2c196b&r=1
302 Found to http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1

GET http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1
302 Found to http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US

GET http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US
302 Found to http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM

GET http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM
200 OK

POST http://67.29.139.220/jump/?affiliate=ss22&subid=1936_1615&Terms=tomato%20seeds&e=
200 OK
#### This is the top position on abcsearch.com ####
GET http://samson-exotic-gardens.com/14.html
200 OK

In this redirect it appears they are using abcsearch.com.
They use spoofed referrers such as indaxis.info/search.php?q=term-used and many other similarly styled refs.

there we go finally some real info in this thread. these spyware guys are straight up stealing adult traffic and sending it to mainstream PPC buyers.

quickdraw hit me up on icq please:

4162727

joy 05-09-2007 06:54 PM

Quote:

Originally Posted by FiReC (Post 12399935)
there we go finally some real info in this thread. these spyware guys are straight up stealing adult traffic and sending it to mainstream PPC buyers.

quickdraw hit me up on icq please:

4162727

That's not the only place its going.

We have been deep into this shit since this thread was started and we are finding some things that when made public, it will rock the industry and not only will it shut down one of the biggest companies in the biz, it will also make the owners run and never look back.

Quickdraw 05-10-2007 07:38 AM

Quote:

Originally Posted by joy (Post 12401081)
That's not the only place its going.

We have been deep into this shit since this thread was started and we are finding some things that when made public, it will rock the industry and not only will it shut down one of the biggest companies in the biz, it will also make the owners run and never look back.

You mean shut down, change their name and come back like nothing happened like megapornbucks? :disgust

Quickdraw 05-10-2007 07:46 AM

Quote:

Originally Posted by FiReC (Post 12399935)
quickdraw hit me up on icq please:

Done . .

biskoppen 05-10-2007 09:40 AM

bump..................

mattz 05-10-2007 09:42 AM

too long for me to read, but I'll bump it

Tanker 05-10-2007 11:00 AM

Quote:

When this become as big a problem for mainstream as it is for adult, then we will see improvements, not until then. I'm afraid that the only solution in the end is that microsoft fixes the rootkit problem and puts a really good anti-malware program in windows update.

there needs to be an organization of webmasters to document what is going on and draft an email that everyone can send to M$ along with making surfers aware that they are infected who knows what else they are stealing besides traffic.

Taass 05-10-2007 11:21 AM

Quote:

Originally Posted by Tanker (Post 12404170)
there needs to be an organization of webmasters to document what is going on and draft an email that everyone can send to M$ along with making surfers aware that they are infected who knows what else they are stealing besides traffic.

Not only that.. there need to be an adult webmasters organization to cover our asses in everything that's hurting adult bizz.. Something that actively tracked down spyware installers, website hackers, password traders, shaving programs etc. and worked to shut them down..

Problem today is that with no organization we are just easy targets waiting for the next bad thing to happend :Oh crap

milambur 05-10-2007 12:34 PM

Quote:

Originally Posted by Tanker (Post 12404170)
there needs to be an organization of webmasters to document what is going on and draft an email that everyone can send to M$ along with making surfers aware that they are infected who knows what else they are stealing besides traffic.

What might actually make things happen is if we could show Microsoft, Yahoo and google how much money they are loosing on ad traffic due to malware. But that means the affiliate progams needs to step up and track how much of the traffic is lost.

joy 05-10-2007 01:27 PM

Quote:

Originally Posted by milambur (Post 12404715)
But that means the affiliate progams needs to step up and track how much of the traffic is lost.

Most program owners think this is just bullshit and are blaming the economy and the card processors.

ATTENTION PROGRAM OWNERS

Do yourselves a favor and please give me the benefit of the dought. See how nice sales were yesterday and how shitty they are today? Now, go look deep into your stats and compare yesterdays join page (YOUR JOIN PAGE) to processor page. You will see that your surfers never leave YOUR join page nor do they make it to the processor. Ain't that a kick in the ass?

Jizar II 05-10-2007 01:55 PM

BUMP - this is some scary shit :mad:

ghood 05-11-2007 06:48 AM

this thread needs to be bumped

porncargo 05-15-2007 04:20 AM

another bump


All times are GMT -7. The time now is 05:28 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123