Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand how a bunch of redirects from his own sites simulates clicking on ads.


What is a click other than a "redirect" from one page to another? Add the appropriate parameters in the HTTP call and you are done. There is no need for actual user interaction for an HTTP call to be considered a "click".

Take a look at the screenshots: You will see that the redirects are URLs that you would "click" as a user to see an ad.

The clever part is that the "clicks" come from a wide variety of IPs, wide variety of browsers, and on different times.


[deleted]



Panos,

Where is the click on the adserver? I don't see that.


The screenshots above redirect to a search engine. (My IP had already been used for clicks and I could not generate the ad clicks for the screenshots)

If you want to see the scheme in action go to the new domains set up by the scammer:

http://www.kidsbeanbags1.com/index2.php

http://www.kingsizemattress1.com/index2.php

http://www.neckpillow1.com/index2.php

http://www.pillowtopmattress1.com/index2.php

http://www.pillowcovers1.com/index2.php

http://www.tempurpillow1.com/index2.php

http://www.contourpillow1.com/index2.php

If you want to observe the full click behavior: Chrome->Tools->DeveloperTools->Network

Let me know what you see. Curious to see if the scammer changed the behavior.


I saw the same kind of redirects as written up.

I still don't understand.

Where is the money? Is this CPC or CPM fraud?

It couldn't be CPC because there is no landing page served.

It couldn't be CPM because there is no ad served.


Confirming your observation.

I got the explanation: All the targeted sites (e.g., Mevio or Current.TV) now have filters in place. So you will not be able to see the actual landing pages. The landing page will be a blank page as the ad click will not work.

Btw for the record: It is mainly CPC fraud, sending (invisible) traffic to sites like Mevio and Current.TV which serve mainly CPM ads.


no, that still does not make sense.

If there is a click on an adserver, where is it in this bunch of redirects?


OK, I added the screenshots that show the adservers as well. When I was writing the article, I was told not to involve any party that has been defrauded and did not give explicit permission to be involved in the story. Since I see them mentioned in the WSJ article, I feel that I can put the relevant screenshots there as well.


thats what I am wondering, how is sending the actual click? does he have access to a PPC feed (from who?) or is he somehow getting the links for the link via javascript and for what ad networks ??


That, unfortunately, I could not observe. My intuition says that he had a PPC feed for his parked domains and he was using the click.mygeek.com etc services to click on them.

Note that he was not always clicking on the links, to maintain a reasonable low clickthrough rate for the ads.


Another commenter explained it this way.

You run a video site or a search engine that serves CPM ads. If you can buy PPC cheap enough, you can arbitrage and make money.

PPC from Google is expensive, but there are companies that sell cheap clicks. Some publishers on these ad networks run porn sites with hidden iframes that generate the clickthrough.

However, iframes generate a http referer, and this gives away the rather dubious traffic sources. The series of redirected clicks are used to subvert click fraud analysis.


Definitely the target publishers were "video sites or a search engines that serve CPM ads". So this explanation is most probably pretty accurate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: