Slashdot Mirror


Google AdSense Click Fraud Made Possible By Uncloaking Advertisers' Sites

An anonymous reader writes: A Spanish researcher claims to have uncovered a vulnerability in the security procedures of Google's AdSense program which would allow a third party to manipulate clicks on Google's syndicated ad service by 'de-cloaking' the obfuscated advertiser URLs that Google AdSense placements provide as links. He has also provided downloadable PHP files to show the exploit in action.

20 of 50 comments (clear)

  1. Java != javascript by agm · · Score: 4, Interesting

    The document mentioned in the summary repeatedly uses the term "Java" when they mean "javascript". That's such a rookie mistake that it's difficult to take anything else they say seriously.

    1. Re:Java != javascript by JustAnotherOldGuy · · Score: 2

      The document mentioned in the summary repeatedly uses the term "Java" when they mean "javascript". That's such a rookie mistake that it's difficult to take anything else they say seriously.

      Yeah, mixing up "java" and "javascript" is kind of a conversation-stopper as far as I'm concerned. It makes my Credibility-O-Meter drop into the negative numbers.

      What he's outlined may well be true, but damn, that's is the kind of mistake that makes you wince.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    2. Re:Java != javascript by Jack9 · · Score: 1

      I think Java is being used correctly (in the PDF/paper http://arxiv.org/pdf/1509.0774... ) and the article linked, does not confuse the terms.

      --

      Often wrong but never in doubt.
      I am Jack9.
      Everyone knows me.
    3. Re:Java != javascript by Anonymous Coward · · Score: 2, Informative

      It's absolutely not. Look at Figure 1 of the PDF you linked. They show JavaScript code (that is clearly identified as such for someone who doesn't even know what it is), but call it Java code. They even go on to call JavaScript files Java files. These are two totally different things. I didn't bother reading any more, but I am sure this is consistently wrong throughout the paper.

    4. Re:Java != javascript by Anonymous Coward · · Score: 2, Insightful

      Meh... half the people on this site still use the term "hacker" over "cracker."

    5. Re:Java != javascript by Xenx · · Score: 2

      that's is the kind of mistake that makes you wince.

      I don't know if I should laugh or wince at that mistake.

    6. Re:Java != javascript by phantomfive · · Score: 1

      Nobody uses "cracker" in that sense anymore, get over it.

      Yeah, kind of a weird thing, right?
      We have hack-a-day, hacker-space, life-hacker, all kinds of things where the MIT meaning of the word "hacker" has entered into the mainstream.
      And yet the word "hacker" as a malicious attacker is also perfectly viable in mainstream.

      Thus we have a word that is both extremely negative and fairly positive, and yet collisions are rare. People always seem to be able to figure out what is meant.

      --
      "First they came for the slanderers and i said nothing."
    7. Re:Java != javascript by Bing+Tsher+E · · Score: 1

      Well, 'people on the inside' easily figure out what is meant. The regular folks just back slowly out of the room. That's appealing for people 'on the inside' who want to remain an elite.

    8. Re:Java != javascript by kelemvor4 · · Score: 1

      I think Java is being used correctly (in the PDF/paper http://arxiv.org/pdf/1509.0774... ) and the article linked, does not confuse the terms.

      You're mistaken. They include the source. It's definitely javascript despite the article referencing it as a "Google Java Applet". Maybe he wrote the article in Yahoo Go on his Microsoft iPad.

    9. Re:Java != javascript by Jack9 · · Score: 1

      I am mistaken. Apologies.

      --

      Often wrong but never in doubt.
      I am Jack9.
      Everyone knows me.
    10. Re:Java != javascript by hairyfeet · · Score: 1

      Uhhh the guy IS Spanish, isn't it possible its simply a translation error or due to the fact English isn't his native tongue?

      --
      ACs don't waste your time replying, your posts are never seen by me.
    11. Re:Java != javascript by Fnord666 · · Score: 1

      I think Java is being used correctly (in the PDF/paper

      Maybe this brief quote will clear things up:

      The java file "show_ads.js" embeds the ads in the target website HTML code once it has been completely loaded in the browser.

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  2. oh no by Anonymous Coward · · Score: 1

    OH NO! NOT... PHP FILES?!?!?! What will we do?!?!?! Gaah, php files.....

    1. Re:oh no by rudy_wayne · · Score: 1

      Except the link that says "downloadable PHP files" takes you to a PDF.

    2. Re:oh no by Fnord666 · · Score: 1

      Except the link that says "downloadable PHP files" takes you to a PDF.

      Here is a link to the source code mentioned.

      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  3. Unbelievable by JustAnotherOldGuy · · Score: 1

    There are ways to defraud The Google? That's unpossible!

    --
    Just cruising through this digital world at 33 1/3 rpm...
    1. Re:Unbelievable by Drakona4 · · Score: 1

      Sarcasm?

    2. Re:Unbelievable by JustAnotherOldGuy · · Score: 1

      Sarcasm?

      Heaven forbid, lol.

      --
      Just cruising through this digital world at 33 1/3 rpm...
  4. Security Through Obscurity by Fnord666 · · Score: 1

    This is just another example of how security through obscurity will never work. At the end of the day the client browser ends up with a URL for the user to click on to view the ad. No amount of obfuscation or iframe shell games can change this fact. Game over.

    --
    'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  5. Re:UBlock & Ghostery don't do as much by thoromyr · · Score: 1

    dang. its a shame I don't have mod points. My rule is always to find posts to mod up, never mod down. But this drivel should be modded down.

    go apk! fight the power! you are not alone! (well, yes, you are very very alone in that basement)