Live data from Hacker News

Hackers Make $5M a Day by Faking 300M Video Views

forbes.com

71–80 of 136 posts

Re: Hackers Make $5M a Day by Faking 300M Video Views

#71
post #36

Earlier quoted context omitted.

If you really want to put a dent in things, search for medical issues and click the law firm ads. I've seen clicks costing in the high hundreds.

For real? I also think that prices are extremely inflated. Even stuff which shows like hundred people a day costs you 8 dollar per click. No amount of selling will you get back the money. Imho something is wrong there...

Early on in my career I was an SEO Account Manager (barf) and mortgage lending PPC ads could run up to $50/click. This was in 2005. Having some specialized markets with clicks in the hundreds these days would make me raise an eyebrow, but certainly isn't shocking.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#73
post #15

Normally a "real browser" can't run 100s of ad players at once, but "methbrowser" is a node.js application with a C module that speaks Flash's plugin protocol directly. It simulates a dom, runs JavaScript in a node VM, but doesn't have to do any of the messy rendering that things like PhantomJS have to. It was discovered years ago because: * Their IP stack was acting like Linux[1] * Their flash player said "I'm Linux…

Given the complexity and quirks of modern browser engines it seems like it should be pretty easy to detect this type of custom "browser".

Aah, they were doing it for the last 10 years or so. People who are serious into botting have software that basicaly runs the browser in a vm.

The level of programming skill in the "industrial scale botting" community is high. Top tier botters can easily get into +$100k club if they were doing whitehat stuff.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#74
post #50
post #15

Normally a "real browser" can't run 100s of ad players at once, but "methbrowser" is a node.js application with a C module that speaks Flash's plugin protocol directly. It simulates a dom, runs JavaScript in a node VM, but doesn't have to do any of the messy rendering that things like PhantomJS have to. It was discovered years ago because: * Their IP stack was acting like Linux[1] * Their flash player said "I'm Linux…

> It was discovered years ago And yet they're still active with the same tech stack.

They only have to do the very minimum to recover from detection. The incentive is for them to keep the largest possible bag of tricks ready to deploy every time they get a dip in revenue due to fraud detection to milk the fraud. Besides, most of the countermeasure takes the form of javascript to be executed by the client, since the fraudsters control the client, they can alter the operating environment of the fraud detection as needed.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#75
post #37

Earlier quoted context omitted.

Can we have a spamhaus for ad fraud? * list of botnet infected IPs participating in ad fraud * list of offending/incompetent SSP blindly accepting forged requests

> Can we have a spamhaus for ad fraud? There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent. The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be…

I don't understand ad networks enough to grasp how fraudulent ad inventory works, but as this article shows - you can make a killing exploiting it..

As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?

Re: Hackers Make $5M a Day by Faking 300M Video Views

#76

Is that the biggest? From 'the past' I believe (but no proof) that the fraud on normal display ads was/is much higher. Bot generated ad clicks, bot generated content to drive up ad prices etc should be much higher than $5m even by individual hacker groups? Maybe video ad clicks are easier to fake but worth less?

If you take the low estimate of 3m$ a day, this is $1B a year. The often quoted figure I've seen for the size of the ad fraud "market" is $7B. That's a big chunk of a "market" that is mostly cottage industry. And as a bonus, they target the highly profitable end of the spectrum.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#77
post #15

Normally a "real browser" can't run 100s of ad players at once, but "methbrowser" is a node.js application with a C module that speaks Flash's plugin protocol directly. It simulates a dom, runs JavaScript in a node VM, but doesn't have to do any of the messy rendering that things like PhantomJS have to. It was discovered years ago because: * Their IP stack was acting like Linux[1] * Their flash player said "I'm Linux…

Speaking of DNS, one of the sdf nameservers you are using is very slow or non-responsive: ns-a.sdf.org

It reminds me of ns.cnet.com

Re: Hackers Make $5M a Day by Faking 300M Video Views

#79
post #37

Earlier quoted context omitted.

> Can we have a spamhaus for ad fraud? There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent. The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be…

I upvoted you because of your helpful list.

Hm I can't seem to see any list. Where is it?

Re: Hackers Make $5M a Day by Faking 300M Video Views

#80
post #75
post #37

Earlier quoted context omitted.

> Can we have a spamhaus for ad fraud? There are a lot of vendors in this space now, offering various kinds of "spamhaus"-type solutions. They're all crap because they operate blacklists of various kinds to keep their customers dependent. The ideal scenario is for ad networks/SSPs to implement the anti-fraud technology themselves, however getting there from here is difficult: The first ad network to go clean will be…

I don't understand ad networks enough to grasp how fraudulent ad inventory works, but as this article shows - you can make a killing exploiting it.. As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?

> I don't understand ad networks enough to grasp how fraudulent ad inventory works, but as this article shows - you can make a killing exploiting it..

Someone has some "sites" that they show to an ad network or an advertiser and tries to sell the impressions on those sites. They receive "ad tags" in exchange, and the theory is that users are exposed to the ads shown by those ad tags, and the advertiser is satisfied.

However, once they have "ad tags", they can do whatever they want with them. They can find the URL signal that represents "give me money" and arrange to fire that signal.

> As is stands, is there any sort of compliance measure (or regulatory body) to monitor/prevent ad fraud in these networks?

No.

The Media Rating Council[1] was endowed by congress with special powers that allow participants to talk to each other antitrust protections kicking in, but these conversations are extremely non-productive.

[1]: http://mediaratingcouncil.org/

Post reply on HN