Live data from Hacker News

Google AdWords Exploit Seen in the Wild

wp.josh.com

1–10 of 163 posts

Re: Google AdWords Exploit Seen in the Wild

#4
This is an explicit tool in adwords, believe it or not.

The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/, without the user seeing that bit of ugly.

It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

Re: Google AdWords Exploit Seen in the Wild

#5
Heh, interesting example.

I would have been weirded out by this specific ad, because when I worked at eBay one thing that got highlighted in a companywide announcement was that some executive had decided to stop running ads for eBay against google searches for "ebay", because that is obviously pointless. (And that this saved a ton of money on advertising without impacting traffic at all.)

With a result like that, I wouldn't have expected them to go back to advertising ebay.com on searches for "ebay".

Re: Google AdWords Exploit Seen in the Wild

#6
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

Wow. What a impressively dumb "feature".

Re: Google AdWords Exploit Seen in the Wild

#7
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

If Google enforced that hosts/domains matched, could you not redirect from your own host to the tracking provider (and them back to you)?

Re: Google AdWords Exploit Seen in the Wild

#9
Every once in a while I'll do a search on Google from a browser with no blocker for something like 'ebay' or some other big brand name and I'm always surprised to see that big brand name has bought ads for themselves, it never made sense since they're always the first search result anyways.

Now I can only assume two things...

1. Some number of those ads were scams 2. Some large number of people just blindly click on the first thing they see below the search box as long as it's close to whatever they search for.

Somewhat related... always surprised to see what search results come up in the IOS app store first for whatever app I'm searching for at the time. It's usually something else, like, search for Uber, first thing that comes up is Lyft.

Re: Google AdWords Exploit Seen in the Wild

#10

Heh, interesting example. I would have been weirded out by this specific ad, because when I worked at eBay one thing that got highlighted in a companywide announcement was that some executive had decided to stop running ads for eBay against google searches for "ebay", because that is obviously pointless. (And that this saved a ton of money on advertising without impacting traffic at all.) With a result like that, I w…

It's a famous story: https://slate.com/business/2013/03/paid-search-ads-did-ebay-...

That's probably why the malware author targeted the eBay keyword. Without any real competition, it would be cheaper for them to win top of page placement.

Post reply on HN