What happens when you call the number?
From seeing scam pranks on youtube. You get a scam call center telling you to install teamviewer or something. They run netstat and open the event viewer, tell you your pc has hundreds of errors and people spying on you. If you're lucky they run syskey [0] as form of ransomware. In the end they ask $200 to fix your pc. [0] https://en.wikipedia.org/wiki/Syskey
Google AdWords Exploit Seen in the Wild
51–60 of 163 posts
Re: Google AdWords Exploit Seen in the Wild
#52Are there trademark infringement issues here, particular on Google's part? They are getting paid (probably a lot) to display this ad, and are explicitly allowing buyers to lie about their identity. If I were eBay, I'd be getting my lawyers on this immediately. Every dollar getting paid to Google for this ad is a dollar out of my revenue, and a lost customer, and is illegal.
Re: Google AdWords Exploit Seen in the Wild
#53This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.
It appears here that the redirection to the ebay.com destination url is not happening and that the user ends up on a different domain. That kind of situation is usually detected when ads are entered into the Google Ads* platform for review, with ads then rejected for "destination url mismatch". One thing checked is that the final destination url after all redirects matches what is specified in the ad's final url fiel…
I'm sure it's easy to find their bot IP's too. Just make a bunch of terrible ads that nobody will click and see who visits the url.
Google needs to abolish this link policy, I don't see how it's enforceable
Re: Google AdWords Exploit Seen in the Wild
#54Re: Google AdWords Exploit Seen in the Wild
#55This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.
Wow. What a impressively dumb "feature".
Re: Google AdWords Exploit Seen in the Wild
#56Earlier quoted context omitted.
If a large brand like Uber wouldn‘t buy (really expensive) keywords like „uber“ some of their rivals like lyft could bid on it. So uber would lose a customer who was really interested in uber to lyft. Exchange company names how you like. Its especially expensive for shops etc. Google will not change any rules to forbid bidding on brand names because they are making a ton of money of it. Think of something like amazon…
Wait ... what ... you can "buy" keywords?
Or am I not getting some joke?
Re: Google AdWords Exploit Seen in the Wild
#57This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.
Facebook closed my report as 'not against ad policy'.
Anyway, this is actually easily fixed without losing tracking/campaign flexibility, by requiring ad orders to be signed by a certificate valid for the target domain, if the URL is different from the displayed one.
Re: Google AdWords Exploit Seen in the Wild
#58Interesting that they go through so much trouble to spoof eBay.com and then not try to collect logins/passwords.
My understanding is that's not the purpose of the obfuscation. The parties doing this don't generally want to hack users or compromise accounts, they want people to go to their site instead of the more recognizable one. If they start actively phishing users this way they're solidly in illegal hacking territory on a pretty massive scale. What they're currently doing is "only" a "growth hack" to get more people on thei…
Re: Google AdWords Exploit Seen in the Wild
#59This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.
Re: Google AdWords Exploit Seen in the Wild
#60Earlier quoted context omitted.
It appears here that the redirection to the ebay.com destination url is not happening and that the user ends up on a different domain. That kind of situation is usually detected when ads are entered into the Google Ads* platform for review, with ads then rejected for "destination url mismatch". One thing checked is that the final destination url after all redirects matches what is specified in the ad's final url fiel…
Wow it seems trivial to trick Google's bots with these links. Have the page redirect until ad is approved, profit? I'm sure it's easy to find their bot IP's too. Just make a bunch of terrible ads that nobody will click and see who visits the url. Google needs to abolish this link policy, I don't see how it's enforceable
Wouldn't work - they do periodic checks after approval. Something more sophisticated appears to be going on here.
>Google needs to abolish this link policy, I don't see how it's enforceable
Link analytics and link trackers are perfectly legitimate. There are many situations in which it is necessary or desirable to go via intermediate urls before the final destination. Throwing out the baby with the bathwater definitely isn't the answer here.