Live data from Hacker News

Google AdWords Exploit Seen in the Wild

wp.josh.com

51–60 of 163 posts

Re: Google AdWords Exploit Seen in the Wild

#51
post #15

What happens when you call the number?

From seeing scam pranks on youtube. You get a scam call center telling you to install teamviewer or something. They run netstat and open the event viewer, tell you your pc has hundreds of errors and people spying on you. If you're lucky they run syskey [0] as form of ransomware. In the end they ask $200 to fix your pc. [0] https://en.wikipedia.org/wiki/Syskey

Thankfully, Microsoft actually removed Syskey from Windows 10, both because it was no longer a useful security feature, and almost solely used today by these scammers.

Re: Google AdWords Exploit Seen in the Wild

#52

Are there trademark infringement issues here, particular on Google's part? They are getting paid (probably a lot) to display this ad, and are explicitly allowing buyers to lie about their identity. If I were eBay, I'd be getting my lawyers on this immediately. Every dollar getting paid to Google for this ad is a dollar out of my revenue, and a lost customer, and is illegal.

https://www.forbes.com/sites/ericgoldman/2012/10/22/google-d...

https://en.m.wikipedia.org/wiki/Rosetta_Stone_Ltd._v._Google....

Re: Google AdWords Exploit Seen in the Wild

#53
post #48
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

It appears here that the redirection to the ebay.com destination url is not happening and that the user ends up on a different domain. That kind of situation is usually detected when ads are entered into the Google Ads* platform for review, with ads then rejected for "destination url mismatch". One thing checked is that the final destination url after all redirects matches what is specified in the ad's final url fiel…

Wow it seems trivial to trick Google's bots with these links. Have the page redirect until ad is approved, profit?

I'm sure it's easy to find their bot IP's too. Just make a bunch of terrible ads that nobody will click and see who visits the url.

Google needs to abolish this link policy, I don't see how it's enforceable

Re: Google AdWords Exploit Seen in the Wild

#55
post #6
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

Wow. What a impressively dumb "feature".

Online ad campaigns depend on redirects to reconcile clicks and analytics. It is dumb, but if you want to get customers/make money in the ad space, you have to support this.

Re: Google AdWords Exploit Seen in the Wild

#56
post #11

Earlier quoted context omitted.

If a large brand like Uber wouldn‘t buy (really expensive) keywords like „uber“ some of their rivals like lyft could bid on it. So uber would lose a customer who was really interested in uber to lyft. Exchange company names how you like. Its especially expensive for shops etc. Google will not change any rules to forbid bidding on brand names because they are making a ton of money of it. Think of something like amazon…

Wait ... what ... you can "buy" keywords?

Of course, that's what Google is basically. You search for something and they show an ad related to that. And those ads are not random but related to your search.

Or am I not getting some joke?

Re: Google AdWords Exploit Seen in the Wild

#57
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

I've had this problem on Facebook. I've reported some ads for various (relatively benign) scams for herbals and the like, that use a famous newspaper as 'their url', when they have nothing to do with it.

Facebook closed my report as 'not against ad policy'.

Anyway, this is actually easily fixed without losing tracking/campaign flexibility, by requiring ad orders to be signed by a certificate valid for the target domain, if the URL is different from the displayed one.

Re: Google AdWords Exploit Seen in the Wild

#58
post #32

Interesting that they go through so much trouble to spoof eBay.com and then not try to collect logins/passwords.

My understanding is that's not the purpose of the obfuscation. The parties doing this don't generally want to hack users or compromise accounts, they want people to go to their site instead of the more recognizable one. If they start actively phishing users this way they're solidly in illegal hacking territory on a pretty massive scale. What they're currently doing is "only" a "growth hack" to get more people on thei…

I agree with you in premise, but if you read the post, the website users were redirected to was a phishing site: https://wpdotjoshdotcom.files.wordpress.com/2019/05/snag-003...

Re: Google AdWords Exploit Seen in the Wild

#59
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

Wouldn’t a simple solution to this problem be to prove ownership of the domain you want displayed? Why is this not done yet, this is almost standard practice nowadays for many types of services.

Re: Google AdWords Exploit Seen in the Wild

#60
post #48

Earlier quoted context omitted.

It appears here that the redirection to the ebay.com destination url is not happening and that the user ends up on a different domain. That kind of situation is usually detected when ads are entered into the Google Ads* platform for review, with ads then rejected for "destination url mismatch". One thing checked is that the final destination url after all redirects matches what is specified in the ad's final url fiel…

Wow it seems trivial to trick Google's bots with these links. Have the page redirect until ad is approved, profit? I'm sure it's easy to find their bot IP's too. Just make a bunch of terrible ads that nobody will click and see who visits the url. Google needs to abolish this link policy, I don't see how it's enforceable

> Have the page redirect until ad is approved, profit?

Wouldn't work - they do periodic checks after approval. Something more sophisticated appears to be going on here.

>Google needs to abolish this link policy, I don't see how it's enforceable

Link analytics and link trackers are perfectly legitimate. There are many situations in which it is necessary or desirable to go via intermediate urls before the final destination. Throwing out the baby with the bathwater definitely isn't the answer here.

Post reply on HN