Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a stunning article, which deserves a close reading if you are advertising online and paying per click. If you've wondered why some of the clicks you've paid for seem to come from very unlikely sources, you might have an answer.

In this scheme, a 'fraudulent' site buys traffic from a 'legitimate' one in the form of a popup or popunder. In some way they get a page opened that they have control over. This page includes a number of invisible iframes, each of which loads a URL for an innocent looking parked domain that belongs to an ad network. So far no one has been defrauded.

But instead of just loading and not displaying that ad-laden page parked page, the site redirects the user's browser to act as if it has clicked on one of those ads. The results of this click are never seen by the user, as it's in a hidden iframe, but the contents are delivered to the user's browser. From an IP and HTTP header analysis it looks a lot like a real user had clicked on the ad.

The owner of the parked domains then collects a few cents per click, or really, per redirect. And it's very hard for the ad network to realize that they've been had. As Panos points out, they might not even look too hard, since they're making more per fraudulent click than the scammer. And the advertiser would have to go pretty deep to figure out that the click was fake, since the content was actually delivered to a legitimate user, just not one who ever actually saw the ad.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: