View Single Post
Old 09-05-2008, 11:41 AM   #63 (permalink)
MajorTom
Contributing Member
 
MajorTom's Avatar
 
Join Date: 08-29-07
Location: FL
Posts: 97
iTrader: 0 / 0%
MajorTom is a jewel in the roughMajorTom is a jewel in the roughMajorTom is a jewel in the roughMajorTom is a jewel in the roughMajorTom is a jewel in the roughMajorTom is a jewel in the roughMajorTom is a jewel in the rough
AFAIK - a cookie can't be stuffed via a remote image on a forum.

Cookies can only originate and be read from the domains they were set on. Even if a black hat programmer were using libcurl with cookies enabled, the cookie file would be stored on the programmer's server and not on the intended victim's browser.

Second, if the black hat were trying to accomplish pulling a remote page and setting a cookie via Javascript/Ajax createElement and appendChild functions, that's a bust because no forum software allows posting of Javascript and if he tried to use a PHP generated image to load the Javascript code, it can't be done because the content-type is set to image/jpeg or whatever image format and trying to output html/javascript would throw a php error.

So how do cookie stuffers do it ? Cookies are stuffed using 1x1 pixel iFrames. One of the cheesiest methods known to developers. They build a page with a hidden iFrame and put that page into rotation in autosurf or traffic exchange programs like TS25 or TrafficPods, LinkReferral, ClixSense, etc... Using ClixSense, a stuffer could pay $5 for 1000 hits to his page and 1000 stuffs. Rinse, repeat and you're stuffing your way to profits.

I'm sure Shawn probably thought he could just say "It wasn't me" that put that iFrame with my affiliate code there, it was someone I banned from my forum who is out to get me. Needless to say, it's no suprise that lazy programmers who get a taste of success at a young age want to party like rockstars and will take shortcuts to profits so they can spend their days and nights with bongs, booze and babes.

My opinion is if eBay really has solid evidence (like a history of payments) they should throw the book at Shawn and make an example of him for all the lazy black hat's who want something for nothing.

btw, has anybody noticed how much spam has been on the decline since "Spam King" Edward Davidson was busted and commit suicide? Same with DDOS attacks since Gregory King was sentenced to two years in prison ?

Tossing the book at Hogan would certainly cause a lot of these black hat kiddies to think twice.
MajorTom is offline