IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Okay.
You know what PPC (Pay Per Click) advertising is.

Now, think about some one having hundreds of Pharmacy or pr0n sites... with TONS-o-Banner ads.

Now, think about some one having a pretty nice pipe that happens to have a misconfigured gloabl variable for an Apache server. that being global "ProxyRequests On" with no deny or anything keeping it from helping out.

Now imagine, using a zombie network of hundres of thousands machines to use that misconfigured Apache server as an http proxy. Along with the 30K or so other misconfugred other servers out there.

Now, imagine them using that setup to "randomly click" on those banner-ads or google-ads using a 30Kx300K matrix

Nearly impossible to see the patterns, nearly impossible to see the directions... etc.

Get paid HUGE money. We are talking about lotsa money.

Knight was a single of many proxy machines being used.

14,000 unique IP Addresses. lotsa different websites as targets.


I have to say, once I fixed the issue, the rate increase quite a bit. But then the requests atarted to look less complex and then the all changed (within a few seconds) to probing to check if it was still working. Then they started trying different methods to discover if I just changed something or fixed the problem.

Here is a site many tried to get after I fixed it: [link|http://grem-too.com/cspamitvsax/proxy.php|http://grem-too.com/...mitvsax/proxy.php]

Neato huh?
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
Freedom is not FREE.
Yeah, but 10s of Trillions of US Dollars?
SELECT * FROM scog WHERE ethics > 0;

0 rows returned.
New Sounds like you saw them working it in real time
So this is slightly beyond script-kiddie activity.

Pay-per-click advertising will die once enough people know it's being abused like this.</naive optimism>
===

Purveyor of Doc Hope's [link|http://DocHope.com|fresh-baked dog biscuits and pet treats].
[link|http://DocHope.com|http://DocHope.com]
     Update on Z's response times? Megapath dumping packets? - (Another Scott) - (10)
         1,546,001 Click Fraud Proxy requests since Jun 11 7:36AM - (folkert) - (3)
             "Click Fraud Proxy requests" - (broomberg) - (2)
                 Okay. - (folkert) - (1)
                     Sounds like you saw them working it in real time - (drewk)
         It has been slow for me for many months - (lincoln)
         Bwahahaha. - (folkert)
         Yet another Update for uptime stats. - (folkert) - (3)
             you might want to contact this guy as well - (boxley)
             Law "enforcement"?!? Surely you jest... - (jb4)
             Thanks muchly! Write up the details! - (Another Scott)

YOU DON'T EVEN RECOGNIZE THE *real* KNOPPIX INTERPRETER
83 ms